Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy
1. Regulatory Framework and Commitment
This Anti-Money Laundering and Know Your Customer Policy
(“Policy”) sets out the standards applied by Mobile Incorporated
Limited (the “Company”, “we”, “us”, or “our”) to prevent the
misuse of its services for money laundering, terrorist financing,
fraud, or any other form of financial crime.
The Company operates under a B2C Gaming Service Licence issued by
the Malta Gaming Authority (MGA) and is classified as a subject
person under Maltese Anti-Money Laundering and Counter-Terrorist
Financing legislation.
Accordingly, the Company applies a risk-based compliance framework
designed to identify, assess, mitigate, and report financial crime
risks across its customer base and transactional activity.
This Policy applies to all users of the Company’s gaming and
betting services.
2. Customer Due Diligence (CDD)
2.1 Identity Verification
Prior to, or during, the establishment of a business relationship,
the Company is required to verify the identity of each customer.
This includes:
-
Collection of valid government-issued photographic
identification
-
Verification of full legal name, date of birth, and residential
address
-
Confirmation that the customer meets the minimum legal age
requirement of 18 years
Verification may be conducted through automated electronic
verification tools or manual document review processes using
reliable and independent sources.
Where verification cannot be satisfactorily completed, the Company
reserves the right to restrict, suspend, or decline account
functionality.
2.2 Enhanced Due Diligence (EDD)
Where higher levels of risk are identified, the Company applies
Enhanced Due Diligence measures.
These circumstances include:
- Classification of a customer as high-risk
- Identification as a Politically Exposed Person (PEP)
- Unusual or high-value transactional activity
- Unclear or insufficient source of funds or wealth
- Elevated geographical or jurisdictional risk indicators
EDD measures may include:
- Requesting additional documentation
- Independent verification of provided information
- Source of funds and wealth validation
-
Senior Management approval prior to continuation of the
relationship
3. Source of Funds and Financial Assessment
The Company may require customers to provide supporting evidence
demonstrating the legitimacy of funds used on the platform.
Acceptable documentation may include:
- Bank account statements
- Employment confirmation or payslips
- Corporate ownership or business records (where relevant)
- Asset sale agreements or similar financial records
Pending satisfactory review, the Company may temporarily limit
deposits, withdrawals, or account activity.
4. Transaction Monitoring and Suspicious Behaviour Detection
The Company operates both automated systems and manual oversight
processes to monitor customer activity.
Monitoring is designed to detect:
- Unusual or inconsistent deposit and withdrawal behaviour
- Rapid movement of funds in and out of accounts
- Structuring or layering patterns
-
Betting or gaming behaviour inconsistent with expected profile
All alerts are reviewed by qualified compliance personnel.
Where concerns arise, the Company may:
- Request further information or documentation
- Restrict or suspend account activity
- Escalate the matter internally for review
- Submit a Suspicious Activity Report (SAR) where required
5. Sanctions Screening and PEP Checks
All customers are screened against relevant international and
national databases, including:
- EU consolidated sanctions lists
- United Nations sanctions lists
- Applicable national sanctions registers
- Politically Exposed Person (PEP) databases
Screening is performed at onboarding and repeated periodically
throughout the business relationship.
6. Regulatory Reporting Obligations
Where the Company knows, suspects, or has reasonable grounds to
suspect money laundering or terrorist financing activity, it is
required to submit a Suspicious Activity Report (SAR) to the
Financial Intelligence Analysis Unit (FIAU) in accordance with
Maltese law.
The Company strictly prohibits any form of tipping-off to
customers or third parties.
The Company fully cooperates with:
- The FIAU
- The Malta Gaming Authority (MGA)
- Law enforcement authorities
7. Record Keeping and Retention
In compliance with applicable AML/CTF regulations, the Company
retains records including:
- Customer identification and verification data
- Transaction and account activity records
- Risk assessments and monitoring outputs
- Suspicious Activity Reports and related documentation
All records are retained for a minimum period of five (5) years
following the end of the business relationship or last
transaction, whichever is later.
8. Risk-Based Assessment and Ongoing Monitoring
The Company applies a risk-based approach to both onboarding and
ongoing customer monitoring.
Customers are assessed and classified according to factors such
as:
- Geographic exposure
- Transaction size, frequency, and behaviour
- Account usage patterns
- Other behavioural or risk indicators
High-risk customers are subject to Enhanced Due Diligence and more
frequent monitoring.
