1.Purpose & Scope
This Anti-Money Laundering, Counter-Terrorism Financing, and Know-Your-Customer Policy (the “Policy”) sets out the principles, controls, and procedures applied by Umbraswap (registered in Costa Rica, registration number 3-102-944661, the “Company”, “we”, “us”) to prevent, detect, and report money laundering (“ML”), terrorism financing (“TF”), proliferation financing, sanctions evasion, fraud, and other financial crime.
The Policy applies to all directors, officers, employees, contractors, agents, and authorised representatives of the Company, as well as to all customers and counterparties using our platform and Services. It applies in conjunction with our Terms and Conditions and Privacy Policy. In the event of any inconsistency between this Policy and those documents, the Terms and Conditions and the Privacy Policy prevail.
2.Regulatory Framework
This Policy is designed to comply with applicable laws, regulations, and international standards, including:
- Costa Rica:
- Law No. 8204 (Law on Narcotic Drugs, Psychotropic Substances, Unauthorised Drugs, Related Activities, Money Laundering and Financing of Terrorism), as amended; Law No. 7786 and its supplementary regulations; and supervisory standards issued by competent authorities, including the Superintendencia General de Entidades Financieras (SUGEF) and the Costa Rican Drug Institute (ICD) where applicable.
- Costa Rica Data Protection:
- Law No. 8968 on the Protection of Persons Regarding the Processing of their Personal Data, governing personal data collected during the KYC and monitoring processes, under the supervision of PRODHAB.
- Astana International Financial Centre (AIFC):
- the AML/CTF framework applicable to our Executing Partner, Collect & Exchange Ltd. (AFSA register number AFSA-G-LA-2023-0002), authorised and supervised by the Astana Financial Services Authority (AFSA).
- International standards:
- the Forty Recommendations of the Financial Action Task Force (FATF), with particular emphasis on Recommendations 10 (Customer Due Diligence), 11 (Record-Keeping), 12 (PEPs), 15 (New Technologies), 16 (Travel Rule for virtual asset service providers), 20 (Reporting of Suspicious Transactions), and 22 (DNFBPs); guidance issued by the Wolfsberg Group; and applicable United Nations Security Council Resolutions.
- Sanctions regimes:
- consolidated sanctions lists maintained by the United Nations, the United States Office of Foreign Assets Control (OFAC), the European Union, the United Kingdom HM Treasury (OFSI), and other applicable national authorities.
Where the Company offers Services in jurisdictions in addition to Costa Rica, applicable local laws are complied with. Where local requirements are stricter than this Policy, the stricter standard applies.
3.Key Definitions
For the purposes of this Policy:
- Money Laundering
- — the process of concealing the illicit origin of criminal proceeds, comprising placement, layering, and integration phases.
- Terrorism Financing
- — the provision or collection of funds with the intention or knowledge that they are to be used to carry out terrorist acts or to support terrorist organisations or individual terrorists.
- Proliferation Financing
- — the provision of funds or financial services for the manufacture, acquisition, possession, development, export, transhipment, brokering, transport, or use of nuclear, chemical, or biological weapons and their delivery systems.
- Customer Due Diligence (CDD)
- — the process of identifying and verifying customers, understanding the purpose and intended nature of the relationship, and conducting ongoing monitoring.
- Enhanced Due Diligence (EDD)
- — additional CDD measures applied where the customer or transaction presents a higher risk.
- Politically Exposed Person (PEP)
- — an individual who is or has been entrusted with prominent public functions, including their family members and close associates, as defined by FATF Recommendation 12.
- Beneficial Owner (UBO)
- — the natural person(s) who ultimately own or control a customer, or on whose behalf a transaction is conducted, including persons who exercise ultimate effective control over a legal person or arrangement.
- Source of Funds (SoF)
- — the activity, business, or origin that generated the specific funds used in a transaction.
- Source of Wealth (SoW)
- — the activities and events that generated the customer’s overall net worth.
- Suspicious Activity Report (SAR/STR)
- — a report submitted to the competent Financial Intelligence Unit (FIU) regarding activity reasonably suspected of being connected to ML, TF, or other criminal conduct.
