Compliance · Draft

Anti-Money Laundering & CFT Policy

Last updated · Draft v0.1

Unreviewed draft, not legal advice, not published

This page is a first-pass working draft prepared for review by qualified legal counsel and EKKA's compliance and issuing partners. It has not been approved, is not in effect, and must not be relied upon, quoted, or published until reviewed and sign-off is obtained from counsel and the relevant compliance / issuing partners.

ContentsPurpose and scopeOpenClose
  1. 1Purpose and scope
  2. 2Customer due diligence and KYC
  3. 3Sanctions and PEP screening
  4. 4Transaction monitoring
  5. 5Blockchain analytics on incoming deposits
  6. 6Prohibited uses and restricted jurisdictions
  7. 7Suspicious activity reporting
  8. 8Record-keeping
  9. 9Division of responsibility
  10. 10Compliance contact

1. Purpose and scope

This Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Policy sets out how [[LEGAL ENTITY NAME]] ('EKKA', 'we', 'us') detects, prevents, and reports money laundering, terrorist financing, and related financial crime risk connected with the EKKA card and its crypto-to-fiat funding flow. It applies to every customer onboarded in EKKA's launch markets, India and the United Arab Emirates, and to every USDC/USDT funding transaction and card transaction processed through the service.

This policy is issued in draft and must be reconciled against the AML/CFT programme of EKKA's card infrastructure provider (Swipeo) and its BIN sponsor / issuer, and against the requirements of [[REGULATOR]] before publication.

2. Customer due diligence and KYC

Before a card is issued, EKKA (directly or via its infrastructure provider) verifies each customer's identity using government-issued identification and, where required, a liveness or selfie check.

  • Identity verification standard: [[KYC VENDOR / VERIFICATION STANDARD]]
  • Enhanced due diligence trigger thresholds: [[EDD THRESHOLDS]]
  • Source-of-funds evidence required above: [[SOURCE OF FUNDS THRESHOLD]]
  • Re-verification / periodic KYC refresh cycle: [[KYC REFRESH PERIOD]]

3. Sanctions and PEP screening

Every customer is screened against applicable sanctions lists (including [[SANCTIONS LISTS SCREENED]]) and politically exposed person (PEP) databases at onboarding and on an ongoing basis. A confirmed sanctions match results in immediate account restriction and escalation.

Screening vendor and match-handling workflow: [[SCREENING VENDOR + ESCALATION PROCESS]].

4. Transaction monitoring

Card spend and USDC/USDT funding activity are monitored on an ongoing basis for patterns consistent with money laundering, structuring, or terrorist financing, including velocity, geographic, and value anomalies.

Monitoring rule set, thresholds, and alert-disposition process: [[TRANSACTION MONITORING RULES + THRESHOLDS]].

5. Blockchain analytics on incoming crypto deposits

Incoming USDC/USDT deposits used to fund an EKKA card are screened using blockchain analytics tooling to identify exposure to sanctioned addresses, mixers, darknet markets, and other high-risk sources before funds are converted to fiat.

Analytics provider and address-risk-scoring thresholds: [[BLOCKCHAIN ANALYTICS VENDOR + RISK THRESHOLDS]]. Deposits scored above the risk threshold are held pending review and may be rejected or reported.

6. Prohibited uses and restricted jurisdictions

The EKKA card may not be used for illegal purposes, to fund sanctioned entities or jurisdictions, for unlicensed money transmission, or for any activity prohibited under the terms of service.

Full restricted-jurisdiction and restricted-merchant-category list: [[RESTRICTED JURISDICTIONS + MCC LIST]].

7. Suspicious activity reporting

Where EKKA or its infrastructure/issuing partners identify activity that reasonably appears suspicious, a Suspicious Activity Report or Suspicious Transaction Report (SAR/STR) is filed with the competent authority.

Consistent with applicable law, EKKA does not disclose to a customer that a SAR/STR has been filed, is being considered, or exists in relation to their account ('tipping-off' is prohibited). No statement to a customer, including in response to an account restriction, will confirm or deny the existence of a report.

Needs legal input

Filing authority and jurisdiction-specific SAR/STR procedure for [[REGULATOR]] in India and the UAE are not yet defined and must be confirmed with local counsel.

8. Record-keeping

KYC records, transaction records, screening results, and SAR/STR-related records are retained for [[RETENTION PERIOD]] from the end of the customer relationship or the date of the transaction, whichever is later, or such longer period as required by applicable law.

9. Division of responsibility between EKKA, Swipeo, and the issuer/BIN sponsor

Needs legal input

EKKA relies on its card infrastructure provider (Swipeo) and the underlying regulated BIN sponsor/issuer for parts of the AML programme, including elements of KYC, sanctions screening, and transaction monitoring. Which party is the AML-regulated obligor of record, which party owns filing SARs/STRs, and how liability for a compliance failure is allocated between EKKA, Swipeo, and the issuer are not yet defined. This division must be documented in the underlying commercial/licensing agreements and reflected here before this policy is finalised.

Issuer / BIN sponsor and licence reference: [[ISSUING PARTNER + LICENCE NO.]].

10. Compliance contact

Questions about this policy, or reports of suspected financial crime, should be directed to [[COMPLIANCE CONTACT EMAIL]].