Legal
AML/KYC Policy
Anti-Money Laundering & Know Your Customer Policy
1. Introduction
This Anti-Money Laundering ("AML") and Know Your Customer ("KYC") Policy ("Policy") is issued by Zenway International FZ-LLC, operating under the brand name ZenVisa International ("Company," "we," "us," or "our"). This Policy sets out the procedures, measures, and controls that the Company has adopted and implemented to prevent, detect, and deter money laundering ("ML"), terrorism financing ("TF"), proliferation financing ("PF"), and other financial crimes in connection with the provision of our Services.
The Company is committed to conducting its business with the highest standards of integrity, transparency, and regulatory compliance. We comply with all applicable UAE anti-money laundering and counter-terrorism financing laws, regulations, and guidance, and we cooperate fully with the UAE Financial Intelligence Unit ("FIU") and other competent authorities.
By engaging our Services, all Customers acknowledge and agree to comply with the requirements set out in this Policy. Failure to comply may result in the refusal, suspension, or termination of Services.
2. Company Identity
The entity responsible for the implementation and enforcement of this Policy is:
| Legal Name: | Zenway International FZ-LLC |
|---|---|
| Operating Name: | ZenVisa International |
| Registered Address: | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE |
| RAKEZ License No.: | 47029828 |
| Email: | legal@zenvisa.net |
| Website: | https://www.zenvisa.net |
| RAKEZ Reference: | 1639588-9LXu-LBZR-80986483 |
3. Purpose of this Policy
The purpose of this Policy is to:
• Ensure compliance with UAE Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations, Cabinet Decision No. 10 of 2019, and all applicable implementing regulations and guidance;
• Establish a risk-based approach to identifying, assessing, and managing money laundering and terrorism financing risks;
• Define the procedures for customer identification, verification, and ongoing monitoring;
• Set out the requirements for identifying and verifying beneficial owners of corporate customers;
• Establish procedures for screening customers against sanctions lists, politically exposed persons ("PEP") databases, and adverse media sources;
• Define the circumstances under which enhanced due diligence is required;
• Establish procedures for detecting, reporting, and recording suspicious activities and transactions;
• Protect the integrity of the Company's services and maintain the trust of customers, regulators, and the public;
• Ensure cooperation with government authorities, regulators, and law enforcement agencies in the prevention and detection of financial crime.
4. Scope
This Policy applies to all Customers who engage the Company's Services, including:
• Individual customers (natural persons) seeking personal services such as visa assistance, residency applications, and document preparation;
• Corporate customers (legal entities) seeking business setup, company formation, corporate restructuring, and business documentation services;
• Trusts, foundations, partnerships, and other legal arrangements;
• Beneficial owners, directors, officers, authorized signatories, and agents of corporate customers;
• Intermediaries, introducers, and referral partners.
This Policy applies to all stages of the business relationship, including onboarding, service delivery, ongoing monitoring, and post-termination record retention.
5. Definitions
"Adverse Media": means publicly available information about a person or entity that suggests involvement in criminal activity, financial crime, corruption, sanctions violations, or other unlawful conduct.
"AML": means Anti-Money Laundering.
"Beneficial Owner": means a natural person who ultimately owns or controls a legal entity, directly or indirectly, whether through ownership of shares, voting rights, or other means, including the right to appoint or remove a majority of the board of directors.
"CDD": means Customer Due Diligence.
"Customer": means any natural person or legal entity that engages the Company's Services.
"EDD": means Enhanced Due Diligence.
"FATF": means the Financial Action Task Force, the inter-governmental body that sets international standards for combating money laundering and terrorist financing.
"FIU": means the UAE Financial Intelligence Unit, established under the UAE AML Law.
"KYC": means Know Your Customer.
"ML": means Money Laundering.
"PEP": means a Politically Exposed Person, defined as an individual who is or has been entrusted with a prominent public function, including heads of state, heads of government, ministers, senior government officials, senior judicial officials, senior military officials, senior executives of state-owned enterprises, and senior political party officials, as well as their family members and close associates.
"PF": means Proliferation Financing, defined as the act of providing funds or financial services used for the manufacture, acquisition, or proliferation of nuclear, chemical, or biological weapons or their means of delivery.
