Skip to main content
IDSXINTERNATIONAL DIGITAL SECURITIES EXCHANGE
Apply to Participate

IDSX KYC / AML REQUIREMENTS

DRAFT

IDSX KYC / AML Requirements

IDSX · Version 1.0 · Draft

Effective Date: To be determined

1. Purpose and Scope

1.1 Purpose

These KYC / AML Requirements set minimum standards for customer identification and due diligence, AML/CFT, sanctions, transaction monitoring and related controls in the IDSX ecosystem. They seek to prevent money laundering, terrorism and proliferation financing, sanctions evasion and other financial crime; identify persons accessing IDSX securities, beneficial owners and controllers; control associated wallets; establish risk-based monitoring and suspicious-activity reporting; protect market integrity; and support Applicable Law.

2. Application

These Requirements apply, as relevant, to Brokers, Trading Participants, Sponsors, Underwriters, Market Makers, Custodians, settlement providers, transfer agents or registry providers, Issuers onboarding investors directly, other Client-facing IDSX service providers and other categories IDSX designates. Each Participant must determine whether it is a reporting entity or otherwise subject to AML/CFT laws. These Requirements do not replace statutory duties.

3. General Principle

Anonymous use is prohibited where identification is required. Participants must establish who the customer is; who ultimately owns or controls it; who acts for it; where appropriate, the source of money or wealth; and whether activity is consistent with what is known about the customer.

4. Risk-Based Approach

4.1 General Requirement

CDD, monitoring and controls must reflect the money-laundering, terrorism-financing, sanctions and other financial-crime risk presented.

4.2 Relevant Risk Factors

Consider customer type and beneficial ownership; jurisdiction and residence; business, products and expected activity; transaction volume and frequency; source of funds and wealth; payment methods and digital assets; external wallets and remote onboarding; PEP and sanctions exposure; complex, nominee or unusual ownership; adverse information; and other relevant indicators.

5. Customer Risk Rating

Each onboarding Participant must maintain a risk-rating method, such as Low, Standard, Elevated and High Risk or an equivalent. Classification must reflect the overall relationship and relevant indicators, not nationality or residence alone.

6. Review of Customer Risk

Review risk periodically and when activity, ownership, business, suspicious activity, PEP or sanctions status, adverse information, product use or another material event changes.

7. Customer Due Diligence

7.1 General Requirement

Complete appropriate CDD before establishing a relationship or permitting relevant activity unless Applicable Law expressly allows otherwise. CDD must be proportionate to the customer and risk.

7.2 CDD Objectives

CDD must reasonably establish the customer’s identity and beneficial ownership; persons acting for it; relationship nature and purpose; anticipated account activity; and applicable risk.

8. Individual Customers

Obtain, as appropriate, legal name, date of birth, residential address, relevant nationality and tax residence, government ID, contact details, occupation or business, account purpose, expected activity and other lawfully required or risk-relevant information.

9. Identity Verification

Verify identity using reliable independent documents, data or information, including government ID, trusted digital identity, approved electronic verification, reliable government databases, certified documents or other legally permitted methods. Electronic verification does not remove Participant responsibility.

10. Entity Customers

Obtain, as appropriate, legal name and form; incorporation jurisdiction and registration number; registered office and principal place of business; business nature; directors or governing persons; authorised account operators; ownership and control, beneficial owners; and the purpose and anticipated nature of the IDSX relationship.

11. Beneficial Ownership

11.1 General Requirement

Identify beneficial owners as required by law and appropriate to risk.

11.2 Look-Through Principle

For holding companies, nominees, trusts, partnerships, custodians, foundations, offshore structures or other intermediaries, take reasonable steps to understand ownership and control.

11.3 No Concealed Beneficial Ownership

A customer must not use an entity, nominee, wallet or other arrangement to conceal the true beneficial owner.

12. Persons Acting on Behalf of Customers

Conduct appropriate due diligence on a representative and establish identity, relationship, authority and its scope, and where appropriate, authenticity. Representatives may include directors, authorised traders, attorneys, trustees, investment managers, employees, guardians and others.

13. Nature and Purpose of Relationship

Obtain enough information to understand investment objectives and size, expected trading and funding flows, external-wallet use, capital source, relevant business activity and intended relationship with IDSX.

14. Simplified Due Diligence

Apply simplified due diligence only where permitted by law. Low risk does not waive identity, sanctions or other mandatory checks. Document the basis.

15. Enhanced Customer Due Diligence

15.1 When EDD May Be Required

Conduct EDD where law requires or elevated risk is indicated, including high-risk customers; complex ownership or unexplained nominees; PEPs or higher-risk jurisdictions; complex, unusually large or purposeless transactions; significant digital-asset or external-wallet use; adverse information; unexplained funds or wealth; sanctions exposure; unusual third-party funding; or other elevated risks.

