JavaScript is required

KYC Policy

KYC Policy of 3-102-946976 SOCIEDAD DE RESPONSABILIDAD LIMITADA

Last updated: 07.07.2026

KYC Policy of 3-102-946976 SOCIEDAD DE RESPONSABILIDAD LIMITADA (“The Company”), hereinafter (the Company, we, us) adheres to and complies with “Know your customer” principles, which aim to prevent financial crime and money laundering through client identification and due diligence.

The Company reserves the right, at any time, to ask for any KYC documentation it deems necessary to determine the identity and location of a user in spinnwon.com.

The Know Your Customer (KYC) Policy establishes the mandatory procedures, principles, and operational standards that need to be implemented by Internet Gaming Operators licensed under the jurisdiction of Anjouan. The purpose of this policy is to ensure that all licenses uphold the highest standards of compliance, integrity, and player protection in their operations.

1. Purpose of the KYC Policy

This policy aims to:

Verify the identity of players and account holders through robust documentation and validation processes to prevent the use of false or stolen identities.

Prevent and detect fraudulent, illegal, or abusive activities, including but not limited to bonus abuse, identity theft, and account manipulation.

Ensure full compliance with Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) obligations as outlined in international best practices and local regulatory frameworks.

Protect the gaming platform from being used for illicit financial activities, such as money laundering, terrorism financing, or proceeds of crime.

Maintain a safe, transparent, and secure gaming environment where all users can engage in fair and responsible gaming practices.

Foster trust between the operator and the customer, regulatory bodies, financial institutions, and other stakeholders by demonstrating commitment to legal and ethical operations.

The Company is expected to integrate this KYC Policy into their daily business processes and ensure their staff are fully trained in its requirements and procedures. Non-compliance may result in regulatory penalties, suspension of license, or further legal consequences.

2. Objectives of KYC

The Know Your Customer (KYC) framework plays a critical role in establishing the integrity and security of online gaming platforms licensed in Anjouan. The primary objectives of the KYC Policy are as follows:

Compliance with Regulatory Requirements

Ensure full compliance with applicable local and international Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) laws, including adherence to the standards and recommendations issued by the Financial Action Task Force (FATF) and other recognized regulatory bodies.

Verification of Player Identity and Integrity

Accurately verify and authenticate the identity of all players to: prevent access by underage individuals; detect and deter identity theft, fraud, and other forms of financial crime; ensure that only legitimate players can access the platform; risk-based assessment and mitigation; implement a risk-based approach to minimize exposure to high-risk customers.

Transactions that are unusual, large, or inconsistent with typical player behavior.

Transparency and Player Protection

Enhance the overall transparency of gaming operations by promoting responsible gaming, maintaining audit trails, and protecting customer data.

The KYC process also serves to: safeguard player funds against misuse or unauthorized access; uphold the Company’s commitment to ethical and fair gaming practices; build trust and credibility with players, regulators, and financial institutions.

3. Scope of the KYC Policy

This Know Your Customer (KYC) Policy applies to all relevant activities and stakeholders involved in the operation of Internet Gaming services licensed under the jurisdiction of Anjouan. The policy establishes a comprehensive framework to ensure that appropriate due diligence measures are applied consistently across all areas of risk exposure.

The policy applies throughout the entire customer lifecycle, from onboarding and verification to ongoing monitoring and transaction review. All departments and personnel responsible for compliance, player support, finance, and risk management need adhere to the principles set forth in this document.

This policy is applicable to: all players and users; any individual who registers, opens an account, deposits funds, or engages in gameplay on the platform is subject to KYC verification procedures. The Company ensures that all such players are identified and verified in accordance with the applicable due diligence requirements; third-party service providers and business relationships.

Any business partnerships, affiliates, agents, or outsourced service providers involved in financial transactions, identity management, or player onboarding also adhere to the principles of this KYC Policy. The Company verifies that these entities maintain adequate AML/CTF controls and operate in compliance with applicable regulatory standards.

Enhanced KYC measures apply to: transactions that exceed pre-established financial thresholds (as defined by the Company or regulator); multiple linked transactions or patterns of activity that raise suspicion; transactions involving jurisdictions identified as high-risk by FATF or the Anjouan offshore financial authority; high-risk customers and situations.

KYC procedures should be escalated when dealing with: politically exposed persons (PEPs); customers from restricted or sanctioned jurisdictions; accounts exhibiting suspicious or irregular activity; attempts to circumvent KYC requirements.

