Licensed Meydan Free Zone Entity | Dubai, UAE
Legal & Compliance

Public AML/CFT, Sanctions & Financial Crime Compliance Policy

Effective 31 August 2026

1

Purpose and Commitment

1.1Epiidosis Global Finance LLC-FZ ("Epiidosis", "Company", "we", "us", "our") is committed to the highest standards of financial-crime compliance and to preventing its Services from being used, directly or indirectly, for money laundering, terrorist financing, proliferation financing, fraud, bribery, corruption, sanctions evasion or any other financial crime.

1.2This Public AML/CFT, Sanctions & Financial Crime Compliance Policy ("Policy") sets out, at a level appropriate for public disclosure, the principles governing the Company's approach to financial-crime risk. It is incorporated by reference into the Company's Terms of Use, Client Engagement & Legal Framework.

1.3This Policy is a summary of principles and does not disclose the Company's internal risk-scoring criteria, specific monitoring thresholds, escalation workflows, or control calibration, disclosure of which could reduce the effectiveness of those controls.

2

Regulatory Framework

2.1The Company's compliance framework is designed with regard to, among other sources: Federal Decree-Law No. (20) of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations, as amended; its implementing Cabinet Decisions and regulations; guidance issued by the UAE's competent authorities, including the Central Bank, the Financial Intelligence Unit and the relevant free-zone authority; and relevant international standards, including the Financial Action Task Force ("FATF") Recommendations.

2.2Where a specific Service is a regulated financial activity, additional sector-specific AML/CFT requirements apply only to the extent the Company is lawfully authorised to perform that activity; this Policy does not extend the Company's regulatory perimeter beyond its actual licence.

2.3This framework operates alongside, and does not replace, the AML/CFT, KYC and sanctions obligations of any bank, lender, broker or other regulated Third-Party Provider involved in a transaction, each of which remains independently responsible for its own compliance programme.

3

No Implied Financial-Services Licence

3.1Publication of this Policy, and the existence of AML/CFT controls, does not mean, and must not be interpreted to mean, that the Company is a bank, financial institution, payment-service provider or Central Bank-regulated entity. The Company's actual regulatory status is determined exclusively by its current, verified trade licence and Applicable Law, as further addressed in the Regulatory Disclosure, Financial Services Disclaimer & Transaction Risk Statement.

3.2The Company maintains AML/CFT controls both because it may be independently required to do so under free-zone or federal requirements applicable to its actual licensed activities, and as a matter of good governance and international best practice appropriate to a business that facilitates introductions to, and prepares Clients for engagement with, regulated financial institutions.

4

Risk-Based Approach

4.1The Company applies a risk-based approach to financial-crime prevention, calibrating the intensity of due diligence and ongoing monitoring to the assessed risk of a Client, relationship or transaction. Relevant risk factors include, without limitation: the type and legal form of the customer; the transparency and complexity of beneficial ownership; the customer's and counterparties' geographic exposure, including higher-risk jurisdictions; the customer's industry sector; the nature, value and purpose of the transaction; the source of funds and source of wealth; sanctions exposure; PEP status; adverse media; the presence of unusual or economically inexplicable structuring; and the involvement of third parties not otherwise connected to the transaction.

4.2Higher-risk indicators trigger enhanced measures under Section 9; lower-risk, well-understood relationships may be subject to standard due diligence proportionate to that lower risk, consistent with Applicable Law.

5

Customer Due Diligence (CDD)

5.1Before or in the course of establishing a business relationship, and on an ongoing basis thereafter, the Company may obtain and independently verify, as appropriate to the assessed risk: government-issued identification and proof of address for individuals; certificates of incorporation, licences, constitutional documents, good-standing certificates and registers of directors and shareholders for entities; the identity of beneficial owners and authorised signatories; the purpose and intended nature of the relationship; and information on source of funds and source of wealth.

5.2CDD is refreshed periodically and on the occurrence of trigger events, such as a material change in ownership or control, a change in the nature or expected pattern of activity, or emergence of adverse information.

6

Know-Your-Customer and Know-Your-Business

6.1KYC (in respect of individuals) and KYB (in respect of legal entities) measures verify that a Client or counterparty is who, and what, it claims to be, and that its business activity, ownership and control structure are understood and documented before an engagement proceeds.

6.2KYB measures for corporate Clients include verification of legal existence and good standing, understanding of the corporate group and control chain, identification of the operating business and its consistency with the proposed engagement, and screening of the entity and its known principals against sanctions and adverse-media sources.

