Banner

AML/CTF AND SANCTIONS COMPLIANCE POLICY

Version: 2.0
Effective Date: 08.05.2026
Approved by: Board of Directors

1. INTRODUCTION

Plustar N.V. (“the Company”) is committed to conducting its business in a lawful, ethical, and responsible manner while maintaining effective safeguards against money laundering, terrorist financing, fraud, sanctions breaches, identity misuse, and other forms of financial crime.

As an operator in the online gaming sector, the Company acknowledges that remote gambling services may be vulnerable to misuse by individuals seeking to disguise the origin of criminal proceeds, move illicit funds, exploit payment systems, or circumvent applicable legal and regulatory controls.

This AML/CFT and Sanctions Compliance Policy (“Policy”) establishes the internal compliance framework adopted by the Company in connection with the operation of waspbet.net. The purpose of this Policy is to ensure that the Company identifies, assesses, monitors, and mitigates financial crime risks through proportionate and risk-based controls.

The Company applies AML/CFT measures in accordance with applicable laws and regulatory obligations in Curaçao, including the National Ordinance on the Reporting of Unusual Transactions (NORUT), the National Ordinance on Identification when Rendering Services (NOIS), and regulatory expectations issued by the Curaçao Gaming Authority (“CGA”).

The Company also takes into consideration international standards issued by the Financial Action Task Force (“FATF”), together with industry best practices relevant to online gaming operators.

2. APPLICATION OF THIS POLICY

This Policy applies to all directors, officers, employees, consultants, contractors, outsourced service providers, and any individual acting on behalf of the Company.

The Policy applies to all customer relationships, products, services, transactions, payment flows, and operational activities associated with waspbet.net.

All personnel are required to understand and comply with the obligations set out in this Policy. Any breach of AML/CFT obligations, internal compliance procedures, or regulatory requirements may result in disciplinary action, suspension of responsibilities, termination of employment or contractual relationships, and, where appropriate, notification to competent authorities.

The Company expects all personnel to act with integrity, exercise professional judgment, and promptly escalate any activity that may give rise to financial crime concerns.

3. GOVERNANCE AND OVERSIGHT

Ultimate responsibility for the effectiveness of the Company’s AML/CFT framework rests with senior management and the Board of Directors.

Senior management is responsible for ensuring that the Company maintains adequate systems, controls, staffing, monitoring procedures, and internal resources appropriate to the nature, scale, and risk profile of the business.

The Company appoints an AML Compliance Officer (“AMLCO”) with sufficient authority, independence, access to information, and operational autonomy to oversee AML/CFT compliance matters.

The AMLCO is responsible for:

overseeing customer due diligence and ongoing monitoring procedures;
reviewing and escalating suspicious activity;
maintaining AML/CFT procedures and internal controls;
supervising sanctions compliance processes;
coordinating employee training;
supporting enterprise-wide risk assessments;
liaising with regulators and competent authorities where necessary.

The AMLCO has direct access to senior management in matters involving financial crime risks, suspicious activity investigations, sanctions concerns, or regulatory obligations.

The Company periodically reviews the effectiveness of its AML/CFT framework and may conduct independent assessments, quality assurance reviews, or internal audits to evaluate whether controls remain appropriate and effective.

4. RISK-BASED APPROACH

The Company applies a risk-based approach to customer onboarding, monitoring, and account management.

Risk assessments are designed to identify and evaluate the level of exposure associated with individual customers, payment methods, jurisdictions, transactional behaviour, and operational activities.

Customer risk assessments may take into account factors including:

jurisdiction of residence;
payment method usage;
source of funds indicators;
account activity and wagering behaviour;
device and IP analysis;
politically exposed person (“PEP”) exposure;
sanctions screening results;
adverse media findings;
account linkages or behavioural anomalies.

Customers identified as presenting elevated risk may be subject to enhanced due diligence measures, increased monitoring, transaction restrictions, or additional verification requirements.

Customer risk profiles remain subject to ongoing review throughout the business relationship and may be adjusted where material changes in activity or risk indicators are identified.

