This page provides the intended corporate structure and plain-language content. It must be reviewed against the group’s final legal entities, processing activities, contracts, markets and applicable laws before publication.
1. Purpose and scope
Know Your Customer and anti-money-laundering controls help relevant services understand who they are dealing with, identify prohibited or suspicious activity and meet applicable obligations.
This overview does not state that every group entity or product is a regulated financial institution. The final controls must reflect the actual service, legal entity, payment flow, partners and jurisdictions involved.
2. Risk-based approach
Verification and monitoring should be proportionate to factors such as customer type, product, transaction value, geography, payment method, ownership structure and observed behaviour.
Lower-risk activity may require simpler checks, while higher-risk relationships or events may require additional evidence, approval or restrictions.
3. Identity verification
Where required, a service may collect and verify information such as legal name, date of birth, address, contact details, government-issued identification and a live or documentary check.
Verification methods should be approved, secure, accessible and designed to reduce impersonation, synthetic identities and use of another person’s credentials.
4. Organisations and beneficial ownership
Business customers and partners may be asked for registration details, operating address, authorised representatives, ownership or control information, tax or licensing information and the purpose of the relationship.
Where required, the service should identify the natural persons who ultimately own or control the organisation.
5. Sanctions, politically exposed persons and other screening
Relevant customers, owners, beneficiaries or transactions may be screened against approved sanctions, watchlist or politically exposed person data where required by law, contract or risk policy.
A potential match should be reviewed by authorised personnel rather than treated as a final conclusion without appropriate checks.
6. Transaction and behavioural monitoring
Relevant products may monitor patterns such as unusual transaction frequency, rapid movement of funds, linked accounts, repeated reversals, inconsistent customer information or activity that does not match the stated purpose of the account.
Monitoring rules should be tested, documented and reviewed to reduce both missed risk and unnecessary disruption to legitimate users.
7. Enhanced due diligence and restrictions
Higher-risk cases may require source-of-funds information, additional ownership evidence, senior approval, transaction limits, delayed settlement, periodic review or a decision not to begin or continue the relationship.
8. Records, retention and privacy
Verification evidence, screening results, review notes and relevant transaction records should be protected, access-controlled and retained only for the approved period.
Users should receive appropriate privacy information explaining what is collected, why it is needed, who may receive it and what rights apply.
9. Escalation and regulatory reporting
Potentially suspicious activity should be escalated to the authorised compliance function. Any external report, account restriction or disclosure must follow the applicable law, internal authority and confidentiality requirements.
Staff should not alert a person in a way that could compromise a lawful investigation or reporting duty.
10. Regional implementation
KYC, sanctions and anti-money-laundering requirements differ across markets and payment models. Each relevant product must document its responsible entity, applicable rules, service providers, thresholds, reporting routes and review schedule.