在真实商业与数字资本之间,构建桥梁
法律文件

KYC, AML & Sanctions Policy

此页面的中文版本正在由专业金融翻译审校中,暂以英文提供。The Chinese version of this page is being reviewed by a professional financial translator and is provided in English for now.
工作草案 v0.1-draft——供审阅;最终文本以法律审阅后为准。

ARCBDS KYC, AML & SANCTIONS POLICY

Including Counter-Terrorist Financing and Proliferation Financing Controls

Document No.: 8 of 14

Version: 1.0

Effective Date: [●]

Last Updated: [●]

Policy Owner: Money Laundering Reporting Officer / Compliance Department

Approved By: Board / Senior Management [●]

Next Review Date: [●]

1. POLICY STATEMENT

ARCBDS is committed to preventing its business, digital-asset infrastructure, Founding Circle programme, accounts, wallets, payment channels and ecosystem from being used for:

money laundering;

terrorist financing;

proliferation financing;

sanctions evasion;

fraud;

corruption;

bribery;

trafficking;

cybercrime;

ransomware;

theft;

market abuse;

proceeds of crime; or

other unlawful activities.

ARCBDS adopts a risk-based approach to Know Your Customer (“KYC”), Know Your Business (“KYB”), Anti-Money Laundering (“AML”), Counter-Terrorist Financing (“CFT”), Counter-Proliferation Financing (“CPF”), sanctions compliance and transaction monitoring.

All Founding Circle Participants must successfully complete applicable identity and compliance verification before participation is finally accepted.

2. PURPOSE

The purpose of this Policy is to establish controls for:

a. identifying Participants;

b. verifying Participants;

c. identifying Ultimate Beneficial Owners;

d. understanding the purpose and nature of relationships;

e. assessing customer risk;

f. screening sanctions;

g. identifying Politically Exposed Persons;

h. assessing source of funds;

i. assessing source of wealth where necessary;

j. screening digital wallets;

k. monitoring blockchain activity;

l. monitoring transactions;

m. detecting suspicious activity;

n. filing required reports;

o. complying with targeted financial sanctions;

p. complying with applicable Travel Rule obligations;

q. preventing sanctions circumvention;

r. maintaining appropriate records;

s. training personnel; and

t. maintaining an effective AML/CFT/CPF compliance programme.

3. SCOPE

This Policy applies to:

a. ARCBDS Website users where applicable;

b. Account holders;

c. prospective Founding Circle Participants;

d. existing Founding Circle Participants;

e. individual Participants;

f. companies;

g. family offices;

h. trusts;

i. foundations;

j. partnerships;

k. institutional Participants;

l. authorised representatives;

m. Ultimate Beneficial Owners;

n. referral participants;

o. business ecosystem partners where due diligence is required;

p. counterparties;

q. wallet holders;

r. Protection Reserve Claimants;

s. ARCBDS employees;

t. officers;

u. directors;

v. contractors; and

w. service providers performing compliance functions.

4. LEGAL AND REGULATORY FRAMEWORK

This Policy shall be implemented in accordance with Applicable Law, including where applicable:

a. Federal Decree-Law No. 10 of 2025 Regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing;

b. Cabinet Resolution No. 134 of 2025 regarding the implementing regulations of Federal Decree-Law No. 10 of 2025;

c. applicable UAE Targeted Financial Sanctions legislation;

d. applicable United Nations Security Council sanctions obligations;

e. applicable UAE Local Terrorist List requirements;

f. applicable beneficial-ownership legislation;

g. applicable UAE Financial Intelligence Unit requirements;

h. applicable VARA Regulations, Rules and Directives where ARCBDS or the relevant operating entity falls within VARA jurisdiction;

i. applicable FATF standards and guidance;

j. applicable foreign AML/CFT and sanctions requirements where legally applicable; and

k. other legally binding requirements applicable to ARCBDS activities.

Where a higher legally mandatory standard applies, that standard shall prevail.

5. REGULATORY STATUS

The final regulated entity responsible for ARCBDS compliance shall be identified before operational launch.

Legal Entity: [●]

Regulatory Authority: [●]

Licence / Registration Number: [●]

Licensed / Approved Activity: [●]

Nothing in this Policy constitutes a representation that ARCBDS currently possesses a particular regulatory licence unless such licence has been formally granted.

6. DEFINITIONS

For purposes of this Policy:

6.1 “AML”

means Anti-Money Laundering.

6.2 “CFT”

means Countering the Financing of Terrorism.

6.3 “CPF”

means Countering Proliferation Financing.

6.4 “CDD”

means Customer Due Diligence.

6.5 “EDD”

means Enhanced Due Diligence.

6.6 “KYC”

means Know Your Customer.

6.7 “KYB”

means Know Your Business.

6.8 “MLRO”

means Money Laundering Reporting Officer.

6.9 “PEP”

means Politically Exposed Person.

6.10 “Participant”

means any individual or legal entity applying for or maintaining an ARCBDS relationship.

6.11 “Sanctions”

means applicable targeted financial sanctions, restrictive measures and legally binding asset-freezing requirements.

6.12 “Suspicious Activity”

means conduct giving rise to knowledge, suspicion or reasonable grounds for suspicion of money laundering, terrorist financing, proliferation financing, proceeds of crime, sanctions evasion or related unlawful conduct.

6.13 “UBO”

means Ultimate Beneficial Owner.

6.14 “VA”

means Virtual Asset.

6.15 “VASP”

means Virtual Asset Service Provider as defined under Applicable Law.

6.16 “Wallet”

means a virtual-asset wallet address or account capable of receiving, holding or transferring Virtual Assets.

7. RISK-BASED APPROACH

ARCBDS shall assess and manage AML/CFT/CPF risk using a risk-based approach.

Risk factors may include:

a. Participant risk;

b. jurisdiction risk;

c. product risk;

d. service risk;

e. transaction risk;

f. wallet risk;

g. blockchain risk;

h. delivery-channel risk;

i. business-sector risk;

j. beneficial-ownership risk;

k. sanctions risk;

l. PEP exposure;

m. source-of-funds risk;

n. source-of-wealth risk;

o. referral risk;

p. counterparty risk; and

q. emerging financial-crime risk.

Higher-risk relationships shall receive stronger controls.

8. ENTERPRISE-WIDE RISK ASSESSMENT

ARCBDS shall maintain an enterprise-wide AML/CFT/CPF risk assessment.

The assessment should consider:

a. nature of ARCBDS activities;

b. Participant profiles;

c. geographic exposure;

d. digital assets used;

e. payment networks;

f. stablecoins;

g. blockchain characteristics;

h. wallet types;

i. transaction volumes;

j. business partners;

k. distribution channels;

l. technology;

m. emerging threats;

n. sanctions exposure; and

o. regulatory developments.

The assessment shall be reviewed periodically and following material changes.

9. GOVERNANCE

Ultimate responsibility for an effective AML/CFT/CPF framework rests with the Board and Senior Management of the applicable legal entity.

Senior Management shall:

a. approve this Policy;

b. support appropriate compliance resources;

c. establish a compliance culture;

d. oversee material AML/CFT/CPF risks;

e. approve high-risk relationships where required;

f. receive appropriate compliance reporting; and

g. ensure material deficiencies are remediated.

10. MONEY LAUNDERING REPORTING OFFICER

ARCBDS shall appoint a qualified MLRO where required by Applicable Law.

MLRO Name: [●]

Title: [●]

Contact: [●]

Deputy MLRO: [●]

Where VARA requirements apply, the MLRO shall satisfy applicable experience, fitness and propriety requirements.

