This policy is designed to ensure that Triangle Digital Ltd. (‘TRI’, the ‘Company’) follows its obligations under Bermuda’s AML/ATF laws and regulations and that it conducts its business with the highest integrity.
Triangle Digital Ltd. is a Bermuda exempted company with no branches in any other jurisdiction.
This Policy all be implemented in an effort to detect, control and mitigate the risk of TRI being used for money laundering activities.
This Policy is not intended to be a “check box” procedure to be followed but provides the minimum standards to be applied in the detection and prevention of money laundering and terrorist financing. Any failure to adhere to this Policy and the systems and controls identified in this Policy that have been put in place by TRI can result in:
A copy of this Policy will be given to each member of staff to use as a source of reference on AML /ATF matters when needed.
Each member of the Board is responsible for fostering a compliance culture throughout TRI. The Board accepts that a ‘tone from the top’ approach is instrumental in ensuring that a compliance culture is embedded. Strong ethical standards are exemplified by providing proper guidance, comprehensive policy manuals and business operational procedures, direct access to Director(s), adequate training and lessons learnt opportunities.
All Directors, employees, and contracted agents of TRI are required to review these policies within 30 days of joining TRI in any capacity, and abide by them. Updates to the manual and annual training is also required. These additional individuals create a ‘four eyes’ (or in many cases, ‘six eyes’) approach to compliance with TRI’ policies.
The reputation of Bermuda and that of TRI is critical. As a result, the employment of counsel, external advisers and key roles within TRI are taken seriously and appointments only made on an established basis of integrity, professionalism, skill and expertise.
Any requests for exemptions from this Policy must be presented to the AML Compliance Person and should be accompanied by a business case outlining the reason for the exemption PRIOR to the action being taken. Failure to seek prior approval will be a breach and can lead to disciplinary action.
Money laundering is the process of making dirty money appear to be clean. It is the process by which persons or businesses attempt to conceal the true origin and ownership of the proceeds of illegal activity such as fraud, theft, corruption, drug trafficking, tax evasion or other crimes in order to avoid detection by a government authority. The process of money laundering often goes undetected ending with the criminal being successful at placing funds through service providers and subsequently having access to what appears to be legitimate funds.
The following legislation constitutes Bermuda’s Anti Money Laundering, Anti-Terrorist Financing and Sanctions Regimes:
This Policy is designed to:
In order for criminals to have the ability to turn the proceeds of their crimes into what appears to be legitimate cash, laundering the money they gain from illegal activity needs to be successful.
There are three stages in the money laundering process.
1. Placement – The start of the money laundering process is the placement stage. This can be achieved by doing any of the following:
2. Layering – During the layering stage, complex layers of financial and other transactions are created. This makes it difficult for an investigator to follow the money. It disguises what is known as the “audit trail”. This can include;
3. Integration – The process of putting the proceeds of crime back into the economy is called integration and gives the perception that the funds are legitimate. There are a number of activities that are difficult to avoid at this stage that could help recognize integration.
These include;
If TRI is used in any part of the money laundering process TRI, and possibly the staff member(s) involved risk being prosecuted as money launderers. In order to avoid being prosecuted TRI’ and that of its staff’s only defence is to report their suspicions to the MLRO and possibly the FIA. “Red Flags” are set out at Appendix A.
There are similarities between the movement of terrorist property and the laundering of criminal property: some terrorist’s groups are known to have well established links with organized crime activity. There are two main differences between financing terrorism and laundering the proceeds of crime. These are:
Terrorist organizations can, however, require significant funding and property to resource their infrastructure. They often control property and funds from a variety of sources and employ modern techniques to manage these funds, and to move them between jurisdictions.
When combating terrorist financing, the obligations are the same as those specified for money laundering such as reporting suspicious activity, knowingly assisting in terrorist financing, tipping off and having appropriate procedures / policies in place to combat such activities.
Money laundering and terrorist financing risk are closely related to the risks of other financial crime, such as fraud. While this Policy does not deal specifically with fraud, the obligations under the Policy still apply to dealing with any proceeds of crime that arise from this activity.
