1. Status and scope
This page is a detailed policy structure for legal, compliance, and operational review. It is not evidence that a specific Wolf Markets entity is licensed, supervised, or currently operating the controls described.
The final policy must identify the legal entity, regulator or AML supervisor, applicable laws, countries served, products, customer types, MLRO or nominated officer, approval owner, effective date, and review cycle.
2. Purpose and financial-crime risks
The intended objective is to prevent services from being used for money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud, bribery, corruption, tax crime, market abuse, trafficking, cybercrime, or handling criminal property.
Controls should be proportionate to the entity’s products, delivery channels, customer base, transaction volumes, payment methods, geographic reach, and identified threats.
3. Governance and responsibility
- The board or governing body approves risk appetite and receives meaningful financial-crime reporting.
- A named senior manager has overall responsibility for AML systems and controls.
- An appropriately independent and resourced MLRO or nominated officer receives internal reports and considers external reporting.
- First-line teams own customer and transaction controls; compliance provides oversight and challenge; audit independently tests effectiveness.
- Employees and relevant contractors receive role-appropriate training and can report concerns without retaliation.
4. Risk-based approach
The entity should document a business-wide risk assessment and customer-level risk methodology covering customer type, ownership, occupation or business, geography, product, delivery channel, expected activity, funding route, transaction behavior, and adverse information.
Risk scoring must support—not replace—documented judgment. Higher risk requires stronger evidence, approval, monitoring, and review. Lower risk must never mean no due diligence.
5. Customer due diligence and identity verification
Before or as otherwise lawfully permitted when establishing a relationship, the entity should identify the customer and verify identity using reliable, independent information or evidence.
- Individuals: name, date of birth, residential address, nationality, and official identity evidence as required.
- Legal persons: legal name, form, registration, registered and operating address, constitutional documents, directors, and authority to bind.
- Representatives: identity and evidence that they are authorized to act.
- Purpose and intended nature of the relationship, expected products, activity, funding, and transaction profile.
- Verification quality, document validity, liveness or digital identity controls, and inconsistency resolution.
The exact acceptable documents, electronic verification vendors, certification rules, and exceptions must be published only after operational approval.
6. Beneficial ownership and control
For companies, partnerships, trusts, foundations, and similar arrangements, the entity should understand the ownership and control structure and identify and take reasonable measures to verify the natural persons who ultimately own, control, benefit from, or direct the customer.
Where no person is identified through ownership thresholds, applicable law may require identifying persons exercising control or senior managing officials. Thresholds and fallback rules must match the relevant jurisdiction.
7. Source of funds and source of wealth
Source of funds concerns the origin of money used for a deposit or relationship. Source of wealth concerns how the customer or beneficial owner accumulated overall wealth.
Evidence may be required based on risk and can include employment or business income, financial statements, tax records, asset sale documents, inheritance records, regulated investment statements, or other credible material. A bank statement alone may show movement without explaining economic origin.
8. Sanctions, PEPs, and adverse information
- Screen customers, beneficial owners, controllers, representatives, and relevant counterparties against applicable sanctions measures.
- Identify politically exposed persons, family members, and known close associates under the governing definition.
- Assess credible adverse information relevant to financial-crime risk rather than treating every media mention as conclusive.
- Investigate potential matches using sufficient identifiers and document false-positive resolution.
- Apply required approvals, source checks, enhanced monitoring, restrictions, freezing, rejection, or reporting.
PEP status indicates a need for risk-sensitive enhanced measures; it does not by itself prove wrongdoing.
9. Enhanced due diligence
Enhanced due diligence may be required for higher-risk customers, products, delivery methods, geographies, ownership structures, transactions, PEP relationships, sanctions exposure, unusual activity, or other legally specified circumstances.
- Obtain additional identity, ownership, occupation, business, purpose, source-of-funds, and source-of-wealth evidence.
- Understand reasons for complex structures, unusual payment routes, or activity inconsistent with the expected profile.
- Require senior-management approval where applicable.
- Apply more frequent review and more intensive transaction monitoring.
