AML/CTF & Financial Crime Prevention Manual

Part I – Governance · Version 1.0 (Draft)

§

1. Purpose

This Manual establishes the Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF), sanctions compliance and financial crime prevention framework for Zagono.

Its purpose is to prevent the Platform from being used for money laundering, terrorist financing, fraud, sanctions evasion, payment abuse and other illicit financial activity.

This Manual complements the Terms & Conditions, Privacy Policy, KYC Policy, Responsible Gaming Policy and related compliance documents.

All personnel and users are expected to comply with this Manual.

§

2. Scope

This Manual applies to Academy Mode, Real Mode, G2F Wallet, tournaments, public and private battles and future services.

It applies to users, employees, contractors, directors, affiliates, payment providers and relevant third parties.

It covers all supported payment methods including cards, bank transfers, digital wallets and supported crypto assets.

§

3. Definitions

  • AML – Anti-Money Laundering.
  • CTF – Counter-Terrorist Financing.
  • CDD – Customer Due Diligence.
  • EDD – Enhanced Due Diligence.
  • PEP – Politically Exposed Person.
  • MLRO – Money Laundering Reporting Officer.
  • G2F Wallet – Zagono's internal wallet.
  • Suspicious Activity – behaviour indicating possible financial crime.
§

4. Regulatory Framework

The Company seeks to maintain a compliance programme aligned with internationally recognised AML/CTF standards.

Policies shall be updated to reflect applicable legal and regulatory requirements in jurisdictions where the Platform lawfully operates.

Where multiple standards apply, the higher compliance standard should be adopted where reasonably practicable.

§

5. Compliance Governance

Senior management is responsible for establishing and maintaining an effective compliance culture.

Compliance controls shall be risk-based and proportionate.

Policies shall be reviewed periodically and updated following legal, operational or technological changes.

§

6. MLRO

The Company shall appoint an appropriately qualified Money Laundering Reporting Officer.

The MLRO oversees investigations, regulatory reporting, internal escalation and policy implementation.

The MLRO shall have sufficient authority and independence to perform these duties.

§

7. Compliance Responsibilities

Employees must report suspected financial crime through approved internal channels.

Users must cooperate with lawful verification and compliance requests.

Breaches may result in suspension, termination, reporting to competent authorities or other lawful action.

§

8. Enterprise Risk Assessment

Zagono shall maintain an enterprise-wide AML/CTF risk assessment that is reviewed at least annually and whenever significant operational, legal or technological changes occur.

The assessment shall evaluate inherent and residual risks associated with customers, products, payment methods, jurisdictions, tournaments, virtual assets and third-party service providers.

The outcome of each assessment shall determine the level of monitoring, due diligence and internal controls applied.

§

9. Customer Risk Classification

All Users shall be assigned a dynamic risk rating.

Risk categories include Low, Medium, High and Critical.

Risk scores may consider identity verification status, transaction history, withdrawal behaviour, payment methods, account age, device intelligence, behavioural indicators and previous compliance events.

High-risk customers may be subject to Enhanced Due Diligence (EDD), transaction limits and manual approval.

§

10. Geographic Risk

The Company shall evaluate the money laundering and sanctions risk associated with each jurisdiction.

Factors include FATF publications, sanctions programmes, corruption indices, financial crime statistics and local regulatory requirements.

Access from prohibited or sanctioned jurisdictions may be blocked or restricted.

§

11. Product & Service Risk

Different Platform products present different financial crime risks.

Academy Mode is generally lower risk because Academy Tokens have no cash redemption value.

Real Mode, prize payouts, tournaments, the G2F Wallet and virtual asset transactions require enhanced monitoring due to their higher financial exposure.

§

12. Payment Method & Cryptocurrency Risk

Payment methods shall be risk-rated based on fraud exposure, chargeback history and regulatory considerations.

Card payments, bank transfers, digital wallets, stablecoins and other supported payment methods may each be subject to different controls.

Transactions involving virtual assets may require blockchain analytics, wallet screening, source-of-funds reviews and additional verification before processing.

§

13. Tournament & Platform Integrity Risk

The Company shall assess the risk of match-fixing, collusion, intentional losing, account sharing, prize laundering and other manipulation affecting competitive integrity.

