Anti-Money Laundering, Fraud Prevention, and Customer Protection Policy

wave shape

Anti-Money Laundering, Fraud Prevention, and Customer Protection Policy

Last Updated September 26, 2026

AYDAPAY – Anti-Money Laundering, Fraud Prevention and Customer Protection Policy

Version3.0 (public summary)
Effective date26 September 2026 (replaces version 1.0 of 9 February 2026)
EntityAYDAPAY SP. Z O.O., Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland · KRS 0001036277
Approved byManagement Board of AYDAPAY SP. Z O.O.
Policy ownerMoney Laundering Reporting Officer (MLRO)
Review cycleAt least annually, and before any new product, partner or country is launched

This is the public summary of AYDAPAY's anti-money laundering and counter-terrorist financing (AML/CFT), sanctions and fraud prevention framework. Our detailed internal procedures are available to supervisory authorities, auditors and regulated partners on request.

1. Legal and regulatory framework

  • Polish Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing;
  • EU anti-money laundering legislation, including Directive (EU) 2015/849 as amended, and Regulation (EU) 2023/1113 on information accompanying transfers of funds;
  • Sanctions of the United Nations, the European Union and Poland, and other sanctions regimes that apply to us or our partners (including UK, US OFAC and Canadian sanctions);
  • FATF Recommendations and guidance of the General Inspector of Financial Information (GIIF) and the Polish Financial Supervision Authority (KNF).

2. Governance

  • The Management Board approves this Policy and the business-wide risk assessment and is ultimately responsible for compliance.
  • A Money Laundering Reporting Officer (MLRO) oversees the programme, decides on suspicious activity reports and reports directly to the Board.
  • The programme is subject to independent review by an external auditor.
  • All staff receive AML/CFT, sanctions and fraud training on joining and at least annually, with assessment and attendance records.

3. Risk-based approach

We assess and document money laundering and terrorist financing risks across our customers, products, delivery channels, countries and partners, and update the assessment at least annually and whenever our business changes. Each customer receives a risk rating that determines the level of due diligence and monitoring applied.

4. Customer due diligence

CustomerWhat we verify
Individual CustomersIdentity using a valid passport, national ID card or residence document, with a live selfie (liveness check) and face match; residence; purpose and expected use of the account; proof of address and source of funds or wealth where required
Business CustomersRegistration extract; articles of association; shareholder and director registers; registered and trading address; nature of the business, expected activity and website; identity and address of directors, authorised representatives, authorised users and beneficial owners
  • Enhanced due diligence applies to higher-risk customers, politically exposed persons and their family members and close associates, higher-risk corridors and unusual activity, including senior approval, source of funds and wealth, and purpose of payment supported by documents such as invoices or contracts.
  • Customers must keep their information up to date and inform us of changes within 14 days.
  • We do not open anonymous accounts, and our services are online only – we do not accept or pay out cash.

5. Sanctions and screening

Customers, beneficial owners and payees are screened against applicable sanctions, PEP and adverse-media lists at onboarding and on every payment. Potential matches are reviewed under the four-eyes principle. We do not make or receive payments involving sanctioned persons, entities, vessels, countries or territories, and we freeze and report assets where the law requires.

6. Restricted jurisdictions and prohibited activities

We do not onboard customers established or resident in comprehensively sanctioned countries, FATF "call for action" countries or EU high-risk third countries. We do not serve prohibited activities, including unlicensed gambling, weapons and dual-use goods, virtual asset trading, unlicensed financial services, pyramid and Ponzi schemes, hawala and informal value transfer systems, shell companies and cash-intensive businesses. Payment and money service businesses are reviewed individually and must hold a valid licence. The full list is in clause 9 of the Customer Account Agreement.

7. Ongoing monitoring

We monitor accounts and payments continuously using rules and AI-assisted tools, supported by transaction and balance limits based on each customer's risk profile. Every alert is reviewed by trained staff. We may request information or documents at any time and may delay, hold or refuse a payment, or restrict an account, while a review is carried out.

8. Suspicious activity reporting

Suspicious transactions and activity are reported to the General Inspector of Financial Information (GIIF) and, where appropriate, to law enforcement. The law prohibits us from informing anyone that a report has been made or that an analysis is under way (prohibition of tipping off).

9. Fraud prevention

We apply Strong Customer Authentication, device and behavioural signals, payee-name verification where supported, scam warnings, holding periods for card and Open Banking funding, and a 24/7 reporting channel. Our Customer Protection & Fraud Awareness Policy explains how customers can protect themselves.

10. Information accompanying transfers

Every transfer of funds carries the payer and payee information required by Regulation (EU) 2023/1113. Transfers with missing or incomplete information may be suspended or rejected.

11. Record keeping

Customer due diligence records, transaction records and analyses are kept for 5 years from the end of the business relationship or the date of the occasional transaction, and longer where the competent authority requires it.

12. Customer obligations

  • Provide true, complete and up-to-date information and documents.
  • Use the account only for yourself or your own business, with funds from a lawful source.
  • Never allow anyone else to use your account and never receive or forward money for others.
  • Respond to information requests within the time we set (usually 72 hours for a payment enquiry).

False information, forged documents or misuse of the account may lead to refusal of payments, closure of the account and reporting to the competent authorities.

12A. Anti-bribery and corruption

AYDAPAY has zero tolerance for bribery and corruption. Staff, partners and service providers may not offer, promise, give, request or accept any improper advantage, in line with the Polish Criminal Code and applicable anti-bribery laws. Gifts and hospitality are recorded and approved, conflicts of interest must be declared, and concerns can be raised confidentially without retaliation.

13. Your rights

These controls are applied fairly and proportionately. Where the law allows, we tell you why a payment or account is held and what we need to release it. You may complain under our Complaints Policy and request human review of automated decisions under our Privacy Policy. Nothing in this Policy limits your statutory rights.

AYDAPAY SP. Z O.O. · Aleja Armii Ludowej 6/164, 00-571 Warsaw, Poland · KRS 0001036277 · help@aydapay.com

Need Help?

If you have any questions about our Anti-Money Laundering, Fraud Prevention, and Customer Protection Policy, please don't hesitate to contact us.

How can I contact customer support?