AML & KYC Policy
Dernière mise à jour 3 September 2026
Northsec (a trading name of Wallsec Limited) is committed to preventing money laundering, terrorist financing, sanctions evasion and fraud. This summary explains the controls we apply to every customer and every transaction.
1. Framework
Our programme follows the UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the UK Proceeds of Crime Act 2002, applicable EU anti-money-laundering directives, and the compliance requirements of our regulated payment and banking partners.
2. Governance
A nominated compliance officer owns the programme, reports to the company's directors, maintains our written policies and risk assessment, and reviews them at least annually or whenever the law or our services change. Staff receive AML and sanctions training before handling customer files and at least once a year thereafter.
3. Customer due diligence
No account is activated before identity verification is complete. For individuals we collect full name, date of birth, residential address, contact details and a government-issued identity document (passport or both sides of a driving licence), and where required a proof of address and a liveness or face check.
For companies we collect the certificate of incorporation, registered address, ownership structure, and identification of directors and of all beneficial owners holding 25% or more. We also record the intended use of the account, expected transaction volumes and the source of funds and wealth.
4. Risk-based approach and EDD
Each customer is risk-rated on onboarding using country, product, channel and activity factors. Enhanced due diligence applies to politically exposed persons and their close associates, customers connected to higher-risk jurisdictions, complex ownership structures and unusually large or unexplained activity. Enhanced files require senior compliance approval and are reviewed more frequently.
5. Sanctions and PEP screening
Customers, beneficial owners and payment counterparties are screened against UK, EU, UN and OFAC sanctions lists and against PEP and adverse-media data at onboarding and on an ongoing basis. A confirmed sanctions match results in an immediate block, freeze of the balance and a report to the relevant authority. We do not onboard customers resident in, or process payments to or from, sanctioned jurisdictions.
6. Transaction monitoring
Payments and digital asset movements are monitored against the customer's expected profile. Alerts are raised for structuring, rapid pass-through of funds, mismatched beneficiaries, high-risk counterparties, and transfers involving mixers or other high-risk blockchain services. Alerts are investigated by compliance staff and every decision is recorded in an audit log.
7. Reporting suspicious activity
Where we have knowledge or suspicion of money laundering or terrorist financing, we submit a suspicious activity report to the relevant financial intelligence unit and, where necessary, freeze the account. We are prohibited by law from informing a customer that a report has been made.
8. Record keeping
Verification records, transaction records, statements and correspondence are retained for at least five years after the end of the customer relationship or the date of the transaction, and are held securely with access restricted to authorised staff.
9. Refusal, suspension and termination
We may refuse an application, request further information, suspend or freeze an account, or terminate the relationship where verification cannot be completed, where information provided is false or incomplete, where activity is inconsistent with the stated purpose of the account, or where continuing would breach our legal obligations.
10. Contact
Compliance enquiries, including requests from partners and authorities, can be sent to contact@northsec.co.uk.