Anti-Money Laundering and Know Your Customer Policy
Coild Ltd
Effective 26 August 2026 · Reviewed annually and on material change · Owner: Money Laundering Reporting Officer · Approved by the Board of Directors
1. About this policy
Coild Ltd is a private limited company incorporated in England and Wales under company number 16955836, with its registered office at 50 Princes Street, Ipswich, England, IP1 1RJ.
This policy sets out the principles by which Coild identifies, assesses and manages the risk that its services could be used for money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud or other financial crime. It applies to every director, officer, employee, contractor, agent and representative of Coild, and to every customer, counterparty and transaction.
This document is a public summary. Coild maintains a separate, confidential set of internal policies, controls and procedures which give operational effect to the principles below. Those documents are made available to our supervisors, auditors, banking partners and law enforcement on request, and are not published. Coild does not disclose its monitoring rules, detection scenarios, thresholds, screening parameters, risk-scoring weightings or investigative methods to any party who does not have a legitimate need to know them.
2. Our commitment
Coild does not tolerate the use of its services for criminal purposes. We apply controls that are proportionate to the risks we face, and we apply them consistently. Where we cannot manage a risk to our own satisfaction, we decline the relationship.
Our framework is built against the requirements and standards set out in:
- the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended, including by the Money Laundering and Terrorist Financing (Amendment) Regulations 2026
- the Proceeds of Crime Act 2002, including the principal money laundering offences, the obligation to disclose, and the offences of tipping off and prejudicing an investigation
- the Terrorism Act 2000
- the Sanctions and Anti-Money Laundering Act 2018 and the financial sanctions regimes made under it
- the Criminal Finances Act 2017, including the corporate offences of failing to prevent the facilitation of tax evasion
- the Economic Crime and Corporate Transparency Act 2023, including the corporate offence of failing to prevent fraud
- the Data Protection Act 2018 and the UK GDPR
- the Recommendations of the Financial Action Task Force and the findings of the UK National Risk Assessment
Where Coild operates in or serves customers from other jurisdictions, applicable local requirements apply in addition to the above.
3. Governance
Responsibility for financial crime risk sits with the Board of Directors, which approves this policy and the underlying internal framework, sets risk appetite, and receives regular reporting on its operation.
A Money Laundering Reporting Officer is appointed and is the point to whom all internal reports of knowledge or suspicion are made. The MLRO decides whether a disclosure is made to the relevant authorities, and has direct and unrestricted access to the Board. A Deputy is appointed to act in the MLRO's absence. A named member of senior management holds accountability for compliance with the applicable anti-money laundering regime.
Coild operates a three-lines-of-defence model: risk ownership within the business, independent oversight by Compliance, and independent assurance over both.
All personnel whose duties relate to financial crime compliance are screened before appointment and periodically thereafter for competence, conduct and integrity.
4. Risk-based approach
Coild maintains a documented, Board-approved assessment of the money laundering, terrorist financing and proliferation financing risks arising from its customers, the jurisdictions to which it is exposed, its products and services, its transaction types and its delivery channels. The assessment is reviewed at least annually and whenever the business, its markets or the external risk environment change materially.
Controls are calibrated to assessed risk. Higher risk attracts greater scrutiny; lower risk attracts proportionately less. A risk-based approach never permits due diligence to be omitted altogether.
5. Know Your Customer and due diligence
Coild verifies the identity of every customer before establishing a business relationship, and re-verifies where circumstances require it.
For individuals we establish and verify identity from reliable and independent sources. For legal entities we establish and verify the identity and legal existence of the entity, understand its ownership and control structure, and identify and take reasonable measures to verify its beneficial owners. Where the customer's structure is layered, offshore, held through nominees or otherwise opaque, we require it to be explained and evidenced to our satisfaction before proceeding.
We establish the purpose and intended nature of every business relationship, and we obtain evidence of the source of funds and, where risk requires, the source of wealth. These are treated as distinct questions: the origin of the money used, and the origin of the customer's accumulated assets. Assertion alone is not evidence.
Where Coild engages third-party providers to support verification, screening or monitoring, legal and regulatory responsibility for compliance remains with Coild in every case. Providers are subject to due diligence before appointment and to ongoing oversight.
