Anti-Money Laundering (AML) Policy

ANTI-MONEY LAUNDERING

AND COUNTER-TERRORIST FINANCING POLICY

INTRODUCTION

Pro Capital Art Ltd. (hereinafter - the “Company”, “We”, “Us”) is firmly committed to conducting its business in full compliance with all applicable laws and regulations of the United Kingdom relating to the prevention of money laundering and the financing of terrorism.

For the purposes of this Policy, money laundering is understood as any act or attempt to conceal, disguise, convert, transfer or otherwise deal with the proceeds of criminal conduct with the aim of giving such proceeds an appearance of legitimate origin. Criminals frequently seek to exploit financial services, trade in high-value goods and art, and other commercial structures to integrate illicit funds into the legitimate economy without the knowledge or suspicion of the businesses involved.

We recognise the elevated AML/CFT risks inherent in the trade of artworks, collectibles and antiques, and the heightened regulatory focus on this sector in the United Kingdom and internationally. Accordingly, the Company has adopted this Anti-Money Laundering and Counter-Terrorist Financing Policy (“Policy” or “AML/CFT Policy”) as an internal framework designed to:

  • protect the integrity of our operations;

  • preserve our commercial and reputational standing;

  • mitigate exposure to financial crime, sanctions breaches and regulatory penalties; and

  • evidence our commitment to a culture of compliance and transparency.

This Policy is intended to align with relevant UK legislation and regulatory expectations, including, where applicable, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the Proceeds of Crime Act 2002, the Terrorism Act 2000, the Sanctions and Anti-Money Laundering Act 2018, and other binding instruments, as well as with recognised international standards (such as FATF Recommendations and EU Directives).

This Policy:

  • sets out the obligations of the Company and its staff in relation to customer due diligence (“CDD”), Know Your Customer/Business (“KYC/KYB”), ongoing monitoring, record-keeping, reporting and escalation;

  • defines our internal risk-based approach to AML/CFT; and

  • establishes responsibilities and procedures for the identification, assessment and management of AML/CFT risks.

This Policy is mandatory for:

  • all employees and officers of the Company;

  • all individuals who manage, monitor or control Client operations;

  • contractors, consultants and any third parties acting on behalf of, or in the name of, the Company.

Any employee or associated person who breaches this Policy or knowingly allows others to do so may be subject to disciplinary measures (up to and including dismissal), contractual remedies and, where applicable, personal civil or criminal liability.

The Company reviews this Policy regularly to ensure that it remains accurate, effective and aligned with changes in applicable law, regulatory guidance and industry best practice.

By adhering to this AML/CFT Policy, the Company demonstrates its ongoing commitment to integrity, transparency and regulatory compliance within the UK legal framework.

1. COMPLIANCE OFFICER

1.1. Appointment

The Company shall appoint an AML/Compliance Officer (“Compliance Officer”) with appropriate seniority, authority, experience and independence to oversee the implementation and maintenance of this Policy.

Where a dedicated Compliance Officer has not yet been formally appointed, the Chief Executive Officer (CEO) of the Company shall temporarily assume the functions and responsibilities of the Compliance Officer.

1.2. Responsibilities

The Compliance Officer is responsible for, inter alia:

1.2.1. monitoring, assessing and ensuring the correct and effective implementation of this Policy, including the practices, measures, controls and procedures adopted by the Company;

1.2.2. reviewing this Policy at regular intervals, at least annually, and updating it when necessary to reflect changes in law, regulation or the Company’s risk profile;

1.2.3. ensuring consistent application of this Policy across all departments, functions and business lines of the Company;

1.2.4. receiving, documenting and assessing internal reports from employees in relation to knowledge, suspicion or reasonable grounds to suspect money laundering, terrorist financing or related criminal activity;

1.2.5. deciding, in accordance with applicable legal requirements, whether an internal suspicion should be escalated to the competent UK authority (e.g. the UK Financial Intelligence Unit (UKFIU) at the National Crime Agency) through a Suspicious Activity Report (SAR) or equivalent;

1.2.6. organising the collection, review and analysis of information in relation to unusual, complex or high-risk transactions, patterns or customer behaviours that may be indicative of money laundering or terrorist financing;

1.2.7. overseeing the design and implementation of AML/CFT training programmes for relevant staff;

1.2.8. ensuring appropriate record-keeping practices in line with UK statutory retention requirements.

1.3. Remediation and Escalation

Where the Compliance Officer identifies deficiencies, weaknesses or failures in the implementation of this Policy, including gaps in controls, training or monitoring, the Compliance Officer shall:

  • issue guidance or instructions for remedial action;

  • follow up to ensure that remediation is effectively implemented; and

  • where material, inform the CEO and, if necessary, senior management or the Board.