16. Enhanced Measures

EDD may include additional identity or ownership data and independent verification; Source of Funds or Wealth; transaction information; senior approval; enhanced monitoring and more frequent reviews; independent evidence; and account or transaction restrictions.

17. Source of Funds

Source of Funds is the origin of money or assets for a specific transaction or relationship. Evidence may include bank or investment statements, sale agreements, payroll or dividend records, loan or inheritance documents, business income, audited accounts or other reliable evidence. Verification must be proportionate to risk.

18. Source of Wealth

Source of Wealth is the origin of overall wealth or financial position, including employment, business ownership or profits, investments, property, inheritance, sale of a business, family wealth or other legitimate sources. Do not demand excessive or irrelevant evidence unjustified by risk and circumstances.

19. Politically Exposed Persons

Identify PEPs as required by law and apply appropriate enhanced measures, which may include Source of Wealth and Funds, senior management approval, enhanced ongoing monitoring and periodic reassessment. PEP status alone is not evidence of wrongdoing.

20. Sanctions Screening

Maintain reasonable systems to identify sanctioned or restricted customers, beneficial owners, directors, controllers, representatives, counterparties, relevant wallet addresses and other connected persons.

21. Sanctions Matches

Investigate potential matches before activity proceeds. Do not knowingly make assets available to prohibited persons, execute prohibited transactions, assist evasion or structure around sanctions. Where appropriate, freeze, reject, block or restrict activity as law requires.

22. Adverse Information

Credible information concerning fraud, money laundering, terrorism financing, corruption, sanctions violations, organised crime, securities offences, serious regulatory misconduct or other financial crime may inform risk. Assess it in context; it is not automatically proof of misconduct.

23. Digital Wallet Identification

Where securities use distributed ledger technology, the responsible Participant must maintain controls linking identity to approved wallets, as applicable: Verified Customer → IDSX Account → Approved Wallet.

24. Wallet Whitelisting

Where required, only approved wallets may receive a security; each must link to an eligible holder who has completed KYC; transfer restrictions must operate; prohibited or sanctioned wallets must not be approved; and IDSX or its authorised provider must be able to remove or restrict approval where appropriate.

25. Self-Custody Wallets

IDSX may permit self-custody, but this does not remove identification duties. Before approval, a Participant may reasonably verify customer control by cryptographic signature, signed message, controlled transfer, authenticated wallet connection, technical ownership verification or another reliable method.

26. Third-Party Wallets

A customer must not direct securities to a third-party wallet to bypass KYC, eligibility, sanctions, ownership or transfer restrictions, or registration. Beneficial ownership changes must follow applicable transfer procedures.

27. Wallet Change

Verify a replacement wallet before it can receive securities. Consider enhanced verification for a change just before material transfer, frequent changes, elevated blockchain risk, unusual account access or suspected takeover.

28. Blockchain Analytics

Use risk-appropriate blockchain monitoring where reasonably necessary. Indicators may include sanctioned addresses, stolen assets, ransomware, darknet markets, scams, mixers or obfuscation, terrorist financing, high-risk services and other illicit activity. Analytics alone is not conclusive evidence.

29. Funding Accounts

Where practical, funds should come from accounts in the customer’s name, an approved joint holder, approved custodian or another verified source. Apply controls to third-party funding.

30. Third-Party Payments

Unexplained third-party payments may be higher risk. If permitted, understand the payer’s identity and relationship, payment purpose and fund ownership, and whether more due diligence is needed.

31. Digital Asset Funding

For accepted digital assets such as stablecoins, maintain risk-appropriate wallet identification, sanctions and blockchain screening, origin-of-funds assessment, monitoring, high-risk wallet restrictions, confirmations and reconciliation.

32. Ongoing Customer Due Diligence

Throughout the relationship, keep information current, understand beneficial ownership, compare activity to the risk profile, identify material changes, maintain suitable risk ratings and obtain further information where necessary.

33. Periodic Reviews

Set risk-based review cycles; review higher-risk customers more often. Reviews may cover identity, address, ownership, corporate status, PEP and sanctions status, funds or wealth where appropriate, expected and actual activity, and overall risk.

34. Event-Driven Reviews

Reassess risk when ownership, directors or controllers change; activity becomes unusual or materially increases; jurisdiction exposure changes; suspicious activity, enforcement, sanctions developments or adverse information arise; wallets change significantly; or the relationship materially changes.

35. Transaction Monitoring

Maintain monitoring proportionate to business nature and scale to identify activity inconsistent with the customer profile, expected patterns, stated funds or wealth, known business or legitimate investment activity.