AI-assisted monitoring, behavioural analytics and manual investigations may be used to identify elevated risks.

Risk indicators shall be reviewed continuously and escalated where suspicious behaviour is identified.

§

14. Risk Escalation & Review

Material AML risks shall be escalated to the Compliance Function or MLRO without undue delay.

Risk assessments shall be documented and retained in accordance with the Company's record retention requirements.

This Risk Management framework shall be reviewed periodically to ensure it remains appropriate for the Company's products, jurisdictions and regulatory obligations.

§

15. Customer Identification

Every User must register using accurate, complete and current personal information.

Anonymous, fictitious or misleading registrations are prohibited.

The Company may refuse registration where identity cannot be reasonably established or where registration presents an unacceptable compliance risk.

§

16. Identity Verification (KYC)

Identity verification shall be performed using a risk-based approach.

The Company may utilise specialised identity verification providers, including biometric verification, liveness detection and document authentication.

Users may be required to provide government-issued identification, selfies, proof of identity and other supporting documentation.

The Company may suspend or restrict an Account until verification has been successfully completed.

§

17. Age Verification

Only individuals meeting the minimum legal participation age may use the Platform.

Age verification may be performed during registration or at any later stage before deposits, competition participation or withdrawals.

Accounts belonging to underage individuals shall be permanently closed in accordance with applicable law.

§

18. Address Verification

The Company may request proof of residential address where required for regulatory or risk management purposes.

Acceptable documentation may include utility bills, bank statements or official government correspondence issued within an acceptable period.

Failure to provide satisfactory proof of address may delay withdrawals or restrict Platform functionality.

§

19. Source of Funds & Source of Wealth

The Company may require Users to demonstrate the legitimate origin of funds used on the Platform.

Enhanced verification may include employment information, bank statements, tax records, business ownership documentation or other reasonable evidence.

Source of Wealth reviews may be conducted for higher-risk customers or where transaction patterns justify additional scrutiny.

§

20. Enhanced Due Diligence (EDD)

EDD shall be applied where elevated AML or financial crime risks are identified.

Triggers may include high transaction volumes, PEP status, sanctions exposure, adverse media, complex ownership structures, cryptocurrency risk indicators or suspicious behaviour.

Additional monitoring and management approval may be required before continued use of the Platform.

§

21. Ongoing Due Diligence

Customer profiles shall be reviewed throughout the business relationship.

The Company may periodically refresh customer information and request updated documentation.

Ongoing monitoring includes transaction analysis, behavioural monitoring, device intelligence, payment monitoring and risk reassessment.

Where inconsistencies are identified, the Company may escalate the matter for further investigation.

§

22. Sanctions Compliance Framework

Zagono shall maintain a sanctions compliance programme designed to prevent the Platform from being used by sanctioned persons, entities or jurisdictions.

The Company shall perform sanctions screening before permitting higher-risk activities and may repeat screening throughout the customer relationship.

The Company may refuse service, suspend accounts or freeze transactions where required by applicable law or contractual obligations with payment providers.

§

23. International Sanctions Screening

Screening may include applicable sanctions lists issued by the United Nations, the European Union, the United Kingdom, the United States (OFAC) and other relevant authorities.

Screening shall also consider local legal requirements applicable to the Company's operating jurisdictions.

Positive matches shall be reviewed by Compliance before any decision is taken.

§

24. FATF High-Risk Jurisdictions

The Company shall consider publications issued by the Financial Action Task Force (FATF) when assessing geographic risk.

Customers connected to jurisdictions identified as high-risk or subject to enhanced monitoring may be required to undergo Enhanced Due Diligence.

The Company may prohibit access from jurisdictions presenting unacceptable legal or financial crime risks.

§

25. Politically Exposed Persons (PEPs)

Zagono shall identify Politically Exposed Persons (PEPs), their family members and known close associates using risk-based screening.

PEP status does not automatically prevent use of the Platform; however, it requires Enhanced Due Diligence, ongoing monitoring and, where appropriate, senior management approval.

PEP reviews shall be refreshed periodically during the customer relationship.

