AML/KYC Policy

    Version 2.0

    Effective date: September 1, 2026

    Card issuance, payment processing, security, settlement and other regulated financial or payment services are provided by independent, licensed or otherwise duly authorized third-party partners on their own terms, conditions, and regulatory requirements and acceptance criteria.

    1. Purpose and status of this Policy

    This Policy describes the financial-crime risk-management framework applied in connection with the CardsPro technology platform, including customer and business due diligence, sanctions controls, transaction monitoring, fraud prevention, risk assessment, escalation, recordkeeping and the operational flow of card-related services.

    The framework supports safe use of CardsPro, fulfilment of contractual duties toward independent Partners and compliance with laws that apply to the System Owner’s own activities. It also assists Partners with information and controls required for their regulated card and payment services.

    This Policy does not represent that Kaizo FZE LLC, is a bank, card issuer, payment institution, electronic-money institution, money-services business or another regulated financial institution. Statutory obligations that apply specifically to an issuer, payment institution or other regulated Partner remain the responsibility of that Partner unless law and an executed agreement expressly provide otherwise.

    Detailed thresholds, scenarios, internal procedures, investigation records and reporting routes may be maintained in confidential manuals. This public or Partner-facing Policy does not disclose controls where disclosure could facilitate evasion, prejudice an investigation or breach law or Partner confidentiality.

    2. Scope

    This Policy applies to prospective and current Clients, beneficial owners, controlling persons, directors, representatives, Authorised Users, End Users, cardholders, API and white-label activity, transactions, funding routes, merchants and other persons or activity connected with CardsPro.

    It applies throughout onboarding, activation, use, periodic review, investigation, suspension, termination and any post-termination period required for settlement, chargebacks, claims or recordkeeping.

    Clients must maintain their own controls appropriate to their business and legal status. Reliance on CardsPro controls does not relieve a Client from laws or Partner requirements that apply directly to it.

    3. Role allocation and regulated Partners

    The System Owner provides technology infrastructure, onboarding orchestration, dashboards, API connectivity, support, risk tools and operational controls.

    Independent licensed or otherwise authorised Partners may perform regulated functions, including:

    • customer account or wallet provision;
    • card issuance and cardholder contracting;
    • acceptance or safeguarding of funds;
    • payment execution, authorisation, clearing and settlement;
    • transaction dispute and chargeback processing;
    • statutory customer due diligence and ongoing monitoring; and
    • suspicious-activity reporting, freezing or disclosure required of the regulated Partner.

    The System Owner may collect, verify, screen and monitor information on its own behalf and on behalf of or in support of a Partner. The exact role is determined by applicable law, product configuration and the relevant agreements.

    Approval by CardsPro does not bind a Partner. A Partner may independently request further information, reject or restrict an applicant, decline a transaction or terminate its service.

    4. Applicable framework and risk-based approach

    The System Owner applies a risk-based approach informed by:

    • laws and sanctions measure applicable to Kaizo FZE LLC in China, License Number: 2629318676888;
    • contractual obligations and lawful instructions of Partners;
    • card-network and payment-scheme rules;
    • applicable requirements in countries where Services are offered;
    • relevant FATF Recommendations and risk-based guidance; and
    • fraud, cybersecurity and financial-crime typologies relevant to the platform.

    References to international standards do not mean that every rule of every jurisdiction applies directly to the System Owner. A requirement is implemented according to its actual legal, contractual or risk-management basis.

    Controls are proportionate to the nature, size, complexity, geography, delivery channel, transaction profile and risk of the relevant relationship.

    5. Governance and responsibility

    Senior management is responsible for approving the financial-crime risk framework, risk appetite, prohibited activity, escalation authority, resources and material remediation.

    The System Owner shall designate a qualified compliance owner responsible for coordinating KYC/KYB, sanctions, PEP screening, transaction monitoring, investigation, Partner escalation, training, recordkeeping and periodic review. Where law requires a formally appointed MLRO or equivalent officer for a specific activity, the required appointment and reporting line shall be documented separately.

    Business, support, engineering, security, finance and compliance personnel must follow approved procedures and promptly escalate relevant concerns. Commercial objectives must not override a mandatory legal, sanctions, fraud or Partner control.

    Material decisions, including acceptance of high-risk relationships, sanctions determinations, serious fraud cases, significant restrictions and termination for financial-crime risk, shall be documented and approved at the appropriate level.