- Virtual Asset Service Provider (VASP)
- — a person or business that conducts virtual-asset activities as defined by FATF, including exchange between virtual assets and fiat currencies, transfer of virtual assets, and custody.
4.Risk-Based Approach
Consistent with FATF Recommendation 1 and applicable Costa Rican law, the Company adopts a risk-based approach (“RBA”) to AML/CTF. Resources, controls, and the intensity of customer due diligence are allocated proportionate to the assessed risk of ML, TF, and sanctions exposure.
Enterprise-wide Risk Assessment
The Company maintains a documented enterprise-wide risk assessment that is reviewed at least annually and whenever a material change occurs (new product, new market, new partner, regulatory change, or significant incident). The assessment considers, at minimum, the following risk dimensions:
- Customer risk:
- customer type, industry, ownership structure, behaviour, and connection to PEPs or sanctioned parties.
- Geographic risk:
- exposure to high-risk jurisdictions, FATF-listed countries (call for action / increased monitoring), and sanctions regimes.
- Product / service risk:
- features of the digital-asset and cross-border payment services, including transaction speed and pseudonymity of certain blockchain networks.
- Channel / delivery risk:
- remote onboarding, third-party introducers, and use of new technologies.
- Counterparty risk:
- exposure to wallets and protocols associated with illicit activity, mixers, sanctioned addresses, or non-compliant exchanges.
Customer Risk Rating
Each customer is assigned a risk rating of Low, Medium, or High at onboarding. Ratings are reviewed periodically and re-assessed upon trigger events (e.g. unusual activity, adverse media, sanctions list update, change in beneficial ownership). The risk rating drives the depth of due diligence, the frequency of review, and the level of senior-management oversight required.
5.Customer Acceptance Policy
Customer acceptance is at the sole discretion of the Company. We reserve the right to refuse or terminate any business relationship without obligation to provide reasons. We will not, in any circumstances, accept or maintain a relationship with:
- Persons or entities subject to applicable financial sanctions, embargoes, or asset-freezing measures.
- Persons or entities resident in, located in, or operating from jurisdictions subject to comprehensive sanctions.
- Persons whom the Company knows or reasonably suspects to be engaged in money laundering, terrorism financing, or other criminal activity.
- Shell banks (banks with no physical presence and no affiliation with a regulated financial group), or persons providing services to shell banks.
- Anonymous or numbered accounts; accounts held in fictitious names; or relationships where beneficial ownership cannot be verified.
- Persons under the age of 18, or who otherwise lack legal capacity to contract.
- Persons unwilling or unable to provide the information and documentation required to complete identification, verification, and ongoing due diligence.
Decisions to onboard or continue a relationship with a High-risk customer require sign-off by the Money Laundering Reporting Officer (MLRO) or a duly delegated senior officer.
6.Customer Due Diligence (KYC)
Before establishing a business relationship and at appropriate intervals thereafter, the Company collects and independently verifies information sufficient to identify each customer. Standard CDD measures include:
Individual customers
- Full legal name, date of birth, nationality, country of residence.
- Government-issued photo identification (passport, national ID card, or driving licence).
- Proof of residential address issued within the last 3 months (utility bill, bank statement, or government correspondence).
- Contact details (email, telephone), and tax residency where applicable.
- Information regarding the purpose and intended nature of the relationship, source of funds and, where the risk justifies it, source of wealth.
- Biometric liveness check matching the customer to the identity document.
Corporate / legal-entity customers
- Certificate of incorporation, registered office address, and articles of association or equivalent constitutive documents.
- Register of directors and authorised signatories, with identification of those acting on the customer's behalf.
- Identification of all beneficial owners holding 25% or more of capital or voting rights, and any natural person otherwise exercising effective control. Where no such individual exists, identification of the senior managing official.
- Group / ownership structure for layered entities, including all intermediate entities up to the ultimate parent.
- Description of the business, regulatory licences (where applicable), tax identification, and country of tax residency.
Verification is performed using a combination of documentary checks, electronic identity-verification providers, document-authentication and biometric services, and screening against sanctions, PEP, and adverse-media databases.