TRI’s use of the KYC2020 platform means that entities’ digital identity is continuously monitored, tracking degradation in reputation and capable of alerting TRI to suspicious activity. Such alerts and tracking are to be reviewed against the Red Flags set out at Appendix A and general consideration of apparent factors that may indicate criminal activity.
TRI will review this policy on an annual basis within 30 days of the end of each calendar year, or more frequently if needed due to a change in TRI’s policy, process or due to legislative or regulatory updates. Previous versions of this policy will be kept by TRI’s AML Compliance Person.
All staff are required to confirm their agreement to comply with all policies and any applicable procedures.
The firm has designated Grant Spurling as its Money Laundering Reporting Officer (‘MLRO’) and Anti-Money Laundering Program Compliance Person (‘AML Compliance Person’), with full responsibility for the firm’s AML program. Mr. Spurling has a working knowledge of the relevant regulations and its implementing regulations. The duties of the AML Compliance Person will include monitoring the firm’s compliance with AML obligations, overseeing communication and training for employees. The AML Compliance Person will also ensure that the firm keeps and maintains all of the required AML records, and will ensure that Suspicious Activity Reports (SARs) are filed when appropriate. The AML Compliance Person is vested with full responsibility and authority to enforce the firm’s AML program.
TRI will ensure that the appropriate systems and controls are in place to ensure the degree of risk associated with each client is reflected having regard to the type of customer, business relationship, product or transaction. The level of due diligence applied must be appropriate in view of the risks of money laundering and / or terrorist financing.
The following items are some of the factors that will be considered in evaluating risk:
Overall risks may be developed based on the results of the above major categories and are classified as Standard, High and PEP.
The risk assessment process will be included as part of the New Client Process.
When a client or engagement is assessed as carrying a normal risk, standard due diligence requirements will be sufficient, however, more extensive due diligence will be necessary for higher risk clients or engagements.
If a client is identified as being a higher than standard risk (high risk) this does not automatically mean that they are a money launderer or terrorist financier. Staff must be vigilant in using their experience and common sense in applying the risk-based criteria and rules.
On an annual basis and additionally prior to TRI launching a new product, service, practice or technology, TRI will assess the risks and risk management undertaken by TRI with respect to the four risk factors of customer, geography, delivery channel and products/services. This assessment shall be documented to reflect category scores prior to and after risk management/mitigation activities, amalgamated to yield an overall TRI risk rating. Risk assessments will be stored electronically for subsequent review and comparison.
TRI’s core obligations in respect of CDD under Bermuda’s AML / ATF regime include that TRI must have identification procedures established and maintained as soon as reasonably practicable after contact is first made with a new client (or prospective client), and require the production by the client of satisfactory evidence of identify or the taking of such measures as will produce satisfactory evidence of the client’s identity. Not under any circumstances, for a new or existing customer, will TRI set up, or allow for, any anonymous accounts or assist in in the creation of a structure to unlawfully obscure the ultimate beneficial owner of any entity.
CDD must be applied when:
Where in relation to any customer, TRI is unable to apply customer due diligence measures in accordance with Bermuda’s AML/ATF Regime, and this policy, TRI will:
Customer due diligence is a primary component of risk identification and assessment and involves:
(a) identifying the customer and verifying the customer’s identity on the basis of documents, data or information obtained from a reliable and independent source;
(b) in the case of a legal entity or legal arrangement, identifying the name and verifying the identity of the relevant natural person having the position of chief executive or a person of equivalent or similar position;
(c) in the case of a legal entity, identifying and verifying the identity of a natural person (either customer, beneficial owner, person of control or ownership) by some means and, where no natural person has been identified, identifying a relevant natural person holding the position of a chief executive or a person of equivalent or similar position; and
(d) in the case of a person purporting to act on behalf of a customer, verifying that the person is in fact so authorised and identifying and verifying the identity of that person.
The Company prohibits providing services to any individual or entity that is the subject of a Sanction or restriction noted by Bermuda’s National Anti-Money Laundering Committee (NAMLC); or other international recognized body such as the United Nations (“UN”), European Union (“EU”), Her Majesty’s Treasury (“HMT”), Office of Foreign Assets Control (“OFAC”); individuals or entities that are involved in the production or distribution of Weapons of Mass Destruction; known Money Launderers or Terrorist Financiers; and Shell Banks.