4. Key KYC Principles

1. Customer Identification and Verification

We are required to verify the identity of all customers under the following circumstances: when the aggregate lifetime deposits of a player equal or exceed $10,000 USD; when a withdrawal request is made by a player, regardless of the amount; when there is any indication of suspicious activity, high-risk behavior, or inconsistencies in account information.

Verification includes the collection and validation of government-issued identification documents, proof of address, and, where applicable, proof of payment method ownership.

2. Risk-Based Approach

The Company adopt a risk-based approach to customer due diligence. This involves applying different levels of scrutiny based on: the customer’s geographical location (e.g. high-risk jurisdictions); the volume and frequency of transactions; the nature of the customer’s gaming behavior; any identified risk indicators (e.g., status as a Politically Exposed Person).

The risk-based approach ensures that resources are allocated efficiently and that higher-risk customers receive Enhanced Due Diligence (EDD), while low-risk customers may qualify for Simplified Due Diligence (SDD) under applicable conditions.

3. Record Retention

All KYC-related documentation and transaction records should be securely stored for a minimum of five (5) years from the date: the customer relationship ends; or the transaction is completed, whichever is later.

Records include identification documents, verification data, transaction logs, communication logs (if applicable), and any reports related to suspicious activity.

4. Continuous Monitoring

The Company is required to implement systems for ongoing monitoring of player accounts. This includes: reviewing transactions for unusual or suspicious patterns; identifying behavior that may indicate fraud, money laundering, or misuse of services; triggering re-verification or escalation procedures when anomalies are detected.

Continuous monitoring helps ensure that previously verified customers continue to meet compliance standards and allows the Company to take timely action in response to emerging risks.

5. Customer Identification and Verification Process

5.1 Information Collection

Information Collection

The Company reserves the right to request, at its sole discretion and at any time, any KYC documentation it deems necessary to verify a user's identity, residence, and source of funds. Such documentation may include, but is not limited to:

Full Legal Name: As it appears on official government-issued identification.

Date of Birth: To confirm that the player meets the minimum legal age requirement (18+ or as defined by jurisdiction).

Nationality: To assess jurisdictional risk and compliance with restricted country policies.

Residential Address: To confirm the player’s place of residence and ensure it is not located in a restricted country.

Contact Information: Including a valid email address and mobile phone number for communication and verification purposes.

Payment Information: Details of the payment method used, including bank account numbers, cardholder information, or e-wallet credentials. This ensures that the customer is the rightful owner of the funds being deposited or withdrawn.

5.2 Document Verification

We reserve the right to restrict access to our services, including but not limited to gameplay, deposits, withdrawals, and bonuses, until identity verification is completed to our satisfaction. We may also suspend or permanently close an account if adequate KYC information is not provided upon request:

A valid government-issued ID (passport, national ID card, or driver's license);

Proof of residential address (utility bill, bank statement, or government correspondence issued within the last 3 months);

Proof of ownership of the payment method used (credit card copy, bank statement, etc.);

Source of funds or source of wealth documentation, especially in high-value or suspicious cases.

1. The following criteria are necessary to fulfill for an identity document to be accepted:

Proof of Identity (ID Document)

Accepted documents include:

Passport (preferred)

National ID card

Government-issued driver's license

The submitted document are obligated meet all of the following conditions:

a. Valid Signature Present

The documents are obliged to include a clear and visible signature of the holder. This is used to compare with any other documents requiring a signature for consistency.

b. Country of Issuance Not on Restricted List

The IDs are obligated to be issued by a country that is not included in our list of restricted or prohibited jurisdictions. Documents from the following countries and regions will be automatically rejected:

Australia

Austria

France and its territories

Germany

Netherlands and its territories

Spain

Union of Comoros

United Kingdom

United States of America (USA) and all of its territories

All countries on the FATF (Financial Action Task Force) blacklist

Any other jurisdictions deemed prohibited by the Anjouan Offshore Financial Authority

c. Full Name Matches Account Holder

The full name displayed on the identity document is obligated to match the name registered in the user’s account. Any discrepancies will result in the document being rejected unless legally explained and supported by additional documentation (e.g., marriage certificate, official name change certificate).

d. Document Expiration

The identity document is obligated to be valid at the time of submission and not due to expire within the next 3 months. Expired or soon-to-expire documents are not accepted, as they do not ensure long-term validity.

e. Age Verification

The document clearly indicates that the account holder is at least 18 years of age or older. Accounts belonging to underage individuals will be permanently closed and any associated funds may be confiscated in accordance with our Terms of Use and regulatory obligations.

f. Payment Verification

To confirm ownership of the payment method used, players may be required to provide:

A bank statement, screenshot, or photo of the online banking dashboard.

