Anti-Money Laundering, Counter-Terrorist Financing & Know-Your-Customer Policy
Operator: Reloader (operated by [NEEDS: registered legal entity name, e.g. "____ Ltd"]) ("Reloader", "the Operator", "we", "us"). Registered office: [NEEDS: registered address]. Licence: Anjouan Gaming Licence No. [NEEDS: licence number], issued under the Computer Gaming Licensing Act / Gaming (Betting) Act 2005 and supervised by the Anjouan Offshore Financial Authority (AOFA) together with Anjouan Licensing Services Inc. (ALSI). Effective date: [NEEDS: on approval]. Version: 1.0. Important: This document is a working template prepared to reflect the AML/CFT obligations applicable to operators licensed in Anjouan (Union of the Comoros). It must be reviewed, completed, and approved by qualified legal/compliance counsel and adopted by the Operator's board before it is relied upon, published, or submitted to the regulator. Bracketed [NEEDS] fields require Operator-specific confirmation.
- Purpose and Regulatory Framework 1.1 This Policy sets out the framework, controls, and procedures by which Reloader identifies, assesses, mitigates, and manages the risks of money laundering ("ML") and terrorist financing ("TF") arising from its online gaming operations, and ensures compliance with its obligations as an Anjouan-licensed operator. 1.2 This Policy is designed to give effect to: (a) the Anjouan gaming licensing framework and the conditions of the Operator's licence as administered by AOFA and ALSI; (b) the Money Laundering (Prevention) Act No. 008 of 2005 of the Union of the Comoros and any regulations, directives, or guidance made under it; (c) applicable United Nations and other international sanctions measures; and (d) international standards issued by the Financial Action Task Force ("FATF"), including the risk-based approach and the FATF Recommendations on virtual assets. 1.3 Where the Operator also serves, markets to, or accepts customers connected with other jurisdictions, it will additionally observe the higher of the applicable AML/CFT standards.
- Scope 2.1 This Policy applies to all Reloader operations, including reloader.gg, play.reloader.gg, and all *.reloader.gg Alliance subdomains, and to all directors, officers, employees, contractors, and Alliance Partners insofar as their activities touch customer onboarding, payments, or monitoring. 2.2 It covers all products and channels through which value enters, moves within, or leaves the platform, including deposits, wagering, the Loads (Ł) credit economy, bonuses and rewards, withdrawals, and any peer-to-peer or social value-transfer features.
- Definitions Money laundering: the process of concealing the origin of criminally derived property, or converting or transferring such property to disguise its illicit source. Terrorist financing: the provision or collection of funds intended to be used to carry out terrorist acts. Customer / player: any natural person who registers, deposits, wagers, or withdraws on the platform. Beneficial owner: the natural person who ultimately owns or controls a customer or on whose behalf a transaction is conducted. CDD: Customer Due Diligence. EDD: Enhanced Due Diligence. PEP: a Politically Exposed Person, being an individual entrusted with a prominent public function, and their family members and close associates. MLRO: the Money Laundering Reporting Officer / AML-CFT Compliance Officer appointed under section 4. STR: Suspicious Transaction Report. Virtual asset: a digital representation of value that can be traded or transferred and used for payment, including the cryptocurrencies accepted by the Operator.
- Governance and the AML/CFT Compliance Officer (MLRO) 4.1 The Operator's board holds ultimate responsibility for AML/CFT compliance and for approving this Policy and its risk assessment. 4.2 The Operator appoints a qualified AML/CFT Compliance Officer (MLRO): [NEEDS: name and title]. The MLRO is a fit-and-proper person of sufficient seniority and independence, with authority and resources to discharge the role, and is the primary point of contact with AOFA/ALSI and any competent authority. 4.3 The MLRO's responsibilities include: maintaining this Policy and the risk assessment; overseeing CDD/EDD; managing sanctions and PEP screening; operating transaction monitoring; receiving internal suspicion reports and deciding on external reporting; maintaining records; delivering staff training; and reporting to the board at least [NEEDS: quarterly] and on material matters without delay. 4.4 A deputy [NEEDS: name] is appointed to act in the MLRO's absence.
- Risk-Based Approach and Enterprise-Wide Risk Assessment 5.1 The Operator applies a risk-based approach, allocating controls proportionate to assessed ML/TF risk. 5.2 The Operator maintains a documented enterprise-wide risk assessment identifying and evaluating ML/TF risks across: (a) customer risk (e.g. anonymity, PEP status, adverse media); (b) geographic risk (customers from or connected to high-risk or sanctioned jurisdictions); (c) product/service risk (rapid deposit-to-withdrawal, crypto rails, skins-based value, rewards convertibility); (d) channel/delivery risk (non-face-to-face, remote onboarding); and (e) payment risk (virtual assets, third-party payment providers). 5.3 The risk assessment is reviewed at least annually and upon any material change to products, customer base, technology, payment methods, or applicable law. Each customer is assigned a risk rating (standard / high) that determines the level of due diligence and monitoring applied.
