KYC / AML Policy

Know Your Customer & Anti-Money Laundering Policy

Last Updated: April 4, 2026

1. Introduction

Infinity Cloud System LIMITED ("we," "us," or "our") is committed to preventing money laundering, terrorist financing, and other financial crimes. This Know Your Customer (KYC) and Anti-Money Laundering (AML) Policy outlines our procedures for customer identification, verification, and ongoing monitoring.

Company Information:

Infinity Cloud System LIMITED

Company Number: 17131879

Registered in England and Wales

Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

2. Legal and Regulatory Framework

This policy complies with:

  • The Proceeds of Crime Act 2002 (POCA) - UK anti-money laundering legislation
  • The Terrorism Act 2000 - Counter-terrorism financing requirements
  • The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (MLR 2017)
  • The Criminal Finances Act 2017 - Corporate criminal offences
  • Financial Conduct Authority (FCA) Guidelines
  • UK GDPR and Data Protection Act 2018 - Data processing requirements
  • Stripe's AML/KYC Requirements - Payment processor compliance

3. Policy Objectives

Our KYC/AML policy aims to:

  • Verify the identity of our customers
  • Assess and manage money laundering and terrorist financing risks
  • Detect and prevent suspicious transactions
  • Comply with legal and regulatory obligations
  • Protect our business from financial crime
  • Maintain the integrity of the financial system
  • Cooperate with law enforcement and regulatory authorities

4. Customer Due Diligence (CDD)

4.1 When CDD is Required

We conduct Customer Due Diligence when:

  • Establishing a business relationship
  • Processing transactions above €1,000
  • Suspecting money laundering or terrorist financing
  • Doubting the veracity of previously obtained identification data
  • As required by risk assessment

4.2 Standard CDD Measures

Standard CDD includes:

  • Identification: Collecting customer name, address, date of birth (for individuals)
  • Verification: Confirming identity using reliable, independent sources
  • Business Purpose: Understanding the nature and purpose of the business relationship
  • Ongoing Monitoring: Scrutinizing transactions and updating customer information

4.3 Enhanced Due Diligence (EDD)

Enhanced measures apply to higher-risk situations:

  • Politically Exposed Persons (PEPs)
  • Customers from high-risk jurisdictions
  • Complex corporate structures
  • Transactions above €10,000
  • Unusual transaction patterns
  • Non-face-to-face business relationships

4.4 Simplified Due Diligence (SDD)

Simplified measures may apply to low-risk situations, such as:

  • UK public authorities
  • Listed companies subject to disclosure requirements
  • Low-value, one-off transactions (below €1,000)

5. Identity Verification Requirements

5.1 Individual Customers

For individual customers, we may request:

  • Full Name: As it appears on official documents
  • Date of Birth: For age verification and identity confirmation
  • Residential Address: Current and verifiable
  • Identification Documents: Passport, driver's license, or national ID card
  • Proof of Address: Utility bill, bank statement (dated within 3 months)
  • Contact Information: Email address and phone number

5.2 Business Customers

For corporate customers, we may request:

  • Company Name: Full legal name
  • Registration Number: Companies House number or equivalent
  • Registered Address: Official registered office address
  • Business Activities: Nature of business and services required
  • Ownership Structure: Details of beneficial owners (25%+ ownership)
  • Authorized Representatives: Identity verification of persons acting on behalf of the company
  • Corporate Documents: Certificate of incorporation, articles of association

5.3 Beneficial Ownership

We identify beneficial owners who:

  • Own or control more than 25% of shares or voting rights
  • Exercise control through other means
  • Are senior managing officials (if no beneficial owner identified)

6. Risk Assessment

6.1 Risk-Based Approach

We adopt a risk-based approach, considering:

  • Customer Risk: Type of customer, business activities, behavior patterns
  • Country Risk: Geographic location, jurisdiction risk ratings
  • Product/Service Risk: Nature and complexity of services provided
  • Transaction Risk: Size, frequency, and nature of transactions
  • Delivery Channel Risk: Face-to-face vs. remote relationships

6.2 High-Risk Indicators

We consider the following as high-risk factors:

  • Customers from FATF high-risk jurisdictions
  • Politically Exposed Persons (PEPs) and their associates
  • Complex ownership structures without clear business rationale
  • Cash-intensive businesses
  • Unusual transaction patterns or amounts
  • Reluctance to provide information or documentation
  • Inconsistent information provided

7. Politically Exposed Persons (PEPs)

We apply enhanced due diligence to PEPs, defined as individuals who hold or have held prominent public functions:

  • Heads of state, government, or senior politicians
  • Senior government, judicial, or military officials
  • Senior executives of state-owned corporations
  • Important political party officials
  • Family members and close associates of PEPs

