Legal
KYB/AML Policy
1. Purpose and Scope
This AML/CFT Policy sets forth Xtrari Limited’s (“Xtrari”, “we”, “Company”) measures to prevent money laundering and terrorist financing in connection with the Platform and its Contractor of Record services.
Xtrari is committed to maintaining a robust compliance framework based on internationally recognised standards, including the recommendations issued by the Financial Action Task Force (“FATF”), and having regard to applicable Hong Kong laws, applicable sanctions regimes, and generally accepted industry practices.
The purpose of this Policy is to establish a risk-based framework for:
- (a) identifying and verifying Clients, Providers (subcontractors), beneficial owners and relevant counterparties,
- (b) understanding the nature and purpose of business relationships,
- (c) assessing and managing financial crime risks,
- (d) detecting and investigating suspicious activities,
- (e) maintaining appropriate records and internal controls.
For the avoidance of doubt, Xtrari is not a financial institution or designated non-financial business or profession subject to the statutory AML/CFT customer due diligence and record-keeping requirements applicable to such regulated entities under Hong Kong law. The controls set out in this Policy are adopted by Xtrari as part of its internal compliance framework and shall be applied to the extent appropriate to the Xtrari's business activities and applicable legal and regulatory requirements.
This Policy applies to all business relationships established by Xtrari, including:
- Clients engaging Xtrari’s services,
- Clients, Providers (including freelancers and individuals) engaged through Xtrari platform,
- beneficial owners, directors, officers and authorised representatives of Clients,
- third-party service providers and other relevant counterparties where applicable.
Definitions
Unless otherwise defined in this Policy, the terms shall have the meanings set out in our Terms of Service.
- “AML/CFT” means Anti-Money Laundering and Countering the Financing of Terrorism.
- “FATF” means the Financial Action Task Force, an international standard-setting body for AML/CFT measures.
- “KYB” (Know Your Business) means the process of identifying, verifying and assessing corporate customers and business counterparties.
- “KYC” (Know Your Customer) means the process of identifying and verifying individuals, including contractors and representatives.
- “CDD” (Customer Due Diligence) means measures undertaken to identify customers, verify their identity, understand the purpose of the relationship and assess associated risks.
- “EDD” (Enhanced Due Diligence) means additional verification and monitoring measures applied to higher-risk customers, jurisdictions or activities.
- “UBO” (Ultimate Beneficial Owner) means the natural person(s) who ultimately own or control a legal entity or exercise effective control over its activities.
- “PEP” (Politically Exposed Person) means an individual entrusted with a prominent public function who may present heightened corruption and financial crime risks.
- “STR/SAR” means Suspicious Transaction Report or Suspicious Activity Report submitted to competent authorities where required.
- “Client” means a legal entity or individual entrepreneur that engages the Contractor to perform, or arrange for the performance of, works, services, tasks, or projects.
- “Provider” means an independent professional, agency, or other service provider that performs the Works and/or provides the Services requested by a Client pursuant to the relevant agreement with the Contractor.
- “Contractor” or “Contractor of Record” means Xtrari, which is engaged by a Client under the Contractor Agreement to perform, or arrange for the performance of, works, services, tasks or projects through one or more Providers.
- “Platform” means the online platform operated by Xtrari and made available through https://xtrari.com, including any associated websites, applications, software, functionality, features, interfaces, and related services made available by us from time to time.
2. Regulatory Framework and Risk-Based Approach
Xtrari maintains its AML/CFT programme based on the principles established by FATF Recommendations and international best practices.
Xtrari applies a risk-based approach, meaning that the nature and extent of compliance measures are proportionate to the level of financial crime risk identified.
Xtrari considers, among others:
- Clients/ Providers profile,
- ownership and control structure,
- geographic exposure,
- business activity,
- payment flows,
- Clients/ Providers locations,
- transaction volumes,
- delivery channels,
- use of third-party providers,
- sanctions and reputational risks.
Where applicable, Xtrari also considers requirements arising from applicable sanctions regimes, local AML/CFT legislation, payment service provider requirements, banking partner requirements, contractual compliance obligations imposed by Clients.
