AML Policy

ANTI-MONEY LAUNDERING (AML) & COMPLIANCE POLICY

Novellis.io

Document Type: Anti-Money Laundering and Compliance Policy
Version: 1.0
Effective Date: January 1, 2026
Responsible Department: Compliance
Review Cycle: At least annually or upon material regulatory changes

 

1. Purpose and Objectives

Novellis.io follows a consistent and risk-based approach to preventing money laundering, terrorist financing, fraud, and other misuse of its services.

This Anti-Money Laundering & Compliance Policy (the “AML Policy”) defines the fundamental standards, procedures, and control mechanisms used by Novellis.io to identify, assess, monitor, and mitigate relevant risks.

Our objectives include, in particular:

  • Protecting the integrity of our business relationships and payment flows;

  • Preventing the misuse of our services;

  • Appropriately identifying and verifying customers and business partners;

  • Detecting unusual or suspicious activities at an early stage;

  • Assessing risks based on a risk-based approach;

  • Complying with applicable legal and regulatory requirements;

  • Taking appropriate measures where reasonable grounds for suspicion exist.

This Policy forms part of our broader compliance and risk management framework.

 

2. Risk-Based Compliance Approach

Novellis.io applies a Risk-Based Approach (RBA).

Not every business relationship presents the same level of risk. Customers, transactions, and business activities may therefore be assessed based on various risk factors.

The risk assessment may take into consideration, in particular:

  • Customer identity and profile;

  • Customer country of residence or registered office;

  • Source of funds;

  • Payment instruments used;

  • Transaction volume and frequency;

  • Nature and purpose of the business relationship;

  • Unusual transaction patterns;

  • Country and geographical risks;

  • Sanctions and PEP risks;

  • Indicators of fraud or identity misuse;

  • Other factors that may indicate an increased level of risk.

The resulting risk classification may determine the type and extent of verification and supporting documentation required.

 

3. Customer Due Diligence (CDD)

Customer Due Diligence (CDD) is a central component of our AML program.

Before establishing or during a business relationship, Novellis.io may collect and verify the information necessary to clearly identify the customer and appropriately assess the risks associated with the business relationship.

CDD may include, in particular:

  1. Collection of personal or business information;

  2. Verification of identity;

  3. Verification of the stated residential or business address;

  4. Assessment of the customer’s financial background, where required;

  5. Assessment of expected transaction behavior;

  6. Screening against relevant sanctions and risk databases;

  7. Ongoing monitoring of the business relationship.

Additional verification measures may be required depending on the customer’s risk profile.

 

4. Know Your Customer (KYC)

As part of our Know Your Customer (KYC) procedures, Novellis.io may request appropriate evidence to verify the customer’s identity.

This may include:

Proof of Identity

  • Passport;

  • National identity card;

  • Driver’s license;

  • Or another comparable government-issued identification document.

The document must generally be valid, complete, and sufficiently legible.

Proof of Address

To verify the customer’s residential address, Novellis.io may request, for example:

  • Bank statements or other banking documents;

  • Utility bills;

  • Government-issued documents;

  • Tax documents;

  • Or other appropriate official proof of address.

Payment and Financial Information

Depending on the payment method and risk profile, additional information concerning the payment instrument used may be required.

Sensitive security information, such as CVV/CVC codes, must not be unnecessarily disclosed.

Novellis.io may adjust documentation requirements where necessary based on the customer’s profile, risk level, or applicable legal and regulatory requirements.

 

5. Enhanced Due Diligence (EDD)

For customers or business relationships presenting an increased level of risk, Novellis.io may conduct Enhanced Due Diligence (EDD).

Enhanced verification may be required, for example, where:

  • Unusually high transaction volumes are identified;

  • Transaction behavior significantly differs from the expected customer profile;

  • Increased geographical risks exist;

  • The source of funds cannot be adequately established;

  • A potential PEP relationship is identified;

  • Sanctions or other compliance alerts are identified;

  • There are indications of fraud, identity misuse, or other unlawful activities;

  • Other relevant risk factors are present.

As part of EDD, additional information and supporting documentation may be requested.

