Suspected fraud or account compromise
Report immediately to both:
- security@finzopark.org
- Binance or Bybit, through their respective official support channels
The division of responsibilities between FinzoPark, Binance, and Bybit, including the controls that FinzoPark operates independently.
FinzoPark-LEG-004 – AML, Sanctions and Financial Crime Policy · Effective 14 August 2026
Report immediately to both:
Questions, due diligence questionnaires and requests for the compliance pack, marked for the attention of the MLRO:
1.1FinzoPark is committed to ensuring that its Platform is not used to facilitate money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud or any other financial crime.
1.2This Policy applies to all employees, officers, contractors and agents of FinzoPark, to all Platform users, and to all commercial counterparties, introducers, affiliates and suppliers.
1.3It is a client-facing summary. The full internal policy, risk assessment, control matrix, and procedures are confidential and may be provided, where appropriate, to competent authorities, auditors, banking partners, Binance, and Bybit upon request and subject to applicable confidentiality obligations.
2.1FinzoPark operates a customer-facing trading interface integrated with the APIs and related infrastructure of Binance and Bybit. Depending on the applicable service arrangements, Binance and/or Bybit may provide underlying trading infrastructure, liquidity, execution, KYC/AML, and, where applicable, custody services. The allocation of financial crime responsibilities follows the respective roles, services, and contractual arrangements of FinzoPark, Binance, and Bybit.
| Control | Performed by Binance and Bybit | Performed by FinzoPark |
|---|---|---|
| Customer identification and verification (KYC) | Yes – identity, documents, biometric liveness, address and account-level verification | No – FinzoPark does not collect or hold identity documents or verification data |
| Customer due diligence, EDD, PEP and adverse media screening | Yes – at account level, on an ongoing basis | No, save for the counterparty due diligence in section 5 |
| Source of funds and source of wealth enquiry | Yes | No |
| Custody of, and controls over, client fiat and crypto-assets | Yes, where applicable | No – FinzoPark never holds or controls user assets |
| Transaction monitoring and blockchain analytics | Yes – across accounts and on-chain activity | Limited – behavioural and abuse monitoring of Platform usage only |
| Travel Rule information transmission | Yes | No |
| Suspicious transaction reporting to a financial intelligence unit | Yes, in respect of account and transaction activity | Yes, in respect of its own knowledge or suspicion, where a reporting obligation applies to FinzoPark |
| Sanctions and restricted-jurisdiction screening of Platform access | At account level | Yes – at interface access level, as described in section 4 |
| Marketing and promotional compliance | Own channels | Yes – for all FinzoPark channels |
2.2Reliance on Binance or Bybit for account-level controls does not reduce FinzoPark’s own accountability for the controls it operates, nor its duty to report any knowledge or suspicion of financial crime where a legal or regulatory obligation applies to FinzoPark.
2.3Where a banking partner, correspondent institution, regulator, Binance, or Bybit imposes a higher standard than this Policy, the higher standard shall apply.
3.1The Board approves this Policy, sets the financial crime risk appetite, and receives reporting on the effectiveness of the framework at least annually. A named member of senior management is accountable for financial crime compliance.
3.2A Compliance Officer and Money Laundering Reporting Officer (MLRO) is appointed with sufficient seniority, independence and resources, and with unrestricted access to records and systems. The MLRO assesses internal reports and makes external reports where required.
3.3A documented business-wide financial crime risk assessment is maintained and reviewed at least annually and whenever there is a material change to the business model, the arrangements with Binance or Bybit, the user base, the jurisdictions served, or the threat environment.
3.4No employee suffers detriment for reporting a suspicion in good faith. Confidential internal reporting and whistleblowing channels are maintained.
4.1FinzoPark maintains a Restricted Jurisdictions list, published on the Platform, covering jurisdictions subject to comprehensive sanctions, jurisdictions where FinzoPark is not permitted to offer the Platform, and jurisdictions excluded on a risk basis.
4.2Access controls include registration-time declarations, IP-based geolocation blocking, detection of VPN, proxy and anonymising infrastructure, device and behavioural signals, and blocking of access from restricted locations.
4.3Platform users, and all commercial counterparties, are screened against consolidated sanctions lists administered by the United Nations, European Union, the United States Office of Foreign Assets Control, the United Kingdom and other applicable authorities, at onboarding and on an ongoing automated basis against list updates.