For PEPs, we:

  • Obtain senior management approval before establishing the relationship
  • Take reasonable measures to establish source of wealth and funds
  • Conduct enhanced ongoing monitoring

8. Transaction Monitoring

8.1 Ongoing Monitoring

We continuously monitor customer transactions to:

  • Ensure consistency with customer profile and business activities
  • Identify unusual or suspicious patterns
  • Keep customer information up to date
  • Detect changes in risk profile

8.2 Suspicious Activity Indicators

We investigate transactions that exhibit:

  • Unusually large payments inconsistent with customer profile
  • Frequent transactions just below reporting thresholds (structuring)
  • Payments from or to high-risk jurisdictions
  • Complex payment patterns without clear business purpose
  • Reluctance to provide transaction details
  • Use of multiple payment methods or accounts
  • Requests for unusual payment arrangements

9. Suspicious Activity Reporting

9.1 Reporting Obligations

We are legally required to report suspicious activities to:

National Crime Agency (NCA)

UK Financial Intelligence Unit

Suspicious Activity Reports (SARs) submitted via NCA online system

9.2 When to Report

We submit a SAR when we know or suspect that:

  • A person is engaged in money laundering
  • A transaction involves the proceeds of crime
  • A person is involved in terrorist financing

9.3 Tipping Off

We do not disclose to customers or third parties that:

  • A SAR has been submitted
  • An investigation is underway
  • Information has been provided to law enforcement

Tipping off is a criminal offence under UK law.

10. Record Keeping

10.1 Retention Period

We retain records for:

  • Customer Identification: 5 years after the relationship ends
  • Transaction Records: 5 years after the transaction is completed
  • Internal Reports: 5 years from the date of report
  • SAR Records: 5 years from submission date

10.2 Records Maintained

We maintain records of:

  • Customer identification and verification documents
  • Transaction details and supporting documentation
  • Risk assessments and due diligence findings
  • Internal suspicious activity reports
  • Training records for staff
  • Policy reviews and updates

10.3 Data Protection

All records are stored securely in compliance with UK GDPR and our Privacy Policy. Access is restricted to authorized personnel only.

11. Payment Processing and Stripe

We use Stripe as our payment processor. Stripe conducts its own KYC/AML checks and compliance procedures:

  • Stripe verifies payment information and cardholder identity
  • Stripe monitors transactions for fraud and suspicious activity
  • Stripe complies with PCI-DSS and international AML regulations
  • We cooperate with Stripe's compliance requirements
  • Suspicious transactions may be blocked or flagged by Stripe

For more information, see Stripe's Restricted Businesses Policy.

12. Sanctions Screening

We screen customers against:

  • UK Sanctions List: HM Treasury's Consolidated List
  • UN Sanctions Lists: United Nations Security Council sanctions
  • EU Sanctions Lists: European Union restrictive measures
  • OFAC Lists: US Office of Foreign Assets Control (where applicable)

We do not conduct business with individuals or entities on sanctions lists.

13. Staff Training and Awareness

We ensure that relevant staff:

  • Receive regular AML/KYC training
  • Understand their legal obligations
  • Can identify suspicious activities
  • Know how to report concerns internally
  • Are aware of tipping-off offences
  • Maintain confidentiality of sensitive information

14. Refusal of Business

We reserve the right to refuse or terminate business relationships if:

  • We cannot complete satisfactory customer due diligence
  • Customer refuses to provide required information
  • We suspect money laundering or terrorist financing
  • Customer is on a sanctions list
  • Risk level is unacceptable
  • Required by law or regulation

15. Policy Review and Updates

This policy is reviewed:

  • Annually, or more frequently if required
  • When there are changes to legislation or regulations
  • Following significant changes to our business
  • After identification of deficiencies or weaknesses

16. Cooperation with Authorities

We cooperate fully with:

  • National Crime Agency (NCA)
  • Financial Conduct Authority (FCA)
  • HM Revenue & Customs (HMRC)
  • Police and law enforcement agencies
  • Other regulatory and supervisory bodies

We respond promptly to requests for information and provide assistance as required by law.

17. Contact Information

For questions about this KYC/AML Policy or to report concerns, please contact:

Infinity Cloud System LIMITED

Money Laundering Reporting Officer (MLRO)

Email: finance@infinitycloudsystemlimited.com

Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Company Number: 17131879

Commitment Statement:

Infinity Cloud System LIMITED is committed to the highest standards of AML/KYC compliance. We have zero tolerance for money laundering, terrorist financing, and financial crime. All staff are required to adhere to this policy and report any suspicious activities.