- Document the rationale to establish, continue, restrict, or exit the relationship.
10. Ongoing due diligence and transaction monitoring
Due diligence continues throughout the relationship. Information should be kept current on a risk-sensitive basis and reviewed when ownership, activity, geography, occupation, funding, behavior, or other relevant circumstances change.
Monitoring should assess whether deposits, withdrawals, transfers, trading, device behavior, and account use are consistent with known purpose, expected activity, source information, and risk profile. Alerts require timely, documented investigation and appropriate escalation.
11. Deposits, withdrawals, and third parties
- Identify and verify the origin and destination of funds to the extent required.
- Restrict or review third-party payments and mismatched account names according to law and risk.
- Apply return-to-source and closed-loop controls where appropriate, without presenting them as universal legal requirements.
- Review unusual velocity, structuring, rapid in-and-out movement, dormant-account activation, and economically unclear activity.
- Understand payment-provider, bank, card, wallet, and virtual-asset exposure and related geographic risk.
12. Suspicious activity and reporting
Employees should promptly escalate knowledge, suspicion, or reasonable grounds for suspicion through the confidential internal route. The MLRO or nominated officer determines whether an external suspicious activity or transaction report is required by the competent financial intelligence unit.
Law may restrict disclosure that a report, investigation, or contemplated report exists. Consequently, support may be unable to explain a delay, restriction, rejection, or closure in detail. This should not be used as a generic excuse for poor customer communication.
13. Account restrictions and refusal
Subject to law and contract, the entity may need to delay onboarding, request information, reject a payment, restrict activity, suspend access, decline or end a relationship, freeze assets, or comply with authority instructions.
The final customer terms must explain permissible actions and treatment of open positions and funds, while preserving confidentiality and anti-tipping-off duties.
14. Records, privacy, and security
CDD, ownership, risk assessment, screening, monitoring, investigation, reporting, approval, and training records should be accurate, secure, accessible to authorized personnel, and retained for the period required by applicable law.
AML processing must also comply with applicable privacy rules. The final privacy notice should state relevant data categories, purposes, lawful bases, recipients, international transfers, retention, automated decisions, and individual rights and restrictions.
15. Customer responsibilities
- Provide complete, accurate, and current information and authentic documents.
- Disclose beneficial owners, controllers, representatives, and the purpose of the account.
- Use funding methods owned or authorized as permitted by account terms.
- Respond to lawful requests about transactions, source of funds, and source of wealth.
- Notify the provider of relevant changes in identity, address, tax status, ownership, occupation, or business.
- Do not structure activity to evade controls, use another person’s account, or permit unauthorized use.
Providing information does not guarantee acceptance or continuation of a relationship.
16. Impersonation and document safety
Customers should upload documents only through a verified secure process. Wolf Markets should never request a password, one-time authentication code, complete card credentials, private key, or crypto seed phrase.
Any AML request received through an unverified domain, messaging account, social profile, or personal email should be treated as suspicious and checked through the official contact route.
17. Training, testing, and policy review
The final program should include screening and role-based training, quality assurance, compliance monitoring, independent testing, management information, issue tracking, regulatory-change management, and periodic review of policies and risk assessments.
Material weaknesses require accountable remediation, validation, and appropriate notification or disclosure where legally required.
18. Applicable law and authoritative references
The exact legal framework depends on the contracting entity and jurisdiction. FATF recommendations provide international standards, while national laws, regulators, supervisors, sanctions authorities, financial intelligence units, and sector guidance impose binding local requirements.
For a UK-regulated model, relevant authoritative material includes the Money Laundering Regulations, FCA Financial Crime Guide and AML pages, JMLSG guidance, sanctions requirements, and National Crime Agency reporting guidance. These must be checked in their current form by qualified counsel and the MLRO.
19. AML enquiries and complaints
The final page must provide a verified secure route for responding to due-diligence requests, correcting personal information, reporting suspected impersonation, and raising complaints. It must also identify the relevant privacy and complaint channels.
A public channel for filing suspicious-activity reports should not replace internal escalation to the MLRO or reporting to the competent authority.