This may include evidence relating to Source of Funds (SoF) and, where appropriate, Source of Wealth (SoW).

 

6. Source of Funds & Source of Wealth

Where required by the applicable risk assessment, Novellis.io may request information regarding the origin of funds used in a transaction.

Source of Funds

Source of Funds” refers to the specific origin of the financial funds being used for a particular transaction.

Possible supporting documentation may include:

  • Bank statements;

  • Salary or income documentation;

  • Sale or purchase documentation;

  • Loan documentation;

  • Corporate or business records;

  • Tax documentation;

  • Or other appropriate supporting evidence.

Source of Wealth

Source of Wealth” generally refers to the origin and accumulation of a customer’s overall wealth.

Depending on the circumstances, information may be requested concerning:

  • Employment or professional income;

  • Business ownership or company interests;

  • Investments;

  • Real estate;

  • Inheritances;

  • Or other sources of wealth.

The nature and extent of the documentation required will depend on the customer’s individual risk profile.

 

7. PEP and Sanctions Screening

Novellis.io may screen customers against relevant sanctions lists and publicly available or lawfully accessible compliance databases.

Such screening may include checks relating to:

  • Politically Exposed Persons (PEPs);

  • Sanctions lists;

  • Terrorist financing risks;

  • Known fraud or financial crime risks;

  • Other relevant compliance risks.

A potential match does not automatically result in rejection of the business relationship. However, it may trigger additional review and, where appropriate, enhanced due diligence measures.

 

8. Transaction Monitoring

Novellis.io may conduct ongoing transaction monitoring to identify unusual or potentially abusive activities.

Monitoring may take into account, among other factors:

  • Transaction amounts and frequency;

  • Deposit and withdrawal behavior;

  • Changes in the customer’s previous activity;

  • Use of different payment instruments;

  • Unusual payment routes;

  • Transactions without an apparent economic purpose;

  • Unusual timing or structural transaction patterns;

  • Potential attempts to circumvent existing control measures.

Transactions may be analyzed using automated technical systems and, where appropriate, through manual compliance reviews.

 

9. Third-Party Payments

As a general principle, deposits must be attributable to a verified customer or an appropriately authorized payment instrument.

Payments originating from unverified or unauthorized third parties may be rejected or subject to additional review.

Novellis.io may request appropriate documentation to establish the customer’s authorization to use a particular payment instrument.

 

10. Payments and Withdrawals

To reduce money laundering and fraud risks, withdrawals may be restricted to the payment instrument originally used or to another appropriately verified payment method.

Different procedures may apply depending on the payment method.

In particular, refunds may generally be returned to the original source of payment where technically possible, legally permitted, and consistent with applicable payment terms.

Cash payments are not supported.

Novellis.io may restrict certain payment methods or payment instruments based on security, risk, or compliance considerations.

 

11. Unusual and Suspicious Activities

A transaction or activity may be subject to enhanced review where, due to its nature, amount, frequency, or other circumstances, it appears unusual.

Potential warning indicators may include:

  • Significant deviations from normal customer behavior;

  • Unusually rapid deposits and withdrawals;

  • Use of multiple unexplained payment sources;

  • Repeated transactions without an identifiable economic purpose;

  • Inconsistent customer information;

  • Use of payment instruments that cannot be clearly attributed to the customer;

  • Indicators of identity misuse;

  • Attempts to circumvent KYC or compliance controls;

  • Concerns regarding the source of funds.

A single indicator does not automatically constitute evidence of unlawful conduct. Assessments are made based on the overall circumstances and the customer’s risk profile.

 

12. Compliance Investigation

Where relevant concerns are identified, Novellis.io may conduct an internal compliance investigation.

Such an investigation may include:

  1. Review of customer information;

  2. Analysis of transaction history;

  3. Review of payment instruments used;

  4. Screening against available compliance data;

  5. Request for additional documentation;

  6. Assessment of the source of funds;

  7. Documented risk assessment;

  8. Determination of appropriate further measures.

During an investigation, certain account or payment functions may be temporarily restricted where necessary to conduct the review or prevent potential harm.