5. CUSTOMER ACCEPTANCE

The Company will not knowingly establish or maintain relationships with individuals or entities connected to criminal activity, sanctions violations, terrorist financing, identity fraud, or other unlawful conduct.

The Company reserves the right to refuse, suspend, restrict, or terminate any customer relationship that may expose the business to unacceptable legal, regulatory, reputational, operational, or financial crime risk.

The Company will not knowingly establish or maintain relationships with:

sanctioned individuals or entities;
persons connected to terrorist organizations or terrorist financing activities;
individuals involved in fraud, identity misuse, financial crime, or unlawful conduct;
customers providing false, misleading, manipulated, or forged information;
customers acting on behalf of undisclosed third parties;
customers attempting to circumvent verification or monitoring controls.

Anonymous accounts, fictitious identities, and the use of falsified documentation are strictly prohibited.

The Company may restrict or prohibit access to its services from jurisdictions considered prohibited, sanctioned, excessively high-risk, or otherwise incompatible with the Company’s compliance obligations and risk appetite.

6. CUSTOMER DUE DILIGENCE

Customer Due Diligence (“CDD”) measures are applied before a customer is permitted to fully access the Company’s services.

The Company may collect and verify information including the customer’s name, date of birth, address, nationality, payment details, device information, geolocation data, and any other information reasonably required to assess identity and risk.

Verification measures may include:

identity document verification;
proof of address checks;
electronic verification systems;
database screening;
payment method verification;
device and IP analysis;
geolocation consistency checks;
sanctions and PEP screening.

The Company may request additional documentation or information at any stage of the customer relationship where this is considered necessary for compliance purposes.

Where satisfactory verification cannot be completed, the Company may suspend transactions, restrict account functionality, decline withdrawals, or terminate the relationship.

7. ENHANCED DUE DILIGENCE

Enhanced Due Diligence (“EDD”) measures may be applied in circumstances presenting elevated money laundering, terrorist financing, sanctions, or fraud risk.

EDD may apply where customers:

are identified as politically exposed persons (“PEPs”);
are connected to higher-risk jurisdictions;
exhibit unusual transactional patterns or gameplay behaviour;
trigger sanctions or adverse media alerts;
conduct significant or atypical financial activity;
present indicators inconsistent with their known profile.

As part of EDD procedures, the Company may request additional information relating to:

source of funds;
source of wealth;
occupation or business activity;
expected account activity;
ownership structures;
supporting financial documentation.

Enhanced monitoring measures, management approvals, or additional account restrictions may also apply where considered appropriate.

8. SOURCE OF FUNDS AND SOURCE OF WEALTH

The Company may request evidence demonstrating the legitimate origin of customer funds or wealth where considered necessary under its risk-based procedures.

Such reviews may be triggered by:

cumulative deposit thresholds;
high-value transactions;
withdrawal behaviour;
unusual wagering activity;
transaction velocity;
elevated customer risk classification;
adverse media findings;
other indicators identified during ongoing monitoring.

Acceptable supporting documentation may include bank statements, payslips, tax records, audited financial statements, business ownership documentation, investment records, inheritance documentation, or similar evidence capable of supporting the lawful origin of funds.

Where satisfactory information is not provided within a reasonable timeframe, the Company reserves the right to suspend transactions, restrict account functionality, terminate the customer relationship, withhold withdrawals where legally permitted, and submit reports to competent authorities where appropriate.

9. ONGOING MONITORING

The Company maintains ongoing monitoring procedures intended to identify unusual, suspicious, fraudulent, or potentially high-risk activity.

Monitoring controls may include review of:

deposit and withdrawal activity;
wagering patterns and gameplay behaviour;
transaction frequency and velocity;
payment instrument usage;
account linkages;
device and IP consistency;
geolocation data;
behavioural anomalies;
bonus abuse indicators;
dormant account reactivation.

The Company may utilize automated monitoring systems, internal risk-scoring methodologies, and manual compliance reviews to support the identification of suspicious activity.

Examples of activity requiring additional review may include rapid deposits and withdrawals with limited gameplay, unusual betting strategies, use of multiple payment instruments, frequent failed transactions, or activity inconsistent with a customer’s known profile or declared source of funds.

