AML Policy
Anti-Money Laundering (AML), Counter-Terrorist Financing (CTF) and KYC Policy
1. General Provisions
1.1. Introduction and Policy Objectives
This Policy on Combating Money Laundering, Terrorism Financing, and Financing of the Proliferation of Weapons of Mass Destruction (hereinafter — “Policy”, “AML Policy”) has been officially adopted by Ace Xchanger (hereinafter — “Service”, “Company”, “we”, “our”).
The Policy has been developed in accordance with international FATF (Financial Action Task Force) standards, statutory compliance metrics, and global best practices for virtual asset service providers (VASPs). The primary objectives of this Policy are:
- Prevention of the use of the Service for the purposes of liquidation or laundering of proceeds of crime;
- Prevention of the financing of terrorist activities and the proliferation of weapons of mass destruction;
- Strict compliance with international and national sanctions regimes;
- Protection of the operational security, compliance standing, and business reputation of the Service and its bona fide clients;
- Establishment of a transparent, predictable, and legally sound systеm of processing transactions and managing user compliance.
1.2. Scope of Application
This Policy applies unconditionally to all natural and legal persons utilizing the infrastructure of Ace Xchanger, all transactions processed through the Service’s platform, incoming and outgoing cryptocurrency addresses interacting with our nodes, and all compliance personnel or external contractors managing corporate workflows.
1.3. Regulatory Framework
The regulatory foundation of this document relies upon international legal frameworks, including:
- FATF 40 Recommendations and updated guidance on Virtual Assets and VASPs;
- EU Markets in Crypto-Assets Regulation (MiCA) guidelines;
- EU Anti-Money Laundering Directives (AMLD5, AMLD6);
- Consolidated sanctions lists maintained by the United Nations (UN), the European uniоn (EU), and the US Office of Foreign Assets Control (OFAC SDN List);
- The FATF Travel Rule requirements for crypto-asset transmissions.
—
2. Key Terms and Definitions
The following standardized terminology applies throughout this framework:
| Term | Definition |
|---|---|
| AML / CFT | Anti-Money Laundering and Counter-Financing of Terrorism procedures designed to halt illicit capital movement. |
| KYC (Know Your Customer) | Mandatory identity verification protocols executed prior to or during the rendering of financial and exchange services. |
| KYT (Know Your Transaction) | Real-time, continuous tracking and blockchain data analysis of incoming and outgoing wallet addresses. |
| Risk Score | A mathematical, percentage-based probability indicator generated by automated analyzers to evaluate the potential connection of a transaction to illicit activities. |
| AML Analyzer | Specialized cryptographic analytical software used to audit smart contracts, token history, and wallet exposure. |
| Bona Fide Customer | A legitimate, well-intentioned user whose transaction origin, documentation, and identity are successfully verified as completely disconnected from any criminal or high-risk exposure. |
| SoF / SoW | Source of Funds / Source of Wealth documentation verifying the lawful, verifiable economic origin of the transacted assets. |
| EDD | Enhanced Due Diligence; deeper background verification and investigative reporting applied to high-risk transactions. |
—
3. Principles of AML Control and Risk Scoring
3.1. Certified AML Analyzers and Risk Thresholds
Ace Xchanger does not make arbitrary compliance determinations. The Service analyzes cryptocurrency addresses and blockchain vectors using certified, market-leading analytical platforms:
- Getblock.net is utilized for preliminary, instantaneous automated AML screening and verification of incoming transactions;
- Bitok.org and Blockcluster.pro are utilized by our compliance team for advanced screening, behavioral pattern tracking, structural blockchain forensics, and deep-dive investigations of flagged funds.
