Legal & policy
Anti-Money Laundering (AML) Policy
Effective Date: June 5, 2026
This Anti-Money Laundering Policy (referred to below as "the Policy") sets out how Fairclough Palmer AG (referred to as "the Company") organises its governance, controls and staff obligations to stop its corporate structures, digital platforms and business relationships being used as a channel for money laundering, terrorist financing, proliferation financing, sanctions evasion, bribery, corruption, tax fraud or any related financial crime. The Policy binds the Company and every member of its subsidiary network, including EquityLink, the Group's founder and investor connection platform, together referred to as "the Group".
The obligations recorded here reach every subsidiary, product line, distribution channel and item of technology operated by the Group, and bind each director, officer, employee, secondee, contractor, introducer and any other person purporting to act on the Company's behalf.
LEGAL DOCUMENT: This Policy is binding on all persons interacting with Fairclough Palmer AG and forms part of the Company's regulatory and compliance framework. It should be read together with the Privacy Policy, the Terms & Conditions and the Risk Disclosure.
1. Policy Statement and Regulatory Commitment
The Company maintains a firm stance against money laundering, terrorist financing, proliferation financing, tax evasion, bribery and any attempt to circumvent international sanctions. The integrity of the financial system, the protection of client and investor funds and the long term standing of the Company each depend on the disciplined application of the controls described in this Policy.
The Company carries out its activities having regard to the Swiss Anti-Money Laundering Act, the Anti-Money Laundering Ordinance, the circulars and guidance issued by the Swiss Financial Market Supervisory Authority, the recommendations published by the Financial Action Task Force, the anti money laundering directives of the European Union where they have extraterritorial relevance, the sanctions frameworks maintained by the United Nations and the United States Office of Foreign Assets Control, and the domestic financial crime legislation of every country in which the Group onboards or services a counterparty.
This Policy is reviewed no less than once a year, and additionally whenever a material change in regulation, technology or the Group's operating model occurs, so that its controls remain proportionate to the risk the Group actually faces.
2. Risk Based Approach
The Company grades its financial crime controls according to risk rather than applying a single standard to every relationship. Each counterparty, transaction, product, distribution channel and geography is scored against documented risk indicators, and that score determines how much due diligence is carried out and how closely the relationship is monitored afterwards.
The scoring exercise has regard, among other things, to:
- the ownership structure of the counterparty, including any use of trusts, holding vehicles, nominee arrangements or layered corporate chains
- the geographic footprint of the counterparty and the origin of its wealth and funds, with additional scrutiny given to jurisdictions flagged as high risk by the Financial Action Task Force, the European Union or the Swiss Financial Market Supervisory Authority
- the specific product or feature being accessed, whether a convertible instrument, an equity participation, or an EquityLink subscription or VIP access add on
- whether the counterparty, or anyone connected to it, is a politically exposed person, a close associate of one, or a person subject to sanctions
- whether the transaction proposed makes economic sense given the counterparty's declared profile
Each counterparty receives a rating of low, medium or high risk. A high risk rating triggers mandatory enhanced due diligence and requires sign off from Senior Management before the relationship proceeds.
3. Customer Due Diligence, Business Due Diligence and Identity Verification
No relationship is opened and no transaction is processed until identity has been verified, beneficial ownership has been established and the source of funds has been assessed to a standard proportionate to the risk the counterparty presents.
