1. Purpose and Scope
This Anti-Money Laundering (AML) and Countering Financing of Terrorism (CFT) Policy governs all activity conducted on the Xhjili platform, including casino, sportsbook, live casino, and related payment flows. It establishes the controls required to detect, prevent, and report money laundering and terrorist financing in accordance with applicable laws and regulatory expectations. The policy applies to all customers, employees, agents, and business partners engaged in onboarding, financing, wagering, and settlement activities on the platform.
2. Regulatory Framework and Governance
Xhjili operates under an integrated AML/CFT program designed to comply with the laws and regulations relevant to online gaming and financial services. A designated Money Laundering Reporting Officer (MLRO) has responsibility for implementing the program, receiving disclosures, and coordinating with competent authorities. Senior management retains ultimate accountability for the program, including resource allocation, policy maintenance, and annual risk review. A Compliance and Risk Committee will review the program no less than quarterly, or more often as required by risk conditions.
3. Risk-Based Approach and Customer Due Diligence
Xhjili conducts customer due diligence (CDD) on a risk-based basis, applying progressively intensive checks according to the assessed risk of the customer and the nature of transactions. The risk framework includes three tiers:
- SDD — Simplified Due Diligence for extremely low-risk, low-value activities that do not meet standard thresholds.
- CDD — Standard due diligence for the majority of customers and routine transactions, including identity verification and basic verification of the source of funds.
- EDD — Enhanced Due Diligence for high-risk customers, politically exposed persons (PEPs), and large or unusual transactions, or when the risk assessment indicates elevated risk.
On an ongoing basis, Xhjili reviews customer activity against their risk profile and adjusts monitoring and escalation accordingly. Risk assessments are conducted at account onboarding and updated at least annually, or sooner upon significant changes in customer behavior.
4. Customer Identification and Verification (KYC)
On onboarding, customers must be identified and verified prior to or during the first substantial interaction with the platform. Verification requires, as applicable:
- Proof of Identity: Government-issued photo ID showing full name, date of birth, and photograph; document must be valid and not expired within the next three months; name must match the customer-provided details; verification may require scanning or uploading both sides of the document where applicable.
- Proof of Residence: Recent (issued within the last three months) document showing the customer’s name and current address (e.g., bank statement, utility bill); the name must match the identity document.
- Selfie Verification: A live selfie of the customer holding the identity document to confirm identity and ownership of the document.
If verification cannot be completed satisfactorily, access to certain platform features may be restricted pending completion of the process. Xhjili reserves the right to request additional information or decline access where required by law or risk considerations.
5. Source of Funds, Payment Origination, and Enhanced Review
For all deposits and significant withdrawals, Xhjili requires reasonable evidence of the source of funds and the origin of wealth consistent with the disclosed profile and activity. The company will request documentation such as:
- Bank statements or other formal financial records showing deposits and balances,
- Pay slips, tax returns, corporate accounts, or audited financials where appropriate, and
- Documentation supporting business activity for corporate or trust structures.
Enhanced Due Diligence applies to high-risk customers, unusual patterns, or transactions that exceed established thresholds. In such cases, Xhjili may require additional corroboration, restrict specific functionality, or halt processing until documentation is reviewed and approved.
6. Suspicious Activity Reporting and Escalation
All employees are obligated to report grounds for knowledge or suspicion of money laundering or terrorist financing to the MLRO. Reports (SARs) must be submitted promptly and in a manner compliant with applicable law, without disclosing the concern to the customer or any other party involved in the investigation. Any disclosure or tipping-off is strictly prohibited and may result in criminal or regulatory penalties. SARs and related actions are documented, preserved, and retained for the statutory period and available to law enforcement upon request.
7. Transaction Monitoring, Withdrawals and Refunds
Xhjili conducts ongoing monitoring of deposits, won losses, and wagering activity to confirm consistency with the customer’s profile and declared source of funds. Before any withdrawal, the platform conducts the following checks:
- Verify that deposits align with the customer’s activity and historical patterns;
- Confirm that the customer’s turnover supports the withdrawal and is not being used as a method to transfer value
- Where feasible, refund funds to the original payment method used for deposits
Withdrawals may be delayed or blocked if there is suspicion of illicit activity, if identity verification is incomplete, or if requested information is not provided within a reasonable time frame.
8. High-Risk Jurisdictions and Politically Exposed Persons (PEPs)
Customers located in or associated with high-risk jurisdictions, as identified by recognized international standards or regulatory bodies, are subjected to Enhanced Due Diligence. PEPs receive heightened scrutiny, and ongoing monitoring is intensified. Access for customers from jurisdictions identified as high risk can be restricted or denied where required by law or policy.
9. Record Keeping and Data Retention
Xhjili maintains comprehensive records to support the AML/CFT program, including identity verification documents, risk assessments, transaction records, SARs, and correspondence with authorities. Records are retained for a minimum period of five years after account closure or last activity, and such data is safeguarded in accordance with applicable data protection laws and industry standards.
10. Training, Awareness, and Roles
All staff receive AML/CFT training relevant to their role, including customer due diligence, SAR procedures, and escalation protocols. The designated MLRO has independent authority and access to resources necessary to perform obligations, including receiving disclosures, reporting to authorities, and coordinating remediation actions. Regular reviews and refreshers are conducted to align with evolving risks and regulatory expectations.
11. Vetting of Employees and Access Controls
New employees undergo verification checks to confirm identity, qualifications, and suitability. Access to AML-sensitive systems is restricted to authorized personnel, with role-based controls and audit trails to prevent internal misuse and protect customer data.
12. Compliance Monitoring, Audit and Policy Updates
The AML/CFT program is subject to periodic internal and external reviews. The policy is reviewed at least annually or sooner in response to regulatory changes, significant risk events, or operational changes. Updates shall be communicated to relevant personnel and integrated into training and procedures.
