Purpose of this Policy

This Anti-Money Laundering (AML), Counter Financing of Terrorism (CFT), Counter Proliferation Financing (CPF) and Targeted Financial Sanctions (TFS) Policy establishes the compliance framework adopted by Smart Property Solutions Ltd ("SPS") to prevent the company from being used for money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud and other financial crime.

The Policy applies to SPS's payment processing, payroll services and its proposed structured digital asset and stablecoin brokerage facilitation operations, including Native USDT and, where approved, Tether Gold (XAUT).

Policy Objectives

  • Define governance responsibilities.
  • Establish customer due diligence standards.
  • Implement wallet and blockchain controls.
  • Support sanctions compliance.
  • Maintain transaction monitoring.
  • Protect the integrity of financial services.

Business Model & Scope

Current Services

Payment processing and payroll-related services supported by customer due diligence, sanctions screening, transaction monitoring and record keeping.

Digital Asset Operations

Structured brokerage facilitation for Native USDT and approved digital assets, subject to regulatory approval and internal compliance controls.

Institutional Focus

Services are designed for institutional, corporate and qualified professional clients within approved jurisdictions.

Regulatory References & Compliance Principles

This Policy should be read together with all applicable laws, regulatory guidance, licence conditions, banking partner requirements and approved digital asset operating standards. Where there is any uncertainty or conflict between commercial objectives and compliance obligations, the stricter compliance control shall apply until reviewed and approved by the Compliance Officer, Principal Officer and Director.

Key References

  • Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (Malaysia).
  • Labuan Financial Services and Securities Act 2010.
  • Labuan FSA AML/CFT/CPF Guidelines.
  • FATF Recommendations.
  • Applicable United Nations and Malaysian sanctions requirements.

Governance & Responsibility

Role Primary Responsibilities
Director / Board Approves this Policy, risk appetite, product scope, high-risk relationships and material business changes.
Principal Officer Oversees day-to-day management of licensed operations and approved digital asset activities.
Compliance Officer Maintains AML/CFT controls, onboarding approval, sanctions screening, transaction monitoring and regulatory reporting.
Operations Collects customer documentation, verifies instructions and escalates unusual transactions.
Technology Maintains cybersecurity, API controls, audit logs, wallet approval workflows and system integrity.
Employees Comply with this Policy, complete mandatory training and report suspicious activities.

Customer Due Diligence (CDD), KYC & KYB

Customer Acceptance Principles

  • No customer may transact before onboarding approval.
  • Every customer must have a legitimate business purpose.
  • All settlement accounts must be verified.
  • All digital asset wallets require approval.
  • Anonymous or unverifiable customers are not accepted.

Minimum Due Diligence

  • Identity verification
  • Corporate verification
  • Beneficial ownership review
  • Source of Funds / Wealth
  • PEP & Sanctions Screening
  • Wallet Verification
  • Blockchain Risk Screening

Risk-Based Approach & Enhanced Due Diligence

SPS adopts a risk-based approach to customer onboarding and transaction monitoring. Every customer relationship is assessed according to customer, geographical, product, transaction, delivery channel, wallet, blockchain network and counterparty risk.

Risk Level Description Minimum Controls
Low Regulated, transparent customers with straightforward ownership, low-risk jurisdictions and predictable business activity.
  • Standard CDD
  • Sanctions screening
  • Approved wallets
  • Periodic review every 5 years
Medium Cross-border activity, higher transaction volumes, or more complex ownership structures.
  • Additional verification
  • Closer transaction monitoring
  • Review every 2–3 years
High PEPs, VASPs, high-risk jurisdictions, complex ownership, high transaction values or elevated blockchain risk.
  • Enhanced Due Diligence (EDD)
  • Senior Management Approval
  • Annual review
  • Enhanced monitoring

Digital Asset High-Risk Factors

Customer Risk

  • Virtual Asset Service Providers (VASPs)
  • Digital asset exchanges
  • OTC desks
  • Liquidity providers
  • Crypto payment businesses
  • High-risk institutional clients

