AML, CTF & Sanctions Policy

Last updated: July 26, 2026

Legal Obligation Notice

CardStack Technologies Ltd is required by law to maintain an Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) programme under the Money Laundering Regulations 2017, Proceeds of Crime Act 2002, and Terrorism Act 2000. We are also required to comply with UK financial sanctions administered by the Office of Financial Sanctions Implementation (OFSI). Failure to comply with these obligations is a criminal offence. This page summarises our programme for transparency; our full internal AML/CTF Policy is available to regulators and law enforcement upon request.

Our AML/CTF Programme

Risk Assessment

We maintain a documented Enterprise-Wide Risk Assessment (EWRA) updated annually and whenever business activities change materially. The EWRA identifies our exposure to money laundering, terrorist financing, and sanctions risk across products, customers, geographies, and channels.

Customer Due Diligence (CDD)

We apply Standard CDD to all new customers (identity verification, beneficial ownership), Simplified CDD for lower-risk categories (MLRs Reg 28), and Enhanced Due Diligence (EDD) for politically exposed persons (PEPs), high-risk third country nationals, and transactions above enhanced thresholds.

Ongoing Monitoring

We continuously monitor customer transactions to detect patterns inconsistent with the stated purpose of the business relationship. Automated transaction monitoring systems flag unusual activity for human review. We re-verify customer identity when material risk indicators change.

Suspicious Activity Reporting

Our Nominated Officer (Money Laundering Reporting Officer — MLRO) reviews internal Suspicious Activity Reports (SARs) and submits external SARs to the National Crime Agency (NCA) Financial Intelligence Unit where required under POCA 2002 s.330. We never tip off subjects of an SAR (POCA 2002 s.333A).

Sanctions Screening

We screen all customers and transactions against the UK (OFSI), US (OFAC/SDN), EU, and UN consolidated sanctions lists. Screening occurs at onboarding, on every transaction, and daily against all active customers. Positive matches result in immediate account freeze and notification to OFSI.

Record Keeping

CDD records are retained for 5 years after the end of the business relationship. Transaction records are retained for a minimum of 5 years. CARF reporting records are retained for 5 years from the date of submission. All records are held securely with access limited to authorised personnel.

KYC Verification Tiers

Tier 0 — Browse Only

Requirement

Email address only

Transaction Limits

No financial transactions permitted

Legal Basis

No CDD required — no business relationship established

Tier 1 — Basic Verified

Requirement

Email, full name, date of birth, country of residence

Transaction Limits

Purchases up to £1,000/month; withdrawals up to £500/month

Legal Basis

Standard CDD — MLRs 2017 Reg 27

Tier 2 — Identity Verified

Requirement

Tier 1 + government-issued photo ID + proof of address

Transaction Limits

Purchases up to £10,000/month; withdrawals up to £5,000/month

Legal Basis

Standard CDD with enhanced identity verification — MLRs Reg 27

Tier 3 — Enhanced Verified

Requirement

Tier 2 + source of funds declaration + source of wealth for >£25k

Transaction Limits

No standard limits — subject to ongoing monitoring

Legal Basis

Enhanced Due Diligence — MLRs 2017 Reg 33

Sanctions & Prohibited Jurisdictions

We do not provide services to persons or entities listed on any UK (OFSI), US (OFAC), EU, or UN sanctions list. All accounts are screened against consolidated sanctions lists at onboarding and on an ongoing basis. A positive or partial match results in immediate account restriction pending investigation by our compliance team.

We do not provide services to residents of the following jurisdictions due to active UK, US, EU, or UN financial sanctions programmes:

Russia (financial sanctions — OFSI Russia Regulations)

Belarus (financial sanctions — OFSI Belarus Regulations)

Iran (UN & OFSI sanctions — Iran (Sanctions) (Nuclear) (EU Exit) Regulations)

North Korea (DPRK) (UN & OFSI sanctions — DPRK (Sanctions) (EU Exit) Regulations)

Syria (OFSI Syria Regulations)

Myanmar (OFSI Myanmar Regulations)

Cuba (OFAC comprehensive sanctions)

Venezuela (OFAC SDN — regime officials)

Zimbabwe (OFSI Zimbabwe Regulations)

Sudan & South Sudan (OFSI Regulations)

This list is not exhaustive. We may restrict services to additional jurisdictions without notice in response to new sanctions programmes or regulatory guidance. Use of a VPN or other means to circumvent jurisdiction screening is prohibited and constitutes a breach of our Terms of Service and applicable sanctions law.

HMRC CARF Reporting (2025 Regulations)

Under the Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 (the UK's implementation of the OECD Cryptoasset Reporting Framework — CARF), CardStack is required to:

  • Apply due diligence procedures to all users (including self-certification of tax residency and TIN)
  • Collect and verify Taxpayer Identification Numbers (TINs) and National Insurance Numbers where applicable
  • Report account holder information, transaction volumes, and gross proceeds to HMRC annually by 31 May
  • Maintain due diligence and reporting records for 5 years
  • Register with HMRC as a Reporting CASP (Cryptoasset Service Provider)

HMRC may exchange this information with tax authorities in other CARF-participating countries under automatic exchange of information (AEOI) agreements. By using the platform, you consent to this reporting as required by our legal obligations.

Reporting Suspicious Activity

If you suspect that your account has been used without your authorisation, or if you have information about potential money laundering, terrorist financing, or sanctions evasion on our platform, please report it immediately to our compliance team:

MLRO / Compliance Email: compliance@cardstack.app

Tipping-off prohibition: Under POCA 2002 s.333A and TA 2000 s.39, we are prohibited from disclosing the existence or content of a Suspicious Activity Report (SAR) to the person who is its subject. If your account is restricted in connection with an SAR, we cannot confirm this or discuss the reasons.

Suspicious activity may also be reported directly to the National Crime Agency (NCA) via the NCA SAR online portal.

Extensions

  • Marketplace
  • Media · Coming Soon
  • Studio · Coming Soon
  • Study · Coming Soon
  • Fund · Coming Soon
  • Agent · Coming Soon
  • Design · Coming Soon

Connect

Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment and you are unlikely to be protected if something goes wrong. Take 2 mins to learn more.

Regulatory Notice: CardStack Technologies Ltd (registered in England & Wales, Co. No. 12345678) is not authorised or regulated by the Financial Conduct Authority (FCA) or any equivalent body to provide investment advice, deal in regulated financial instruments, or provide payment services under the PSR 2017. Digital assets and BBB Cards are not protected by the Financial Services Compensation Scheme (FSCS) or the Financial Ombudsman Service (FOS). Trading digital assets involves substantial risk of loss — the value of your investments can go down as well as up and you may lose more than you invest. Past performance is not a reliable indicator of future results. Nothing on this platform constitutes financial, investment, tax, or legal advice. CardStack complies with the Money Laundering Regulations 2017 (MLR 2017) and the Sanctions and Anti-Money Laundering Act 2018 (SAMLA 2018).

© 2026 CardStack Technologies Ltd. All rights reserved.