AML and KYC Compliance Policy
AML – KYC Policy
Last updated: 15-04-2026
1. Policy Objective
This Anti-Money Laundering and Know Your Customer Policy explains the comprehensive measures that HMC Ltd. (referred to as "the Company," "Us," "We," or "Whaleplay") has implemented to prevent money laundering, terrorist financing, and other financial crimes within our online gaming operations.
While the Company does not operate as a traditional financial institution, we are classified as a designated "reporting entity" under several important regulatory frameworks. This designation means we have specific legal obligations to monitor, report, and prevent financial crimes.
Our reporting obligations are governed by the Money Laundering (Prevention) Act 2005 of the Union of the Comoros and the Computer Gaming Licensing Act 007 2005, along with the related Anti-Money Laundering and Know Your Customer Code issued by Gaming Control Anjouan.
This policy has been designed to achieve three primary objectives that protect both our business and our customers. First, we aim to prevent the misuse of HMC Ltd.'s online gaming services for money laundering activities or terrorist financing purposes. Second, we establish comprehensive internal procedures covering customer identification processes, due diligence requirements, ongoing transaction monitoring, and suspicious activity reporting protocols. Third, we ensure full compliance with applicable European Union regulations that impose sanctions, embargoes, and restrictions on dual-use goods and technologies as defined in the current regulatory framework below:
2. Regulatory Framework
This policy aligns with the following EU directives and regulations:
- Directive (EU) 2015/849 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing.
- Regulation (EU) 2015/847 on information accompanying transfers of funds.
- Relevant EU sanctions regulations imposing restrictive measures against individuals, entities, and embargoes on certain goods and technologies, including dual-use items.
Applicable local AML/CFT laws and licensing conditions within the operator's jurisdiction.
- Money Laundering (Prevention) Act 2005 of the Union of the Comoros;
- Computer Gaming Licensing Act 2005 and the related AML & KYC Code issued by Gaming Control Anjouan; and
3. Definitions
Money Laundering (ML) - refers to the process of disguising illicitly obtained funds to make them appear legitimate and lawful. This involves concealing the true origin, ownership, or destination of money that has been gained through illegal activities.
Terrorist Financing (TF) - encompasses the act of providing, collecting, or facilitating the transfer of funds that are intended to support terrorist activities, organizations, or individuals involved in terrorism.
Customer Due Diligence (CDD) - represents our standard procedures for identifying and verifying the restricted identity of our customers. This process helps us understand who our customers are and assess the risks they may present to our platform.
Enhanced Due Diligence (EDD) - involves implementing additional and more intensive scrutiny measures for customers or transactions that present higher risks. This may include more detailed background checks and ongoing monitoring.
Politically Exposed Person (PEP) - refers to individuals who hold or have held prominent public positions, such as government officials or senior executives of state-owned enterprises, as well as their close associates and family members.
Risk-Based Approach (RBA) - describes our method of adjusting compliance controls and monitoring procedures based on the assessed level of risk presented by different customers, transactions, or business relationships.
Sanctions Screening - involves systematically checking our customers and their transactions against European Union sanctions lists and other international sanctions databases to ensure compliance with applicable restrictions.
User/Customer - means any individual who has registered as a player on Whaleplay's gaming platform and uses our services.
Third-Party Verification Tool - refers to external service providers, such as Jumio, that we utilize to conduct identity verification and document authentication services on our behalf.
4. Customer Identification and Verification (KYC)
Customer identification serves as a fundamental component of our anti-money laundering framework and plays a critical role in ensuring the legitimacy of all transactions and user profiles on our platform. Through proper identification procedures, we can verify that our customers are who they claim to be and maintain the integrity of our gaming environment.
To complete the customer identification process, Users must provide the following documentation and information either directly through our platform interface or through our trusted third-party verification tools (e.g., Jumio):
- Valid government-issued photo ID.
- Proof of residential address (dated within the last 3 months).
- Verification of payment methods used.
Geofencing: access is blocked to all FATF-blacklisted and Anjouan-restricted jurisdictions.
4.1 Customer Due-Diligence (CDD)
1. Standard
Trigger: Account creation
Minimum Requirements:
- e-mail verification
- IP/geolocation screening
- Screening of wallet/IBAN via blockchain analytics provider
Ongoing Monitoring: Automated behaviour & sanctions screening
2. Enhanced (EDD)
Trigger: Red-flag event OR PEP
Minimum Requirements:
- Government-issued photo ID
- Live selfie or biometric match
- Proof of address (≤ 90 days)
- Source-of-funds/wealth questionnaire
Ongoing Monitoring: Transaction-pattern review every 30 days
3. High-Risk / E-High-Risk
Trigger: Crypto mixers, high-risk jurisdictions, adverse media
Minimum Requirements:
- Independent SoF/SoW verification (bank statements, payslips etc.)