11. MLRO INDEPENDENCE

The MLRO shall:

a. have sufficient authority;

b. have appropriate access to information;

c. have access to Senior Management;

d. be able to escalate matters independently;

e. receive appropriate resources;

f. be free from improper commercial interference; and

g. avoid material conflicts of interest.

Commercial teams must not overrule legally required suspicious-activity or sanctions decisions.

12. MLRO RESPONSIBILITIES

The MLRO shall be responsible for functions including:

a. implementation of this Policy;

b. AML/CFT risk assessments;

c. oversight of CDD;

d. oversight of EDD;

e. transaction-monitoring oversight;

f. sanctions-compliance oversight;

g. suspicious-activity investigation;

h. regulatory reporting;

i. FIU reporting where required;

j. AML/CFT training;

k. management reporting;

l. compliance-system oversight;

m. compliance-provider oversight;

n. recordkeeping oversight; and

o. periodic policy review.

13. COMPLIANCE DEPARTMENT

The Compliance Department may perform:

a. customer onboarding review;

b. document validation;

c. PEP screening;

d. sanctions screening;

e. adverse-media screening;

f. blockchain screening;

g. source-of-funds analysis;

h. source-of-wealth analysis;

i. transaction monitoring;

j. alert investigation;

k. periodic review;

l. wallet verification; and

m. case documentation.

14. THREE LINES OF DEFENCE

Where appropriate, ARCBDS should operate a three-lines framework:

First Line

Business and operations personnel are responsible for identifying and escalating compliance concerns.

Second Line

Compliance and risk functions establish controls and independently challenge the first line.

Third Line

Internal audit or independent assurance periodically assesses control effectiveness.

15. NO ANONYMOUS PARTICIPATION

ARCBDS shall not knowingly permit anonymous Founding Circle participation.

Every accepted Participant must be associated with a verified legal identity.

Pseudonymous blockchain addresses do not replace identity verification.

16. KYC REQUIRED FOR FOUNDING CIRCLE

All Founding Circle Participants must complete applicable KYC or KYB before final participation acceptance.

This requirement applies regardless of whether the minimum participation amount is below a regulatory occasional-transaction threshold because Founding Circle participation establishes an ongoing contractual and economic relationship.

17. INDIVIDUAL KYC INFORMATION

An individual applicant may be required to provide:

a. full legal name;

b. date of birth;

c. nationality;

d. country of birth;

e. residential address;

f. telephone number;

g. email address;

h. occupation;

i. employer;

j. tax residency;

k. identification document;

l. selfie/liveness verification;

m. wallet information;

n. expected participation amount;

o. source of funds;

p. source of wealth where required;

q. purpose of participation; and

r. other information required by Applicable Law.

18. ACCEPTABLE IDENTITY DOCUMENTS

Subject to jurisdiction and provider capability, acceptable documents may include:

a. passport;

b. national identity card;

c. government-issued residence identity;

d. another officially recognised identity document; or

e. another document approved by Compliance.

Documents must ordinarily be:

a. valid;

b. unexpired unless legally acceptable otherwise;

c. legible;

d. authentic;

e. sufficiently complete; and

f. issued by a recognised authority.

19. IDENTITY VERIFICATION

Identity may be verified using:

a. automated document verification;

b. biometric comparison;

c. liveness verification;

d. database verification;

e. manual document review;

f. government-record validation where legally available; or

g. another reliable independent method.

Verification should establish reasonable confidence that the applicant is the person they claim to be.

20. ADDRESS VERIFICATION

Where required, residential address may be verified through:

a. bank statement;

b. utility bill;

c. government correspondence;

d. tenancy documentation;

e. official registry data;

f. regulated financial-institution information; or

g. another reliable source.

Compliance may impose document-age requirements according to applicable procedures.

21. CORPORATE KYB

Legal entities may be required to provide:

a. full registered legal name;

b. trading name;

c. registration number;

d. incorporation date;

e. jurisdiction;

f. registered address;

g. operating address;

h. business activity;

i. constitutional documents;

j. licence;

k. certificate of incorporation;

l. register of directors;

m. shareholder register;

n. ownership structure;

o. UBO information;

p. authorised representative;

q. board resolution where required;

r. tax information;

s. bank or wallet information;

t. source of funds;

u. source of wealth where applicable; and

v. other information reasonably required.

22. LEGAL EXISTENCE

ARCBDS shall take reasonable steps to verify that a corporate Participant:

a. legally exists;

b. remains active where applicable;

c. has authority to enter the relationship;

d. carries on a legitimate activity; and

e. is not established solely to obscure beneficial ownership or unlawful activity.

23. AUTHORISED REPRESENTATIVES

Where a person acts on behalf of another individual or legal entity, ARCBDS may require:

a. identity verification of the representative;

b. evidence of authority;

c. board resolution;

d. power of attorney;

e. mandate;

f. specimen signature; and

g. other supporting documentation.

24. ULTIMATE BENEFICIAL OWNERSHIP

ARCBDS shall identify and verify UBOs where required.

Compliance shall seek to understand:

a. ownership structure;

b. control structure;

c. persons exercising ultimate effective control;

d. direct ownership;

e. indirect ownership;

f. nominee arrangements;

g. trusts or foundations; and

h. other arrangements capable of obscuring control.

25. COMPLEX OWNERSHIP STRUCTURES

Complex structures may require EDD where:

a. multiple holding companies are involved;

b. entities are incorporated across multiple jurisdictions;

c. nominees are used;

d. trusts or foundations are involved;

e. bearer-share risks exist;

f. ownership appears unnecessarily complicated;

g. control differs from legal ownership; or

h. the commercial rationale is unclear.

26. TRUSTS, FOUNDATIONS AND SIMILAR ARRANGEMENTS

Where legally accepted, due diligence should identify appropriate parties including:

a. settlor;

b. trustee;

c. protector;

d. beneficiary;

e. founder;

f. council member;

g. controlling person; and

h. other relevant persons

to the extent required by Applicable Law.

27. PURPOSE AND NATURE OF RELATIONSHIP

Before establishing a relationship, ARCBDS should understand:

a. why the Participant wishes to participate;

b. expected participation size;

c. expected transaction frequency;

d. expected funding source;

e. relevant wallet arrangements;

f. anticipated geographic activity;

g. whether the Participant acts for themselves; and

h. any other information relevant to the risk assessment.

28. CUSTOMER RISK ASSESSMENT

Each Participant shall be assigned an appropriate risk classification.

A typical framework may include:

Low Risk;

Standard / Medium Risk;

High Risk; and

Prohibited / Unacceptable Risk.

Risk classification shall be based on documented criteria rather than sales value alone.

29. RISK FACTORS

Factors may include:

a. country of residence;

b. nationality where legally relevant;

c. business jurisdiction;

d. business sector;

e. PEP status;

f. adverse media;

g. sanctions exposure;

h. ownership structure;

i. transaction size;

j. transaction frequency;

k. funding source;

l. wallet history;

m. blockchain exposure;

n. use of self-hosted wallets;

o. privacy-enhancing technology;

p. third-party funding;

q. unexplained wealth;

r. unusual transaction patterns; and

s. other relevant information.

30. HIGH-RISK CUSTOMERS

A Participant may be classified as High Risk where factors include:

a. PEP status;

b. high-risk jurisdiction exposure;

c. complex beneficial ownership;

d. material adverse media;

e. unusual digital-asset activity;

f. high-risk wallet exposure;

g. unexplained source of funds;

h. unusually large participation;

i. significant cash-intensive business activity;

j. substantial cross-border complexity;

k. significant sanctions-risk indicators; or

l. other risk factors identified by Compliance.

High-risk status does not always require rejection but requires enhanced controls.

