AML/CFT Policy
Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) Policy
1. INTRODUCTION
Whitebit Kripto Varlık Alım Satım Platformu Anonim Şirketi (hereinafter referred to as WhiteBIT TR or the Company) has been included among the entities subject to MASAK obligations due to its activities as a crypto asset service provider, in accordance with the "Crypto Asset Service Providers Guide" published by the Financial Crimes Investigation Board on May 4, 2021. Within this scope, the Company is obligated to MASAK regarding "customer identification, reporting suspicious transactions, providing information and documents, continuous reporting, and retention and presentation" in relation to all crypto asset purchase and sale transactions carried out through the Company.
2. PURPOSE
This policy contains rules aimed at preventing money laundering in relation to the provision of crypto asset services by the Company. The provisions of the policy are in addition to the Company's rules and also cover matters required under Turkish legislation.
This document aims to ensure that the Company's policies and practices, as well as its control, monitoring, risk management, and training activities, comply with regulations issued by the law and institutions authorized by the law regarding the laundering of criminal proceeds and the financing of terrorism.
- Ensuring that the Company's policies and practices, as well as its control, monitoring, risk management, and training activities, comply with the regulations issued by the law and the institutions authorized by the law,
- To establish the necessary compliance risk and legal risk management systems, including internal implementation, monitoring, communication, reporting, and relevant information system infrastructure, to protect the Company against risks related to money laundering and terrorist financing and to prevent the Company from being used for such purposes. To report suspicious transactions identified to MASAK in accordance with the Law on the Prevention of Money Laundering.
- Compliance with the principles of Customer Acceptance and Customer Identification set out in this policy,
- Identifying risky transactions and services that may be subject to laundering, and assessing customers, transactions, and services based on a risk-based approach to mitigate risks,
- Ensuring that company employees are aware of their legal obligations,
- Protecting the company's reputation and customer quality in the course of its activities,
- Ensuring the company's compliance with legal regulations on Combating Money Laundering and Terrorist Financing,
- Establishing principles for identifying and investigating risks that may be related to criminal proceeds and terrorist financing, and ensuring the necessary flow of information.
3. SCOPE
This Policy covers all units and employees of the Company.
4. APPLICABLE LEGISLATION
This policy has been prepared based on current Turkish and international AML/CFT legislation on the prevention of money laundering and terrorist financing.
5. DEFINITIONS
- Ministry: Ministry of Treasury and Finance
- Presidency: Presidency of the Financial Crimes Investigation Board of the Ministry of Treasury and Finance
- FATF: Financial Action Task Force An organization established within the OECD in 1989 by the G-7 countries to take measures aimed at developing national legal systems, harmonizing legislation, strengthening the role of the financial system, and ensuring continuous cooperation among member countries in the prevention of money laundering and terrorist financing. Turkey became a member in 1991. The recommendations published by the organization are binding on member countries.
- Compliance Officer: The person who is the Company's Legal Representative for the prevention of money laundering and terrorist financing. The Compliance Officer is a person authorized by the Company and responsible for developing and implementing the effective application of AML/CFT. The Compliance Officer is responsible for reporting any violations of AML/CFT procedures and is responsible for collecting and filing Suspicious Transaction Reports (STRs). The Compliance Officer has the authority to interact with legal authorities involved in the prevention of money laundering, terrorist financing, and other illegal activities.
- Law: Law No. 5549 on the Prevention of Money Laundering of Criminal Proceeds dated October 11, 2006.
- Money Laundering: The conversion or transfer of property derived from criminal activity or property used in place of such property, knowing that such property is derived from criminal activity or obtained as a result of participation in such activity, with the intent to conceal the illegal origin of the property or to hide it from the public, or to assist any person involved in such activity to evade the legal consequences of that activity;
Acquiring, holding, or using property known to be derived from criminal activity or obtained as a result of participation in such activity, where at the time of acquisition it was known that the property was derived from criminal activity;
The use of property known to be derived from criminal activity or obtained as a result of participation in such activity for the purpose of concealing or disguising its true nature, source, location, disposition, movement, rights, or ownership from the public.