- Senior management approval
Ongoing Monitoring: Continuous, MLRO-led
4.2 Financial Thresholds and Information Requests
To ensure we maintain proper due diligence standards and effectively mitigate financial crime risks, we have established specific limits and verification steps that apply to all customer accounts. These measures are designed to protect both our platform and our customers while maintaining compliance with regulatory requirements. The following limits and steps apply:
If a customer's balance is at least five (5) times greater than the total sum of all deposits, the customer:
- Will be subject to enhanced due diligence.
- Will be required to provide proof of source of funds and source of wealth.
- Will be limited to a maximum withdrawal of 5,000 USDT (or currency equivalent) per month until verification is complete.
In all other cases:
- The maximum withdrawal amount is 50,000 USDT per week, and 200,000 USDT per month.
- Withdrawals exceeding these thresholds may be subject to additional verification and documentation.
All documentation must be submitted through secure channels. The Compliance Team reserves the right to request further details before approving or processing transactions.
4.3 Enhanced Due Diligence
EDD is triggered in scenarios such as:
- High-value transactions or large balances.
- High-risk geographic locations.
- PEP status.
- Disproportionate gambling activity compared to known income.
EDD measures include:
- Source of Funds (e.g., salary slips, inheritance, asset sale).
- Source of Wealth (e.g., investment portfolio, property holdings).
- In-depth identity verification and transaction reviews.
5. User Verification Process Table
Our user verification process is designed to be transparent and straightforward while ensuring we meet all regulatory requirements. The licensee must gather, review, and confirm player ID and KYC documents consisting of no less than a recently issued, valid government photo id and a recently issued utility bill in the players name when an aggregate total deposits for play reaches US $10,000 or equivalent.
Mandatory for All Withdrawals
Trigger / Requirement: Required before any withdrawal or payment is processed.
Verification Actions:
Complete online registration form:
- First and second names
- Gender
- Date of birth
- Country of residence
- Upload a clear photo of the official ID (passport, national ID, or driver's license).
- Include a handwritten note with six randomly generated digits next to the ID in the photo.
- The system will perform electronic validation via two independent databases.
- If electronic checks fail, users must submit proof of residence (e.g., government-issued certificate of registration).
Notes: Mandatory regardless of withdrawal amount, payment method, or nationality.
6. Documentation Standards
ID Verification
- Clear image of the ID document with all four corners visible
- Six-digit handwritten note displayed next to the ID
- A separate selfie holding the ID
- Only essential information must remain visible; others may be blurred
Proof of Address
This is Automatically verified using 3rd party tool such as Jumio, however, if verification fails, user must upload one of the following (dated within 3 months):
- Utility bill
- Bank statement
- Government-issued correspondence
- Document must be clearly legible with all four corners visible
7. Withdrawal Limits and Financial Triggers
To help protect against financial crime and ensure the safety of your account, we have established certain withdrawal limits and financial monitoring rules. These guidelines are designed to keep your transactions secure and compliant with regulatory requirements. The following limits and rules apply:
If your account balance exceeds 5× the total of your deposits:
· You will be limited to 5,000 USDT (or currency equivalent) per month in withdrawals until further verification.
In all other cases:
· Maximum weekly withdrawal: 50,000 USDT
· Maximum monthly withdrawal: 200,000 USDT
The maximum winning payout per single game round is 50,000 USDT (or equivalent). Any winnings that exceed this limit in a single game round will be capped at 50,000 USDT, and the Customer will be entitled to receive only the maximum payout amount.
Withdrawals exceeding these limits will be subject to further KYC checks, and funds may be held until verification is completed.
8. Politically Exposed Persons (PEPs)
If a user is identified as a Politically Exposed Person, we apply extra checks to reduce potential risks. Any dealings with a PEP must be carefully reviewed, fully documented, and approved by senior compliance staff before proceeding.
9. Sanctions and High-Risk Jurisdictions
We do not accept customers from countries under international sanctions or from jurisdictions classified as high-risk by the FATF or EU regulations. All customers are screened against the latest global sanctions lists on an ongoing basis to ensure compliance.
10. Record-Keeping
All identification, transactional, and verification records will be stored securely for a minimum of five (5) years post-relationship termination, as required by applicable law.