A wallet transaction confirmation or proof of e-wallet ownership.

The name on the account matches the name on the player’s ID and registration information.

All documents should be submitted in high resolution. Any attempts to forge or manipulate documents will be treated as fraudulent activity and may lead to accounting suspension or termination.

Proof of Residence (Address Verification)

Accepted documents include:

Bank Statement (showing account holder’s name and address)

Utility Bill (gas, electricity, water, landline telephone, fixed (not mobile) internet)

Government-issued Letter (e.g., tax notice, municipality letter)

Lease Agreement (only if issued by a licensed property manager and accompanied by a recent utility bill)

The submitted document should meet all the following requirements:

a. Type of Document

The document should be either a bank statement or a utility bill, clearly showing both the user’s full name and residential address. Screenshots or cropped images are not accepted; the entire page needs to be visible and legible.

b. Country of Residence Not on Restricted List

The document should confirm residence in a jurisdiction that is not listed among restricted or prohibited countries. Documents showing an address from any of the following will be rejected:

Austria

France and its territories

Germany

Netherlands and its territories

Spain

Union of Comoros

United Kingdom

United States of America (USA) and its territories

Any country on the FATF (Financial Action Task Force) blacklist

Any other jurisdiction prohibited by the Anjouan Offshore Financial Authority

c. Name Matching

The full name on the proof of residence should exactly match the name provided on the proof of ID and the name registered in the user's account. Any inconsistencies should be justified with legal documentation.

d. Date of Issue

The document is recommended to have been issued within the last 3 months from the date of submission. Older documents will not be accepted, regardless of content accuracy.

The date should be clearly visible and should reflect a recent billing or issuance cycle to confirm that the residence is current and valid.

Selfie with ID (Liveness and Identity Confirmation)

To ensure the authenticity of the user and prevent impersonation or the use of stolen documents, a selfie photograph holding the identity document should be submitted as part of the KYC process.

The selfie should meet the following requirements:

a. Identity Match

The individual in the selfie should be the same person as shown on the identity document previously submitted. Facial features should be clearly visible, without any obstructions (e.g., no sunglasses, hats, or masks).

b. Matching ID Document

The user should be holding the same identity document that was submitted as Proof of ID. This includes the same ID number, name, and photo as previously provided. The ID should be clearly visible and legible in the selfie.

Tips for acceptance:

Ensure good lighting (avoid shadows or glare on the face or ID)

Hold the ID next to the face, not in front of it

Do not apply filters or edit the image

Full face and both eyes should be clearly visible.

5.3 Enhanced Due Diligence (EDD)

Enhanced Due Diligence (EDD) is an intensified set of Know‑Your‑Customer (KYC) controls applied whenever a player or transaction presents an elevated risk of money‑laundering, terrorism‑financing, fraud, or other financial crime. EDD supplements, and does not replace, the Standard Due Diligence (SDD) measures set out in § 5.2.

5.3.1 EDD Triggers

EDD should be initiated in each of the following circumstances:

Trigger: a

Description

High-risk player profile

The player is a Politically Exposed Person (PEP), a family member/close associate of a PEP, or is resident in / a citizen of a jurisdiction classed as high-risk by the FATF, EU, or our internal Country Risk Assessment.

Examples

Ministers, judges, senior military officers; residents of jurisdictions on the FATF “grey” or “black” lists.

Trigger: b

Description

​​High-value transactions

Any single transaction ≥ USD 10 000 (or the equivalent in other currencies), or an aggregate of linked transactions that together reach this threshold within a rolling 24-hour period.​

Examples

Multiple deposits of USD 2 500 within a day that sum to USD 10 000.

Trigger: c

Description

Unusual or complex patterns

Transaction behavior that deviates from the player’s stated profile or expected gaming activity.

Examples

Repeated late-night deposits followed by immediate withdrawals; circular fund movements among several accounts.

5.3.2 EDD Objectives

The objectives of EDD are to:

Establish deeper knowledge of the player’s identity, financial background, and business activities.

Verify the legitimacy of the source of funds (SoF) and source of wealth (SoW).

