RWANFTFI Corporation — AML/CTF Policy and Procedures

Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Compliance Policy

Version: 1.1
Effective date: 30 September 2026
Review: at least annually, and whenever there is a material change in the business, law or risk environment

1. Purpose and scope

This Policy sets out how RWANFTFI Corporation ("RWANFTFI" or the "Company") prevents its services from being used for money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud and other financial crime.

RWANFTFI Corporation is a corporation incorporated in the Republic of Panama and registered with the Public Registry of Panama, Mercantile Section, under Folio No. 155774978. Its registered address is Advanced Tower Building, First Floor, Ricardo Arias Street, Panama City, Republic of Panama.

This Policy applies to:

  • the RWANFTFI website, NFT platform and platform wallet features available at https://app.rwanftfi.com;
  • all users, including NFT purchasers, sellers and creators;
  • all directors, officers, employees, contractors and service providers acting on behalf of the Company;
  • integrations with third-party providers, including fiat-to-crypto on-ramp providers.

2. Legal and regulatory framework

The Company applies this Policy on a risk-based approach, in line with:

  • Panamanian law to the extent applicable, including Law No. 23 of 27 April 2015 on the prevention of money laundering, terrorist financing and financing of the proliferation of weapons of mass destruction;
  • the FATF Recommendations, including Recommendation 15 and FATF guidance on virtual assets and virtual asset service providers;
  • sanctions lists issued by the United Nations Security Council, the U.S. Office of Foreign Assets Control (OFAC), the European Union and the United Kingdom;
  • contractual AML/CTF requirements of the Company's banking, payment and on-ramp partners.

Where requirements differ, the Company applies the stricter standard.

3. Business model and risk overview

RWANFTFI operates an NFT platform. Users may connect digital wallets, purchase and sell NFTs, and use platform wallet features. Transactions are settled in supported cryptocurrencies.

Users connect their own self-custodial wallets; the Company has no access to users' private keys. Where a user tops up a platform balance, the funds are held in the platform smart contracts on BNB Smart Chain, audited by CertiK, and the balance is recorded on-chain against the user's wallet address. Withdrawals are made only to the user's connected wallet and are authorised by the platform's automated verification service, which applies the checks set out in this Policy. The Company wallet receives only platform fees through a dedicated contract function and does not withdraw user balances.

The Company does not accept fiat currency directly from users. Fiat-to-crypto purchases are provided by an independent licensed or registered on-ramp provider, such as Guardarian. The on-ramp provider performs its own KYC, AML, payment and fraud checks when a user buys cryptocurrency.

The main financial-crime risks identified for the business are:

  • use of funds derived from crime, fraud, scams, hacks or ransomware;
  • use of NFTs to transfer value between connected persons at artificial prices;
  • wash trading and market manipulation;
  • sanctions evasion through wallets, related persons or prohibited jurisdictions;
  • use of mixers, privacy tools and chain-hopping to conceal the origin of funds;
  • account takeover, identity fraud and multiple accounts;
  • third-party use of accounts or wallets.

4. Governance and responsibilities

Board of Directors or authorised representative. The Board of Directors, or a representative duly authorised by the Company, approves this Policy, ensures that adequate resources are allocated to compliance, and receives compliance reports at least annually.

AML Compliance Officer. The Board appoints an AML Compliance Officer with sufficient authority, independence and access to information. The AML Compliance Officer is responsible for:

  • implementing and maintaining this Policy;
  • approving high-risk customers and enhanced due diligence decisions;
  • reviewing alerts and investigating unusual activity;
  • deciding whether to reject, suspend, restrict or terminate a relationship;
  • filing reports with competent authorities where required;
  • responding to requests from authorities and partners;
  • maintaining records, training and periodic reviews.

Staff and contractors. All persons acting for the Company must follow this Policy and promptly report suspicious activity to the AML Compliance Officer.

5. Risk-based approach

The Company assesses risk before and during the business relationship. Risk is assessed using:

  • Customer risk: identity, profile, adverse media, PEP status, sanctions matches, use of multiple accounts.
  • Geographic risk: nationality, residence, IP address and connection to high-risk or prohibited jurisdictions.
  • Wallet risk: blockchain analytics results, exposure to sanctioned addresses, darknet markets, mixers, scams, stolen funds or ransomware.
  • Transaction risk: value, frequency, velocity, price consistency, connected counterparties and unusual patterns.
  • Product risk: NFT sales, resale activity, royalties, platform balances and withdrawals.