TRI will apply customer due diligence measures at appropriate times to existing customers on a risk-sensitive basis. For example, TRI will, on existing clients, examine the transactions undertaken for the purposes of making an assessment regarding consistency between the transactions undertaken by the customer and our knowledge of the business and the customer’s risk profile.
Client verification is done in two stages;
TRI’s structure is such that it does not qualify for the right to conduct client verification after the issuance of a digital asset. Therefore, CLIENT VERIFICATION MUST BE CONDUCTED PRIOR TO THE ISSUANCE OF A DIGITAL ASSET TO A TRI PLATFORM USER.
The key to reducing the risk of money laundering or terrorist financing is to be completely satisfied a client’s identity has been accurately verified.
The below details the identification procedures that must be followed to verify the identity of a client or a prospective client, as defined in the previous sections of this policy.
The following is to be used when trying to verify the identity of a potential client:
For the purposes of meeting the AML / ATF requirements the identity of an individual comprises:
In those instances where there are joint applicants for business the identity of all individuals must be verified.
In order to verify the identification of the above information the following documents should be obtained:
With respect to customer identification as required by relevant legislation, and further to TRI’s own interests being protected through verification of customer identity, TRI will conduct customer identification verification through the use of KYC technology supplied by industry partners. Where individuals’ identity musty be confirmed, TRI will do so in one of two manners: “Classic” submission, whereby an individual supplies a paper copy of identification documents, which has been endorsed on its face by an attorney, notary or other professional person as a true copy of the original; and “Selfie” Three-sided image verification process, whereby an individual provides scans or photographs of identification documents, and thereafter presents themselves via video interface, showing their face and the original identification documents previously provided This service will be provided by ‘Vouched’ (www.vouched.id).
Thereafter, individuals will be subject to due diligence performed in partnership with IdentityMinds, reviewing identities against sanctions lists, red flagged jurisdictions, identified potential fraud instances, known associates and continuous monitoring of transactions, compared against risk indicators and flagging uncharacteristic activity.
The following provisions apply where the client is a company:
For the purposes of meeting the AML / ATF requirements the identity of a company comprises;
To establish verification of the above information, copies of the following documents (or their jurisdictional/structural equivalent) should be obtained:
This is the minimum information required for normal risk clients
The following provisions apply where the client is a trust.
For the purposes of meeting the AML/ATF requirements, full CDD must be completed on the following:
For the purposes of meeting the AML / ATF requirements the identity of a partnership comprises:
Should there be any doubt of an individual or entity’s identity once verification has been completed, this should be raised to the MLRO.
In cases where the documentation is provided by the client and is in a language other than English, the client should obtain a translation from a registered translator and must be apostilled. Alternatively a document may be translated by a person certifying their fluency in both English and the language of the document before a notary. If the client is unable to retain a translator TRI will do so on the client’s behalf.
The decision to require additional or less information for CDD will be based on the results of the risk assessment. As such when a client is deemed to be low risk the documents requested may be less than if the client is deemed to be high risk where additional verification may be necessary.
In the following circumstances TRI will not be required to apply CDD measures referred to in the AML legislation where there are reasonable grounds for believing:
(A) that the customer, product or transaction falls within any of the following:
And (B) that a risk assessment is conducted prior to applying such simplified due diligence and determined a low risk of ML/TF activity and the person conducting the assessment does not suspect ML/TF activity and records those determinations.
Where Simplified Due Diligence is justified in accordance with the above, TRI will not be required to determine the underlying beneficial ownership of such customer, verify the identity of any chief executive or person of similar stature, but shall still identify and confirm the customer’s identity on the basis of documents, data or information obtained from a reliable and independent source; obtain information on and take steps to understand the purpose and intended nature of the business relationship, and the nature of the customer’s business; and in the case of a person purporting to act on behalf of a customer, verifying that the person is in fact so authorised and identifying and verifying the identity of that person.
Clients that meet the following criteria will be risk rated as high and will therefore require EDD conducted on them.