Detects and mitigate potential money-laundering, terrorism-financing, fraud, or sanctions-evasion risks.

Provide a defensible audit trial demonstrating that heightened risks have been addressed in line with regulatory obligations.

5.3.3 EDD Measures and Controls

The following measures should be applied cumulatively unless otherwise approved by the Money-Laundering Reporting Officer (MLRO):

Category Mandatory Actions

Identity verification - Obtain and independently validate at least one additional government-issued photo ID. - Acquire a selfie with liveness check or video KYC session. - Perform biometric or facial-recognition matching where permissible.

Source of funds / wealth - Require recent bank statements (minimum three months) showing salary, dividends, or other income sources. - Request documentary proof of SoW (e.g., employment contract, audited financial statements, property sale deed). - Cross-check declared SoF/SoW against open-source intelligence and adverse-media databases.

Enhanced screening - Re-run PEP, sanctions, and adverse-media screening using expanded data sets. - Apply heightened name-matching thresholds and manual review of potential matches. - For high-risk jurisdictions, screen the player’s counterparties where identifiable.

Transaction monitoring - Flag the player in the monitoring engine for real-time alerts and daily post-event reviews. - Lower automated rule thresholds (e.g., unusual-withdrawal triggers). - Generate a written EDD case file documenting all findings and rationale for continued relationships or exit.

6. Risk-Based Approach

We apply a risk-based approach in our compliance procedures, meaning that the level of due diligence required depends on the customer's profile, behavior, geographic location, and transaction history.

Risk Categories and Due Diligence Measures

Based on the results of the initial and ongoing risk assessment, players should be classified into one of the following categories, with corresponding due diligence requirements:

Low-Risk Players

Characteristics:

Reside in low-risk jurisdictions.

Conduct low-value, infrequent transactions.

Show consistent and expected behavior.

Required Measure:

Simplified Due Diligence (SDD) may be applied, with minimal document collection where legally permitted.

Medium-Risk Players

Characteristics:

Moderate transaction volume.

No red flags, but risk indicators present (e.g., new user with large deposits).

Required Measure:

Customer Due Diligence (CDD), including collection of standard identity and address documents.

High-Risk Players

Characteristics:

Reside in high-risk countries.

Identified as PEPs or have adverse reputational indicators.

Conduct high-value, complex, or suspicious transactions.

Required Measure:

Enhanced Due Diligence (EDD) as detailed in Section 6, including verification of source of funds and frequent monitoring.

We implement the following tiers of due diligence:

Enhanced Due Diligence (EDD)

Enhanced Due Diligence (EDD) is a mandatory procedure applied to customers or transactions that pose a higher level of risk in relation to money laundering, terrorist financing, fraud, or other financial crimes. EDD goes beyond standard Customer Due Diligence (CDD) measures and involves a deeper investigation into the player’s identity, source of funds, and transactional behavior.

When EDD Is Required

EDD should be applied under the following circumstances:

High-Risk Customer Profiles

This includes individuals who:

Are classified as Politically Exposed Persons (PEPs).

Are residents or nationals of high-risk or FATF-blacklisted jurisdictions.

Display behaviors are inconsistent with typical gaming activity.

High-Value Transactions

Single transactions exceeding $10,000 USD.

Linked transactions that cumulatively exceed $10,000 USD within a short timeframe, especially if structured to avoid detection.

Suspicious or Complex Transaction Patterns

Frequent large deposits and withdrawals without proportional gaming activity.

Use of multiple payment methods or accounts.

Attempts to obscure or misrepresent the source of funds.

EDD Measures

The following measures should be implemented as part of the Enhanced Due Diligence process:

Verification of Source of Funds (SoF)

We obtain clear evidence regarding the origin of the funds used for gaming activities.

Acceptable documents include bank statements, payslips, asset sale contracts, or other legal financial records.

Verification of Source of Wealth (SoW)

In cases involving significant or unusual wealth, documentation may be required to demonstrate how the customer acquired their overall wealth (e.g., inheritance, investments, business income).

Additional Identity Checks

Requesting multiple forms of government-issued identification.

Verifying documents through third-party providers or public databases where available.

Conducting live video calls or selfie verification with ID.

Ongoing Transaction Monitoring

The customer’s account should be flagged for frequent manual or automated reviews.

Monitoring should focus on identifying patterns of activity that are inconsistent with stated gaming behavior or declared financial capacity.

