1. Purpose and scope
This AML/KYC Policy describes how the OmniWallet operator (“we”, “us”) works to prevent OmniWallet (the “Service”) from being used for money laundering, terrorist financing, sanctions evasion, fraud and other financial crime. The operator’s full legal name and registered address will be specified here before this policy takes effect.
This policy applies to all merchants, their Authorized Users and sub-accounts, and to all Payments, settlements, Payouts and Conversions. It forms part of our Terms of Service and should be read together with our Acceptable Use Policy; capitalized terms have the meanings given in the Terms.
We apply this policy as part of our risk management and, where required by applicable law, to meet our legal obligations. It summarizes our approach and is not a complete description of our internal procedures.
2. Risk-based approach and governance
We take a risk-based approach: the depth of our checks and monitoring depends on the risk each merchant presents, taking into account factors such as its type of business, ownership structure, the jurisdictions involved, the products and channels it uses, the assets and blockchains involved, and its expected and actual volumes.
A designated compliance function is responsible for implementing this policy, approving higher-risk merchants, reviewing alerts and making reports, and has the authority and access to information it needs to do so.
We review this policy at least once a year, and sooner if laws, our products or our risk assessment change.
3. Merchant due diligence (KYB)
Every merchant must pass verification before accepting live payments (the Test Environment, which handles only test coins, is approved automatically). We collect and verify:
- company registration details and supporting documents;
- the identity of its directors;
- the identity of its beneficial owners, meaning the natural persons who directly or indirectly own 25% or more of the merchant’s shares or capital, or who otherwise control it;
- the identity and authority of its authorized representatives;
- a description of its business, its website or app, expected volumes and the source of funds; and
- additional information and documents for higher-risk merchants.
We screen the company, its directors and its beneficial owners against sanctions lists and for politically exposed persons (PEPs), and assign each merchant a risk rating. Every application is reviewed manually. We may refuse any application, and we will not establish or continue a business relationship where we cannot complete due diligence.
4. Enhanced due diligence
We apply enhanced due diligence where the risk is higher, for example: businesses that need our prior approval under the Acceptable Use Policy; merchants or beneficial owners who are PEPs; complex or opaque ownership structures; links to higher-risk jurisdictions; unusually high volumes; or adverse screening results.
Enhanced measures may include obtaining further information on ownership, source of funds and source of wealth, evidence of any required licenses, information about the merchant’s own compliance controls, approval by the compliance function, more frequent reviews, lower limits and closer transaction monitoring.
5. Ongoing monitoring and periodic review
We monitor merchants’ activity on an ongoing basis to check that it is consistent with what we know about the merchant, its business and its risk profile, and we investigate unusual activity, such as volumes far above expectations, patterns suggesting structuring, or repeated deposits from high-risk sources.
We review merchant information periodically (more often for higher-risk merchants) and whenever we learn of relevant changes. Merchants must keep their information up to date and respond to our requests (see section 11).
6. Transaction screening
Incoming funds are screened against the OFAC, UN and EU sanctions lists, the ScamSniffer scam list and Tether freeze lists. Payout destinations are screened as well.
Screening results and other risk indicators produce a risk score. Matches and high-risk results raise alerts for manual review, and the related funds may be held until the review is complete.
We keep the lists we use up to date. Screening relies on third-party data and cannot detect every risk, so it complements, rather than replaces, merchants’ own controls.
7. Sanctions and restricted jurisdictions
We do not provide the Service to, or process transactions for the benefit of, persons or entities on applicable sanctions lists, entities owned or controlled by them, or persons located, organized or resident in jurisdictions subject to comprehensive sanctions.
We determine which jurisdictions are restricted on the basis of applicable sanctions regimes and our risk assessment, and we may restrict additional jurisdictions. Any attempt to circumvent these restrictions (for example, by using another person’s account or by concealing your location or ownership) is prohibited.
8. Actions on alerts
Depending on the circumstances, we may:
- hold a Payment, settlement or Payout pending review;
- freeze funds;
- mark a Payment as
failed; - request information or documents from the merchant;
- reject transactions or restrict account features; and
- suspend or terminate the business relationship.
If a deposit matches a sanctions list, the Payment is marked failed and the funds are frozen. We will never automatically return such funds to a sanctioned address; frozen funds are released or otherwise dealt with only as permitted by law or as directed by a competent authority.
9. Reporting to competent authorities
Where required by applicable law, we report suspicious transactions, sanctions matches and other relevant information to competent authorities, and we respond to their lawful requests.
The law may prohibit us from telling a merchant or anyone else that a report has been made or that an investigation is under way.
10. Record keeping
We keep due diligence records, transaction records, screening results, alerts, investigations and reports for at least five years after the business relationship ends, or longer where required by law, in a form that allows individual transactions to be reconstructed and information to be provided promptly to competent authorities.
These records are protected as described in our Privacy Policy.
11. Merchant obligations
Merchants must:
- provide accurate and complete information, and tell us promptly about changes to their ownership, directors, authorized representatives, business or licenses;
- respond fully and promptly to our requests for information or documents, including about their customers and specific transactions;
- carry out their own customer due diligence (KYC) where the law that applies to them requires it, in particular for users of their sub-accounts, and keep records of their customers and orders;
- not use the Service for any prohibited business or activity, or to receive funds they know or suspect to be illicit; and
- tell us promptly if they suspect fraud, money laundering or sanctions evasion involving the Service.
If a merchant fails to meet these obligations, we may take any of the actions described in section 8.
12. Training and independent review
Staff involved in merchant verification, transaction monitoring, payouts and compliance receive anti-money laundering, counter-terrorist financing and sanctions training when they join and regularly afterwards.
The effectiveness of this program is reviewed periodically by a person or function independent of day-to-day compliance work, and any weaknesses identified are remedied.
13. Updates and contact
We may update this policy to reflect changes in law, our products or our risk assessment. The “Last updated” date shows the latest version, and we will notify merchants of material changes.
For questions about this policy, or to report suspected financial crime involving the Service, contact support@ewin888.com.