AML CFT Policy
How Quantoz Payments B.V. prevents money laundering and the financing of terrorism, and the regulatory framework the policy rests on.
Version 1.3. Effective 17 August 2026Introduction
With this policy, Quantoz Payments B.V. (the Company) emphasises the importance of the prevention of and fight against money laundering and terrorist financing. The purpose of this policy is to govern how the Company fulfils its obligations pursuant to AML/CFT regulation. Key elements of this policy are the Customer Due Diligence (CDD) process, the transaction monitoring process, the reporting of unusual transactions and, where relevant, the AML/CFT interface with sanctions-related alerts as further described in the Company's Sanctions Policy.
The Company holds a licence as an electronic money institution, granted by De Nederlandsche Bank (DNB), and is authorised to issue and redeem electronic money and to provide payment services 3 and 5 as referred to in Annex I to PSD2. The Company has extended its licence to include payment services 1 and 2, which authorises the Company to offer payment accounts enabling customers to execute credit transfers to and from third parties outside the Company's own infrastructure. The Company offers these services primarily to business customers, including corporates, fintechs and platforms, both directly and through an embedded model. This policy applies to all products and services offered by the Company. The payment services 1 and 2 activities currently offered by the Company do not include services enabling physical cash, coins or banknotes to be placed on, or withdrawn from, a payment account.
The Company applies a risk-based approach to AML/CFT and maintains a low risk appetite with respect to money laundering and terrorist financing. The Company provides services only to customers whose residual AML/CFT risk, after completion of appropriate customer due diligence, can be adequately mitigated within the Company's risk management framework. Customers classified as unacceptable risk are not serviced by the Company. Existing business relationships that deteriorate to that level are offboarded within a reasonable timeframe.
The Company conducts a Systematic Integrity Risk Analysis (SIRA) at least annually. The SIRA identifies and assesses the integrity risks arising from the Company's products, services, customer base and geographic activities, and directly results in the standards set out in this policy. The SIRA is approved by senior management.
This policy applies to the Company and all staff members involved with the CDD process. The policy is made available to all staff members. Every employee, internal and external, is trained in order to ensure that they are aware of the contents of this policy and are able to apply it, and the related procedures, in their day-to-day practice.
Prior to establishing a business relationship with a customer, the Company ensures that the customer is fully onboarded following the CDD process. During the business relationship the Company monitors the transactions performed by the customer. As soon as the Company identifies an unusual transaction of a customer, the Company reports that transaction to the FIU.
Terms and abbreviations
In this policy the following terms and abbreviations are used.
- Additional Services
- The payment services following the extension of the Company's licence to include payment services 1 and 2, consisting of online-accessible payment accounts in the form of virtual IBANs enabling customers to receive third-party fiat pay-ins and initiate third-party fiat payouts or credit transfers.
- AML
- Anti-Money Laundering.
- Board of Directors
- The Board of Directors of the Company, consisting of the day-to-day policymakers of the Company, being its statutory directors.
- Business relationship
- A business, professional or commercial relationship which is connected with the professional activities of the Company and which is expected, at the time when the contact is established, to have an element of duration.
- CDD
- Customer Due Diligence (cliëntenonderzoek) within the meaning of the Wwft, including, where applicable, the measures referred to in Article 3(2) Wwft: identifying the customer and verifying its identity; identifying the customer's UBO and taking reasonable measures to verify the UBO's identity and, where the customer is a legal person, to understand the customer's ownership and control structure; establishing the purpose and intended nature of the business relationship; conducting ongoing monitoring of the business relationship and transactions; establishing whether any person acting as representative of the customer is authorised to do so and identifying and verifying that person's identity; and establishing whether the customer acts for itself or on behalf of a third party.
- CFT
- Combating the Financing of Terrorism.
- Company
- Quantoz Payments B.V.
- Compliance officer
- The person or persons designated by the Company to perform the AML/CFT compliance function under this policy, including monitoring compliance with the Wwft and the Company's AML/CFT policies and procedures, coordinating FIU reporting obligations and advising the Board of Directors and the board member responsible for AML/CFT compliance.
- Customer
- Any natural or legal person with whom the Company enters or intends to enter into a business relationship.
- DNB
- De Nederlandsche Bank N.V., the Dutch central bank.
