AML/CFT Policy

Regulatory Status 

MDF AG is a Swiss financial intermediary under Art. 2(3) of the Swiss Anti-Money Laundering Act (AMLA) and a member of SO-FIT, a FINMA-recognised self-regulatory organisation (SRO). MDF operates under a risk-based AML/CTF compliance framework aligned with SO-FIT’s regulatory requirements for Virtual Asset Service Providers (VASPs), including SO-FIT Directive 15 (Swiss substance, AML Officer access rights, and VASP-specific monitoring standards). 

Governance 

Compliance is organised around a “three lines of defence” model: 

  • Board of Directors — sets overall AML/CTF risk appetite, approves the policy, and oversees implementation. 
  • Executive Committee — implements the policy and decides on onboarding, continuation, and termination of business relationships and on regulatory notifications. 
  • AML Officer — an independent compliance function with full access to all AML-relevant systems and data, at least three years of VASP-sector AML experience, and a direct reporting line to both the Executive Committee and the Board. 
  • First-line staff — perform initial onboarding checks and day-to-day KYC review ahead of AML Officer sign-off. 

An independent external auditor reviews the AML/CTF programme at least annually, covering customer due diligence, transaction monitoring, sanctions screening, and record-keeping, with findings reported to the Board. 

Customer Due Diligence (KYC/KYB) 

Before any business relationship is established, MDF identifies and verifies customers through in-person, correspondence, video, or online identification methods that meet Swiss regulatory standards (FINMA Circular 2016/7), including document authentication, biometric/liveness checks, and proof of address. Legal entities are identified through commercial-register documentation and identification of their beneficial owners and controlling persons. 

Every customer and beneficial owner is screened against sanctions and politically-exposed-person (PEP) lists at onboarding and on an ongoing basis. Sanctioned individuals, PEPs, and customers presenting money-laundering or terrorism-financing indicators are not onboarded. 

Each business relationship is risk-classified using a documented set of factors — including jurisdictional exposure, business sector, and ownership-structure complexity — with higher-risk relationships subject to enhanced due diligence, more frequent review, and senior management approval. Country and sector risk is assessed against recognised external sources (FATF lists, EU sanctions/high-risk-third-country lists, and internationally recognised governance and corruption indices). 

Ongoing Monitoring 

Business relationships and transactions are monitored on a continuous, risk-based basis for both fiat and virtual-asset activity. For Virtual Assets specifically, MDF applies additional VASP-specific controls: 

  • Verification that a customer controls any external wallet used for deposits or withdrawals (“proof of control”), re-verified periodically based on risk classification. 
  • Automated blockchain analytics on all incoming and outgoing Virtual Asset transactions to screen for sanctioned addresses, illicit-activity exposure, and other risk indicators, with escalation to enhanced due diligence or investigation where warranted. 
  • Compliance with the FATF Travel Rule for originator/beneficiary information exchange between virtual asset service providers. 
  • Automated controls that prevent execution of transactions flagged as high-risk pending compliance review. 
  • Customer assets are held in institutional-grade, multi-approval custody infrastructure rather than under unilateral internal control, and the same monitoring and Travel Rule standards apply regardless of custody venue. 
  • Privacy coins, mixing/anonymisation services, and similar higher-risk instruments are not supported. 

Sanctions Compliance 

Customers and beneficial owners are screened against Swiss (SECO), EU, and US (OFAC) sanctions lists at onboarding and on an ongoing automated basis. Confirmed matches trigger immediate escalation, asset freezing, and regulatory notification in line with Swiss law. 

Prohibited Activity 

MDF does not onboard or transact for entities subject to comprehensive international sanctions or FATF blacklisting, shell banks, or higher-risk sectors such as unlicensed gambling, adult entertainment, or darknet marketplaces. Structuring transactions to evade due-diligence thresholds and cross-border transfers without full Travel Rule data are expressly prohibited. 

Reporting & Record-Keeping 

Where MDF knows or has reasonable grounds to suspect money laundering, terrorist financing, or sanctions violations, it is legally required to notify Switzerland’s Money Laundering Reporting Office (MROS) and to freeze the relevant assets. Records supporting compliance with AML/CTF obligations are retained for ten years in secure, Switzerland-based, encrypted storage. 

Training 

All employees in AML-relevant roles complete mandatory onboarding and annual refresher training on anti-money laundering, counter-terrorism-financing, and sanctions compliance.