AML and KYC Compliance Policy

1. Purpose and Regulatory Status

This Anti-Money Laundering and Know Your Customer Compliance Policy (“Policy”) defines the procedures implemented by Mobile Incorporated Limited (the “Company”, “we”, “us”, or “our”) to prevent, detect, and mitigate risks relating to money laundering, terrorist financing, fraud, and other financial crimes.

The Company operates under a B2C Gaming Service Licence issued by the Malta Gaming Authority (MGA) and is subject to Maltese Anti-Money Laundering and Counter-Terrorist Financing laws as a regulated subject person.

A risk-based approach is applied across all customer interactions, transactions, and account activity to ensure compliance with applicable legal and regulatory obligations.

This Policy applies to all users of the Company’s services.

2. Identity Verification and Customer Onboarding

2.1 Standard Verification Requirements

Before or during the establishment of a business relationship, the Company performs identity verification measures to confirm the authenticity of customer information.

These measures include:

  • Collection of valid government-issued photographic identification
  • Verification of legal name, date of birth, and residential address
  • Confirmation that the customer is at least 18 years of age
  • Validation through reliable electronic or manual verification methods

The Company reserves the right to limit or suspend account functionality until verification is successfully completed.

2.2 Enhanced Verification Procedures

Enhanced Due Diligence (EDD) is applied in situations where increased risk is identified.

This includes circumstances such as:

  • High-risk customer classification
  • Identification of Politically Exposed Persons (PEPs)
  • Suspicious or inconsistent transactional activity
  • Unclear source of funds or wealth
  • High-risk jurisdictional exposure

EDD measures may include:

  • Additional identity or financial documentation requests
  • Independent verification of submitted information
  • Source of funds or wealth validation
  • Senior Management approval before continuation of the relationship

3. Source of Funds Requirements

The Company may request documentation to verify the legitimacy of funds used on the platform.

Such documentation may include:

  • Bank statements
  • Salary slips or employment confirmation letters
  • Business ownership or corporate records
  • Asset sale or liquidation agreements

The Company may apply temporary restrictions on deposits, gameplay, or withdrawals until satisfactory verification is completed.

4. Transaction Monitoring and Risk Detection

The Company maintains ongoing monitoring systems combining automated tools and manual review processes.

Monitoring is designed to identify:

  • Unusual or irregular deposit and withdrawal behaviour
  • Rapid movement of funds without corresponding gameplay activity
  • Structuring or fragmentation of transactions
  • Activity inconsistent with the customer’s expected profile

Alerts generated are reviewed by qualified compliance personnel.

Where required, the Company may:

  • Request additional supporting documentation
  • Restrict or suspend account access temporarily
  • Escalate the matter internally for further review
  • Submit a Suspicious Activity Report (SAR) to the FIAU

5. Sanctions Screening and PEP Controls

Customers are screened against relevant sanctions and risk databases, including:

  • European Union sanctions lists
  • United Nations sanctions lists
  • National sanctions lists where applicable
  • Politically Exposed Person (PEP) databases

Screening is conducted at onboarding and periodically throughout the business relationship.

6. Reporting Obligations and Regulatory Cooperation

Where the Company knows, suspects, or has reasonable grounds to suspect money laundering or terrorist financing, it is required to submit a Suspicious Activity Report (SAR) to the Financial Intelligence Analysis Unit (FIAU).

The Company strictly prohibits any disclosure that could constitute tipping-off.

The Company cooperates fully with:

  • FIAU
  • Malta Gaming Authority (MGA)
  • Law enforcement authorities

7. Record Retention

The Company retains AML/KYC-related records in accordance with regulatory requirements, including:

  • Identity verification documentation
  • Transaction and account activity records
  • Risk assessments and monitoring outputs
  • Suspicious Activity Reports and supporting documentation

All records are retained for a minimum of five (5) years after the end of the business relationship or the last transaction, whichever is later.

8. Ongoing Risk Assessment and Monitoring

The Company applies a continuous risk-based monitoring model throughout the customer lifecycle.

Risk classification is based on:

  • Geographic location and exposure
  • Transaction volume and behavioural patterns
  • Account usage and activity trends
  • Additional risk indicators identified through monitoring systems

Higher-risk customers are subject to enhanced monitoring and more frequent review.

Compliance reporting may be prepared periodically and submitted to the MGA where required under licence conditions.

9. Customer Compliance Obligations

Customers are required to:

  • Provide accurate and truthful information during registration
  • Maintain updated account and identity details
  • Provide requested documents for verification in a timely manner

Failure to comply with AML/KYC requirements may result in:

  • Suspension of account functionality
  • Restriction of deposits or withdrawals
  • Account closure in line with regulatory obligations

10. Governance, MLRO Oversight, and Training

The Company maintains a formal AML governance structure, including:

  • Appointment of a Money Laundering Reporting Officer (MLRO)
  • Internal AML policies and documented procedures
  • Defined escalation and decision-making frameworks
  • Regular staff training on AML and CTF obligations

The effectiveness of the AML control framework is reviewed on a periodic basis.

11. Data Protection and Confidentiality

All personal and financial data collected under this Policy is processed in accordance with applicable data protection laws, including GDPR and relevant regulatory standards.

The Company ensures:

  • Secure storage of all sensitive information
  • Access limited strictly to authorised personnel
  • Controlled sharing only with regulatory or legal authorities when required
  • Compliance with confidentiality, integrity, and retention requirements

AML/KYC records are retained for a minimum of five (5) years following termination of the business relationship or last transaction.

12. Withdrawal Conditions and Identity Verification Threshold

All withdrawals are subject to compliance review and may require additional identity verification.

The Company applies enhanced verification where a customer’s cumulative deposits exceed €2,000.

This threshold may be assessed using either:

  • a daily cumulative calculation, aggregating all deposits made since the start of the business relationship; or
  • a rolling 180-day assessment period, taking into account all deposits made within that timeframe

Where this threshold is reached, the Company may require completion of enhanced identity verification before processing withdrawal requests.

Failure to complete verification may result in delays, suspension, or restriction of withdrawals.

13. Policy Updates

This Policy may be updated from time to time to reflect regulatory, legal, or operational developments.

The most recent version will always apply and will be made available through the Company’s official communication channels.