Version 2.0
Effective date: September 1, 2026
Card issuance, payment processing, security, settlement and other regulated financial or payment services are provided by independent, licensed or otherwise duly authorized third-party partners on their own terms, conditions, and regulatory requirements and acceptance criteria.
This Policy describes the financial-crime risk-management framework applied in connection with the CardsPro technology platform, including customer and business due diligence, sanctions controls, transaction monitoring, fraud prevention, risk assessment, escalation, recordkeeping and the operational flow of card-related services.
The framework supports safe use of CardsPro, fulfilment of contractual duties toward independent Partners and compliance with laws that apply to the System Owner’s own activities. It also assists Partners with information and controls required for their regulated card and payment services.
This Policy does not represent that Kaizo FZE LLC, is a bank, card issuer, payment institution, electronic-money institution, money-services business or another regulated financial institution. Statutory obligations that apply specifically to an issuer, payment institution or other regulated Partner remain the responsibility of that Partner unless law and an executed agreement expressly provide otherwise.
Detailed thresholds, scenarios, internal procedures, investigation records and reporting routes may be maintained in confidential manuals. This public or Partner-facing Policy does not disclose controls where disclosure could facilitate evasion, prejudice an investigation or breach law or Partner confidentiality.
This Policy applies to prospective and current Clients, beneficial owners, controlling persons, directors, representatives, Authorised Users, End Users, cardholders, API and white-label activity, transactions, funding routes, merchants and other persons or activity connected with CardsPro.
It applies throughout onboarding, activation, use, periodic review, investigation, suspension, termination and any post-termination period required for settlement, chargebacks, claims or recordkeeping.
Clients must maintain their own controls appropriate to their business and legal status. Reliance on CardsPro controls does not relieve a Client from laws or Partner requirements that apply directly to it.
The System Owner provides technology infrastructure, onboarding orchestration, dashboards, API connectivity, support, risk tools and operational controls.
Independent licensed or otherwise authorised Partners may perform regulated functions, including:
The System Owner may collect, verify, screen and monitor information on its own behalf and on behalf of or in support of a Partner. The exact role is determined by applicable law, product configuration and the relevant agreements.
Approval by CardsPro does not bind a Partner. A Partner may independently request further information, reject or restrict an applicant, decline a transaction or terminate its service.
The System Owner applies a risk-based approach informed by:
References to international standards do not mean that every rule of every jurisdiction applies directly to the System Owner. A requirement is implemented according to its actual legal, contractual or risk-management basis.
Controls are proportionate to the nature, size, complexity, geography, delivery channel, transaction profile and risk of the relevant relationship.
Senior management is responsible for approving the financial-crime risk framework, risk appetite, prohibited activity, escalation authority, resources and material remediation.
The System Owner shall designate a qualified compliance owner responsible for coordinating KYC/KYB, sanctions, PEP screening, transaction monitoring, investigation, Partner escalation, training, recordkeeping and periodic review. Where law requires a formally appointed MLRO or equivalent officer for a specific activity, the required appointment and reporting line shall be documented separately.
Business, support, engineering, security, finance and compliance personnel must follow approved procedures and promptly escalate relevant concerns. Commercial objectives must not override a mandatory legal, sanctions, fraud or Partner control.
Material decisions, including acceptance of high-risk relationships, sanctions determinations, serious fraud cases, significant restrictions and termination for financial-crime risk, shall be documented and approved at the appropriate level.
The System Owner shall periodically assess inherent and residual risk across:
New products, Partners, jurisdictions or material changes must undergo risk review before launch. Identified risk must be accepted within risk appetite, mitigated through controls or avoided.
CardsPro is available only for approved lawful business use by adults. Anonymous, fictitious or materially opaque relationships are not accepted.
Before activation, the System Owner may assess whether:
The System Owner may reject a relationship without completing onboarding. It need not disclose internal risk scoring or a reason where disclosure is restricted, could enable control circumvention or is inconsistent with Partner requirements.
Required KYB information may include:
Required KYC information may include full name, date of birth, nationality, residence, contact details, identity document, address evidence, photograph, selfie, liveness result, tax information and other information reasonably necessary for verification.
The System Owner may request certified, translated, notarised or apostilled documents where risk or Partner rules justify it.
The Client must disclose natural persons who ultimately own or control it according to applicable thresholds and Partner requirements, as well as any person exercising control through voting rights, contractual arrangements, nominee relationships or other means.
Where no natural person is identified under an ownership threshold, the System Owner may identify a senior managing official or another person required by the applicable framework, without treating that person as an owner where they are not one.
Layered, nominee, trust, foundation or other complex structures require a clear structure chart, legal rationale and supporting evidence. Unexplained complexity, inconsistent registers or inability to identify control may result in enhanced due diligence, refusal or termination.
The Client shall notify the System Owner promptly of any ownership or control change and provide updated documentation before continued use where requested.
Documents and data must be valid, legible, complete, current and consistent. Verification may use documentary, electronic, database, biometric and Partner-provided methods.