- Customer Due Diligence (CDD) / KYC 6.1 Onboarding. The Operator applies CDD before or during the establishment of the customer relationship and always before processing a first withdrawal. No customer may withdraw funds until identity verification is satisfactorily completed. 6.2 Standard identification data. The Operator collects and verifies, at minimum: full legal name; date of birth (confirming the customer is at least 18 or the age of majority in their jurisdiction, whichever is higher); residential address; nationality; and email/contact details. Identity is verified using reliable, independent sources. 6.3 Documentary verification. The Operator obtains a valid government-issued photographic identity document (passport, national ID, or driving licence) and, where required by risk, proof of address dated within the last three months (utility bill, bank/financial statement, or government correspondence). The Operator may apply electronic identity verification and liveness/biometric checks to confirm the customer is genuine and present. 6.4 Verification triggers. In addition to the pre-withdrawal requirement, verification (or re-verification) is triggered by, among other things: cumulative deposits or withdrawals reaching [NEEDS: threshold, e.g. EUR/USD 2,000 single or aggregated]; the customer being identified as a PEP or sanctions match; suspicious activity; inconsistent or suspect information; or reactivation of a dormant account. 6.5 Beneficial ownership. Where there is any indication that a customer is acting on behalf of another person, the Operator identifies and takes reasonable measures to verify the beneficial owner and understands the purpose and intended nature of the relationship. 6.6 One account. Each customer may hold only one account. The Operator applies anti-fraud and duplicate-account controls (including device, IP, and disposable-email detection) to detect multiple or synthetic identities. 6.7 Failure to complete CDD. Where CDD cannot be completed, the Operator will not open the account, will not process the transaction, will suspend account activity, and will consider whether the circumstances give rise to a reportable suspicion.
- Enhanced Due Diligence (EDD) 7.1 EDD applies to any customer or transaction assessed as higher risk, including: PEPs and their family members/close associates; customers connected with high-risk or sanctioned jurisdictions; customers exhibiting unusual patterns or high-value activity; and any relationship where standard CDD raises concern. 7.2 EDD measures include: obtaining additional identity and background information; establishing source of funds and, where appropriate, source of wealth; obtaining senior management (MLRO or board) approval to establish or continue the relationship; and applying enhanced ongoing monitoring with more frequent review. 7.3 The Operator screens all customers against PEP and adverse-media data at onboarding and on an ongoing basis, and treats a PEP relationship as high risk for so long as the risk persists.
- Sanctions Screening 8.1 The Operator screens all customers (and, where relevant, counterparties and wallet addresses) against applicable sanctions lists, including United Nations Security Council consolidated lists and any other lists applicable to the Operator, at onboarding and on an ongoing basis as lists are updated. 8.2 The Operator will not establish or continue a relationship with, or process a transaction for, any person subject to applicable financial sanctions, will freeze relevant assets as required, and will report matches to the MLRO and competent authorities as required by law. 8.3 The platform is not available to persons located in or accessing from restricted jurisdictions [NEEDS: list]. Geolocation and IP controls support enforcement of these restrictions.
- Source of Funds and Source of Wealth 9.1 The Operator obtains and, where risk requires, verifies the source of funds used for deposits, and for higher-risk customers the source of wealth. Requests may include bank/payment statements, proof of ownership of crypto assets, salary or business documentation, or other credible evidence. 9.2 Where a satisfactory explanation of source of funds/wealth is not provided, the Operator may decline the transaction, suspend the account, and consider filing an STR.
- Payments, Crypto and Skins-Specific Controls 10.1 Accepted methods. The Operator accepts value through the payment methods it publishes from time to time, which currently include cryptocurrency deposits (e.g. USDT and other supported assets) via [NEEDS: named payment provider] and CS2 in-game items via [NEEDS: named skins provider], credited at assessed value after any applicable trade-protection hold. 10.2 Virtual-asset controls. For crypto deposits and withdrawals, the Operator applies blockchain analytics/wallet screening to detect exposure to sanctioned addresses, darknet markets, mixers/tumblers, and other high-risk sources; declines or freezes transactions with unacceptable risk exposure; and observes applicable "travel rule" and VASP-related obligations where relevant. Deposits and withdrawals are, so far as practicable, restricted to wallets in the customer's control, and third-party payments are prohibited. 10.3 No third-party funding. Customers may only fund and withdraw using instruments and wallets in their own name/control. The Operator declines identified third-party deposits or withdrawals. 10.4 Skins/items. In-game items accepted as deposits are assessed for value and provenance; items linked to fraud, trade holds, or suspicious sourcing are rejected. 10.5 No chargebacks / reversibility abuse. The Operator monitors for payment-reversal abuse and treats coordinated reversal activity as a potential ML indicator.