Where due diligence cannot be completed, Coild will not establish the relationship, will not carry out the transaction, and will terminate any existing relationship. We will consider whether the circumstances require a disclosure to the authorities. Where a disclosure has been made, we may be prohibited by law from proceeding, from explaining our reasons, and from confirming or denying that any report exists.
6. Higher-risk relationships
Coild accepts customers and sectors that carry elevated financial crime risk. We do not de-risk indiscriminately, and we do not exit entire categories of customer simply because they are difficult. What we require is that elevated risk is identified before onboarding, is approved at the appropriate level of seniority, is subject to enhanced due diligence and enhanced ongoing scrutiny, and is documented so that the basis for the decision can be reconstructed and defended at any point afterwards.
Enhanced due diligence is applied where the customer or transaction is connected to a jurisdiction on the FATF list of High-Risk Jurisdictions subject to a Call for Action; where the customer is a politically exposed person, or a family member or known close associate of one; where a transaction is unusually complex or unusually large given its nature, follows an unusual pattern, or has no apparent economic or lawful purpose; where the relationship falls within Schedule C to this policy; and in any other case where our own risk assessment identifies a heightened risk.
Politically exposed persons are not excluded. PEP status is a risk factor, not a disqualification, and it is assessed proportionately. Relationships involving a PEP require senior management approval before they are established or continued, evidence of source of wealth and source of funds, and enhanced ongoing monitoring.
7. Prohibited jurisdictions
Coild does not establish or maintain relationships with, provide services to, or process transactions to or from the jurisdictions and territories listed in Schedule A. Jurisdictions subject to elevated scrutiny rather than prohibition are listed in Schedule A2.
8. Prohibited activities
Coild does not provide services in connection with the activities listed in Schedule B. These are activities which are unlawful, which would expose Coild to criminal liability, or which fall outside our risk appetite in every case. There is no approval route for them and no exception process.
Activities which are lawful but carry elevated risk, and which Coild will support subject to enhanced controls and senior approval, are listed in Schedule C.
9. Financial sanctions
Sanctions compliance is a strict liability obligation and is separate from, and additional to, our anti-money laundering obligations.
Coild screens customers, beneficial owners, controllers, directors and counterparties against the UK Sanctions List administered by the Office of Financial Sanctions Implementation, United Nations Security Council consolidated lists, and other regimes applicable to our operations, including those of the European Union and the United States Office of Foreign Assets Control. Screening is carried out before onboarding and on a continuing basis as designations change.
Where a designated person or entity is identified, Coild will freeze the relevant funds or economic resources, will not deal with them, will not make funds or economic resources available directly or indirectly to or for the benefit of that person, and will report as required. There is no de minimis threshold. Any activity that would otherwise be prohibited is undertaken only under a licence issued by the competent authority.
Coild also assesses ownership and control below designation thresholds, and treats deliberate structuring to avoid a sanctions designation as sanctions evasion.
10. Ongoing monitoring
Business relationships are monitored throughout their life to confirm that activity remains consistent with what we know of the customer, their stated purpose and their risk profile, and that the information we hold remains current. Monitoring combines automated and manual review. Activity that is inconsistent, unexplained or without apparent lawful purpose is escalated for investigation.
For reasons of control integrity, Coild does not publish, and will not disclose to customers, the parameters, indicators, thresholds or logic on which its monitoring operates.
11. Reporting suspicion
Every person acting for Coild is required to report knowledge or suspicion of money laundering, terrorist financing or sanctions breach to the MLRO immediately. There is no internal threshold below which a report need not be made, and no individual may decide alone that a matter is not worth reporting.
The MLRO assesses every internal report, records the decision and its reasons, and makes a disclosure to the relevant authority where the legal test is met. Where consent is required before a transaction may proceed, Coild does not proceed until that consent is obtained or the applicable statutory periods have expired.
Disclosing to a customer or any third party that a report has been made or is contemplated, or that an investigation may be underway, is a criminal offence. This is why Coild may at times be unable to explain a delay, a refusal, a restriction or a closure. We will not confirm or deny whether any report has been made.
Anyone reporting a concern in good faith is protected from retaliation. Concerns may also be raised confidentially, including anonymously, using the contact details in section 16.