7.Enhanced Due Diligence
Enhanced Due Diligence (EDD) is mandatory in all higher-risk situations, including:
- Customers identified as PEPs (foreign or domestic), their family members, and known close associates.
- Customers from, or transactions involving, jurisdictions identified by FATF as high-risk or under increased monitoring.
- Customers exposed to sanctioned regimes or industries that present elevated ML/TF risk.
- Complex, unusual, or large transactions, and unusual patterns of transactions, that have no apparent or visible economic or lawful purpose.
- Transactions or counterparty wallets associated with mixers, tumblers, anonymity-enhanced coins, darknet markets, ransomware payments, sanctioned entities, or other typologies of illicit conduct.
- Cash-intensive industries, shell entities, or ownership structures that lack transparency.
- Non-face-to-face onboarding with insufficient electronic identity-verification confidence.
EDD measures may include, in addition to standard CDD:
- Senior-management approval to onboard or continue the relationship.
- Additional independently corroborated source-of-funds and source-of-wealth documentation.
- Increased frequency and depth of ongoing review.
- Lower thresholds for transaction-monitoring alerts.
- On-chain risk scoring of incoming and outgoing wallet addresses using accredited blockchain-intelligence providers.
- Restrictions on transaction size, destination, or product set.
8.Beneficial Ownership
For all corporate, trust, and other legal-entity customers, the Company identifies and takes reasonable measures to verify the identity of every beneficial owner. The Company does not rely solely on the customer’s self-declaration: where appropriate, it consults independent registers of beneficial ownership, public filings, and reliable third-party data.
Where ownership is layered through multiple entities, the chain of control is documented and verified up to the ultimate beneficial owner. The Company refuses to establish or continue relationships where beneficial ownership cannot be reliably determined.
9.PEPs, Sanctions & Adverse Media
All customers, beneficial owners, and counterparties are screened at onboarding and continuously thereafter against:
- United Nations Security Council Consolidated Sanctions List.
- Office of Foreign Assets Control (OFAC) lists, including the SDN List and Sectoral Sanctions Identifications List.
- European Union Consolidated List of Persons, Groups and Entities subject to financial sanctions.
- United Kingdom HM Treasury Office of Financial Sanctions Implementation (OFSI) Consolidated List.
- Costa Rica national sanctions, freezing orders, and watchlists.
- International, regional, and national PEP databases.
- Adverse-media databases covering financial crime, fraud, corruption, and reputational concerns.
Re-screening is performed (a) when a list is updated, (b) when the customer’s profile materially changes, and (c) at least monthly. True-positive matches trigger a workflow involving the Compliance team and, where appropriate, the MLRO. Confirmed sanctions matches result in immediate freezing of assets in accordance with applicable law and reporting to competent authorities.
10.Ongoing Transaction Monitoring
The Company operates automated monitoring of customer activity in real time. Monitoring rules are calibrated to the customer’s risk rating, product use, and behavioural baseline. Indicative rule families include:
- Threshold and velocity rules (single-transaction, daily, monthly).
- Structuring and smurfing detection.
- Rapid in-and-out (pass-through) movement of funds.
- Inconsistency between declared activity / occupation and observed transaction profile.
- On-chain risk scoring of counterparty wallets, including exposure to mixers, sanctioned addresses, scam, ransomware, darknet markets, and high-risk exchanges.
- Geographic anomalies, including sudden activity from high-risk or sanctioned regions.
- Behavioural anomalies indicative of account takeover, social-engineering fraud, or coercion.
- Re-screening alerts triggered by sanctions / PEP / adverse-media list updates.
Alerts are reviewed by the Compliance team within defined service-level targets. Where appropriate, the Company may pause a transaction, request additional information, freeze assets pending investigation, terminate the relationship, and/or file a SAR/STR.
11.FATF Travel Rule (Recommendation 16)
For virtual-asset transfers above applicable thresholds, the Company collects, retains, and (where required) transmits originator and beneficiary information to counterparty VASPs in accordance with FATF Recommendation 16 and applicable local rules. Information typically transmitted includes:
- Originator name, account / wallet identifier, and physical address (or alternative identifier permitted by applicable rules).