Approval from Senior Compliance Officers

Any decision to establish or continue a business relationship with a high-risk customer should be approved by a designated compliance officer or member of senior management.

Documentation and Recordkeeping

All steps taken under EDD should be fully documented, including:

The rationale for categorizing the player as high-risk.

Copies of all additional documents collected.

Results of any external verification checks.

Notes from internal review or escalation decisions.

These records should be retained for a minimum of five (5) years and be readily available for audit or regulatory review.

In addition to the above, the Company enforces strict KYC checks in the following scenarios:

When a user requests a withdrawal of any amount;

When a user attempts or completes a transaction that is flagged as suspicious or unusual by our monitoring systems;

When a user's activity shows signs of elevated risk, including rapid deposit and withdrawal cycles or irregular gameplay.

In such cases, completion of the full KYC process becomes mandatory. No withdrawals or further transactions will be processed until KYC is successfully completed and verified.

7. Ongoing Monitoring

7.1 Transaction Monitoring

The Company implements both automated systems and manual review processes to monitor financial transactions on an ongoing basis. Monitoring should focus on identifying irregular, inconsistent, or suspicious activity that may indicate attempted money laundering, fraud, or misuse of the gaming platform.

Key indicators include:

Unusually large deposits or withdrawals are inconsistent with the player’s profile or declared source of income.

Rapid movement of funds, especially in and out of accounts with minimal gaming activity.

Structuring behavior (also known as "smurfing"), where a player conducts multiple small transactions designed to avoid reporting thresholds or trigger limits.

Use of multiple accounts or different payment instruments that appear linked.

All transactions should be subject to risk-scoring algorithms or flagging systems that escalate suspicious activity to the compliance team for further investigation.

7.2 Behavioral Monitoring:

In addition to financial activity, we monitor player behavior to identify signs of abuse, problem gambling, or risk of financial crime. This includes:

Irregular or compulsive betting patterns (e.g., increasing bet sizes rapidly, erratic deposit behavior).

Extended or unusually intense gaming sessions.

Repeated attempts to bypass account limits or verification steps.

Signs of third-party account control or impersonation.

Behavioral anomalies should trigger an internal review and, if necessary, additional KYC checks, player communication, or restrictions on the account.

7.3 Trigger Events

The Company conducts periodic reviews and reassesses player risk levels whenever specific events occur that could signal a change in the player’s risk profile. These trigger events include:

Unexplained inactivity followed by large transactions, which may suggest accounting misuse.

Material changes to the player’s profile, such as:

Update to personal details (e.g., address, nationality, occupation).

Change in payment method or financial information.

Alerts or negative matches received from:

External sanctions screening or PEP databases.

Third-party transaction monitoring or fraud detection services.

Law enforcement or regulatory bodies.

Each trigger event should initiate a review of the account, including potential re-verification of identity and updated due diligence, particularly if the player’s risk level increases.

8. Politically Exposed Persons (PEPs)

8.1 Identification

We take appropriate steps to identify whether a player is PEP at the time of onboarding and throughout the course of the business relationship.

A PEP is defined as an individual who:

Holds or has held a prominent public function either domestically or internationally, such as:

Heads of state or government.

Senior politicians, ministers, or members of parliament.

Senior government officials or civil servants.

High-ranking members of the armed forces.

Senior executives of state-owned enterprises.

Members of judicial bodies at a national level.

In addition, the following are also treated as PEPs:

Immediate family members of the above individuals, including spouses, children, parents, and siblings.

Close associates, including people known to have joint beneficial ownership or significant close business or personal relationships with a PEP.

8.2. Enhanced Due Diligence Measures

When a player is identified as a PEP or has connections to a PEP, the Company apply Enhanced Due Diligence (EDD) measures before establishing or continuing the relationship.

These include: independent verification; use of reputable third-party screening tools and global databases to identify PEP status; cross-checks against sanctions, watchlists, and adverse media sources; senior management approval.

The decision to onboard or continue a relationship with a PEP should be approved by a designated compliance officer or a member of senior management. All decisions and risk assessments should be fully documented.

The account should be flagged for enhanced and frequent review, including closer scrutiny of all transactions and behavior; periodic reassessment of risk level; monitoring for significant changes in occupation, jurisdiction, or transaction volume; verification of source of funds and wealth.

PEPs should provide credible documentation proving the origin of funds and, where necessary, the source of their overall wealth.

