AML/KYC Policy

3-102-949565 SOCIEDAD DE RESPONSABILIDAD LIMITADA | Last updated: 2026-06-16

The English version prevails.

This AML/KYC Policy consolidates and replaces the previous KYC Procedure and AML/KYC Procedure. It sets out the Company framework for anti-money laundering, counter-terrorist financing, counter-proliferation financing, sanctions compliance, customer due diligence, enhanced due diligence, transaction monitoring, suspicious activity reporting and record keeping.

1. Regulatory Framework and Scope

1.1 This Policy is designed to comply with the Tobique Gaming Act 2023, the TGC Remote Gambling AML Code of Practice, the TGC General Code of Practice, the TGC Regulations Concerning AML and Counter Terrorist Financing, FATF Recommendations and applicable AML/CFT laws.

1.2 The Policy applies to all players, Accounts, transactions, payment methods, employees, contractors, relevant third parties and business relationships of 3-102-949565 SOCIEDAD DE RESPONSABILIDAD LIMITADA (the "Company").

1.3 This Policy should be read with the Terms and Conditions, Payments Policy, Crypto-Currency Policy, Privacy Policy and Responsible Gambling Policy  or any other Policies which could be added on the website or through the official communication channels. Where behaviour described in Section 6 of the Terms and Conditions creates reasonable grounds for suspicion of money laundering, terrorist financing, fraud, sanctions evasion or other financial crime, this Policy applies in full.

1.4 The Company applies a risk-based approach. Measures are proportionate to the size, nature and risk profile of the business, while ensuring the minimum controls required by the Tobique framework are met.

2. AML/CFT Program

2.1 The Company maintains an AML/CFT Program consisting of: (i) an enterprise-wide risk assessment; and (ii) written policies, controls and procedures designed to manage and mitigate identified risks.

2.2 The AML/CFT Program includes risk management practices, internal controls, CDD and EDD procedures, sanctions and PEP screening, transaction monitoring, reporting, record keeping, staff training, employee due diligence, independent review and governance oversight.

2.3 The Program is reviewed at least annually and whenever material changes occur in products, technologies, delivery channels, payment methods, jurisdictions, customer typologies, outsourcing or regulatory requirements.

3. Definitions and Money Laundering Typologies

3.1 Money laundering includes using, transferring, converting, concealing, acquiring, possessing or dealing with criminal property or proceeds of crime, including arrangements that facilitate the acquisition, retention, use or control of criminal property by or on behalf of another person.

3.2 In the remote gaming sector, the Company recognises the following typologies: disguise of illicit funds as legitimate funds; conversion of illicit funds into apparently legitimate winnings; and disposal of illicit funds through losses, debt settlement, chip-dumping, peer-to-peer transfers or similar methods.

3.3 Financing of terrorism and proliferation financing include providing or collecting funds, or becoming involved in arrangements that make money or property available, where there is intent, negligence, recklessness or reasonable cause to suspect terrorist or proliferation purposes.

3.4 Red flags include, without limitation: high losses inconsistent with known financial means; sudden spikes in activity; avoidance or delay in communication; false or implausible documents; inconsistent personal information; adverse media; withdrawals inconsistent with gameplay; deposits from corporate or third-party instruments; problem gambling funded by stolen funds; misleading source-of-funds explanations; player-to-player transfer of criminal funds; low-risk or minimal play used to recycle funds; and use of VPNs or geolocation manipulation.

4. Governance and Responsibilities

4.1 The Board and senior management retain ultimate responsibility for AML/CFT compliance and must provide appropriate resources, oversight and challenge.

4.2 The Company appoints an AML Compliance Officer / Money Laundering Reporting Officer (AMLCO/MLRO) who is responsible for implementation and oversight of the AML/CFT Program. The AMLCO/MLRO must have sufficient AML/CFT knowledge, autonomy, seniority and understanding of remote gaming ML/TF risks.

4.3 The existence of the AMLCO/MLRO and compliance staff does not remove the responsibility of other senior executives or employees to prevent, detect and report money laundering or terrorist financing risks.

4.4 Major changes to this Policy require approval by senior management and the AMLCO/MLRO. The Board receives at least an annual AML/CFT report including risk assessment updates, material issues, SAR/SMR metrics, control weaknesses and remediation progress.

5. Customer Due Diligence Triggers

5.1 CDD measures are initiated when establishing business relations, which for players occurs at registration and acceptance of the Terms and Conditions.

5.2 CDD measures are also initiated when carrying out occasional transactions above applicable thresholds, where there is suspicion of money laundering or terrorist financing, where there is doubt about the veracity or adequacy of previously obtained KYC data, when a customer’s risk assessment changes, or where fraud indicators under the Terms and Conditions require additional checks.

