Anti-Money Laundering & Counter-Terrorist Financing Policy
Digital goods that settle in minutes are attractive to people moving criminal money. This is what we do about it.
Effective 27 July 2026 · ARCTOPUP LIMITED
1. Why this policy exists
ARCTOPUP LIMITED sells digital top-up value that is delivered almost instantly and is difficult to reverse. That combination is exactly what makes the product useful to honest customers and attractive to people laundering funds or financing terrorism.
This policy sets out the controls we operate to stop the second group without making life difficult for the first. It reflects the standards expected of a digital goods merchant, including the recommendations of the Financial Action Task Force and the requirements our payment partners impose on us.
2. Who it applies to
The policy binds every director, employee, contractor and agent of ARCTOPUP LIMITED, and governs every customer relationship and transaction on arctopup.com regardless of value, payment method or region.
It also frames what we expect from suppliers, distributors and payment partners: they are required to maintain financial-crime controls at least equivalent to those described here.
3. Terms used here
- Money laundering — processing criminal proceeds to disguise their illegal origin.
- Terrorist financing — providing or collecting funds intended to be used for terrorist acts, whether or not the funds are of lawful origin.
- Customer due diligence (CDD) — identifying a customer, verifying that identity, and understanding the purpose of the relationship.
- Enhanced due diligence (EDD) — the stricter measures applied to higher-risk customers and transactions.
- Politically exposed person (PEP) — an individual entrusted with a prominent public function, together with their close associates and family members.
- Beneficial owner — the natural person who ultimately owns or controls a customer, or on whose behalf a transaction is conducted.
- Sanctions — restrictive measures imposed by the United Nations, Hong Kong, the European Union, the United Kingdom, the United States or another applicable authority.
- Suspicious activity — any transaction or behaviour giving reasonable grounds to suspect proceeds of crime or terrorist financing.
4. Legal framework
As a Hong Kong company we operate with reference to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615), the Organized and Serious Crimes Ordinance (Cap. 455), the Drug Trafficking (Recovery of Proceeds) Ordinance (Cap. 405) and the United Nations (Anti-Terrorism Measures) Ordinance (Cap. 575).
Where we serve customers elsewhere, we also observe the financial-crime requirements that apply in those markets and the scheme rules of the card networks and payment providers we use.
5. A risk-based approach
Controls are applied in proportion to risk rather than uniformly, so that the friction lands where the danger is.
5.1 What we assess
- Customer risk — order history, account age, device and identity signals, PEP status, and links to previously blocked accounts.
- Geographic risk — the customer’s country, the issuing country of the payment method, and any sanctions or high-risk-jurisdiction exposure.
- Product risk — how liquid and resellable a product is, and how easily it can be converted back into value elsewhere.
- Channel and payment risk — anonymity of the payment method, use of virtual assets, and card-not-present exposure.
- Transaction risk — value, frequency, velocity, structuring patterns and inconsistency with the customer’s established behaviour.
5.2 What we do about it
Each relationship is scored low, medium or high. Low risk proceeds with standard checks; medium risk attracts additional verification or limits; high risk requires enhanced due diligence and senior sign-off, or is declined outright.
Scores are not static. They are recalculated as behaviour changes, and an account can move between tiers in either direction.
6. Accountability
| Role | Responsibility |
|---|---|
| Board and senior management | Approve this policy, allocate resources, and set the tone that compliance outranks revenue |
| Compliance Officer | Own the programme day to day, decide escalations, and file reports with the authorities |
| Risk and operations team | Run monitoring and screening, review alerts, and escalate what does not resolve |
| Customer support | Spot and escalate red flags surfacing in customer conversations |
| All staff | Complete training, apply the policy, and never tip off a customer about a report |
The Compliance Officer has direct access to senior management and the authority to suspend an account, block a transaction or terminate a relationship without commercial override.
7. Customer due diligence
7.1 When we run it
- When an account is opened.
- When cumulative activity crosses an internal value or velocity threshold.
- When a transaction or pattern triggers a risk alert.
- When a sanctions or PEP screening hit needs resolving.
- When earlier identification data is doubtful, stale or inconsistent.
7.2 What we may ask for
Ordinary low-value purchases need only an email address and a valid payment method. Where risk justifies more, we may request:
- Full legal name, date of birth and nationality.
- A government-issued photo identity document.
- Proof of residential address dated within the last three months.
- Evidence that the payment instrument belongs to you.
- Source of funds, and for higher values source of wealth.
- For a corporate customer: incorporation documents, ownership structure and beneficial-owner identification.
7.3 Understanding the relationship
We form a view of why an account exists and what normal looks like for it — expected volume, typical products, usual payment methods. That baseline is what makes later anomaly detection meaningful.
7.4 If due diligence cannot be completed
Where a customer will not or cannot provide what we reasonably request, we do not open or continue the relationship. Pending transactions are cancelled and refunded to the original payment method, the account is restricted, and we consider whether a suspicious activity report is warranted.
8. Enhanced due diligence
EDD applies to PEPs and their associates, customers connected to high-risk or sanctioned jurisdictions, unusually large or complex transactions, relationships showing structuring behaviour, and any case where standard checks leave doubt unresolved.
EDD means additional identity evidence, documented source of funds and source of wealth, senior management approval before the relationship proceeds, tighter transaction limits, and more frequent review.
