Anti-money Laundering Policy

Introduction

Xhjili maintains an effective anti-money laundering and countering the financing of terrorism framework. This policy sets out the governance, risk-based controls, and operational procedures applied to all customer on-boarding, ongoing activity, and payment flows to detect and prevent money laundering and terrorist financing.

Scope and Objective

This policy applies to all customers, transactions, employees, and agents of Xhjili, and governs identity verification, due diligence, heightened scrutiny for high risk relationships, ongoing monitoring, escalation, and reporting to competent authorities. Its objective is to identify financial crime risks, mitigate them through proportionate controls, and maintain an auditable record Trail for law enforcement and regulatory purposes.

Governance and Oversight

  • Senior Management responsibility: ultimate accountability for the AML program and allocation of resources necessary to maintain effective controls.
  • Money Laundering Reporting Officer (MLRO): designated officer responsible for receiving disclosures from employees, evaluating suspicious activity, initiating reports to authorities where required, and ensuring independent operation with adequate authority and resources.
  • Compliance and Risk Committee: governance body overseeing AML/CFT risk, meeting no less than quarterly, and including the MLRO and a compliance officer as core members.

Customer Due Diligence (CDD)

  1. Identity and information collection: for all customers, collect and verify the minimum data set: full name, date of birth, citizenship, current address, and a unique customer identifier. Obtain primary identification documents such as a passport or national ID card and proof of address (eg, a recent utility bill or bank statement).
  2. Risk-based verification: apply proportionate verification based on risk assessment. Enhanced verification may be required for high-risk customers or activities.
  3. Source of funds and wealth: obtain documentation to verify the funds used to open the account and ongoing activity. Acceptable sources include payslips, pension or dividends, bank statements showing a consistent inflow from identifiable sources, or a trust deed illustrating entitlement to funds. For higher-risk cases, request additional documentation describing the source of wealth and the purpose of anticipated activity.
  4. Ongoing monitoring and risk profiling: assign a risk rating to each customer and refresh it with significant events. Review transactional patterns, deposits, and turnover against the customer profile on a risk-sensitive basis.
  5. Enhanced Due Diligence (EDD): apply additional checks for high-risk customers, including politically exposed persons, customers from high-risk jurisdictions, non-face-to-face relationships, or unusual source of funds evidence. Document all enhanced steps and retain supporting records.

PEP and High-Risk Customers

Politically exposed persons and their close associates or family are subject to enhanced due diligence. Screening includes verification of identity, assessment of ongoing political exposure, and monitoring commensurate with risk level. The combined effect of PEP status and other risk indicators may lead to extended verification, source-of-funds validation, and restricted product access where appropriate.

Sanctions, Watchlists, and Sanctioned Jurisdiction Screening

Xhjili screens customer data against applicable sanctions and watchlists at onboarding and on an ongoing basis. Any match triggers immediate escalation, temporary account restrictions, and a review by the MLRO in consultation with regulatory obligations. Transactions involving sanctioned persons or entities must be blocked and reported as required by law.

Transaction Monitoring and Suspicious Activity

All activity is monitored on a risk-based basis for indicators of money laundering or terrorist financing. Grounds for knowledge or suspicion arise when staff know, suspect, or have reasonable grounds for suspecting illicit activity. On such grounds, staff must:

  • Notify the MLRO promptly and securely;
  • Document the basis of suspicion and supporting data in a Risk Entry;
  • Escalate to appropriate authorities as required by law; and
  • Maintain strict confidentiality and avoid discussing the concern with the customer or third parties to prevent tipping off.

Specific monitoring measures include ongoing review of deposits and withdrawals, turnover relative to activity, and confirmation that funds originate from legitimate sources before settlement. When possible, funds are returned to the original payment method used by the customer.

Suspicious Activity Reporting (SAR) and Escalation

Employees must report grounds for knowledge or suspicion to the MLRO. The MLRO must assess whether the information constitutes a SAR and submit it to the competent authorities in a timely manner. Tipping off or premature disclosure is prohibited and may constitute a criminal offense. All SAR processing is conducted confidentially, and notes should not be disclosed to the customer or other parties outside the investigative framework.

Record Keeping and Data Retention

Xhjili maintains an auditable trail for AML purposes. Records kept include:

  • Identity verification materials and the process used;
  • Details of AML monitoring and compliance activities;
  • Risk assessments and customer risk profiles;
  • All internal and external SARs and reporting communications;
  • Customer transaction records and related correspondence;
  • Training records for staff involved in AML/CFT obligations.

Records are retained for a minimum of eight (8) years after the end of the customer relationship or as otherwise required by applicable law, whichever is longer. Access to records is restricted to authorized personnel and regulatory authorities as required by law.

Staff Training and Awareness

All employees receive initial AML/CFT training and annual refreshers. Training covers customer due diligence, enhanced due diligence for high-risk relationships, suspicious activity reporting, and the legal consequences of non-compliance. Training records are maintained to demonstrate compliance obligations have been met.

High-Risk Jurisdictions

We apply enhanced due diligence to customers located in or transacting with jurisdictions identified by international authorities as high risk. The list includes, but is not limited to, jurisdictions with elevated money-laundering or terrorist-financing risk profiles. Where risk indicators converge, Xhjili may impose limits on certain products, request additional documentation, or decline business in accordance with risk assessment outcomes.

Data Privacy and Handling

Xhjili acts as a data controller for personal information processed under AML/CFT obligations. We collect and process personal data strictly for the purposes of identity verification, due diligence, monitoring, and reporting. We retain personal data for a minimum of eight (8) years after the conclusion of the customer relationship and in compliance with applicable data protection laws. All processing is conducted with appropriate technical and organizational safeguards.

Cooperation with Authorities

Xhjili cooperates fully with law enforcement and regulatory bodies. Information sharing is conducted in accordance with applicable law and is limited to what is legally permissible and necessary for AML/CFT purposes. We do not disclose or discuss ongoing investigations with customers or third parties outside of the investigative framework.

Policy Review and Amendments

This policy is reviewed at least annually or upon material regulatory changes. Any amendments are approved by the MLRO and Senior Management and communicated to relevant stakeholders.