The System Owner may compare information against public registers, trusted databases, device information, domain records, business documents and Partner data. A successful automated check does not prevent manual review.
Identity photographs or liveness information may be processed by specialised verification providers. Where such processing constitutes biometric or special-category processing, an applicable legal condition and appropriate safeguards must be used.
Suspected forgery, tampering, impersonation, stolen identity or unexplained inconsistency shall be escalated. The System Owner may request a video call, additional document, source evidence or another verification step.
Relationships may be classified as low, standard, high or prohibited risk using documented factors and professional judgment.
Low or standard risk may receive proportionate standard due diligence and monitoring. High risk requires enhanced due diligence, additional approval, tighter limits, more frequent review or other mitigation. Prohibited risk must be rejected, suspended or terminated.
Risk scoring may consider geography, ownership, PEP status, adverse media, product, delivery channel, funding, expected transaction profile, merchant categories, regulatory status, data quality, fraud indicators and Partner assessment.
A risk rating may change at any time based on new information, transaction behaviour, sanctions developments, Partner notices or control findings.
Enhanced due diligence (“EDD”) may be required for high-risk jurisdictions, PEP involvement, adverse media, complex ownership, unusually high volumes, crypto exposure, third-party funding, regulated or sensitive industries, high decline or refund rates, sanctions nexus, unexplained activity or Partner escalation.
EDD measures may include:
EDD does not guarantee acceptance. A relationship may be refused where risk cannot be sufficiently understood or mitigated.
Relevant individuals may be screened to determine whether they are a politically exposed person (“PEP”), family member or known close associate under the applicable framework.
PEP status does not automatically establish wrongdoing. It may require senior approval, source-of-wealth and source-of-funds review, enhanced monitoring and periodic reassessment.
Adverse-media screening may identify credible information concerning financial crime, corruption, fraud, sanctions, organised crime, regulatory enforcement or other material integrity concerns. Sources must be assessed for reliability, recency, relevance, corroboration and identity match.
Unverified or irrelevant allegations should not be treated as confirmed facts, but material unresolved risk may justify further review or refusal.
Screening may cover Clients, beneficial owners, controlling persons, directors, Authorised Users, End Users, counterparties, merchants, transactions, vessels, wallets, banks and jurisdictions where relevant.
Lists and measures may include United Nations sanctions, sanctions applicable in the China, relevant UK measures extended to the Territory, and EU, OFAC or other lists where legally applicable or required by a Partner or card network.
Potential matches are reviewed for identifiers, ownership, control, geography and context. False positives should be documented and resolved. A confirmed or unresolved material match may result in refusal, blocking, suspension, preservation of records, Partner escalation or reporting.
The Client must not use CardsPro to evade sanctions through intermediaries, nominees, altered payment routes, indirect ownership, false descriptions or another circumvention method.
Sanctions change frequently. Screening and geographic restrictions may be updated without prior notice where necessary.
Due diligence continues after onboarding. The System Owner may periodically refresh information according to risk and Partner requirements.
Trigger events include:
The Client shall cooperate with a refresh request within the stated deadline. Features may be restricted until the review is completed.
The System Owner and Partners may use automated scenarios, rules, thresholds, risk scores, case management and manual review to identify activity inconsistent with the expected profile or indicative of financial crime, fraud, misuse or excessive operational risk.
Monitoring may occur in real time, near real time or after the event depending on available data and the relevant risk. Controls may operate at Client, account, End User, card, device, merchant, transaction, API and aggregate portfolio levels.
Thresholds may be static or dynamic and may differ by product, geography, Partner, merchant category and risk rating. Thresholds and detection logic are confidential and do not create a right to transact up to any particular amount.
Indicators may include:
An indicator does not by itself prove wrongdoing. Alerts require proportionate review and contextual assessment.
An alert may be generated automatically or manually. The review process may include:
Outcomes may include closure with no further action, continued monitoring, profile update, EDD, limit change, transaction rejection, card block, account suspension, Partner escalation, termination or legally permitted reporting.
High-risk or complex cases must be escalated to the compliance owner or senior management according to the authority matrix.
Where activity is suspected to involve financial crime, the System Owner shall determine its own legal and contractual reporting obligations and coordinate with the relevant regulated Partner.
The System Owner may submit information to a Partner, card network, competent authority, financial-intelligence unit or law-enforcement body where required or permitted. A regulated Partner remains responsible for any statutory report that applies specifically to its regulated service, unless law provides otherwise.
Personnel and Clients must not disclose the existence or content of a suspicious-activity report, investigation, authority request or confidential monitoring action where such disclosure is prohibited or could prejudice the matter.
The System Owner may be unable to provide a detailed reason for delay, restriction, termination or disclosure.
Financial-crime controls are coordinated with fraud and cybersecurity measures. Relevant events include account takeover, phishing, credential stuffing, malware, bot activity, API abuse, identity theft, social engineering, unauthorised card use and manipulation of onboarding or rewards.
Controls may include multi-factor authentication, credential rotation, device and IP analysis, rate limits, access segregation, transaction limits, card freezing, token revocation, log review and incident response.