9. Ongoing monitoring
Monitoring is continuous rather than a one-off gate at signup. Automated rules and risk scoring run on every order and look for, among other things:
- Values or frequencies inconsistent with the account’s established pattern.
- Orders deliberately kept below a reporting or verification threshold.
- Many payment instruments used by one account, or one instrument used across many accounts.
- Rapid buying followed by refund or chargeback requests.
- Device, IP and billing-country signals that contradict each other, including proxy and VPN concealment.
- Delivery concentrated on a single account identifier from many unrelated buyers.
- Any link to an account previously blocked for financial crime.
Alerts are reviewed by the risk team, and every review — including a decision to take no action — is documented with its reasoning.
10. Sanctions
Customers, payment counterparties and, where relevant, beneficial owners are screened against applicable United Nations, Hong Kong, EU, UK and US sanctions lists at onboarding and on an ongoing basis, with re-screening when lists are updated.
A confirmed match means the transaction is blocked, the account frozen and the matter reported to the relevant authority. We do not do business with sanctioned persons or entities, and we do not sell into jurisdictions subject to comprehensive sanctions. Attempts to disguise location through proxies, VPNs or intermediaries are treated as a serious red flag in their own right.
11. Transaction controls
- Per-transaction, daily and cumulative value limits, calibrated by risk tier.
- Velocity limits on order count and payment attempts within a rolling window.
- Additional verification triggered when a customer crosses a threshold.
- Refunds returned only to the original payment method — never redirected to a third party.
- Restrictions or prohibitions on payment methods that offer inadequate traceability.
- Manual review holds on transactions the automated layer cannot clear.
12. Reporting suspicious activity
Any staff member who suspects money laundering or terrorist financing must escalate internally to the Compliance Officer without delay. There is no minimum value and no requirement to be certain — reasonable suspicion is enough, and staff are never penalised for escalating in good faith.
The Compliance Officer investigates and, where suspicion remains, files a suspicious transaction report with the Joint Financial Intelligence Unit in Hong Kong or the equivalent authority in the relevant jurisdiction. Reports are filed promptly, the customer is never informed, and we act on any instruction the authority gives about continuing or halting the relationship.
13. Records
We keep identification data, due-diligence evidence, transaction records, screening results, alert reviews, internal escalations and filed reports for at least five years from the end of the relationship or the date of the transaction, whichever is later — longer where an authority requires it.
Records are stored securely, are retrievable on lawful request, and are handled in line with the Privacy Policy.
14. Training
Every employee completes AML and CTF training at induction and at least annually thereafter, with additional sessions when regulations or internal procedures change. Staff in risk, compliance and support receive deeper role-specific training on red flags and escalation.
Completion is tracked, and effectiveness is tested rather than assumed.
15. Independent review
The programme is independently reviewed at least annually. The review covers policy adequacy, whether controls are actually operating, the quality of alert handling, training coverage and record completeness. Findings go to senior management with remediation owners and deadlines attached.
16. Third parties
We may rely on regulated payment providers and identity-verification vendors for elements of due diligence, but reliance does not transfer responsibility — the obligation to comply remains ours.
Suppliers, distributors and payment partners are assessed before onboarding and reviewed periodically. A partner unwilling to meet equivalent financial-crime standards is not engaged.
17. Prohibited activity
The following are prohibited on ARCTopup and will result in account closure and, where appropriate, a report to the authorities:
- Using proceeds of crime, or funds of unexplained origin, to buy Products.
- Buying with stolen, cloned or otherwise unauthorised payment credentials.
- Structuring purchases to stay below verification or reporting thresholds.
- Buying on behalf of an undisclosed third party, or acting as a money mule.
- Commercial resale of Products bought here without our written agreement.
- Providing false, forged or altered identification documents.
- Concealing location or identity to circumvent sanctions or regional restrictions.
- Any use of the Platform to move value for a person or entity subject to sanctions.
18. Consequences of breach
Depending on severity, breach may lead to a transaction being blocked, an account being restricted, suspended or closed, funds being frozen pending investigation, a report to the relevant financial intelligence unit, referral to law enforcement, and recovery of losses.
Staff who breach this policy face disciplinary action up to dismissal, and personal criminal liability where the law provides for it.
19. Privacy
Personal data gathered for AML purposes is processed to comply with a legal obligation, is limited to what the obligation requires, is accessible only to authorised compliance staff, and is retained for the period in section 13. Full detail sits in the Privacy Policy.
20. Review cycle
This policy is reviewed at least once a year, and sooner when regulations change, when the independent review recommends it, or when the business enters a new market or adopts a new payment method. Material changes are approved by senior management before they take effect.
21. Reporting a concern
Concerns about financial crime on the Platform can be raised in confidence with the Compliance Officer at [email protected] using the subject line "AML". Reports made in good faith are treated confidentially and the reporter is protected from retaliation.
22. Disclaimer
This policy is published for transparency. It is a summary of our internal control framework, not legal advice, and it does not create rights for third parties or oblige us to disclose the operational detail of any specific control, threshold or investigation.
Legal entity: ARCTOPUP LIMITED
Registered office: 340 BELCHER'S STREET, SAI YING PUN, CENTRAL AND WESTERN DISTRICT, HONG KONG 999077
Telephone: 00852-6809239
Email: [email protected]