Transaction & Wallet Risk

  • Self-hosted wallets
  • Unknown wallet ownership
  • Sanctioned or tainted wallets
  • Mixer or tumbler exposure
  • Rapid fiat ↔ stablecoin conversions
  • Unsupported blockchain networks

EDD Measures

Corporate Verification

  • Corporate documents
  • Audited financial statements
  • Ownership verification
  • Beneficial owners

Compliance Review

  • PEP Screening
  • Sanctions Screening
  • Adverse Media
  • Law Enforcement Checks

Transaction Controls

  • Blockchain tracing
  • Senior approval
  • Transaction limits
  • Enhanced monitoring

Approved Digital Asset Wallet Principle

SPS will only send digital assets to, or receive digital assets from, wallets that have successfully completed wallet verification, sanctions screening, blockchain risk screening and internal approval. Each approved wallet shall be linked to:

  • Wallet owner
  • Blockchain network
  • Approved digital asset
  • Risk assessment
  • Purpose of use
  • Approval date

Approval Principle

Any modification to a wallet address, supported blockchain network or ownership information requires a new compliance review before further transactions are permitted.

Wallet Ownership Verification

Custodial Wallets

  • Obtain confirmation from the custodian or VASP.
  • Verify the customer-to-wallet relationship.
  • Confirm wallet ownership before activation.
  • Maintain supporting documentary evidence.

Self-Hosted Wallets

  • Signed message verification.
  • Micro-transfer confirmation.
  • Screenshot or video confirmation.
  • Independent ownership verification.
  • Any wallet change requires fresh approval.

Blockchain Analytics & Risk Screening

Stage Minimum Requirement
Before Onboarding Screen all declared wallets and associated wallet clusters.
Before Transaction Screen source wallet, destination wallet, counterparty and transaction route.
After Transaction Monitor confirmation, transaction hash, network and post-transaction alerts.
Ongoing Monitoring Re-screen approved wallets periodically and immediately after new sanctions or blockchain alerts.
Alert Handling Escalate medium and high-risk alerts to the Compliance Officer before transaction release.

Approved Counterparties & Liquidity Providers

Due Diligence Requirements

  • KYB verification
  • Sanctions screening
  • Adverse media review
  • Operational due diligence
  • Regulatory status confirmation

Operational Assessment

  • AML/CFT framework
  • Travel Rule capability
  • Wallet controls
  • Custody arrangements
  • Cybersecurity controls
  • Incident history

Monitoring Objectives

  • Ensure transactions remain consistent with customer profiles.
  • Detect unusual transaction patterns and layering activity.
  • Identify sanctions, fraud, ransomware and darknet exposure.
  • Investigate and escalate compliance alerts promptly.
  • Maintain complete audit trails and supporting documentation.

Pre-Transaction Compliance Checklist

Confirm customer onboarding approval
Verify customer risk rating
Validate transaction purpose
Confirm approved fiat account
Confirm approved digital asset wallet
Screen customer and counterparty
Screen wallet address
Apply Travel Rule requirements
Obtain Compliance approval where required

Post-Transaction Controls

01

Transaction reconciliation

02

Blockchain confirmation

03

Compliance review

04

Customer profile update

Compliance Trigger Events

Trigger Required Action
Transaction exceeds expected volume Compliance review before execution.
New wallet or blockchain network Fresh screening and approval.
Third-party funding request Enhanced Due Diligence.
Medium or High blockchain alert Hold processing pending investigation.
Customer refuses information request Suspend processing and assess relationship.
Transaction inconsistent with profile Enhanced monitoring and possible STR.

Stablecoin Issuance, Redemption & Settlement Controls

Role of USDT

USDT is used only as an approved digital settlement asset for client-driven transactions. SPS does not engage in speculative proprietary trading.