12. Records and data protection
Coild retains identification and verification evidence, records of relationships and transactions, risk assessments, internal reports and the reasoning behind decisions taken.
Records are retained for five years from the end of the business relationship or the completion of the transaction, and are deleted at the end of that period unless retention is required or permitted by law.
Personal data is processed in accordance with the UK GDPR and the Data Protection Act 2018. Our lawful basis for this processing is compliance with a legal obligation, together with the substantial public interest condition relating to the prevention and detection of unlawful acts. Certain data subject rights are lawfully restricted where their exercise would prejudice the prevention or detection of crime or would amount to tipping off.
13. Training
All personnel receive financial crime training on appointment and at least annually thereafter, with additional role-specific training for those in onboarding, transaction handling, monitoring and compliance roles. Training covers the applicable law, our own requirements, current criminal methods, and the personal criminal liability that attaches to individuals. Completion is recorded and tested, and non-completion is escalated.
14. Audit, assurance and defensibility
Coild's controls are subject to independent testing and to internal and external audit.
Every material financial crime decision — to onboard, to decline, to approve a higher-risk relationship, to escalate, to restrict, to report or to exit — is recorded at the time it is taken, together with the evidence relied on and the reasoning applied. Records are maintained so that any decision can be reconstructed and evidenced to an auditor, supervisor, banking partner or court, in full, at any point within the retention period.
Findings from testing and audit are tracked to remediation with assigned ownership and deadlines, and are reported to the Board.
15. Our rights
Coild may, at its sole discretion and without prior notice, decline to establish a relationship, request further information or documentation, delay or refuse a transaction, suspend or restrict access to services, freeze funds, and terminate a relationship, where it considers this necessary to comply with its legal obligations or to manage financial crime risk.
Where Coild takes any such action, it is under no obligation to disclose its reasons, and in certain circumstances is prohibited by law from doing so. Coild accepts no liability for any loss, cost or damage arising from action taken in good faith to comply with legal obligations or with this policy.
Coild will cooperate fully with law enforcement, regulators and supervisory authorities, and will disclose information where required or permitted to do so by law.
16. Contact
| Purpose | Contact |
|---|---|
| Compliance and AML enquiries | compliance@coild.co |
| Money Laundering Reporting Officer (confidential) | mlro@coild.co |
| Data protection | privacy@coild.co |
| Reporting a concern, including anonymously | compliance@coild.co |
| Post | Coild Ltd, 50 Princes Street, Ipswich, England, IP1 1RJ |
We aim to acknowledge compliance enquiries within three business days and to respond substantively within fifteen business days. Complex cases, or cases dependent on third-party information, may take longer, and we will say so. Where legal obligations prevent us from responding, giving reasons or meeting these timescales, we will not do so.
Verification requirements are set by law and by our risk assessment. They cannot be waived, and partial information will not accelerate a review.
Schedule A — Prohibited jurisdictions
Coild does not onboard customers resident, incorporated, established or operating in, and does not process transactions to, from or through, the following jurisdictions and territories. This applies to customers, beneficial owners, controllers, directors and counterparties.
Afghanistan · Åland Islands · American Samoa · Barbados · Belarus · Bolivia · Botswana · Burkina Faso · Burundi · Cameroon · Central African Republic · Chad · Christmas Island · Cocos (Keeling) Islands · Cuba · Democratic Republic of the Congo · Eritrea · Ethiopia · Falkland Islands (Malvinas) · Faroe Islands · French Guiana · Ghana · Guadeloupe · Guam · Haiti · Honduras · Iran · Iraq · Korea, Democratic People's Republic of (North Korea) · Korea, Republic of (South Korea) · Lebanon · Libya · Mali · Martinique · Mozambique · Myanmar · New Caledonia · Nicaragua · Nigeria · Norfolk Island · Oman · Pakistan · Palau · Pitcairn · Puerto Rico · Réunion · Russian Federation · Saint Barthélemy · Saint Helena · Saint Kitts and Nevis · Saint Pierre and Miquelon · Samoa · Saudi Arabia · Somalia · South Sudan · Sudan · Svalbard and Jan Mayen · Syria · Tanzania · Tokelau · Trinidad and Tobago · Turkmenistan · Uganda · Vanuatu · Venezuela · Vietnam · Wallis and Futuna · Western Sahara · Yemen · Zambia · Zimbabwe
Contested and occupied territories: Crimea, and the non-government-controlled areas of the Donetsk, Luhansk, Kherson and Zaporizhzhia regions of Ukraine.