In addition, money laundering also includes participation in, collaboration with, attempting to process, and assisting, encouraging, facilitating, and suggesting the processing of any of the activities mentioned above. - Assets: Money, movable or immovable property, tangible or intangible assets, and rights that can be represented by money, as well as any legal documents or instruments evidencing rights over such assets.
- MASAK: Financial Crimes Investigation Board
- Know Your Customer Principle: One of the measures to be taken by financial and non-financial institutions and business and professional practitioners to prevent money laundering and terrorist financing; the principle of ensuring that complete and accurate information is obtained about customers and that all necessary measures are implemented.
- Unusual Activity: Transactions or activities that are inconsistent with the customer's or legal owner's contract, commercial or professional position, or economic situation, or that do not serve any reasonable purpose when considering financial, professional, or personal characteristics,
- Risk: The possibility of financial or reputational damage to which the company or its employees may be exposed due to the use of the services provided for the purpose of laundering criminal proceeds or financing terrorism, or due to non-compliance with legal obligations,
- High-Risk Countries: Countries that lack adequate regulations to prevent money laundering and terrorist financing, do not cooperate in combating these crimes, or are deemed high-risk by competent international organizations,
- Proceeds of Crime: Any property value derived from any crime,
- Laundering of Criminal Proceeds: Any process aimed at making gains obtained from acts considered criminal by law appear to have been obtained through legal means, specifically by introducing such gains into the financial system, converting them from cash, and changing their identity through a process within the financial system to make them appear legitimate,
- Company: Whitebit Kripto Varlık Alım Satım Platformu Anonim Şirketi
- Suspicious Transaction: Any information, suspicion, or circumstance giving rise to suspicion that the money involved in a transaction conducted or attempted to be conducted at or through the Company or a member business was obtained through illegal means or used for illegal purposes, or that it was used for terrorist acts or by terrorist organizations, terrorists, or those financing terrorism, or that it is related or connected to such acts,
- Communique: The General Communique of the Financial Crimes Investigation Board,
- Financing of Terrorism: Obtaining or collecting money or any goods, rights, receivables, income, and benefits that can be represented by money, in whole or in part, knowing or intending that they will be used in the commission of terrorist crimes, as well as the benefits and value resulting from the conversion of these into each other,
- Regulation: The Regulation on Measures for the Prevention of Money Laundering and Terrorist Financing, published in the Official Gazette dated 09.01.2008 and numbered 26751.
6. APPLICATION PRINCIPLES
It is essential that all of the Company's activities comply with all legal regulations and relevant legislation to the maximum extent possible.
7. GENERAL RULES
All Company employees are required to take all necessary measures to obtain and keep up-to-date the necessary information and documents regarding customers and transactions in accordance with the law, and to store such information and documents in any medium for 10 years as specified in Law No. 5549, in order to communicate them to the Compliance Officer and law enforcement and investigation units upon request.
The Company's obligations under the "Guide for Crypto Asset Service Providers" published by MASAK on May 4, 2021, and other regulations are outlined under the following main headings.
- Customer Identification-Identity Verification
- Reporting of Suspicious Transactions,
- Providing information and documentation,
- Continuous reporting,
- Retention and presentation
Detailed procedures have been prepared regarding the matters covered in this policy, and these procedures are applied to each specific subject.
7.1. Principles Regarding Customer Identification
7.1.1. Customer Acceptance Policy
The Company has adopted the following principles regarding customer acceptance within the scope of preventing money laundering and terrorist financing.
a. Identity verification is completed before establishing a business relationship or conducting a transaction.
b. It is essential that the necessary identifying information for the identification, verification, and address confirmation of customers is obtained in full prior to any transactions. In cases where identity cannot be verified or sufficient information about the purpose of the business relationship cannot be obtained, the business relationship will not be established and the requested transaction will not be carried out.
c. In establishing a continuous business relationship, information is obtained about the purpose and nature of the business relationship.
d. No business relationship shall be established with individuals or organizations on the company's blacklist.
e. Customer accounts are opened in the customer's real name or title. Accounts cannot be opened using another name, an anonymous name, or a pseudonym.
f. Individuals who are reluctant to provide information or who provide misleading or unverifiable information cannot be accepted as customers. Transparency must be ensured in customer transactions and information.