31. ENHANCED DUE DILIGENCE

EDD may include:

a. additional identity information;

b. additional UBO verification;

c. detailed purpose-of-relationship information;

d. source-of-funds verification;

e. source-of-wealth verification;

f. residential-address verification;

g. additional business documentation;

h. senior-management approval;

i. enhanced blockchain analysis;

j. additional adverse-media analysis;

k. transaction rationale;

l. increased monitoring;

m. shorter review periods; and

n. other proportionate controls.

32. SIMPLIFIED DUE DILIGENCE

Simplified measures may only be used where:

a. Applicable Law permits them;

b. risk is demonstrably lower;

c. sanctions concerns do not exist;

d. suspicious activity is not present; and

e. Compliance approves.

Simplified measures shall not mean anonymous participation.

33. POLITICALLY EXPOSED PERSONS

PEPs may include persons entrusted with prominent public functions, together with other categories recognised under Applicable Law.

PEP screening shall apply to:

a. Participants;

b. UBOs;

c. authorised representatives where appropriate; and

d. relevant connected persons where required.

34. PEPs ARE NOT AUTOMATICALLY PROHIBITED

PEP status alone does not automatically mean unlawful activity.

However, a PEP relationship normally requires enhanced risk management.

Controls may include:

a. senior-management approval;

b. source-of-funds verification;

c. source-of-wealth verification;

d. enhanced monitoring;

e. adverse-media review; and

f. periodic reassessment.

35. FAMILY MEMBERS AND CLOSE ASSOCIATES

Where required by Applicable Law, PEP controls may extend to:

a. family members; and

b. known close associates.

Compliance shall apply applicable regulatory definitions.

36. FORMER PEPs

A person who ceases to hold a prominent public function shall continue to receive risk-based treatment for the period required by Applicable Law and until relevant PEP-related risks are reasonably assessed to have reduced.

37. SANCTIONS POLICY

ARCBDS shall not knowingly establish or continue a relationship prohibited by applicable targeted financial sanctions.

Sanctions compliance applies to:

a. Participants;

b. UBOs;

c. authorised representatives;

d. counterparties;

e. wallets;

f. transactions;

g. recipients;

h. senders; and

i. other relevant persons.

38. SANCTIONS LISTS

Screening shall include lists required under Applicable Law, including where applicable:

a. United Nations Security Council sanctions lists;

b. UAE Local Terrorist List;

c. other UAE-mandated targeted financial sanctions lists; and

d. additional sanctions lists adopted by the Company where appropriate to legal, banking, counterparty or risk requirements.

The official mandatory lists shall take priority.

39. REAL-TIME SANCTIONS SCREENING

Where technologically and legally applicable, sanctions screening should occur:

a. at onboarding;

b. before transactions;

c. upon changes in Participant information;

d. when sanctions lists update;

e. periodically during the relationship; and

f. before certain payouts or Protection Reserve settlements.

40. POTENTIAL SANCTIONS MATCH

A potential sanctions match shall be promptly escalated to Compliance.

The Company may temporarily restrict:

a. Account activity;

b. Contributions;

c. allocations;

d. withdrawals;

e. transfers;

f. refunds; and

g. Protection Reserve settlements

while the match is investigated.

41. CONFIRMED SANCTIONS MATCH

Where a confirmed match requires action under Applicable Law, ARCBDS shall take required measures, which may include:

a. immediately freezing relevant assets;

b. preventing withdrawals;

c. preventing transfers;

d. declining transactions;

e. maintaining freeze records;

f. reporting to relevant authorities; and

g. complying with regulatory instructions.

No employee may release frozen property without lawful authorisation.

42. NO SANCTIONS CIRCUMVENTION

Participants must not attempt to avoid sanctions controls using:

a. nominees;

b. third-party wallets;

c. false identities;

d. shell companies;

e. VPNs;

f. proxies;

g. chain-hopping;

h. intermediary accounts;

i. related persons; or

j. any other circumvention technique.

Attempts may result in immediate restriction and regulatory escalation.

43. HIGH-RISK JURISDICTIONS

ARCBDS shall maintain a dynamic jurisdiction-risk framework.

Factors may include:

a. FATF public statements;

b. UAE regulatory guidance;

c. sanctions;

d. corruption risk;

e. terrorism-financing risk;

f. proliferation-financing risk;

g. weak AML controls;

h. secrecy risk;

i. cybercrime exposure;

j. political instability; and

k. internal risk assessments.

The jurisdiction list must be reviewed regularly rather than permanently hard-coded into this Policy.

44. RESTRICTED JURISDICTIONS

Countries or territories in which ARCBDS participation is prohibited or restricted shall be maintained under the ARCBDS Eligibility & Restricted Jurisdiction Policy.

AML risk classification and legal eligibility are separate concepts.

A high-risk jurisdiction is not necessarily prohibited unless Applicable Law or Company risk appetite requires prohibition.

45. SOURCE OF FUNDS

Source of Funds means the origin of the specific money or Virtual Assets used for a transaction or participation.

Evidence may include:

a. salary;

b. business income;

c. investment proceeds;

d. bank savings;

e. crypto trading records;

f. sale of property;

g. sale of company interests;

h. inheritance;

i. dividends;

j. loan proceeds where legitimate and understood;

k. audited accounts;

l. bank statements;

m. tax records;

n. exchange statements; or

o. other reliable evidence.

46. SOURCE OF WEALTH

Source of Wealth means how a person accumulated their overall wealth.

Evidence may include:

a. long-term employment;

b. business ownership;

c. investment portfolio;

d. property ownership;

e. inheritance;

f. corporate sale;

g. professional income;

h. family wealth; or

i. other legitimate accumulation.

47. WHEN SOURCE OF FUNDS IS REQUIRED

Source-of-funds information may be required:

a. for higher-value participation;

b. for High-Risk Participants;

c. for PEPs;

d. where wallet history is unusual;

e. where funds originate from third parties;

f. where stated occupation does not reasonably support participation;

g. where transactions materially exceed expected activity;

h. where adverse information exists;

i. where Compliance requires clarification; or

j. where Applicable Law requires it.

48. WHEN SOURCE OF WEALTH IS REQUIRED

Source-of-wealth verification may be required for:

a. High-Risk Participants;

b. PEPs;

c. unusually large Participants;

d. complex corporate structures;

e. unexplained wealth;

f. high-risk jurisdictions; or

g. other circumstances identified by the risk assessment.

49. DIGITAL-ASSET SOURCE OF FUNDS

Where Contributions originate from digital assets, ARCBDS may require:

a. exchange statements;

b. wallet history;

c. purchase records;

d. on-chain transaction history;

e. evidence of mining or staking where relevant;

f. prior investment records;

g. OTC documentation;

h. business records; or

i. other evidence explaining asset origin.

50. WALLET SCREENING

Wallets used in connection with ARCBDS may be screened using distributed-ledger analytics or equivalent tools.

Screening may assess exposure to:

a. sanctioned addresses;

b. stolen assets;

c. ransomware;

d. darknet markets;

e. terrorist-financing indicators;

f. scams;

g. fraud;

h. hacks;

i. illicit marketplaces;

j. high-risk services;

k. mixers or tumblers;

l. chain-hopping patterns;

m. gambling exposure where relevant;

n. unlicensed services; and

o. other risk indicators.

51. BLOCKCHAIN ANALYTICS

ARCBDS may use an approved blockchain-analytics provider.

Provider: [●]

Networks Covered: [●]

Risk Scoring Method: [●]

Alert Threshold: [●]

The capabilities and limitations of the tool should be periodically reviewed.

Blockchain analytics must assist human compliance judgment rather than automatically determine every outcome without review.