3. AML/CFT Governance and Responsibilities
Xtrari maintains appropriate governance arrangements to ensure the effective implementation, oversight, and continuous improvement of this AML/CFT Policy.
3.1 Senior Management
Senior Management is responsible for:
- (a) approving the AML/CFT framework and ensuring it remains appropriate for Xtrari’s business model and risk profile,
- (b) ensuring adequate resources, systems, and expertise are allocated to support effective AML/CFT compliance,
- (c) reviewing significant compliance risks and approving risk mitigation measures,
- (d) promoting a strong culture of compliance and ethical business conduct throughout the organisation.
3.2 Compliance Officer
Xtrari may, at its discretion, appoint a Compliance Officer responsible for the implementation, administration, and oversight of the AML/CFT Policy.
Where a Compliance Officer is appointed, the Compliance Officer is responsible for:
- (a) maintaining and updating AML/CFT policies, procedures, and controls,
- (b) overseeing customer and business partner due diligence processes, including KYB, KYC, UBO identification, and risk assessments,
- (c) conducting or coordinating AML/CFT risk assessments and recommending appropriate mitigation measures,
- (d) monitoring transactions, activities, and business relationships for potential suspicious activity,
- (e) managing internal escalation procedures and ensuring appropriate investigation and documentation of compliance concerns,
- (f) coordinating responses to regulatory, governmental, or law enforcement requests,
- (g) ensuring that relevant personnel involved in Xtrari’s operations receive appropriate AML/CFT guidance and training.
3.3 Service Providers
Providers engaged by Xtrari, including subcontractors, consultants, agents, and third-party service providers involved in onboarding, payments, customer support, operational activities, or other relevant functions, are required to:
- (a) comply with this AML/CFT Policy and applicable internal procedures,
- (b) complete any required compliance training or awareness activities,
- (c) promptly identify and escalate any suspected money laundering, terrorist financing, fraud, sanctions, or other compliance concerns,
- (d) cooperate with compliance reviews, investigations, and information requests.
Xtrari maintains appropriate reporting and escalation channels to enable service providers to raise compliance concerns in good faith without fear of retaliation or adverse treatment.
4. Client/ Provider Risk Assessment
Xtrari applies a Client/ Provider risk classification methodology:
A Low Risk. Clients/ Providers that present limited financial crime exposure and demonstrate transparent ownership, business activity and expected payment behaviour.
B Medium Risk. Clients/ Providers that require standard due diligence and ongoing monitoring due to increased complexity, geographic exposure or transaction profile.
C High Risk. Clients/ Providers that present elevated risks, including:
- (a) complex ownership structures,
- (b) high-risk jurisdictions,
- (c) PEP involvement,
- (d) adverse media,
- (e) unusual payment patterns,
- (f) unclear business purpose,
- (g) significant payroll volumes.
High-risk relationships are subject to enhanced due diligence and increased monitoring.
5. Client/ Provider Acceptance Policy
5.1 General Principles
Xtrari applies a risk-based Client/Provider Acceptance Procedure (“Acceptance Procedure”) as an integral part of this AML/CFT Policy to ensure that business relationships are established only with Clients, Providers, and counterparties whose identity, ownership structure, business activities, and intended use of the Xtrari Platform and services can be reasonably verified and assessed.
The purpose of the Acceptance Procedure is to prevent Xtrari from being used for money laundering, terrorist financing, sanctions evasion, fraud or fraudulent employment arrangements, unlawful labour practices, concealment of beneficial ownership, and processing of funds derived from illegal activities.
Before establishing a business relationship, Xtrari performs appropriate due diligence procedures proportionate to the identified risk level, including, where applicable, identification and verification of the Client/Provider and its relevant representatives, beneficial owners and controlling persons, assessment of its business activities and purpose of the relationship, sanctions screening and other applicable AML/CFT and financial crime checks.
No relationship may be established where:
- (a) the identity of the Client/Provider or relevant parties cannot be verified,
- (b) the beneficial ownership structure cannot be reasonably established,
- (c) the purpose and expected nature of the relationship or the expected use of the Platform or services cannot be reasonably established,
- (d) the Client/Provider is involved in prohibited activities,
- (e) applicable sanctions restrictions prevent engagement,
- (f) the identified risks cannot be adequately mitigated.