    6. Enterprise and product risk assessment

    The System Owner shall periodically assess inherent and residual risk across:

    • Clients and ownership: legal form, transparency, beneficial ownership, PEP exposure, reputation and regulatory status;
    • Products: virtual or physical cards, bulk issuance, API distribution, white-label services, multi-currency use and transaction limits;
    • Geography: incorporation, residence, operations, customer base, IP indicators, merchants, funding source and destination;
    • Delivery channels: remote onboarding, API automation, introducers, agents, sub-distributors and non-face-to-face interaction;
    • Transactions: value, frequency, velocity, merchant category, refunds, chargebacks, cross-border activity and expected behaviour;
    • Funding: source, ownership, method, third-party involvement, crypto exposure, speed and circularity;
    • Partners and vendors: licensing, control environment, service location, data quality, resilience and contractual allocation; and
    • Technology: account takeover, credential misuse, bots, automation, device risk and API abuse.

    New products, Partners, jurisdictions or material changes must undergo risk review before launch. Identified risk must be accepted within risk appetite, mitigated through controls or avoided.

    7. Customer acceptance principles

    CardsPro is available only for approved lawful business use by adults. Anonymous, fictitious or materially opaque relationships are not accepted.

    Before activation, the System Owner may assess whether:

    • the Client and relevant persons can be reliably identified and verified;
    • beneficial ownership and control are sufficiently transparent;
    • the business model and intended use are lawful and commercially coherent;
    • required licences or registrations are valid;
    • expected volume, geography, merchants and funding are understood;
    • the relationship is within System Owner and Partner risk appetite; and
    • required Partner approval has been obtained.

    The System Owner may reject a relationship without completing onboarding. It need not disclose internal risk scoring or a reason where disclosure is restricted, could enable control circumvention or is inconsistent with Partner requirements.

    8. Business and individual due diligence

    Required KYB information may include:

    • legal name, registration number, legal form, registered office and operating address;
    • constitutional documents, register extracts and certificates of good standing where relevant;
    • directors, officers, authorised representatives and proof of authority;
    • ownership and control structure, including intermediate entities;
    • ultimate beneficial owners and persons exercising control by other means;
    • tax residence and taxpayer information where required;
    • business activity, websites, licences, counterparties and target markets;
    • expected cards, users, volumes, currencies, merchant categories and jurisdictions; and
    • source of funds, source of wealth and supporting commercial evidence where required.

    Required KYC information may include full name, date of birth, nationality, residence, contact details, identity document, address evidence, photograph, selfie, liveness result, tax information and other information reasonably necessary for verification.

    The System Owner may request certified, translated, notarised or apostilled documents where risk or Partner rules justify it.

    9. Beneficial ownership and control

    The Client must disclose natural persons who ultimately own or control it according to applicable thresholds and Partner requirements, as well as any person exercising control through voting rights, contractual arrangements, nominee relationships or other means.

    Where no natural person is identified under an ownership threshold, the System Owner may identify a senior managing official or another person required by the applicable framework, without treating that person as an owner where they are not one.

    Layered, nominee, trust, foundation or other complex structures require a clear structure chart, legal rationale and supporting evidence. Unexplained complexity, inconsistent registers or inability to identify control may result in enhanced due diligence, refusal or termination.

    The Client shall notify the System Owner promptly of any ownership or control change and provide updated documentation before continued use where requested.

    10. Verification standards

    Documents and data must be valid, legible, complete, current and consistent. Verification may use documentary, electronic, database, biometric and Partner-provided methods.

    The System Owner may compare information against public registers, trusted databases, device information, domain records, business documents and Partner data. A successful automated check does not prevent manual review.

    Identity photographs or liveness information may be processed by specialised verification providers. Where such processing constitutes biometric or special-category processing, an applicable legal condition and appropriate safeguards must be used.

    Suspected forgery, tampering, impersonation, stolen identity or unexplained inconsistency shall be escalated. The System Owner may request a video call, additional document, source evidence or another verification step.

    11. Risk classification

    Relationships may be classified as low, standard, high or prohibited risk using documented factors and professional judgment.

    Low or standard risk may receive proportionate standard due diligence and monitoring. High risk requires enhanced due diligence, additional approval, tighter limits, more frequent review or other mitigation. Prohibited risk must be rejected, suspended or terminated.

    Risk scoring may consider geography, ownership, PEP status, adverse media, product, delivery channel, funding, expected transaction profile, merchant categories, regulatory status, data quality, fraud indicators and Partner assessment.

    A risk rating may change at any time based on new information, transaction behaviour, sanctions developments, Partner notices or control findings.

    12. Enhanced due diligence

    Enhanced due diligence (“EDD”) may be required for high-risk jurisdictions, PEP involvement, adverse media, complex ownership, unusually high volumes, crypto exposure, third-party funding, regulated or sensitive industries, high decline or refund rates, sanctions nexus, unexplained activity or Partner escalation.