52. WALLET OWNERSHIP

ARCBDS may require evidence that a Participant controls a wallet used for:

a. Contributions;

b. distributions;

c. withdrawals;

d. Protection Reserve Claims; or

e. other material transactions.

Verification methods may include:

a. cryptographic signature;

b. micro-transfer;

c. exchange statement;

d. account screenshot supported by additional evidence;

e. wallet-connect verification; or

f. another reliable method.

53. SELF-HOSTED WALLETS

Self-hosted wallets are not automatically prohibited.

However, they may require risk-based controls including:

a. ownership verification;

b. wallet screening;

c. transaction-history review;

d. Travel Rule assessment;

e. counterparty assessment;

f. source-of-funds checks; and

g. enhanced monitoring where necessary.

54. THIRD-PARTY FUNDING

Contributions should ordinarily originate from the Participant or an appropriately verified source.

Third-party payments may be:

a. rejected;

b. returned where lawful;

c. placed on hold;

d. subject to EDD; or

e. accepted only where the relationship and source are adequately verified.

55. PROHIBITED FUNDING SOURCES

ARCBDS shall not knowingly accept assets directly attributable to prohibited activity, including:

a. sanctioned persons;

b. terrorist organisations;

c. ransomware;

d. stolen funds;

e. darknet-market proceeds;

f. fraud;

g. trafficking;

h. corruption;

i. bribery;

j. hacking;

k. illegal weapons activity;

l. proliferation financing; or

m. other serious crime.

56. MIXERS AND PRIVACY-ENHANCING SERVICES

Interaction with mixers, tumblers, anonymity-enhancing services or similar infrastructure may increase risk.

Such exposure may trigger:

a. additional blockchain investigation;

b. source-of-funds evidence;

c. EDD;

d. transaction restriction; or

e. rejection.

Treatment shall be risk-based unless Applicable Law requires prohibition.

57. PRIVACY-ENHANCING VIRTUAL ASSETS

Where ARCBDS considers accepting Virtual Assets designed to obscure transaction details, Compliance must assess:

a. traceability;

b. sanctions risk;

c. transaction-monitoring capability;

d. Travel Rule compliance;

e. regulatory acceptability; and

f. overall AML/CFT risk.

No such asset should be accepted without formal approval.

58. TRANSACTION MONITORING

ARCBDS shall maintain transaction-monitoring controls proportionate to its activities.

Monitoring may cover:

a. Contributions;

b. refunds;

c. ARCBDS distributions;

d. withdrawals;

e. wallet changes;

f. internal transfers;

g. Protection Reserve Claims;

h. referral rewards;

i. unusual transaction patterns; and

j. other relevant activity.

59. ONGOING MONITORING

Ongoing monitoring should assess whether activity remains consistent with:

a. Participant identity;

b. Participant profile;

c. expected transaction activity;

d. stated source of funds;

e. stated business;

f. Participant risk rating; and

g. known purpose of the relationship.

60. TRANSACTION-MONITORING RED FLAGS

Potential red flags may include:

a. rapid movement of assets through multiple wallets;

b. unexplained third-party transfers;

c. sudden increase in transaction volume;

d. repeated activity just below internal review thresholds;

e. multiple Accounts linked to common control;

f. sanctions exposure;

g. darknet exposure;

h. stolen-funds exposure;

i. ransomware exposure;

j. unexplained high-risk exchange usage;

k. geographic inconsistency;

l. unusual wallet switching;

m. inconsistent source of funds;

n. false documentation;

o. transaction splitting;

p. unexplained chain-hopping;

q. circular transfers;

r. unnecessary complexity;

s. attempts to avoid KYC;

t. abnormal Protection Reserve Claims; and

u. other FATF or regulator-recognised red flags.

61. STRUCTURING

Participants must not deliberately divide transactions into smaller amounts for the purpose of avoiding:

a. KYC;

b. reporting;

c. Travel Rule requirements;

d. source-of-funds review;

e. transaction monitoring; or

f. other controls.

Linked transactions may be aggregated for compliance purposes.

62. OCCASIONAL TRANSACTIONS

Where VARA rules apply, CDD requirements may arise for qualifying occasional transactions at or above applicable regulatory thresholds, including linked transactions.

Because Founding Circle participation normally establishes a business relationship, ARCBDS will generally conduct CDD regardless of the initial Contribution amount.

63. FATF TRAVEL RULE

Where ARCBDS performs or facilitates Virtual Asset transfers within the scope of applicable Travel Rule requirements, it shall obtain, retain and transmit required originator and beneficiary information.

Where current VARA requirements apply, the relevant rules include transfers exceeding the applicable AED 3,500 equivalent threshold, subject to the Federal AML/CFT Laws and any later regulatory change.

64. ORIGINATOR INFORMATION

Travel Rule information may include, as applicable:

a. originator name;

b. account number or wallet address;

c. residential or business address;

d. identification information; and

e. other information required by Applicable Law.

65. BENEFICIARY INFORMATION

Travel Rule information may include, as applicable:

a. beneficiary name;

b. account number or wallet address; and

c. other information required under Applicable Law.

66. INCOMPLETE TRAVEL RULE INFORMATION

ARCBDS shall maintain procedures for transfers where required Travel Rule information is:

a. missing;

b. incomplete;

c. inaccurate; or

d. suspicious.

Possible actions include:

a. requesting information;

b. delaying a transfer;

c. rejecting a transfer;

d. returning assets where lawful;

e. EDD;

f. restricting a counterparty VASP; or

g. suspicious-activity escalation.

67. VASP COUNTERPARTY DUE DILIGENCE

Where ARCBDS transacts with another VASP, Compliance may assess:

a. legal identity;

b. regulatory status;

c. jurisdiction;

d. AML controls;

e. sanctions exposure;

f. Travel Rule capability;

g. reputation;

h. ownership; and

i. other material risks.

68. UNLICENSED OR HIGH-RISK VASPs

Transactions involving unlicensed, unregistered or materially high-risk Virtual Asset service providers may be:

a. restricted;

b. subject to EDD;

c. rejected; or

d. escalated.

The decision shall reflect Applicable Law and risk appetite.

69. ADVERSE MEDIA

ARCBDS may screen for credible adverse information relating to:

a. financial crime;

b. corruption;

c. bribery;

d. fraud;

e. sanctions evasion;

f. terrorism;

g. organised crime;

h. cybercrime;

i. trafficking;

j. tax crime;

k. regulatory misconduct; and

l. other relevant matters.

Adverse media alone should not automatically be treated as proof of wrongdoing.

Compliance shall assess credibility, relevance and recency.

70. ONGOING KYC

CDD is not a one-time process.

Participant information shall be refreshed according to:

a. risk level;

b. material changes;

c. transaction behaviour;

d. document expiry;

e. sanctions events;

f. PEP changes;

g. regulatory requirements; and

h. other triggering events.

71. PERIODIC REVIEW

Internal review periods shall be risk-based.

Indicative internal parameters may be established as:

High Risk: [●]

Medium Risk: [●]

Low Risk: [●]

A triggering event may require review sooner than the scheduled period.

72. TRIGGER EVENTS

A KYC review may be triggered by:

a. change of name;

b. change of address;

c. change of nationality;

d. change of beneficial ownership;

e. change of directors;

f. PEP status change;

g. sanctions-list update;

h. expired identity document;

i. abnormal transaction;

j. significant participation increase;

k. new high-risk jurisdiction exposure;

l. adverse media;

m. suspicious wallet activity;

n. Protection Reserve Claim; or

o. Compliance request.

73. ACCOUNT RESTRICTION DURING REVIEW

ARCBDS may restrict certain functions during a compliance review.

