AML Policy
Introduction
Citobet is operated by Gamerly Holding Ltd, a company registered at PO Box 1212, Hamchako, Mutsamudu, Autonomous Island of Anjouan, Union of Comoros, under Company Registration Number 16003.
Citobet is committed to preventing money laundering, terrorist financing, fraud, and any other illegal activities through the implementation of effective internal controls, procedures, and monitoring systems.
AML Policy Objectives and Framework
The objective of this AML Policy is to ensure a high level of security for all users of Citobet and to prevent the misuse of the platform for money laundering, terrorist financing, or other illicit activities.
To support this objective, Citobet has implemented a risk-based customer verification (KYC) process, including a multi-level account verification system designed to confirm customer identity, validate registration details, and verify the legitimacy of payment methods used for deposits and withdrawals.
Citobet applies a risk-based approach, taking into account factors such as the customer's jurisdiction, source of funds, transaction patterns, and payment methods, in order to determine the appropriate level of due diligence and monitoring.
The Company is committed to implementing appropriate controls and dedicating sufficient resources to identify, assess, and mitigate money laundering risks.
Citobet maintains AML standards in line with internationally recognized principles and applicable regulatory requirements. All employees, management, and relevant stakeholders are required to adhere to these standards and to support the prevention, detection, and reporting of suspicious activities.
Regulatory Compliance
The AML program of Citobet is designed to align with internationally recognized anti-money laundering (AML) and counter-terrorist financing (CTF) standards, including, where applicable, the following regulatory frameworks:
- European Union (EU): Directive (EU) 2015/849 on the prevention of the use of the financial system for the purposes of money laundering and terrorist financing;
- European Union (EU): Regulation (EU) 2015/847 on information accompanying transfers of funds;
- European Union (EU): applicable sanctions regimes and restrictive measures, including those relating to embargoed jurisdictions, individuals, and dual-use goods;
- Belgium (BE): Law of 18 September 2017 on the prevention of money laundering and the limitation of the use of cash (where relevant).
Citobet applies these standards in a risk-based manner, taking into account the nature of its operations, customer base, and applicable licensing requirements.
Definition of Money Laundering
For the purposes of this Policy, money laundering includes, but is not limited to, the following activities:
- The conversion or transfer of property, including funds, knowing or suspecting that such property is derived from criminal activity, for the purpose of concealing or disguising its illicit origin or assisting any person involved in such activity to evade legal consequences;
- The concealment or disguise of the true nature, source, location, disposition, movement, ownership, or rights related to property, knowing or suspecting that such property is derived from criminal activity;
- The acquisition, possession, or use of property, knowing or suspecting at the time of receipt that such property was derived from criminal activity;
- Participation in, association with, attempts to commit, or aiding, abetting, facilitating, or advising the commission of any of the activities described above.
Money laundering shall be considered as such regardless of whether the underlying criminal activity occurred within the same jurisdiction or in another jurisdiction.
AML Governance and Organization
In accordance with applicable AML and counter-terrorist financing (CTF) requirements, Citobet has established an internal governance framework to prevent, detect, and manage risks related to money laundering and other financial crimes.
Ultimate responsibility for AML compliance rests with the management of Gamerly Holding Ltd, which oversees the implementation and effectiveness of AML controls across the organization.
Citobet has appointed an Anti-Money Laundering Compliance Officer (AMLCO), who is responsible for the day-to-day implementation, monitoring, and enforcement of AML policies and procedures. The AMLCO operates independently and reports directly to senior management.
The AMLCO's responsibilities include, but are not limited to:
- Monitoring compliance with AML and CTF obligations;
- Overseeing customer due diligence (CDD) and enhanced due diligence (EDD) processes;
- Reviewing and escalating suspicious activity where appropriate;
- Ensuring staff awareness and adherence to AML procedures.
AML Policy Changes and Implementation
Material changes to this AML Policy must be reviewed and approved by senior management of Gamerly Holding Ltd and the Anti-Money Laundering Compliance Officer (AMLCO).
Customer Verification Procedures (KYC)
Citobet applies a risk-based, multi-level customer verification process to comply with AML and KYC requirements.
Step 1: Basic Customer Identification
Step 1 verification must be completed by all customers prior to initiating any withdrawal. Customers are required to provide accurate personal information, including:
- First name;
- Last name;
- Date of birth;
- Country of residence;
- Residential address.
Citobet reserves the right to request supporting documentation to validate this information where necessary.
Step 2: Identity Verification
Step 2 verification is required where cumulative deposits or withdrawals exceed €/$2,000, or where risk factors indicate the need for additional due diligence. Until Step 2 verification is completed, withdrawals may be suspended and deposits may be restricted.
To complete this step, customers must submit a valid government-issued identification document. Citobet may require additional verification measures, including a photograph (selfie) of the customer holding the ID document.
Citobet may perform electronic verification checks using reliable data sources. Where such verification is unsuccessful or not possible, customers may be required to provide additional documentation, including proof of address or equivalent official records.