7

Beneficial Ownership

7.1The Company seeks to identify the natural person(s) who ultimately own or exercise control over a corporate Client or transaction structure, whether through direct or indirect ownership, voting rights, the right to appoint or remove management, or other means of control, in accordance with Applicable Law's beneficial-ownership thresholds and definitions.

7.2Complex, layered, opaque or nominee ownership structures, or structures involving jurisdictions with weak beneficial-ownership transparency, will generally trigger enhanced review under Section 9 before the Company proceeds.

8

Politically Exposed Persons

8.1The Company screens Clients, beneficial owners, authorised signatories and, where relevant, close associates and family members, against recognised PEP indicators, covering domestic and foreign prominent public functions and, where applicable under Applicable Law, prominent functions in international organisations.

8.2A PEP finding does not automatically preclude an engagement, but triggers enhanced due diligence under Section 9, including senior-management approval, enhanced source-of-wealth and source-of-funds inquiry, and enhanced ongoing monitoring, proportionate to the assessed risk.

9

Enhanced Due Diligence (EDD)

9.1EDD measures apply where risk factors under Section 4 indicate elevated risk, including without limitation: exposure to jurisdictions identified by FATF or other competent bodies as presenting strategic AML/CFT deficiencies; complex or non-transparent ownership structures; confirmed or suspected PEP exposure; sanctions-adjacent exposure not itself amounting to a match requiring refusal; unusually large, complex or economically inexplicable transactions; unexplained involvement of unrelated third-party funders; inconsistent, contradictory or apparently altered documentation; and material adverse media.

9.2EDD measures may include: obtaining additional independent verification of identity and ownership; requiring documented, verifiable evidence of source of funds and source of wealth; senior-management or compliance-function approval prior to onboarding or before a specific transaction proceeds; more frequent and intensive ongoing monitoring; and, where warranted, independent third-party integrity due diligence.

10

Sanctions Compliance

10.1The Company screens Clients, beneficial owners, authorised signatories, known counterparties and, where relevant, transaction parties against applicable sanctions lists and restricted-party sources, including United Nations Security Council sanctions lists, UAE domestic sanctions and targeted financial sanctions lists, and other sanctions regimes relevant to the transaction's parties, currencies or jurisdictions.

10.2The Company will decline to establish, or will suspend or terminate, a relationship or transaction where proceeding would breach applicable sanctions, where a party is a designated or restricted person, or where proceeding would otherwise create unacceptable sanctions, legal or regulatory risk, regardless of whether a positive match is confirmed with certainty.

10.3The Company does not provide, and will not assist in circumventing, sanctions compliance for any party, and will not structure or facilitate a transaction designed to evade sanctions, export controls or restrictive measures.

11

Terrorist Financing and Proliferation Financing

11.1The Company applies measures designed to prevent its Services being used, directly or indirectly, to raise, move, or provide funds or other assets, or financial or related services, in support of terrorism, terrorist organisations, or individual terrorists, or in support of the proliferation of weapons of mass destruction, consistent with Applicable Law and relevant UN Security Council resolutions.

11.2Indicators considered may include: transactions inconsistent with a customer's known profile or stated purpose; involvement of jurisdictions or entities subject to proliferation-related sanctions or export-control concern; and patterns consistent with typologies published by competent authorities or FATF, without disclosure here of the Company's internal detection methodology.

12

Fraud Prevention

12.1The Company maintains measures to detect and prevent fraud in connection with its Services, including identity fraud, document fraud, impersonation of the Company or its personnel, and payment fraud, including business email compromise targeting fee or transaction payments (see also Section 17 of the Terms of Use).

12.2Indicative fraud red flags include, without limitation: forged, altered or inconsistent identity or corporate documents; attempted impersonation of a Client, director or authorised signatory; unexplained last-minute changes to payment or banking instructions; unexplained third-party funding of a transaction inconsistent with the stated structure; and deliberate attempts to bypass or rush compliance procedures.

13

Anti-Bribery and Anti-Corruption

13.1The Company prohibits bribery and corruption in all forms, whether involving public officials or private parties, and whether committed directly or through an intermediary, consistent with UAE law and applicable international anti-corruption standards.

13.2Personnel, agents and introducers acting on the Company's behalf are prohibited from offering, promising, giving, soliciting or accepting any bribe, kickback or improper advantage in connection with the Company's business, including in connection with obtaining or retaining business or securing an improper advantage in the conduct of business.