4.4A positive or potential match results in the immediate suspension of platform access pending review, escalation to the MLRO, notification of Binance or Bybit where the relevant account relationship is affected, and reporting to the competent authority where required.
4.5Deliberate circumvention of geographic or sanctions controls is a material breach of the Terms of Use, results in permanent loss of access, and is reported.
5.1Due diligence is performed before onboarding any introducer, affiliate, marketing partner, payment provider or material supplier, covering ownership and control, beneficial owners, sanctions and adverse media screening, licensing status where relevant, and the integrity of the commercial arrangement.
5.2Introducer and affiliate arrangements are documented in writing, prohibit misleading or non-compliant promotion, prohibit the offering of unauthorised rebates or inducements, and are subject to periodic review and audit.
5.3Payments of commission or referral fees are made only to verified counterparties, in their own name, through traceable banking or on-chain rails, and never in cash.
6.2The Platform must not be used to engage in market abuse, including wash trading, spoofing, layering, ramping, insider dealing, or coordinated market manipulation. Such conduct is reported to Binance and Bybit, where relevant, and to competent authorities where required.
6.3FinzoPark does not accept payments from users in connection with trading and does not hold user assets. Any attempt to route funds through FinzoPark is refused and investigated.
7.1FinzoPark monitors Platform usage for indicators of abuse and financial crime, including: registration and login anomalies; device, IP and geolocation inconsistencies; use of anonymising infrastructure; clustering of profiles sharing devices, addresses or contact details; patterns consistent with account takeover, coercion or third-party control; automated or scripted abuse; and behaviour consistent with scam typologies affecting the user.
7.2Alerts are triaged, investigated, and documented within defined service levels. Outcomes may include requests for information, restriction or termination of Platform access, notification to Binance or Bybit, where relevant, and internal escalation to the MLRO.
7.3Monitoring at the Platform level supplements, and does not replace, the account-level transaction monitoring conducted by Binance and Bybit, where applicable.
8.1All employees must report internally, promptly and without conducting their own external enquiries, any knowledge or suspicion of money laundering, terrorist financing, sanctions breach, fraud or other financial crime.
8.2The MLRO assesses each internal report and, where a reporting obligation applies to FinzoPark, submits a report to the competent financial intelligence unit in the applicable jurisdiction within the required timeframe.
8.3FinzoPark cooperates fully with lawful requests from competent authorities and with requests from Binance or Bybit made in connection with their respective regulatory obligations, subject to applicable data protection laws and any legal restrictions on disclosure.
8.4Employees must not disclose to a user or any third party that a report has been made or is contemplated, or that an investigation is under way. Unauthorised disclosure may be a criminal offence.
9.1Screening results, access restriction decisions, internal reports, MLRO assessments, external reports, counterparty due diligence and related correspondence are retained for at least five (5) years from the date of the record or the end of the relationship, and for longer where required by law or by a competent authority.
9.2Records are held securely, are retrievable without undue delay, and are processed in accordance with the Privacy Policy.
10.1All staff receive financial crime and sanctions training at induction and at least annually, with enhanced role-specific training for support, operations, marketing and compliance staff, and briefings for the Board.
10.2Training covers applicable obligations, the division of responsibilities with Binance and Bybit, crypto-asset typologies, red flags, internal reporting duties, tipping-off prohibitions, and personal liability. Attendance and comprehension are recorded and tested.
11.1The framework is subject to independent review by internal audit or an external specialist at least annually, covering control design, operating effectiveness, screening calibration, alert quality, record keeping and training.
11.2Findings are reported to the Board with tracked remediation, owners and target dates. The MLRO produces an annual report on the operation and effectiveness of the framework.
11.3This Policy is reviewed at least annually and whenever there is a material change to applicable law, the business model, or the arrangements with Binance or Bybit.
12.1Users must provide accurate information, comply with all applicable information requests from Binance or Bybit, and must not attempt to circumvent any control described in this Policy.
12.2Questions, due diligence questionnaires, and requests for the compliance pack should be sent to [compliance@finzopark.org](mailto:compliance@finzopark.org), marked for the attention of the MLRO. Suspected fraud or account compromise should be reported immediately to [security@finzopark.org](mailto:security@finzopark.org) and, where relevant, to Binance or Bybit through their respective official support channels.
End of AML, Sanctions and Financial Crime Policy.