5.3 Verification is commenced at account opening and must be completed before the earlier of: (i) 30 days from first deposit; (ii) cumulative deposits reaching EUR 2,000 or currency equivalent; or (iii) first withdrawal request. Age and identity must be formally verified before winnings are paid out.

6. Three-Step Verification

6.1 Step One - Registration and electronic footprint. At registration, the Company collects at least name, email address, date of birth and physical address. The registration process includes positive age affirmation, detects under-18 registrants and false information where possible, and records electronic footprint data such as IP address, device identifier, cookies and technical data.

6.2 Step Two - Identity, address and screening verification. Step Two is required when the player deposits over EUR 2,000 cumulatively, requests any withdrawal, or reaches 30 days after first deposit. Until Step Two is completed, deposits, withdrawals and gameplay may be held. The player must provide a valid government-issued ID photographed with a randomly generated six-digit code, and the Company performs electronic validation using at least two independent databases where available.

6.3 If electronic address verification fails or cannot be performed, the player must provide proof of current residential address such as a recent utility bill, bank or card statement, government correspondence, residence certificate or registration document.

6.4 At Step Two, the Company conducts sanctions, PEP and adverse media screening through a reputable third-party provider with coverage of UN, EU, OFAC, HMT and other relevant sanctions lists, domestic, foreign and international PEPs, and adverse media relating to financial crime, corruption, fraud, terrorism and predicate offences.

6.5 If there is no match, verification may proceed. If there is a possible match, the Account is placed in pending status and no transactions are processed until manual review. Confirmed sanctions matches require immediate blocking/freezing and SAR/SMR filing. Confirmed PEPs require EDD, senior management approval, SOF/SOW verification and enhanced monitoring. Material adverse media may result in additional documents, restrictions or termination of the relationship.

6.6 Step Three - Source of Funds / Source of Wealth. Step Three is required when the player deposits more than USD 5,000 or EUR 5,000 cumulatively or in a single transaction, requests a withdrawal over USD 5,000 or currency equivalent, transfers more than USD 3,000 to another user, or otherwise triggers EDD. Until completed, deposits, withdrawals and gameplay may be held.

6.7 Acceptable SOF/SOW evidence may include business ownership documents, audited accounts, employment income evidence, tax returns, inheritance documents, investment records, bank statements, sale agreements, gift/family support evidence or other credible documents accepted by the AMLCO/MLRO.

7. KYC Documentation Standards

7.1 Proof of identity must be a clear copy of a valid passport, national ID card or driver’s license. The document must show all four corners and visible first and last name, date of birth, gender, nationality and photograph. The Company may request unobscured copies where necessary for verification.

7.2 Selfie verification may be required as a live or static facial image for biometric comparison with the submitted ID document. Images must be high resolution, without glare, blur or obstruction.

7.3 Proof of address documents must be recent, normally issued within the last three months, and must display the customer’s full name and residential address. Cropped, altered or incomplete documents will not be accepted.

7.4 Payment method verification may require proof of ownership of cards, bank accounts, wallets or other instruments. Card images must obscure CVV and non-essential middle digits unless full details are legally required.

7.5 Where a customer is a legal entity or corporate account holder, the Company will verify the entity, ownership and control structure, beneficial owners, purpose and intended nature of the relationship and predicted transactional profile, applying EDD where required.

8. Risk Rating and Levels of Due Diligence

8.1 Each player is assigned a risk rating based on residence and IP location, nationality, payment methods, transaction volume and frequency, gameplay behaviour, bonus activity, adverse media, sanctions/PEP screening results, device/electronic footprint, linked accounts and other risk indicators.

8.2 Standard Due Diligence applies to low and medium risk players where no high-risk factor or red flag is present.

8.3 Enhanced Due Diligence applies where higher ML/TF risk is identified, including high-risk jurisdictions, PEPs or close associates, PCSEs, significant adverse media, high-value or high-volume transactions, use of high-risk payment methods such as prepaid cards or cryptocurrency, faked/stolen ID, suspicious gameplay, fund cycling, VPN/geolocation manipulation or doubts about previously obtained KYC data.

8.4 EDD may include additional identity verification, certified documents, SOF/SOW evidence, enhanced screening, senior management and AMLCO/MLRO approval, transaction limits, payment restrictions, enhanced monitoring, periodic reviews and review of linked accounts.

9. Country Risk, Restricted and EDD Jurisdictions

9.1 The Company will not do business with any individual or entity subject to EU, UN, UK, US or other applicable international sanctions. Sanctioned customers and sanctioned wallets must not be allowed to deposit, play or withdraw, and funds/assets must be frozen without delay where required.

