YWO (MU) Ltd · Legal
AML Policy
Last Updated: May 2026
1. INTRODUCTION
YWO (MU) LTD (the “Company”) is incorporated and existing under the Laws of Mauritius with registration number 229766, and registered address Legacy Capital Co Ltd, 2 Floor, Suite 201, The Catalyst, Ebene, Republic of Mauritius.
The Company is an Investment Dealer (Full-Service Dealer, Excluding Underwriting) Licensee, regulated and authorized by the Financial Services Commission (“FSC”), Mauritius under the license number GB25205550.
This Policy is provided by the Company to assist Clients in understanding the procedures the Company follows to comply with the applicable anti-money laundering and counter-terrorist financing (“AML/CFT”) laws and regulations of Mauritius.
As part of our commitment to maintaining high ethical standards and adhering to all relevant legislation, the Company is obligated to prohibit, detect, and actively prevent money laundering (“ML”), terrorist financing (“TF”), and any activity facilitating criminal or illicit financial conduct.
1.1. Governance and Oversight
The Company’s Anti-Money Laundering and Counter-Terrorist Financing framework is overseen by the Board of Directors, which retains ultimate responsibility for ensuring compliance with applicable AML/CFT laws and regulations.
The Board appoints an Anti-Money Laundering Compliance Officer (“AMLCO”) with sufficient authority, independence, and access to information to effectively discharge AML/CFT responsibilities. Where required, the AMLCO may be supported by one or more Assistant AML Compliance Officers.
The roles, responsibilities, reporting lines, escalation procedures, and decision-making authorities of the Board of Directors, senior management, the AMLCO, and any Assistant AMLCOs are set out in detail in the Company’s AML Manual, which forms an integral part of the Company’s AML/CFT framework.
While the AMLCO is responsible for the implementation, oversight, and enforcement of the AML/CFT framework, final approval or rejection of higher-risk clients, including PEPs and complex structures, may require senior management or Board approval, as further detailed in the Company’s AML Manual.
1.2. Relationship Between AML Policy and AML Manual
This AML Policy sets out the high-level principles and standards adopted by the Company to prevent money laundering and terrorist financing.
The Company’s AML Manual provides the detailed internal procedures, controls, operational processes, reporting mechanisms, and staff responsibilities necessary to implement this, Policy.
In the event of any inconsistency between this Policy and the AML Manual, the provisions of the AML Manual shall prevail for internal operational and compliance purposes.
2. LEGISLATIVE BACKGROUND OF MONEY LAUNDERING Money Laundering is the process by which criminals attempt to hide and disguise the true origin and ownership of the proceeds of their criminal activities, thereby avoiding criminal prosecution, conviction and confiscation of the illegally obtained funds. The main money laundering stages are:
a) Placement: cash are placed into the financial system or retail economy or are smuggled out of the country. The aims of the launderer are to remove the cash from the location of acquisition so as to avoid detection from the authorities and to then transform it into other asset forms for example: travellers’ cheques or postal orders
b) Layering: is the first attempt at concealment or disguise of the source of the ownership of the funds by creating complex layers of financial transactions designed to disguise the audit trail and provide anonymity
c) Integration: the money is integrated into the legitimate economic and financial system and is assimilated with all other assets in the system. Integration of the "cleaned" money into the economy is accomplished by the launderer making it appear to have been legally earned
2.1. Money Laundering Offences
Under Mauritian law, any person who: -
a) Commits an offence under this part; or b) Disposes or otherwise deals with property subject to a forfeiture order shall,
on conviction, be liable to a fine not exceeding 2 million rupees and to penal servitude for a term not exceeding 10 years.
2.2. Terrorism Financing
Terrorist financing is the act of providing financial support to terrorists, terrorist acts, or terrorist organisations. The objective of AML/CFT measures on terrorist financing is to identify, trace, and disrupt the financial flows that enable such activities, regardless of whether the funds originate from legitimate or illegitimate sources.