Record Types and Retention:
1. KYC files
Retention: ≥ 5 years after relationship ends
2. Transaction data, game logs
Retention: ≥ 7 years (licence condition)
3. Training & audit reports
Retention: ≥ 5 years
Records are secured on encrypted servers hosted in Anjouan, in line with the regulator’s data-localisation requirement.
11. Ongoing Monitoring and Reporting
Our AML-Compliance ensures that an "ongoing transaction monitoring" is conducted to identify any activity that is unusual or suspicious relative to a customer's profile.
- Continuous monitoring is carried out through a combination of automated systems and manual reviews to ensure thorough oversight.
- Any suspicious transactions or behaviors are escalated internally and may be reported to the relevant Financial Intelligence Units (FIUs) as required by law.
- All employees receive regular AML training and are expected to promptly report any concerns to the Compliance Officer.
Whaleplay ensures that ongoing transaction monitoring is conducted to detect unusual or suspicious activity in relation to each customer's profile. This monitoring is carried out through a three-tiered system that combines automated checks, employee oversight, and compliance escalation, ensuring full alignment with regulatory requirements.
Suspicious Transaction Reporting
- All employees must escalate red-flag activity to the MLRO within one (1) business day.
- The MLRO files STRs to the Comoros FIU via the secure reporting portal within 48 hours of determining suspicion, in accordance with the Money Laundering (Prevention) Act 2005.
- A zero-reporting regime is in place (monthly nil-return if no STRs)
Monitoring and Controls
- Real-time rule engine flags anomalies (velocity, amount, device mismatch, sudden jurisdiction changes).
- Blockchain analytics (e.g., Chainalysis or equivalent) classify crypto deposits/withdrawals; (high-risk) auto-freeze the transaction pending MLRO review.
- Withdrawal lock until KYC is completed and approved
- Account aggregation to detect multi-accounting and ban-evasion attempts.
- Manual review for: Bonus abuse, cascading bonuses, chip-dumping, suspected collusion.
Three-tiered control system
First Line of Control: Payment Service Provider (PSP) Oversight
Whaleplay partners exclusively with trusted Payment Service Providers (PSPs) that maintain strong AML policies and comprehensive KYC procedures. This first line of defense helps ensure that potentially suspicious deposits are identified before they reach the Whaleplay platform. PSPs act as a gatekeeper by verifying customer identities and conducting thorough due diligence during onboarding and funding.
Second Line of Control: Internal Monitoring and Due Diligence
Whaleplay ensures that all internal teams and customer-facing staff are aware that any interaction with a customer, player, or authorized representative must trigger a heightened awareness and exercise of due diligence regarding the customer's transactions.
This includes but is not limited to:
- Requests to execute financial transactions on the account.
- Inquiries or requests relating to payment methods or services linked to the account.
Our internal monitoring process includes:
- Three-step verification with risk-based adjustments to keep customer information accurate and up to date.
- Automated transaction screening through a dedicated monitoring system.
- Human oversight, where a qualified employee reviews flagged transactions to ensure accuracy.
- The AML Compliance Officer oversees all monitoring activities and escalations, with additional oversight provided by General Management.
Specific transactions routed to the Customer Support Manager or via their Compliance Manager are also subject to enhanced due diligence protocols.
Suspicious or unusual activity is determined based on:
- The customer's known profile and KYC data.
- Their financial behaviour and patterns.
- The identity and nature of the transaction counterparty.
Any transaction that cannot be explained by a lawful purpose or source of funds is considered atypical and must be escalated immediately. Employees who identify such transactions are required to promptly report them to the AMLRO.
Third Line of Control: Manual Review and Escalation
As the final layer of defence against money laundering, Whaleplay conducts manual reviews of all suspicious or high-risk user activity. This level of scrutiny applies to users or transactions that are flagged as:
- Irregular or complex.
- Inconsistent with the customer profile.
- Potentially fraudulent or indicative of money laundering.
If fraud or money laundering is suspected or confirmed, Whaleplay will immediately notify the appropriate authorities in accordance with applicable law.
Reporting of Suspicious Transactions
Whaleplay has established clear internal procedures for handling suspicious activity. These procedures define:
- When and how staff must report suspicious activity.
- The precise reporting workflow.
- The responsible roles involved in decision-making.
All reports of atypical transactions are reviewed by the AML Team, following a structured methodology as outlined in the internal compliance manual.
Based on the findings and evidence gathered, the AML Team will:
- Determine whether a Suspicious Transaction Report (STR) should be submitted to the Financial Intelligence Unit (FIU), in accordance with the Law of 18 September 2017.
