1. Purpose
This Financial Crime Prevention Policy establishes Kuraye's framework for preventing, detecting, and responding to financial crime. The policy covers money laundering, terrorist financing, proliferation financing, bribery, corruption, fraud, cybercrime, account takeover, identity theft, invoice fraud, marketplace abuse, shell companies, and synthetic identities.
2. Scope
This policy applies to all business operations, including digital marketplace transactions, enterprise software and implementation services, customer onboarding and due diligence, payment processing and settlement, marketplace seller and buyer relationships, employee and contractor conduct, third-party partnerships and agency relationships, and technology and data security.
3. Money Laundering & Terrorist Financing
Money laundering is the process of disguising the proceeds of crime to obscure their illegal origin. Kuraye considers risk factors including large cash transactions or cash-intensive business models, rapid movement of funds through multiple accounts or jurisdictions, structuring transactions to avoid reporting thresholds, unusual transaction patterns inconsistent with customer profile, use of complex corporate structures or trusts without commercial rationale, reluctance to provide identity or business information, and transactions involving high-risk jurisdictions. Controls include customer due diligence and identity verification, transaction monitoring and anomaly detection, sanctions screening, beneficial ownership identification, source of wealth and funds verification, and suspicious activity reporting.
Terrorist financing involves providing or collecting funds with the intention that they may be used to support terrorist acts, organisations, or individuals. Risk factors include donations or payments to high-risk charities or NGOs, transactions to or from conflict zones or sanctioned jurisdictions, unexplained large-value transfers to jurisdictions with known terrorist financing risks, suspicious patterns of small-value transactions aggregating to significant amounts, and links to known terrorist financing networks or facilitators. Controls include sanctions screening against terrorist lists, transaction monitoring for suspicious patterns, enhanced due diligence for high-risk jurisdictions, suspicious activity reporting to law enforcement, and awareness training for employees.
4. Proliferation Financing & Bribery
Proliferation financing involves providing funds or financial services that could contribute to the development or acquisition of weapons of mass destruction. Risk factors include transactions involving dual-use goods or technologies, business relationships with entities in proliferation-sensitive jurisdictions, complex supply chains or end-use declarations, unusual shipping or logistics arrangements, and high-risk industry sectors. Controls include customer and transaction risk assessment, sanctions screening including proliferation-specific lists, enhanced due diligence for sensitive industries, and monitoring of high-risk product and service categories.
Bribery involves offering, giving, receiving, or soliciting something of value to influence an official or decision-maker. Corruption is the abuse of entrusted power for private gain. Risk factors include requests for facilitation payments, unusual payments to government officials or agents, lack of transparency in contracting or procurement, use of agents or intermediaries with unclear remuneration, repeated winning of contracts through opaque processes, unusually high commissions or success fees, and political exposure or connections. Controls include KYC and KYB due diligence, PEP screening and enhanced due diligence, transaction monitoring for unusual payment patterns, third-party due diligence and contract terms, gifts, hospitality, and entertainment policies, and whistleblowing and escalation channels.
5. Fraud, Cybercrime & Account Takeover
Fraud involves deliberate deception to secure unfair or unlawful gain. Fraud risk areas include payment fraud, identity fraud, document fraud, transaction fraud, marketplace fraud, account takeover and credential theft, and social engineering and phishing. Controls include identity verification and authentication, transaction monitoring and anomaly detection, device and IP address monitoring, two-factor authentication, customer and employee awareness training, and incident response and investigation procedures.
Cybercrime involves criminal activity targeting computers, networks, or digital assets. Risk areas include account takeover and credential theft, payment redirection and man-in-the-middle attacks, ransomware and data extortion, distributed denial-of-service attacks, phishing and social engineering, and insider threats and privilege misuse. Controls include strong authentication and access controls, network security and monitoring, encryption of sensitive data, security awareness training, incident response planning, regular security assessments and penetration testing, and secure development practices.
Account takeover occurs when an unauthorised party gains access to a customer or employee account. Indicators include login from unfamiliar device or location, changed contact details or password, unusual transaction requests, multiple failed authentication attempts, customer complaints of unauthorised activity, and alerts from fraud detection systems. Controls include multi-factor authentication, session monitoring and anomaly detection, customer notification of account changes, account recovery procedures, temporary holds on suspicious transactions, and law enforcement referral where required.
6. Identity Theft, Invoice Fraud & Marketplace Abuse
Identity theft involves the unauthorised use of another person's identity to commit fraud or other crimes. Types include stolen identity documents, synthetic identities, credential stuffing and password reuse attacks, social security number or tax ID theft, and business identity theft. Controls include identity verification at onboarding, document authenticity checks, liveness and biometric verification, watchlist screening, re-verification triggers for suspicious activity, and customer identity protection advice.
Invoice fraud involves manipulating or falsifying invoices to deceive a payer into making payments to fraudulent accounts. Types include fake invoices for goods or services not provided, intercepted and amended legitimate invoices, duplicate invoicing, overcharging or undisclosed price changes, and payment redirection to fraudulent accounts. Controls include vendor and payee verification, invoice approval workflows with dual control, bank account verification for new payees, change of account details verification, payment confirmation with known contacts, and employee awareness training.
Marketplace abuse includes fraudulent or manipulative activity within the marketplace environment. Types include fake seller accounts or listings, non-delivery after payment, sale of counterfeit or infringing goods, review or rating manipulation, account farming or review manipulation, collusion between buyers and sellers, and phishing or scam within marketplace messaging. Controls include marketplace seller verification and due diligence, product and service listing reviews, transaction and delivery monitoring, customer feedback and dispute resolution, account behaviour monitoring, and law enforcement cooperation.
7. Shell Companies & Synthetic Identities
A shell company is a corporate entity with no significant assets, operations, or employees, often used to obscure beneficial ownership or facilitate financial crime. Red flags include no physical presence or employees, registered address shared with many other entities, nominee directors with no decision-making authority, lack of verifiable business activity, complex ownership chains without commercial rationale, rapid formation for specific high-value transactions, and use of registered agent services to obscure ownership. Controls include business verification and operational assessment, beneficial ownership identification and verification, source of wealth and funds verification, enhanced due diligence for opaque structures, senior management approval for high-risk structures, and ongoing monitoring and periodic review.
A synthetic identity is a combination of real (stolen) and fake information used to create a fraudulent identity. Indicators include inconsistent information across documents, mix of real and fabricated personal details, no credit history or thin file despite apparent age, documents from different jurisdictions with mismatched details, reluctance to provide certain identity elements, and use of temporary or disposable contact details. Controls include identity verification across multiple data sources, document authenticity and consistency checks, liveness and biometric verification, behavioural monitoring during onboarding, transaction monitoring for suspicious patterns, and law enforcement referral where fraud is confirmed.
8. Contact & Compliance Inquiries
For inquiries regarding financial crime prevention, fraud reporting, or compliance matters, please contact our compliance desk at info@aakuraye.tech.