36. Potential Risk Indicators

Review unexplained large deposits; rapid withdrawal; purposeless repetition; activity inconsistent with wealth; rapid movement among wallets; unusual third-party funding; multiple accounts avoiding controls; circular or wash trading; rapid security transfer without rationale; inconsistent ownership; unusual geography; high-risk wallets; sanctions evasion; and attempts to avoid KYC. Indicators do not themselves prove wrongdoing.

37. Market Surveillance and AML Monitoring

Market surveillance and AML monitoring may overlap but have distinct purposes. Subject to law, relevant information may be shared among AML, compliance, surveillance, cybersecurity, fraud prevention, custody and other control functions.

38. Suspicious Activity

On reasonable grounds for suspicion, follow internal investigation and statutory reporting procedures. Do not disregard activity because a transaction completed, initial KYC passed, a customer is wealthy or institutional, another intermediary onboarded it, or blockchain was used.

39. Suspicious Activity Reports

Submit required Suspicious Activity Reports or equivalent within statutory timeframes and channels. IDSX may also require notice where relevant to integrity, manipulation, ownership restrictions, settlement, IDSX securities, Participant misconduct or systemic crime risk.

40. No Tipping Off

Prevent unlawful disclosure that a suspicious report has or may be made, an AML investigation is underway, or law enforcement requested information, where law prohibits disclosure.

41. Reliance on Third Parties

A Participant may rely on another person for CDD only where legally permitted, including another regulated financial institution or reporting entity, IDSX Broker, regulated Custodian, regulated foreign intermediary or approved provider.

42. Responsibility When Relying on Others

Reliance does not automatically transfer ultimate responsibility. Confirm it is lawful and appropriate to risk, CDD was performed, information is promptly available, records can be obtained, and third-party supervision is adequate where required.

43. IDSX Shared KYC Infrastructure

IDSX may operate or designate shared infrastructure containing verified identity, KYC status, beneficial owners, eligibility, sanctions status, wallet approvals, jurisdiction restrictions and other compliance attributes. This does not remove a Participant’s own legal duties.

44. KYC Status

IDSX systems may classify investors as Pending, Verified, Enhanced Review, Restricted, Suspended or Rejected. Participants must not permit activity inconsistent with status restrictions.

45. Investor Eligibility Attributes

IDSX may maintain separate attributes such as Retail, Wholesale, Professional or Institutional Investor; eligible or restricted jurisdiction; accredited or equivalent status; and product-specific eligibility. Passing KYC does not confer eligibility for every security.

46. Issuer-Specific Restrictions

Apply additional security requirements arising from securities laws, offering exemptions, constitutional documents, shareholder limits, foreign ownership, approvals or security terms, in addition to general KYC.

47. Transfer-Level Compliance

Check compliance at transfer where appropriate. A transfer may be rejected if the recipient is unverified or ineligible, wallet unapproved, sanctions concern exists, ownership limit would be breached, lock-up applies or another legal restriction exists.

48. No Uncontrolled Peer-to-Peer Transfer

Where eligibility or ownership controls apply, securities must not be freely transferred to an unidentified external holder merely by blockchain transfer. IDSX may require technical restrictions to approved receiving addresses.

49. Transfer Agent and Register Integration

Where relevant, reconcile wallet compliance with the legally recognised register, transfer-agent and beneficial-ownership records, custody records, and IDSX trading and settlement records. Blockchain balances alone are insufficient if they are not the legal ownership record.

50. Privacy and Data Protection

Collect, store, access and disclose KYC information according to law, with reasonable safeguards for identification, ownership, financial, wealth, funds, wallet and other sensitive data.

51. Data Minimisation

Obtain sufficient information for legal, regulatory and risk needs while avoiding personal information without a legitimate purpose.

52. Access Controls

Limit access to personnel with legitimate need. Controls may include role-based access, logs, multi-factor authentication, encryption, approvals and administrative-access monitoring.

53. Record Keeping

Maintain evidence of compliance, including IDs, verification, ownership, risk assessments, funds and wealth, PEP and sanctions checks, wallet verification, monitoring alerts and investigations, decisions, approvals and legally retainable reports.

54. Retention Period

Retain records at least as long as required by law and determine applicable periods when multiple jurisdictions apply. IDSX may set longer periods needed to reconstruct market activity.

55. Availability of Records

Records must be retrievable without undue delay and provided to IDSX when properly requested for surveillance, investigations, supervision, ownership, regulatory enquiries, sanctions, settlement or enforcement.

56. AML/CFT Programme

Statutorily covered Participants must maintain a programme complying with law; others must maintain controls proportionate to IDSX activity and risk. A programme may cover governance, CDD/EDD, risk ratings, monitoring, sanctions, escalation, records, employee vetting and training, outsourcing, quality assurance, independent review and remediation.

