Aml Policy

Introduction

MMk121 is a regulated online gaming operator licensed by the Curaçao Gaming Control Board under license number OGL/2024/376/0148. This Anti-Money Laundering (AML) Policy sets out the controls, procedures and responsibilities implemented to prevent the use of MMk121 for money laundering or the financing of terrorism. The Policy applies to all customers, transactions and MMk121 personnel, including employees, contractors and agents acting on behalf of MMk121.

Regulatory Framework and Supervisory Oversight

The AML framework is designed to comply with applicable Curaçao laws and guidelines, including the National Ordinance on Hazard Games (NOIS), the NORUT and related provisions. MMk121 will also adhere to internationally recognized standards as adopted by Curaçao and aligned with FATF best practices. MMk121 acknowledges its responsibility to cooperate with the Financial Intelligence Analysis Unit and any other competent supervisory authority in relation to AML/CFT obligations.

Governing Responsibility

The ultimate responsibility for the MMk121 AML Policy lies with the Director. The Compliance function leads the design, implementation and ongoing review of AML controls, including risk assessment, policy maintenance, staff training and incident reporting. All staff are accountable for applying the policy and reporting concerns through the internal escalation channels.

Risk-Based Approach

MMk121 operates a risk-based framework to identify, assess and mitigate financial crime risk. The framework considers customer risk, product/service risk, channel risk and geographical risk. Risk ratings drive the level of due diligence, frequency of reviews and monitoring intensity. The Board receives periodic updates on risk posture and controls.

Customer Due Diligence (CDD) and Verification

MMk121 conducts CDD on all new customers prior to establishing a business relationship and conducts ongoing due diligence throughout the relationship. Verification procedures include:

  • Identity verification: obtain and verify government-issued identification (e.g., passport or national ID) and confirm name, date of birth and nationality.
  • Proof of address: obtain a document dated within the last three months showing the customer’s name and residential address (e.g., utility bill, bank statement).
  • Source of funds and source of wealth: assess the origin of funds used for deposits and ascertain legitimate wealth sources for higher-risk cases.
  • Payment method validation: verify ownership of payment accounts and ensure alignment with customer information; block or hold unusual or conflicting payment flows.

Onboarding is conducted in a risk-based manner. For deposits above EUR 2,000 or equivalent, customers must provide documentation demonstrating the origin of funds. For deposits above EUR 10,000 or equivalent, additional verification of source of wealth and ongoing monitoring are applied.

Enhanced Due Diligence (EDD)

EDD is required for higher-risk customers or activities, including:

  • Politically Exposed Persons (PEPs) and family/close associates;
  • Customers from high-risk jurisdictions as identified by internal risk assessments;
  • Unusually complex ownership structures or large, rapid, or repetitive transfers not consistent with the customer profile.

EDD measures include intensified identity verification, additional documentation of the source of funds/wealth, enhanced ongoing monitoring and, where appropriate, management approval for continuing the business relationship.

Ongoing Monitoring and Transaction Surveillance

MMk121 maintains ongoing monitoring of customer activity and transactions against the established risk profile. Monitoring includes:

  • Automated transaction monitoring to detect anomalous or suspicious activity;
  • Periodic review of customer profiles and activity, with higher frequency for elevated risk levels;
  • Escalation of suspicious activity to Compliance for further investigation.

Key risk indicators are reviewed at least monthly, with updates to customer risk ratings and controls as needed.

Sanctions, PEPs and Third-Party Screening

All customers and beneficial owners undergo sanctions and PEP screening prior to onboarding and on an ongoing basis. If a match or elevated risk is identified, MMk121 applies enhanced due diligence, augments monitoring and may restrict or terminate the business relationship in line with regulatory requirements.

Record Keeping and Data Retention

MMk121 retains KYC documentation, verification records, source-of-funds information, transaction records and internal communications for a minimum period of five years after the end of the business relationship or the last transaction, whichever is later. Records are stored securely with access restricted to authorized personnel and in accordance with applicable data protection laws.

Reporting and Cooperation with Authorities

Suspicious activity must be promptly escalated through the internal Compliance channel. Where warranted, MMk121 will file reports with the Financial Intelligence Analysis Unit in accordance with applicable law and cooperate with regulatory or law enforcement requests, subject to data protection and privacy constraints.

Training and Awareness

All MMk121 personnel receive AML/CFT training on onboarding and at least annually thereafter. Training covers identification and reporting of suspicious activity, compliance obligations under NOIS/NORUT/NOPML and internal reporting procedures.

Non-Face-to-Face Onboarding

Remote onboarding is permitted where identity verification can be robustly demonstrated through trusted verification technologies and documentary evidence. In all non-face-to-face cases, verification steps are completed before enabling services and are documented for audit purposes.

Third-Party and Payment Service Provider Due Diligence

MMk121 conducts due diligence on third-party service providers and payment processors to prevent misuse for money laundering or terrorist financing. Contracts with providers include AML/CFT obligations, data protection commitments and ongoing monitoring requirements.

Policy Review and Updates

This AML Policy is reviewed at least annually and upon material regulatory change. Material amendments require approval by the Board and prompt dissemination to staff and relevant stakeholders.