    EDD measures may include:

    • additional independent identity and corporate verification;
    • senior-management approval;
    • detailed source-of-funds and source-of-wealth evidence;
    • contracts, invoices, bank statements and proof of economic purpose;
    • licence and regulatory-status verification;
    • review of key customers, suppliers, merchants or counterparties;
    • reduced limits, reserves, prefunding or restricted functionality;
    • more frequent review and enhanced transaction monitoring; and
    • confirmation or approval from the relevant Partner.

    EDD does not guarantee acceptance. A relationship may be refused where risk cannot be sufficiently understood or mitigated.

    13. Politically exposed persons and adverse media

    Relevant individuals may be screened to determine whether they are a politically exposed person (“PEP”), family member or known close associate under the applicable framework.

    PEP status does not automatically establish wrongdoing. It may require senior approval, source-of-wealth and source-of-funds review, enhanced monitoring and periodic reassessment.

    Adverse-media screening may identify credible information concerning financial crime, corruption, fraud, sanctions, organised crime, regulatory enforcement or other material integrity concerns. Sources must be assessed for reliability, recency, relevance, corroboration and identity match.

    Unverified or irrelevant allegations should not be treated as confirmed facts, but material unresolved risk may justify further review or refusal.

    14. Sanctions and restricted-party controls

    Screening may cover Clients, beneficial owners, controlling persons, directors, Authorised Users, End Users, counterparties, merchants, transactions, vessels, wallets, banks and jurisdictions where relevant.

    Lists and measures may include United Nations sanctions, sanctions applicable in the China, relevant UK measures extended to the Territory, and EU, OFAC or other lists where legally applicable or required by a Partner or card network.

    Potential matches are reviewed for identifiers, ownership, control, geography and context. False positives should be documented and resolved. A confirmed or unresolved material match may result in refusal, blocking, suspension, preservation of records, Partner escalation or reporting.

    The Client must not use CardsPro to evade sanctions through intermediaries, nominees, altered payment routes, indirect ownership, false descriptions or another circumvention method.

    Sanctions change frequently. Screening and geographic restrictions may be updated without prior notice where necessary.

    15. Ongoing due diligence and trigger events

    Due diligence continues after onboarding. The System Owner may periodically refresh information according to risk and Partner requirements.

    Trigger events include:

    • change in ownership, control, directors or authorised representatives;
    • change in business model, licence, website, geography or customer base;
    • material change in volume, funding method, merchants or transaction pattern;
    • expired, inconsistent or unreliable documentation;
    • new PEP, sanctions or adverse-media information;
    • fraud, chargeback, security or compliance alert;
    • Partner, card-network, regulator or law-enforcement request; and
    • reactivation after inactivity or prior restriction.

    The Client shall cooperate with a refresh request within the stated deadline. Features may be restricted until the review is completed.

    16. Transaction monitoring framework

    The System Owner and Partners may use automated scenarios, rules, thresholds, risk scores, case management and manual review to identify activity inconsistent with the expected profile or indicative of financial crime, fraud, misuse or excessive operational risk.

    Monitoring may occur in real time, near real time or after the event depending on available data and the relevant risk. Controls may operate at Client, account, End User, card, device, merchant, transaction, API and aggregate portfolio levels.

    Thresholds may be static or dynamic and may differ by product, geography, Partner, merchant category and risk rating. Thresholds and detection logic are confidential and do not create a right to transact up to any particular amount.

    17. Non-exhaustive monitoring indicators

    Indicators may include:

    • transactions materially above expected value or volume;
    • rapid funding and spending, pass-through or circular movement;
    • unexplained third-party funding or mismatch between payer and Client;
    • unusual geographic, IP, device, currency or time patterns;
    • repeated failed authorisations, card testing or blocked-card reuse;
    • excessive declines, refunds, reversals, disputes or chargebacks;
    • duplicated, split, patterned or round-amount transactions;
    • prohibited or high-risk merchant categories and unusual merchant concentration;
    • activity inconsistent with the declared business model or user role;
    • multiple linked accounts, shared credentials or suspicious API automation;
    • trial abuse, advertising-account manipulation, fake traffic or mass activations;
    • sanctions, PEP, adverse-media or high-risk jurisdiction connections;
    • unsupported top-ups, indirect routes or crypto-related source concerns; and
    • manual reports from support, Partners, merchants, authorities or users.

    An indicator does not by itself prove wrongdoing. Alerts require proportionate review and contextual assessment.