- Assess whether it is necessary to terminate the business relationship with the customer involved.
12. Risk Management
To manage varying levels of financial risk across different regions, Whaleplay classifies all countries into three distinct risk categories.
These classifications help guide the application of tailored verification and compliance measures, ensuring that each customer is subject to the appropriate level of scrutiny based on their region's risk profile.
Regional Risk Classifications:
1. Region One (Low Risk)
Risk Level: Low Risk
Verification Triggers: Standard thresholds apply as per the three-step verification process.
Verification Steps: Follows Step One, Step Two, and Step Three as outlined in the verification policy.
2. Region Two (Medium Risk)
Risk Level: Medium Risk
Verification Triggers:
- Step One: Initial registration
- Step Two: Triggered after deposits or withdrawals totalling 2,000 USDT, or tips over 500 USDT
- Step Three: Triggered after deposits or withdrawals over 5,000 USDT or tips over 3,000 USDT
- Crypto conversion also treated as Region Two
Verification Steps: Same verification steps as Region One, but thresholds are lower.
3. Region Three (High Risk)
Risk Level: High Risk
Verification Triggers: Usage of www.whaleplay.com is prohibited.
Verification Steps: Access denied. Regular updates applied to the high-risk region list.
Additional Measures
An AI system, supervised by the AML Compliance Officer, monitors unusual behaviour to detect unusual behavior and immediately reports it to the relevant personnel.
Following a risk-based approach and leveraging institutional experience, human employees review all AI-generated alerts and other staff reviews, performing additional verifications as needed.
In addition, advanced electronic analytic systems are used to monitor for suspicious patterns, including, but not limited to:
- Deposits and withdrawals without significant betting activity
- Use of different bank accounts for deposits and withdrawals
- Nationality or currency changes
- Sudden behavioural or activity shifts
- Verification that the account is being used by its original owner
To prevent money laundering, users must withdraw funds using the same method initially used for deposits, at least for the amount of the original deposit.
Enterprise-Wide Risk Assessment (EWRA)
As part of its risk-based approach, Whaleplay conducts an annual Enterprise-Wide Risk Assessment (EWRA) to identify and understand AML risks unique to its platform and service offerings.
The assessment takes into account:
- Services offered by the platform
- User profiles and activity patterns
- Transaction types and volumes
- Delivery channels used
- Geographic locations involved in operations and transactions
- Emerging qualitative and quantitative risks, particularly those unique to internet-based services
AML risk categories are determined based on Whaleplay’s interpretation of regulatory requirements, industry best practices, and standards. The EWRA is updated every year to ensure the company continuously adapts to the evolving risk landscape.
Risk Domains and Assessment
1. Services Provided by Platform
Impact: High | Likelihood: Medium | Risk Level: High
Description: Core functionalities such as payment processing, data storage, user interaction, and service integration
Potential Risks: Data breaches, Service outages, Compliance failure (e.g. GDPR, PCI-DSS)
Mitigation Strategy: Regular penetration testing, Compliance audits, Redundant architecture
2. User Profiles and Activities
Impact: High | Likelihood: High | Risk Level: Critical
Description: Range from individual users to corporate accounts, with varying access rights and activities
Potential Risks: Account takeover, Identity theft, Insider threats
Mitigation Strategy: Multi-factor authentication, Activity monitoring, Role-based access control
3. Transaction Types and Volumes
Impact: High | Likelihood: Medium | Risk Level: High
Description: Financial transactions, data transfers, subscriptions, etc.
Potential Risks: Fraudulent transactions, Money laundering, Transactional errors
Mitigation Strategy: KYC/AML controls, Transaction limits, Real-time fraud monitoring
4. Delivery Channels
Impact: Medium | Likelihood: High | Risk Level: High
Description: Web, mobile apps, APIs, third-party integrations
Potential Risks: Channel-specific vulnerabilities, API abuse, Session hijacking
Mitigation Strategy: Secure API gateways, Rate limiting, TLS encryption
5. Geographic Locations Involved
Impact: Medium | Likelihood: Medium | Risk Level: Medium
Description: Cross-border operations, multi-jurisdictional data handling, and financial transactions
Potential Risks: Regulatory conflicts, Sanctioned entities, Currency controls
Mitigation Strategy: Legal counsel reviews, Geo-blocking high-risk regions, Compliance with local laws
6. Emerging Risks (Qualitative & Quantitative)
Impact: High | Likelihood: Medium | Risk Level: High
Description: Includes rapidly evolving threats such as AI-generated fraud, zero-day exploits, and platform manipulation.