§

26. Adverse Media & Reputation Screening

Compliance may review reliable public information relating to allegations or findings of fraud, corruption, organised crime, money laundering, sanctions evasion or terrorist financing.

Adverse media findings shall be evaluated together with other risk indicators and shall not be relied upon in isolation.

Material findings may result in additional verification, transaction restrictions or account suspension pending investigation.

§

27. Escalation & Record Keeping

Potential sanctions or PEP matches shall be escalated to the Compliance Function or MLRO for assessment.

Decisions, supporting evidence and rationale shall be documented and retained in accordance with the Company's record retention policy.

Where legally required, the Company shall report relevant matters to competent authorities and comply with asset-freezing or reporting obligations.

§

28. Transaction Monitoring Framework

Zagono shall maintain a risk-based transaction monitoring programme designed to detect unusual, suspicious or prohibited financial activity.

Monitoring shall apply to deposits, withdrawals, internal wallet activity, prize distributions and other financial transactions processed through the Platform.

Automated monitoring shall be supplemented by manual compliance reviews where appropriate.

§

29. Behavioural Monitoring

The Platform may analyse customer behaviour to identify indicators of fraud, money laundering, collusion or account misuse.

Behavioural indicators may include abnormal gameplay, unusual login activity, inconsistent entry fee patterns, rapid balance movements, repeated failed payments and other anomalies.

Behavioural monitoring shall be proportionate and conducted in accordance with applicable data protection laws.

§

30. Device, Network & IP Intelligence

The Company may utilise device fingerprinting, IP intelligence, browser analysis and geolocation technologies to assess financial crime risk.

The use of VPNs, proxy services, anonymisation tools or other methods intended to conceal a user's true location may result in enhanced monitoring or account restrictions.

Device and network intelligence may be combined with other risk indicators when determining customer risk.

§

31. Payment & Wallet Monitoring

All deposits and withdrawals shall be monitored for suspicious patterns.

Monitoring may include rapid deposit-withdrawal activity, multiple payment instruments, payment reversals, unusual funding sources, high-value transactions and wallet abuse.

Transactions may be delayed or suspended pending completion of compliance reviews.

§

32. Tournament & Prize Monitoring

Zagono shall monitor tournaments and prize distributions for evidence of financial crime or manipulation.

Monitoring includes match-fixing, intentional losing, prize laundering, collusion, account sharing, boosting and suspicious tournament behaviour.

Where integrity concerns are identified, prizes may be withheld until investigations are concluded.

§

33. AI-Assisted Fraud Detection & Escalation

The Company may employ artificial intelligence, machine learning and rule-based detection systems to identify elevated financial crime risk.

AI-generated alerts shall be reviewed by appropriately trained personnel before material compliance decisions are made.

Confirmed suspicious activity shall be escalated to the Compliance Function or MLRO for further investigation and any required reporting.

§

34. Purpose and Scope of Virtual Asset Controls

This Part establishes the compliance framework governing the use of cryptocurrencies, stablecoins, virtual assets and the G2F Wallet.

These controls are intended to reduce the risk of money laundering, terrorist financing, sanctions evasion, fraud and other illicit financial activity involving digital assets.

The Company shall review these controls periodically to reflect regulatory developments and emerging financial crime typologies.

§

35. G2F Wallet Governance

The G2F Wallet is an internal ledger used to record eligible customer balances and transactions.

The G2F Wallet is not a bank account, payment account or regulated deposit account.

Wallet balances do not accrue interest and are subject to these Terms, the Platform Terms & Conditions and applicable law.

The Company reserves the right to freeze, restrict or suspend wallet functionality where required for compliance purposes.

§

36. Cryptocurrency Deposits and Withdrawals

The Company may support selected cryptocurrencies or stablecoins through approved payment providers.

Every cryptocurrency transaction may be subject to blockchain analytics, sanctions screening, wallet risk assessment and source-of-funds verification.

The Company may reject, delay or suspend any cryptocurrency transaction that presents an elevated financial crime risk.

§

37. Blockchain Analytics & Wallet Risk

The Company may utilise blockchain analytics solutions to assess wallet risk.