2.3. Purpose
The prevention of money laundering and terrorist financing is of critical importance for the Company’s integrity and reputation, and it is the company’s main responsibility to identify, report and take measures against money laundering and financing terrorism. For this reason, in order for the Company to prevent the money laundering activities through its services, the following steps are followed:
a) Identifying and verifying the identity of all clients through reliable, independent documentation. b) Obtaining sufficient information to understand the purpose and intended nature of the business relationship. c) Conducting ongoing monitoring of client activity, including transactions, to identify unusual or suspicious patterns. d) Investigating and reporting suspicious transactions to the Mauritius FIU. e) Maintaining records for a minimum of seven (7) years. f) Ensuring staff are adequately trained on AML/CFT obligations.
3. COMPANY PROCEDURES
3.1. Client Risk Assessment
The Company conducts a comprehensive assessment of its business-wide exposure to Money Laundering and Terrorist Financing risks. This assessment considers the inherent risks associated with:
- the types of clients the Company attracts
- the products and services offered by the Company;
- the jurisdictions our clients are located in;
- the nature, volume, and complexity of transactions;
- the delivery channels used to onboard and service clients.
Through this assessment, the Company evaluates the likelihood and potential impact of ML/TF risks across its operations and implements appropriate mitigating controls to ensure ongoing compliance with applicable AML/CFT laws and regulations.
Risk factor 1: Our clients
The Company identifies the types of clients it serves and assesses whether any client category is known to present a higher risk of being used for money laundering activities, classifying clients by industry, size, and legal form (e.g., individual, trust, LLP, or limited company).
To identify and assess the types of clients the Company serves, we:
- consider whether any principals or key personnel have specialised knowledge of particular industries;
- review the Company’s website and promotional material for references to client industries or business activities;
- identify client types that may require senior management approval prior to onboarding.
The Company then assesses the ML/TF risk associated with each client type, taking into account characteristics known to be associated with higher-risk profiles or typologies used by money launderers.
Following the assessment, the Company identifies appropriate mitigating measures for each client category. These may include applying Enhanced Due Diligence (EDD), obtaining senior management approval prior to onboarding, or conducting more frequent updates of client due diligence information.
Risk factor 2: Products and services we provide The Company identifies all products and services it offers and assesses whether any of them could be used for money laundering or terrorist financing purposes. In doing so, the Company takes into consideration the specific activities it is authorised to provide under its FSC licence.
Once the Company has assessed the ML/TF risk associated with each product or service, it identifies the mitigating measures already in place or those that need to be implemented to effectively address the identified risks.
Risk factor 3: The countries that our clients reside/operate in
The Company identifies the jurisdictions in which its clients reside, are incorporated, operate, or from which they obtain their funding. This includes:
- the countries where clients are based or conduct their main business activities;
- the jurisdictions from which clients’ funds or wealth originate.
The Company then assesses the ML/TF risk associated with each jurisdiction. When evaluating geographic risk, the Company considers factors such as:
- the level of corruption or governance concerns within the jurisdiction;
- the presence of organised crime or known criminal activity;
- whether the jurisdiction is subject to sanctions, FATF listings, or other international restrictions;
- the effectiveness of the jurisdiction’s AML/CFT regulatory framework.
Risk factor 4: The transactions we are involved in
The Company identifies all types of transactions it facilitates and assesses the risk that these transactions may involve the proceeds of crime or be linked to terrorist financing.
The Company reviews the nature, size, frequency, and purpose of transactions conducted through clients’ accounts, and evaluates the ML/TF risk associated with each transaction type. Deposits and withdrawals processed by the Company’s Back Office Department may also present risks if used to support criminal activity or to execute illegal transfers.
The Company documents its assessment of transactional risks and identifies the controls and mitigating measures necessary to address these risks.
Risk factor 5: Delivery channels
The Company identifies all the methods of interaction it has with its clients. Some delivery channels can increase risk because they can make it more difficult to determine the identity of a client.
Factors to consider are:
a) whether we meet our clients face-to-face; b) whether our clients are introduced through an intermediary and whether the Company only corresponds with that intermediary; c) the extent to which the Company relies on the Client Due Diligence (hereinafter referred to as “CDD”) of the referrer or intermediary (and the procedures we employ to justify reliance) or the quality of evidence obtained from them to support our own CDD.