The following additional steps may need to be taken in order for EDD to be carried out:
The risks associated with PEPs occur when such individuals abuse their power for the personal benefit of themselves or others. A politically exposed person (either local or foreign) is defined in the AML/ ATF legislation as:
Bermuda’s current PEP guidance is included at Appendix B.
Customers shall be queried as to their ‘PEP’ status upon onboarding and compared automatically against IdentityMinds PEP database. A positive PEP hit will trigger manual review. PEP database is compared annually against existing customers during annual CDD
In order to help identify local PEPs, TRI may consult as necessary the following sources:
In all PEP matters, senior management approval will be required and all such files must be signed off by the AML Compliance Officer and one senior manager – which may include a director of TRI.
Where the person or entity with which TRI is doing business is considered a Politically Exposed Person, TRI shall conduct ongoing monitoring on an enhanced due diligence basis once in every 12 month period in accordance with Section 6.0 hereof (‘Monitoring’).
1 http://www.parliament.bm/about-parliament/house-of-assembly/register-of-interest.aspx
The identification processes specified in this manual must be complied with in respect of the following:
A new client will be required to provide information regarding their intended use of the TRI platform and the services required of TRI.
TRI must also be comfortable that funds introduced as well as any future funds are from a legitimate, legal source. The client’s sources of income and wealth and the extent of it should also be verified and documented. Source of funds and source of wealth can be verified using financial statements (preferably audited), direct communication with banks, credit agency reports, informal interviews and visits, news reports, or other appropriate evidence.
It is TRI’s policy that no reliance is to be undertaken and that CDD is to be reviewed and periodically monitored by TRI in all cases. TRI will not rely ‘blindly’ on third parties.
TRI shall not accept cash.
TRI shall not accept funds on a trust or escrow basis.
Ongoing monitoring procedures must apply to all clients. This is necessary in order to identify and analyze unusual or potential suspicious activity. This is achieved through monitoring of transactions in concert with IdentityMind, and keeping documents, data and/or CDD information up-to date. Obtaining CDD about the Beneficial Ownership provides the basis for a client risk assessment and effective ongoing monitoring program.
Ongoing monitoring shall be carried out on a risk sensitive basis (higher risk clients will require more frequent and intensive monitoring). The Company’s Risk Based Assessment to ongoing monitoring is driven by the client overall client risk rating and adopts the approach broadly described below.
If discovered, TRI will take additional measures, where appropriate, to prevent the use for money laundering or terrorist financing of products and transactions which might favour anonymity, and on a case by case basis would require management approval for any such products or transactions.
All ongoing monitoring will include the following:
Low Risk Clients review cycle occurs at least every 24 months and includes:
Medium Risk Clients review cycle occurs at least every 18 months and includes:
High Risk and PEPs review cycle occurs at least every 12 months and includes:
Further, IdentityMind continuously monitors transactions on the TRI platform, flagging inconsistent activity. There may be other events that occur from time to time that will require CDD information to be reviewed, and/or refreshed and revised. Example events are:
It is the policy of the Company that if an employee has concerns that a client’s activity gives rise to suspicion or knowledge that a person is engaged in money laundering or terrorist financing that must be reported to the MLRO using the internal reporting form annexed hereto as Annex 1.
All staff must be vigilant in considering red flags and reporting suspicions to the MLRO. A staff member’s failure to file a SAR could result in disciplinary action that could lead to termination of employment.
The MLRO is charged with the responsibility for investigating internally all SARs submitted. Given the seriousness related to the review of an SAR as soon as is practicable, it is important to record the date and timing of receipt of the SAR, this should be captured on the SAR form, either in hand or with a date and time stamp.
The MLRO must review the SAR form and determine whether the report gives rise to a suspicion or knowledge of ML or TF. The rationale for not filing the SAR with the FIA must be documented by the MLRO along with any additional supporting information as applicable. Following the investigation, the MLRO will determine whether the SAR and the investigation supports the suspicion and whether a SAR should be made to the FIA.
Following an internal investigation should the MLRO feel as though the report does give rise to knowledge or suspicion (on reasonable grounds thereof) of money laundering or terrorist financing, they must make a report to the FIA as soon as it is reasonably practicable.
The MLRO will include in any external report filed with the FIA as much detail as possible in relation to the customer, transaction or the activity it has within its records.
