Compliance
KYC / AML Policy
Last updated: July 2026
1. Purpose and Scope
This Know Your Customer ("KYC") and Anti-Money Laundering ("AML") Policy explains how INTELLIGENCE AI LTD("we", "us", "our") identifies and verifies customers, assesses and manages financial crime risk, and prevents our services from being used to facilitate money laundering, terrorist financing, fraud, sanctions evasion, or other unlawful activity.
This policy applies to everyone who accesses our website, creates an account, requests information about our services, or enters into a business relationship with us. It is designed to be consistent with the UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended (the "MLRs"), the Proceeds of Crime Act 2002, the Terrorism Act 2000 (as amended), and related guidance issued by the UK Financial Conduct Authority and the National Crime Agency, where applicable.
For general information about how we process personal data as part of these activities, please see our Privacy Policy.
2. Our Approach to KYC and AML
Although INTELLIGENCE AI LTD primarily provides no-code business process automation software and related implementation services and is not a regulated financial institution, we voluntarily adopt risk-based KYC and AML controls to protect our business, our customers, and the integrity of the payment ecosystem through which we operate.
All payments are processed by Stripe, Inc. ("Stripe"), a PCI DSS Level 1 certified payment processor regulated in multiple jurisdictions. Stripe performs its own customer and transaction-level risk assessment, fraud prevention, identity verification, and sanctions screening in accordance with its own terms and compliance programmes. Our KYC/AML Policy complements, and does not replace, Stripe's obligations as a payment service provider.
3. Customer Due Diligence (CDD)
3.1 When we carry out due diligence
We carry out customer due diligence before, or at the point of, entering into a business relationship with a new customer, and on an ongoing basis as described in Section 5. We may also carry out additional checks before processing large transactions, onboarding high-risk customers, or where we have reason to suspect that a customer or transaction may be linked to financial crime.
3.2 Information we collect
The nature and extent of the information we collect depends on the Plan, service value, and assessed risk. Typical identification data includes:
- Full name, email address, telephone number, and billing address of the person placing the order
- Business or organisation name, registration number, registered address, and country of incorporation
- Name and contact details of beneficial owners, directors, or authorised signatories (for corporate customers)
- Nature of business, expected use of the Platform, and source of funds where relevant
- Payment method verification information, including billing details collected by Stripe
We do not collect or store full payment card numbers, CVC codes, or authentication credentials. Stripe handles that information directly under its own privacy and security standards.
3.3 Verification
We verify the information we collect against reliable and independent sources, which may include commercial registers, credit-reference databases, government identification databases, electoral rolls, or reputable business information services. We may also request supporting documents, such as a certificate of incorporation, articles of association, or government-issued photographic identification. Verification may be performed manually or through automated third-party verification tools.
3.4 Failure to provide information
If a prospective or existing customer does not provide the information or documentation we reasonably request, we may refuse to enter into the business relationship, suspend or terminate access to the Platform, or decline to process a transaction. We will inform you if this occurs unless prohibited by law.
4. Risk Assessment
4.1 Risk categories
We assess each customer relationship according to a risk-based approach. Factors we consider include, but are not limited to:
- The customer's country of residence, incorporation, or place of business
- The nature of the customer's business and whether it operates in a high-risk sector
- The expected value, volume, and frequency of transactions
- The complexity of the requested automation or integration
- Whether the customer is a politically exposed person ("PEP"), a family member of a PEP, or a known associate
- Whether the customer or transaction is connected to a sanctioned individual, entity, or jurisdiction
- Any adverse media, regulatory action, or law enforcement interest
4.2 Standard due diligence
Customers assessed as presenting standard risk are subject to the verification and monitoring procedures described in this policy.
4.3 Enhanced due diligence (EDD)
Customers assessed as presenting higher risk undergo enhanced due diligence. This may include requesting additional identification documents, understanding the source of funds or wealth, obtaining senior management approval before onboarding, more frequent transaction monitoring, or refusing the relationship if the risk cannot be adequately mitigated.
4.4 Low-risk simplifications
Where a customer relationship is assessed as low risk and permitted by law, we may apply simplified due diligence. This does not exempt us from ongoing monitoring or from escalating concerns if we become aware of suspicious activity.
5. Ongoing Monitoring
5.1 Transaction and activity monitoring
We monitor customer accounts and transactions for unusual or suspicious patterns. Examples of activity that may trigger review include:
- Payments that are inconsistent with the customer's stated business or expected use of the Platform
- Repeated failed, disputed, or chargeback transactions
- Use of payment methods from high-risk or sanctioned jurisdictions
- Attempts to obscure identity, ownership, or the source of funds
- Rapid changes in account behaviour or volume without a clear business reason
- Information that appears false, inconsistent, or fabricated
5.2 Periodic review
We periodically review customer records to ensure they remain up to date, accurate, and consistent with the assessed risk profile. Customers may be asked to refresh identification documents or confirm business details from time to time.