- DNB Q&As and Good Practices Wwft
- DNB guidance on the Wwft, published on 8 May 2024, as amended or replaced from time to time.
- EBA ML/TF Risk Factors Guidelines
- The Guidelines on customer due diligence and the factors credit and financial institutions should consider when assessing the money laundering and terrorist financing risks associated with individual business relationships and occasional transactions under Articles 17 and 18(4) of Directive (EU) 2015/849, from the European Banking Authority.
- FIU
- The Financial Intelligence Unit, Netherlands.
- Policy
- This AML/CFT policy.
- Staff
- Any employee or such other person who performs activities under the responsibility of the Company involved with the performance of the CDD procedures or supervision of its performance.
- Supervisory Board
- The Supervisory Board of the Company.
- Sw
- The Dutch Sanctions Act 1977 (Sanctiewet 1977).
- Travel Rule Regulation
- Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849.
- Wft
- The Dutch Financial Supervision Act (Wet op het financieel toezicht).
- Wwft
- The Dutch Anti-Money Laundering and Counter Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme).
Legal framework
This policy is derived from and should be read in light of the following legal and regulatory sources, to the extent applicable to the Company:
- the Wwft;
- the Implementing Decree Wwft 2018;
- the Implementing Regulations Wwft;
- Wft Articles 3:10 and 3:17 and Bpr Wft Article 10, to the extent relevant to integrity risk management, controlled and sound business operations and the Company's systematic integrity risk analysis;
- the EBA ML/TF Risk Factors Guidelines;
- the EBA Guidelines on the role and responsibilities of the AML/CFT compliance officer;
- the DNB Q&As and Good Practices Wwft;
- the General Guidance on the Wwft published by the Dutch Ministry of Finance and the Ministry of Justice and Security;
- the Travel Rule Regulation and the EBA Travel Rule Guidelines, to the extent relevant to transfers of funds and certain crypto-assets; and
- the GDPR, to the extent relevant to the processing of personal data for AML/CFT purposes.
The Company maintains a separate Sanctions Policy. Sanctions legislation and sanctions-screening controls are therefore addressed primarily in that policy, while this policy addresses the AML/CFT relevance of sanctions-related alerts and findings where applicable.
The Company monitors future developments under the EU AML/CFT framework, including Regulation (EU) 2024/1624, Directive (EU) 2024/1640 and Regulation (EU) 2024/1620. This policy has not been converted into an AMLR-based policy at this stage, as the current Wwft framework remains applicable.
Money laundering and terrorist financing
The term money laundering means an act intended to have the effect of making any property:
- that is the proceeds obtained from the commission of a criminal offence under Dutch law, or of any conduct which if it had occurred in the Netherlands would constitute a criminal offence under Dutch law; or
- that in whole or in part, directly or indirectly, represents such proceeds, not to appear to be or so represent such proceeds.
There are three common stages in the laundering of money, and they frequently involve numerous transactions. These stages are:
- Placement. The physical disposal of cash proceeds derived from illegal activities.
- Layering. Separating illicit proceeds from their source by creating complex layers of financial transactions designed to disguise the source of the money, subvert the audit trail and provide anonymity.
- Integration. Creating the impression of apparent legitimacy to criminally derived wealth. In situations where the layering process succeeds, integration schemes effectively return the laundered proceeds back into the general financial system and the proceeds appear to be the result of, or connected to, legitimate business activities.
The term terrorist financing means:
- the provision or collection, by any means, directly or indirectly, of any property with the intention that the property be used, or knowing that the property will be used, in whole or in part, to commit one or more terrorist acts, whether or not the property is actually so used; or
- the making available of any property or financial or related services, by any means, directly or indirectly, to or for the benefit of a person knowing that, or being reckless as to whether, the person is a terrorist or terrorist associate; or
- the collection of property or solicitation of financial or related services, by any means, directly or indirectly, for the benefit of a person knowing that, or being reckless as to whether, the person is a terrorist or terrorist associate.
Policy governance
The Board of Directors adopts and implements this policy and is responsible for its application in day-to-day practice. This policy may be amended from time to time by a decision of the Board of Directors, in coordination with the Supervisory Board. Staff are informed of any material change to this policy.