2. DUE DILIGENCE MEASURES

2.1. Circumstances Requiring Due Diligence

The Company applies customer due diligence (“CDD”) and KYC/KYB measures to both natural and legal persons in the following circumstances, at a minimum:

2.1.1. Upon establishment of a business relationship, including where a Client engages in repeated or ongoing transactions with the Company.

Business relationship means a business, commercial or professional relationship connected with the Company’s activities which is expected, at the time of establishment, to have an element of duration.

2.1.2. Where there is knowledge, suspicion or reasonable grounds to suspect that a User or transaction may involve money laundering, terrorist financing, sanctions evasion or other financial crime.

2.1.3. Where a transaction (or series of linked transactions) carried out through the Company equals or exceeds GBP 10,000 (or the equivalent in other assets or currencies), or is otherwise deemed high-risk based on the Company’s internal risk assessment.

2.2. CDD/KYC Measures

The Company applies the following due diligence measures in accordance with UK regulatory expectations:

2.2.1. Identification of the Customer (or a person involved in an occasional transaction) and verification of their identity on the basis of reliable, independent source documents, data or information, which may include electronic identification means and trusted digital verification services.

2.2.2. Identification and verification of any representative of the Customer (e.g. an individual authorised to act on behalf of a company) and verification of their authority to act (e.g. via power of attorney, board resolution, company mandate).

2.2.3. Identification of the beneficial owner(s) and, where necessary, taking reasonable measures to verify their identity so that the Company is satisfied it knows who the beneficial owner(s) are and understands the Customer’s ownership and control structure.

2.2.4. Understanding the purpose and intended nature of the business relationship, transaction or operation, and obtaining information relevant to the Customer’s business, source of funds and source of wealth as appropriate.

2.2.5. Determining whether the Customer or beneficial owner is a Politically Exposed Person (“PEP”), a family member of a PEP or a known close associate of a PEP, and applying enhanced measures where required.

2.2.6. Ongoing monitoring of the business relationship, including scrutiny of transactions undertaken to ensure that they are consistent with the Company’s knowledge of the Customer, their business and risk profile.

2.3. Scope and Depth of Screening

The exact scope and intensity of due diligence are determined using a risk-based approach. In all cases, the Company performs KYC/KYB on:

  • each Customer (natural or legal person);

  • any individual acting as a Representative of a Customer;

  • the Beneficial Owner(s) of a Customer;

  • any Customer or connected party identified as a PEP or linked to a PEP.

2.4. Information and Documentation Required

During the KYC procedure, each Customer must provide sufficient personal and/or corporate information and documents to enable the Company to:

  • establish the Customer’s identity;

  • build an appropriate risk profile; and

  • assess the AML/CFT risk associated with the proposed relationship (see Section 3).

This information is summarised in LIST (1) One below.

2.5. Use of Third-Party Tools

The Company may utilise reputable third-party KYC/KYB and blockchain analytics providers, such as Sum and Substance Ltd (SumSub), Chainalysis, or other equivalent services, in order to verify identity, screen sanctions and monitor transactions.

2.6. Internal Verification

The Company may also conduct manual or internal verification of information and forms submitted during the KYC process through its employees and authorised officers, including open-source checks, company registry searches and sanctions list checks.

2.7. Categorisation of Customers

The Company obtains all information necessary to be satisfied as to the identity of each new Customer and the purpose and intended nature of the relationship. The extent of information and documentation depends on the Customer type and risk level.

Accordingly, Customers are categorised as follows:

LIST (1) One - Customer Types and CDD Requirements

Natural Person vs Legal Entity

Low Risk

Natural Person - Low Risk

The Company shall obtain at least the following:

  • full legal name;

  • date of birth and residential address (and, where applicable, a national insurance number or tax identifier);

  • information documenting any right of representation where the individual acts on behalf of another person;

  • contact details, including email address and telephone number.

The Company will identify a natural person on the basis of one or more of the following valid, original documents (or certified copies where appropriate):

  • a valid passport;

  • a valid national identity card (where applicable);

  • a valid photocard driving licence;

  • other official government-issued photo ID acceptable under UK AML standards.

Documents must be supplied, preferably in colour, clearly legible, and must show the full document (no cropping of edges or key data).