5.2 Customer Categories
For the purposes of this Policy, Xtrari identifies the following categories of relevant counterparties:
(a) Clients
Clients are companies or organisations engaging Xtrari for services, including subcontractor engagement and administration and payout coordination. Clients are subject to KYB procedures before onboarding.
(b) Providers (Subcontractor)
Providers are individuals or companies engaged through Xtrari acting as subcontractors to provide services at the request of Clients. Providers are subject to identity verification and screening procedures appropriate to the services provided and applicable legal requirements.
(c) Beneficial Owners, Directors and Representatives
Xtrari identifies and verifies relevant individuals connected with Clients, including:
- UBOs,
- directors,
- authorised representatives,
- controlling persons,
- individuals authorised to instruct or manage the relationship.
(d) Third-Party Service Providers
Where Xtrari relies on third-party providers, including payment providers, compliance providers, technology providers or other operational partners, Xtrari applies appropriate onboarding and monitoring measures based on the associated risk.
5.3 Prohibited Customers and Activities
Xtrari does not establish or maintain relationships with Clients, Providers or counterparties involved in activities that present unacceptable AML/CFT, sanctions, legal or reputational risks.
Xtrari reserves the right to refuse onboarding, suspend services or terminate relationships where compliance risks cannot be appropriately managed.
6. Clients/ Providers Due Diligence (KYB/KYC)
6.1 General Customer Due Diligence Requirements
Xtrari applies Customer Due Diligence measures before establishing a business relationship and throughout the relationship on a risk-sensitive basis.
CDD measures include:
- (1) identification and verification of the Clients/ Providers,
- (2) identification and verification of beneficial ownership,
- (3) understanding the purpose and intended nature of the relationship,
- (4) assessment of AML/CFT risks,
- (5) ongoing monitoring of the relationship.
Xtrari applies a proportionate approach, meaning that higher-risk customers and relationships are subject to enhanced verification and monitoring.
6.2 Client KYB Procedures
Before onboarding the Client, Xtrari collects and verifies appropriate corporate information.
The required information may include:
A Corporate Information
- (a) full legal name,
- (b) registration number,
- (c) jurisdiction of incorporation/ registration,
- (d) registered office address,
- (e) principal place of business,
- (f) constitutional documents,
- (g) business activity description,
- (h) website and public business information,
- (i) licensing information where applicable.
B Corporate Documentation
Depending on jurisdiction and risk level, Xtrari may request:
- (a) certificate of incorporation,
- (b) memorandum and articles of association or equivalent constitutional documents,
- (c) certificate of good standing or equivalent,
- (d) register of directors,
- (e) register of shareholders,
- (f) ownership structure chart,
- (g) business licence or regulatory authorisation,
- (h) financial information or proof of legitimate business activity.
Documents may be required to be current, certified or notarised where appropriate, issued by competent authorities, and translated where necessary.
6.3 Verification of Corporate Purpose and Business Activities
Xtrari assesses whether the Clients stated business activities are consistent with the requested services, expected Provider arrangements, expected payment flows, geographic exposure, and commercial rationale.
Xtrari may request additional information, including:
- (a) description of business operations,
- (b) explanation of service requirements,
- (c) details of Providers to be engaged,
- (d) expected countries of contractor activity,
- (e) expected payment volumes,
- (f) source of funds information.
Where information provided is inconsistent, incomplete or raises concerns, Xtrari may conduct enhanced review before approval.
6.4 Provider KYC Procedures
All Providers engaged through Xtrari Platform are subject to risk-based identification and verification procedures appropriate to their legal status, the nature of the services provided, and the assessed AML/CFT risk.
Xtrari provides Contractor of Record services solely in respect of independent contractor engagements. Nothing in Xtrari's services, the Platform, agreements or related documentation creates, or is intended to create, an employment or similar relationship between Xtrari and any Provider, Client or other user of the Platform.
Depending on applicable requirements and risk assessment, Xtrari may collect:
- (a) full legal name,
- (b) date of birth,
- (c) nationality,
- (d) residential address,
- (e) contact details,
- (f) tax-related information where required.
Identity Documents
Examples include:
- (a) passport,
- (b) national identity document,
- (c) other government-issued identification documents.