Where unusual activity is identified, the Company may conduct additional reviews, request supporting documentation, restrict account functionality, or escalate the matter internally for further investigation.

10. SANCTIONS COMPLIANCE

The Company maintains sanctions compliance procedures intended to prevent the use of its services by sanctioned persons, entities, or jurisdictions.

Customers and transactions may be screened against sanctions lists issued by the United Nations, the European Union, OFAC, and other applicable authorities where relevant.

Where a potential sanctions match is identified, the Company may temporarily restrict the account pending further review.

If a confirmed sanctions match is identified, the Company may freeze or terminate the account and take any further action required by applicable law or regulatory obligations.

11. REPORTING OF SUSPICIOUS ACTIVITY

Employees are required to immediately escalate any activity that appears suspicious, unusual, fraudulent, or inconsistent with a customer’s expected behaviour.

The AMLCO is responsible for reviewing internal escalations and determining whether a report should be submitted to the Financial Intelligence Unit Curaçao (“FIU Curaçao”) or any other competent authority.

Internal investigations, compliance reviews, suspicious activity assessments, and regulatory reporting decisions must be documented and retained securely.

The Company strictly prohibits tipping-off. Employees must not disclose to customers or third parties that an internal investigation, suspicious activity review, or regulatory report has been initiated or considered.

12. RECORD RETENTION

The Company maintains records relating to customer identification, account activity, transaction history, compliance reviews, suspicious activity investigations, training, and regulatory reporting in accordance with applicable legal and regulatory requirements.

Records are maintained securely, and access is restricted to authorized personnel with a legitimate business need.

The Company takes reasonable technical and organizational measures to protect confidential information against unauthorized access, misuse, alteration, disclosure, or destruction.

Records must remain accessible for regulatory inspection, audit purposes, internal investigations, and lawful requests from competent authorities.

13. EMPLOYEE TRAINING

Relevant employees receive periodic AML/CFT and sanctions compliance training appropriate to their roles and responsibilities.

Training programs are designed to ensure personnel remain familiar with:

financial crime risks associated with online gaming;
customer due diligence obligations;
suspicious activity indicators;
escalation and reporting procedures;
sanctions compliance obligations;
data protection and confidentiality requirements;
emerging fraud and financial crime typologies.

The Company maintains records of employee training, attendance, and related compliance activities.

14. ENTERPRISE-WIDE RISK ASSESSMENT

The Company conducts periodic enterprise-wide risk assessments to identify, assess, and evaluate money laundering and terrorist financing risks associated with its operations.

The assessment may consider:
customer types and behaviour;
geographic exposure;
payment channels and transaction methods;
products and services offered;
technological risks;
fraud trends;
sanctions exposure;
emerging financial crime threats relevant to the online gaming industry.

Risk assessments are reviewed periodically and updated where material legal, operational, technological, or regulatory changes occur.

15. DATA PROTECTION AND CONFIDENTIALITY

Information collected for AML/CFT purposes is processed and retained confidentially and in accordance with applicable data protection obligations.

Access to customer information and internal compliance records is limited to personnel with a legitimate business need.

The Company does not disclose confidential compliance information except where required by law, regulation, court order, lawful regulatory request, or other legally binding obligation.

16. POLICY REVIEW

This Policy is reviewed periodically to ensure continued compliance with applicable laws, regulatory expectations, operational developments, and industry standards.

The Company reserves the right to amend, supplement, or update this Policy where necessary to address changes in legislation, regulatory guidance, operational activities, emerging financial crime risks, or evolving compliance expectations.

Material changes to this Policy must be approved by senior management.

17. FINAL PROVISIONS

Plustar N.V. is committed to maintaining effective, proportionate, and risk-based controls designed to prevent the misuse of its services for money laundering, terrorist financing, sanctions evasion, fraud, or other unlawful activity.

The Company will continue to strengthen its internal compliance framework, monitoring systems, operational controls, and governance arrangements in line with applicable legal obligations, regulatory expectations, and evolving industry standards relevant to the online gaming sector.