The Company prepares periodic compliance and risk reports, which
may be submitted to the MGA in accordance with licensing
requirements.
9. Customer Obligations
Customers are required to:
-
Provide accurate, complete, and truthful information during
registration
- Maintain up-to-date account and identity information
-
Provide additional documentation upon request for AML/KYC
purposes
Failure to comply with verification or AML/KYC requirements may
result in:
- Suspension of account access
- Restriction of deposits or withdrawals
- Closure of the account
All actions are taken in accordance with applicable regulatory
obligations.
10. Internal Governance, Controls, and Training
The Company maintains a structured AML governance framework
including:
-
Appointment of a Money Laundering Reporting Officer (MLRO)
- Documented internal AML/CTF procedures
- Defined escalation and decision-making protocols
- Regular employee training programmes
The effectiveness of the AML control framework is reviewed on a
periodic basis.
11. Data Protection and Information Security
All personal and financial information collected under this Policy
is processed in accordance with applicable data protection laws,
including GDPR and relevant regulatory standards.
The Company ensures:
- Secure storage of personal data
- Restricted access to authorised personnel only
-
Controlled sharing with regulatory and legal authorities where
required
-
Protection of confidentiality, integrity, and availability of
data
AML and KYC records are retained for at least five (5) years after
the end of the business relationship, in accordance with
regulatory requirements.
12. Withdrawal Conditions and Identity Verification Threshold
The Company applies conditions to withdrawals as part of its AML
and fraud prevention framework.
Withdrawals may be subject to identity verification requirements,
including where a customer’s cumulative deposits exceed €2,000.
This threshold may be calculated using either:
-
a daily cumulative basis, taking into account all deposits made
by the customer from the commencement of the business
relationship; or
-
a rolling period of one hundred and eighty (180) days,
aggregating deposits within that timeframe
Where this threshold is reached, the Company may require enhanced
identity verification prior to processing withdrawal requests.
Failure to complete required verification may result in delays or
restrictions on withdrawal processing.
13. Policy Updates
This Policy may be amended from time to time to reflect changes in
legal, regulatory, or operational requirements.
The most current version will always be made available through the
Company’s official website or customer information channels.
Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy 1.
Regulatory Framework and Commitment This Anti-Money Laundering and
Know Your Customer Policy (“Policy”) sets out the standards applied
by Mobile Incorporated Limited (the “Company”, “we”, “us”, or “our”)
to prevent the misuse of its services for money laundering,
terrorist financing, fraud, or any other form of financial crime.
The Company operates under a B2C Gaming Service Licence issued by
the Malta Gaming Authority (MGA) and is classified as a subject
person under Maltese Anti-Money Laundering and Counter-Terrorist
Financing legislation. Accordingly, the Company applies a risk-based
compliance framework designed to identify, assess, mitigate, and
report financial crime risks across its customer base and
transactional activity. This Policy applies to all users of the
Company’s gaming and betting services. 2. Customer Due Diligence
(CDD) 2.1 Identity Verification Prior to, or during, the
establishment of a business relationship, the Company is required to
verify the identity of each customer. This includes: Collection of
valid government-issued photographic identification Verification of
full legal name, date of birth, and residential address Confirmation
that the customer meets the minimum legal age requirement of 18
years Verification may be conducted through automated electronic
verification tools or manual document review processes using
reliable and independent sources. Where verification cannot be
satisfactorily completed, the Company reserves the right to
restrict, suspend, or decline account functionality. 2.2 Enhanced
Due Diligence (EDD) Where higher levels of risk are identified, the
Company applies Enhanced Due Diligence measures. These circumstances
include: Classification of a customer as high-risk Identification as
a Politically Exposed Person (PEP) Unusual or high-value
transactional activity Unclear or insufficient source of funds or
wealth Elevated geographical or jurisdictional risk indicators EDD
measures may include: Requesting additional documentation
Independent verification of provided information Source of funds and
wealth validation Senior Management approval prior to continuation
of the relationship 3. Source of Funds and Financial Assessment The
Company may require customers to provide supporting evidence
demonstrating the legitimacy of funds used on the platform.