g. In order to open an account for individuals who request to become customers via mail, email, internet, telephone, mobile application, etc., without face-to-face contact, it is essential to first obtain the necessary information and identification documents by meeting with the customer or the customer's legal representative face-to-face or through channels that allow remote identification.
h. In particular, care should be taken to verify all information obtained about customers who are willing to pay high fees and commissions without requiring any effort, to the extent possible, from another source, and it should be ensured that the person has chosen the company for reasonable reasons.
i. Unless the customer is clearly authorized by law and the purpose and necessity of opening an account are explained, requests from third parties to open accounts on behalf of one or more persons by proxy shall not be fulfilled.
j. Powers of attorney must be notarized.
7.1.2. Customer Identification
Regarding crypto asset transactions,
- Regardless of the amount, in the establishment of an ongoing business relationship,
- When the transaction amount or the total amount of multiple interconnected transactions exceeds the limit set by MASAK,
- In cases requiring a suspicious transaction report, regardless of the amount,
- When there is doubt about the adequacy and accuracy of previously obtained customer identification information, regardless of the amount, it is mandatory to identify customers and those acting on behalf of or on the account of customers by obtaining identity-related information and verifying the accuracy of this information.
In crypto asset transactions, the customers to whom identity verification will be applied, based on their nature and amount, are as follows:
- Natural Persons
- Legal entities registered in the commercial register
- Those acting on behalf of others and the identification of the beneficial owner
The identity verification obligation is required for all obligated parties, but there are differences between natural and legal persons in terms of the documents used for identity verification. Similarly, there are differences in the measures to be taken for identity verification depending on the type of legal person.
7.1.3. Electronic Account Membership Exclusively in Electronic Environment
When transactions are conducted exclusively through an electronic account membership in an electronic environment without face-to-face contact with the customer:
- For natural person customers, in the application received electronically,
- information related to identity (name, surname, date of birth, nationality,
- Turkish ID number for Turkish citizens,
- foreign ID number for foreign nationals)
- must be verified by querying the identity sharing system database of the General Directorate of Population and Citizenship Affairs of the Ministry of Interior,
- In the application received electronically from a legal entity customer registered in the commercial registry, the identity information of the person authorized to represent the legal entity must be verified according to the procedure for natural persons, and the information related to the legal entity (legal entity's title, commercial > registry number, tax identification number, field of activity, physical address) Verification by querying registration documents and records through the databases of the Union of Chambers and Commodity Exchanges of Turkey, the Revenue Administration, or other institutions that maintain central records of this information,
- All collections and payments must be made through a bank account that matches the identity information of the person whose membership has been accepted after their identity information has been verified. Under this condition, the customer's identity information must be verified in accordance with the procedures set out in Articles 6 and 7 of the Regulation.
7.1.4. Persons and Institutions Not Accepted as Customers
In cases where officials are unable to verify identity or obtain sufficient information about the purpose of the business relationship, they shall not establish a business relationship and shall not perform the requested transaction. In this context, they cannot open accounts under anonymous or fictitious names or define products. If there is doubt about the adequacy and accuracy of previously obtained identity information/whether the account holder/partners/representatives are the beneficial owners, and/or if sufficient information about the economic purpose of the requested transactions cannot be obtained, the business relationship must be terminated.
In this context;
- Individuals and institutions that refuse to provide the necessary documents and information cannot be accepted as customers.
- Accounts cannot be opened for individuals who request to deposit funds into accounts that are not appropriate for their financial profile and activities, engage in cryptocurrency trading, or give rise to the belief that they are concealing the beneficial owner, and products for cryptocurrency trading cannot be defined for them.
- If the ultimate beneficiary, representative, agents, type, and purpose of the relationship cannot be determined, they cannot be accepted as a customer.
- If information regarding the legal source of the financial assets of the customer or the person or institution with whom a business relationship is to be established cannot be provided, or if there is any suspicion in this regard, the customer relationship cannot be established.
- Individuals and institutions whose address information is only "PO BOX" cannot be accepted as customers. The address information must be clear.
- Foreign/overseas registered bearer share institutions cannot be accepted as customers.
