Legal

AML & CTF Policy

Last updated: 26 January 2026

1. Introduction

This Anti-Money Laundering and Counter-Terrorist Financing Policy ("Policy") sets out the principles, rules, and procedures adopted by FINBPM LIMITED ("FINBPM", "we", "us", "our") to prevent money laundering, terrorist financing, and other financial crimes. FINBPM LIMITED is registered in Gibraltar under company number 126267, with its registered address at Unit G02, EuroCity, Europort Avenue, Gibraltar GX11 1AA, operating as a master merchant under the laws of Gibraltar. FINBPM provides services exclusively to corporate and business entities and does not offer services to individual or retail customers. FINBPM is committed to complying with all applicable AML/CTF laws, regulations, and regulatory guidance in Gibraltar, the EEA, and the United Kingdom, where applicable.

2. Purpose and Scope

The purpose of this Policy is to:

  • Prevent FINBPM from being used for money laundering, terrorist financing, fraud, or other financial crime;
  • Ensure compliance with applicable AML/CTF regulations;
  • Protect FINBPM’s reputation and integrity;
  • Establish effective internal controls and procedures.

This Policy applies to: All directors, officers, employees, agents, and contractors of FINBPM; and All corporate merchants, business partners, and counterparties using FINBPM’s services. FINBPM does not establish business relationships with natural persons acting in a personal capacity.

3. Legal and Regulatory Framework

FINBPM operates in accordance with applicable AML/CTF legislation, including but not limited to:

  • Gibraltar Proceeds of Crime Act;
  • Gibraltar Terrorism Act;
  • Financial Services (Money Laundering) Regulations;
  • EU AML Directives (where applicable);
  • UK Money Laundering Regulations (where relevant);
  • Guidance issued by competent authorities.

FINBPM monitors regulatory developments and updates this Policy as required.

4. Risk-Based Approach

FINBPM applies a risk-based approach to AML/CTF compliance, taking into account:

  • Corporate customer risk;
  • Ownership and control structure risk;
  • Geographic risk;
  • Product and service risk;
  • Transaction risk;
  • Delivery channel risk.

Merchants and transactions are classified as low, medium, or high risk, and due diligence measures are applied accordingly.

5. Governance and Responsibilities

5.1 Board and Senior Management

The Board and senior management are responsible for:

  • Approving and overseeing this Policy;
  • Ensuring adequate resources for AML/CTF compliance;
  • Promoting a culture of compliance.

5.2 Outsourced Money Laundering Reporting Officer (MLRO)

FINBPM appoints an independent, external service provider to act as its Money Laundering Reporting Officer (MLRO). The outsourced MLRO is responsible for: Designing, implementing, and maintaining AML/CTF controls; Receiving and assessing internal suspicious activity reports; Submitting Suspicious Activity Reports (SARs) to relevant authorities; Liaising with regulators and law enforcement agencies; Advising senior management on AML/CTF matters; Overseeing training and compliance programs. FINBPM remains ultimately responsible for AML/CTF compliance notwithstanding the outsourcing of the MLRO function.

5.3 Employees and Agents

All staff and agents must:

  • Comply with this Policy and related procedures;
  • Complete mandatory AML/CTF training;
  • Report suspicious activity promptly;
  • Cooperate with compliance reviews and audits.

6. Customer Due Diligence (CDD)

FINBPM performs Customer Due Diligence before establishing a business relationship and on an ongoing basis.

6.1 Corporate Identification and Verification

FINBPM will obtain and verify, as applicable:

  • Certificate of incorporation and constitutional documents;
  • Company registry extracts;
  • Registered and principal place of business addresses;
  • Details of directors and senior management;
  • Business activities and source of funds;
  • Tax and regulatory status.

6.2 Beneficial Ownership

FINBPM identifies and verifies all ultimate beneficial owners holding 25% or more ownership or control, or otherwise exercising significant influence, in line with applicable regulations.

