Aml Policy

Introduction

Xhjili is a remote gaming operator licensed to provide online casino and betting services. This Anti-Money Laundering Policy (AML Policy) establishes the controls, responsibilities, and processes implemented to detect, prevent, and report money laundering and the financing of terrorism across all Xhjili activities, products, and customer relationships. The Policy aligns with applicable national AML/CFT legislation, guidance from the competent supervisory authorities, and international standards, including FATF recommendations, and applies to all Xhjili personnel, contractors, and agents.

Scope and Applicability

This Policy governs all aspects of Xhjili's business operations, including customer onboarding, ongoing customer relationships, and all payment transactions and product offerings. It covers casino games, live dealer activities, and sports betting, and applies to all jurisdictions in which Xhjili operates or facilitates customer activity.

Regulatory Framework

Xhjili operates under the AML/CFT regime applicable to its licensing jurisdiction and is subject to supervision by the designated regulatory authority. The Policy implements the requirements of relevant national laws and guidelines governing customer due diligence, record keeping, reporting, and the prevention of money laundering and the financing of terrorism. Where applicable, Xhjili incorporates international standards and the supervisory authority’s guidance to maintain an effective control environment.

Policy Governance and Responsibilities

The ultimate responsibility for the AML Policy rests with the Board, with day-to-day oversight conducted by the Chief Compliance Officer (CCO) and the dedicated AML/compliance function. The CCO leads the design, implementation, training, monitoring, and periodic review of AML controls. Internal audit and senior management participate in ongoing assurance activities, including updates to the risk framework and control enhancements following regulatory developments.

Risk-Based Approach and Risk Management

Xhjili operates a risk-based approach to prevent financial crime. The risk framework classifies AML risk into core domains: client risk, product risk, interface (channel) risk, and geographical risk. An initial risk assessment is conducted at onboarding and reviewed on an ongoing basis, with monthly reassessments to reflect changes in products, customers, or markets. The risk rating determines the depth of due diligence, monitoring intensity, and escalation procedures.

  • High risk indicators include new high value customers, complex ownership structures, unusual transaction patterns, or customers from higher risk geographies.
  • Medium and low risk profiles are monitored with proportionate diligence and ongoing review.

Customer Due Diligence and Ongoing Monitoring

Onboarding and ongoing monitoring are performed on a risk-based basis to identify and verify the identity of customers and to assess the purpose and intended nature of the business relationship. The procedures cover:

  • Initial due diligence to establish identity, verify identity, and collect information about the customer and the purpose of the relationship;
  • Ongoing due diligence to keep customer information up to date and to monitor transactions for suspicious activity;
  • Periodic review of high risk customers and transactions, with enhanced monitoring where warranted by risk factors.

Know Your Customer (KYC) and Identity Verification

All customers must be subject to verification before or during the course of business. Verification procedures include the following documented requirements:

  • Identity Verification: submission of government issued identification documents (for example, a passport, national identity card, or driver’s license) that clearly show the customer’s name, date of birth, and photograph.
  • Address Verification: documentation dated within the last three months confirming residential address (for example, utility bill, bank statement, or official government correspondence).
  • Payment Verification: where required for security, verification of payment methods (for example, front and back copy of the payment card with sensitive data redacted, or statements confirming ownership of the payment source).
  • Age Verification: customers must be above the legal age for gambling in their jurisdiction and not minors under applicable law.

All verification information is processed in accordance with data protection requirements. Non-face-to-face onboarding and ongoing monitoring are performed using risk-based, documented procedures with appropriate escalation where needed.

Enhanced Due Diligence (EDD)

Where risk indicators are present or where customers engage in high risk activity, Xhjili undertakes Enhanced Due Diligence. EDD procedures may include additional identity checks, verification of the source of funds and source of wealth, enhanced transaction monitoring, and, where applicable, beneficial ownership verification. Any EDD activity requires approval by the designated AML authority within Xhjili and is documented for audit purposes.

Source of Funds and Source of Wealth

For higher risk customers or transactions, Xhjili requires documentation to establish the source of funds and, where relevant, the source of wealth. Acceptable evidence includes employer pay slips, tax statements, bank statements showing inflows, or other corroborating documentation consistent with the customer’s stated business activities and transaction history.

Data Protection and Privacy

Personal data collected for AML purposes is processed lawfully, kept confidential, and stored securely with access restricted to authorized personnel. Data retention complies with applicable laws and is sufficient to meet regulatory and audit requirements. Data subjects’ rights and cross-border transfer controls are observed as required by data protection legislation.

Record Keeping and Data Retention

All records arising from AML/CFT procedures, including identity verification, due diligence, risk assessments, transaction monitoring, and internal reporting, are maintained for at least the minimum period required by applicable law and regulatory guidance, or longer where warranted by risk or litigation holds. Records are stored securely and are readily retrievable for regulatory examination or internal audits.

Monitoring, Screening, and Reporting

Transaction monitoring and screening systems are employed to identify and escalate suspicious activity. Internal reporting channels are available for staff to raise concerns, and the Compliance function coordinates reporting to the appropriate supervisory or law enforcement authorities in accordance with applicable law. No disclosure or tipping-off is permitted when handling sensitive information or ongoing investigations.

Training and Awareness

All Xhjili personnel receive AML/CFT training at onboarding and on an ongoing basis. Training covers legal obligations, red flag indicators, customer due diligence procedures, internal reporting requirements, and the process for escalation and cooperation with authorities. Training effectiveness is assessed through periodic reviews and targeted refreshers.

Review, Amendments, and Continuous Improvement

This AML Policy is reviewed at least annually or in response to regulatory changes or material risk events. Updates are approved by the Board and communicated to staff. The compliance program includes ongoing assurance activities, including testing of controls and remediation of any identified deficiencies.

Roles, Responsibilities, and Contact

The Board retains ultimate responsibility for AML governance. The Chief Compliance Officer leads the implementation of controls, monitoring, and reporting. All staff have a duty to comply with this Policy, report concerns promptly, and cooperate with regulatory examinations. For AML related inquiries or to report concerns, contact the Xhjili Compliance Department at compliance@Xhjili.