1. Purpose and scope
TronnBank aims to identify, assess and manage financial-crime risk across onboarding, wallet activity, package activation, rewards and withdrawals. The policy applies to users, beneficial owners, authorised representatives, staff and relevant service providers.
2. Risk-based assessment
Risk may be assessed using customer type, jurisdiction, product, delivery channel, transaction behaviour, source of funds, sanctions exposure and blockchain analytics. Enhanced controls may apply where risk is higher.
3. Customer due diligence
Before or during a relationship, TronnBank may identify and verify the customer and, where applicable, beneficial owners and authorised representatives. The nature and purpose of the relationship may be recorded, and enhanced due diligence may be requested.
4. Sanctions, PEP and adverse-media screening
Users may be screened against applicable sanctions lists, politically exposed person information and credible adverse-media sources. A potential match can result in delay, enhanced review, rejection, restriction or reporting where required.
5. Transaction monitoring
Account and blockchain activity may be monitored for unusual patterns, structuring, rapid movement, use of high-risk services, inconsistent source information, multiple linked accounts or other indicators. Monitoring thresholds and models should be tested and reviewed.
6. Escalation and reporting
Suspicious activity should be escalated to the designated compliance function. Where legally required, reports may be submitted to the competent authority without notifying the affected person. Accounts or transactions may be held where permitted or required.
7. Record keeping
Identity, verification, risk-assessment, transaction, investigation and reporting records should be retained for the legally required period and protected against unauthorised access or alteration.
8. Governance and review
The programme should include a designated owner, independent oversight where appropriate, staff training, screening and monitoring controls, internal escalation, periodic testing and documented updates. FATF materials provide general international risk-based guidance; local law controls actual obligations.
Reference: FATF guidance on digital identity.

STAKE • EARN • GROW