Wallets associated with ransomware, darknet marketplaces, sanctioned entities, mixers, terrorist financing or other prohibited activity may be blocked.

Compliance personnel may request additional information regarding the origin or destination of virtual assets.

§

38. Stablecoins, Tokenised Assets & G2F Tokens

Stablecoins accepted by the Platform shall be subject to the same AML and sanctions controls as fiat transactions.

G2F Tokens and other virtual assets supported by the Platform shall be monitored for suspicious activity.

The Company reserves the right to impose transaction limits or additional verification requirements for virtual asset activity.

§

39. Travel Rule, Record Keeping & Compliance

Where legally applicable, the Company shall comply with virtual asset transfer information requirements commonly referred to as the 'Travel Rule'.

Records relating to cryptocurrency transactions shall be retained in accordance with applicable AML legislation and internal record retention policies.

Compliance personnel shall periodically review virtual asset controls to ensure their continued effectiveness.

§

40. Financial Crime Investigations

The Company shall investigate suspected money laundering, terrorist financing, fraud, sanctions breaches, payment abuse and other financial crime in a timely, risk-based manner.

Investigations may be initiated through automated monitoring, employee reports, customer complaints, payment provider notifications, AI-generated alerts or regulatory requests.

Every investigation shall be assigned a unique case reference and documented from initiation through closure.

§

41. Suspicious Activity Identification

Employees and automated systems shall identify activity that appears unusual, inconsistent with the customer's known profile or indicative of financial crime.

Indicators include unusual transaction patterns, account takeovers, multiple accounts, chargeback abuse, prize laundering, match-fixing, identity inconsistencies, sanctioned wallet interaction and other risk indicators.

Suspicion does not require proof of criminal activity before escalation.

§

42. Escalation Procedures

Suspected financial crime shall be escalated immediately to the Compliance Function or MLRO.

High-risk matters may result in temporary account restrictions, wallet freezes, delayed withdrawals or suspension of tournament participation pending investigation.

Escalation decisions shall be recorded together with supporting evidence and rationale.

§

43. Suspicious Activity Reporting (SAR)

Where required by applicable law, the Company shall submit Suspicious Activity Reports (SARs) or equivalent reports to the competent authority.

Employees shall not disclose to customers that a SAR has been submitted where such disclosure is prohibited by law (tipping-off prohibition).

Regulatory reporting shall be performed only by authorised compliance personnel.

§

44. Evidence Management & AI-Assisted Investigations

Investigations may rely upon payment records, blockchain analytics, tournament logs, gameplay telemetry, device intelligence, API results, chat logs and other lawful evidence.

AI systems may assist in prioritising alerts and identifying behavioural anomalies; however, material compliance decisions shall be reviewed by trained personnel.

Evidence shall be retained securely in accordance with the Company's record retention policy.

§

45. Appeals, Case Closure & Record Retention

Users may submit an appeal where permitted under the Platform's dispute procedures.

Compliance shall document investigation outcomes, actions taken and the basis for closing each case.

Investigation records shall be retained for the period required by applicable law and internal policy, after which they shall be securely archived or disposed of.

§

46. Regulatory Reporting

The Company shall comply with all applicable legal obligations relating to the reporting of suspicious activities, sanctions matters and other reportable financial crime events.

Regulatory reports shall only be submitted by authorised compliance personnel or the MLRO.

Reporting decisions shall be documented and supported by appropriate evidence.

§

47. Record Retention

The Company shall maintain complete and accurate records relating to customer identification, KYC, transactions, investigations, sanctions screening and compliance decisions.

Records shall be retained for the minimum period required by applicable law and contractual obligations.

At the end of the retention period, records shall be securely archived or destroyed in accordance with the Company's data retention policy.

§

48. Audit Trail & Evidence Integrity

Compliance activities shall be supported by a secure audit trail recording material actions, approvals and investigations.

Audit records shall be protected against unauthorised alteration or deletion.

Electronic logs may be used to demonstrate compliance with regulatory obligations and internal policies.

§

49. Independent Review & Internal Audit

The AML/CTF programme shall be subject to periodic independent review.

Reviews shall assess the effectiveness of governance, customer due diligence, transaction monitoring, sanctions controls, reporting procedures and financial crime investigations.