Legal Entity - Low Risk

The Company shall obtain at least the following information and documents:

  • full legal name / registered name of the entity;

  • registered number and date of incorporation/registration;

  • names and positions of directors, partners, or members of the governing body, and their authority to represent the entity;

  • registered office address and principal place of business;

  • contact details (email, telephone);

  • an extract from the relevant company register (e.g. Companies House in the UK or equivalent foreign registry);

  • certificate of incorporation and, where available, certificate of good standing;

  • identification of individuals duly authorised to operate any account or act on behalf of the entity;

  • identification of beneficial owners of private companies or public companies that are not listed on a regulated market with equivalent transparency requirements;

  • details of any nominee shareholders acting for beneficial owners;

  • a brief economic profile of the company, including nature of business, main counterparties and expected transaction types/volumes.

Normal Risk

Natural Person - Normal Risk

In addition to the Low Risk requirements, the Company may request:

  • further information about the Customer’s identification and background;

  • more detailed information on the planned nature and purpose of the business relationship;

  • information on the source of funds and source of wealth of the Customer and, where relevant, their beneficial owner;

  • explanations of the economic rationale for planned or executed transactions;

  • any other information needed to decide whether to enter into or continue a business relationship;

  • confirmation of the Customer’s account(s) held with a credit institution in an EEA state or a third country applying standards equivalent to Directive (EU) 2015/849.

Legal Entity - Normal Risk

In addition to the Low Risk requirements, the Company may request:

  • additional information regarding the Customer entity and its beneficial owners;

  • more detailed description of the intended business relationship;

  • information on the source of funds and source of wealth of the Customer and its beneficial owners;

  • explanations of the economic rationale of planned or completed transactions;

  • any additional information needed to assess whether a relationship should be established or maintained.

Where an account or relationship has been opened but verification problems subsequently arise that cannot be resolved, the Company may terminate the relationship, close the account (if any) and, where lawful, return any funds to the original source.

High Risk

Natural Person - High Risk

For High-Risk Customers, the Company will obtain all documents required for Low and Normal Risk Customers, but:

  • may require certified true copies or notarised documents;

  • may request an autoportrait/selfie;

  • may arrange a telephone or video call to confirm identity;

  • will demand robust proofs of source of funds (e.g. bank statements, sale agreements, inheritance documents);

  • may require supporting documentation and, where necessary, apostilled documents.

The Company may also require that payments originate only from an account held in a credit or financial institution located in the UK, the EU or another jurisdiction with robust AML standards.

Legal Entity - High Risk

As an additional CDD measure, on a risk-sensitive basis, the Company may:

  • conduct enhanced searches in company registers and other official databases in the country of incorporation;

  • obtain confirmation that the entity is not being dissolved, liquidated or struck off and remains an active trading company;

  • request further documentation on ownership, governance and financials;

  • require autoportraits/selfies of authorised persons;

  • hold a video or telephone call with the appointed/authorised representative;

  • request detailed proofs of source of funds and source of wealth;

  • require notarisation and, where relevant, apostille of key KYC documents.

3. RISK LEVELS AND CATEGORIES

3.1. Risk Levels

The Company classifies AML/CFT risk into three levels, as indicated in LIST (2) Two.

LIST(2) Two - Risk Levels

RISK LEVEL RISK DESCRIPTION
Normal Customers who do not meet any of the criteria listed under “High” or “Extra High” risk categories.
High Customers whose profile, activity, geography or connections indicate significantly elevated AML/CFT risk.
Extra High Customers connected to financial crime, high-risk geography, PEPs or complex structures, as described below.

High Risk may include, for example:

  • Customers from high-risk or monitored jurisdictions;

  • local PEPs or persons associated with PEPs;

  • legal entities with activities associated with enhanced money-laundering risk;

  • entities registered in countries listed on the Company’s list of risk countries;

  • entities whose activities are insufficiently regulated or transparent;

  • representatives or beneficial owners who are local PEPs or their family members.

Extra High Risk may include, for example:

  • Customers suspected to be, or to have been, involved in financial offences or suspicious activities;

  • non-resident individuals whose residence or main activity is in a high-risk country;

  • legal entities whose representatives or beneficial owners are PEPs or their close associates;

  • entities registered outside the EEA, operating in sectors associated with high ML risk, or registered in low-tax or secrecy jurisdictions.

3.2. Risk by Customers, Countries and Transactions

Risk is further broken down by Customer risk, Country risk and Transaction risk.

LIST (3) Three - Risk by Customers

Suspicious facts (examples):

  • discrepancies or inconsistencies in submitted identification documents;

  • fictitious or non-existing persons;

  • suspected stolen identity;

  • forged or counterfeit ID documents;

  • previous financial crime or terrorist records;

  • being on a wanted list or subject to law enforcement action;

  • absence of a valid contact phone number or email;

  • invalid or expired documents;

  • discrepancies in corporate documents for legal entities.