3.2. Identification Procedures
The Company is under an obligation to confirm and verify the identity of each customer when establishing a business relationship with the Company. Documents are request for each of the below categories of clients:
3.2.1. Individual Clients
The following types of identity verification are acceptable:
a) Current valid passport; or b) Current valid driving license; or c) National identity card
Proof of Identity core characteristics:
- If the proof of Identity has expired – is not accepted
- Proof of Identity must always bear a client’s photo in adult age
- Both sides of the Proof of Identity need to be provided
- All Sides of the Document to be visible (not cropped)
- Date and place of birth
- Unique Personal identification number must be visible
- The Driving license needs to be issued by a Government/Public authority
The following types of Proof of address are acceptable:
a) Utility bills (electricity, water, gas, landline) b) Bank statements
These documents must:
- display the client’s full name and full residential address
- be issued within the last 3 months
Mobile phone bills and P.O Box addresses are not acceptable.
The Company does not accept the same document as both proof of identity and proof of address; separate and independent documents must be provided for each requirement.
Form of Documents
For non-face-to-face onboarding, the Company accepts high-resolution electronic copies of documents, which are subjected to electronic verification, including checks for authenticity, metadata analysis, fraud patterns, and digital consistency. In addition, the Company performs a liveness verification, requiring clients to complete a real-time selfie or biometric check to confirm that the person presenting the documents is the genuine holder.
Where the Company determines that additional verification is required, certified true copies may be requested, certified by a lawyer, notary, accountant, or a member of a recognised professional body.
3.2.2. Legal Entities
For legal entities, the Company collects sufficient information and documentation to establish and verify the client’s legal existence, ownership, control structure, and authorised representatives.
Limited Liability Companies
The Company requires the following:
a) Certificate of Incorporation
b) Certificate of Good Standing
c) Certificate of Registered Office
d) Certificate of Directors, Secretary, and Shareholders or a Certificate of Incumbency
e) Memorandum and Articles of Association
f) Ownership/Group Structure Chart, if applicable
g) Proof of Operating Address
h) Latest audited financial statements, management accounts, or recent bank statement
For each natural person authorised representative, director, shareholder and Beneficial Owner: individual KYC requirements apply.
For each corporate director or corporate shareholder: full corporate KYC as listed above from points (b) to (g) are required.
Regulated Entities
In addition to the documents required for limited liability companies, regulated entities must also provide:
a) A copy of their licence or authorisation issued by the relevant supervisory authority – if same is not publicly available.
Public Listed Companies
For publicly listed entities, the Company obtains:
a) Proof of listing (exchange website extract, reputable registry, or newspaper listing)
b) Corporate documents necessary to identify directors, authorised signatories, and ownership
c) Completed Corporate Application Form
Trusts For trusts, the Company requires:
a) Trust Due Diligence Form
b) Trust Deed (including schedule of assets and governance provisions)
c) Certificate of Registration
d) Latest financial statements or asset statement
e) List of authorised signatories
For all trustees, settlors, beneficiaries, and protectors: individual or corporate KYC applies, depending on their legal form.
Certification and Verification of Corporate Documents
The corporate documents must be submitted either as original documents or certified true copies, certified by a lawyer, notary, accountant, or another recognised professional. However, where documents can be verified directly through an official government registry, corporate affairs commission, or equivalent online portal of the jurisdiction of incorporation, such documents shall be deemed original, and no certification will be required. The Company reserves the right to request certified copies or additional verification where Enhanced Due Diligence is necessary or where the authenticity of documents cannot be reliably confirmed.
3.3. Screening Procedure
The Company utilises automated and manual screening and monitoring tools to identify sanctioned persons, politically exposed persons (“PEPs”), adverse media, and other higher-risk indicators, both at onboarding and on an ongoing basis.
The frequency, scope, and calibration of client screening, transaction monitoring, and periodic re-screening are determined based on the client’s risk classification and are documented in the Company’s AML Manual.