9. Record Keeping and Confidentiality

9.1. Retention Period

All KYC documentation, player identification records, transaction logs, communication history, and due diligence reports should be retained for a minimum period of five (5) years following:

The termination of the business relationship; or the date of the last transaction or player activity - whichever is later.

This retention policy is designed to meet the requirements of the Anjouan Offshore Financial Authority, international AML/CTF regulations, and applicable recordkeeping laws.

9.2. Data Protection

To ensure data privacy and confidentiality, the Company shall:

Store all player data using encrypted and secure systems, with access restricted to authorized personnel only.

Adhere to applicable data protection laws.

Use player information exclusively for:

Identity verification.

AML/CTF risk assessments.

Compliance with regulatory and legal obligations.

That personal data is not sold, shared, or disclosed to third parties without the user’s explicit consent, except where required by law or for regulatory reporting purposes.

9.3. Accessibility and Audit Readiness

All KYC records should be readily accessible for examination by authorized representatives of regulatory bodies, financial intelligence units, or law enforcement authorities upon formal request.

Systems and procedures should be in place to:

Retrieve historical records efficiently.

Demonstrate compliance with KYC/AML obligations during audits or inspections.

Preserve the integrity and traceability of data.

Employees and service providers with access to sensitive player information are required to sign confidentiality agreements and undergo AML/KYC training. Any breach or unauthorized disclosure of player information should be reported immediately and investigated under the Company’s Data Breach Response Plan.

10. Reporting Obligations

In accordance with applicable anti-money laundering (AML) and counter-terrorist financing (CTF) regulations, the following reporting obligations should be strictly observed by all relevant staff and departments:

In accordance with applicable anti-money laundering (AML) and counter-terrorist financing (CTF) regulations, the following reporting obligations should be strictly observed by all relevant staff and departments:

10.1. Suspicious Activity Reporting (SARs)

All employees are required to identify and report any activity that may be considered suspicious, as defined under local and international AML/CTF guidelines.

Reporting Timeframe:

Any suspicious activity should be reported to the designated compliance officer or the appropriate regulatory body within seven (7) calendar days from the date of detection.

Report Content:

The report should include comprehensive and accurate information regarding:

The identity and account details of the involved player(s);

A full description of the suspicious transaction(s), including date, amount, and method;

The specific reasons why the activity is deemed suspicious, supported by factual observations, patterns, or documentation where available.

Confidentiality and Non-Tipping Off:

All SARs should be handled with the highest level of confidentiality. Under no circumstances should the subject of a SAR be informed or made aware that they are under review or investigation, in line with anti-tipping-off regulations.

10. 2. Threshold Transaction Reporting

Certain transactions should be reported regardless of whether any suspicion exists. These include high-value transactions that meet or exceed a specified monetary threshold.

Threshold Limit:

All single or related transactions with a cumulative value exceeding $10,000 USD (or equivalent in other currencies) should be reported to the appropriate regulatory authority.

Report Requirements:

Reports should include:

Full customer identification details (including verification documents);

The amount, type, and date of the transaction(s);

Any related accounts or counterparties involved;

Supporting documentation, where applicable.

A copy of all reports and supporting information should be securely stored in compliance with data retention policies, typically for a minimum of five (5) years, unless otherwise specified by law.

11. Compliance Oversight

11.1. Appointment of a Compliance Officer

The Company appoints a designated Compliance Officer who will serve as the primary individual responsible for the organization’s compliance program. The Compliance Officer should possess the requisite knowledge, authority, and independence to perform their duties effectively.

Key Responsibilities include:

Overseeing the implementation and effectiveness of KYC policies and procedures, ensuring they are aligned with regulatory requirements and internal risk assessments.

Acting as the primary liaison with regulatory and law enforcement authorities, including timely responses to requests for information or cooperation.

Ensuring the timely submission of Suspicious Activity Reports (SARs) and other mandatory transaction reports in accordance with Anjouan’s regulatory framework and applicable international standards.

11.2. Internal Audits

The Company is required to conduct regular internal audits to assess and enhance the effectiveness of their compliance and risk management systems.

Audit Scope and Frequency:

Internal audits should be conducted periodically, at minimum on an annual basis, or more frequently depending on the organization’s risk profile.

Audits should evaluate the adequacy and effectiveness of KYC measures, reporting procedures, staff compliance, and overall adherence to AML/CTF obligations.

Audit Reporting:

Findings should be documented in a formal audit report and reviewed by senior management.