  • Verified customers only
  • Approved business purpose
  • Approved wallets only
  • Approved counterparties only

Source & Destination Controls

  • Verified customer bank accounts
  • Approved institutional liquidity arrangements
  • Approved blockchain networks
  • No anonymous funding
  • No prohibited jurisdictions
  • Complete reconciliation records

Approved Stablecoin Network Controls

Control Requirement
Supported Networks Maintain an approved list of blockchain networks.
Network Selection Confirm blockchain network before execution.
Native USDT Supply only approved native USDT.
Unsupported Networks Reject unsupported assets and blockchain networks.
Reconciliation Record wallet, transaction hash, amount and fees.

Tether Gold (XAUT)

SPS may facilitate Tether Gold (XAUT) transactions for eligible institutional and corporate clients subject to regulatory approval.

  • Institutional purpose verification
  • Customer suitability assessment
  • KYC / KYB compliance
  • Approved wallet screening
  • Travel Rule compliance
  • No physical precious metal trading
  • No physical delivery by SPS

Suspicious Transaction Reporting

Internal Escalation

  • Immediate escalation to Compliance Officer.
  • Review customer profile.
  • Review wallet screening results.
  • Review blockchain tracing.
  • Review Travel Rule information.
  • Maintain investigation records.

Tipping-Off Prohibition

Employees must not disclose that an investigation or Suspicious Transaction Report has been filed or may be filed.

Sanctions, TFS & Prohibited Relationships

Sanctions Controls

  • Customer screening
  • Beneficial owner screening
  • Wallet screening
  • Counterparty screening
  • Immediate escalation
  • Maintain screening evidence

Prohibited Relationships

  • Anonymous customers
  • Shell banks
  • Sanctioned entities
  • Darknet markets
  • Ransomware
  • Scam wallets
  • Mixers & tumblers
  • Unsupported digital assets
  • Unsupported blockchain networks

Training & Awareness

  • AML / CFT / CPF obligations
  • Digital asset risk typologies
  • KYC / KYB procedures
  • Travel Rule implementation
  • Wallet ownership verification
  • Blockchain transaction review
  • Confidentiality obligations
  • Tipping-off restrictions

Independent Audit & Compliance Review

CDD & KYB

Blockchain Analytics

Travel Rule

Transaction Monitoring

Wallet Controls

Vendor Management

Record Keeping & Data Retention

SPS maintains accurate, complete and retrievable records for customer onboarding, transaction processing, compliance reviews and digital asset activities. Records shall be retained for a minimum of seven (7) years from the completion of a transaction or termination of the customer relationship, or longer where required by law, regulatory investigation or litigation hold.

Records Maintained

  • CDD / KYB Records
  • Wallet Verification
  • Blockchain Screening
  • Travel Rule Records
  • Transaction Monitoring
  • Governance & Audit Records

Technology, Outsourcing & Vendor Oversight

Technology Controls

  • Role-based access
  • API authentication
  • Audit logging
  • Secure integrations
  • Backup & recovery

Vendor Oversight

  • Due diligence
  • Information security review
  • Business continuity
  • Service monitoring
  • Incident reporting

Operational Controls

  • Manual fallback procedures
  • Periodic access review
  • Change management
  • Compliance monitoring
  • Operational resilience

Policy Review & Board Approval

This Policy shall be reviewed at least annually and whenever there is a material change to SPS's business model, digital asset scope, regulatory framework, blockchain networks, custody arrangements, technology platform, transaction volumes, customer base or risk appetite.

Approval Item Approving Authority Frequency
AML / CFT Policy Director / Board Annual
Digital Asset Products Director / Board Before Launch
High-Risk Customer Director Before Onboarding
High-Risk Transaction Compliance Officer / Principal Officer Before Execution
Compliance Vendors Director / Board Annual Review

Operational Compliance Checklists

Customer Onboarding

  • Corporate documentation
  • UBO verification
  • KYC / KYB completed
  • Risk assessment
  • Wallet approval
  • Compliance approval

Transaction Processing

  • Transaction instruction
  • Wallet verification
  • Blockchain screening
  • Travel Rule
  • Settlement reconciliation
  • Post-transaction review