 

13. Measures in Cases of Increased or Unacceptable Risk

Depending on the outcome of a compliance review, Novellis.io may take appropriate measures.

Such measures may include:

  • Requesting additional documentation;

  • Enhanced monitoring;

  • Temporary restriction of certain account functions;

  • Rejection of a transaction;

  • Rejection of a payment;

  • Returning funds to a verified original payment source, where legally permissible;

  • Restriction of the business relationship;

  • Termination of the business relationship;

  • Reporting to competent authorities where legally required or permitted.

The specific measure will depend on the circumstances of the individual case.

 

14. Suspicious Activity Reporting

Where a reasonable suspicion of money laundering, terrorist financing, fraud, or other relevant unlawful activity arises during a review, Novellis.io may be required to provide relevant information to competent authorities or other legally designated bodies.

Where required by law, such reports will be handled confidentially.

Accordingly, Novellis.io may be legally prohibited from informing customers about certain internal reviews or about the submission or intended submission of a report.

 

15. Record Keeping and Documentation

Relevant KYC, transaction, and compliance information may be documented and retained in accordance with applicable legal and regulatory requirements.

Records may include, among other things:

  • Identification information;

  • Submitted documentation;

  • Results of KYC checks;

  • Risk assessments;

  • Transaction data;

  • Compliance reviews;

  • Communications relating to compliance measures;

  • Where applicable, documentation relevant to competent authorities.

Records will be retained in accordance with applicable data protection and record-retention requirements.

 

16. Data Protection and Confidentiality

Personal data will only be processed as part of KYC, AML, and compliance procedures where an appropriate legal basis exists and where processing is necessary for the relevant purposes.

Novellis.io implements appropriate organizational and technical measures to protect the information processed.

Further details concerning the processing of personal data are set out in the applicable Privacy Policy.

 

17. Responsibilities

The implementation of AML and compliance requirements is carried out within a defined area of responsibility.

Key responsibilities include:

  • Monitoring relevant compliance risks;

  • Conducting or coordinating KYC reviews;

  • Assessing unusual or potentially suspicious activities;

  • Documenting compliance decisions;

  • Reviewing and updating internal control procedures;

  • Where appropriate, cooperating with competent authorities and external service providers.

Employees or appointed persons responsible for KYC, payment, or compliance-related functions should receive appropriate training and information according to their respective roles.

 

18. Training and Awareness

Novellis.io promotes a corporate culture in which compliance and the responsible handling of financial activities are given high importance.

Employees with relevant responsibilities may receive regular training concerning areas such as:

  • Anti-Money Laundering;

  • KYC;

  • Fraud prevention;

  • Sanctions requirements;

  • Data protection;

  • Detection of suspicious activities.

Training content may be adapted according to the respective roles and responsibilities of employees.

 

19. Review and Updating of this Policy

This AML Policy will be reviewed regularly and updated where necessary.

A review may be required in particular due to:

  • Changes in applicable legal requirements;

  • Changes in regulatory standards;

  • New or evolving money laundering risks;

  • Changes to the business model;

  • Introduction of new products or payment methods;

  • Material changes to the overall risk profile.

The latest version of this Policy will be made available on the Novellis.io website.

 

20. Customer Cooperation

The effectiveness of our compliance measures depends on the cooperation of our customers.

Customers are required to provide complete, accurate, and up-to-date information when requested.

In particular, customers must not submit forged, manipulated, or misleading documents.

Failure to provide required information or the submission of inconsistent or inaccurate information may result in certain services being unavailable or transactions being declined or delayed.

 

21. Zero Tolerance for Financial Crime

Novellis.io maintains a strict position against the misuse of its services.

Any activity intended to conceal the origin of assets, obscure identities, circumvent financial controls, or move illicit funds through our services is prohibited.

We reserve the right to take appropriate measures where such risks are identified.

 

22. Contact

Questions regarding our AML, KYC, or compliance procedures may be directed to our Support or Compliance Team.

Email: support@novellis.net

Novellis.io
Anti-Money Laundering & Compliance Department