The Company has installed a compliance function that is responsible for monitoring the Company's compliance with this policy, as referred to in Article 2d(3) Wwft. Operational implementation of AML/CFT controls is carried out by the relevant business owners and staff under the oversight of the compliance function. The internal audit function is outsourced to an external party.
In order to guarantee compliance with laws and regulations, the Company evaluates the effectiveness of this policy on an annual basis as well as ad hoc if required. The policy is also reviewed annually to ensure it is in line with the Company's risk appetite. The compliance officer maintains the policy and involves the compliance function and specialised legal advisers when performing this task.
Each staff member may report breaches of this policy internally to the board member responsible for AML/CFT compliance, anonymously or otherwise. The Company does not disadvantage any staff member in any way for having reported a breach of this policy internally, or for having reported unusual transactions to the FIU in line with the applicable procedures.
Roles and responsibilities
Board of Directors
The Board of Directors is responsible for approving the Company's overall AML/CFT strategy and for overseeing its implementation. The Board of Directors:
- implements the appropriate and effective organisational and operational structure necessary to comply with the AML/CFT strategy it has adopted, paying particular attention to sufficient authority and to the appropriateness of the human and technical resources allocated to the compliance function, including the need for dedicated AML/CFT knowledge available for the compliance officer;
- ensures that a risk assessment framework for business-wide and individual AML/CFT risk assessments is developed and maintained;
- ensures implementation of internal AML/CFT policies and procedures;
- ensures that the compliance function and the internal audit function are able to perform their responsibilities properly in relation to this policy and the AML/CFT procedures;
- ensures adequate, timely and sufficiently detailed AML/CFT reporting to the competent authorities;
- where operational functions of this policy or the AML/CFT procedures are outsourced, ensures compliance with the applicable laws and regulations, including guidance of the competent authorities, and receives regular reporting from the service provider.
The board member responsible for AML/CFT compliance:
- ensures that this policy, the AML/CFT procedures and the internal control measures are adequate and proportionate, taking into account the nature, size and activities of the Company and the AML/CFT risks to which it is exposed;
- ensures that sufficient capacity and knowledge is available for staff members involved in executing this policy, in the first line of defence as well as in compliance and internal audit;
- ensures that there is periodical reporting to the Board of Directors on the activities carried out by the compliance officer, and that the Board of Directors is provided with sufficiently comprehensive and timely information on AML/CFT risks and compliance. Such information also covers the Company's engagements with the national competent authority and communications with the FIU, without prejudice to the confidentiality of suspicious transactions, and any AML/CFT-related findings of the competent authority against the Company including measures or sanctions imposed;
- informs the Board of Directors of any serious or significant AML/CFT issues and breaches and recommends actions to remedy them;
- ensures that the compliance officer has direct access to all the information necessary to perform their tasks, has sufficient human and technical resources and tools, and is well informed of AML/CFT-related incidents and shortcomings identified by the internal control systems and by supervisory authorities;
- acts as the main contact point in the Board of Directors for the compliance officer;
- ensures that any AML/CFT concerns the compliance officer has are duly addressed and, where this is not possible, are duly considered by the Board of Directors. If the Board of Directors decides not to follow the recommendation of the compliance officer, it justifies and records that decision in light of the risks and concerns raised;
- ensures that in the case of a significant incident, the compliance officer has direct access to the Supervisory Board.
Supervisory Board
The Supervisory Board is responsible for overseeing and monitoring the implementation of the internal governance and internal control framework to ensure compliance with applicable requirements in the context of the prevention of money laundering and terrorist financing. The Supervisory Board:
- is informed of the results of the business-wide AML/CFT risk assessment;
- oversees and monitors the extent to which the AML/CFT policies and procedures are adequate and effective in light of the AML/CFT risks to which the Company is exposed, and takes appropriate steps to ensure remedial measures are taken where necessary;
- at least once a year, discusses activities that expose the Company to higher AML/CFT risks;
- at least once a year, assesses the effective functioning of the compliance function, including by taking into account the conclusions of any AML/CFT-related internal or external audits, and including the appropriateness of the human and technical resources allocated to the compliance officer;
- ensures that the board member responsible for AML/CFT compliance has the knowledge, skills and experience necessary to identify, assess and manage the AML/CFT risks to which the Company is exposed, has a good understanding of the Company's business model and the sector in which it operates, and is informed in a timely manner of decisions that may affect the risks to which the Company is exposed.