5.3 Alerts and escalation
Any unusual or suspicious activity is escalated internally for review. Where appropriate, we may temporarily suspend access, request additional information, block a transaction, terminate the relationship, or file a suspicious activity report with the relevant authorities.
6. Sanctions and PEP Screening
6.1 Sanctions screening
We screen customers, beneficial owners, directors, and payment details against applicable sanctions lists, including UK HM Treasury financial sanctions, United Nations sanctions, European Union sanctions where relevant, and other international sanctions regimes. We do not knowingly provide services to, or receive funds from, sanctioned persons, entities, or jurisdictions.
6.2 Politically exposed persons
We identify whether a customer, beneficial owner, or authorised signatory is a PEP or a close family member or known associate of a PEP. Enhanced due diligence and senior approval are required before entering into or continuing a relationship with a PEP.
6.3 Adverse media and adverse information
As part of our risk assessment, we may review publicly available information about the customer, beneficial owners, and associated parties. Credible adverse media relating to financial crime, corruption, fraud, or sanctions may lead to enhanced due diligence or refusal of the relationship.
7. Suspicious Activity Reporting
7.1 Internal reporting
Any member of our team who identifies suspicious activity must report it promptly to the appointed AML lead or compliance contact. Suspicious activity may include transactions that appear designed to avoid detection, inconsistent customer behaviour, or any other indicator of money laundering, terrorist financing, or fraud.
7.2 External reporting
Where we know or suspect that an activity involves money laundering, terrorist financing, or sanctions evasion, we will consider whether a disclosure is required to the National Crime Agency (NCA) or other relevant authority. We will not disclose to the customer or any third party that a suspicious activity report has been made ("tipping off") unless permitted by law.
8. Record Keeping
We keep records of customer due diligence, risk assessments, monitoring, decisions, and any suspicious activity reports for at least five (5) years after the end of a business relationship, or for such longer period as may be required by law, regulatory direction, or legal proceedings. These records are stored securely and access is restricted to authorised personnel.
9. Cooperation with Stripe
Because Stripe processes all payments on our behalf, we cooperate with Stripe's risk, compliance, and verification requests. This may include providing customer or transaction information to Stripe when required to resolve disputes, chargebacks, fraud alerts, sanctions hits, or regulatory inquiries. Stripe's own KYC, AML, and fraud prevention programmes apply to payment processing and may impose additional requirements on customers before a payment can be completed.
Customers should also review Stripe's terms of service, privacy policy, and connected account terms, which are available at stripe.com.
10. Prohibited Activities and Use of Services
Customers must not use, or attempt to use, the Platform or our services in connection with:
- Money laundering, terrorist financing, or proceeds of crime
- Sanctions evasion or dealings with sanctioned persons or jurisdictions
- Fraud, identity theft, impersonation, or unauthorised access to accounts
- Transactions involving illegal goods or services
- Concealing the origin, ownership, destination, or purpose of funds
- Any other activity that would violate applicable AML, counter-terrorist financing, or sanctions laws
If we reasonably believe that a customer has engaged, or is attempting to engage, in any prohibited activity, we may suspend or terminate the Account, decline or reverse transactions, report the activity to the relevant authorities, and take any other lawful action.
11. Data Protection and Confidentiality
We process personal data collected for KYC and AML purposes in accordance with UK GDPR and the Data Protection Act 2018. Information obtained during due diligence is kept confidential and is used only for the purposes of preventing financial crime, complying with legal obligations, managing risk, and defending legal rights. We may disclose KYC/AML information where required by law, court order, or regulatory request, or to Stripe for payment-related risk purposes.
12. Training and Awareness
All team members involved in customer onboarding, payment operations, account management, and compliance receive regular training on this policy, the relevant UK AML/CFT legislation, red-flag indicators, and how to escalate concerns. Training is reviewed and refreshed at least annually and whenever there are material changes to applicable law or our risk profile.
13. Governance and Review
This policy is owned and maintained by our compliance lead and approved by senior management. We review the policy at least annually, and sooner if there are significant changes in law, regulation, our business activities, or our risk exposure. Updates are posted on this page with a revised "Last updated" date.
14. Contact Us
If you have any questions about this KYC / AML Policy, need to provide updated identification information, or wish to report a concern, please contact us via the contact page on our website, or by email at info@intelligenceailtd.com.