Each user is classified as low, medium or high risk. The classification determines the level of due diligence and monitoring.

6. Prohibited users and activities

The Company does not provide services to:

  • persons under 18 years of age;
  • persons or entities listed on UN, OFAC, EU or UK sanctions lists, or owned or controlled by such persons;
  • persons resident in, or acting from, jurisdictions subject to comprehensive sanctions or an FATF call for countermeasures. This currently includes the Democratic People's Republic of Korea (North Korea), Iran, Cuba, and the Crimea, so-called Donetsk People's Republic and so-called Luhansk People's Republic regions of Ukraine;
  • users who refuse to provide requested due diligence information or provide false, forged or misleading information;
  • users acting on behalf of an undisclosed third party;
  • shell banks or unlicensed money transmission businesses.

The following activities are prohibited:

  • transactions involving proceeds of crime, fraud, hacks, scams or ransomware;
  • wash trading, self-dealing, price manipulation and circular trading;
  • use of the platform to transfer value unrelated to genuine NFT purchases;
  • deliberate splitting of transactions to avoid thresholds;
  • use of VPNs or other tools to circumvent geographic restrictions;
  • listing NFTs connected with illegal, sanctioned or infringing content.

Enhanced due diligence applies to Myanmar, other jurisdictions listed by FATF as under increased monitoring, and jurisdictions subject to targeted sanctions programmes, including Russia and Belarus. Services are not provided where prohibited by applicable sanctions.

The list of prohibited and high-risk jurisdictions is reviewed after each FATF plenary and whenever sanctions change.

7. Customer due diligence

7.1 Standard due diligence

All users must:

  • accept the Terms and this Policy's requirements;
  • confirm that they are at least 18 years old;
  • confirm that they are not a sanctioned person and are not located in a prohibited jurisdiction;
  • connect a wallet that is screened before use, as described in Section 8.

The Company collects account data such as email address, wallet address and technical data including IP address and device information.

7.2 Identity verification

Identity verification (KYC) is required before a user may:

  • sell NFTs or receive sale proceeds or royalties;
  • withdraw funds from a platform balance;
  • carry out transactions with a cumulative value of USD 1,000 or more in a 30-day period;
  • continue using the Services after a risk alert or a request from the Company.

KYC includes:

  • full name, date of birth, nationality and residential address;
  • a valid government-issued identity document;
  • liveness or selfie verification;
  • sanctions, PEP and adverse media screening.

For legal entities, the Company additionally verifies company registration details, directors, beneficial owners holding 25% or more, and authorised representatives.

7.3 Enhanced due diligence

Enhanced due diligence (EDD) applies to:

  • high-risk users;
  • politically exposed persons (PEPs), their family members and close associates;
  • users connected to high-risk jurisdictions;
  • transactions with a cumulative value of USD 10,000 or more in a 30-day period;
  • unusual transactions or patterns identified by monitoring;
  • wallets with medium or elevated risk exposure.

EDD may include:

  • source of funds and source of wealth information and supporting documents;
  • additional verification of identity and address;
  • explanation of the purpose of transactions;
  • approval by the AML Compliance Officer before continuing the relationship;
  • more frequent monitoring and lower transaction limits.

7.4 On-ramp transactions

When a user purchases cryptocurrency through an integrated on-ramp provider, the provider performs KYC and AML checks for the fiat payment under its own obligations. The Company:

  • does not receive or store the user's card or bank payment details;
  • does not bypass, alter or interfere with the provider's controls;
  • screens the destination wallet and monitors related platform activity;
  • promptly cooperates with the provider's requests for information;
  • restricts users who are rejected or restricted by the on-ramp provider for financial-crime reasons, where lawful and appropriate.

7.5 Ongoing due diligence

Customer information is updated when documents expire, when there is a material change in the user's profile or activity, and at least:

  • every 12 months for high-risk users;
  • every 36 months for other verified users.

8. Wallet screening and blockchain analytics

The Company uses blockchain analytics and wallet-screening tools, such as MistTrack, to assess the risk of wallet addresses and transactions.