Where appropriate, Xtrari may also verify:
- (a) eligibility to perform the contracted services where required by applicable law,
- (b) professional licences or qualifications relevant to the services,
- (c) bank account ownership or other payment information,
- (d) tax residency or registration details, where applicable.
Where a Provider is a legal entity, Xtrari may perform risk-based KYB procedures, including obtaining and verifying, where appropriate:
- (a) legal name,
- (b) registration number,
- (c) jurisdiction of incorporation or establishment,
- (d) registered office address,
- (e) principal place of business,
- (f) constitutional documents,
- (g) details of directors or authorised representatives;
- (h) UBO information,
- (i) business activities and the nature of the services to be provided.
Xtrari may also verify the authority of any individual acting on behalf of the corporate Provider.
Xtrari reserves the right to request additional information or documentation where necessary.
6.5 Identification and Verification of Ultimate Beneficial Owners (UBO)
Xtrari identifies and verifies the UBOs of corporate Clients. Where ownership is indirect, Xtrari examines the ownership chain until the ultimate natural person(s) exercising ownership or control are identified.
Xtrari may obtain:
- (a) full name of each UBO,
- (b) date of birth,
- (c) nationality,
- (d) residential address,
- (e) ownership percentage,
- (f) nature of control,
- (g) identification documents.
Supporting documentation may include:
- (a) shareholder registers,
- (b) ownership charts,
- (c) corporate filings,
- (d) trust or foundation documents where applicable,
- (e) declarations of beneficial ownership.
Xtrari may request additional information where ownership structures are complex, nominee shareholders are involved, trusts or similar arrangements exist, or ownership information is inconsistent or unclear.
6.6 Failure to Complete Due Diligence
Where Xtrari cannot satisfactorily complete required KYB/KYC procedures, it may:
- (1) refuse onboarding,
- (2) delay activation of services,
- (3) restrict certain activities,
- (4) request additional documentation,
- (5) suspend or terminate the relationship.
Xtrari shall not knowingly establish or continue a relationship where the identity, ownership or purpose of the relationship cannot be reasonably verified.
7. Enhanced Due Diligence (“EDD”)
7.1 General Principles
Xtrari applies EDD measures where Client, Provider, beneficial owner, transaction, jurisdiction or business relationship presents an increased level of AML/CFT, sanctions, fraud or reputational risk.
EDD measures are applied on a risk-sensitive basis and are designed to obtain a deeper understanding of the customer’s ownership and control structure, the source and legitimacy of funds, the purpose and expected nature of the relationship, the rationale for the proposed business activity, and potential exposure to financial crime risks.
The application of EDD does not, in itself, preclude Xtrari from establishing or continuing a business relationship. No higher-risk relationship shall be established or maintained unless Xtrari is satisfied that the identified risks have been appropriately assessed, mitigated and approved in accordance with this Policy. Such relationships shall remain subject to enhanced monitoring throughout their duration.
7.2 Circumstances Requiring Enhanced Due Diligence
Xtrari may apply EDD where one or more higher-risk indicators are identified, including:
A Customer Risk Factors
- (a) complex or opaque ownership structures,
- (b) difficulty identifying the UBO,
- (c) ownership involving trusts, foundations, nominees or offshore structures,
- (d) Clients/ Providers operating in high-risk industries,
- (e) Clients/ Providers with significant international operations,
- (f) Clients/ Providers with limited operating history,
- (g) inconsistent or incomplete information provided during onboarding.
B Geographic Risk Factors
EDD may be required where Clients, Providers, beneficial owners or transaction flows involve:
- (a) FATF-identified high-risk jurisdictions,
- (b) jurisdictions subject to enhanced monitoring by international bodies,
- (c) countries with elevated corruption, fraud or financial crime risks,
- (d) sanctioned or restricted jurisdictions.
B Individual Risk Factors
EDD may be required where relevant persons include:
- (a) Politically Exposed Persons (“PEPs”),
- (b) close family members or known close associates of PEPs,
- (c) persons subject to adverse media reports,
- (d) individuals connected with financial crime investigations.