Restrictions may include:

a. new Contributions;

b. withdrawals;

c. transfers;

d. wallet changes;

e. refund processing;

f. Protection Reserve settlement; or

g. other higher-risk activities.

Restrictions should be proportionate and legally justified.

74. SUSPICIOUS ACTIVITY

Employees must promptly escalate any activity that they know, suspect or have reasonable grounds to suspect may involve:

a. money laundering;

b. terrorist financing;

c. proliferation financing;

d. proceeds of crime;

e. sanctions evasion;

f. fraud;

g. criminal property; or

h. other relevant unlawful activity.

75. INTERNAL SUSPICIOUS ACTIVITY REPORT

Staff shall submit an internal report to the MLRO using the approved process.

The report should contain available information including:

a. Participant identity;

b. Account ID;

c. wallet information;

d. transaction details;

e. relevant dates;

f. reason for suspicion;

g. supporting documents;

h. blockchain analysis; and

i. other relevant information.

76. MLRO INVESTIGATION

The MLRO or authorised Compliance personnel may:

a. review Account activity;

b. review KYC;

c. review transactions;

d. conduct blockchain analysis;

e. review source of funds;

f. review source of wealth;

g. request additional information;

h. review related Accounts;

i. assess sanctions exposure;

j. review adverse media; and

k. document conclusions.

77. EXTERNAL SUSPICIOUS REPORTING

Where the applicable legal threshold for reporting is met, the MLRO shall submit the required suspicious transaction, suspicious activity or other AML/CFT report to the competent authority using the legally required reporting mechanism.

Where ARCBDS is a UAE reporting entity, this may include reporting through the UAE Financial Intelligence Unit's goAML platform.

78. ATTEMPTED TRANSACTIONS

Suspicion may arise even where a transaction was:

a. attempted;

b. rejected;

c. cancelled;

d. blocked; or

e. never completed.

The fact that funds were not successfully transferred does not necessarily remove reporting obligations.

79. NO TIPPING OFF

Employees, contractors and other persons subject to confidentiality obligations must not disclose information in a manner prohibited by Applicable Law concerning:

a. suspicious reporting;

b. FIU reports;

c. active investigations;

d. regulatory enquiries; or

e. other confidential AML matters.

A Participant should not be told that an STR or SAR has been filed where such disclosure would constitute prohibited tipping off.

80. TRANSACTION DELAYS

Where a transaction is under AML review, communications should be carefully managed.

ARCBDS may state that:

the transaction is undergoing compliance review;

additional information is required; or

processing is temporarily restricted,

without unlawfully disclosing confidential suspicious-activity information.

81. TARGETED FINANCIAL SANCTIONS

ARCBDS shall maintain controls designed to implement applicable targeted financial sanctions without delay.

Controls shall include:

a. screening;

b. match investigation;

c. asset freezing where legally required;

d. transaction blocking;

e. reporting;

f. recordkeeping; and

g. ongoing list updates.

82. SANCTIONS FREEZE

Where legally required, assets subject to a sanctions freeze must not be:

a. transferred;

b. withdrawn;

c. converted;

d. released;

e. returned;

f. pledged;

g. made available to a designated person; or

h. dealt with contrary to Applicable Law.

83. FALSE POSITIVES

Potential sanctions matches should be resolved carefully.

Compliance may compare:

a. full name;

b. date of birth;

c. nationality;

d. identification number;

e. address;

f. aliases;

g. entity information;

h. ownership; and

i. other identifiers.

A false positive should be documented before a restriction is removed.

84. PROLIFERATION FINANCING

ARCBDS shall consider proliferation-financing risks, including:

a. designated persons;

b. sanctioned entities;

c. dual-use goods exposure;

d. proliferation networks;

e. jurisdictions subject to applicable restrictions;

f. unusual company structures;

g. trade-related concerns; and

h. other relevant indicators.

85. TERRORIST FINANCING

Terrorist-financing risk may arise even where funds originate from apparently legitimate sources.

Controls therefore focus not only on source of funds but also:

a. destination;

b. counterparties;

c. network connections;

d. sanctioned organisations;

e. suspicious behaviour; and

f. other relevant indicators.

86. PROHIBITED RELATIONSHIPS

ARCBDS shall not knowingly establish or maintain relationships involving:

a. false identity;

b. confirmed sanctioned persons where prohibited;

c. terrorist organisations;

d. persons acting on behalf of prohibited organisations;

e. clearly criminal proceeds;

f. fraudulent KYC;

g. deliberate UBO concealment;

h. illegal source of funds;

i. deliberate sanctions evasion; or

j. other relationships prohibited by Applicable Law.

87. UNACCEPTABLE RISK

ARCBDS may decline a relationship even where no criminal activity has been established if the overall compliance risk is outside approved risk appetite.

Reasons may include:

a. inability to verify identity;

b. inability to establish UBO;

c. inability to establish lawful source of funds;

d. excessive unexplained wallet risk;

e. serious adverse information;

f. unacceptable jurisdiction exposure;

g. refusal to provide required information;

h. excessive complexity without legitimate explanation; or

i. other material risks.

88. REFUSAL TO PROVIDE INFORMATION

If a Participant refuses to provide reasonably required compliance information, ARCBDS may:

a. decline onboarding;

b. restrict the Account;

c. reject a transaction;

d. terminate the relationship;

e. hold or return assets subject to Applicable Law; or

f. escalate the matter for suspicious-activity review.

89. REFUNDS FOLLOWING KYC FAILURE

Where participation is rejected after funds have been received, any refund must comply with:

a. AML requirements;

b. sanctions requirements;

c. wallet screening;

d. original source verification;

e. ARCBDS Cancellation & Refund Policy; and

f. Applicable Law.

A refund should not automatically be sent to a different third-party wallet merely at the Participant's request.

90. RETURN-TO-SOURCE PRINCIPLE

Where lawful and technically feasible, rejected or refunded funds should ordinarily be returned to the verified original funding source.

Exceptions require appropriate Compliance approval.

91. PROTECTION RESERVE CLAIMS

Protection Reserve Claims shall be subject to AML controls.

Before settlement, ARCBDS may:

a. re-screen the Participant;

b. re-screen wallets;

c. re-screen sanctions;

d. review transaction history;

e. verify ownership;

f. assess fraud indicators; and

g. request updated KYC.

92. REFERRAL PROGRAMME AML RISK

Referral arrangements shall not bypass KYC.

Referrers:

a. may introduce Participants;

b. may provide approved educational information; but

c. may not approve KYC;

d. may not override Compliance;

e. may not receive funds on behalf of ARCBDS unless formally authorised;

f. may not structure transactions; and

g. may not conceal Participant identity.

93. EMPLOYEE SCREENING

Where appropriate, ARCBDS shall conduct pre-employment or engagement screening for personnel in sensitive roles.

Checks may include:

a. identity;

b. qualifications;

c. employment history;

d. conflicts;

e. criminal-history checks where lawful;

f. sanctions;

g. adverse information; and

h. fitness and propriety.

94. STAFF TRAINING

Relevant employees and contractors shall receive AML/CFT/CPF training.

Training may cover:

a. AML law;

b. terrorist financing;

c. proliferation financing;

d. sanctions;

e. KYC;

f. UBOs;

g. PEPs;

h. suspicious activity;

i. blockchain risks;

j. transaction monitoring;

k. Travel Rule;

l. tipping off;

m. internal escalation;

n. fraud; and

o. emerging risks.

95. TRAINING FREQUENCY

Training shall occur:

a. during onboarding for relevant staff;

b. periodically thereafter;

c. when laws materially change;

d. when new risks arise;

e. when significant control weaknesses are identified; and

f. where required by a regulator.

Training completion shall be recorded.