Politically Exposed Persons (PEPs) - individuals entrusted with prominent public functions, including but not limited to:

  • head of state or government;

  • minister, deputy or assistant minister;

  • member of parliament or similar legislative body;

  • senior official of a political party;

  • member of a supreme court, court of auditors or central bank board;

  • ambassador, chargé d’affaires, high-ranking officer in the armed forces;

  • member of an administrative, management or supervisory body of a state-owned enterprise;

  • director, deputy director or member of the board (or equivalent) of an international organisation, excluding middle or junior officials.

LIST (4) Four - Risk by Countries

The below lists (as provided) distinguish between High--Risk Jurisdictions and Prohibited Jurisdictions. These lists are informed by, inter alia, assessments by the European Commission, the Financial Action Task Force (FATF) and relevant sanctions regimes (UN, EU, UK, US).

High-Risk Jurisdictions
(Countries identified by the European Commission and/or under increased monitoring by FATF)

  • Barbados

  • Burkina Faso

  • Cameroon

  • Cayman Islands

  • Croatia

  • Gibraltar

  • Jamaica

  • Jordan

  • Kenya

  • Mozambique

  • Namibia

  • Nigeria

  • Panama

  • Senegal

  • South Africa

  • Tanzania

  • Trinidad and Tobago

  • Uganda

  • Vanuatu

  • Vietnam

Other:

  • Algeria

  • Angola

  • Benin

  • East Timor (Timor-Leste)

  • Ethiopia

  • Eswatini

  • Federal State of Micronesia

  • India

  • Kiribati

  • Laos

  • Lesotho

  • Morocco

  • Montenegro

  • Oman

  • Papua New Guinea

  • Paraguay

  • Saint Lucia

  • Togo

Prohibited Jurisdictions
(Sanctioned or otherwise prohibited countries - UN/EU/UK/US - and certain high-risk jurisdictions identified by FATF)

  • Afghanistan

  • Belarus

  • Bosnia and Herzegovina

  • Burundi

  • Central African Republic

  • Democratic Republic of the Congo

  • Guatemala

  • Guinea

  • Guinea-Bissau

  • Haiti

  • Iran

  • Iraq

  • Lebanon

  • Libya

  • Mali

  • Moldova

  • Montenegro

  • Myanmar (Burma)

  • Nicaragua

  • Niger

  • North Korea (DPRK)

  • Russia

  • Serbia

  • Somalia

  • South Sudan

  • Sudan

  • Syria

  • Tunisia

  • Venezuela

  • Yemen

  • Zimbabwe

Other:

  • Abkhazia

  • Cambodia

  • Crimea (region of Ukraine)

  • Donetsk (region of Ukraine)

  • Federal Republic of Ambazonia

  • Gabon

  • Honduras

  • Kosovo

  • Luhansk (region of Ukraine)

  • Pakistan

  • South Ossetia

  • Tajikistan

  • Transnistria

  • Turkmenistan

3.3. Transaction Risk and Outstanding Transactions

The Company pays particular attention to outstanding or unusual transactions, including but not limited to:

3.3.1. large or complex transactions that do not match the Customer’s known source of funds or source of wealth;

3.3.2. payments executed via non-licensed or unregulated payment institutions, or structures designed to obscure origin or ownership.

Such transactions are subject to heightened scrutiny and may be escalated in accordance with Section 5 (Detection of Suspicious Transactions).

4. NOT ACCEPTABLE CUSTOMERS

4.1. Prohibited Business Relationships

The Company shall not establish or maintain a business relationship or carry out an occasional transaction with any Customer who falls into one or more of the following categories:

4.1.1. Shell banks - banks or similar institutions with no physical presence in any country and unaffiliated with a regulated financial group;

4.1.2. Customers resident or incorporated in jurisdictions that are banned under the Company’s internal policies or subject to comprehensive international sanctions;

4.1.3. Customers identified as being subject to the UK, EU, UN or other recognised international sanctions regimes, including but not limited to:

  • UK sanctions administered by the Office of Financial Sanctions Implementation (OFSI);

  • US sanctions administered by the Office of Foreign Assets Control (OFAC);

4.1.4. Customers in respect of whom the Company has knowledge, suspicion or reasonable grounds to suspect involvement in money laundering, terrorist financing or related financial crime;

4.1.5. any Customer whom the Company, in its sole discretion, considers to pose an unacceptably high AML/CFT or sanctions risk to its business or reputation;

4.1.6. any person or entity whose capital consists of bearer shares or other bearer securities to the extent of more than 10%.