    18. Alert review and case management

    An alert may be generated automatically or manually. The review process may include:

    • confirming data quality and whether the alert is a false positive;
    • reviewing identity, ownership, risk rating and expected activity;
    • analysing transaction history, devices, merchants and linked accounts;
    • requesting an explanation and supporting evidence;
    • consulting the relevant Partner or card network;
    • applying interim limits or restrictions where necessary; and
    • documenting findings, decision, approval and follow-up action.

    Outcomes may include closure with no further action, continued monitoring, profile update, EDD, limit change, transaction rejection, card block, account suspension, Partner escalation, termination or legally permitted reporting.

    High-risk or complex cases must be escalated to the compliance owner or senior management according to the authority matrix.

    19. Suspicious activity, reporting and tipping-off

    Where activity is suspected to involve financial crime, the System Owner shall determine its own legal and contractual reporting obligations and coordinate with the relevant regulated Partner.

    The System Owner may submit information to a Partner, card network, competent authority, financial-intelligence unit or law-enforcement body where required or permitted. A regulated Partner remains responsible for any statutory report that applies specifically to its regulated service, unless law provides otherwise.

    Personnel and Clients must not disclose the existence or content of a suspicious-activity report, investigation, authority request or confidential monitoring action where such disclosure is prohibited or could prejudice the matter.

    The System Owner may be unable to provide a detailed reason for delay, restriction, termination or disclosure.

    20. Fraud and cybersecurity controls

    Financial-crime controls are coordinated with fraud and cybersecurity measures. Relevant events include account takeover, phishing, credential stuffing, malware, bot activity, API abuse, identity theft, social engineering, unauthorised card use and manipulation of onboarding or rewards.

    Controls may include multi-factor authentication, credential rotation, device and IP analysis, rate limits, access segregation, transaction limits, card freezing, token revocation, log review and incident response.

    Clients must promptly report suspected compromise, preserve relevant evidence and follow remediation instructions. Failure to maintain reasonable security may result in restriction or liability under the Terms of Service.

    21. Prohibited and restricted activity

    CardsPro must not be used for money laundering, terrorist or proliferation financing, sanctions evasion, fraud, scams, criminal proceeds, stolen credentials, illegal marketplaces, prohibited goods or services, unlicensed regulated activity or card-network abuse.

    The System Owner may maintain a more detailed prohibited and restricted activity list by country, Partner, merchant category and product. Restricted activity requires written approval, proof of legal authority and additional controls.

    Attempts to conceal activity, misclassify merchants, divide transactions, use undisclosed intermediaries or otherwise circumvent controls are independently prohibited.

    22. Partner reliance and vendor oversight

    The System Owner may use specialist providers for identity verification, sanctions and PEP screening, adverse media, fraud detection, transaction monitoring, hosting and case management.

    Before reliance, the System Owner should assess the provider’s competence, security, data protection, geographic coverage, service resilience, audit rights and contractual obligations. Performance should be monitored and material deficiencies remediated.

    Use of a provider does not transfer responsibility for the System Owner’s own decisions. Likewise, assistance provided by the System Owner does not transfer a regulated Partner’s statutory responsibilities to Kaizo FZE LLC,

    Where Partner data is delayed, incomplete or corrected, the System Owner may adjust dashboard records, risk decisions, fees, reserves or transaction statuses accordingly.

    23. Financial and operational logic

    The CardsPro service flow is designed as follows:

    • Application: the Client requests access and provides business, ownership, representative, user and expected-activity information.
    • Due diligence: the System Owner and relevant Partners perform applicable KYB, KYC, beneficial-ownership, sanctions, PEP, adverse-media and risk checks.
    • Approval and configuration: approved Clients receive dashboard, API or white-label configuration, supported cards, BINs, currencies, limits, permissions and controls based on Partner approval and risk rating.
    • Funding: funds are sent only through approved routes to the relevant financial infrastructure. Unless expressly agreed and lawfully authorized, Kaizo FZE LLC does not accept or safeguard funds on its own balance sheet.
    • Card request: CardsPro technology transmits a card request and associated data to the relevant issuing or programme Partner. The Partner performs the regulated issuance function and may approve or reject the request.
    • Authorisation: a merchant request passes through acquiring, card-network, processing and issuing infrastructure. The issuer or relevant Partner determines approval under its rules and available funds.
    • Clearing and settlement: final amounts, exchange rates, reversals, refunds, chargebacks and settlement are processed through Partner and card-network systems.
    • Dashboard and API records: CardsPro receives or calculates operational records and displays them to the Client. Displayed data may be corrected to match final Partner or settlement records.
    • Fees and revenue: the System Owner may charge agreed technology, onboarding, support, issuance, transaction or other fees and may receive Partner commissions or revenue share. Kaizo FZE LLC does not earn interest in safeguarded Client funds unless an applicable lawful arrangement expressly states otherwise.
    • Risk controls: limits, reserves, prefunding, transaction review, card blocks or service restrictions may be applied to manage expected exposure.
    • Refunds and disputes: merchants and Partners process refunds, reversals and chargebacks under applicable network rules, while CardsPro may provide operational support and display status data.
    • Exit: upon suspension or termination, access may be revoked, cards closed by the Partner and records or reserves retained for unresolved exposure and legal retention.