- Beneficiary name and account / wallet identifier.
- Where required, originator date and place of birth, customer identification number, or other unique identifier.
The Company performs a risk assessment of counterparty VASPs (a “VASP due diligence”) before exchanging Travel Rule information and refuses transfers where the counterparty cannot be reliably identified or appears to be non-compliant. Travel Rule data is processed in accordance with applicable data-protection laws.
12.Prohibited Activities
The platform must not be used in connection with any of the following:
- Money laundering, terrorism financing, or proliferation financing.
- Fraud, scams, phishing, romance fraud, business email compromise, or any other deceptive financial conduct.
- Tax evasion or transactions structured to evade reporting thresholds.
- Trafficking in narcotics, weapons, persons, child sexual exploitation material, or any other illegal goods or services.
- Cybercrime, including ransomware payments, theft of digital assets, and laundering proceeds of hacking incidents.
- Mixers, tumblers, coin-join services, or any other anonymity-enhancing service designed primarily to obfuscate the origin of funds.
- Transactions involving sanctioned persons, entities, or jurisdictions, or any attempt to evade applicable sanctions.
- Transactions on behalf of an undisclosed third party, or any breach of clauses 17 or 19 of our Terms and Conditions.
- Any activity prohibited by applicable law or by our Terms and Conditions.
13.Suspicious Activity Reporting
Where the Company knows, suspects, or has reasonable grounds to suspect that a transaction or attempted transaction is connected to ML, TF, the proceeds of crime, or any other reportable conduct, it will:
- File a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) with the competent Financial Intelligence Unit (FIU) and any other relevant authority, as soon as practicable and in any event within the timeframes prescribed by applicable law.
- Cooperate fully with law enforcement, regulators, and judicial authorities, including providing transaction records, KYC files, monitoring alerts, and on-chain analytics where lawfully required.
- Where required by law, restrict, suspend, or terminate access to the affected account, and freeze associated assets.
- Maintain confidentiality of the report and the underlying suspicions, in accordance with the tipping-off prohibition (section 14).
A SAR/STR may also be filed in respect of attempted transactions, including those that did not complete, and regardless of the amount involved. The decision to file a report rests with the MLRO, who acts independently and is not subject to commercial pressure.
14.Tipping-Off Prohibition
Where lawful, the Company may communicate generic, non-incriminating information to a customer (for example, that an account has been suspended pending review). Such communications are designed and reviewed by Compliance to avoid tipping-off.
15.Record-Keeping
The Company retains records relating to its AML/CTF programme in line with applicable law and FATF Recommendation 11. Minimum retention periods are:
- KYC documentation and verification records: 5 years following the end of the business relationship, or longer where required by a competent authority or pending investigation.
- Transaction records (including wallet addresses, identifiers, amounts, dates, and counterparties): minimum 5 years following the date of the transaction.
- Transaction-monitoring alerts, investigation files, and SAR/STR-related materials: minimum 5 years from the date of the alert or report.
- Sanctions-screening hits and dispositions: minimum 5 years.
- Risk assessments, policies, training records, and policy versions: minimum 5 years.
- MLRO and senior-management decisions on high-risk customers and reportable matters: minimum 5 years.
Records are stored in a manner that allows reconstruction of individual transactions and timely response to information requests by competent authorities. For the full retention schedule of personal data, see section 14 of our Privacy Policy.
16.Governance & MLRO
AML/CTF compliance is owned by senior management and embedded in the Company’s governance. The principal roles are:
- Board / senior management:
- approves this Policy, approves the enterprise-wide risk assessment, allocates resources, and receives regular Compliance reporting.
- Money Laundering Reporting Officer (MLRO):
- a senior person with sufficient seniority, independence, authority, and resources, responsible for the AML/CTF programme, SAR/STR filings, communications with the FIU and regulators, and final decisions on high-risk relationships. The MLRO has direct access to senior management and reports at least annually on the programme’s effectiveness.
- Deputy MLRO:
- covers the MLRO’s responsibilities during absence and supports day-to-day operations.
- Compliance team:
- performs CDD/EDD, sanctions screening, transaction-monitoring alert review, investigations, and recordkeeping.