4.2. Prohibited Jurisdictions

The Company will not accept as Customers persons or entities from Prohibited Jurisdictions (as set out in Table 4) and from other jurisdictions where the provision of the Company’s services would be contrary to local or UK law.

4.3. Licence/Permit Constraints

Persons or entities located in jurisdictions where a specific licence or permit is required to provide or receive the relevant services shall not be accepted as Customers unless the Company has obtained such licence or permit, or verified that no such requirement applies.

5. SUSPICIOUS TRANSACTIONS AND TRANSACTIONS WITH PEPs

5.1. Identification of Suspicious Transactions

Where the Company identifies an activity, transaction or pattern of behaviour whose characteristics are commonly associated with the use of criminal proceeds, terrorist financing or related offences, or where the Company has knowledge or suspicion that such activity constitutes money laundering, terrorist financing or an attempt thereof (a “Suspicious Transaction”), the Company shall act in accordance with UK law and this Policy.

5.2. Indicators of Suspicion

A Suspicious Transaction is often one that is inconsistent with a Customer’s known legitimate business, personal activities or declared profile, or diverges markedly from the normal transaction pattern for that type of account or business relationship.

5.3. PEP-Specific Measures

Where the Customer, a party to a transaction or their beneficial owner is a Politically Exposed Person, a family member of a PEP or a known close associate of a PEP, the Company applies additional, enhanced due diligence measures, including:

5.3.1. obtaining senior management approval prior to establishing or continuing a business relationship with such person;

5.3.2. taking appropriate measures to establish the source of wealth and source of funds used in the relationship or for occasional transactions;

5.3.3. applying enhanced ongoing monitoring of the business relationship proportionate to the elevated risk.

5.4. Former PEPs

Where a PEP no longer holds a prominent public function, the Company will, for at least 12 months, continue to treat the person as higher risk, taking into account residual risk factors. Enhanced measures may be relaxed only where the Company is satisfied that the risks associated with PEP status no longer apply.

6. REPORTING TO COMPETENT AUTHORITIES

6.1. Suspicious Activity Reporting

If, in the course of its economic or professional activities, the Company identifies an activity, transaction or circumstance that might indicate money laundering or terrorist financing, or if it has reason to suspect or knows that money laundering or terrorist financing is taking place or has been attempted, the Company shall:

  • escalate the matter immediately to the Compliance Officer; and

  • where appropriate, ensure that a Suspicious Activity Report (SAR) or equivalent is submitted to the competent UK authority (e.g. the UKFIU at the National Crime Agency) as soon as practicable, and in any event without undue delay.

6.2. Financial Sanctions

If, as a result of CDD measures or ongoing monitoring, the Company:

  • identifies a Customer, beneficial owner, representative or transaction as being a subject of financial sanctions; or

  • determines that a planned or executed transaction may violate applicable financial sanctions; or

  • cannot, after reasonable steps, rule out such a violation,

the Company shall immediately inform the competent authority (e.g. OFSI in the UK) and act in accordance with any instructions received, including freezing funds or suspending transactions where required.

6.3. Tipping-Off Prohibition

The Company, its employees and representatives are prohibited from disclosing to the Customer, beneficial owner, representative or any third party:

  • that a report has been or may be submitted to a competent authority;

  • that an investigation or criminal proceedings are contemplated or underway;

  • the content of any instructions or orders received from the relevant authorities.

Only after the competent authority’s instructions have been fully complied with may the Company, if appropriate and permissible, inform a Customer that certain restrictions have been placed on their account or assets.

7. RELIEF FROM LIABILITY

7.1. Provided that the Company and its employees act in good faith and in accordance with applicable UK AML/CFT legislation when:

  • refraining from executing a transaction or delaying it;

  • terminating a business relationship;

  • submitting a SAR or similar report to the competent authority;

the Company, its employees, representatives and any person acting on its behalf shall not be liable for losses or damages suffered by the Customer or any third party as a direct consequence of:

  • refusing or delaying to enter into, or execute, a transaction;

  • terminating a contract or business relationship;

  • any other protective action taken to comply with AML/CFT or sanctions obligations.

7.2. This exemption applies irrespective of whether the suspicion ultimately proves unfounded, provided the actions were taken honestly, without malice and in accordance with the law and this Policy.

If you have any questions regarding this AML/CFT Policy or require further clarification, please contact us by email at: info@procapitalart.com