- Opening accounts for fictitious transactions, defining crypto asset trading products, and accepting customer transactions are not permitted.
- Requests to open accounts and/or perform crypto asset trading transactions from individuals and institutions on national and international sanction lists under national and international sanctions are not accepted.
- Individuals and institutions subject to asset freezing decisions shall not be dealt with.
- Financial institutions and insurance companies based in countries that are not members of the FATF and offering investment-purpose insurance products are not accepted as customers.
- Asset management companies affiliated with the governments and heads of state of countries not subject to FATF and EU regulations, and institutions and companies acting on their behalf, cannot be accepted as customers.
- Heavily sanctioned resident/registered persons and institutions are not accepted as customers, and no intermediary services are provided for transactions and trade related to this region.
- Requests to open accounts on behalf of others through a power of attorney will be rejected if there is any suspicion or information that the power of attorney relationship stems from a relationship that cannot be explained within the legal framework.
- Signboard banks (entities registered in offshore regions that are known only by their name and give the impression of providing banking services, but do not have a physical address or the tangible equipment and conditions necessary for normal banking operations) cannot be accepted as customers.
- Pursuant to Law No. 7258 on the Regulation of Betting and Games of Chance in Football and Other Sports Competitions, accounts shall not be opened for individuals and institutions that offer joint betting on sports competitions via websites, terminals, or similar machines without the permission of the Sports Toto Organization Presidency, and crypto asset products shall not be defined. Crypto asset transfers made to these individuals cannot be facilitated.
- Foreign exchange offices may not acquire new customers.
- Foundations/associations cannot be acquired; exceptional cases are evaluated by the Compliance Officer.
- Providing a place and means for gambling is considered a crime under the Turkish Penal Code. In this context, accounts cannot be opened for individuals and institutions that provide a place and means for gambling, and products related to the purchase and sale of crypto assets cannot be defined. In such cases, the Compliance Manager, who is the legal representative of the company, must be informed about the rejected customer and whether the transactions require a suspicious transaction report.
7.2. Countries Requiring Special Attention Due to Risk
High-risk countries are those announced by the Ministry that lack adequate regulations to prevent money laundering and terrorist financing, do not cooperate sufficiently in combating these crimes, or are considered high-risk by authorized international organizations. Country risk is involved in business relationships and transactions with the citizens, companies, and financial institutions of the countries listed in the definition.
The following regions are considered high-risk under all circumstances.
- European Union (EU), countries subject to sanctions or embargoes by the UN.
- Countries that have not implemented the necessary legal regulations to combat crime proceeds.
- Countries listed in the Non-Cooperative Countries List announced by the Financial Action Task Force (FATF) to its member countries. (Available at http://www.fatf-gafi.org) (Natural persons who are citizens of or reside in countries on the blacklist, such as North Korea, Myanmar, and Iran, or legal entities established in such countries, cannot be Users on the platform.
- Countries identified by reliable sources as providing resources for terrorism.
- Offshore and free zones, tax havens, or countries known worldwide as tax havens (Anguilla, Andorra, Antigua, Aruba, Bahamas, Bahrain, Barbados, Belize, British Virgin Islands, Cook Islands, Dominica, Gibraltar, Grenada, Guernsey/Sark/Alderney, Isle of Man, Jersey, Liberia, Liechtenstein, Maldives, Marshall Islands, Monaco, Montserrat, Nauru, Netherlands Antilles, Niue, Panama, St. Kitts and Nevis, St. Lucia, St. Vincent, Seychelles, Tonga, Turks and Caicos Islands, U.S. Virgin Islands, Vanuatu, and Western Samoa).
Individuals who are citizens of or reside in the United States, Canada, or the United Kingdom, or legal entities established in those countries, cannot be Users on the platform.
7.3. Risk Management Policy
The Company must pay special attention to the risk of new and emerging technologies being used for money laundering and terrorist financing purposes and take appropriate measures to prevent this. The Company must pay special attention to transactions such as depositing money into an account, withdrawing money from an account, and transferring crypto assets carried out using systems that enable non-face-to-face transactions, closely monitor transactions that are not appropriate for the customer's financial profile and activities or are unrelated to their activities, and take appropriate and effective measures, including setting limits on amounts and transaction numbers.