- The Loads (Ł) Economy and Withdrawal Controls 11.1 Reward-balance funds (bonuses, promotions, campaigns, level rewards) are not directly withdrawable and become withdrawable only after satisfying applicable wagering requirements and converting to real-money balance. Only real-money (deposit-sourced) balance is withdrawable. This structure limits the platform's exposure to being used purely as a value-transfer conduit. 11.2 The Operator monitors for "minimal-play" or "pass-through" patterns — deposits followed by little or no genuine play and prompt withdrawal — which are treated as ML red flags and may trigger EDD, holds, and STR consideration. 11.3 Withdrawals are subject to KYC/AML checks and, where warranted, manual review; the Operator may decline, delay, or claw back a withdrawal where it reasonably suspects fraud, error, abuse, or breach.
- Ongoing Monitoring and Transaction Monitoring 12.1 The Operator conducts ongoing monitoring of the business relationship and scrutinises transactions to ensure they are consistent with its knowledge of the customer, their risk profile, and their source of funds. 12.2 Automated and manual monitoring detects unusual or suspicious patterns, including but not limited to: rapid deposit-and-withdraw with minimal play; structuring of deposits/withdrawals below thresholds; high-velocity or high-value activity inconsistent with profile; use of multiple accounts or coordinated play; transactions involving high-risk jurisdictions or flagged wallets; and sudden changes in behaviour. 12.3 Alerts are reviewed and dispositioned by the compliance team; the customer's risk rating and CDD are refreshed as appropriate.
- Identifying and Reporting Suspicious Activity 13.1 Any employee, contractor, or Alliance Partner who knows or suspects, or has reasonable grounds to know or suspect, that a customer or transaction is connected with ML/TF must report it to the MLRO promptly and without alerting the customer. 13.2 The MLRO evaluates internal reports and, where suspicion is established, files a Suspicious Transaction Report (STR) with the competent authority / Financial Intelligence Unit of the Union of the Comoros and/or AOFA as required by the Money Laundering (Prevention) Act No. 008 of 2005 and applicable directions, within any prescribed timeframe, and cooperates with follow-up requests. 13.3 The Operator may freeze or restrict an account and delay a transaction pending assessment where reporting obligations may arise.
- Tipping-Off and Confidentiality 14.1 No person may disclose to a customer or any third party that a suspicion has been raised, an STR has been or may be filed, or that an investigation is under way, where such disclosure is likely to prejudice an investigation ("tipping-off"). Breach is a serious matter and may constitute an offence. 14.2 AML/CFT information is handled confidentially and shared only with those who need it for compliance purposes or as required by law.
- Record Keeping 15.1 The Operator retains CDD/EDD records, account and transaction records, screening results, internal suspicion reports, STRs, MLRO decisions, and training records. 15.2 Records are retained for at least [NEEDS: retention period — commonly 5 years, confirm against Anjouan/Comoros requirements] following the end of the customer relationship or the completion of the transaction, or longer where required by law or requested by a competent authority, and are made available to AOFA/ALSI and other authorities on request.
- Staff Training and Awareness 16.1 All relevant staff receive AML/CFT training on induction and at least annually thereafter, covering ML/TF risks, this Policy, red-flag indicators, CDD/EDD, sanctions, the internal reporting route to the MLRO, and tipping-off. 16.2 Training is recorded and its effectiveness is periodically assessed. Additional targeted training is provided when risks, systems, or obligations change.
- Third-Party Providers, Alliance Partners and Outsourcing 17.1 Where the Operator relies on third parties (payment processors, KYC/verification vendors, game or platform providers), it satisfies itself that they meet appropriate standards and, where required under the Anjouan framework, hold a B2B licence or valid B2B Recognition Certificate. The Operator remains responsible for compliance and retains access to underlying CDD data. 17.2 Alliance Partners are independent marketing/community partners and are not operators; they do not hold customer funds or perform CDD. The Operator remains responsible for onboarding, monitoring, and reporting for all customers, including those introduced through Alliance channels, and requires Alliance Partners to report any AML/CFT concerns to the MLRO.
- Responsible Gaming Interface 18.1 AML/CFT monitoring operates alongside responsible-gaming controls. Indicators of harm or of funds beyond a customer's apparent means may be relevant to both frameworks; the compliance and responsible-gaming functions share information as appropriate.
- Independent Review, Audit and Assurance 19.1 The adequacy and effectiveness of this Policy and the AML/CFT programme are subject to independent review/audit at least [NEEDS: annually], with findings reported to the board and remediation tracked to completion. 19.2 The Operator cooperates fully with AOFA/ALSI supervisory reviews, information requests, and inspections, and implements required corrective actions.
- Governance, Review and Approval 20.1 This Policy is reviewed at least annually and upon material change to the business, risks, or applicable law. 20.2 Non-compliance by staff or partners may result in disciplinary action, termination, and referral to authorities. The Operator recognises that AML/CFT non-compliance may lead to regulatory action by AOFA/ALSI up to and including suspension or revocation of the licence. 20.3 Approved by the board of [NEEDS: entity name] on [date]. Signed: [NEEDS: name, title]. MLRO: [NEEDS: name]. Next review due: [date].