Fiatside

Legal document

Anti-money-laundering and counter-terrorist-financing policy

Converting a digital asset into legal tender is the step where money leaves the chain. That is exactly where AML supervision concentrates. This document describes our controls, including the ones that slow you down.

Version
1.0.0
Effective from
15 September 2026
Last updated
2 September 2026

This document is a template and must be reviewed by legal counsel before going to production

The text below was drafted from the obligations applicable to a digital asset service provider, but it has not yet been validated by a lawyer in the jurisdiction of establishment. It is therefore not enforceable as it stands and must not be treated as a final contractual commitment.

Document contents
  1. 01The contact point between the chain and the bank
  2. 02Customer due diligence
  3. 03Sanctions and politically exposed person screening
  4. 04Chain analytics
  5. 05Travel Rule
  6. 06Ongoing transaction monitoring
  7. 07Suspicious activity reporting
  8. 08Record keeping
  9. 09Governance of the framework
01

The contact point between the chain and the bank

An off-ramp is, by construction, the point where funds moving on public networks enter the banking system. That is where anti-money-laundering supervision concentrates, and where a control failure is paid for — by us in penalties, by you in a frozen bank account.

Our framework follows a risk-based approach: the intensity of control is proportionate to the risk presented by the customer, the product, the country and the distribution channel. Concretely, a first EUR 200 conversion to an IBAN in the verified customer’s own name is not treated like an EUR 80,000 deposit from an address exposed to a mixing service.

02

Customer due diligence

Identity verification is the first layer. It is graduated by cumulative amount tiers, and each tier adds a requirement: declared identity, then official document and liveness check, then proof of address and source of funds, then a compliance interview.

  • Identification and verification of identity before any payout above the first tier.
  • Verification that the payment beneficiary is the verified customer: we do not pay third parties.
  • Collection and understanding of the purpose of the business relationship for high amounts.
  • Periodic refresh of information: an expired identity document triggers a new verification, even on a long-standing account.
03

Sanctions and politically exposed person screening

The declared name, date of birth and nationality are compared against applicable sanctions lists, politically exposed person lists and wanted-person lists. Screening happens at sign-up, before every payout, and again whenever the lists are updated.

A match is not guilt. Homonyms are frequent, particularly for transliterated names. A match suspends the operation and triggers a human review comparing distinguishing elements — date of birth, nationality, place. A cleared match releases the operation and is recorded so the same false positive does not recur.

A confirmed match leads to freezing the operation, an inability to return the funds without authorisation from the competent authority, and the reporting the law prescribes. We have no discretion on this point.

04

Chain analytics

Every deposit address and every incoming transaction is analysed for exposure. The principle: trace flows back to identified entities and measure the share of funds coming directly or indirectly from risk categories.

Exposure categoryTreatment
Address on a sanctions listRefusal, freeze and reporting. No return possible without authorisation.
Mixing service, anonymisation protocolConversion refused. Return assessed case by case after review.
Darknet market, ransomware, reported fraudRefusal and reporting.
Unregulated exchange, high-risk serviceHuman review, source-of-funds evidence requested.
Indirect exposure beyond two hops, minority shareNormal handling, note on file, enhanced monitoring afterwards.
The exact trigger thresholds are not published: publishing them would amount to handing out the circumvention manual.
05

Travel Rule

The European regulation on information accompanying transfers of funds and certain crypto-assets requires originator and beneficiary information to travel with every transfer of digital assets between providers. Unlike conventional wires, there is no threshold below which the obligation falls away.

  • Where your deposit comes from another provider, that provider must transmit your name and the transfer references. A deposit arriving without them may be held while we obtain them.
  • Where the deposit comes from a self-hosted wallet, above a certain amount we must verify that the wallet is yours. Proof is by signing a message with the wallet key, not by declaration.
  • The information transmitted is limited to what the text requires. It serves no commercial purpose.
06

Ongoing transaction monitoring

Diligence does not stop at onboarding. Monitoring rules run continuously and raise alerts handled by an analyst. The following patterns are explicitly looked for.

  • Structuring: several orders kept just below a tier threshold over a short period.
  • Acceleration: a sharp break in the usual rhythm or amounts of an established account.
  • Inconsistency: a declared profile unrelated to the amounts converted, or a source of funds contradicted by chain analytics.
  • Immediate in-out: a deposit converted and withdrawn straight away with no apparent economic purpose.
  • Concentration: several separate accounts converging on the same beneficiary or the same deposit address.
07

Suspicious activity reporting

Where a suspicion remains after analysis, a report is filed with the competent financial intelligence unit. Such a report is not an accusation and is never made public.

08

Record keeping

Identification records, source-of-funds evidence, screening results, alert analyses and transaction traces are kept for five years from the end of the business relationship or from the transaction. That period is imposed; it can be neither shortened at your request nor extended at our convenience.

09

Governance of the framework

The compliance function is independent from commercial functions: it can block an operation without commercial arbitration and reports directly to management. The compliance officer will be named publicly as soon as the entity is registered and the authorisation file filed. Until then, we publish no name.

  • Risk mapping reviewed at least annually and at every corridor opening.
  • Mandatory training for anyone accessing compliance data, renewed each year.
  • Independent testing of the framework, with a remediation plan tracked to closure.
  • Full logging of access to compliance files, with periodic access review.
10

Version history

VersionLast updatedNature of the change
1.0.02 September 2026First publication of the document.

Stable anchors: every section carries an identifier that will not change. You can cite a clause by its direct link.