🇻🇳 Vietnamese 🇬🇧 English

Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy

1. Purpose and Scope

Ventures Lab Malta Limited (the "Company", "we", "our", or "us") is committed to conducting its business with the highest standards of integrity and to preventing its products and services from being used to facilitate money laundering, terrorist financing, fraud, or any other illicit activity.

The Company is licensed by the Malta Gaming Authority ("MGA") and, as a subject person under Maltese anti-money laundering legislation, maintains policies and procedures designed to meet its legal and regulatory obligations. These measures are founded on a risk-based approach, ensuring that customer due diligence and ongoing monitoring are proportionate to the level of risk presented.

This Policy applies to all customers, prospective customers, and any individual seeking to establish or maintain a business relationship with the Company.

2. AML and KYC Compliance Framework

The Company has established an AML and KYC programme to:

  • verify the identity of customers;
  • understand the nature and intended purpose of customer relationships;
  • identify and manage financial crime risks;
  • conduct ongoing monitoring of customer activity;
  • identify and investigate suspicious behaviour;
  • comply with reporting obligations imposed by law; and
  • maintain appropriate governance and internal controls.

Compliance procedures are reviewed periodically to ensure they remain effective and aligned with regulatory expectations.

3. Customer Due Diligence

Customer Due Diligence ("CDD") measures are applied before, during, or after the establishment of a business relationship where required by applicable legislation or the Company's internal risk assessment.

The Company may request information and documentation to verify:

  • full legal name;
  • date of birth;
  • permanent residential address;
  • nationality;
  • identity documentation;
  • ownership of payment methods; and
  • any additional information necessary to satisfy legal or regulatory obligations.

Verification may be completed through electronic verification providers, manual review of documents, or other reliable and independent sources.

Where identity cannot be verified satisfactorily, the Company may decline to establish the business relationship, suspend account functionality, or restrict access to certain services until verification has been completed.

4. Enhanced Due Diligence

Where a customer or transaction presents an increased level of risk, the Company will apply Enhanced Due Diligence ("EDD") measures.

EDD may be appropriate where:

  • a customer is identified as a Politically Exposed Person ("PEP");
  • sanctions screening identifies a potential match;
  • transactions involve unusually high values or volumes;
  • source of funds or source of wealth cannot readily be established;
  • business relationships involve higher-risk jurisdictions; or
  • transaction patterns differ significantly from expected customer behaviour.

Depending on the level of risk, enhanced measures may include:

  • obtaining additional identification documents;
  • requesting information regarding source of funds or source of wealth;
  • conducting enhanced verification using independent sources;
  • increased monitoring of account activity; and
  • approval from senior compliance personnel before continuing the relationship.

5. Source of Funds Assessment

The Company may request evidence confirming the legitimate origin of funds used to finance gaming activity.

Examples of acceptable documentation include:

  • bank statements;
  • salary or employment records;
  • tax documentation;
  • company ownership documentation;
  • investment records;
  • inheritance documentation;
  • sale agreements relating to assets; or
  • other documentation demonstrating lawful ownership of funds.

Where sufficient evidence is not provided, the Company may suspend or restrict account activity while additional verification is undertaken.

6. Ongoing Customer Monitoring

The Company continuously monitors customer activity throughout the duration of the business relationship.

Monitoring procedures are intended to identify:

  • unusual deposit or withdrawal activity;
  • rapid movement of funds;
  • irregular betting patterns;
  • transactions inconsistent with the customer's known profile;
  • attempts to structure transactions below reporting thresholds; and
  • any other behaviour indicating potential financial crime.

Where necessary, the Company may request further information before permitting additional transactions.

7. Withdrawal Verification Procedures

To comply with applicable AML, CTF, fraud prevention, and regulatory obligations, the Company may conduct additional verification before authorising withdrawals.

Identity verification may be required where a customer's cumulative deposits exceed €2,000.

For this purpose, cumulative deposits may be calculated:

  • by aggregating all deposits made by the customer from the commencement of the business relationship on a daily cumulative basis; or
  • by aggregating deposits made within a rolling period of one hundred and eighty (180) days.

Where verification requirements have not been satisfied, withdrawal requests may remain pending until the requested documentation has been received and approved.

The Company may also require customers to verify ownership of payment methods, provide evidence of source of funds, or submit any additional documentation considered necessary to satisfy its legal and regulatory obligations.

8. Sanctions and Politically Exposed Persons

As part of its AML programme, the Company conducts sanctions and Politically Exposed Person ("PEP") screening at onboarding and periodically thereafter.

Customers may be screened against:

  • European Union sanctions lists;
  • United Nations sanctions lists;
  • national sanctions registers;
  • PEP databases; and
  • other recognised compliance databases.

Potential matches are assessed by the Compliance function before any decision concerning the customer relationship is made.

9. Suspicious Activity Reporting

Where the Company knows, suspects, or has reasonable grounds to suspect that customer activity is connected with money laundering, terrorist financing, or another criminal offence, it will submit a Suspicious Activity Report ("SAR") to the Financial Intelligence Analysis Unit ("FIAU") in accordance with Maltese law.

The Company and its employees are prohibited from disclosing to customers that a report has been submitted or that an investigation is underway.

The Company will cooperate fully with the FIAU, the Malta Gaming Authority, and other competent authorities where required.

10. Customer Responsibilities

Customers are expected to:

  • provide accurate and complete information during registration;
  • keep personal information up to date;
  • provide requested documentation within reasonable timeframes;
  • ensure all submitted documents are genuine and valid; and
  • cooperate with compliance reviews conducted by the Company.

Failure to comply with these obligations may result in transaction restrictions, delayed withdrawals, suspension of account functionality, or closure of the account where appropriate.

11. Governance and Internal Controls

The Company's AML and KYC programme is supported by an internal governance framework that includes:

  • a designated Money Laundering Reporting Officer (MLRO);
  • documented AML and CTF policies and procedures;
  • internal escalation and reporting mechanisms;
  • periodic financial crime risk assessments;
  • compliance monitoring and internal reviews; and
  • ongoing employee training tailored to AML and CTF responsibilities.

These arrangements are reviewed regularly to ensure continued effectiveness and regulatory compliance.

12. Record Retention and Data Protection

The Company maintains records relating to customer identification, verification, transaction monitoring, risk assessments, and regulatory reporting in accordance with applicable legal requirements.

Unless otherwise required by law, such records are retained for a minimum period of five (5) years following the end of the business relationship or completion of the relevant transaction.

All personal data collected under this Policy is processed in accordance with the General Data Protection Regulation (GDPR) and the Company's internal information security policies. Access to customer information is restricted to authorised personnel and disclosed only where legally required.

13. Review and Amendments

This Policy forms part of the Company's compliance framework and is reviewed periodically to ensure continued alignment with legislative requirements, regulatory guidance, and operational practices.

The Company may amend this Policy at any time to reflect changes in applicable laws, regulatory expectations, or internal procedures. The latest version of the Policy will be made available through the Company's official customer communication channels.