The risk management policy covers, at a minimum, the internal measures and operating rules related to the measures set out in the section titled "Principles Regarding Customer Identification" of the Measures Regulation. Activities related to risk management cover, at a minimum, the following:
- Developing risk identification, rating, classification, and assessment methods based on customer risk, service risk, and country risk,
- The rating and classification of services, transactions, and customers according to risks,
- Ensuring the monitoring and control of risky customers, transactions, or services, reporting them in a manner that alerts the relevant units, performing the transaction with the approval of higher authorities, and developing appropriate operational and control rules for auditing when necessary,
- Reviewing the consistency and effectiveness of risk identification and assessment methods, risk rating and classification methods retrospectively through case studies or completed transactions, reassessing and updating them based on the results obtained and changing conditions,
- Compliance with national legislation and recommendations, principles, standards, and guidelines issued by international organizations on matters covered by risk, and carrying out the necessary development work.
Additional measures for high-risk groups: Obligors must take at least the following additional measures to reduce the risk assumed for groups identified as high-risk as a result of risk rating:
- Obtaining additional information about the customer and updating the identity information of the customer and the beneficial owner more frequently,
- Obtaining additional information about the nature of the business relationship,
- Obtain information about the source of the assets subject to the transaction and the customer's funds to the extent possible,
- Obtain information about the purpose of the transaction,
- Making the establishment of the business relationship, the continuation of the existing business relationship, or the execution of the transaction subject to the approval of a senior officer,
- To keep the business relationship under close supervision by increasing the number and frequency of controls applied and determining the types of transactions that require additional control, such as obtaining additional information and documents within the scope of customer identification, and taking additional measures regarding the confirmation and verification of the information provided.
7.4. Monitoring and Control Obligation
The company carries out monitoring and control activities by considering the nature of the transactions performed by customers.
The purpose of monitoring and control is to continuously monitor and control whether the company is protected from risks and whether its activities are carried out in accordance with the Law and the regulations and communiqués issued pursuant to the Law, as well as the institution's policies and procedures.
Within this scope, the monitoring and control activities that must be carried out within the Company in accordance with the aforementioned legislation are as follows:
a) Monitoring and control of high-risk customers and transactions,
b) Monitoring and control of transactions conducted with high-risk countries,
c) Monitoring and control of complex and unusual transactions,
d) Control of transactions above an amount determined by the company's risk policy to ensure they are consistent with the customer profile, using a sampling method,
e) Monitoring and controlling, using sampling methods, linked transactions that, when taken together, exceed the amount requiring identification,
f) Monitoring information and documents about customers that must be stored electronically or in writing through sampling, completing any deficiencies, and updating them,
g) Continuous monitoring throughout the business relationship to ensure that the transaction conducted by the customer is consistent with information about the customer, their business, risk profile, and funding sources,
h) Control of transactions conducted using systems that enable non-face-to-face transactions,
i) Risk-based control activities covering services that may become susceptible to abuse due to newly offered products and technological developments.
The functions to be performed within the scope of monitoring and control activities are as follows:
- Monitoring and control of high-risk customers and transactions
- Monitoring and control of transactions conducted with high-risk countries,
- Monitoring and control of complex and unusual transactions,
- Checking whether transactions above a specified amount are consistent with the customer profile using a sampling method.
- Monitoring and control of transactions requiring identity verification,
- Control of transactions conducted using systems that enable non-face-to-face transactions,
- Risk-based control of services that may become vulnerable to abuse due to new products and technological developments,
- Control of information and documents that must be stored electronically or in writing in the system and archives,
- Control of the compliance of activities and transactions with the approval and authorization mechanism established within the company and the defined job description.
- Control of the frequency with which all company employees report suspicious transactions to the Compliance Officer.
- Checking accounts that have been inactive for a long time but have a large transaction amount at once.
In this context, the scope and details of risk management, control, and monitoring activities are updated to ensure compliance with developments in customer profiles, products, services, legislation, and the sector.