Acceptable documentation may include: Bank account statements
Employment confirmation or payslips Corporate ownership or business
records (where relevant) Asset sale agreements or similar financial
records Pending satisfactory review, the Company may temporarily
limit deposits, withdrawals, or account activity. 4. Transaction
Monitoring and Suspicious Behaviour Detection The Company operates
both automated systems and manual oversight processes to monitor
customer activity. Monitoring is designed to detect: Unusual or
inconsistent deposit and withdrawal behaviour Rapid movement of
funds in and out of accounts Structuring or layering patterns
Betting or gaming behaviour inconsistent with expected profile All
alerts are reviewed by qualified compliance personnel. Where
concerns arise, the Company may: Request further information or
documentation Restrict or suspend account activity Escalate the
matter internally for review Submit a Suspicious Activity Report
(SAR) where required 5. Sanctions Screening and PEP Checks All
customers are screened against relevant international and national
databases, including: EU consolidated sanctions lists United Nations
sanctions lists Applicable national sanctions registers Politically
Exposed Person (PEP) databases Screening is performed at onboarding
and repeated periodically throughout the business relationship. 6.
Regulatory Reporting Obligations Where the Company knows, suspects,
or has reasonable grounds to suspect money laundering or terrorist
financing activity, it is required to submit a Suspicious Activity
Report (SAR) to the Financial Intelligence Analysis Unit (FIAU) in
accordance with Maltese law. The Company strictly prohibits any form
of tipping-off to customers or third parties. The Company fully
cooperates with: The FIAU The Malta Gaming Authority (MGA) Law
enforcement authorities 7. Record Keeping and Retention In
compliance with applicable AML/CTF regulations, the Company retains
records including: Customer identification and verification data
Transaction and account activity records Risk assessments and
monitoring outputs Suspicious Activity Reports and related
documentation All records are retained for a minimum period of five
(5) years following the end of the business relationship or last
transaction, whichever is later. 8. Risk-Based Assessment and
Ongoing Monitoring The Company applies a risk-based approach to both
onboarding and ongoing customer monitoring. Customers are assessed
and classified according to factors such as: Geographic exposure
Transaction size, frequency, and behaviour Account usage patterns
Other behavioural or risk indicators High-risk customers are subject
to Enhanced Due Diligence and more frequent monitoring. The Company
prepares periodic compliance and risk reports, which may be
submitted to the MGA in accordance with licensing requirements. 9.
Customer Obligations Customers are required to: Provide accurate,
complete, and truthful information during registration Maintain
up-to-date account and identity information Provide additional
documentation upon request for AML/KYC purposes Failure to comply
with verification or AML/KYC requirements may result in: Suspension
of account access Restriction of deposits or withdrawals Closure of
the account All actions are taken in accordance with applicable
regulatory obligations. 10. Internal Governance, Controls, and
Training The Company maintains a structured AML governance framework
including: Appointment of a Money Laundering Reporting Officer
(MLRO) Documented internal AML/CTF procedures Defined escalation and
decision-making protocols Regular employee training programmes The
effectiveness of the AML control framework is reviewed on a periodic
basis. 11. Data Protection and Information Security All personal and
financial information collected under this Policy is processed in
accordance with applicable data protection laws, including GDPR and
relevant regulatory standards. The Company ensures: Secure storage
of personal data Restricted access to authorised personnel only
Controlled sharing with regulatory and legal authorities where
required Protection of confidentiality, integrity, and availability
of data AML and KYC records are retained for at least five (5) years
after the end of the business relationship, in accordance with
regulatory requirements. 12. Withdrawal Conditions and Identity
Verification Threshold The Company applies conditions to withdrawals
as part of its AML and fraud prevention framework. Withdrawals may
be subject to identity verification requirements, including where a
customer’s cumulative deposits exceed €2,000. This threshold may be
calculated using either: a daily cumulative basis, taking into
account all deposits made by the customer from the commencement of
the business relationship; or a rolling period of one hundred and
eighty (180) days, aggregating deposits within that timeframe Where
this threshold is reached, the Company may require enhanced identity
verification prior to processing withdrawal requests. Failure to
complete required verification may result in delays or restrictions
on withdrawal processing. 13. Policy Updates This Policy may be
amended from time to time to reflect changes in legal, regulatory,
or operational requirements. The most current version will always be
made available through the Company’s official website or customer
information channels.