The Company may utilise third-party electronic verification and screening service providers, as further detailed in the AML Manual.
4. ENHANCED DUE DILIGENCE
The Company applies Enhanced Due Diligence (“EDD”) in situations where a higher risk of money laundering or terrorist financing has been identified. EDD measures may include obtaining additional information on the client’s identity, source of funds and wealth, intended account activity, and beneficial ownership, as well as conducting more frequent reviews and enhanced ongoing monitoring. EDD is applied particularly to high-risk clients, PEPs, complex ownership structures, high-risk jurisdictions, and any situation where the nature or pattern of transactions raises concerns.
5. POLITICAL EXPOSED PERSONS
Where the Company knows or has reasonable grounds to believe that a client or a beneficial owner of a client, residing in or outside Mauritius is or becomes a politically exposed person, the Company shall apply, enhanced due diligence measures and enhanced ongoing monitoring.
The meaning of Politically Exposed Persons (“PEP”) includes the following natural persons who are or who have been entrusted with prominent public functions:
a) a foreign politically exposed person;
b) a domestic politically exposed person; or
c) who is, or has been, entrusted with a prominent function by an international organisation.
The following are immediate family members of a politically exposed person:
a) a spouse;
b) a partner;
c) children and their spouses or partners;
d) parents;
e) grandparents and grandchildren; and
f) siblings.
The following are close associates of a politically exposed person:
a) an individual who is closely connected to a PEP, either socially or professionally; and b) any other person as may be specified by a supervisory authority or regulatory body after consultation with the National Committee Procedure when dealing with a Political Exposed Person:
The data and information that are used for the construction of the identification and due diligence of a political exposed person shall include, the following:
a) verification documents (please refer to the Identification Procedures of this Policy, for individuals) b) take reasonable measures to establish the person’s source of funds and wealth c) ensure that the person completes the “PEP declaration Form” of the Company d) obtain the approval of senior management before establishing a business relationship with a PEP or family member or close associate of the PEP
6. ON-GOING MONITORING OF TRANSACTIONS
The Company conducts ongoing monitoring of client transactions to identify activity that may be unusual or inconsistent with the client’s known profile, expected behaviour, or declared business activities. A transaction may be considered suspicious if it deviates from the client’s economic profile or displays characteristics associated with money laundering, terrorist financing, proliferation financing, corruption, or any other criminal activity.
Monitoring includes reviewing changes in clients’ financial behaviour, the nature and frequency of transactions, and any patterns that may suggest heightened risk or lack of economic rationale. The Company ensures it maintains sufficient and up-to-date information on each client to recognise unusual or suspicious activity in a timely manner.
Where suspicious transactions or patterns are detected, the Company is required to report them to the relevant Authorities and must not inform the client that such a report has been or may be made (“tipping-off”). Any misuse of an account may result in regulatory or criminal consequences.
Suspicious activities are escalated initially internally through documented reporting procedures before any external disclosure, as detailed in the AML Manual.
7. RESTRICTED COUNTRIES
The Company does not provide services to residents or entities from certain jurisdictions, including but not limited to countries that are subject to international sanctions, European Union (EU), United States (U.S), or those listed on the FATF High Risk Countries. The Company may also restrict or prohibit services to jurisdictions that it considers to present a higher-than-normal ML/TF risk based on its internal risk assessment, regulatory guidance, or emerging geopolitical developments. The list of restricted countries may be updated at any time in accordance with the Company’s risk appetite and applicable legal or regulatory obligations.
8. RETENTION AND UPDATING OF RECORDS
The Company maintains all records related to client onboarding, verification, account activity, and transactions in accordance with applicable AML/CFT legislation. Customer identification data and transaction records are securely stored for a minimum of seven (7) years from the date of each transaction and for seven (7) years after the termination of the business relationship. Records must remain readily accessible to support regulatory inquiries, reviews, or investigations.
9. TEST OF THE AML POLICY
The Company ensures that its AML/CFT framework is subject to ongoing internal reviews and, where required by regulation or risk assessment, independent external audits, as further described in the AML Manual.