"Sanctions List": means any list of sanctioned persons, entities, or jurisdictions maintained by the United Nations Security Council, the UAE Ministry of Foreign Affairs, the UAE Cabinet, the U.S. Office of Foreign Assets Control (OFAC), the UK HM Treasury, the European Union, or any other applicable sanctions authority.
"SAR": means a Suspicious Activity Report or Suspicious Transaction Report filed with the FIU.
"Source of Funds": means the origin of the funds used in a particular transaction or business relationship.
"Source of Wealth": means the total financial position of a customer and the origin of their overall wealth.
"TF": means Terrorism Financing.
"UBO": means Ultimate Beneficial Owner.
6. Legal and Regulatory Framework
This Policy is designed to ensure compliance with the following legal and regulatory framework:
• UAE Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations, as amended;
• UAE Cabinet Decision No. 10 of 2019 concerning the Implementing Regulation of Decree-Law No. 20 of 2018, as amended;
• All circulars, guidance notes, and instructions issued by the UAE Ministry of Economy, the UAE Central Bank, and other relevant supervisory authorities;
• All directives, guidelines, and requirements issued by the UAE Financial Intelligence Unit (FIU);
• All requirements issued by the UAE Executive Office for Control and Non-Proliferation;
• All applicable resolutions of the United Nations Security Council concerning sanctions;
• The UAE National Committee for Combating Money Laundering and the Financing of Terrorism and Illegal Organisations ("NAMLCFT") guidance;
• The FATF Recommendations and related guidance;
• Applicable RAKEZ compliance requirements and circulars.
The Company reviews this Policy regularly to ensure alignment with changes in the legal and regulatory framework.
7. Risk-Based Approach
The Company adopts a risk-based approach to AML/CFT compliance, as required by the UAE AML Law and FATF Recommendations. This means that the nature and extent of due diligence measures applied to each Customer are proportionate to the assessed level of money laundering and terrorism financing risk.
Risk factors considered in the risk assessment include:
• Customer risk factors: PEP status, sanctions exposure, geographic origin, nature of business activity, ownership structure, and reputation;
• Geographic risk factors: country of residence, country of incorporation, country of business operations, and whether any jurisdiction is designated as high-risk by the FATF or subject to international sanctions;
• Service risk factors: complexity of the service, value of the transaction, use of intermediaries, urgency of the request, and whether the service involves cross-border elements;
• Transaction risk factors: unusual patterns, large cash payments, transactions involving high-risk jurisdictions, and transactions inconsistent with the Customer's known profile.
Based on the risk assessment, Customers are classified into risk categories (low, medium, high, or prohibited). Higher-risk Customers are subject to enhanced due diligence measures.
8. Customer Due Diligence (CDD)
The Company applies Customer Due Diligence ("CDD") measures to all Customers before establishing a business relationship or conducting any transaction. CDD measures include:
• Identifying the Customer and verifying their identity using reliable, independent source documents, data, or information;
• Identifying the beneficial owner of corporate customers and taking reasonable measures to verify their identity;
• Understanding the purpose and intended nature of the business relationship;
• Conducting ongoing due diligence and scrutiny of transactions throughout the business relationship to ensure that transactions are consistent with the Company's knowledge of the Customer, their business, and risk profile.
CDD must be completed before the commencement of Services. In exceptional circumstances where it is necessary to commence Services before CDD is completed, the Company may proceed only with senior management approval and subject to enhanced monitoring until CDD is finalized.
9. Enhanced Due Diligence (EDD)
Enhanced Due Diligence ("EDD") is applied to Customers that present a higher risk of money laundering or terrorism financing. EDD measures are in addition to standard CDD measures and include:
• Obtaining additional information about the Customer's identity, source of funds, and source of wealth;
• Obtaining senior management approval for establishing or continuing the business relationship;
• Conducting enhanced ongoing monitoring of the business relationship, including more frequent review of transactions and documentation;
• Conducting enhanced sanctions, PEP, and adverse media screening;
• Requiring additional verification documents, including certified copies and original documents;
• Conducting site visits or face-to-face verification where appropriate.
