KYC and AML/CTF policy
Identity checks, risk assessment and transaction monitoring help prevent misuse of financial services and support Australian anti-money laundering and counter-terrorism financing obligations.
1. Purpose of this policy
Know Your Customer (KYC) and anti-money laundering and counter-terrorism financing (AML/CTF) procedures help identify customers, understand relevant risk and detect activity that may involve fraud or other unlawful conduct. They also protect users from some forms of account takeover and impersonation.
The checks applied depend on the actual service, provider, customer and risk indicators. This policy is a general description and does not replace the obligations of the legal entity providing execution, custody or payment services.
2. What KYC means
KYC is the process of collecting identifying information and taking reasonable steps to verify that it is accurate. For an individual this commonly includes legal name, date of birth, residential address and contact details.
Verification may compare submitted information with a government-issued document and reliable electronic sources. A successful check confirms selected attributes; it is not a judgement about investment knowledge or suitability.
3. What AML/CTF means
AML/CTF controls are intended to reduce the risk that services are used to disguise criminal proceeds, finance prohibited activity or evade legal requirements. They include customer risk assessment, sanctions and politically exposed person screening where applicable, transaction monitoring and escalation of unusual activity.
Not every unusual transaction is unlawful. A review examines context and may seek an explanation or supporting evidence before a decision is made.
4. Why identity verification is required
Identity verification supports compliance with applicable Australian law, prevents duplicate or fictitious accounts, protects payment destinations and makes it harder for another person to use stolen details. It can also assist recovery when access is lost.
Users cannot opt out where a check is required for a service. Refusal to provide necessary information may prevent activation, funding, trading or withdrawal.
5. Documents and information
Depending on the provider process, a user may be asked for a current Australian passport or driver licence, plus a bank statement, utility notice or government correspondence showing residential address. The document must be legible, current and belong to the applicant.
A live image, selfie or short liveness step may be requested where the verification provider uses it to compare the applicant with the identity document. Additional evidence can include source-of-funds or source-of-wealth information when risk or transaction activity justifies it.
Only submit documents through the approved secure channel. Do not send passwords, private keys, recovery phrases or one-time codes.
6. Verification process
- Registration: the user supplies basic contact and identity information.
- Documents: required evidence is uploaded through the designated secure process.
- Automated checks: information may be checked for validity, consistency and screening matches.
- Manual review: trained staff assess unresolved results or higher-risk circumstances.
- Outcome: the user is informed whether verification is complete, more information is needed or access cannot be provided.
Approval in one context does not prevent a later review when information expires, the service changes or new risk information arises.
7. Enhanced due diligence
Enhanced due diligence may apply where the customer, jurisdiction, ownership structure, payment pattern, occupation, public role or other factor indicates higher risk. It is a deeper review, not an allegation of wrongdoing.
Additional information may include the purpose of the account, employment or business activity, beneficial ownership, source of funds, source of wealth and evidence supporting an intended transaction. Certain functions may remain limited while review is incomplete.
8. Verification time
Many straightforward electronic checks can be completed promptly, but no universal time is promised. Image quality, expired documents, name differences, address history, screening similarities and the need for provider or manual review can extend the process.
Submitting repeated or inconsistent applications can create further delay. Respond through the verified channel and provide only the information requested.
9. Rejection or suspension
A check can be rejected or paused if a document is expired, altered, unreadable or unsupported; information does not match; identity cannot be established; required evidence is not provided; or fraud, sanctions or other material risk concerns remain unresolved.
Legal or security obligations can limit the detail that may be given about a decision. Where possible, the user will be told whether corrected information can be submitted.
10. Transaction monitoring
Where applicable, transactions are reviewed using risk rules and contextual information. Relevant indicators can include unexpected size or frequency, rapid movement through an account, unrelated third-party payments, unusual destinations or behaviour inconsistent with the account purpose.
A review may delay a payment, restrict a function or request documents. Matters can be escalated internally or reported to an authorised body when required by law; the user may not be notified where disclosure is prohibited.
11. User responsibilities
Users must provide accurate, current and genuine information, use an account only for lawful purposes and update material changes. An account must not be opened or operated for another person unless a formally approved arrangement applies.
False documents, concealed ownership or misleading explanations can lead to restriction, closure, rejection of a transaction and referral to the appropriate authority. Users remain responsible for securing their login and payment methods.
12. Storage and protection
KYC and AML/CTF records are protected through technical and organisational controls, including restricted access, logging and secure transfer. Information is retained for the period required by applicable law and legitimate operational needs.
The Privacy Policy explains categories, purposes, disclosures, retention and individual rights. Some deletion requests cannot be completed immediately where a legal retention duty applies.
13. Data recipients
Information may be shared with the executing or account provider, specialist identity-verification and screening providers, secure hosting or IT services, related entities performing an approved function, professional advisers, regulators, AUSTRAC, law-enforcement or other public authorities where authorised or required.
Recipients receive only information relevant to their function and are subject to legal, contractual or professional duties. Personal information is not sold as a verification product.
14. Australian requirements
Australia's AML/CTF framework is administered by AUSTRAC and can apply to designated services. The precise enrolment, registration, programme and reporting duties depend on the service and the entity providing it.
This website does not invent an AUSTRAC registration for Corvenhall Trust. Users should confirm the named provider and applicable records before funding an account. Privacy handling also remains subject to Australian privacy requirements where they apply.
15. Contact and support
Questions about verification, a request for documents or an account restriction can be sent to [email protected]. Include your name, a safe contact method and the relevant case reference, but do not attach sensitive documents until the approved channel is confirmed.
Support cannot waive a mandatory check or disclose a confidential monitoring rule. It can explain the process, identify outstanding information and record a complaint if you believe the matter has been handled incorrectly.