7.5. Training Policy
Within the scope of legislation on combating money laundering and terrorist financing, training programs are organized annually under the supervision and coordination of the Compliance Officer. In addition, any changes in the legal framework are communicated company-wide by the Compliance Officer.
The purpose of the training policy is to ensure compliance with the obligations imposed by the Law on the Prevention of Money Laundering and the regulations and circulars issued pursuant to said Law, and to prevent money laundering within To ensure compliance with the obligations imposed by the Law on the Prevention of Money Laundering and the regulations and circulars issued pursuant to said Law, and to ensure compliance with the Company's policy on money laundering by raising employee awareness of company policies and procedures and risk-based approaches, thereby creating a corporate culture and updating employee knowledge.
Training activities are organized at least once a year. Interim training sessions may also be planned if deemed necessary.
Training topics include, at a minimum:
- (a) The concepts of money laundering and terrorist financing,
- (b) Stages and methods of money laundering and case studies on this subject,
- (c) Legislation related to the prevention of money laundering and terrorist financing,
- (d) Risk areas,
- (e) Company policies and procedures,
- (f) Within the framework of the law and relevant legislation;
- Principles regarding customer identification,
- Principles regarding the reporting of suspicious transactions,
- Obligation to provide information and documentation,
- Obligation to retain and present information,
- Penalties applicable in case of non-compliance with obligations,
- International regulations on combating money laundering and terrorist financing.
7.6. Principles Regarding the Suspicious Transaction Reporting Process
A suspicious transaction is a transaction conducted or attempted through a company or account user where there is any information, suspicion, or circumstance that may give rise to suspicion that the assets involved in the transaction were obtained through illegal means or are being used for illegal purposes.
Control mechanisms are established to enable the systematic filtering and tracking of transactions that match the scenarios specified under the heading "Detection of Suspicious Transactions."
Transactions that match predefined scenarios are filtered and reviewed for transactions carried out within the scope of the services provided by the Company as a crypto asset service provider.
MASAK is authorized to determine suspicious transaction types. In all cases, the final decision on whether to report a suspicious transaction to the Financial Crimes Investigation Board (MASAK) rests with the Compliance Officer. The MASAK General Communiqué No. 13 provides general suspicious transaction types. When the Company encounters any suspicious transaction, the Compliance Officer shall conduct an investigation and review, and a decision on whether to report the suspicious transaction to MASAK shall be made as soon as possible. If it is decided that the suspicious transaction should be reported, the report shall be submitted to MASAK in accordance with the necessary procedures.
8. RETENTION OF RECORDS
In accordance with the provisions of Law No. 5549 on the Prevention of Money Laundering and the Regulations and Communiqués published regarding its implementation; The Company shall ensure that all documents related to the obligations and transactions imposed by the aforementioned Law are retained for 10 (ten) years from the date of preparation, books and records from the date of the last entry, and documents related to identity verification from the date of the last transaction, and shall present them to the authorities upon request. Suspicious transaction reports and their attachments are subject to the retention and presentation obligation.
9. TRAINING AND AWARENESS
The company is responsible for ensuring that all employees have sufficient knowledge about KYC/KYB practices, MASAK obligations, and compliance processes. In this regard, comprehensive training is provided to all personnel at least once a year. In addition, new employees undergo orientation on the relevant procedures before starting their duties.
The company implements an annual training program on the prevention of money laundering and terrorist financing. The program includes MASAK compliance training, CMB legislation training, and suspicious transaction monitoring and reporting training. Training content is updated each term in line with legislative changes and suspicious transaction updates.
Task-specific training is provided to employees in the customer acceptance unit, risk assessment team, transfer control unit, compliance officers, and internal audit unit. The effectiveness of the training is measured through tests. Training records, participant lists, and evaluation results are kept regularly.
10. REVIEW AND UPDATE
This policy is reviewed at least once a year and updated as necessary. In the event of updates due to changes in legislation, sectoral developments, or new requirements arising in company operations, the revised version is submitted to the board of directors for approval and implementation. Update proposals are evaluated by the Compliance Unit and submitted to senior management for approval after obtaining the opinion of the Legal Unit. Version control is performed for approved updates and change logs are kept. Current policies and procedures are communicated to relevant personnel and archived in the central system.