EDD is required in the following circumstances:
• The Customer is a Politically Exposed Person ("PEP") or a family member or close associate of a PEP;
• The Customer is from or has business connections with a high-risk jurisdiction;
• The Customer is subject to sanctions screening alerts;
• The transaction is complex, unusually large, or has no apparent economic or lawful purpose;
• The Customer's business or ownership structure is complex or opaque;
• The Company has any other reason to believe the Customer presents a heightened ML/TF risk.
10. Simplified Due Diligence
Simplified Due Diligence ("SDD") may be applied to Customers that present a low risk of money laundering or terrorism financing, where permitted by Applicable Law. SDD involves reducing the extent of CDD measures proportionate to the assessed low risk.
SDD may be considered only where all of the following conditions are met:
• The Customer is a well-established, publicly listed company in a regulated and low-risk jurisdiction;
• The Customer is a government body or state-owned enterprise of a low-risk jurisdiction;
• The transaction value is below the threshold specified by the UAE AML Law;
• There are no other risk factors that would require standard or enhanced due diligence.
The decision to apply SDD must be documented and approved by the Company's AML Compliance Officer. SDD does not exempt the Company from ongoing monitoring obligations.
11. Customer Identification Requirements
All Customers must provide the following identification information before Services commence:
• Full legal name (as shown on government-issued identification);
• Date and place of birth;
• Nationality and citizenship;
• Current residential address;
• Government-issued identification number (passport, national ID, or Emirates ID);
• Contact information (email address and telephone number);
• Occupation and employer details (for individuals);
• Purpose of engaging the Company's Services.
Failure to provide complete and accurate identification information will result in the refusal or suspension of Services.
12. Individual Customer Verification
For individual Customers, identity verification is conducted using at least one government-issued photo identification document from the following list:
• Valid passport (internationally recognized);
• Valid national identity card (for citizens of the issuing country);
• Valid Emirates ID (for UAE residents);
• Valid driving license (supplementary only, not as sole verification).
Verification methods include:
• Visual inspection of the original document in person or via secure video verification;
• Comparison of the document photograph with the individual's live image;
• Use of third-party electronic identity verification services;
• Cross-referencing document details with official government databases where available.
Proof of address is verified using a document issued within the last three (3) months, such as a utility bill, bank statement, or official government correspondence.
13. Corporate Customer Verification
For corporate Customers, the Company verifies the following:
• Legal existence and good standing of the entity through a certified copy of the certificate of incorporation or commercial registration;
• Articles of association, memorandum of association, or equivalent constitutional documents;
• Certificate of good standing or equivalent (if applicable);
• Valid trade license (for UAE-registered entities);
• List of directors, officers, and authorized signatories;
• Shareholder register or equivalent document showing ownership structure;
• Board resolution or authorization letter confirming the engagement of the Company's Services;
• Identity verification of all directors, authorized signatories, and beneficial owners (as per individual verification requirements).
14. Ultimate Beneficial Owner (UBO) Verification
The Company is required to identify and verify the Ultimate Beneficial Owner(s) of all corporate Customers. A Beneficial Owner is any natural person who ultimately owns or controls the Customer, directly or indirectly, through ownership of shares, voting rights, or other means.
The ownership threshold for identifying a Beneficial Owner is twenty-five percent (25%) or more of the shares or voting rights. Where no natural person meets this threshold, the senior managing official(s) of the entity are treated as the Beneficial Owner(s).
UBO verification includes:
• Obtaining a declaration of beneficial ownership from the Customer;
• Reviewing the shareholder register, partnership agreement, trust deed, or equivalent documents;
• Verifying the identity of each Beneficial Owner using individual verification procedures;
• Screening each Beneficial Owner against sanctions lists, PEP databases, and adverse media sources;
• Documenting the ownership and control structure of the entity.
For complex ownership structures (e.g., multi-layered holdings, trusts, nominee arrangements), the Company requires a detailed ownership chart and may require additional documentation to trace ownership to the natural person level.
15. Politically Exposed Persons (PEPs)
The Company screens all Customers and Beneficial Owners against PEP databases as part of the onboarding process and on an ongoing basis.