13.3Facilitation payments are prohibited. Gifts and hospitality offered or received in connection with the Company's business must be reasonable, proportionate, transparent, properly recorded, and not intended or perceived as an inducement to improper conduct.

14

Suspicious Activity and Reporting

14.1Where the Company identifies activity giving rise to knowledge or suspicion of money laundering, terrorist financing, proliferation financing or other financial crime, and a legal reporting obligation applies, the Company will report the relevant information to the competent authority (which, in the UAE, includes the Financial Intelligence Unit) in accordance with Applicable Law.

14.2Consistent with "tipping-off" prohibitions under Applicable Law, the Company will not disclose to a Client, counterparty or third party that a suspicious-activity report has been made, that it is contemplating doing so, or that a related investigation is underway, and will not disclose any information where such disclosure is prohibited by law or would prejudice a lawful investigation.

15

Refusal, Suspension and Termination

15.1The Company may decline to establish, or may suspend or terminate, an existing engagement, without liability for resulting loss to the Client, where: identity or beneficial ownership cannot be established or verified to the Company's reasonable satisfaction; information provided is materially incomplete, inconsistent or apparently false; a sanctions, PEP or adverse-media concern cannot be adequately resolved; source of funds or source of wealth is unexplained, inconsistent or unacceptable; the proposed transaction appears unlawful, fictitious, or structured to evade a legal, tax or regulatory requirement; the Client or a related party attempts to circumvent, delay or obstruct compliance procedures; or continuing the relationship would expose the Company to unacceptable legal, regulatory, sanctions or reputational risk.

15.2Where legally permitted, the Company will provide the Client with such explanation for refusal, suspension or termination as does not compromise a legal reporting obligation, an ongoing investigation, or a tipping-off restriction.

16

Record Keeping

16.1The Company retains KYC/KYB documentation, beneficial-ownership records, transaction records, correspondence, risk assessments and compliance decision records for the period(s) required by Applicable Law, which will typically extend beyond the end of a business relationship or the completion of a transaction, and in any event as further described in the Company's Privacy & Data Protection Policy.

16.2Records are maintained in a form that allows timely retrieval in response to a lawful request from a competent authority.

17

Third-Party and Correspondent Risk

17.1Banks, lenders, investors, brokers, funds and other regulated Third-Party Providers to which the Company introduces a Client remain independently responsible for their own AML/CFT, sanctions and KYC obligations under their own licence and applicable law. An introduction by the Company does not transfer, delegate or diminish that responsibility, and the Company does not warrant a Third-Party Provider's compliance programme.

17.2Where the Company relies on a third party (such as a regulated introducer or a group affiliate) to perform an element of CDD, it will do so only where permitted by Applicable Law and subject to appropriate assurance that the relied-upon party applies equivalent standards and will make underlying records available on request.

18

Personnel, Training and Governance

18.1Personnel with client-facing, compliance, or transaction-execution responsibilities are expected to understand their obligations under this Policy, complete periodic AML/CFT training proportionate to their role, follow the Company's onboarding and ongoing-monitoring procedures, escalate concerns promptly to the compliance function, and maintain confidentiality regarding suspicious-activity considerations.

18.2The Company designates appropriate senior ownership for its financial-crime compliance programme, commensurate with its size, structure and risk profile, and applicable regulatory expectations.

19

Independent Review

19.1The Company's compliance framework, policies and controls should be subject to periodic independent review — which may include internal audit, external audit, or regulatory examination as applicable — proportionate to the Company's risk profile, business model and legal obligations, with findings addressed through a documented remediation process.

20

Data Protection

20.1Personal Data processed for AML/KYC, sanctions-screening and financial-crime-prevention purposes is processed in accordance with the Company's Privacy & Data Protection Policy and Applicable Law, including applicable retention, security and data-subject-rights provisions, which are qualified, where necessary, by the Company's overriding legal obligations under this Policy.

21

No Guarantee of Outcome

21.1Successful completion of the Company's KYC/AML process does not mean, and must not be represented as meaning, that a proposed transaction will be approved, financed, invested in, insured, confirmed or otherwise completed. Approval of any transaction remains subject to the independent decision of the relevant Third-Party Provider and to satisfaction of all other applicable conditions.

22

Contact

22.1Compliance-related queries, and reports of suspected financial crime or attempted misuse of the Company's name, should be submitted through the Company's official corporate contact channel:

  • Compliance contact: enquiry@epiidosisglobalfin.com