Last updated: 4 October 2026 · Template — to be reviewed by qualified legal counsel before publication.
1. Purpose and Scope
This Anti-Money Laundering and Know Your Customer Policy (the “Policy”) sets out the measures applied by OCTO FINANCIAL LTD (“OctoHex”) to prevent the Platform from being used for money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud and other financial crime. It applies to all clients and partners and to all employees, officers and contractors of OctoHex, and is implemented in accordance with the laws of England and Wales and applicable international standards, including the recommendations of the Financial Action Task Force (FATF).
2. Governance and MLRO
OctoHex has appointed a Money Laundering Reporting Officer (“MLRO”), reachable at compliance@octohex.com, who is responsible for the implementation and oversight of this Policy, the assessment of internal reports of suspicion and reporting to the competent financial intelligence unit. The MLRO can be contacted at compliance@octohex.com. Senior management approves this Policy and reviews it at least annually or upon material changes in law or in our risk profile.
3. Risk-Based Approach
We apply a risk-based approach. Each client is assigned a risk rating based on factors including country of residence and nationality, PEP status, sanctions and adverse media results, expected and actual deposit volumes, source of funds, wallet risk scores, use of the partner program and behavioural indicators. The risk rating determines the level of due diligence and monitoring applied and is reviewed periodically and upon trigger events.
4. Customer Due Diligence (CDD)
Verification is mandatory for all clients and partners. No deposit, Package purchase, trading activity or partner payout is permitted before verification has been approved. Standard due diligence includes:
collection of full name, date of birth, nationality, residential address and contact details;
verification of a valid government-issued identity document;
a liveness check and biometric comparison between the selfie and the document photo;
screening against sanctions, PEP and adverse media databases;
proof of address where required by our risk assessment or by law;
information on the purpose and intended nature of the business relationship and the expected level of activity.
5. Verification Flow via Didit
Identity verification is carried out through our third-party provider Didit. The typical flow is: (1) the client starts verification from the client area; (2) the client captures images of an identity document, which are checked for authenticity, validity and data consistency; (3) the client completes a liveness check and selfie, which is biometrically matched to the document; (4) the client’s data is screened against sanctions, PEP and adverse media lists; (5) where required, the client uploads proof of address; (6) the result is returned to OctoHex, where it is approved automatically, referred to a compliance officer for manual review, or declined.
OctoHex remains responsible for its due diligence obligations and may request further documents or carry out additional checks at any time.
6. Enhanced Due Diligence (EDD)
Enhanced due diligence is applied to higher-risk relationships, including PEPs, their family members and close associates, clients connected to higher-risk third countries, clients with high-risk wallet exposure, unusual activity patterns and clients whose cumulative deposits exceed $250,000. EDD may include:
documentary evidence of source of funds (for example, exchange account statements, payslips, sale agreements) for deposits above $100,000;
evidence of source of wealth for cumulative deposits above $500,000;
senior management approval to establish or continue the relationship;
more frequent reviews and enhanced transaction monitoring.
7. Sanctions and PEP Screening
Clients are screened at onboarding and on an ongoing basis against applicable sanctions lists, including those of the United Nations, the European Union, the United Kingdom, the United States (OFAC) and England and Wales, as well as PEP and adverse media databases. Positive matches are reviewed by compliance. Where a confirmed sanctions match exists, we will freeze relevant assets as required by law, refuse or terminate the relationship and report to the competent authority.
8. Crypto Wallet Screening and Blockchain Analytics
All deposit and withdrawal wallet addresses are screened using blockchain analytics tools to assess exposure to sanctioned entities, darknet markets, mixers, ransomware, scams, stolen funds and other illicit sources. Withdrawals are made only to wallets verified as belonging to the client. We may require the client to demonstrate ownership of a wallet, for example by a signed message or a test transaction. Deposits from high-risk sources may be held, rejected or returned, and may be reported to the authorities.
9. Travel Rule
Where applicable, we comply with the FATF Travel Rule and corresponding local legislation by collecting, verifying, transmitting and retaining required originator and beneficiary information for crypto-asset transfers, including transfers to and from self-hosted wallets. Transfers lacking required information may be suspended, returned or rejected.
10. Ongoing Monitoring
We monitor client activity throughout the relationship, including deposits, withdrawals, wallet changes, early-termination requests, login patterns, IP and device data, and partner referral structures. Indicators such as rapid deposit and withdrawal cycles, structuring below thresholds, use of multiple wallets, mismatches between declared and actual activity, logins from restricted jurisdictions or anonymising tools, and connected accounts are reviewed. Client information is refreshed periodically according to risk rating.
11. Suspicious Activity Reporting
Employees must report any knowledge or suspicion of money laundering or terrorist financing to the MLRO without delay. The MLRO assesses internal reports and, where appropriate, files a suspicious activity or transaction report with the UK Financial Intelligence Unit (UKFIU) of the National Crime Agency. We are prohibited by law from informing the client or third parties that a report has been made or is being considered (“tipping off”). We cooperate fully with competent authorities.
12. Restricted Jurisdictions
We do not onboard clients or partners who are resident in, citizens of, or located in jurisdictions subject to comprehensive sanctions, jurisdictions identified by the FATF as subject to a call for action, or the jurisdictions listed in our list of restricted countries (Afghanistan, Algeria, Angola, Benin, Botswana, Burkina Faso, Burundi, Cameroon, Cape Verde, Central African Republic, Chad, Comoros, Congo - Brazzaville, Congo - Kinshasa, Côte d’Ivoire, Cuba, Djibouti, Egypt, Equatorial Guinea, Eritrea, Eswatini, Ethiopia, Gabon, Gambia, Ghana, Guinea, Guinea-Bissau, Iran, Iraq, Kenya, Lesotho, Liberia, Libya, Madagascar, Malawi, Mali, Mauritania, Mauritius, Morocco, Mozambique, Myanmar (Burma), Namibia, Niger, Nigeria, North Korea, Puerto Rico, Rwanda, São Tomé & Príncipe, Senegal, Seychelles, Sierra Leone, Somalia, South Africa, South Sudan, Sudan, Syria, Tanzania, Togo, Tunisia, Türkiye, Uganda, United States, Zambia, Zimbabwe). US persons (citizens, green-card holders and residents of the United States) are not accepted. We use IP geolocation and other controls to enforce these restrictions.
13. Refusal, Suspension and Termination
We may refuse to establish a relationship, refuse or delay a transaction, suspend an account or terminate a relationship where due diligence cannot be completed, where information provided is false or inconsistent, where the client’s risk exceeds our risk appetite, or where required by law. Where funds are returned, they will be returned only to the originating or a verified wallet, subject to any legal requirement to freeze or withhold them.
14. Record Keeping
We retain customer due diligence documents, verification results, transaction records, screening results, internal and external reports and related correspondence for at least five (5) years after the end of the business relationship or the date of an occasional transaction, or longer where required by law or a competent authority. Records are kept securely and in a form that allows them to be made available to authorities promptly.
15. Training and Review
All relevant staff receive AML/CFT and sanctions training upon joining and at least annually, appropriate to their role. Compliance with this Policy is subject to periodic independent review. This Policy is reviewed at least annually and updated as necessary. Questions may be addressed to compliance@octohex.com.
