cripto.md cripto.md AML/KYC policy
Legal

AML/KYC policy

How we prevent money laundering, terrorist financing and sanctions breaches. In short: we know who our customers are, we understand where the money comes from for large amounts, and we screen every crypto address we deal with.

Version
1.0
Last updated
26 September 2026

1. Legal framework

As a virtual asset service provider, cripto.md is a reporting entity within the meaning of Law No. 308/2017 on preventing and combating money laundering and terrorist financing. We also apply:

  • the law on the crypto-asset market and the regulations of the National Commission for Financial Markets (CNPF), once in force;
  • the international sanctions regime applicable in the Republic of Moldova, including UN Security Council sanctions and the restrictive measures of the European Union;
  • the recommendations of the Financial Action Task Force (FATF) on virtual assets, including the travel rule;
  • the guidance of the Service for Prevention and Combating of Money Laundering (SPCSB).

2. Who is responsible

Management approves this policy and reviews it at least once a year. Its application is coordinated by a designated compliance officer, to fill in: name, independent of the commercial team, with direct access to management and to all the information needed. Questions about this policy can be sent to support@cripto.md with the subject "AML compliance".

3. A risk-based approach

We do not treat every customer the same way, but according to risk. We assess each customer and each operation by:

  • the customer: country of residence, occupation, politically exposed person status, history;
  • the product: type of crypto-asset, network, amounts and frequency;
  • the channel: payment method, cash or transfer, own wallet or platform;
  • geography: high-risk or sanctioned jurisdictions.

The risk decides what we check, how often we refresh your data and which limits apply.

4. Know your customer (KYC)

LevelMonthly limitWhat we ask for
Without verificationup to 10,000 MDLa confirmed email address, phone number, receiving address; payment only from accounts or cards in your name
Verified accountup to 500,000 MDLa valid identity document (ID card or passport), a verification photo with liveness detection, IDNP, home address, occupation
Enhanced verificationabove 500,000 MDL or high riskproof of address, evidence of the source of funds and wealth (for example an employment contract, a bank statement, a sale contract), an interview where needed

We may ask for verification at any level whenever we have doubts about identity or the origin of funds, and whenever the law requires it, whatever the amount. Linked operations are added together: splitting an amount into several orders to stay under a limit is treated as a risk signal.

For legal entities we ask for the registration documents, the ownership structure, the identity of the beneficial owners and of the people acting on behalf of the company.

5. Politically exposed persons and beneficial owners

We check whether you are a politically exposed person, a family member or a close associate of one. If so, we apply enhanced measures: approval of the relationship by management, establishing the source of wealth and funds, and closer ongoing monitoring.

We ask you to declare that you act on your own behalf. If you act for someone else, you must tell us and give us that person's details.

6. International sanctions

We screen customers, beneficial owners and counterparties against national, UN and European Union sanctions lists when the account is opened and continuously after that. We do not serve sanctioned persons and do not carry out operations that would benefit them. Assets of sanctioned persons are frozen and reported as the law requires.

7. Transaction monitoring and blockchain analysis

We follow operations throughout the relationship, to see whether they fit the customer's profile. Every crypto address we receive from or send to is screened with specialised blockchain analytics tools, which show links to:

  • illegal darknet markets, known frauds and scams, ransomware;
  • sanctioned addresses;
  • mixing services and other tools that hide where funds come from;
  • unlicensed platforms or platforms without customer checks.

Crypto-assets with high exposure to such sources may be refused, and the operation may be suspended for review.

8. The travel rule and own wallets

For crypto transfers, we collect and pass on the originator and beneficiary information the law requires when the transfer goes to or comes from another virtual asset service provider. When we send to your own wallet, we may ask you to prove you control it, for example by signing a message or sending a small test amount.

9. What we do not accept

  • anonymous accounts or accounts in fictitious names, accounts opened for other people;
  • third-party payments, meaning from accounts, cards or wallets that are not yours;
  • customers from jurisdictions under comprehensive sanctions or identified by the FATF as high-risk and non-cooperative;
  • funds from unlawful activities, unlicensed gambling, darknet markets or fraud;
  • privacy coins that do not allow transactions to be traced.

10. Reporting to the authorities

We report suspicious operations and the other operations the law specifies to the Service for Prevention and Combating of Money Laundering, within the legal time limits. We may suspend a suspicious operation as the law provides.

The law forbids us from telling you that an operation has been reported or is under review. That is why we sometimes cannot tell you the exact reason an order is delayed or refused.

11. Record keeping

We keep identification data, documents, correspondence and records of operations for 5 years from the end of the relationship or from the date of an occasional operation, or longer if an authority requires it. How this data is protected is set out in the Privacy policy.

12. Training and control

Staff are trained when they join and at least once a year. The effectiveness of our procedures is checked periodically by an independent audit function, and findings are tracked until they are fixed.

13. What we ask of you, in practice

  • real, up-to-date details; tell us when your name, address or identity document changes;
  • payments only from your own accounts, cards and wallets;
  • answers to our requests for information within the time given;
  • receiving addresses that are yours or belong to a person you declare to us.

If we do not receive the information requested, we may suspend the account or refuse the operation, under the Terms and conditions.