9.2 The following jurisdictions are treated as Tobique Restricted Jurisdictions and are outside risk appetite. Players located in these jurisdictions are not permitted to register, access, deposit, wager or withdraw under the Tobique license: Afghanistan, Canadian Province of New Brunswick, Belarus China, Cuba, Central African Republic, Democratic Republic of Congo, Haiti, Iran, Iraq, Israel, Libya, Myanmar, North Korea, Poland, Russia, Somalia, South Sudan, Syria, United Kingdom, United States of America, Yemen, Ukraine, Venezuela.

9.3 The Company also maintains additional restricted jurisdictions based on its own risk appetite, payment provider constraints, game provider constraints, legal risk and operational controls. These additional Company restrictions are operational/commercial restrictions and do not by themselves classify the jurisdiction as Tobique-banned or AML high-risk. Unless and until removed by senior management and compliance approval, the additional Company restricted jurisdictions include: Armenia, Azerbaijan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, Australia, Belgium, Canada (Ontario), Croatia, Denmark, France, Georgia, Guinea Bissau, Jamaica, Lebanon, Netherlands, Nicaragua, Pakistan, Panama, Philippines, Portugal, Spain, Switzerland, Turkey, Zimbabwe.

9.4 Where a jurisdiction is not restricted but is listed by Tobique as subject to Enhanced Due Diligence, players associated with that jurisdiction are subject to EDD at first deposit and enhanced monitoring. Current Tobique EDD jurisdictions include: Albania, Barbados, Bulgaria, Burkina Faso, Burundi, Chad, Comoros, Cameroon, Cayman Islands, Croatia, Equatorial Guinea, Gibraltar, Jamaica, Jordan, Lebanon, Mali, Mozambique, Nicaragua, Nigeria, Pakistan, Palestinian Territory, Panama, Philippines, Senegal, South Africa, Tanzania, Tajikistan, Turkey, Turkmenistan, Uganda, United Arab Emirates, Vietnam, Zimbabwe. The Compliance function must update this list promptly if Tobique amends its assessment.

9.5 The jurisdiction lists are reviewed regularly against Tobique updates, sanctions lists, FATF lists, regulatory guidance, legal developments, payment provider rules and the Company EWRA. Missing mandatory Tobique restricted jurisdictions must be added without delay.

10. Screening: Sanctions, PEPs, Adverse Media and PCSE

10.1 All players are screened at registration and on an ongoing basis against sanctions, PEP and adverse media databases. Screening is repeated upon list updates, material changes to customer data, risk review, event-driven review or manual compliance trigger.

10.2 PEPs, immediate family members and close associates require EDD, senior management approval for establishing or continuing the relationship, SOF/SOW verification and enhanced ongoing monitoring. Former PEPs remain subject to risk assessment for at least 12 months after leaving office.

10.3 Persons Connected to Sporting Events (PCSEs) include individuals who own, play with, coach, train, manage or hold a senior role in a sporting team or organisation on which the Company accepts bets, and their close family members or associates. PCSEs require senior management approval, SOF/SOW measures and enhanced monitoring.

10.4 Significant adverse media connected to financial crime, corruption, fraud, terrorism, match-fixing, sanctions evasion or serious criminal conduct is assessed by the AMLCO/MLRO and may result in EDD, restrictions, refusal or termination.

11. Ongoing Monitoring and Event-Driven Reviews

11.1 Ongoing monitoring includes regular screening against sanctions, PEP and adverse media databases, transaction monitoring of deposits, withdrawals, transfers and gameplay, linked-account monitoring, comparison against expected customer profiles, and escalation of unusual activity to the AMLCO/MLRO.

11.2 Transaction monitoring must detect unusual or inconsistent transaction behaviour, rapid deposit/withdrawal patterns, structuring, multiple accounts or instruments, third-party payment use, minimal or low-risk play, use of cryptocurrency or prepaid cards, VPN/geolocation anomalies, bonus abuse, bot/script indicators and fund cycling.

11.3 Periodic reviews refresh customer risk assessments, KYC information, documents, screening and transaction profiles. Frequency is risk-based. High-risk customers, PEPs, PCSEs and customers subject to EDD are reviewed more frequently.

11.4 Event-driven reviews are triggered by red flags, high-risk factors, unusual bets or transactions, sanctions/PEP list updates, personal data changes, material corporate ownership or control changes, payment method changes, use of restricted jurisdictions, suspicious behaviour, fraud indicators or AMLCO/MLRO direction.

12. Crypto and High-Risk Payment Methods

12.1 Cryptocurrency is treated as a high-risk payment method and is subject to the Crypto-Currency Policy. Customers intending to use cryptocurrency may be subject to EDD before activation of crypto services.