Potential Risks: Synthetic identity fraud, Deepfake social engineering, Market manipulation via bots
Mitigation Strategy: AI-powered anomaly detection, Staff awareness training, Continuous threat intelligence
7. Reputational Risk
Impact: High | Likelihood: Medium | Risk Level: High
Description: Public perception shaped by service performance, breaches, or negative news
Potential Risks: Loss of user trust, Media exposure from incidents, Regulatory sanctions
Mitigation Strategy: Crisis response planning, Transparent communication, Reputation monitoring tools
Residual Risk Summary
While existing controls are robust, some risks remain:
- Residual Risks - Cross-border compliance gaps, sophisticated cyber-attacks, and evolving fraud techniques.
- Risk Appetite - Moderate – Whaleplay aims to grow its platform while minimizing operational and regulatory risks.
Recommendations
1. Continuous Risk Monitoring: Implement a dynamic monitoring system that updates in real time.
2. Enhanced User Verification: Strengthen identity verification measures to deter fraudulent activity.
3. Regulatory Intelligence: Proactively track global regulatory changes, particularly in financial services.
4. Incident Response Plan: Maintain a tested, scalable strategy for responding to incidents.
5. Third-Party Risk Assessment: Regularly audit vendors and partners to ensure alignment with security and compliance standards.
13. Policy Review
This policy will be reviewed every 12 months or following any major legal or regulatory update. Or on the anniversary of the date of issue. Updates will be approved by senior management and communicated appropriately to all stakeholders.
14. Auditing
Internal audits are regularly conducted to assess the effectiveness of AML measures and procedures. These audits include detailed missions and reporting related to AML activities, ensuring continuous improvement and accountability.
- An AML expert reviews the programme at least every 12 months.
- The policy itself is reviewed annually or promptly upon material changes in law, risk profile or regulator guidance (e.g., new advisories from Gaming Control Anjouan).
15. Data Security
We are committed to safeguarding all customer data:
- All personal and transactional data provided by users will be kept secure and confidential.
- Data will never be sold or disclosed to third parties, except:
- When required by law.
- When necessary to prevent money laundering or terrorist financing.
- When disclosure is mandated by an AML authority of the relevant jurisdiction.
Whaleplay fully adheres to applicable data protection regulations, including the EU Data Protection Directive (Directive 95/46/EC), and ensures that all systems and practices comply with the highest standards of information security.
16. Training and Awareness
At Whaleplay, Anti-Money Laundering (AML) and Know Your Customer (KYC) responsibilities are conducted with a risk-based approach. Human employees carry out manual controls based on their assessed risk level, and all personnel involved in these processes undergo specialized training to ensure effective compliance.
Our AML training and awareness program includes:
- Mandatory AML Training: All employees involved in financial operations must complete a mandatory AML training program. This training is aligned with the latest regulatory developments and tailored to the nature of the business.
- Onboarding AML Education: All new employees are required to attend introductory academic AML learning sessions.
16.1 Training
- Induction: within 2 weeks of hire (covers AML/CFT basics, customer red flags, escalation paths).
Annual refresher: e-learning plus short assessment (≥ 80% pass).
- Role-specific workshops for VIP team, payments, tech.
Attendance is logged; non-completion triggers account lock and HR notification
These sessions are conducted by an AML specialist from the AML Team, ensuring expert guidance and alignment with internal policy and regulatory expectations.
Non-Compliance & Disciplinary Action
Any breach of this policy is taken very seriously. Depending on the nature and severity of the violation, consequences may include account suspension, employment dismissal, regulatory reporting, and, in extreme cases, referral for criminal investigation.
Whaleplay maintains a zero-tolerance policy for willful or deliberate violations of AML requirements. All employees, contractors, and users are expected to fully comply with this policy to protect the integrity of the platform and ensure adherence to applicable laws and regulations.
17. Contact Information
For any questions or concerns regarding our AML and KYC Policy, please contact us:
General Inquiries: [email protected]
Complaints or Concerns: If you have any complaints regarding our AML/KYC checks or procedures, please reach out to us via email at [email protected] .
________________________________________
Annexure A — Key Red-Flag Indicators (non-exhaustive; apply to both fiat and crypto)
- Multiple accounts controlled from same device/IP;
- Deposits just below EDD threshold or immediately withdrawn without game play;
- Use of newly created, mixer-linked or sanctioned addresses;
- Rapid changes in location, device language or VPN usage;
- Attempts to bypass self-exclusion or responsible-gaming limits;
- Third-party card or wallet funding inconsistent with player profile.