It is a criminal offence for any person who knows or suspects that a disclosure has been made to the FIA or an MLRO to disclose to any person information in relation to that disclosure or to disclose information or any other matter which is likely to prejudice any investigation which might be conducted following disclosure. In addition, TRI will not perform customer due diligence measures where doing so may result in a disclosure (tipping off) to any other person of information, or any other activity which is likely to prejudice an investigation or proposed investigation.
If TRI is unable to perform customer due diligence in accordance with the above, the matter will be referred to the MLRO who will review and may consider a disclosure to the FIA.
TRI will periodically receive requests from authorities for information or action, such as Police production orders. All orders must immediately be given to the ACO/MLRO for review and action. A file will be opened for the request, and all orders will be tracked by the ACO/MLRO and processed within the required timeframe.
It is the responsibility of the MLRO/ACO to ensure that the Order has been fulfilled in a timely and comprehensive manner. Information must be maintained confidentially, at all times limiting access to those persons that are required to know the details of the Order. It is necessary to protect the integrity of any ongoing investigations that may be in place; therefore, it is important that a copy of the Order is NEVER placed with customer materials.
Where the nature of an Order indicates a particular trend the MLRO must conduct an internal review to determine root causes and, if necessary, consider making a SAR to the FIA. The MLRO must also include the results of this review in the annual report that is made to the Board.
The Director(s) of TRI have appointed an MLRO who has been given the authority to act independently in order to carry out his responsibilities. The MLRO is free to liaise with the FIA on any question of whether to proceed with a transaction in the circumstances.
The relationship between the MLRO and the Director(s) will be clearly defined and documented so that each knows the extent of their roles and day-to-day responsibilities. The Director(s) will ensure that the MLRO has sufficient resources available including appropriate staff and technology in order for him to carry out his duties efficiently and in accordance with the law.
Management reports should be made at least annually. The Board has commissioned the MLRO with the responsibility for preparing the annual report. In addition to the presentation of the annual report, the MLRO must bring to the attention of the Board their own assessment of the effectiveness of TRI systems and controls pertaining to ML/TF risks. It is the responsibility of the Board to ensure that any recommendations made by the MLRO to remedy deficiencies are fully considered and remediated in a timely manner.
All staff will be provided with AML/ATF training. This should take place for new staff within 30 days of joining TRI. This includes individuals working on a temporary, contract or parttime basis. Compliance personnel will not be permitted to engage in compliance activities without direct supervision until AML.ATF training is completed. For existing staff, refresher training must occur at least once annually. It is the responsibility of the MLRO to ensure that the training material that is delivered or arranged remains current, is locally relevant, and includes information that is specific to the risks that are faced by TRI.
TRI will ensure all relevant employees are—
TRI will maintain a central record of all AML/ATF training provided to staff to be evidenced in TRI’s Anti Money Laundering & Anti-Terrorist Financing Staff Training Log.
Keeping accurate records is essential in order to assist in issuer-users’ ICO Audits, any financial investigation and to ensure that criminal funds are kept out of the financial system, or if not, that they may be detected and confiscated by the authorities. TRI will retain the following information:
TRI will maintain appropriate systems for retaining records and will maintain those systems for making records available when required to do so. This includes retention of customer email correspondence, maintenance of electronic documents, transaction records, and any other correspondence that may be received by an competent local or overseas authority (FinTech Advisory Board, Bermuda Monetary Authority, Ministry of Finance, NAMLC, FIA, overseas police and regulatory authorities etc.).
The Compliance Officer will commission an AML Audit on a yearly basis. This review shall be conducted by a qualified independent third party. A written report on the findings of this compliance review will then be forwarded to the Board of Directors for action and consideration, as they are ultimately responsible for the compliance program.
This Audit of the Financial Crime & AML/ATF compliance program will ensure that policies and procedures are legally sufficient, appropriate for the business, and that they have been complied with. Such a review could consist of the following:
The United Nations issues resolutions from time to time which place obligations on its member states. In September 2001, the UN issued a Resolution in relation to freezing the funds of entities and / or persons suspected of committing, or posing a significant risk of committing, or providing material support for acts of terrorism.