The prohibition extends automatically to:
- any jurisdiction or territory subject to comprehensive or territorial financial sanctions under any regime applicable to Coild
- any jurisdiction added to the FATF list of High-Risk Jurisdictions subject to a Call for Action
As at the FATF Plenary of 19 June 2026, the jurisdictions subject to a Call for Action are Iran, the Democratic People's Republic of Korea and Myanmar, each of which is prohibited above. Iran and the DPRK are additionally subject to a call for countermeasures.
Restrictions in this Schedule are applied by reference to a person's jurisdiction of residence, incorporation, establishment or operation. They reflect Coild's assessment of financial crime and sanctions exposure, the availability of reliable identity and beneficial ownership information, and Coild's own operational capacity in the market concerned. They are not applied by reference to any individual's race, ethnicity, national origin, religion or any other protected characteristic, and they are reviewed periodically to confirm that they remain a proportionate means of managing the risks identified.
This Schedule reflects Coild's commercial risk appetite and is separate from, and additional to, the legally binding financial sanctions regimes described in section 9, which apply in full irrespective of this Schedule. It is reviewed following each FATF Plenary — which convenes in February, June and October — and whenever a relevant sanctions designation changes.
Schedule A2 — Jurisdictions subject to enhanced scrutiny
Relationships and transactions connected to the following are permitted, but require enhanced due diligence, senior approval and enhanced ongoing monitoring.
Jurisdictions under FATF Increased Monitoring, as identified at the Plenary of 19 June 2026, which are not already prohibited under Schedule A:
Angola · Bosnia and Herzegovina · Bulgaria · Côte d'Ivoire · Kenya · Kuwait · Lao People's Democratic Republic · Monaco · Nepal · Papua New Guinea · Virgin Islands (UK)
The remaining eleven jurisdictions under FATF Increased Monitoring — Bolivia, Cameroon, the Democratic Republic of the Congo, Haiti, Iraq, Lebanon, South Sudan, Syria, Venezuela, Vietnam and Yemen — are prohibited under Schedule A, which prevails.
The FATF does not itself call for enhanced due diligence on these jurisdictions and cautions against indiscriminate de-risking. Coild applies enhanced scrutiny as a matter of its own risk appetite, assessed case by case, and does not refuse relationships on the basis of connection to these jurisdictions alone.
In addition, enhanced scrutiny applies to:
- jurisdictions subject to targeted or sectoral sanctions under any applicable regime
- jurisdictions identified in the UK National Risk Assessment as presenting elevated money laundering or terrorist financing risk
- jurisdictions assessed as presenting significant corruption risk, financial secrecy risk, or weak beneficial ownership transparency
- jurisdictions experiencing armed conflict, state collapse or the absence of effective supervision
- jurisdictions identified as significant sources of proliferation financing or sanctions circumvention
Schedule B — Prohibited activities
Coild will not provide services to, process transactions for, or knowingly facilitate any of the following. There is no approval route and no exception process. Involvement in any of these will result in immediate termination and, where required, disclosure to the authorities.