    This allocation must be reflected consistently in Client agreements, Partner contracts, accounting treatment, privacy documentation, dashboards and marketing materials.

    24. Limits, reserves and financial-risk controls

    The System Owner or a Partner may apply transaction limits, prefunding, security deposits or reserves based on expected exposure, settlement timing, chargebacks, refunds, fines, Partner requirements and Client risk.

    Reserves are not deposits, savings products or interest-bearing accounts unless a separate lawful agreement expressly states otherwise. They may be retained for as long as unresolved exposure reasonably continues and used against matured obligations to the extent permitted.

    Negative balances and shortfalls are payable immediately on demand. A pending review or dispute does not suspend undisputed payment obligations.

    25. Recordkeeping and audit trail

    Records may include applications, KYC/KYB documents, verification results, ownership information, risk assessments, screening results, transaction data, alerts, investigation notes, supporting evidence, decisions, approvals, Partner communications, reports, restrictions, training and audit findings.

    Records must be accurate, access-controlled, searchable and protected against unauthorised alteration or deletion. Material actions should identify the decision-maker, date, evidence and rationale.

    Retention is determined by applicable law, Partner obligations, card-network rules, tax and accounting requirements, limitation periods, investigation needs and the CardsPro Privacy Policy. Records may be retained after account closure where required or permitted.

    26. Data protection and confidentiality

    Personal data processed for KYC, sanctions, monitoring and fraud prevention is handled according to the CardsPro Privacy Policy, applicable Data Processing Agreements and relevant Partner privacy notices.

    Access is limited to persons with a legitimate need. Sensitive information should be protected through appropriate encryption, authentication, logging, segregation, vendor controls and incident-response measures.

    Information must not be disclosed where disclosure would violate law, reveal a confidential monitoring rule, prejudice an investigation or constitute prohibited tipping off.

    27. Training and awareness

    Relevant personnel shall receive role-appropriate initial and periodic training on financial-crime risk, sanctions, PEPs, fraud typologies, red flags, prohibited activity, escalation, confidentiality, data protection, recordkeeping and Partner requirements.

    Training completion and effectiveness should be documented. Material changes in products, laws, sanctions or typologies should be communicated promptly rather than waiting for the next scheduled session.

    28. Testing, quality assurance and independent review

    The System Owner should periodically test onboarding quality, screening performance, alert disposition, escalation, access controls, recordkeeping, data quality and Partner reporting.

    Independent review may be performed by internal personnel independent from the tested function, qualified external advisers or auditors, taking account of scale and risk. Findings must be prioritised, assigned, remediated and reported to appropriate management.

    Model, rule and vendor performance should be reviewed for false positives, false negatives, coverage gaps, data drift and inappropriate bias where relevant.

    29. Incidents, breaches and remediation

    Material control failures, missed screening, data-quality issues, Partner breaches, suspicious-activity handling errors and unauthorised disclosures must be escalated promptly.

    The response should include containment, impact assessment, preservation of evidence, corrective action, Partner or authority notification where required, root-cause analysis and verification that remediation is effective.

    Repeated or systemic issues may require product restriction, revised risk appetite, additional resources or suspension of the affected service.

    30. Review and updates

    This Policy shall be reviewed at least annually and after a material change in law, Partner, product, geography, funding method, card network, monitoring methodology, risk appetite or business model.

    Changes must be approved at the appropriate management level and communicated to affected personnel, Clients or Partners where required. Historical versions and approval records should be retained.

    31. Contact and escalation

    System Owner: Kaizo FZE LLC, License Number: 2629318676888

    Registered office: UAE, BC-892957, Amber Gem Tower, Ajman.

    Compliance, sanctions, AML/KYC and general contact: contacts.

    Confidential reports by Partners, regulators or law-enforcement bodies should also use any dedicated secure channel established in the relevant agreement. The identity and direct contact details of the appointed compliance owner or statutory MLRO, if required, are maintained in the System Owner’s internal governance records and provided to competent recipients where appropriate.