96. ROLE-SPECIFIC TRAINING

Enhanced training should be provided to personnel working in:

a. Compliance;

b. Finance;

c. Participant onboarding;

d. customer support;

e. transaction operations;

f. Protection Reserve Claims;

g. cybersecurity;

h. management; and

i. referral oversight.

97. KYC SERVICE PROVIDERS

ARCBDS may outsource certain technical KYC functions to approved providers.

KYC Provider: [●]

Outsourcing does not remove ARCBDS's legal responsibility where Applicable Law places responsibility on ARCBDS.

98. SERVICE-PROVIDER DUE DILIGENCE

Before appointing a material AML service provider, ARCBDS should assess:

a. regulatory standing;

b. technical capability;

c. data security;

d. data protection;

e. accuracy;

f. coverage;

g. sanctions-list quality;

h. blockchain coverage;

i. service continuity;

j. audit rights;

k. sub-contractors; and

l. contractual obligations.

99. AUTOMATED SYSTEMS

Automated screening may assist in identifying risk.

However:

a. technology may generate false positives;

b. technology may miss risk;

c. blockchain attribution may change;

d. sanctions data may change; and

e. human review remains necessary for material decisions.

100. MODEL AND TOOL VALIDATION

ARCBDS should periodically assess AML tools for:

a. effectiveness;

b. coverage;

c. false-positive rate;

d. false-negative risk;

e. blockchain attribution quality;

f. list-update frequency;

g. technical reliability; and

h. continued suitability.

101. RECORDKEEPING

ARCBDS shall maintain appropriate AML/CFT/CPF records including:

a. KYC files;

b. KYB files;

c. UBO information;

d. transaction records;

e. wallet-screening results;

f. source-of-funds records;

g. source-of-wealth records;

h. risk assessments;

i. PEP reviews;

j. sanctions reviews;

k. adverse-media reviews;

l. transaction-monitoring alerts;

m. investigations;

n. suspicious-report records;

o. regulatory correspondence;

p. Travel Rule records;

q. training records; and

r. policy approvals.

102. RECORD RETENTION

Where VARA requirements apply, relevant AML/CFT records shall generally be retained for no less than eight (8) years, or longer where Applicable Law requires.

Records relating to UAE national-security matters may be subject to longer or indefinite retention requirements where legally required.

Other retention requirements shall be managed under the ARCBDS Privacy Policy and internal retention schedule.

103. RECORD QUALITY

Records must be:

a. accurate;

b. sufficiently complete;

c. retrievable;

d. protected against unauthorised alteration;

e. accessible to authorised personnel;

f. appropriately secured; and

g. available for regulatory inspection where legally required.

104. CONFIDENTIALITY

AML records are confidential.

Access shall be restricted to persons who require the information for:

a. compliance;

b. risk;

c. legal;

d. audit;

e. security;

f. regulatory; or

g. authorised operational purposes.

105. PERSONAL DATA

AML processing shall comply with the ARCBDS Privacy Policy and Applicable Law.

Data minimisation does not require ARCBDS to delete records that AML law requires it to retain.

106. INTERNAL MANAGEMENT INFORMATION

The MLRO should periodically report appropriate information to Senior Management, including:

a. number of onboarding reviews;

b. high-risk Participants;

c. PEPs;

d. sanctions alerts;

e. wallet alerts;

f. transaction-monitoring alerts;

g. suspicious reports;

h. rejected relationships;

i. overdue KYC reviews;

j. training completion;

k. regulatory changes;

l. material incidents; and

m. remediation status.

Reports must not be used to interfere improperly with MLRO decisions.

107. INDEPENDENT TESTING

The AML/CFT framework should be independently tested at appropriate intervals.

Testing may assess:

a. governance;

b. KYC;

c. KYB;

d. UBO verification;

e. sanctions;

f. transaction monitoring;

g. blockchain analytics;

h. suspicious reporting;

i. Travel Rule;

j. training;

k. recordkeeping;

l. service providers; and

m. remediation.

108. INTERNAL AUDIT

Where an internal audit function exists, it should have appropriate independence from operational Compliance activities.

Material findings shall be:

a. documented;

b. assigned to owners;

c. given deadlines;

d. tracked; and

e. escalated if overdue.

109. POLICY REVIEW

This Policy shall be reviewed:

a. at least annually or at another legally required frequency;

b. following material regulatory change;

c. following launch of new products;

d. following entry into new jurisdictions;

e. following significant AML incidents;

f. following major audit findings; or

g. when the risk profile materially changes.

110. POLICY AMENDMENTS

Material amendments must be approved according to applicable governance requirements.

Where VARA approval, notification, attestation or submission is required, the Company shall comply with those requirements.

111. BREACH OF POLICY

Employees who deliberately breach this Policy may face:

a. retraining;

b. disciplinary action;

c. suspension;

d. termination; or

e. legal or regulatory reporting

as appropriate.

112. PARTICIPANT BREACH

Participants who deliberately breach compliance requirements may face:

a. onboarding rejection;

b. transaction rejection;

c. Account restriction;

d. Account termination;

e. asset freezing where legally required;

f. referral disqualification;

g. Protection Reserve Claim rejection where relevant;

h. regulatory reporting; and

i. law-enforcement referral.

113. COMMERCIAL PRESSURE

No sales target, referral target, token-allocation target, marketing objective or revenue objective may override mandatory AML/CFT/CPF requirements.

Compliance decisions shall be based on law, policy and risk.

114. NO GUARANTEE OF ACCEPTANCE

Completion of KYC does not guarantee:

a. Founding Circle acceptance;

b. transaction approval;

c. refund approval;

d. wallet approval;

e. Protection Reserve approval; or

f. continued Account availability.

KYC is one part of the overall compliance assessment.

115. RIGHT TO REQUEST ADDITIONAL INFORMATION

ARCBDS may request additional information at any point during the relationship.

A Participant may therefore be asked to provide updated:

a. identity documents;

b. address evidence;

c. business records;

d. ownership records;

e. bank statements;

f. exchange statements;

g. wallet evidence;

h. source-of-funds records;

i. source-of-wealth records; or

j. transaction explanations.

116. LIMITATION OF DISCLOSURE

Where ARCBDS restricts or terminates a relationship for compliance reasons, ARCBDS may be legally unable to provide the Participant with complete details concerning:

a. screening results;

b. investigations;

c. suspicious reports;

d. sanctions enquiries;

e. regulator instructions; or

f. confidential intelligence.

117. NO LIABILITY FOR LEGALLY REQUIRED ACTIONS

To the extent permitted by Applicable Law, ARCBDS shall not be liable merely because it:

a. performs KYC;

b. requests compliance documents;

c. delays a transaction for legitimate review;

d. freezes assets where legally required;

e. rejects prohibited activity;

f. reports suspicious activity where required;

g. performs sanctions screening; or

h. complies with a regulator or court order.

This does not exclude liability for unlawful or negligent conduct that cannot legally be excluded.

118. PARTICIPANT OBLIGATIONS

Every Participant must:

a. provide accurate information;

b. keep information current;

c. cooperate with lawful KYC requests;

d. disclose UBOs truthfully;

e. use lawful funds;

f. avoid sanctions circumvention;

g. avoid fraudulent documents;

h. avoid third-party impersonation;

i. provide reasonable transaction explanations when required; and

j. comply with Applicable Law.

119. PARTICIPANT DECLARATION

As part of onboarding, a Participant may be required to confirm:

☐ I am participating on my own behalf or have disclosed the person/entity on whose behalf I act.

☐ The information I provided is accurate and complete.

☐ My Contribution is derived from lawful sources.

☐ I am not knowingly using proceeds of crime.

☐ I am not knowingly acting for a sanctioned or prohibited person.