3.1 Standard Due Diligence for Natural Persons
- confirmation of full legal name, date of birth, nationality and residential address against an independent government issued identity document
- a biometric liveness check confirming that the person presenting the document is its rightful holder
- a declaration of tax residency consistent with the Common Reporting Standard
- evidence of source of wealth and source of funds proportionate to the size and character of the intended investment
3.2 Business Due Diligence for Legal Entities
- confirmation of the entity's legal existence by reference to commercial registry extracts, incorporation certificates and constitutional documents
- identification and verification of every ultimate beneficial owner holding, directly or indirectly, 25% or more of the entity, together with any individual who exercises ultimate effective control regardless of formal shareholding
- identification of directors, authorised signatories and controlling officers
- an assessment of the entity's licensing position, regulatory standing and ownership chain across every relevant jurisdiction
- adverse media, sanctions and politically exposed person screening applied to every individual and entity within the ownership and control chain
3.3 Enhanced Due Diligence
Enhanced due diligence applies wherever elevated risk is identified, which includes without limitation:
- counterparties based in, or connected to, high risk or sanctioned jurisdictions
- politically exposed persons and their family members or close associates
- counterparties with complex, opaque or cross border ownership arrangements
- transactions that do not fit the counterparty's documented economic profile
Enhanced due diligence involves independent corroboration of source of wealth, further documentary proof of the origin of funds, heightened ongoing transaction monitoring and mandatory approval from Senior Management or Compliance before the relationship is onboarded or allowed to continue.
4. Technology Partner: Didit Global Verification Infrastructure
All identity, business and sanctions screening carried out by Fairclough Palmer AG runs through Didit, a specialist identity and compliance infrastructure provider connected to the Company's onboarding and monitoring systems by a secure application programming interface. Didit was chosen after a thorough vendor assessment covering regulatory coverage, data security, jurisdictional reach and the reliability of its underlying intelligence sources.
Through Didit, the Company has real time access to a consolidated global compliance database spanning more than 200 jurisdictions, drawing on official identity registries, corporate registries, consolidated international sanctions lists issued by the United Nations, the Office of Foreign Assets Control, the European Union, HM Treasury and the Swiss State Secretariat for Economic Affairs, politically exposed person inventories, regulatory watchlists and a continuously refreshed body of adverse media.
The Didit integration specifically gives Fairclough Palmer AG:
- Document Verification: machine learning authentication of passports, national identity cards and residence permits, checked forensically against templates from more than 200 issuing authorities
- Biometric and Liveness Checks: facial biometric matching and active liveness detection designed to defeat impersonation, deepfake and photo replay attempts
- Address Validation: independent confirmation of residential details against utility, banking and governmental data sources
- Business Verification: automated extraction and verification of entity records, beneficial ownership chains and director information from commercial registries worldwide
- Sanctions, Politically Exposed Person and Watchlist Screening: continuous real time screening of every counterparty against consolidated global sanctions lists, politically exposed person databases and law enforcement watchlists
- Adverse Media Monitoring: ongoing surveillance of structured and unstructured media in multiple languages to surface financial crime, fraud, regulatory or reputational concerns
- Continuous Re-screening: counterparties are re-screened automatically on an ongoing basis, and the Company is alerted to a new sanctions designation, a change in politically exposed person status, an adverse media event or a material change in corporate ownership as soon as it arises
The system is configured so that no counterparty can finish onboarding, increase their exposure or settle a transaction unless the relevant Didit result has been logged and reviewed within the Company's compliance workflow. Verification records, supporting documents and audit trails are kept in tamper evident form and made available to regulators, auditors and internal compliance staff on request.
Didit operates under contractual terms that mirror the Company's own standards for data protection, confidentiality and information security, including encryption of data in transit and at rest, role based access controls, operational practices aligned with recognised security frameworks, and full compliance with the Swiss Federal Act on Data Protection and the EU General Data Protection Regulation. Use of Didit supports, but does not replace, the independent judgement and ultimate compliance responsibility retained by the Company's Compliance function.
5. Sanctions, Politically Exposed Person and Watchlist Screening
Every prospective and existing counterparty, along with their beneficial owners, directors and authorised representatives, is screened at onboarding and on an ongoing basis against consolidated international sanctions lists maintained by the United Nations Security Council, the Swiss State Secretariat for Economic Affairs, the European Union, the United States Office of Foreign Assets Control, HM Treasury and any other applicable national authority.
