> For the complete documentation index, see [llms.txt](https://golden-shield-digital-treasury-b.gitbook.io/product-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://golden-shield-digital-treasury-b.gitbook.io/product-docs/others/aml-cft-policy.md).

# AML/CFT Policy

### 1. Introduction to AML Policy

Guided by the rules and regulations of the **BVI Financial Services Commission (FSC)**, the purpose of this policy is to set the GDB Platform’s internal practices, procedures, and controls for preventing **money laundering (AML)**, **terrorist financing (CFT)**, and ensuring full adherence to **Know-Your-Customer (KYC)** principles.

This policy is established and updated by the appointed **Money Laundering Reporting Officer (MLRO)**, who also serves as Compliance Officer for the GDB Platform. The policy applies to all employees, contractors, and service providers operating within the GDB ecosystem.

The AML/CFT Policy has been prepared to comply with:

* The BVI **Regulatory Code (2020, revised)**
* The **Anti-Money Laundering and Terrorist Financing Code of Practice (2020, revised)**
* The **Anti-Money Laundering and Terrorist Financing (Amendment) Code of Practice (2022)**
* Relevant FATF recommendations and international standards

The **Financial Investigation Agency (FIA)** is the authority where suspicious activities are reported. The MLRO ensures full implementation of GDB’s AML/CFT regime and monitors adherence to internal controls and external obligations.

All GDB employees and node operators are obliged to report suspicious activity or transactions involving **GDB or GDO tokens, user wallets, or digital asset transfers** to the MLRO. The MLRO will escalate and report such activities to the **FIA**.

***

### 2. Compliance Monitoring

The **Board of GDB** oversees AML/CFT arrangements. The **Compliance Officer**, supported by external advisors if required, is responsible for:

* Enforcing this AML/CFT policy across all GDB operations (issuance, trading, custody, redemption).
* Maintaining and updating internal controls in line with FSC and FATF requirements.
* Identifying compliance risks specific to **digital assets and sovereign bond tokenization**.
* Conducting compliance monitoring programs and periodic reviews.
* Ensuring accurate and timely filing of reports with regulators.
* Addressing breaches, incidents, and reporting findings to the Board.

***

### 3. Client Onboarding: Know Your Customer (KYC)

#### 3.1 KYC for New Accounts

All **investors, wallet-holders, and platform participants** must undergo KYC before accessing GDB’s products (e.g., GDB governance token purchases, GDO bond package subscriptions).

Required data:

* Full legal name (and aliases if applicable).
* National ID, passport, or incorporation/business registration number.
* Residential or business address.
* Date of birth or incorporation.
* Nationality or jurisdiction of incorporation.

#### 3.2 Legal Entities

For corporate clients, GDB requires:

* Identification of ownership, governance, and control structures.
* Identification of connected parties (directors, beneficial owners).
* Proof of incorporation, existence, and powers.

#### 3.3 Authorized Representatives

Where natural persons act on behalf of legal entities, GDB verifies:

* Identity (full name, ID/passport, residential address, date of birth).
* Authority (board resolution, mandate, power of attorney).
* Specimen signatures.

#### 3.4 Ongoing Monitoring

* All **wallets and transactions** are continuously monitored for suspicious activity.
* **Biennial reviews** of standard-risk clients’ CDD data; **annual reviews** for high-risk.
* Enhanced monitoring applied to complex or unusual on-chain transactions.

***

### 4. Anti-Money Laundering & Counter-Terrorist Financing (AML/CFT)

* GDB Platform adopts a **risk-based approach** to assess AML/CFT risks of investors, products, jurisdictions, and token flows.
* All risks are documented, updated annually, and approved by the Board.
* GDB aligns with **FATF recommendations** for virtual asset service providers (VASPs), including the **Travel Rule** for transactions over USD 1,000.

***

### 5. GDB’s Responsibilities

* Exercise due diligence for all **GDB/GDO wallet-holders and participants**.
* Conduct operations in line with **high ethical standards**.
* Avoid onboarding clients or processing transactions linked to money laundering or terrorist financing.
* Cooperate fully with global regulators and law enforcement in relevant jurisdictions.

***

### 6. Risk-Based Approach

* Each investor is assigned a **risk rating** (low, medium, high).
* Risk factors include nationality, industry, PEP status, wallet activity, and transaction patterns.
* Reviews:
  * Low risk: every 3 years
  * Medium risk: every 2 years
  * High risk: annually
* GDB also conducts **enterprise-wide AML risk assessments** every 2 years.

***

### 7. Onboarding Approval

Before onboarding, GDB requires:

* Client profile and account opening forms
* Identification of connected/authorized persons
* Beneficial ownership declaration
* Screening against sanctions and watchlists
* Enhanced Due Diligence for high-risk clients (Board approval required)
* Compliance with **Travel Rule** for crypto transactions > USD 1,000

***

### 8. Customer Due Diligence (CDD)

* **Beneficial Owners:** Identify ultimate beneficial owners (UBOs) in all legal persons.
* **Simplified CDD:** Allowed only for low-risk clients and not for high-risk jurisdictions.
* **Enhanced CDD:** Mandatory for PEPs, high-risk jurisdictions, and suspicious clients. Includes Board approval, proof of source of wealth/funds, and intensified monitoring.
* **Screening:** Continuous screening against global AML/CTF lists and wallet-risk databases (e.g., blockchain analytics providers).

***

### 9. Record-Keeping

* GDB maintains records of all **wallet addresses, transactions, CDD files, and risk assessments** for at least **5 years** post-termination of business.
* All records are securely stored and easily retrievable for regulatory inspection.

***

### 10. Suspicious Transaction Reporting

* Employees must escalate suspicious **on-chain transfers, unusual redemption patterns, or wallet activities**.
* MLRO assesses objectively and reports to the **FIA** when warranted.
* Examples of red flags:
  * Unusually large GDB/GDO transfers.
  * Attempted anonymous trades or unverified wallets.
  * Transactions involving high-risk jurisdictions.
  * Use of mixing services or privacy coins linked to GDB wallets.

***

### 11. Staff Training

* All staff and relevant technical operators must undergo **annual AML/CFT training**.
* Training covers AML regulations, blockchain-specific red flags, and GDB internal procedures.
* Knowledge testing is conducted periodically to ensure staff readiness.

***

✅ This version preserves **regulatory compliance detail** but adapts it to the **GDB digital bond platform**, with explicit mention of **GDB/GDO tokens, wallets, and exchanges**.