- All staff:
- required to apply this Policy, escalate suspicions internally without delay, and never engage in tipping-off.
The MLRO is the Company’s single point of contact for AML/CTF matters and is reachable at the address in section 23 below.
17.Training & Awareness
The Company maintains a structured AML/CTF training programme, comprising:
- Onboarding training for all new joiners covering ML/TF typologies, sanctions, this Policy, internal escalation procedures, and the tipping-off prohibition.
- Annual refresher training for all relevant staff.
- Role-specific deep-dives for Compliance, Operations, Customer Support, and Engineering on topics including on-chain analytics, the FATF Travel Rule, sanctions screening, and SAR/STR drafting.
- Targeted updates on emerging typologies, regulatory changes, and lessons learned from internal investigations or external incidents.
- Training attendance and outcomes are recorded and made available to regulators on request.
18.Independent Audit & Review
The AML/CTF programme is subject to periodic independent review (internal or external) at intervals appropriate to the size and risk profile of the Company. The review evaluates the design and operating effectiveness of controls, the adequacy of resources, the quality of CDD/EDD records, monitoring effectiveness, sanctions-screening accuracy, SAR/STR quality, and the level of senior-management oversight. Findings and remediation actions are reported to senior management and tracked to closure.
19.Whistleblowing
Staff and contractors are encouraged to raise, in good faith, concerns about possible breaches of this Policy, suspicious activity, or unethical conduct. Concerns may be raised confidentially to the MLRO. The Company prohibits retaliation against any person who raises a concern in good faith, and treats reports with the highest level of confidentiality consistent with the requirement to investigate.
20.Data Protection in AML Processes
Personal data collected and processed for AML/CTF purposes is handled in accordance with Costa Rica Data Protection Law (Law No. 8968) and our Privacy Policy. Such data is processed for the purpose of complying with our legal obligations and is shared with the Executing Partner, sanctions-screening providers, blockchain-intelligence providers, and competent authorities only to the extent necessary, and subject to appropriate contractual and technical safeguards.
Where personal data is shared with authorities under a legal obligation, the customer’s data-subject rights may be limited as permitted by law (in particular, to avoid prejudicing investigations). The Company’s tipping-off obligations may require us to refrain from confirming or denying disclosures.
21.User Obligations
By using our Services, you agree to:
- Provide accurate, complete, and up-to-date information at onboarding and throughout your relationship with us.
- Promptly notify us of any change to your identification details, address, beneficial ownership, regulatory status, or country of residence.
- Respond to requests for additional information or documentation without undue delay.
- Use our Services only for lawful purposes, and only on your own behalf unless expressly authorised.
- Confirm that all funds you transact through our platform are derived from legitimate sources, and provide independent verification of source of funds and source of wealth where requested.
- Refrain from any conduct that could cause the Company to breach applicable AML/CTF or sanctions laws.
Failure to meet these obligations may result in delays, refusal of transactions, freezing of assets, termination of the account, and/or reporting to competent authorities, in accordance with our Terms and Conditions.
22.Policy Review & Updates
This Policy is reviewed at least annually and whenever a material change occurs (regulatory, product, market, partner, or following a significant incident). Updates are approved by senior management and published on our Website. Continued use of the Services after publication of an updated Policy constitutes acknowledgement of the revised version.
23.Compliance Contact
For questions about this Policy, to provide additional verification information, or to report a concern, please contact our Compliance team:
Email (Compliance / MLRO): info@umbraswap.com
Post: Umbraswap, Province 01 San José, Canton 15 Montes de Oca, Costa Rica
This Policy is provided for transparency and is read in conjunction with — and is subordinate to — our Terms and Conditions and Privacy Policy. In the event of any inconsistency between this Policy and those documents, the Terms and Conditions and the Privacy Policy prevail. Nothing in this Policy creates rights or obligations in addition to those contained in the Terms and Conditions, and nothing in this Policy is intended to constitute legal advice.
Umbraswap | Province 01 San José, Canton 15 Montes de Oca, Costa Rica | Registration No. 3-102-944661
Last updated: May 2026