Where a genuine match arises, the relationship is frozen immediately, no further transaction is processed, and the matter is escalated to the Compliance Officer for assessment and, where necessary, reporting to the competent authority. The Company never engages, under any circumstance, with sanctioned individuals, entities or jurisdictions, and never facilitates a transaction structured to work around an applicable sanctions regime.
6. Ongoing Monitoring and Transaction Surveillance
Every counterparty relationship is watched throughout its life, not only at the point of onboarding. Transactions are compared against the counterparty's documented profile, expected pattern of activity and assigned risk rating, and automated and manual surveillance is used to catch unusual patterns, structuring behaviour, unexplained third party flows or any departure from the economic rationale originally given for the relationship.
Refresh cycles run on a schedule set by risk rating. A high risk relationship is reviewed at least once a year, a medium risk relationship every two years and a low risk relationship every three years, in each case in addition to reviews triggered by a change in ownership, sanctions exposure, adverse media or transactional behaviour.
7. Governance and the Three Lines of Defence
The Company organises its financial crime controls around three distinct lines of defence. The first line consists of client facing and commercial staff who apply due diligence procedures at the point of onboarding and remain alert to red flags during the ordinary course of business. The second line consists of the Compliance function, which sets policy, monitors adherence, operates the screening infrastructure and provides advice to the first line. The third line consists of internal or external audit, which tests independently whether the first and second lines are functioning as intended.
Each line operates independently of the others in the exercise of its core responsibilities, and no member of the first line may override a decision taken by Compliance in respect of onboarding, screening or the filing of a report.
8. Role of the Compliance Officer and the Money Laundering Reporting Officer
Ultimate accountability for the Group's financial crime framework rests with the Board of Directors, which approves this Policy and reviews its effectiveness. Day to day responsibility is delegated to the Compliance Officer, who also acts as the Company's Money Laundering Reporting Officer, remains independent of commercial functions and reports directly to the Board on financial crime matters.
The Compliance Officer and Money Laundering Reporting Officer is responsible for keeping this Policy current, supervising the Didit integration and any other compliance technology, deciding whether an internal report warrants escalation to the authorities, carrying out periodic risk assessments across the Group, and confirming that staff receive training suited to their role at least once a year.
9. Tipping Off Prohibition
No director, officer, employee or contractor may disclose to a counterparty, or to any person outside the Compliance function, that an internal report has been made, that an enquiry is under way, or that a matter has been or may be referred to the Money Laundering Reporting Office Switzerland or another authority. This prohibition applies regardless of the relationship the discloser has with the counterparty and continues to apply after the person's engagement with the Company ends.
10. Suspicious Activity Reporting to MROS
Any person working for or with the Company who forms a suspicion of money laundering, terrorist financing, sanctions evasion or other financial crime must pass that suspicion to the Compliance Officer without delay and without alerting the counterparty. The Compliance Officer assesses the report, makes such further enquiries as are appropriate and, where a reasonable suspicion is confirmed, files a report with the Money Laundering Reporting Office Switzerland or the equivalent financial intelligence unit in the relevant jurisdiction.
A person who raises a concern in good faith is protected from retaliation, demotion, discrimination or any other adverse consequence connected with having made that report.
11. Record Keeping and Retention
Identity documents, due diligence findings, Didit screening outcomes, transaction records, internal escalations and reports filed with a competent authority are kept for at least ten years from the end of the business relationship or the date of the transaction concerned, whichever falls later, consistent with the Swiss Anti-Money Laundering Act and the Code of Obligations. Records are held in secure, tamper evident systems and are made available to regulators, auditors and law enforcement bodies as required by law.
12. Staff Training and Attestation
Every director, employee and relevant contractor completes structured training on money laundering, sanctions and wider financial crime at the start of their engagement and at recurring intervals thereafter. Training content is tailored to the individual's role and exposure to risk, and is refreshed to reflect regulatory developments, new typologies and updates to the controls run through Didit. Each individual signs an attestation confirming that training has been completed and understood, and that record forms part of their personnel file.