Identified deficiencies should be addressed through corrective action plans with defined timelines.

11.3. Training Programs

The Company should implement ongoing training and awareness programs to ensure all relevant employees are well-equipped to fulfill their compliance responsibilities.

Training Content should cover, at a minimum:

Proper identification and verification procedures, including how to detect fraudulent or altered customer documentation.

Recognition of red flags associated with money laundering and terrorist financing activities.

Understanding legal and regulatory obligations, including specific reporting duties under Anjouan’s AML/CTF regulatory framework.

Frequency and Documentation:

Training should be conducted at onboarding and regularly thereafter (e.g., annually or as needed based on risk exposure or regulatory changes).

Records of all training sessions, including attendance and materials used, should be retained for audit and regulatory purposes.

12. Penalties for Non-Compliance

Consequences of Non-Compliance

Any failure to implement, enforce, or adhere to the required compliance standards may lead to the following penalties:

Administrative Sanctions:

Regulatory authorities may impose a range of administrative penalties, including but not limited to:

Fines and monetary penalties scaled based on the severity and frequency of the violations.

Warnings or reprimands, issued to the Company and/or responsible individuals.

Orders to take corrective actions within a specified timeframe.

Suspension or Revocation of License:

In cases of repeated or significant breaches, the Company may face:

Temporary suspension of its license to operate, pending remediation.

Full revocation of the gaming or business license, effectively terminating the company’s legal right to conduct operations within the jurisdiction.

Referral for Criminal Investigation:

If the non-compliance involves suspected criminal conduct - such as intentional facilitation of money laundering, willful blindness, or deliberate concealment of customer identity - The case may be referred to law enforcement agencies for criminal investigation.

Individuals involved may face prosecution, with penalties including fines, imprisonment, or both, depending on the applicable laws of Anjouan and any cooperating jurisdictions.

Mitigating Factors

While penalties are enforced to maintain the integrity of the financial and gaming system, regulators may consider certain mitigating factors, such as:

Voluntary self-reporting of the breach;

Demonstrated cooperation with authorities;

Timely and effective remedial actions;

The absence of prior violations.

The Company is encouraged to maintain a proactive compliance culture to avoid enforcement actions and uphold their reputational and legal standing.

13. Continuous Improvement

Ongoing Policy Review and Enhancement

The Company should regularly review, assess, and update their KYC policies and procedures to ensure they remain compliant with evolving legal and regulatory requirements at both the local and international levels.

Policy updates should reflect:

Changes in Anjouan’s AML/CTF regulatory framework;

Emerging risks and typologies identified through internal monitoring or industry advisories;

Feedback from internal audits, regulatory inspections, or compliance incidents.

Adoption of Innovative Technologies

The Company is encouraged to embrace advanced technological solutions to strengthen their compliance capabilities and improve operational efficiency.

Recommended technologies include:

Artificial Intelligence (AI) and machine learning algorithms for detecting suspicious behavior patterns, automating risk assessments, and enhancing transaction monitoring.

Blockchain and distributed ledger technologies (DLT) to support secure, transparent, and tamper-proof customer identity verification and audit trails.

Biometric authentication, document scanning, and optical character recognition (OCR) to streamline the customer onboarding process and reduce the risk of identity fraud.

Commitment to Best Practices

Continuous improvement should be embedded within the company’s compliance culture, with senior management actively supporting innovation and adaptability.

The Company should stay informed about industry’s best practices, global compliance trends, and technological advancements, participating in relevant training, workshops, and industry forums.

14. Contact Information

For questions, assistance, or further information related to Know Your Customer (KYC) compliance, regulatory obligations, or any aspect of AML/CTF policy implementation, we are encouraged to contact the designated regulatory support office.

Regulatory Contact Details:

Anjouan Licensing Services Inc.

Email: admin@anjouangaming.com

Website: www.anjouangaming.com

The compliance support team is available to:

Provide clarification on regulatory requirements;

Offer guidance on best practices for KYC implementation;

Address concerns related to licensing, reporting obligations, or enforcement procedures.

The Company should maintain up-to-date contact records and ensure that their compliance staff are familiar with the appropriate channels for regulatory communication.

If you have questions about this Policy or wish to report suspicious activity, contact:

Email: complaints@spinnwon.com

Address: Province 01 San Jose, Canton 09 Santa Ana, Pozos, Forum Uno, Building G, First Floor, Offices of NCC Law