C Transaction and Operational Risk Factors
EDD may be required where:
- (a) expected payment volumes are unusually high,
- (b) payment flows are inconsistent with the Client/Provider’s business profile,
- (c) there are unusual payment instructions,
- (d) third-party payment arrangements are used,
- (e) Client/Provider’s locations or payment destinations create additional risk.
7.3 Enhanced Due Diligence Measures
Depending on the identified risks, Xtrari may implement additional measures, including obtaining additional corporate documentation, obtaining certified or notarised documents, verifying information through independent sources, obtaining additional information regarding business activities, obtaining evidence of source of funds or source of wealth, conducting enhanced adverse media searches, obtaining senior management approval before onboarding, or applying enhanced ongoing monitoring.
The level of EDD applied shall be proportionate to the identified risk.
8. Sanctions and PEP
8.1 Sanctions Compliance
Xtrari maintains procedures designed to identify and mitigate risks arising from applicable sanctions regimes.
Sanctions screening is conducted to identify potential matches involving:
- (a) Clients,
- (b) Providers,
- (c) UBO,
- (d) directors and authorised representatives,
- (e) relevant third parties.
Xtrari considers applicable sanctions requirements issued by relevant authorities, including international sanctions regimes applicable to its operations and contractual obligations.
8.2 Sanctions Screening
Before establishing a business relationship, Xtrari performs sanctions screening against relevant persons and entities.
Screening may include:
- (a) Client/Provider legal name or identity information,
- (b) trading names,
- (c) UBO,
- (d) directors,
- (e) authorised representatives.
Where a potential sanctions match is identified:
- (1) the relationship shall be reviewed,
- (2) additional information may be requested,
- (3) the match shall be assessed to determine whether it is a true match,
- (4) appropriate restrictions shall be applied where required.
Xtrari does not knowingly provide services to sanctioned persons or entities.
8.3 Politically Exposed Persons (“PEP”) Screening
Xtrari identifies whether Clients, Providers, UBOs, or representatives are Politically Exposed Persons (“PEPs”).
PEPs include individuals entrusted with prominent public functions, including, depending on applicable standards senior government officials, senior judicial or military officials, senior executives of state-owned enterprises, or senior political party officials. Xtrari also considers family members of PEPs, or close associates of PEPs.
9. Ongoing Monitoring and Review
9.1 General Monitoring Obligations
Xtrari applies ongoing monitoring throughout the business relationship to ensure Client and Provider information remains accurate and that activity is consistent with the known profile.
Ongoing monitoring includes:
- (1) reviewing changes in Client/Provider information,
- (2) monitoring unusual activity,
- (3) reviewing payment-related risks,
- (4) updating risk assessments,
- (5) conducting periodic due diligence reviews.
9.2 Monitoring of Clients
Xtrari monitors Clients for:
- (a) significant changes in ownership or control,
- (b) changes in business activities,
- (c) unusual Provider engagement patterns,
- (d) unexpected increases in payment volumes or unusual payment instructions,
- (e) inconsistencies between expected and actual activity.
Clients may be required to provide updated documentation periodically or upon request.
9.3 Monitoring of Provider Relationships
Xtrari may monitor Provider-related activities (subcontractor) to identify risks including:
- (a) identity fraud or impersonation,
- (b) changes in business activities,
- (c) fraudulent payment instructions or unusual payment changes,
- (d) suspicious use of Provider arrangements.
Xtrari information may be reviewed where:
- (1) payment details change,
- (2) risk indicators arise,
- (3) compliance requirements require verification.
9.4 Record of Monitoring Activities
Xtrari maintains appropriate records of customer reviews, risk assessments, screening results, EDD measures, compliance decisions, or escalation outcomes. Records are maintained in accordance with applicable legal requirements and internal retention policies.
10. Suspicious Activity Identification and Reporting
10.1 General Principles
Xtrari maintains procedures designed to identify, assess, escalate and appropriately respond to potential money laundering, terrorist financing, sanctions violations, fraud and other financial crime risks.
Xtrari recognises that suspicious activity may not always involve large transactions or obvious criminal behaviour. Suspicious activity may arise from unusual patterns, inconsistent information, unexplained business arrangements or activities that do not align with the known purpose of the relationship.