The PEP categories covered include:
• Foreign PEPs: individuals who are or have been entrusted with prominent public functions by a foreign country;
• Domestic PEPs: individuals who are or have been entrusted with prominent public functions by the UAE;
• International organization PEPs: individuals who are or have been entrusted with a prominent function by an international organization;
• Family members: parents, children, siblings, spouses, and partners of PEPs;
• Close associates: individuals known to have close business or personal relationships with PEPs.
Where a Customer or Beneficial Owner is identified as a PEP:
• Enhanced Due Diligence is applied;
• Senior management approval is required before establishing the business relationship;
• The source of funds and source of wealth are verified;
• The business relationship is subject to enhanced ongoing monitoring.
16. Sanctions Screening
The Company screens all Customers, Beneficial Owners, directors, authorized signatories, and agents against applicable Sanctions Lists before establishing a business relationship and on an ongoing basis.
Sanctions Lists screened include:
• United Nations Security Council Consolidated List;
• UAE Local Terrorist List;
• UAE Cabinet Resolution lists;
• U.S. Office of Foreign Assets Control (OFAC) Specially Designated Nationals and Blocked Persons List;
• UK HM Treasury Consolidated List of Financial Sanctions Targets;
• European Union Consolidated List;
• Other applicable national and international sanctions lists.
If a positive sanctions match is identified:
• The onboarding or transaction is immediately halted;
• Senior management and the AML Compliance Officer are notified immediately;
• No business relationship is established or continued;
• A report is filed with the FIU and the Executive Office for Control and Non-Proliferation as required by law;
• All records relating to the match are retained for at least five (5) years.
17. Adverse Media Screening
The Company conducts adverse media screening on all Customers and Beneficial Owners as part of the onboarding process and on an ongoing basis. Adverse media screening involves searching publicly available information for indications of criminal activity, financial crime, corruption, fraud, sanctions violations, terrorism, or other unlawful conduct.
Sources of adverse media include:
• International and local news outlets;
• Regulatory enforcement actions and disciplinary records;
• Court records and litigation databases;
• Law enforcement alerts and watchlists;
• Specialized risk intelligence databases.
Where adverse media is identified, the Company assesses the relevance, credibility, and severity of the information. If the adverse media raises material concerns about ML/TF risk, Enhanced Due Diligence is applied and senior management approval is required before proceeding.
18. Source of Funds Verification
The Company verifies the source of funds for all transactions and engagements. Source of funds verification is designed to ensure that the funds used to pay for Services are derived from legitimate sources.
Customers may be required to provide documentary evidence of the source of funds, including:
• Bank statements showing the origin of funds;
• Employment income documentation (salary slips, employment contracts);
• Business income documentation ( audited financial statements, tax returns);
• Investment income documentation (dividend statements, investment account statements);
• Sale of property or asset documentation;
• Inheritance documentation;
• Loan documentation (if funds are borrowed);
• Gift documentation and donor verification.
Enhanced source of funds verification is required for: high-value transactions, transactions involving cash, transactions from high-risk jurisdictions, and Customers identified as PEPs.
19. Source of Wealth Verification
Source of wealth verification is conducted for high-risk Customers, PEPs, and Customers involved in high-value transactions. Source of wealth refers to the total financial position of the Customer and the origin of their overall wealth.
Customers may be required to provide:
• A written statement describing the origin of their wealth;
• Supporting documentation such as property valuations, business valuations, investment portfolios, or inheritance documents;
• Tax returns or financial statements evidencing accumulated wealth;
• Any other documentation the Company deems necessary to verify the legitimacy of the Customer's wealth.
20. Ongoing Monitoring
The Company conducts ongoing monitoring of all business relationships to ensure that transactions and activities are consistent with the Company's knowledge of the Customer, their business, and risk profile.
Ongoing monitoring includes:
• Periodic review of Customer identification documents (at least annually for high-risk Customers and every three (3) years for standard-risk Customers);
• Updating Customer risk profiles based on new information or changed circumstances;
• Re-screening Customers against sanctions lists and PEP databases;
• Monitoring for changes in beneficial ownership;
• Reviewing transaction patterns for unusual or suspicious activity.
21. Transaction Monitoring
The Company monitors all transactions to detect unusual or suspicious patterns that may indicate money laundering, terrorism financing, or other financial crime.