13. Correspondent and Payment Channel Controls
Funds moving to or from the Group pass exclusively through regulated banking and payment channels that have themselves been subject to due diligence covering their licensing status, ownership and history of financial crime controls. The Company does not accept funds routed through unregulated payment intermediaries, shell arrangements or channels that obscure the identity of the original payer, and reserves the right to reject or reverse a payment where the originating channel cannot be adequately identified.
14. Cash and Crypto Asset Restrictions
The Company does not accept cash in connection with any subscription, investment or fee arising from its activities, and does not accept payment in crypto assets, virtual currencies or other digital tokens through its platforms, including EquityLink. Any attempt to structure a payment so as to avoid the ordinary banking channel required by the Company is treated as a red flag warranting immediate escalation to the Compliance Officer.
15. Third Party Introducer Controls
Where a founder, issuer or investor reaches the Group through an introducer, the introducer is itself subject to due diligence covering its ownership, regulatory status and history before any referral fee is agreed or paid. The Company does not treat due diligence carried out by an introducer as a substitute for its own verification of the person introduced, and retains the right to decline an introduced relationship notwithstanding the introducer's own assurances.
16. EquityLink Onboarding of Founders, Issuers and Investors
A founder or issuer seeking to raise capital through EquityLink is subject to business due diligence before a profile is published, including verification of corporate existence, identification of beneficial owners and screening of directors and controllers. An investor seeking access to opportunities through EquityLink, whether under a standard subscription, a paid tier or the VIP access add on, is subject to identity verification and source of funds assessment before any introduction is arranged, and payment of a subscription or add on fee does not shorten or waive any element of that process.
Access to EquityLink is suspended immediately if a founder, issuer or investor fails to complete the verification required of them, provides information that cannot be corroborated, or is subsequently found to present a risk inconsistent with the Group's risk appetite.
17. Independent Audit and Testing
The effectiveness of the controls described in this Policy is tested by internal or external audit on a periodic basis, covering the accuracy of risk ratings, the completeness of due diligence files, the functioning of the Didit integration and the timeliness of escalations to the Compliance Officer. Findings are reported to the Board, and any deficiency identified is remediated within a timeframe set by the Board having regard to the severity of the issue.
18. Breach and Disciplinary Consequences
A director, employee or contractor who fails to follow this Policy, who circumvents a control it establishes, or who fails to escalate a matter that ought reasonably to have been escalated, is subject to disciplinary action up to and including termination of engagement, and may additionally face personal liability where their conduct amounts to a criminal offence under Swiss law. A collaborator or introducer who breaches its obligations under this Policy is liable to have its arrangement with the Company terminated with immediate effect.
19. Refusal, Termination and Reservation of Rights
The Company may, at its sole discretion, decline to onboard a counterparty, refuse a transaction, suspend platform access or bring an existing relationship to an end where the required verification cannot be completed, where information supplied is incomplete or misleading, where the origin of funds cannot be evidenced, or where the relationship presents a level of financial crime, sanctions, reputational or regulatory risk the Company is unwilling to accept.
A decision of this kind may be taken without any obligation to explain the reasoning behind it, except to the extent disclosure is compelled by law.
20. Policy Review and Approval
This Policy is owned by the Compliance Officer and approved by the Board of Directors. It is formally reviewed no less than annually, and on an ad hoc basis whenever regulatory change, an audit finding or a material incident indicates that revision is warranted. Each version is dated and archived, and the version published on the Company's website at any given time is the version in force.
Compliance Contact
Fairclough Palmer AG — Compliance Office
Schifflände 26, 8001 Zürich, Switzerland
Email: Compliance@FaircloughPalmer.com
Contact Telephone: +41 (0) 44 505 33 47
Commercial Register Number: CHE-171.548.749