Compliance officer
The compliance officer:
- reports the results of the business-wide and individual AML/CFT risk assessments to the Board of Directors and proposes the measures to take to mitigate those risks. The launch of a new product or service, significant changes to existing ones, the development of a new market or the undertaking of new activities are not initiated until adequate resources to understand and manage the associated risks are available and effectively implemented;
- ensures that adequate policies and procedures are put in place, kept up to date and implemented effectively on an ongoing basis, commensurate with the AML/CFT risks the Company has identified;
- is consulted before a final decision is taken by senior management on onboarding new higher-risk customers or maintaining business relationships with them, and in particular where senior management approval is explicitly required by law. If senior management decides not to follow the advice of the compliance officer, it records its decision and addresses how it proposes to mitigate the risks raised;
- monitors whether the measures, policies, controls and procedures implemented by the Company comply with the Company's AML/CFT obligations, and oversees the effective application of AML/CFT controls applied by business lines and internal units;
- recommends to the Board of Directors corrective measures to address identified weaknesses in the Company's AML/CFT framework, including weaknesses identified by competent authorities or by internal or external auditors;
- advises the management body on measures to be taken to ensure compliance with applicable laws, rules, regulations and standards, and provides an assessment of the possible impact of any changes in the legal or regulatory environment;
- brings to the attention of the board member responsible for AML/CFT the areas where AML/CFT controls should be implemented or improved, the improvements suggested, a progress report of any significant remedial programmes at least once a year, and whether the human and technical resources allocated to the compliance function are insufficient;
- is responsible for notifying the FIU of any unusual transactions;
- is responsible for notifying DNB in the case of a true hit under the sanctions regulation;
- informs staff about the AML/CFT risks to which the Company is exposed, including methods, trends and typologies, as well as the risk-based approach implemented to mitigate them;
- oversees the preparation and implementation of an ongoing AML/CFT training programme, and ensures that the internal reporting procedures adopted by the Company are brought to the attention of all staff.
Internal audit function
The internal audit function is responsible for controlling the adequate functioning of the compliance function in the context of its role with respect to this policy and compliance with AML/CFT regulation in general. The exact role of the internal audit function is laid down in the annual programme of the internal auditor.
The risk-based approach
The Company uses a risk-based approach to combat money laundering and terrorist financing. The general principle is that where customers are assessed to be of higher AML/CFT risk, the Company takes enhanced measures to manage and mitigate those risks, and that correspondingly where the risks are lower, simplified measures may be applied.
Business-wide risk assessment
The Company takes the appropriate steps to identify, assess and understand the AML/CFT risks in relation to its business. The Company records the results in its SIRA and keeps the risk assessment up to date, evaluating and updating it if necessary and in any event annually. The risk assessment takes into account at least:
- the risk factors set out in the applicable AML/CFT framework, including AMLD4 as amended, the EBA ML/TF Risk Factors Guidelines, and, as relevant for horizon-scanning purposes, the forthcoming EU AML/CFT framework;
- the supranational risk assessment report published by the European Commission; and
- the national risk assessment report published by the Dutch Minister of Finance and the Dutch Minister of Justice and Security.
Where possible, the relevant risks are supported by qualitative and quantitative analysis and information obtained from relevant internal and external sources. If required by DNB, the Company sends the outcome of the most recent risk assessment to DNB.
Customer risk assessment
The Company assesses the AML/CFT risks of customers. Relevant factors in this risk assessment are customer risk, geographic risk, product risk, delivery channel risk, PEP risk, sanctions risk and other risks such as compliance and regulatory findings and audit findings. This list is not exhaustive and may change from time to time.
Based on this risk assessment, customers are classified as low, medium, high or unacceptable risk. High and unacceptable risk consumers, being natural persons, are not serviced by the Company. Unacceptable risk business customers, including merchants where applicable, are not serviced by the Company.
During the year, the Company records matters that may affect the established risk profile, the transaction profile of the customer and the risk analysis as a whole, such as internal reports of suspicious transactions or information about physical and non-physical contact with customers. The Company may adjust the risk classification of a particular customer based on a review, whether event-driven or regular.