Indicators that may trigger further investigation include:
• Transactions that are unusually large or complex;
• Transactions that have no apparent economic or lawful purpose;
• Transactions involving cash payments above the threshold specified by the UAE AML Law;
• Transactions involving high-risk jurisdictions;
• Unusual patterns of transactions that are inconsistent with the Customer's known profile;
• Transactions involving third parties not connected to the engagement;
• Rapid movement of funds through multiple accounts or jurisdictions;
• Requests to structure transactions to avoid reporting thresholds.
Where suspicious activity is detected, the Company will file a Suspicious Activity Report (SAR) with the FIU as required by law.
22. Identity Verification Documents
The following documents are accepted for identity verification, subject to the Company's assessment of their authenticity and validity:
• Passport (international travel document issued by a recognized government);
• National identity card (issued by the Customer's country of citizenship);
• Emirates ID (issued by the Federal Authority for Identity and Citizenship for UAE residents);
• Residence permit or visa (as supplementary evidence);
• Driving license (as supplementary evidence only).
All identification documents must be valid (not expired) and must be presented in original form or as a certified true copy. Documents in languages other than English or Arabic must be accompanied by a certified translation.
23. Passport Verification
Passports are verified through the following methods:
• Visual inspection of security features (watermarks, holograms, machine-readable zones, biometric chips);
• Comparison of the passport photograph with the individual's live image;
• Use of electronic passport verification services where available;
• Checking the passport against lost, stolen, and invalidated passport databases where available;
• Verifying the issuing authority's authenticity.
Passports must be valid for at least six (6) months from the date of verification. Passports from unrecognized or disputed jurisdictions are not accepted.
24. Emirates ID Verification
For UAE residents, the Emirates ID is verified through:
• Visual inspection of the physical card, including security features;
• Reading the Emirates ID chip using approved electronic readers where available;
• Cross-referencing with the Federal Authority for Identity and Citizenship (ICA) database;
• Verifying the card number format and validity period.
An expired Emirates ID is not accepted for verification purposes. The Customer must renew their Emirates ID before Services can commence.
25. Corporate Documentation Requirements
Corporate Customers must provide the following documentation:
• Certificate of incorporation or commercial registration (certified true copy);
• Memorandum and articles of association (or equivalent constitutional documents);
• Valid trade license (for UAE entities);
• Shareholder register showing all shareholders and their ownership percentages;
• Director register showing all current directors;
• Register of beneficial owners;
• Board resolution or power of attorney authorizing the engagement;
• Audited financial statements (for the most recent financial year, where available);
• Certificate of incumbency or good standing (where applicable).
26. Document Authentication
The Company may require document authentication for certain documents, including:
• Notarization by a recognized notary public;
• Attestation by the Ministry of Foreign Affairs of the issuing country;
• Attestation by the UAE Embassy or Consulate in the issuing country;
• Legal translation and certification (for documents not in English or Arabic);
• Apostille certification (for documents from Hague Convention member countries).
The specific authentication requirements depend on the nature of the document, the issuing jurisdiction, and the intended use of the document. The Company will advise the Customer of the applicable authentication requirements on a case-by-case basis.
27. False or Forged Documents
The submission of false, forged, altered, tampered with, counterfeit, or fraudulently obtained documents is strictly prohibited. The Company maintains a zero-tolerance policy towards document fraud.
If the Company suspects or determines that a document is false or forged:
• The onboarding process or engagement is immediately halted;
• All documents and communications relating to the Customer are retained;
• A Suspicious Activity Report (SAR) is filed with the FIU where required by law;
• The matter may be reported to law enforcement authorities;
• The Customer is refused Services and may be permanently barred from future engagement;
• No refund will be provided for any fees paid.
The Company uses document verification technologies, including AI-assisted fraud detection tools, to identify potentially fraudulent documents.
28. High-Risk Jurisdictions
High-risk jurisdictions are countries or territories identified by the FATF as having strategic deficiencies in their AML/CFT regimes ("grey list" and "black list" jurisdictions), as well as jurisdictions subject to enhanced monitoring by international organizations.