All relevant personnel, contractors, service providers and representatives involved in Xtrari’s operations are expected to promptly escalate potential compliance concerns in accordance with internal procedures.
10.2 Indicators of Suspicious Activity
Potential indicators of suspicious activity may include, without limitation:
A Client: refusal or unwillingness to provide required KYB information, provision of false, misleading or inconsistent information, unexplained complexity in ownership structures, inability to identify UBO, use of nominee shareholders or directors without legitimate explanation, frequent changes in ownership or control, and unusual reluctance to explain business activities.
B Business Activity Indicators: business activities inconsistent with the Client profile, unclear commercial purpose for engaging Xtrari’s services, unusually complex arrangements, requests involving unnecessary intermediaries, and activities inconsistent with expected service requirements.
C Payment and Financial Indicators: unusual payment instructions, requests to make payments to unrelated third parties, frequent changes to payment destinations, unusual payment volumes, payment activity inconsistent with the stated business model.
D Provider-Related Indicators: verification concerns, multiple individuals appearing to use the same identity information, suspicious requests to change payment details, unusual locations or arrangements, or suspected fraudulent profiles.
10.3 Internal Escalation Procedures
Where suspicious activity or a compliance concern is identified:
- (1) The concern shall be reported internally to the person responsible for AML/CFT matters or, where applicable, the designated compliance function, which shall assess the available information and determine the appropriate next steps.
- (2) Additional information may be requested from relevant parties.
- (3) The relationship or activity may be restricted, suspended or subject to enhanced monitoring where appropriate.
- (4) Where required by applicable law, a report shall be submitted to the relevant competent authority.
Xtrari maintains procedures to ensure that compliance investigations are conducted confidentially and appropriately documented.
10.4 Suspicious Activity Reporting
Where Xtrari determines that activity gives rise to reasonable suspicion of money laundering, terrorist financing or other relevant financial crime, the Company shall consider whether reporting obligations apply under applicable law.
Reports shall be prepared and submitted by authorised persons in accordance with applicable regulatory requirements.
Xtrari maintains appropriate records of internal escalations, investigations conducted, decisions made, supporting documentation, and regulatory reports submitted, where applicable.
11. Prohibited Clients/Providers Activities and Business Relationships
Xtrari does not knowingly establish or maintain relationships involving activities that present unacceptable AML/CFT, sanctions, legal or reputational risks.
Xtrari may refuse onboarding, restrict services, suspend activities or terminate relationships where risks cannot be adequately managed.
Unless expressly approved following an enhanced compliance review, Xtrari does not provide services to Clients or engage Providers in connection with activities prohibited under its Terms of Service or applicable laws and regulations.
12. Record Keeping and Data Protection
12.1 Record Keeping Requirements
Xtrari maintains appropriate records relating to AML/CFT compliance activities.
Records may include:
- (a) KYB and KYC documentation,
- (b) verification records,
- (c) ownership information,
- (d) risk assessments,
- (e) screening results,
- (f) EDD documentation,
- (g) compliance decisions,
- (h) monitoring records,
- (i) suspicious activity investigations,
- (g) regulatory communications.
12.2 Retention Period
Records shall be retained for the period required by applicable laws and regulations.
Unless a longer period is required, Xtrari aims to retain relevant AML/CFT records for a minimum period consistent with FATF standards and applicable local requirements.
Records shall remain accessible for internal compliance reviews, audits, regulatory inspections, and law enforcement requests.
In the event of a lawful request or during a regulatory examination/audit, Xtrari can retrieve and provide the required records promptly.
13. Policy Review and Updates
Xtrari reviews this Policy periodically to ensure that it remains:
- (a) aligned with FATF recommendations,
- (b) appropriate for Xtrari business model,
- (c) consistent with applicable legal and regulatory requirements,
- (d) effective in managing identified risks.
14. Final Statement
Xtrari is committed to maintaining a robust and proportionate AML/CFT framework that supports responsible growth of its services while preventing misuse of its platform and services for financial crime purposes.
Through effective customer due diligence, risk-based controls, sanctions compliance, ongoing monitoring and appropriate governance, Xtrari seeks to maintain the highest standards of integrity, transparency and regulatory compliance.