6.3 Enhanced Due Diligence (EDD)

Enhanced Due Diligence is applied to higher-risk corporate merchants, including those with:

  • Politically Exposed Persons (PEPs) among beneficial owners or controllers;
  • Complex or opaque ownership structures;
  • Exposure to higher-risk jurisdictions;
  • Unusual business models or transaction profiles.
  • EDD measures may include additional documentation, independent verification, site visits, senior management approval, and increased monitoring.

7. Ongoing Monitoring and Compliance Tools

FINBPM implements ongoing monitoring to detect unusual or suspicious activity and ensure continued compliance. Monitoring is supported through a combination of internal controls and specialised third-party compliance tools, including: Automated transaction monitoring systems; Real-time and post-transaction screening solutions; Sanctions and PEP screening platforms; Adverse media and reputational risk databases; Behavioural and pattern-recognition tools; Risk-scoring and profiling systems. These tools are used to: Identify abnormal transaction volumes or values; Detect inconsistent activity patterns; Monitor cross-border and high-risk transactions; Flag potential structuring, layering, or other suspicious behaviour. Alerts generated are reviewed by compliance personnel and, where necessary, escalated to the outsourced MLRO.

8. Sanctions and PEP Screening

FINBPM screens all corporate merchants, beneficial owners, directors, and counterparties against:

  • International and national sanctions lists;
  • Government and regulatory watchlists;
  • Politically Exposed Persons (PEP) databases;
  • Law enforcement and enforcement action registers.
  • Screening is conducted at onboarding and on an ongoing basis using specialised compliance software.

9. Suspicious Activity Reporting

9.1 Internal Reporting

All staff and agents must report suspicious activity promptly through internal reporting channels to the compliance function and the outsourced MLRO.

9.2 External Reporting

Where required, the outsourced MLRO submits Suspicious Activity Reports (SARs) to the relevant Financial Intelligence Unit (FIU) or competent authority. FINBPM prohibits tipping off and maintains strict confidentiality in accordance with applicable law.

10. Record Keeping

FINBPM maintains accurate and complete records of:

  • Corporate customer identification and verification data;
  • Beneficial ownership information;
  • Transaction records;
  • Risk assessments and monitoring results;
  • Due diligence and EDD documentation;
  • SARs and related correspondence.
  • Records are retained for at least five (5) years or longer where required by law.

11. Training and Awareness

FINBPM provides regular AML/CTF training to all relevant staff, covering:

  • Corporate financial crime risks;
  • Transaction monitoring procedures;
  • Use of compliance systems and tools;
  • Reporting obligations;
  • Regulatory developments.
  • Training is conducted at onboarding and at least annually thereafter.

12. Internal Controls and Audit

FINBPM maintains internal controls designed to ensure AML/CTF compliance, including:

  • Segregation of duties;
  • Independent compliance reviews;
  • Periodic internal and external audits;
  • Technology-based monitoring systems;
  • Regular risk assessments.
  • Deficiencies identified are documented and addressed promptly.

13. High-Risk Activities and Prohibited Relationships

FINBPM does not establish or maintain relationships with:

  • Shell banks;
  • Anonymous or fictitious entities;
  • Unregulated intermediaries;
  • Entities operating in prohibited or sanctioned jurisdictions;
  • Businesses engaged in illegal or prohibited activities.
  • High-risk corporate relationships are subject to enhanced scrutiny or refusal.

14. Data Protection and Confidentiality

Personal data processed under this Policy is handled in accordance with applicable data protection laws, including GDPR and UK GDPR. Confidential AML/CTF information is disclosed only where legally required.

15. Breaches and Disciplinary Measures

Breaches of this Policy may result in disciplinary action, contractual termination, and reporting to authorities where required.

16. Policy Review and Updates

This Policy is reviewed at least annually and updated as necessary to reflect legal, regulatory, or operational changes. Material changes are approved by senior management.

17. Governing Law

This Policy shall be governed by and construed in accordance with the laws of Gibraltar.

18. Contact Information

AML/CTF Compliance Function FINBPM LIMITED Unit G02, EuroCity Europort Avenue Gibraltar GX11 1AA Gibraltar AML/CTF matters are handled in coordination with FINBPM’s outsourced MLRO through official internal channels.