Customers from or with business connections to high-risk jurisdictions are subject to Enhanced Due Diligence. Additional measures may include:
• Enhanced verification of identity and beneficial ownership;
• Enhanced source of funds and source of wealth verification;
• Senior management approval for the engagement;
• Enhanced ongoing monitoring;
• Additional adverse media screening.
The list of high-risk jurisdictions is updated regularly based on FATF publications and other authoritative sources.
29. Restricted Countries
Restricted countries are jurisdictions subject to comprehensive international sanctions or embargoes, or jurisdictions designated by the UAE government as prohibited for business transactions.
The Company does not provide Services to Customers from restricted countries, or to Customers with beneficial owners, directors, or authorized signatories from restricted countries, except where explicitly authorized by the relevant sanctions authority or as permitted by Applicable Law.
Restricted country determinations are based on:
• United Nations Security Council sanctions resolutions;
• UAE Cabinet sanctions designations;
• U.S. OFAC comprehensive sanctions programs;
• EU Council sanctions regulations;
• UK HM Treasury sanctions designations.
30. Refusal of Service
The Company reserves the right to refuse Services to any person or entity where:
• The Customer fails to provide satisfactory identification or verification documentation;
• The Customer is identified as a match on a Sanctions List;
• The Customer is a PEP and senior management approval is not obtained;
• The Customer is from a restricted country;
• The Customer's risk profile exceeds the Company's risk appetite;
• The Company suspects that the Services may be used for illegal purposes;
• The Customer provides false, misleading, or fraudulent information;
• Providing Services would violate Applicable Law.
The Company is not required to provide reasons for refusing Services where disclosure would compromise AML/CFT investigations or tip off the Customer.
31. Suspension of Services
The Company may suspend Services to a Customer at any time where:
• The Customer fails to provide requested AML/KYC documentation within a reasonable timeframe;
• The Company identifies a change in the Customer's risk profile that requires further investigation;
• A sanctions screening alert requires further review;
• The Company suspects suspicious activity and is conducting an internal investigation;
• The Customer's behavior raises compliance concerns.
During suspension, the Company will not process any new transactions or submissions on behalf of the Customer. Suspension does not affect the Customer's obligation to pay all fees and charges incurred prior to the suspension.
32. Termination of Business Relationship
The Company may terminate a business relationship at any time, with or without notice, where:
• The Customer is confirmed as a match on a Sanctions List;
• The Customer is convicted of a financial crime or other serious offense;
• The Customer repeatedly provides false or misleading information;
• The Company files a Suspicious Activity Report with the FIU;
• The Customer fails to cooperate with the Company's AML/CFT procedures;
• Continuing the relationship would violate Applicable Law;
• The Company determines that the risk of the relationship is unacceptable.
Upon termination, all outstanding fees and charges remain payable. No refund will be provided where termination is due to AML/CFT concerns.
33. Suspicious Activity Detection
All employees and agents of the Company are trained to detect suspicious activities and transactions. Suspicious activity indicators include:
• Reluctance to provide identification or verification documents;
• Inconsistent or contradictory information provided by the Customer;
• Complex ownership structures with no apparent commercial rationale;
• Use of nominees, shell companies, or trusts to obscure ownership;
• Requests to structure payments to avoid thresholds;
• Unusual urgency in processing without reasonable explanation;
• Transactions involving jurisdictions known for ML/TF risks;
• Significant changes in the nature or volume of transactions;
• Cash payments above prescribed thresholds;
• Customers with no apparent connection to the UAE seeking services.
Any employee who detects suspicious activity must immediately report it to the AML Compliance Officer.
34. Suspicious Transaction Reporting
Where the Company knows, suspects, or has reasonable grounds to suspect that a transaction or activity involves proceeds of crime, money laundering, terrorism financing, or proliferation financing, the Company is required to file a Suspicious Activity Report ("SAR") with the FIU.
SAR filing procedures:
• The SAR must be filed promptly, and in any event no later than thirty-five (35) calendar days from the date of detection;
• The SAR is filed electronically through the FIU's goAML portal;
• All supporting documentation is retained;
• The Customer is not informed of the SAR filing ("tipping off" is a criminal offense under UAE law).
The decision to file a SAR is made by the AML Compliance Officer or their designated deputy. Filing a SAR does not automatically result in termination of the business relationship, unless required by law or instructed by the FIU.