12.2 Crypto transactions are screened using blockchain analytics, wallet risk scoring and sanctions/blacklist checks. Transactions involving mixers, tumblers, chain-hopping, darknet markets, ransomware, sanctioned wallets or illicit typologies are blocked and escalated.

12.3 Prepaid cards, third-party payment instruments, mismatched payment details, corporate cards, high velocity transactions and large cash-like movements are high-risk indicators requiring additional review or EDD.

13. Suspicious Activity Reporting and Tipping Off

13.1 All employees must report internally to the AMLCO/MLRO without delay if they know, suspect or have reasonable grounds to suspect money laundering, terrorist financing, sanctions evasion, fraud, identity misrepresentation, unlawful activity or a transaction lacking lawful economic purpose.

13.2 A suspicious matter report/SAR must be lodged with the TGC within five business days after the Company forms a suspicion concerning possible money laundering or other criminal activity. A report concerning possible terrorist financing must be lodged within 24 hours after forming the relevant suspicion. Where required, reports are also submitted to the relevant FIU.

13.3 The Company documents grounds for submission or non-submission of each SAR/SMR and retains supporting evidence, investigation notes and decisions.

13.4 Tipping off is prohibited. Once a suspicion has been formed, a report lodged, or information communicated to the TGC, no employee or associated person may disclose that fact to any person other than the TGC, Direct Licensee, FIU, law enforcement or other authorised person, except as legally permitted.

14. Reliance on Third Parties and Outsourcing

14.1 The Company may use third-party providers for electronic identity verification, sanctions/PEP/adverse media screening, blockchain analytics, fraud prevention, payments or technical monitoring. Ultimate responsibility for compliance remains with the Company.

14.2 Before reliance, the Company assesses third-party suitability, controls, licensing/registration where relevant, data protection, AML/CFT capability, service resilience and ability to provide records without delay upon request.

14.3 Responsibilities of the Company and third party must be clearly defined in written agreements, including AML/CFT compliance, confidentiality, data protection, audit cooperation and record access.

15. Enterprise-Wide Risk Assessment

15.1 The Company conducts an EWRA at least annually. The EWRA considers customer typologies, countries and geographic areas, products and services, payment methods and transaction patterns, operational setup and delivery channels, third-party suppliers and service providers, and new products or technologies.

15.2 EWRA findings are documented and used to update policies, controls, thresholds, monitoring rules, training and reporting. The EWRA and supporting records are provided to the TGC or Direct Licensee upon request.

16. Training and Employee Due Diligence

16.1 All relevant employees receive AML/CFT training appropriate to their role, including the law and regulatory obligations, red flags, suspicious activity, internal reporting, sanctions, PEPs, CDD/EDD, crypto typologies, problem gambling and fraud indicators.

16.2 New employees receive initial training. Refresher training is provided annually and when there are material changes to laws, policies, products or risks. Training records and assessment results are retained.

16.3 The Company performs risk-based employee due diligence, including identity verification, background and reference checks, integrity assessment, and rescreening when employees move into sensitive roles. Non-compliance by employees is managed under internal disciplinary controls.

17. Record Keeping

17.1 The Company keeps all records obtained through CDD, including identification documents, verification results, account files, business correspondence and KYC evidence, for at least five years after the business relationship ends or after the date of the occasional transaction.

17.2 The Company maintains transaction records, originator/payer information and beneficiary/payee information on wire transfers, electronic fund transfers, crypto transfers and other electronic payments for at least five years, or longer where required by law, investigation, litigation hold or regulatory direction.

17.3 Records are stored securely, protected against unauthorised alteration or deletion, and made available to the TGC, Direct Licensee, auditors, FIU or law enforcement upon request.

18. Independent Review, Audit and Remediation

18.1 The AML/CFT Program is subject to regular independent and, where appropriate, external review. The review is undertaken at least once every two years, or more frequently based on the nature, size, complexity and risk profile of the business.

18.2 The review assesses whether the Program is effective, has been implemented, and has been complied with. Results are provided to senior management and, where required, the governing body and TGC.

18.3 The TGC or Direct Licensee may audit the Company AML/CFT framework at any time. When weaknesses are identified, remedial action, including process change, must be implemented promptly.

19. Policy Review and Version Control

19.1 This Policy is reviewed annually, following regulatory changes, after material incidents, after EWRA changes, when new products or payment methods are introduced, and whenever required by the TGC or Direct Licensee.

19.2 Operational guidance, procedures and templates implementing this Policy are maintained by the Compliance function and made available to relevant employees.

Anti-Money Laundering and Verification Policies at Winari Casino