Findings shall be reported to senior management together with corrective action plans where appropriate.

§

50. Regulatory Inspections & Cooperation

The Company shall cooperate with competent authorities, payment service providers and authorised auditors where legally required.

Requested records shall be produced in accordance with applicable law while protecting customer confidentiality.

Regulatory enquiries and inspections shall be coordinated through the Compliance Function.

§

51. Continuous Improvement

Compliance metrics, audit findings, emerging threats and regulatory developments shall be used to improve the AML/CTF programme.

Policies, procedures and controls shall be reviewed on a regular basis to ensure they remain effective, proportionate and aligned with business operations.

§

52. AML/CTF Training Programme

Zagono shall maintain a structured AML/CTF training programme for all relevant employees, contractors and compliance personnel.

Training shall be risk-based and proportionate to each individual's responsibilities.

Topics include AML/CTF obligations, sanctions, fraud prevention, KYC, suspicious activity identification, data protection, tournament integrity, payment fraud and internal reporting procedures.

§

53. Role-Specific Competency Requirements

Personnel performing compliance-sensitive functions shall receive additional specialised training.

Compliance staff, investigators, customer support, finance personnel and senior management shall receive role-specific instruction relevant to their responsibilities.

Completion of mandatory training may be documented and periodically reassessed.

§

54. Policy Governance & Review

This Manual shall be reviewed at least annually or sooner where material regulatory, operational or technological changes occur.

Proposed amendments shall be approved through the Company's governance process.

Superseded versions shall be retained in accordance with the Company's record retention policy.

§

55. Management Oversight

Senior management is responsible for ensuring adequate AML/CTF resources, staffing and governance.

Periodic compliance reports shall be presented to management, including key risks, investigations, training completion, audit findings and remediation progress.

Material deficiencies shall be addressed through documented corrective action plans.

§

56. Compliance Culture & Whistleblowing

The Company encourages a culture of integrity, transparency and lawful conduct.

Employees may report suspected misconduct through approved confidential reporting channels without fear of retaliation, subject to applicable law.

Reports shall be reviewed impartially and investigated where appropriate.

§

57. Version Control & Document Management

Each edition of this Manual shall include version information, approval dates and document ownership.

Changes shall be documented in a revision history to support auditability.

Controlled copies shall be maintained to ensure employees access the current approved version.

§

58. Financial Crime Risk Indicators

The Company shall maintain a catalogue of financial crime indicators to support proactive monitoring.

Examples include rapid deposits followed by withdrawals, repeated payment failures, multiple accounts linked to the same device, unusual tournament outcomes, prize laundering, sanctioned wallet interactions, identity inconsistencies and abnormal behavioural patterns.

Risk indicators shall be reviewed periodically to address emerging threats.

§

59. Operational Escalation Matrix

Compliance alerts shall be categorised according to severity (Low, Medium, High and Critical).

High and Critical alerts shall be escalated promptly to the MLRO or authorised Compliance personnel.

Escalation procedures shall define ownership, response times, documentation standards and approval requirements.

§

60. Key Compliance Metrics

The Company shall maintain measurable compliance indicators including KYC completion rates, sanctions screening statistics, investigation volumes, SAR submissions, training completion, payment fraud rates and audit findings.

Metrics shall be reviewed by management to assess programme effectiveness and identify areas requiring improvement.

§

61. External Service Providers

The Company may utilise specialist providers for identity verification, sanctions screening, payment processing, blockchain analytics, fraud detection and compliance technology.

Third-party providers shall be subject to appropriate due diligence, contractual controls and periodic performance reviews.

§

62. Document Ownership & Approval

This Manual shall be owned by the Company's Compliance Function.

Material amendments require approval through the Company's governance framework.

Each published version shall include an effective date, version number and revision history.

§

63. Final Provisions

This Manual forms part of Zagono's wider compliance framework and shall be read together with all related policies.

Nothing in this Manual limits the Company's ability to implement additional controls where required by law, regulatory expectations, payment service providers or risk assessments.

Still have questions?

If you have any questions about this policy, please contact our Compliance team.

Contact Support

This policy may be updated from time to time. Please review periodically for changes.