Last updated: July 26, 2026
Legal Obligation Notice
CardStack Technologies Ltd is required by law to maintain an Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) programme under the Money Laundering Regulations 2017, Proceeds of Crime Act 2002, and Terrorism Act 2000. We are also required to comply with UK financial sanctions administered by the Office of Financial Sanctions Implementation (OFSI). Failure to comply with these obligations is a criminal offence. This page summarises our programme for transparency; our full internal AML/CTF Policy is available to regulators and law enforcement upon request.
We maintain a documented Enterprise-Wide Risk Assessment (EWRA) updated annually and whenever business activities change materially. The EWRA identifies our exposure to money laundering, terrorist financing, and sanctions risk across products, customers, geographies, and channels.
We apply Standard CDD to all new customers (identity verification, beneficial ownership), Simplified CDD for lower-risk categories (MLRs Reg 28), and Enhanced Due Diligence (EDD) for politically exposed persons (PEPs), high-risk third country nationals, and transactions above enhanced thresholds.
We continuously monitor customer transactions to detect patterns inconsistent with the stated purpose of the business relationship. Automated transaction monitoring systems flag unusual activity for human review. We re-verify customer identity when material risk indicators change.
Our Nominated Officer (Money Laundering Reporting Officer — MLRO) reviews internal Suspicious Activity Reports (SARs) and submits external SARs to the National Crime Agency (NCA) Financial Intelligence Unit where required under POCA 2002 s.330. We never tip off subjects of an SAR (POCA 2002 s.333A).
We screen all customers and transactions against the UK (OFSI), US (OFAC/SDN), EU, and UN consolidated sanctions lists. Screening occurs at onboarding, on every transaction, and daily against all active customers. Positive matches result in immediate account freeze and notification to OFSI.
CDD records are retained for 5 years after the end of the business relationship. Transaction records are retained for a minimum of 5 years. CARF reporting records are retained for 5 years from the date of submission. All records are held securely with access limited to authorised personnel.
Requirement
Email address only
Transaction Limits
No financial transactions permitted
Legal Basis
No CDD required — no business relationship established
Requirement
Email, full name, date of birth, country of residence
Transaction Limits
Purchases up to £1,000/month; withdrawals up to £500/month
Legal Basis
Standard CDD — MLRs 2017 Reg 27
Requirement
Tier 1 + government-issued photo ID + proof of address
Transaction Limits
Purchases up to £10,000/month; withdrawals up to £5,000/month
Legal Basis
Standard CDD with enhanced identity verification — MLRs Reg 27
Requirement
Tier 2 + source of funds declaration + source of wealth for >£25k
Transaction Limits
No standard limits — subject to ongoing monitoring
Legal Basis
Enhanced Due Diligence — MLRs 2017 Reg 33
We do not provide services to persons or entities listed on any UK (OFSI), US (OFAC), EU, or UN sanctions list. All accounts are screened against consolidated sanctions lists at onboarding and on an ongoing basis. A positive or partial match results in immediate account restriction pending investigation by our compliance team.
We do not provide services to residents of the following jurisdictions due to active UK, US, EU, or UN financial sanctions programmes:
Russia (financial sanctions — OFSI Russia Regulations)
Belarus (financial sanctions — OFSI Belarus Regulations)
Iran (UN & OFSI sanctions — Iran (Sanctions) (Nuclear) (EU Exit) Regulations)
North Korea (DPRK) (UN & OFSI sanctions — DPRK (Sanctions) (EU Exit) Regulations)
Syria (OFSI Syria Regulations)
Myanmar (OFSI Myanmar Regulations)
Cuba (OFAC comprehensive sanctions)
Venezuela (OFAC SDN — regime officials)
Zimbabwe (OFSI Zimbabwe Regulations)
Sudan & South Sudan (OFSI Regulations)
This list is not exhaustive. We may restrict services to additional jurisdictions without notice in response to new sanctions programmes or regulatory guidance. Use of a VPN or other means to circumvent jurisdiction screening is prohibited and constitutes a breach of our Terms of Service and applicable sanctions law.
Under the Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 (the UK's implementation of the OECD Cryptoasset Reporting Framework — CARF), CardStack is required to:
HMRC may exchange this information with tax authorities in other CARF-participating countries under automatic exchange of information (AEOI) agreements. By using the platform, you consent to this reporting as required by our legal obligations.
If you suspect that your account has been used without your authorisation, or if you have information about potential money laundering, terrorist financing, or sanctions evasion on our platform, please report it immediately to our compliance team:
MLRO / Compliance Email: compliance@cardstack.app
Tipping-off prohibition: Under POCA 2002 s.333A and TA 2000 s.39, we are prohibited from disclosing the existence or content of a Suspicious Activity Report (SAR) to the person who is its subject. If your account is restricted in connection with an SAR, we cannot confirm this or discuss the reasons.
Suspicious activity may also be reported directly to the National Crime Agency (NCA) via the NCA SAR online portal.