The Office of Foreign Assets Control (OFAC) is an agency of the United States Department of the Treasury under the auspices of the Under Secretary of the Treasury for Terrorism and Financial Intelligence. OFAC administers and enforces economic and trade sanctions based on U.S. foreign policy and national security goals against targeted foreign states, organizations, an individuals.
The Bermuda sanctions regime is based upon the United Kingdom’s sanctions regime as issued by Her Majesty’s Treasury and supervised by the Office of Financial Sanctions Implementation at the HM Treasury. The International Sanctions Act 2003 grants Bermuda’s Minister of Legal Affairs authority to make regulations giving effect to any international sanctions obligation of the United Kingdom. The International Sanctions Regulations 2013 are made pursuant to that authority.
Schedule 1 of the International Sanctions Regulations 2013 lists the United Kingdom’s sanctions-related Overseas Territories Orders in Council (“Orders”) that have been brought into force in Bermuda.
TRI is committed to appropriately respond to all matters that may involve Sanctions & Proliferation matters. Compliance should be contacted immediately if there is any activity which may be connected to any sanctions or proliferation program. Failure to comply with financial sanctions legislation or to seek to circumvent its provisions is a criminal offense.
Some relevant local guidance on sanctions is contained in:
Cornhill_Natural_Resources_Fund_Limited_v_Libyan_et_al, 2016_SC_Bda_9_Com
On a periodic basis, TRI will check whether we maintain any accounts or hold any funds or economic resources for those listed by Bermuda in the International Sanctions Act 2003 and accompanying Regulations and other relevant laws as necessary, including those published by OFAC and HMT.
TRI will review platform user identities against HM Treasury sanctions as sanctions lists are updated and notified to determine whether a relationship exists with such a sanctioned person or jurisdiction. This is in addition to review at client on-boarding.
If sanctions related accounts are discovered, TRI will, through the AML Compliance Officer:
i. freeze such accounts, and other funds or assets;
ii. refrain from dealing with the funds or assets or making them available to such persons unless licensed by the FSIU;
iii. report any findings to the FSIU, together with any additional information that would facilitate compliance;
iv. If deemed appropriate, and does not conflict with any SAR filing requirements, notify the client;
v. if deemed appropriate, file an internal SAR with the MLRO;
vi. cooperate fully and provide any information concerning the frozen assets of designated persons that the FSIU may request.
ALL BERMUDA SANCTIONS-RELATED LICENSE APPLICATIONS, NOTIFICATIONS AND AUTHORIZATIONS MUST BE MADE TO:
Financial Sanctions Implementation Unit
Ministry of Legal Affairs
Global House, Fourth Floor
Church Street
Hamilton HM 12
Bermuda
General enquiries: 41) 292-2463
Email: fsiu@gov.bm
All TRI staff will be screened at the time of recruitment. As part of this process, we will, as appropriate for the nature of the employee’s role and responsibilities:
Staff should notify the AML Compliance Officer of any change in circumstances, like marriage, divorce or bankruptcy and on a case by case basis, we will assess the need for re-screening employees who are transferred or promoted.
As part of the screening process, the AML Compliance Officer shall review and where appropriate, sign off on all new hires.
The following is a list of red flags that staff should be aware as there may be an indication of money laundering or terrorist financing. This list is not exhaustive and will be updated from time to time. This list should be used as a guide only.
For the purposes of regulation 11(6)—
(a) individuals who are or have been entrusted with prominent public functions include the following—
(b) the categories set out in sub-paragraphs (i) to (vi) of paragraph (a) do not include middle-ranking or more junior officials;
(c) the categories set out in sub-paragraphs (i) to (v) of paragraph (a) include, where applicable, positions at domestic and international level;
(d) immediate family members include the following—
(e) persons known to be close associates include the following—
For the purposes of regulation 11(6A)—
(a) individuals who are or have been entrusted with prominent public functions include the following—
(b) the categories set out in subparagraphs (i) to (vi) of paragraph (a) do not include middle-ranking or more junior officials;
(c) the categories set out in subparagraphs (i) to (v) of paragraph (a) include, where applicable, positions at domestic and international levels;
(d) immediate family members include the following—
(e) persons known to be close associates include the following—