57. AML Compliance Officer

Where law requires, appoint an appropriate AML/CFT officer with sufficient authority, independence, management access, information access and resources.

58. Staff Training

Train relevant personnel proportionately on KYC, ownership, funds and wealth, PEPs, sanctions, suspicious activity, monitoring, wallets, market abuse, escalation and confidentiality.

59. Independent Review and Audit

Where law requires, independently audit or review programmes at prescribed intervals. IDSX may request evidence and require remediation of material weaknesses.

60. Outsourcing

Outsourcing does not transfer compliance responsibility. Maintain oversight of identity, sanctions, adverse media and PEP screening, blockchain analytics, monitoring, document verification and related providers.

61. Automated Decision Systems

Automated systems may be used, with governance for testing, thresholds, false positives, escalation, appropriate human review, updates and access. They are not infallible.

62. Refusal of Business

Refuse or end a relationship if required CDD cannot be completed, ownership cannot reasonably be established, required funds or wealth cannot be satisfactorily established, sanctions would be breached, risk is unacceptable or law requires refusal.

63. Account Restriction

Where appropriate and lawful, restrict accounts during review, including deposits, withdrawals, purchases, transfers, external wallets or API access, or allow closing trades only.

64. Account Termination

A Participant may end a relationship presenting unacceptable legal, regulatory or financial-crime risk, in accordance with law and obligations concerning existing securities and assets.

65. IDSX Authority

IDSX may require evidence of controls and request policies, assessments, programme documents, customer records where lawful, ownership and wallet information, investigations, training, audit findings and remediation plans.

66. IDSX Restrictions

For material AML, sanctions or crime concerns, IDSX may require due diligence or remediation; restrict investors, wallets, Participants, onboarding, transfers or trading; suspend Participant status; or take other action under IDSX Rules.

67. Information Sharing

Where lawful, IDSX and Participants may share relevant information for identity and ownership verification, sanctions, fraud prevention, suspicious activity, surveillance, cybersecurity, ownership, regulatory compliance and integrity.

68. Cooperation with Authorities

Participants must comply with lawful competent-authority requests. Where permitted, IDSX may cooperate with financial regulators, FIUs, law enforcement, courts, sanctions authorities, overseas regulators and other competent authorities.

69. Overseas Participants

Overseas Participants must comply with home-jurisdiction AML/CFT rules, laws applying to IDSX activities, these Requirements and IDSX additions. IDSX may require extra controls to maintain market integrity where standards differ.

70. Equivalent Foreign KYC

IDSX may recognise CDD by an appropriately regulated foreign institution if legally permitted, standards acceptable, information and records promptly available, and fresh verification is not required by material risk. IDSX may require more verification.

71. Prohibited Conduct

Do not knowingly assist evasion of KYC or sanctions; concealment of ownership or funds; transaction structuring; improper nominee use; wallet-information manipulation; fictitious customers or identity misuse; transfer-control bypass; or circumvention of these Requirements.

72. Breach Notification

Promptly notify IDSX of material incidents affecting it or market integrity, including systemic KYC or monitoring failure, sanctions breach, customer-data breach, wallet-control failure, identity fraud, unauthorised token transfers, regulatory enforcement or other material AML/CFT failure.

73. Enforcement

Non-compliance may result in warning, remediation, enhanced supervision or reporting, customer or wallet restrictions, activity restrictions, suspension, termination or referral to an authority where appropriate or required.

74. Responsibility of Participants

Market-level IDSX controls do not replace Participant duties. A Participant must not rely solely on IDSX KYC, blockchain controls or surveillance, another Participant or provider where it has an independent obligation.

75. Responsibility of IDSX

Central infrastructure does not guarantee universal Participant compliance, risk-free customers, detection of every suspicious transaction or identification of every illicit asset by blockchain analysis. Each Participant remains responsible for its obligations.

76. Interpretation

General Rules definitions apply unless stated otherwise. AML includes, as relevant, AML, CFT, sanctions, proliferation-financing controls and related crime prevention. KYC includes identification, verification, ownership and related CDD.

77. Applicable Law

Participants subject to New Zealand’s Anti-Money Laundering and Countering Financing of Terrorism Act 2009 must comply with it and applicable regulations, codes and guidance. Nothing reduces Applicable Law duties. Where legally permissible, a higher IDSX operational standard applies as a participation condition.

78. Amendments

IDSX may amend these Requirements or issue KYC, wallet verification, sanctions, investor eligibility, risk classification standards, technical specifications and compliance guidance.

79. Effective Date

These KYC / AML Requirements take effect on the date determined and published by IDSX.

IDSX · KYC / AML Requirements — Version 1.0