If the Company learns before the annual update of this policy that a new AML/CFT risk has arisen, or that an existing risk has increased, the Company assesses on a risk-based basis whether and to what extent relevant customer risk classifications or customer groups should be reviewed or adjusted.
Politically exposed persons
Identification of a customer or UBO as a politically exposed person (PEP) always leads to enhanced customer due diligence. During enhanced due diligence, the compliance officer may request additional information and documentation from the customer, assesses that information and documentation, and assigns the customer a risk level accordingly.
In accordance with Article 8(5)(b)(1°) to (3°) Wwft, read in conjunction with Article 8(8) Wwft, where a customer or UBO is identified as a PEP, a family member of a PEP or a person known to be a close associate of a PEP, the Company applies the following enhanced measures in addition to the standard CDD measures:
- the approval of senior management is obtained before establishing or continuing the business relationship or, where applicable, before carrying out an occasional transaction;
- adequate measures are taken to establish the source of wealth and the source of funds involved in the business relationship or the occasional transaction; and
- enhanced ongoing monitoring of the business relationship is conducted.
Where a customer or UBO becomes or is found to be a PEP during an existing business relationship, the Company applies these measures without delay, in accordance with Article 8(9) Wwft. Where a customer or UBO ceases to be a PEP, the Company continues to apply these measures for at least twelve months thereafter and subsequently for as long as the higher risk associated with the person's former PEP status persists, in accordance with Article 8(7) Wwft.
Customer due diligence
The Company performs CDD with respect to its customers and has implemented a risk-based approach to conducting it. Every customer is assigned a risk rating before onboarding and differentiated customer due diligence measures are adopted accordingly.
The Company does not enter into a business relationship before the proper level of CDD has been concluded successfully. All customers are subject to continuous monitoring during the entire lifecycle of the business relationship.
Outsourcing customer due diligence
Where the Company uses a third party or third-party tooling to perform or support parts of the CDD process, the Company assesses whether the arrangement qualifies as outsourcing, the use of ICT services from a third-party service provider, both, or neither, in accordance with the Company's Outsourcing Policy.
The Company may have a third party perform only those parts of the CDD process that may be outsourced under Article 10 Wwft, including the identification and verification of the customer, the identification and verification of the customer's UBO, establishing the purpose and intended nature of the business relationship, establishing the authority of and identifying and verifying any representative of the customer, and verifying whether the customer acts for itself or on behalf of a third party.
The Company remains responsible for compliance with the Wwft. The decision whether to enter into, continue or terminate a business relationship, the customer risk classification and the ongoing monitoring of the business relationship and transactions remain with the Company. The use of third-party software or third-party service providers to support CDD or monitoring does not relieve the Company of these responsibilities.
Where the performance of parts of the CDD process by a third party has a structural character, the Company records the arrangement in writing and ensures that it is assessed and governed in accordance with the Outsourcing Policy and applicable privacy and information-security requirements. Where relevant, the Company takes into account the policies, procedures and operational controls of the relevant third party in relation to the outsourced CDD elements, provided that these are not impermissibly inconsistent with the Company's own AML/CFT policy, Outsourcing Policy or applicable legal requirements.
Ongoing monitoring
The Company continuously monitors the business relationship with a customer and the transactions performed by or on behalf of a customer, to ensure that they are in line with the Company's knowledge of the customer, including its financial situation and its risk profile. These reviews can consist of periodic reviews and event-driven reviews.
In addition to the ongoing monitoring of customer business relationships, the Company monitors payment transactions processed on behalf of holders of payment accounts, including virtual IBANs. Because incoming and outgoing payments may involve third-party counterparties that are not customers of the Company, the Company applies transaction-level and pattern-based monitoring to detect unusual activity in payment flows based on the customer's transactional profile, expected activity and risk classification.
Relevant indicators may include, without limitation, unusual volumes or frequencies, high-risk jurisdictions, rapid in-and-out movement of funds, counterparty concentration, pass-through patterns, structuring indicators and payments inconsistent with the customer's business profile.