Crimes against the person
Human trafficking, modern slavery, forced labour and child labour · any exploitation of, or content involving, minors · trade in human organs, tissue or bodily fluids · commercial sexual exploitation and non-consensual services · kidnapping, extortion and violence for hire
Terrorism, proliferation and sanctions
Terrorist financing, and any dealing with proscribed organisations or their affiliates · proliferation of weapons of mass destruction and related dual-use goods · any dealing with a designated person or entity, and any structure, arrangement or transaction designed to evade, circumvent or obscure a sanctions designation · provision of services to or on behalf of any jurisdiction listed in Schedule A
Controlled substances and regulated goods
Illegal drugs, narcotics, controlled substances and drug precursors · new psychoactive substances and unregulated research chemicals · prescription pharmaceuticals supplied without valid prescription or licence · unlicensed trade in firearms, ammunition, weapons components, explosives and military equipment · unlicensed trade in dual-use goods and technology
Financial crime and unlicensed financial activity
Money laundering in any form · unlicensed money transmission, remittance and currency exchange · informal value transfer systems, including hawala and equivalent arrangements · unlicensed deposit-taking, lending, insurance, investment and securities activity · unregistered cryptoasset exchange and custody services · shell banks, and any institution permitting its accounts to be used by a shell bank · anonymous accounts, accounts in fictitious names, and relationships where the beneficial owner cannot be established · bearer share and bearer instrument arrangements · Ponzi schemes, pyramid schemes, chain referral schemes, high-yield investment programmes and multi-level marketing without a genuine underlying product · unlicensed gambling, betting, lotteries and gaming · unregistered trust and company service provision · unlicensed dealing in precious metals and stones
Fraud and cybercrime
Fraud of any kind, including advance fee, invoice, mandate, romance, investment and authorised push payment fraud · phishing, smishing and social engineering operations · identity theft and the trade in stolen or synthetic identity data · trade in stolen payment card or account credentials · money mule recruitment and networks · ransomware, malware, botnets, hacking services and denial-of-service services · services enabling anonymised or untraceable value transfer for the purpose of evading controls, including mixing and tumbling services · darknet marketplaces and services enabling access to them
Evasion and concealment
Tax evasion, and the facilitation of tax evasion by any person · deliberate structuring or smurfing to avoid reporting or verification requirements · use of shell or front companies without genuine economic purpose · undisclosed nominee arrangements · falsified, forged or altered identification, corporate or financial documentation · concealment or misrepresentation of the source of funds, source of wealth, beneficial ownership or the true purpose of a transaction · trade-based money laundering, including false invoicing, over- and under-invoicing and phantom shipment
Illicit trade
Counterfeit goods and goods infringing intellectual property · pirated media and software · trafficking in wildlife, protected species and their products · trafficking in cultural property and antiquities of unlawful or unverifiable provenance · conflict minerals and diamonds outside the Kimberley Process · trade in stolen goods
Other
Bribery and corruption, including facilitation payments · child sexual abuse material · any content or service that is unlawful in the jurisdiction of the customer or of Coild · any activity in respect of which Coild forms the view that it cannot adequately manage the associated financial crime risk
Schedule C — Higher-risk activities accepted with enhanced controls
Coild supports customers in the following sectors and activities. These are lawful and are accepted, but they carry elevated financial crime risk. They require enhanced due diligence, senior management approval before onboarding, evidence of appropriate licensing where the activity is regulated, and enhanced ongoing monitoring throughout the relationship.
- Licensed gambling, betting and gaming operators, and their suppliers
- Registered cryptoasset exchange providers, custodian wallet providers and other virtual asset service providers
- Money service businesses, currency exchange, remittance and payment institutions
- Trust and company service providers, and company formation agents
- Dealers in precious metals, precious stones, jewellery and other high-value goods
- Art dealers, auction houses, galleries and dealers in antiquities
- Real estate agents, developers and property investment vehicles
- Charities, non-profit organisations and religious institutions
- Licensed defence, security and dual-use goods businesses
- Extractive industries, commodities trading and trade finance
- Shipping, freight forwarding and logistics
- Cash-intensive businesses
- Adult entertainment operating lawfully and under licence
- Pharmaceuticals, telemedicine, nutraceuticals, cannabinoid products, tobacco and vaping products
- Debt collection, factoring and invoice finance
- Marketplaces, payment facilitators and platforms with sub-merchant or sub-account structures
- Customers with complex, multi-layered or cross-border ownership structures, including trusts and foundations
- Customers incorporated in, or with material connections to, financial secrecy jurisdictions
- Politically exposed persons, their family members and known close associates
- Customers onboarded remotely from jurisdictions listed in Schedule A2
Acceptance of any relationship within this Schedule is a decision, not an entitlement. Coild may decline or exit any such relationship at any time where the risk cannot be managed to its satisfaction.
Coild Ltd · Company number 16955836 · 50 Princes Street, Ipswich, England, IP1 1RJ · This policy is reviewed at least annually and following any material change to Coild's business, its regulatory position, or applicable law.