Step 3: Enhanced Due Diligence (EDD)
Step 3 verification applies where cumulative deposits or withdrawals exceed €/$5,000, or where higher risk is identified. In such cases, customers may be required to provide documentation evidencing the source of funds and/or source of wealth. Until Enhanced Due Diligence is completed, transactions may be delayed, restricted, or declined.
Customer Identification and Verification (KYC)
Customer identification is a fundamental requirement of Citobet's AML framework and is conducted prior to establishing a business relationship and/or processing withdrawals. Citobet applies a risk-based approach to identity verification and may request additional documentation where necessary.
Identification Requirements
To verify identity, customers must provide a valid government-issued identification document, such as a Passport, National ID card, or Driving Licence. The following requirements apply:
- The document must be valid and not expired;
- The document must clearly display the customer's full name, date of birth, photograph, and, where applicable, signature;
- All four corners of the document must be visible, and the image must be clear and legible;
- Citobet may require a photograph (selfie) of the customer holding the identification document to confirm ownership;
- Citobet reserves the right to request unredacted copies of identification documents where necessary for compliance purposes.
Additional verification checks may be conducted depending on the customer's risk profile, transaction activity, or other relevant factors.
Proof of Address
Citobet may verify a customer's residential address through electronic verification checks using reliable and independent data sources. Where electronic verification is unsuccessful or not possible, customers may be required to provide manual proof of address. Accepted documents include:
- A recent utility bill issued within the last three (3) months;
- A bank or credit card statement issued within the last three (3) months;
- An official government-issued document confirming the customer's residential address.
All documents must clearly display the customer's full name and residential address, be fully visible with all four corners shown, and be clear, legible, and submitted in high resolution. Citobet reserves the right to request additional documentation or perform further verification checks where necessary.
Source of Funds and Source of Wealth
Citobet may require customers to provide information and/or documentation regarding the Source of Funds (SoF) and/or Source of Wealth (SoW) where deposits or cumulative transactions exceed €/$5,000, or where risk factors indicate the need for enhanced due diligence. Examples of Source of Wealth may include:
- Employment income;
- Business ownership or commercial activities;
- Investments or savings;
- Inheritance;
- Family or third-party contributions (where permitted and verified).
Customers may be required to provide supporting documentation to substantiate the origin and legitimacy of funds used. Where sufficient information or documentation is not provided, Citobet reserves the right to restrict, suspend, or temporarily freeze the account and/or transactions until verification is completed. Citobet may also request additional payment method verification, including bank or card details, where necessary to confirm the legitimacy of transactions and the identity of the customer.
Risk Management
Citobet applies a risk-based approach to customer due diligence, taking into account factors such as jurisdiction, payment methods, transaction behavior, and source of funds. Customers may be classified into different risk categories (low, medium, or high risk), and the level of due diligence applied will vary accordingly.
Low-Risk Customers
Customers assessed as low risk are subject to standard customer due diligence (CDD), including basic identification and verification procedures as outlined in this Policy.
Medium-Risk Customers
Customers assessed as medium risk may be subject to enhanced monitoring and earlier application of additional verification measures, including identity verification and source of funds checks at lower transaction thresholds. Triggers for additional verification may include, but are not limited to:
- Increased transaction volumes;
- Use of certain payment methods (including cryptocurrencies);
- Behavioral or transactional risk indicators.
High-Risk Customers
Customers identified as high risk may be subject to Enhanced Due Diligence (EDD), including detailed verification of identity, source of funds, and source of wealth, as well as ongoing monitoring of account activity. Citobet reserves the right to restrict, suspend, or terminate accounts associated with jurisdictions or activities deemed high risk, in accordance with applicable laws, sanctions, and regulatory requirements.
Additional Measures
Citobet implements automated and manual monitoring systems to detect unusual or suspicious activity. These systems operate under the oversight of the Anti-Money Laundering Compliance Officer (AMLCO). All automated monitoring outputs are subject to review by trained personnel. Citobet reserves the right to conduct additional checks and request further documentation based on the customer's risk profile, transaction behavior, or other relevant indicators. Monitoring procedures may include the identification of:
- Unusual transaction patterns, including deposits and withdrawals with limited or no genuine gameplay;
- Use of multiple or inconsistent payment methods;
- Significant changes in customer behavior, jurisdiction, or activity patterns;
- Indicators suggesting that an account may not be operated by the registered account holder.
Where required for AML purposes, Citobet may restrict withdrawals to the original payment method used for deposits, subject to operational and regulatory constraints.
Enterprise-Wide Risk Assessment (EWRA)
As part of its risk-based AML framework, Citobet conducts an Enterprise-Wide Risk Assessment (EWRA) to identify, evaluate, and mitigate risks associated with its operations. The EWRA considers, among other factors:
- The nature of the services offered;
- The customer base and user profiles;
- Transaction types and volumes;
- Delivery channels and technologies used;
- Geographic exposure, including customer and transaction locations;
- Emerging and evolving risk factors.