The Company pays special attention to the detection of unusual transactions and monitors and investigates customer activities which, by their nature, could be regarded as associated with money laundering or terrorist financing. The Company subsequently makes an independent assessment of whether the transaction at hand is usual or unusual, which may mean investigating the case in more detail. If necessary, the transaction is reported to the FIU. Any such investigation is performed urgently, as unusual transactions must be reported promptly and without delay once the Company becomes aware of the unusual nature of the transaction.
The Company may request additional information or documentation from a customer in order to determine whether a transaction is unusual.
Sanctions
The Company maintains a separate Sanctions Policy setting out the procedures and controls for compliance with applicable sanctions legislation, including screening of relevant relations and transactions, handling of potential matches, freezing measures and reporting to DNB where required. For the purposes of this policy, sanctions-related alerts, potential matches or confirmed matches may also be relevant as indicators for AML/CFT risk assessment, ongoing monitoring and, where appropriate, the assessment of whether an unusual transaction report to the FIU is required.
Travel Rule
The Company operates three business models, each with different characteristics when it comes to the applicability of the Travel Rule.
The first is a fully closed-loop model, where all e-money token transactions take place entirely within the Company's own infrastructure. Customers use wallets and accounts that are fully controlled by the Company, with no interaction with external platforms or third-party wallets. Since there are no transfers leaving the closed environment, the Travel Rule does not apply.
The second model includes both a primary and a secondary market. In the primary market, all users are fully verified, and transactions occur without any change in ownership. Because no value is actually transferred between separate parties, these transactions fall outside the scope of the Travel Rule Regulation. In the secondary market, e-money tokens are exchanged between customers within the Company's own infrastructure. Because the Company maintains KYC-verified customer information on both the originating and the receiving side of every secondary market transaction, and no transfer occurs to or from an external payment service provider, the Company satisfies the requirements of Regulation (EU) 2023/1113 by retaining all required originator and beneficiary data internally. No separate information transmission to another payment service provider is required.
The third business model consists of the offering of payment accounts in the form of virtual IBANs to customers. Under this model, the Company acts as the account-servicing payment service provider and processes SEPA credit transfers on behalf of virtual IBAN holders. Unlike the first and second models, the counterparties to these transactions, the payers and payees, are not necessarily customers of the Company and have not been subject to the Company's own CDD procedures. The SEPA transactions of the third business model constitute fund transfers within the scope of the Travel Rule Regulation. The Company ensures that the required payer and payee information accompanies all SEPA credit transfers processed on behalf of virtual IBAN payment account holders, and that this information is retained in accordance with Article 26 of Regulation (EU) 2023/1113 for a minimum of five years.
Depending on the role the Company performs in a given transfer of funds, the Company applies role-dependent, risk-based procedures in accordance with Articles 4 to 13 of Regulation (EU) 2023/1113.
Where the Company acts as the payment service provider of the payer, it ensures that transfers of funds are accompanied by the required payer and payee information and verifies the accuracy of the payer information, in accordance with Articles 4 to 6.
Where the Company acts as the payment service provider of the payee, it implements effective risk-based procedures to detect missing or incomplete payer or payee information and to determine, on a risk-sensitive basis, whether to execute, reject or suspend the transfer of funds and which appropriate follow-up action should be taken, in accordance with Articles 7 to 9.
Where the Company acts as an intermediary payment service provider, it applies the corresponding requirements of Articles 10 to 13. Missing or incomplete information therefore does not automatically lead to the rejection or suspension of a transfer of funds in every case; the appropriate response is determined on a risk-sensitive basis.
Reporting of unusual transactions
The Company promptly reports all unusual transactions to the FIU when the objective indicator is triggered or upon becoming aware of the unusual nature of such a transaction. Such filing provides the Company with an indemnification with respect to the offence of money laundering or terrorist financing in respect of the acts mentioned in the filing, if:
- the report is made before the Company undertakes the disclosed acts and the transactions are undertaken with the consent of the FIU; or
- the report is made after the Company has performed the disclosed transactions and the report is made on the Company's own initiative and as soon as it is reasonable for the Company to do so.
Pursuant to the Wwft, the Company and persons working for the Company are obliged, unless and insofar as disclosure is required under the Wwft, to keep confidential the fact that a report of an unusual transaction has been or will be made to the FIU. It is an offence, known as tipping off, to reveal to any person any information which might prejudice an investigation. If a customer is told that a report has been made, this would prejudice the investigation and an offence would be committed.
