Anti-Money Laundering, Customer Identification and Transaction Screening Policy
This AML / KYC / KYT Policy (hereinafter the “Policy”) defines the procedure for verifying customers, transactions and the source of funds when using the vn-exchange.com service.
By using the site and services of the vn-exchange.com service, the user confirms that they have read this Policy, understands its content and accepts its terms.
1. Purpose of the Policy
The purpose of this Policy is to prevent the use of the service for money laundering, terrorist financing, fraud, circumvention of sanctions restrictions and other illegal operations, as well as to comply with internal security procedures and compliance monitoring.
2. Scope of Application
This Policy applies to all operations performed using the Service, including:
- exchange of digital assets
- operations with fiat funds
- transfers
- screening of addresses, wallets and transactions
- other actions available to the user within the site functionality
3. General Provisions
The vn-exchange.com service applies internal AML, KYC, KYT and SoF procedures for:
- preventing money laundering
- countering terrorist financing
- detecting fraudulent operations
- reducing the risk of the Service being used to transfer stolen, sanctioned or other high-risk digital assets
- complying with internal security procedures and obligations to partners, payment systems and counterparties of the Service
The Service reserves the right to suspend, reject, conduct additional checks or cancel operations in cases where the transaction, wallet, address, user or source of funds creates justified AML/KYC/KYT risks.
4. Key Terms
AML (Anti-Money Laundering) — a set of measures aimed at preventing the use of the Service for money laundering, terrorist financing and other illegal operations.
KYC (Know Your Customer) — a procedure for identifying the user, which may include verification of identity, place of residence, payment details and other data.
KYT (Know Your Transaction) — a procedure for analyzing a transaction, wallet, the sender’s or recipient’s address in order to detect signs of increased risk.
SoF (Source of Funds) — confirmation of the source of funds used by the user when carrying out an operation.
Risk Score — an indicator of the risk level of an address, wallet, transaction or operation formed based on data from analytics systems, results of manual review and internal risk assessment criteria.
5. Transaction Screening and Analysis Methods
The Service may carry out AML/KYT screening of incoming and outgoing digital assets, addresses, wallets and transactions using:
- third-party AML analytics
- internal risk assessment procedures
- manual review by an operator or responsible employee
- additional information provided by the user
- information received from payment systems, partners, liquidity providers, compliance partners or other involved parties
The screening is carried out using one or more third-party AML analytics and internal risk assessment procedures. The final Risk Score is formed based on the data from the analytical tools used and the results of additional review.
The screening may consider:
- the overall risk of an address or transaction
- matches with sanctions lists and restrictive registers
- links with darknet, stolen funds, scam, fraud, mixers, ransomware, high-risk exchanges and other high-risk categories
- the structure and nature of the transaction history
- behavioral and operational indicators indicating increased risk
- consistency of the operation with the data stated by the user in the application
The results of AML/KYT screening are formed based on available analytical data that may be updated in real time. Therefore, the risk level of the same address, wallet or transaction may change over time.
6. Sanctions Screening and Enhanced Risk Categories
The Service may screen users, addresses, wallets and transactions for matches with sanctions lists, restrictive registers and other sources of enhanced risk.
If matches, significant sanctions risks or other signs of enhanced compliance risk are identified, the operation may be:
- temporarily suspended
- referred for additional review
- declined
- returned to the sender in accordance with this Policy
The Service may also apply additional verification measures regarding politically exposed persons (PEP), their close relatives, affiliated persons, as well as users who fall into enhanced compliance risk categories.
7. Risk-Based Approach
The Service applies a risk-based approach when assessing users, transactions, addresses, wallets and the source of funds.
The scope of screening, the list of requested documents and the decision-making procedure depend on the risk level of the specific operation, user, address or source of funds.
Additional attention may be given to operations related to anonymizing technologies, transit transfers, atypical structuring of fund movements, and other operations that make it difficult to assess the origin of assets.
8. Risk Assessment Model and Thresholds
The Service uses a risk-based model to assess operations.
When analyzing, the following are considered:
- the final Risk Score
- types of identified risk categories
- the nature of the transaction
- results of manual review
- explanations and documents provided by the user
- signs that the operation does not match the data stated by the user
Internal indicative thresholds are applied as follows:
0–33% — low risk. The operation may be processed in the standard manner. 34–49% — moderate risk. The operation may be referred for additional manual review. 50–74% — high risk. The Service may temporarily suspend the operation, request KYC/SoF and additional information. 75% and above — critical risk. The Service may refuse to execute the operation or carry out a refund in accordance with this Policy.
These values are indicative and are applied considering the totality of factors. The final decision for a specific operation is made by the Service based on a complete risk assessment.
9. Pre-AML Screening
The user is recommended to complete such screening before agreeing to this Policy and before creating an application.
Before creating an application and transferring digital assets, the user is recommended to undergo preliminary AML screening of the address or wallet.
For this purpose, the user may:
independently use available screening tools, including the address screening page on the monitoring platform BestChange; provide the address or wallet number to the Service operator to clarify details and receive assistance with preliminary screening via the chat on the site or by email to info@vn-exchange.com; provide the screening result to the operator for risk assessment and recommendations on whether to proceed with the exchange.
By creating an application and accepting this Policy, the user confirms that they are informed about the availability of preliminary AML screening, understands the risks of using an address or wallet with an increased risk level and accepts the consequences of refusing such screening.
Regardless of whether the preliminary screening is completed or refused, the Service may carry out its own AML/KYT screening after funds are received, and may also request additional information and documents within AML/KYC/SoF procedures.