Risk tiers are mathematically calculated using a comprehensive Risk Score model assigned to transactions from 0% to 100%:
| Risk Level | Threshold Range | Service Action Required |
|---|---|---|
| LOW RISK | 0% — 49% | The transaction is safe and permissible. The exchange order is executed automatically without any manual intervention. |
| MEDIUM RISK | 50% — 69% | The order triggers a temporary systеm hold. Standard identity verification is initialized, and the item is escalated to our compliance specialists for manual verification and address context analysis. |
| HIGH RISK | 70% — 100% | The transaction is automatically blocked. The systеm locks the incoming funds, halts the exchange workflow, and mandates an immediate transition to full KYC and Enhanced Due Diligence (EDD), including a mandatory Source of Funds (SoF) review. |
3.2. Prohibited Categories and Zero-Tolerance Sources
Certain high-risk transaction markers possess a zero-tolerance status (0% permissible baseline). Any traceable direct or heavy indirect exposure to the following signals will immediately result in a high-risk classification, regardless of the overall average score:
- Child Exploitation material or illicit marketplaces;
- Terrorist Financing signals or networks;
- Ransomware vectors, extortion payouts, or cyber-attack proceeds;
- Explicit addresses appearing on global international sanctions lists (OFAC, UN, EU);
- Darknet Marketplaces and associated darknet infrastructure services;
- Mixing services, decentralized tumblers, and high-anonymity obfuscation tools;
- Stolen coins or assets tied directly to smart contract exploits, hacks, or verified frauds.
3.3. Preliminary Paid AML Screening Option
Before initiating an exchange transaction, users are provided with an independent choice to undergo a preliminary paid AML screening to assess transaction risks beforehand. This evaluation option is integrated into the order creation process:
- Users may independently choose to perform screening via recognized analyzers or proceed via the BestChange AML Screening page, provided the software utilized there is recognized as valid by the Service.
- The user has the option to provide these external screening results to the Service for initial exchange risk assessment.
- Alternatively, the user may knowingly decline the preliminary screening by selecting the dedicated checkbox or acknowledgment pop-up notice, explicitly confirming their complete understanding and acceptance of the related risks, blockchain exposures, and potential automated transaction holds.
—
4. Client Verification Framework (KYC via Didit.me)
4.1. Integration with Verification Infrastructure
To preserve absolute transparency, user data integrity, and strict confidentiality, Ace Xchanger utilizes Didit.me as its exclusive third-party provider for the automated collection, processing, verification, and secure storage of identity records and KYC documents. All personal information is transmitted using end-to-end TLS 1.3 encryption and stored on highly fortified infrastructure secured with AES-256 encryption within SOC 2 and ISO 27001 certified data systems.
4.2. Verification Levels and Materials
Whenever a manual compliance hold or an Enhanced Due Diligence (EDD) sequence is triggered, users must provide valid documentation across the following categories:
- Identity Verification: A high-resolution, unedited photograph of a government-issued International Passport, National Identity Card, or formal Driving License. A live biometric selfie and liveness check executed through the Didit.me terminal is required to confirm identity match.
- Address Verification: A verified utility bill, residential internet invoice, or localized bank statement issued within the trailing six (6) months showing the customer’s full name and address. Digital and paper copies are acceptable provided they contain zero alterations.
- Source of Funds (SoF): Legally sound financial documentation validating how the crypto assets were acquired. This includes corporate salary bank statements, certified P2P exchange history ledgers, investment brokerage records, or screenshots of verified trading balances across compliant,映射 Tier-1 exchanges.
—
5. Liquidity and Transaction Routing Cleanliness
Ace Xchanger enforces strict operational boundaries regarding liquid assets to protect the integrity of outgoing transfers. The Service explicitly guarantees that it does not interact with, mix with, or route client funds through non-compliant, unverified, or high-risk merchant wallets.
All digital currencies dispatched by Ace Xchanger to users are drawn strictly from Tier-1, whitelisted, and well-reputable institutional cryptocurrency platforms and regulated liquidity pools (such as Binance and established global market makers). This guarantees that outgoing assets possess a pristine compliance score and will never place the destination wallet of the receiver at risk of compliance penalties.