☐ I will provide additional compliance information where reasonably required.

☐ I understand ARCBDS may screen my public wallet activity.

☐ I understand transactions may be delayed or rejected for compliance purposes.

☐ I understand ARCBDS may make legally required disclosures to authorities.

120. KYC CONSENT AND PRIVACY

KYC data shall be handled in accordance with the ARCBDS Privacy Policy.

Where biometric or other Sensitive Personal Data is used, additional notices or consent shall be obtained where required.

Participants must not be required to consent to unrelated marketing as a condition of KYC.

SCHEDULE 1

INDIVIDUAL KYC CHECKLIST

Basic Information

☐ Full Legal Name

☐ Date of Birth

☐ Nationality

☐ Country of Residence

☐ Residential Address

☐ Email

☐ Mobile Number

☐ Occupation

☐ Employer / Business

☐ Tax Residence where required

Identity

☐ Valid Identity Document

☐ Document Number

☐ Issue Date

☐ Expiry Date

☐ Issuing Country

☐ Photograph

☐ Liveness / Selfie Verification where applicable

Screening

☐ Sanctions Screening

☐ PEP Screening

☐ Adverse Media

☐ Jurisdiction Risk

☐ Fraud Screening

Financial

☐ Expected Participation Amount

☐ Source of Funds

☐ Source of Wealth where required

Blockchain

☐ Funding Wallet

☐ Wallet Ownership Verification where required

☐ Blockchain Analytics

☐ Risk Score

Outcome

☐ Low Risk

☐ Medium Risk

☐ High Risk

☐ Prohibited

☐ Approved

☐ EDD Required

☐ Rejected

SCHEDULE 2

CORPORATE KYB CHECKLIST

☐ Company Legal Name

☐ Registration Number

☐ Jurisdiction

☐ Registered Address

☐ Business Address

☐ Certificate of Incorporation

☐ Business Licence

☐ Constitutional Documents

☐ Business Activity

☐ Director Register

☐ Shareholder Register

☐ Ownership Structure

☐ UBOs

☐ Authorised Signatories

☐ Board Resolution where required

☐ Tax Information where required

☐ Company Wallet

☐ Source of Funds

☐ Source of Wealth where required

☐ Sanctions Screening

☐ PEP Screening

☐ Adverse Media

☐ Blockchain Screening

☐ Risk Assessment

SCHEDULE 3

UBO RECORD

Legal Entity: [●]

UBO Name: [●]

Date of Birth: [●]

Nationality: [●]

Residence: [●]

Ownership Percentage: [●]

Nature of Control: [●]

Identity Verified: Yes / No

Sanctions Result: [●]

PEP Result: [●]

Adverse Media: [●]

Source of Wealth: [●]

Risk Classification: [●]

SCHEDULE 4

CUSTOMER RISK ASSESSMENT

Customer Risk

Score: [●]

Jurisdiction Risk

Score: [●]

Product / Service Risk

Score: [●]

Transaction Risk

Score: [●]

Wallet / Blockchain Risk

Score: [●]

PEP Risk

Score: [●]

Sanctions Risk

Score: [●]

Source of Funds Risk

Score: [●]

Beneficial Ownership Risk

Score: [●]

Adverse Media Risk

Score: [●]

TOTAL RISK

Score: [●]

Classification:

☐ Low

☐ Medium

☐ High

☐ Prohibited

Reviewer: [●]

Approval: [●]

Next Review: [●]

SCHEDULE 5

ENHANCED DUE DILIGENCE CHECKLIST

☐ Additional ID obtained

☐ Address independently verified

☐ UBO independently verified

☐ Purpose of relationship documented

☐ Expected transaction activity documented

☐ Source of Funds verified

☐ Source of Wealth verified

☐ Bank / exchange evidence reviewed

☐ Wallet history reviewed

☐ Blockchain analytics completed

☐ PEP review completed

☐ Sanctions review completed

☐ Adverse-media review completed

☐ Related-party review completed

☐ Senior Management approval obtained

☐ Enhanced monitoring activated

SCHEDULE 6

SOURCE OF FUNDS FORM

Participant: [●]

Participation Amount: [●]

Funding Asset: [●]

Funding Wallet: [●]

Source

☐ Salary / Employment Income

☐ Business Income

☐ Investment Proceeds

☐ Crypto Trading / Investment

☐ Property Sale

☐ Company Sale

☐ Inheritance

☐ Savings

☐ Dividend

☐ Loan

☐ Other: [●]

Supporting Evidence

[●]

Compliance Assessment

Verified: Yes / No

Additional Evidence Required: [●]

Reviewer: [●]

SCHEDULE 7

SOURCE OF WEALTH FORM

Participant / UBO: [●]

Principal Wealth Source

☐ Business Ownership

☐ Employment

☐ Investments

☐ Property

☐ Inheritance

☐ Company Sale

☐ Family Wealth

☐ Professional Practice

☐ Other: [●]

Estimated Wealth Range: [●]

Evidence: [●]

Assessment: [●]

Reviewer: [●]

SCHEDULE 8

WALLET SCREENING RECORD

Participant ID: [●]

Wallet Address: [●]

Blockchain: [●]

Analytics Provider: [●]

Screening Date: [●]

Exposure

☐ Sanctions

☐ Scam

☐ Fraud

☐ Stolen Funds

☐ Ransomware

☐ Darknet

☐ Mixer / Tumbler

☐ Hack / Exploit

☐ Terrorist Financing

☐ Gambling

☐ High-Risk Exchange

☐ Unlicensed Service

☐ Other

Risk Score: [●]

Direct Exposure: [●]

Indirect Exposure: [●]

Decision:

☐ Approved

☐ Manual Review

☐ EDD

☐ Rejected

☐ Report to MLRO

SCHEDULE 9

TRANSACTION MONITORING RED FLAGS

ARCBDS monitoring should consider indicators including:

unexplained large Contributions;

repeated third-party payments;

rapid wallet movement;

repeated wallet changes;

multiple related Accounts;

unusual geographic activity;

structuring;

inconsistent source of funds;

suspicious exchange activity;

sanctioned wallet exposure;

ransomware exposure;

darknet-market exposure;

stolen-asset exposure;

mixer activity;

chain-hopping without clear rationale;

circular transactions;

multiple failed KYC attempts;

identity mismatch;

unexplained PEP-linked funds;

inconsistent company activity;

unusual refund requests;

refunds to third parties;

unusual Protection Reserve Claims;

fabricated liquidation evidence;

unusual referral-network activity;

unusual use of shell companies;

unusually complex structures;

attempted sanctions circumvention;

use of nominees;

activity inconsistent with Participant profile; and

other current FATF/UAE/VARA red flags.

SCHEDULE 10

INTERNAL SUSPICIOUS ACTIVITY REPORT

Report ID: [●]

Date: [●]

Employee: [●]

Participant: [●]

Participant ID: [●]

Wallet: [●]

Transaction: [●]

Amount: [●]

Reason for Suspicion

[●]

Red Flags

[●]

Supporting Evidence

[●]

Immediate Action Taken

☐ None

☐ Transaction Paused

☐ Account Restricted

☐ Compliance Escalation

☐ Sanctions Hold

MLRO Decision

[●]

External Report Required: Yes / No

Reference: [●]

SCHEDULE 11

SANCTIONS MATCH PROCEDURE

Step 1

Identify potential match.

Step 2

Prevent inappropriate transaction completion where necessary.

Step 3

Escalate to Compliance.

Step 4

Compare identifying information.

Step 5

Determine:

☐ False Positive

☐ Possible Match

☐ Confirmed Match

Step 6

Where confirmed and legally required:

freeze assets without delay;

prevent transactions;

notify required authority;

preserve records;

prohibit making assets available; and

follow regulator instructions.

