Kyc & Aml Policies

Purpose and scope

Ffbet implements a comprehensive know your customer (KYC) and anti‑money laundering (AML) framework to prevent the platform from being used for money laundering, terrorist financing, or other criminal activity. This policy applies to all user accounts, activities, deposits, withdrawals, and identity verification conducted on the platform, and governs the ongoing assessment and monitoring of all such activities.

Risk-based framework and governance

Ffbet adopts a risk‑based approach to AML and KYC, aligned with international guidance. The company conducts risk assessments that consider customer characteristics, geographic risk, and transactional patterns. A dedicated compliance function oversees policy implementation, controls, and training, and the framework is reviewed regularly to reflect developments in law, regulation, and enforcement expectations.

Know Your Customer and verification triggers

The Company applies standard verification in circumstances that indicate potential risk or where regulatory obligations require identity confirmation. Triggers include:

  • The cumulative value of a user’s transactions reaches or exceeds EUR 1,000; and/or
  • The risk assessment identifies significant money laundering or terrorist financing risk; and/or
  • The user’s activity suggests non‑compliance with the Terms and Conditions or this policy; and/or
  • Any other situation where verification is deemed necessary by the Company’s compliance function.

Documentation and process for standard verification

When standard verification is triggered, the user shall provide the following information and documents to the Company’s satisfaction. The Company may request additional data where justified by risk assessment or regulatory requirements:

  • A clear copy or high‑quality photograph of a government‑issued identification document showing the user’s full name and date of birth (e.g., passport, national ID card, or equivalent);
  • A photograph of the payment card to be used for deposits or the payment instrument connected to the account, with the cardholder name clearly visible and matching the user’s account name; CVV code and other sensitive data may be masked, but the cardholder’s name must be legible;
  • A photograph or live image of the user holding the identification document, or any other method approved by the Company to verify identity;
  • Proof of address such as a utility bill, bank statement, or other acceptable documents showing the user’s name and residential address;
  • Confirmation of the user’s registered contact information and any additional data that may be required by the Company (for example, tax or employment documents) in jurisdictions where such data is customary; and
  • In some cases, a handwritten note containing the user’s registered email address and a verification code, plus any additional data required to complete identity verification.

The Company may require a live verification step, including video or real‑time identity confirmation, where risk indicators or regulatory obligations warrant heightened scrutiny.

Enhanced due diligence for politically exposed persons and high‑risk jurisdictions

For Politically Exposed Persons (PEPs) and their family members, or users tied to high‑risk or monitored jurisdictions, the Company applies enhanced due diligence. Measures may include additional data requests, secondary sources of wealth information, extended verification timelines, and senior management approval of the final verification decision. The Company may request documentation that explains the source of funds and wealth in accordance with applicable laws. If the user refuses to comply with enhanced verification or if credible concerns remain, the Company may escalate the matter to regulatory or supervisory authorities and suspend or restrict account activity as permitted by law.

Ongoing monitoring and suspicious activity reporting

All user activity is subject to ongoing monitoring for indicators of suspicious behavior. Examples of suspicious activity include, but are not limited to, multiple cards or payment methods used in rapid succession, unusual or inconsistent geographic indicators, mismatches between geolocation data and registration information, or refusal to complete verification. Findings are reviewed by the antifraud function, with escalation to the appropriate departments as warranted. If a credible suspicion of illicit activity persists, the Company may report such activity to the competent authorities in accordance with law and regulatory requirements.

Transactions monitoring and payment integrity

All deposits and withdrawals must be traceable to the user. The following rules apply:

  • Deposits and withdrawals must use payment instruments that are owned by the account holder and in the same name as the registered user; third‑party payments are prohibited unless specifically approved under a separate process;
  • For card payments, the cardholder name must match the registered user; for electronic wallets, the wallet email must be the same as the user’s registration email;
  • Funds deposited with instruments that cannot be linked back to the user shall be returned or redirected to a verifiable instrument, where permissible;
  • The Company does not accept payments from anonymous or untraceable instruments and does not permit withdrawals to a payment instrument belonging to another user; and
  • The Company reserves the right to block, delay, or reverse transactions where there is a risk of non‑compliance with this policy or related regulatory obligations.

Record‑keeping and data protection

All documents and data collected under Verification, together with transaction records and supportive evidence, are stored and processed in accordance with applicable AML laws and data protection regulations. This includes retention, access control, and secure disposal practices, as well as compliance with the governing data protection framework in force in the applicable jurisdiction. Information may be retained for the period required by law or regulation and as necessary for legitimate business purposes.

Amendments and communications

This policy may be amended at any time in the Company’s sole discretion. The Company will notify registered users of changes by email to the address on file. Continued use of the platform after such notice constitutes acceptance of the updated policy.