AML risk categories are defined based on applicable regulatory requirements, industry standards, and internal risk assessments. Appropriate controls and mitigation measures are implemented to address identified risks, particularly those associated with remote and online operations. The EWRA is reviewed and updated on a periodic basis, at least annually or when material changes occur.
Ongoing Transaction Monitoring
Citobet conducts ongoing transaction monitoring to identify, assess, and report transactions that are unusual or inconsistent with a customer's known profile, behavior, or source of funds. Monitoring is performed in accordance with a risk-based approach and applies throughout the entire customer lifecycle.
First Line of Defense: Payment Controls
Citobet collaborates with regulated and reputable Payment Service Providers (PSPs) that maintain appropriate AML and KYC controls. These controls contribute to the prevention of suspicious or unauthorized transactions and support the verification of customer identity prior to the execution of financial transactions.
Second Line of Defense: Operational Monitoring and Compliance Oversight
Citobet ensures that relevant personnel are trained to identify and escalate potentially suspicious activity. Monitoring includes, but is not limited to:
- Customer requests involving financial transactions or account changes;
- Use of payment methods and related account activity;
- Transaction patterns inconsistent with the customer's profile or expected behavior.
Customer activity is reviewed in the context of KYC information, transaction history, and known financial behavior. Automated monitoring systems perform initial screening, followed by manual review where necessary. Any transaction that cannot be reasonably justified in terms of lawful activity or source of funds shall be treated as potentially suspicious and escalated to the AML Compliance function. All employees are required to promptly report such activity in accordance with internal AML procedures.
Third Line of Defense: Enhanced Review and Escalation
Citobet performs enhanced manual reviews of high-risk accounts and flagged transactions. Where there is reasonable suspicion of money laundering, fraud, or other financial crime, Citobet reserves the right to take appropriate action, including account restriction or suspension, and to report the matter to the relevant authorities in accordance with applicable laws and regulatory obligations.
Reporting of Suspicious Transactions
Citobet maintains internal procedures for the identification, assessment, and reporting of suspicious transactions, in accordance with applicable AML and counter-terrorist financing (CTF) requirements. All employees are required to promptly report any activity that appears unusual, inconsistent, or suspicious to the AML Compliance function.
Reporting Procedures
All reported transactions are reviewed and assessed by the AML team in accordance with established internal procedures and a risk-based methodology. Based on the outcome of the assessment, Citobet may:
- Submit a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) to the relevant Financial Intelligence Unit (FIU), in accordance with applicable legal and regulatory obligations;
- Apply appropriate risk mitigation measures, including restricting or suspending the account;
- Terminate the business relationship with the customer where deemed necessary.
All reporting decisions are documented and handled in accordance with confidentiality and data protection requirements.
Operational Guidance
AML policies and procedures, including minimum KYC and due diligence standards, are translated into internal operational guidelines available to relevant personnel. All employees are required to adhere to these procedures in the performance of their duties and to ensure compliance with applicable AML and CTF requirements.
Record Keeping
Citobet maintains records in accordance with applicable legal and regulatory requirements.
- Customer Identification Data: records obtained for identification and verification purposes are retained for a minimum of ten (10) years following the end of the business relationship.
- Transaction Data: records of transactions are retained for a minimum of ten (10) years from the date of the transaction or termination of the business relationship, whichever is later.
All records are stored securely using appropriate technical and organizational measures, including encryption and access controls, to protect sensitive information.
Training and Awareness
Citobet maintains an ongoing AML and counter-terrorist financing (CTF) training program to ensure that all relevant employees are aware of their legal obligations and internal procedures. The training program includes:
- Mandatory AML and CTF training for all employees involved in customer handling, financial operations, and compliance functions;
- Induction training for all new employees, covering core AML and KYC principles and internal procedures;
- Role-based training tailored to specific responsibilities and risk exposure;
- Periodic refresher training to reflect regulatory developments and emerging risks.
Training is delivered by qualified personnel and/or AML specialists within Gamerly Holding Ltd or external providers, as appropriate.
Auditing
Citobet conducts periodic internal audits of its AML and counter-terrorist financing (CTF) framework to ensure compliance with applicable requirements and internal policies. The audit function operates independently and evaluates the effectiveness of AML controls, procedures, and monitoring systems. Audit findings are documented and reported to senior management, and appropriate corrective actions are implemented where necessary.
Data Security
Citobet implements appropriate technical and organizational measures to ensure the security, integrity, and confidentiality of all customer data. Customer data will not be sold or disclosed to third parties, except where required for regulatory compliance, including AML and CTF obligations, fraud prevention, or where disclosure is mandated by applicable law or competent authorities. Personal data is processed in accordance with applicable data protection laws and regulations, including the General Data Protection Regulation (EU) 2016/679 (GDPR), where applicable.
Contact Us
For any questions regarding this AML and KYC Policy, you may contact Citobet at [email protected].
For complaints related to AML and KYC procedures, account verification, or the processing of personal data, you may also contact [email protected]. All inquiries and complaints will be handled in accordance with applicable regulatory requirements and internal procedures.