10. Grounds for Additional Review
The Service may request KYC, SoF and other materials, including in the following cases:
- increased or high risk is identified
- the address, wallet or transaction has links to high-risk categories
- signs of fraud, circumvention of Service rules or unreliable data are identified
- the operation differs from the user’s usual profile
- data in the application does not match the actual transfer parameters
- a request is received from a payment, compliance or other Service partner
- additional verification of the lawful source of funds is required
- there are other justified grounds for AML/KYC/KYT screening
11. Documents and Information That May Be Requested
As part of AML/KYC/SoF screening, the Service may request from the user one or more of the following materials.
11.1. For identity identification:
- passport
- national identity document
- driver’s license
- selfie with a document
- photo- or video confirmation of identity
11.2. For proof of residential address:
- bank statement
- utility bill
- another official document indicating the name and address issued no earlier than within the last 3 months
11.3. For proof of the source of funds (SoF):
- bank statements
- transaction history
- wallet screenshots
- confirmation of receipt of funds
- contracts, invoices, settlement documents
- other materials confirming the lawful origin of funds
11.4. For proof of the payment method:
- confirmation that the bank account, wallet or other payment details belong to the user
- bank statement, receipt, payment order, screenshot from the banking application or another document confirming the sending of funds
- other information required to confirm that the payment was made by the user using their own details
The Service does not accept payment by bank cards. Verification of the payment method, if necessary, is carried out exclusively with respect to bank transfers, the sender’s payment details and other allowed payment methods used by the Service.
12. Re-Verification and Additional Control
The Service may at any time request re-verification of the user’s identity, including via photo- or video confirmation, if required by the circumstances of a specific operation, a change in the user’s risk profile or internal security procedures.
The Service may verify the authenticity of documents and information provided by the user using:
- automated solutions
- open and closed sources of information
- additional requests to the user
- manual review by a Service employee
- information received from partners and compliance solution providers
Re-verification or an updated review may be requested if:
- previously provided documents have become outdated
- user data has changed
- atypical activity has been detected
- additional AML/KYC/KYT risks have appeared
- this is required by the circumstances of a specific operation
13. Internal Control and Responsible Parties
For the purposes of complying with AML/KYC/KYT requirements, the Service ensures the presence of a responsible employee or an involved external specialist or partner participating in risk assessment, review of disputed cases and support of verification procedures.
The Service also applies internal control measures aimed at:
- detecting suspicious operations
- ensuring compliance with AML/KYC/KYT procedures
- protecting user data
- reducing operational and compliance risks
14. Review Timelines
The estimated time for the initial review of an AML/KYC/SoF case is from 24 to 72 hours from the moment the complete set of requested documents and information is received.
In more complex cases, the review period may be extended if:
- additional documents are required
- manual review of multiple transactions is necessary
- participation of third parties, partners or external providers is required
- it is necessary to wait for additional transfer information
The Service informs the user about the review status through available communication channels.
15. Refunds and Fees
If the operation cannot be executed based on the results of AML/KYC/KYT/SoF screening, the Service may refund funds to the user.
Refunds are generally made to the sender’s details from which the transaction was received, unless otherwise additionally agreed and does not contradict security requirements, internal Service procedures and screening results.
15.1. Fee for Refunds in AML Cases
In the event of a refund within AML/KYC/SoF screening, the Service may withhold a fee of 1.5% of the refund amount, but no more than 100 USD in equivalent, and also a network fee if the refund is associated with actual costs for processing, verification and transferring the funds.
15.2. Bona Fide Clients
If the user has successfully passed KYC/SoF and there is no evidence of an unlawful source of funds, an additional Service fee for a refund or exchange is not charged; only the network fee is withheld.
15.3. Refund Time
After the decision to refund is made, the Service performs the refund within a reasonable period, taking into account technical, payment and compliance limitations, as a rule within 48 hours, if additional verification is no longer required.
16. Refusal to Execute the Operation
The Service may refuse to execute the operation, temporarily suspend it or cancel the application if:
- the user has not provided the requested documents or information
- the provided documents raise doubts about authenticity
- the risk level is deemed unacceptable
- the operation violates the Service rules
- signs of fraud, circumvention of restrictions or the use of third parties are identified
- the execution may violate internal security requirements, AML/KYC/KYT procedures or the Service’s obligations to partners
17. Limitation on Disclosure of Internal Information
The Service is not obliged to disclose to the user:
- internal technical parameters of scoring models
- specific risk assessment algorithms
- full details of how analytical systems work
- internal security procedures, if such disclosure could reduce the effectiveness of AML/KYC/KYT controls
At the same time, the Service provides the user with information about the review status, the list of required documents and the final decision to the extent permitted by internal rules and applicable requirements.
18. Personal Data Processing
Documents and personal data provided by the user within AML/KYC/SoF screening are used exclusively for:
- user identification
- risk assessment
- fraud prevention
- performing AML/KYC/KYT procedures
- fulfilling internal security requirements
- complying with obligations to partners and authorized bodies in the cases provided for
The Service takes reasonable measures to protect personal data from unauthorized access, modification, disclosure or destruction.
Personal data may be transferred only to:
authorized Service employees; providers of AML/KYC solutions; compliance partners; payment partners; authorized government bodies — in cases provided for by law or mandatory requirements.
The Service does not carry out long-term storage of copies of user documents in its own database unless otherwise required by applicable obligations, security requirements, requests from authorized bodies or participation of external verification providers. Based on the results of the review, the Service may store information about the fact of verification, review status and the minimum necessary service information related to the execution of internal security procedures.
19. Final Provisions
The Service may amend this Policy without prior individual notice by publishing the current version on the site.
If any provisions of this Policy are found invalid or unenforceable, it does not affect the validity of the remaining provisions.
In all matters not directly regulated by this Policy, the Service is guided by the current site rules, internal security procedures and applicable obligations.