—
6. Sequence of Compliance Review Stages and Timeframes
The operational handling of an order transitions through standard, predictable time windows once an asset interacts with our platform:
| Review Stage | Operational Action | Approximate Timeframe |
|---|---|---|
| Stage 1: Automated KYT Screening | Instantaneous address, smart-contract, and wallet validation using real-time automated scoring via Getblock.net. | Instantaneous (1 to 5 minutes upon block confirmation). |
| Stage 2: Manual Specialist Audit | Escalation of flagged or borderline transactions to our compliance specialists for detailed forensics using Bitok.org and Blockcluster.pro tracking metrics. | 1 to 3 business hours from initial systеm hold. |
| Stage 3: Customer Notification | Formal electronic communication dispatching secure compliance documentation request links to the user. | Within 1 business day from order suspension. |
| Stage 4: User Submission Window | The time window allocated for the client to upload clear, unedited verification documents to the secure Didit.me gateway terminal. | Up to 5 business days allocated to the client. |
| Stage 5: Verification Review | Thorough compliance analysis of the uploaded documentation, biometric liveness metrics, and data integrity parameters. | 24 to 48 hours following document submission. |
| Stage 6: Final Resolution | systеm action to complete the original exchange transaction or trigger a secure financial refund to the verified source. | Maximum of 10 business days from the close of the document investigation. |
—
7. Refunds and Administrative Cost Protections
7.1. Strict Fee Limitations and Protections for Bona Fide Users
Ace Xchanger does not authorize the indefinite or arbitrary retention of customer assets without a defined legal or law enforcement mandate. If a transaction is blocked due to non-compliant risk signals or a refusal to fulfill compliance verification protocols, the resolution follows two clear paths:
- Outcome 1: Comprehensive Refund to the Original Source
If a transaction cannot be fully completed but no definitive connection to active malicious criminal enterprise or terrorist networks is proved, the client is granted a full refund of their assets under the following constraints:- Bona Fide Customer Protections: For all legitimate, bona fide customers whose funds, following a standard KYC/SoF compliance review, are explicitly confirmed as completely disconnected from money laundering, malicious intent, or illegal origin, absolutely no administrative fees, exchange surcharges, or penalties will be withheld. The user will be refunded their full principal amount, bearing only the standard, organic blockchain network fee required to transmit the return transaction.
- Administrative Non-Compliance Fee Cap: If a refund is authorized under general compliance risk issues or due to the client’s explicit refusal to undergo the mandatory KYC/SoF review, any administrative processing fee applied to cover transactional forensic costs and compliance infrastructure expenses is strictly limited to documented expenses and must never exceed 5% of the total blocked amount or a maximum cap equivalent to 100 USD.
- Outcome 2: Escalation to Legal Authorities
If clear, undeniable proof emerges that the transaction originates from known criminal organizations, terrorist cells, or severe localized cyber exploits, the Service will freeze the assets, draft an official Suspicious Transaction Report (STR), and place the funds under the strict control of judicial or state law enforcement authorities.
7.2. Guidelines for Objective Communication
The Service ensures that its staff and internal communications utilize entirely neutral, objective, and legally sound terminology. Valuative descriptions or arbitrary personal judgments (e.g., classifying a user as a “fraudster” or “criminal” without a formal court ruling) are strictly prohibited. The correct legal characterizations used by our team inсlude:
- “The transaction has been classified as high-risk due to blockchain analyzer signals.”
- “The client has chosen not to submit required verification materials within the designated timeline.”
- “Processing cannot proceed due to structural non-compliance with established AML threshold guidelines.”
—
8. Sanctions Control and Restricted Platforms
Ace Xchanger enforces absolute isolation from blacklisted and highly dangerous platforms. The Service does not process transactions interacting with high-risk platforms, mixers, or darknet infrastructures. The following platforms are explicitly banned from our network architecture:
Garantex; Tornado Cash; Hydra; Blender.io; Lazarus Group; Genesis Market; CoinCola ; ChipMixer; Shinbad.io; Commex; Capitalist; NetEx24.net; Stake.com; Bitpapa; AlphaPo; Samourai Wallet; Grinex; Rapira; meer.kg; 1xbet and related entities; Aifory.pro; terminal.cash; SkyCrypto.net; FlashObmen.com; 60cek.net; hd-change.com; CoinBlinker.com; Metka.cc; AlfaBit.org; Vexel; Fun Pay; Web Money; Freekassa; Yobit; EXMO; Crypto Cloud; Cripta; BitBits; Nix Money; Bixter; Payeer; Nobitex; alongside any Iranian platforms or custodial systems operating physically inside heavily sanctioned nation-states.
—
9. Data Retention, Privacy and Auditing
All documentation compiled through the Didit.me platform, including transactional hashes, risk assessment telemetry reports generated by Getblock.net, Bitok.org, or Blockcluster.pro, IP network logs, and user identity credentials, is securely retained for a minimum mandatory duration of five (5) years following the formal closure of the business relationship or transaction date, aligning with standard international financial requirements.
Internal compliance updates and systemic infrastructure checks are executed regularly to assess vulnerabilities, monitor analytical accuracy thresholds, ensure policy efficacy, and keep our platform fully updated against the latest global financial directives.
Last Updated: July 2026