1. Our commitment
BitHz does not knowingly allow the platform to be used to launder money, to finance terrorism or to move funds for a person or entity that is subject to sanctions. We build the controls that make that promise real, and we accept that they cost us customers and revenue.
Our programme follows the federal anti-money laundering and counter-terrorist financing laws of the United Arab Emirates and the standards of the Financial Action Task Force, alongside the rulebooks and directives of the Virtual Assets Regulatory Authority of Dubai.
2. Who is responsible
A Compliance Officer, supported by a Money Laundering Reporting Officer, owns the programme and reports to the board. The compliance function is independent of the business teams, has access to every record it needs, and can stop a customer relationship or a transaction without asking the commercial side.
Our policies are documented, reviewed at least once a year and whenever the business or the rules change, and they are tested by an independent reviewer who is not involved in running them.
3. Knowing our customers
We do not open an account before we have identified and verified the customer. We collect the customer's name, date of birth, nationality, address and identity document, verify them against reliable sources, and identify the beneficial owner behind a corporate customer.
Every customer is risk-rated at onboarding and again as their activity changes. The rating sets how much we ask for and how closely we watch the account.
We must be able to explain where a customer's funds come from. Where a customer cannot provide that explanation, we do not open the relationship, and we may have to undo it.
4. Higher-risk customers
Some customers carry more risk: politically exposed persons and their close associates, customers in higher-risk countries, customers whose funds come from opaque sources, and customers whose activity does not match their profile. For them we apply enhanced due diligence:
- we establish the source of funds and the source of wealth, and check them against documents
- we establish why the customer wants the relationship and why they are moving the amounts they move
- we get senior management approval before the relationship starts or continues
- we re-check the customer's documents and profile more often, and watch the account more closely
5. Sanctions and screening
We screen customers, beneficial owners and transactions against the sanctions lists that apply to us, including the consolidated lists of the United Nations Security Council and the local terrorist list maintained by the Executive Office for Control and Non-Proliferation.
We also screen the blockchain addresses a customer deposits from or withdraws to, using analytics that trace the origin of funds. A match is investigated before the transaction is allowed to complete.
6. Watching transactions
Every account is monitored continuously against rules and behavioural profiles that we document, approve and review. Unusual activity — an unusual amount, an unusual pattern, a sudden change in behaviour, or a transfer linked to a high-risk address — is raised with the compliance team for investigation.
We keep the indicators we look for up to date, so that the alerts follow the ways that money is actually moved.
7. Reporting suspicious activity
Anyone in BitHz who knows or suspects that funds are the proceeds of crime, or that a transaction is linked to money laundering or terrorist financing, must report it immediately to the Money Laundering Reporting Officer — and may not discuss it with the customer or with colleagues who are not involved.
The Money Laundering Reporting Officer reports to the Financial Intelligence Unit of the United Arab Emirates through the goAML platform, immediately and without filtering the report. We answer follow-up requests from the Financial Intelligence Unit and from our regulator promptly, and within 48 hours.
We continue to monitor a customer whose transaction has been reported, and we do not act in a way that would tell them that a report was made.
8. Information that travels with a transfer
Transfers of virtual assets to or from another regulated platform carry the information the law requires about the sender and the recipient, and we verify it. Verification is mandatory for transfers at or above AED 3,500 and for any transfer that we consider suspicious.
Where a transfer involves a self-hosted wallet, we apply enhanced checks: we confirm the customer controls the wallet and establish where the funds come from. If the information we need cannot be provided, we decline the transfer, delay it, or handle the assets as the rules require.
We only send to, and accept from, counterparties that are properly regulated, and we do our own checks on them.
9. What we do not allow
The following are not permitted on the platform, and accounts involved in them are closed and reported where the law requires:
- anonymity-enhanced virtual assets, and any asset whose design hides the sender, the recipient or the amount
- funds that come from a mixer, a tumbler or another service that hides the origin of the assets
- structuring — splitting an amount into smaller pieces to stay under a reporting or verification threshold
- transferring to or from a platform that is not regulated, or that we cannot identify
- accounts opened with false, borrowed or third-party identity documents
- transactions for a person or entity that is subject to sanctions
10. Records we keep
We keep the records of our identity checks, our customers' transactions, our monitoring and our reports for at least 8 years after the end of the customer relationship, and indefinitely where a record may relate to national security. The records are kept in their original format, with the audit trail needed to reconstruct a transaction.
We give these records to our regulator and to the authorities when they ask for them.
11. Training and audit
Everyone who works on the platform is trained on money laundering and terrorist financing when they join and at least once a year afterwards, including the people who handle customer support and withdrawals. The training covers the indicators we watch for and what to do when they appear.
Our controls are tested every quarter by our own compliance team and at least once a year by an independent reviewer whose work is not carried out by the same firm that advises us on the programme.
12. What we need from you
Our controls only work if the information we hold is right. Please help us by:
- keeping your personal details and documents up to date, and answering our requests promptly
- explaining where the funds you deposit came from, and giving us the documents that show it
- confirming your own wallet address when you withdraw, and telling us if you are sending to a third party
- telling us before you become a politically exposed person, or if your circumstances change in a way that affects our risk assessment
We may have to pause a withdrawal, decline a deposit or close an account while we carry out these checks. We know that is inconvenient, and we do it because the law requires it.
13. Contact
For questions about this policy or about a verification request, write to [compliance email]. To report suspicious activity on the platform, use the same address.