Training of staff
Board members and relevant staff are trained on the AML/CFT requirements to the extent relevant for the performance of their duties. The content and intensity of the training is tailored to the AML/CFT risks, nature and size of the Company. Board members and relevant staff are trained, among other things, on how to identify unusual transactions in practice.
The Company organises at least one internal session among the board members and relevant staff in order to understand the scope and content of this policy. If amendments have been made to this policy, board members and relevant staff are provided with the revised policy and, if required, an explanation of the changes in the form of internal training sessions. This policy is always available for all relevant staff members.
Staff members who are primarily responsible for the maintenance and execution of this policy may attend external training about the Wwft, AML/CFT, the sanctions interface and integrity requirements in general, where relevant for their role. Where relevant in the case of amendments in applicable AML/CFT regulation, additional external training sessions may need to be attended. The Company engages external advisers to advise on any amendments in applicable AML/CFT regulations, such as in connection with the implementation of any new EU money laundering directive or other new legislation. This may also qualify as training for this purpose.
Evidence of each training session is recorded for five years, or longer if necessary for the Company to comply with its legal obligations, all in compliance with the provisions of the GDPR. The Company has set up a training and education plan, which is reviewed and updated annually by the compliance officer.
Integrity of staff
To ensure that staff are reliable, uphold the integrity standards of the Company and are not involved in criminal activities, it is important that a staff member is screened before employment. This enables the Company to establish an estimation of his or her integrity, reliability and susceptibility to fraud, money laundering and other potential issues. The pre-employment screening of employees is set out in the Company's recruitment, selection and screening policy.
Record keeping
All information and documentation obtained in respect of a customer is recorded, in the individual customer file, for at least five years following the termination of the business relationship with the customer. This includes information and documentation obtained in connection with the risk assessment, customer due diligence, any updates of the information, sanctions-related records to the extent relevant under the Sanctions Policy, Travel Rule information where applicable, reported unusual transactions, transaction-monitoring alerts and dispositions, and evidence and records of transactions executed for customers.
The Company maintains all information in individual customer files in order to be able to retrieve all relevant information in case of information requests from the FIU, DNB or the AFM.
The documents retained include in any event the data set out in Article 33(2) of the Wwft, which encompasses the following.
For natural persons:
- first name or names, surname, gender, date of birth, residency and, if applicable, the person who acts on behalf of the customer;
- the type of identity document that is verified, the document number, the date the document expires and the issuing country.
For ultimate beneficial owners:
- the identity, including at least the first name or names and surname;
- the documents used to verify the identity of the ultimate beneficial owner.
For legal persons:
- the legal form, the registered name, the trade name, the address, the registered place of business and the country of registered office;
- if the company or other legal entity is registered with the Chamber of Commerce, the registration number and the way in which the identity has been verified;
- of those who act for the company or legal entity in the institution: the surname, the first names and the date of birth.
Privacy
The Company processes personal data within the meaning of the GDPR, as collected on the basis of this policy, in accordance with the provisions of the GDPR and implementing legislation. The Company only processes personal data obtained under the Wwft procedure to the extent that such processing is necessary to comply with a legal obligation, including the obligations arising from the Wwft and the Sanctions Act.
Personal data is not processed for other, commercial purposes. Insofar as the Company intends to process personal data collected on the basis of this policy for purposes other than those stated above, the Company informs the relevant data subjects about this prior to the intended processing.
Before entering into a business relationship or performing an incidental transaction, the Company informs the customer in accordance with Article 13 GDPR or Article 14 GDPR, as applicable, of the context in which personal data will be processed. The customer is informed through the Data Protection Policy on this website.
The Company destroys the personal data it has obtained in the context of this policy if the processing is no longer necessary for the purpose being served, subject to the statutory retention periods that apply to the Company. The Company in any event destroys the relevant personal data immediately after the expiry of the statutory retention period of five years referred to in Articles 33(3) and 34 of the Wwft, unless otherwise provided by law.
Contact
If you have any questions relating to this policy, please contact us at contact@quantozpay.com.
Version 1.3. Effective 17 August 2026.