Kyc Policies

Introduction

Wunderwins maintains a comprehensive KYC policy to verify customers, assess and mitigate money laundering and terrorist financing risks, and ensure compliance with applicable laws. This policy governs onboarding, ongoing monitoring, data handling, and the allocation of responsibilities across Wunderwins and its staff.

Definitions

  • KYC (Know Your Customer): the process of obtaining and verifying information to establish the true identity of customers and assess the associated risk.
  • CDD (Customer Due Diligence): risk-based measures to identify and verify customers and to monitor their relationship with Wunderwins.
  • EDD (Enhanced Due Diligence): intensified checks applied to higher risk customers or transactions.
  • MLRO (Money Laundering Reporting Officer): the designated officer responsible for AML/CFT reporting and compliance.
  • PEP (Politically Exposed Person): an individual who is or has been entrusted with prominent public functions and their immediate family or close associates.
  • SAR (Suspicious Activity Report): a report filed when grounds for knowledge or suspicion of money laundering or terrorist financing arise.
  • NOIS: the regulatory framework governing anti-money laundering and related controls applicable to Wunderwins operations.

Regulatory Scope and Governance

Wunderwins operates under applicable gaming and financial crime laws. The board assigns the MLRO and a Compliance Officer with responsibility for the design, implementation, and ongoing adequacy of the KYC program. The policy is reviewed regularly to reflect changes in risk, law, and business development. Wunderwins maintains an audit trail for all CDD/EDD activities and related communications with regulators or law enforcement where required.

Customer Due Diligence

CDD applies to all customers at onboarding and is maintained on a risk-based basis throughout the business relationship. Customer risk is assessed using criteria including identity, source of funds, expected activity, geography, and product usage. The level of due diligence is determined by the customer risk rating and can include enhanced verification, ongoing monitoring, and periodic reviews.

Identity Verification and Age Verification

  1. On registration, Wunderwins collects identity information including legal name, date of birth, and residential address. The customer’s date of birth must indicate an age of at least 18 years.
  2. Accepted identity documents include government issued travel documents and national identity cards. Address verification requires documents such as a recent utility bill, bank statement, or government correspondence showing the customer’s name and address.
  3. Electronic verification may be performed where available. If electronic verification cannot be completed or is inconclusive, Wunderwins may request additional documentary evidence within 72 hours of the initial request.
  4. Until identity and age verification are completed to Wunderwins satisfaction, account creation or certain transactions may be restricted, including withdrawal of winnings.
  5. If verification indicates the customer is underage, Wunderwins will nullify winnings, restrict future activity, and close the account in accordance with applicable law.

Source of Funds and Wealth

Wunderwins requires customers to provide information on the source of funds for certain deposits or to reflect a consistent pattern of activity with the declared purpose of the account. In higher risk cases, customers may be asked to provide supporting documentation such as recent bank statements, payslips, or other documentation that reasonably demonstrates the origin of funds. Wunderwins retains the right to refuse, suspend, or reverse transactions where the source of funds cannot be verified or appears inconsistent with the customer’s profile.

Ongoing Monitoring and Risk Review

Customer activity is monitored on a risk-based basis to identify unusual or inappropriate patterns. The customer’s risk profile is reviewed at intervals commensurate with the level of risk and at significant events such as changes in geography, product usage, or the magnitude of activity. Data used for monitoring includes transaction history, login behavior, and device information, all handled in accordance with Wunderwins data protection policies.

Enhanced Due Diligence

EDD is applied where a customer or transaction presents elevated risk circumstances, including but not limited to high risk geography, involvement of high risk counterparties, politically exposed persons, or unusual or complex transaction patterns. EDD may include additional identity checks, source of funds verification, enhanced ongoing monitoring, and periodic reviews beyond standard CDD requirements.

High Risk Jurisdictions and PEPs

Customers identified as originating from or transacting in jurisdictions designated as high risk by competent authorities will be subject to enhanced due diligence and ongoing monitoring. PEPs are subject to intensified scrutiny, including verification of source of wealth, extended due diligence, and ongoing monitoring of transactions and account activity.

Suspicious Activity Reporting and Cooperation

All employees must report grounds for knowledge or suspicion of money laundering or terrorist financing to the MLRO promptly and through secure channels. Disclosure or tipping off to the customer or third parties is strictly prohibited. The MLRO has authority to report to authorities and to request additional information as needed. Wunderwins maintains confidentiality in investigations and preserves audit trails for regulatory review.

Records, Retention, and Data Security

Wunderwins maintains comprehensive records of identity verification, due diligence, risk assessments, and transactional data for a period aligned with applicable laws and regulatory guidance. Records include documentation of CDD/EDD, SARs, and communication with the MLRO. Access is restricted to authorized personnel and data is protected in accordance with Wunderwins data protection standards and privacy policy.

Training and Awareness

All staff receive AML/CFT training covering identification of customer risk, escalation procedures, and the handling of sensitive information. Training is refreshed at least annually or when regulatory changes require updates. Senior management, including the MLRO and Compliance Officer, provide ongoing oversight and resources to support the program.

Governance and Roles

The MLRO oversees AML compliance and SAR processes. The Compliance Officer oversees privacy and data protection aspects of the KYC program. A governance body, including a risk or compliance committee, meets regularly to review the program’s effectiveness and to supervise remediation of any identified gaps.

Account Management and Sanctions

Wunderwins may suspend or terminate any customer account, or refuse payments if there are AML concerns, if verification cannot be completed, or if activity indicates potential wrongdoing. In such cases Wunderwins will preserve the customer’s remaining funds and provide a notice in accordance with applicable law and policy terms.

Policy Updates and Customer Notification

Wunderwins reserves the right to amend this KYC policy at any time to reflect regulatory changes or risk considerations. Material updates will be communicated through appropriate channels. Continued use of Wunderwins services after changes constitutes acceptance of the updated policy.

Onboarding Flow Summary

  1. Submit identity information and consent for verification.
  2. Complete age and identity checks; verify address and contact details.
  3. Provide evidence of source of funds when required by risk assessment.
  4. Receive risk rating and determine ongoing monitoring level.
  5. Account activation upon successful verification and funding.

Privacy and Data Processing

Personal data collected for KYC purposes is processed in accordance with Wunderwins privacy policy and applicable data protection laws. Data may be used to verify identity, assess risk, and fulfill regulatory reporting obligations. Customers retain rights to access, rectify, or request deletion of their personal data as permitted by law.