Step 7

Document the complete decision.

SCHEDULE 12

TRAVEL RULE CONTROL

For applicable VA transfers, ARCBDS shall determine:

Transfer Value: [●]

AED Equivalent: [●]

Travel Rule Applicable: Yes / No

Originator

Name: [●]

Account / Wallet: [●]

Address: [●]

Required Identification: [●]

Beneficiary

Name: [●]

Account / Wallet: [●]

Required Information: [●]

Counterparty VASP

Name: [●]

Jurisdiction: [●]

Licence: [●]

Travel Rule Provider / Channel: [●]

Compliance Decision: [●]

SCHEDULE 13

HIGH-RISK CUSTOMER APPROVAL

Participant: [●]

Risk Score: [●]

Risk Reasons: [●]

EDD Completed: Yes / No

Source of Funds: Verified / Not Verified

Source of Wealth: Verified / Not Verified

PEP: Yes / No

Sanctions: Clear / Review

Wallet Risk: [●]

Compliance Recommendation: [●]

Senior Management Decision

☐ Approve

☐ Approve with Conditions

☐ Reject

Authorised Person: [●]

Date: [●]

SCHEDULE 14

PERIODIC REVIEW

Participant: [●]

Risk Level: [●]

Previous Review: [●]

Current Review: [●]

Review

☐ Identity Current

☐ Address Current

☐ UBO Current

☐ Business Activity Current

☐ PEP Re-Screened

☐ Sanctions Re-Screened

☐ Adverse Media Re-Screened

☐ Wallet Re-Screened

☐ Source of Funds Still Reasonable

☐ Transaction Activity Consistent

☐ Risk Rating Updated

New Risk Level: [●]

Next Review: [●]

SCHEDULE 15

PROHIBITED PRACTICES

ARCBDS personnel and Participants must not:

bypass KYC;

fabricate identity records;

conceal UBOs;

split transactions to avoid controls;

accept funds through unofficial personal wallets;

override sanctions matches without Compliance approval;

knowingly accept criminal proceeds;

tip off Participants concerning confidential suspicious reports;

destroy AML records improperly;

manipulate blockchain risk reports;

approve their own high-risk related-party relationship;

accept bribes for KYC approval;

allow referral leaders to approve Participants;

misrepresent KYC as optional where it is required;

allow commercial pressure to override Compliance;

disclose confidential compliance information without authority; or

interfere with MLRO independence.

SCHEDULE 16

AML GOVERNANCE REGISTER

Board / Senior Management AML Owner: [●]

MLRO: [●]

Deputy MLRO: [●]

Compliance Officer: [●]

KYC Provider: [●]

Blockchain Analytics Provider: [●]

Sanctions Screening Provider: [●]

Travel Rule Provider: [●]

goAML Registration Number: [●]

Primary Regulator: [●]

External AML Adviser: [●]

Independent AML Auditor: [●]

SCHEDULE 17

AML RECORD RETENTION

Record

Minimum Internal Standard

KYC / KYB

At least 8 years where applicable

UBO Records

At least 8 years where applicable

Transaction Records

At least 8 years where applicable

Wallet Screening

At least 8 years where applicable

CDD / EDD

At least 8 years where applicable

Source of Funds / Wealth

At least 8 years where applicable

PEP / Sanctions Records

At least 8 years where applicable

Transaction Monitoring

At least 8 years where applicable

Suspicious Report Records

At least 8 years where applicable

Travel Rule Records

Applicable regulatory period

Training Records

Applicable regulatory period

AML Risk Assessments

Applicable regulatory period

Policy Versions

Applicable regulatory period

Longer retention shall apply where required by law, regulator, legal hold or national-security requirements.

SCHEDULE 18

FOUNDING CIRCLE ONBOARDING FLOW

Step 1 — Registration

Email / Mobile / OTP

Step 2 — Identity Information

Personal or corporate information

Step 3 — KYC / KYB

Document + Identity Verification

Step 4 — Sanctions / PEP

Automated and manual screening

Step 5 — Risk Assessment

Customer + Jurisdiction + Product + Wallet Risk

Step 6 — Wallet Screening

Blockchain Analytics

Step 7 — Source of Funds

Where required

Step 8 — EDD

Where required

Step 9 — Compliance Decision

Approved / EDD / Rejected

Step 10 — Participation Documents

Agreement + Risk Disclosure + Relevant Policies

Step 11 — Contribution

Official supported wallet/network only

Step 12 — Transaction Screening

Blockchain + sanctions + transaction controls

Step 13 — Final Acceptance

Participation Confirmation issued

SCHEDULE 19

PARTICIPANT KYC NOTICE

Before commencing verification, ARCBDS should display substantially the following:

IDENTITY & COMPLIANCE VERIFICATION

To participate in the ARCBDS Founding Circle, you must complete applicable identity and compliance verification.

ARCBDS and its authorised compliance providers may process information for:

KYC/KYB;

sanctions screening;

PEP screening;

AML/CFT/CPF compliance;

fraud prevention;

wallet verification;

blockchain analytics;

source-of-funds verification; and

regulatory compliance.

Completion of KYC does not guarantee acceptance.

ARCBDS may request additional information where required by law or risk assessment.

Please review the ARCBDS Privacy Policy for information concerning how your Personal Data is processed.

SCHEDULE 20

FINAL PARTICIPANT AML DECLARATION

Before final Founding Circle acceptance, the Participant should confirm:

☐ I confirm that the identity information I provided is true and complete.

☐ I confirm that I am participating for myself unless I have disclosed that I am acting for another person or entity.

☐ I have truthfully disclosed any required beneficial ownership.

☐ I confirm that my participation funds come from lawful sources.

☐ I am not knowingly using ARCBDS to launder proceeds of crime.

☐ I am not knowingly financing terrorism.

☐ I am not knowingly involved in proliferation financing.

☐ I am not knowingly acting on behalf of a sanctioned or prohibited person.

☐ I will not attempt to circumvent ARCBDS sanctions or geographic controls.

☐ I understand that ARCBDS may screen my public wallet address and associated blockchain activity.

☐ I agree to provide additional source-of-funds or source-of-wealth evidence where reasonably required.

☐ I understand that transactions may be delayed, rejected, frozen or reported where required by law.

☐ I understand that ARCBDS may be legally prohibited from explaining certain compliance actions in detail.

☐ I agree to comply with this KYC, AML & Sanctions Policy.

CONTACT

ARCBDS COMPLIANCE

Legal Entity: [●]

MLRO: [●]

Compliance Email: [●]

Registered Address: [●]

Website: www.arcbds.com

Participants should use the Compliance channel to report suspected:

fraud;

impersonation;

sanctions violations;

suspicious transactions;

misuse of ARCBDS; or

other potential financial crime.

Participants should not use this contact to request information about whether a suspicious report has been filed.

FINAL AML/CFT/CPF STATEMENT

ARCBDS operates a zero-tolerance approach toward the knowing use of its ecosystem for financial crime.

However, a risk-based approach does not mean that every high-risk Participant is automatically criminal or prohibited.

The purpose of this framework is to:

Know who participates.

Understand where funds come from.

Understand relevant wallet activity.

Detect prohibited and suspicious activity.

Protect legitimate Participants.

Comply with sanctions.

Prevent misuse of the ARCBDS ecosystem.

Cooperate with competent authorities where legally required.

No commercial objective, referral relationship, community status, participation amount or business relationship may exempt a Participant from mandatory compliance requirements.

END OF ARCBDS KYC, AML & SANCTIONS POLICY

KYC, AML & Sanctions Policy — ARCB Digital Share