Screening is performed:

  • when a wallet is connected;
  • before deposits are credited to a platform balance;
  • before withdrawals or payouts;
  • periodically, and when new risk information becomes available.

The Company rejects or freezes transactions, where lawful, and escalates to the AML Compliance Officer when a wallet has direct or significant indirect exposure to:

  • sanctioned persons or addresses;
  • darknet markets;
  • stolen funds, hacks or exploits;
  • ransomware, scams or fraud;
  • terrorist financing;
  • child sexual abuse material;
  • mixers or services designed to obscure transaction history.

Medium-risk results are reviewed manually and may require EDD before the user continues.

9. Transaction monitoring

The Company monitors platform activity for unusual transactions. Red flags include:

  • NFT sales at prices significantly inconsistent with market value or previous sales;
  • repeated trades of the same NFT between the same or connected wallets;
  • rapid purchase and resale without economic rationale;
  • funds deposited and withdrawn shortly afterwards with little or no platform activity;
  • multiple accounts or wallets linked to the same person, device or IP address;
  • transactions split to remain below verification thresholds;
  • activity inconsistent with the user's declared profile or source of funds;
  • IP addresses or behaviour indicating a prohibited jurisdiction;
  • use of newly created wallets funded from high-risk sources;
  • reluctance to provide information or provision of inconsistent documents.

Alerts are reviewed by the AML Compliance Officer. Each review, decision and rationale is documented.

10. Sanctions compliance

All users, beneficial owners, wallets and counterparties are screened against applicable sanctions lists:

  • at onboarding or when a wallet is first connected;
  • when lists are updated;
  • before payouts and withdrawals.

If a potential match is found, the transaction is held pending review. If a true match is confirmed, the Company blocks the account and assets where required by law, does not proceed with the transaction and reports to the competent authority where required.

11. Suspicious activity reporting

Staff must report suspicious activity to the AML Compliance Officer immediately.

The AML Compliance Officer investigates and decides whether to:

  • request additional information;
  • restrict, suspend or terminate the relationship;
  • reject or delay a transaction where lawful;
  • file a suspicious transaction report.

Where the Company is subject to a reporting obligation, suspicious transactions are reported to the competent financial intelligence unit, including the Unidad de Análisis Financiero (UAF) of Panama. The Company also cooperates with lawful requests from authorities and informs its regulated partners where required by contract and permitted by law.

Tipping-off is prohibited. No person may inform a user or third party that a report has been made or an investigation is underway.

12. Record keeping

The Company keeps the following records for at least five (5) years after the end of the business relationship or the relevant transaction, or longer where required by law or an ongoing investigation:

  • due diligence data and documents;
  • wallet-screening and sanctions-screening results;
  • transaction records;
  • alerts, investigations, decisions and reports;
  • communications relating to compliance requests;
  • training records.

Records are stored securely and made available to competent authorities upon lawful request. Personal data is processed in accordance with the Company's Privacy Policy.

13. Third-party providers

The Company may rely on third-party providers for identity verification, blockchain analytics, sanctions screening and on-ramp services. The Company:

  • selects providers based on their reputation, regulatory status and data protection standards;
  • defines responsibilities in the service agreement;
  • retains responsibility for its own AML/CTF decisions;
  • reviews provider performance periodically.

14. Training

All persons with access to user operations or compliance matters receive AML/CTF and sanctions training:

  • when they start working with the Company;
  • at least annually;
  • when there are material changes to laws, risks or this Policy.

Training covers the Company's risks, red flags, reporting procedure, sanctions and tipping-off prohibition.

15. Independent review and policy updates

This Policy and its implementation are reviewed at least annually by the AML Compliance Officer. The Board may commission an independent review based on the Company's size and risk profile.

The Policy is updated when there are changes in:

  • applicable laws or sanctions;
  • FATF lists or guidance;
  • products, services, target markets or providers;
  • identified risks or review findings.

16. Breaches of this Policy

Failure to comply with this Policy may result in disciplinary action, termination of engagement and reporting to competent authorities where required.

Users who breach this Policy or the Terms may have their access restricted, listings removed, transactions rejected or accounts terminated, subject to applicable law.

17. Contact

AML/CTF and compliance enquiries: [email protected]
Subject line: "AML Compliance"