Clients must promptly report suspected compromise, preserve relevant evidence and follow remediation instructions. Failure to maintain reasonable security may result in restriction or liability under the Terms of Service.
CardsPro must not be used for money laundering, terrorist or proliferation financing, sanctions evasion, fraud, scams, criminal proceeds, stolen credentials, illegal marketplaces, prohibited goods or services, unlicensed regulated activity or card-network abuse.
The System Owner may maintain a more detailed prohibited and restricted activity list by country, Partner, merchant category and product. Restricted activity requires written approval, proof of legal authority and additional controls.
Attempts to conceal activity, misclassify merchants, divide transactions, use undisclosed intermediaries or otherwise circumvent controls are independently prohibited.
The System Owner may use specialist providers for identity verification, sanctions and PEP screening, adverse media, fraud detection, transaction monitoring, hosting and case management.
Before reliance, the System Owner should assess the provider’s competence, security, data protection, geographic coverage, service resilience, audit rights and contractual obligations. Performance should be monitored and material deficiencies remediated.
Use of a provider does not transfer responsibility for the System Owner’s own decisions. Likewise, assistance provided by the System Owner does not transfer a regulated Partner’s statutory responsibilities to Kaizo FZE LLC,
Where Partner data is delayed, incomplete or corrected, the System Owner may adjust dashboard records, risk decisions, fees, reserves or transaction statuses accordingly.
The CardsPro service flow is designed as follows:
This allocation must be reflected consistently in Client agreements, Partner contracts, accounting treatment, privacy documentation, dashboards and marketing materials.
The System Owner or a Partner may apply transaction limits, prefunding, security deposits or reserves based on expected exposure, settlement timing, chargebacks, refunds, fines, Partner requirements and Client risk.
Reserves are not deposits, savings products or interest-bearing accounts unless a separate lawful agreement expressly states otherwise. They may be retained for as long as unresolved exposure reasonably continues and used against matured obligations to the extent permitted.
Negative balances and shortfalls are payable immediately on demand. A pending review or dispute does not suspend undisputed payment obligations.
Records may include applications, KYC/KYB documents, verification results, ownership information, risk assessments, screening results, transaction data, alerts, investigation notes, supporting evidence, decisions, approvals, Partner communications, reports, restrictions, training and audit findings.
Records must be accurate, access-controlled, searchable and protected against unauthorised alteration or deletion. Material actions should identify the decision-maker, date, evidence and rationale.
Retention is determined by applicable law, Partner obligations, card-network rules, tax and accounting requirements, limitation periods, investigation needs and the CardsPro Privacy Policy. Records may be retained after account closure where required or permitted.
Personal data processed for KYC, sanctions, monitoring and fraud prevention is handled according to the CardsPro Privacy Policy, applicable Data Processing Agreements and relevant Partner privacy notices.
Access is limited to persons with a legitimate need. Sensitive information should be protected through appropriate encryption, authentication, logging, segregation, vendor controls and incident-response measures.
Information must not be disclosed where disclosure would violate law, reveal a confidential monitoring rule, prejudice an investigation or constitute prohibited tipping off.
Relevant personnel shall receive role-appropriate initial and periodic training on financial-crime risk, sanctions, PEPs, fraud typologies, red flags, prohibited activity, escalation, confidentiality, data protection, recordkeeping and Partner requirements.
Training completion and effectiveness should be documented. Material changes in products, laws, sanctions or typologies should be communicated promptly rather than waiting for the next scheduled session.
The System Owner should periodically test onboarding quality, screening performance, alert disposition, escalation, access controls, recordkeeping, data quality and Partner reporting.
Independent review may be performed by internal personnel independent from the tested function, qualified external advisers or auditors, taking account of scale and risk. Findings must be prioritised, assigned, remediated and reported to appropriate management.
Model, rule and vendor performance should be reviewed for false positives, false negatives, coverage gaps, data drift and inappropriate bias where relevant.
Material control failures, missed screening, data-quality issues, Partner breaches, suspicious-activity handling errors and unauthorised disclosures must be escalated promptly.
The response should include containment, impact assessment, preservation of evidence, corrective action, Partner or authority notification where required, root-cause analysis and verification that remediation is effective.
Repeated or systemic issues may require product restriction, revised risk appetite, additional resources or suspension of the affected service.
This Policy shall be reviewed at least annually and after a material change in law, Partner, product, geography, funding method, card network, monitoring methodology, risk appetite or business model.
Changes must be approved at the appropriate management level and communicated to affected personnel, Clients or Partners where required. Historical versions and approval records should be retained.
System Owner: Kaizo FZE LLC, License Number: 2629318676888
Registered office: UAE, BC-892957, Amber Gem Tower, Ajman.
Compliance, sanctions, AML/KYC and general contact: contacts.
Confidential reports by Partners, regulators or law-enforcement bodies should also use any dedicated secure channel established in the relevant agreement. The identity and direct contact details of the appointed compliance owner or statutory MLRO, if required, are maintained in the System Owner’s internal governance records and provided to competent recipients where appropriate.