35. Cooperation with Government Authorities
The Company cooperates fully with all government authorities, regulators, and law enforcement agencies in the prevention and detection of financial crime. This cooperation includes:
• Responding promptly to information requests from the FIU, law enforcement, and regulatory authorities;
• Providing access to records, documents, and information as required by law;
• Facilitating interviews and on-site inspections;
• Implementing regulatory directives and corrective measures;
• Attending training and awareness programs organized by supervisory authorities.
The Company will not inform the Customer of any inquiry, investigation, or information request relating to the Customer unless required by law to do so.
36. Confidentiality of AML Investigations
All AML/CFT investigations, SAR filings, and related internal procedures are treated as strictly confidential.
Confidentiality obligations include:
• Employees must not disclose SAR filings or AML investigations to any person other than those authorized to receive such information;
• Customers must not be informed ("tipped off") that a SAR has been filed or that an investigation is underway;
• AML records are stored separately from general business records;
• Access to AML records is restricted to authorized personnel only.
Breach of AML confidentiality is a serious matter and may result in disciplinary action, including termination of employment, and may constitute a criminal offense under UAE law.
37. Record Retention
The Company retains all AML/KYC records for a minimum period of five (5) years from the date of termination of the business relationship or the date of the transaction, whichever is later. Records retained include:
• Customer identification and verification documents;
• CDD, EDD, and SDD records and risk assessments;
• Transaction records and supporting documentation;
• SAR filings and related correspondence;
• Sanctions, PEP, and adverse media screening results;
• Source of funds and source of wealth documentation;
• Internal audit and compliance review records;
• Employee training records.
Records are retained in a secure manner, with access restricted to authorized personnel. Electronic records are stored with encryption and access controls. Paper records are stored in locked facilities.
38. Data Protection
The Company processes personal data collected for AML/KYC purposes in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and our Privacy Policy.
Personal data collected for AML/KYC purposes is:
• Processed lawfully, fairly, and transparently;
• Collected for specified, explicit, and legitimate purposes;
• Adequate, relevant, and limited to what is necessary;
• Accurate and kept up to date;
• Retained only for as long as required by law;
• Processed securely with appropriate technical and organizational measures.
Customers have the right to access their personal data and request corrections of inaccurate data, subject to legal restrictions on disclosure of SAR information.
39. Cross-Border Information Sharing
The Company may share AML/KYC information with foreign affiliates, correspondent entities, and regulatory authorities in other jurisdictions where permitted by Applicable Law and where necessary for AML/CFT compliance.
Cross-border information sharing is subject to:
• Compliance with data protection laws in both the sending and receiving jurisdictions;
• Appropriate safeguards, including data sharing agreements and confidentiality undertakings;
• Legitimate purposes related to AML/CFT compliance;
• Regulatory authorization where required.
40. Employee AML Responsibilities
All employees, directors, officers, and agents of the Company are required to:
• Comply with this Policy and all applicable AML/CFT laws and regulations;
• Complete AML/CFT training upon commencement of employment and at least annually thereafter;
• Report any suspicious activity or transaction to the AML Compliance Officer immediately;
• Maintain the confidentiality of all AML/CFT investigations and SAR filings;
• Cooperate with internal and external AML/CFT audits and reviews;
• Ensure that Customer due diligence is completed before Services commence.
Failure to comply with AML/CFT obligations may result in disciplinary action, including termination of employment, and may expose the employee to criminal liability.
41. Third-Party Verification Providers
The Company engages third-party service providers to assist with identity verification, sanctions screening, PEP screening, adverse media screening, and electronic identity verification.
Third-party providers are selected based on their:
• Regulatory licenses and certifications;
• Data security and privacy standards;
• Coverage of sanctions lists, PEP databases, and adverse media sources;
• Accuracy and reliability of screening results;
• Compliance with Applicable Law.
The Company maintains written agreements with all third-party providers that include data protection obligations, confidentiality requirements, and service level agreements.
42. Digital Identity Verification
The Company uses digital identity verification technologies to verify the identity of Customers remotely. Digital identity verification may include:
• Biometric verification (facial recognition, liveness detection);
• Document authentication using machine-readable zone (MRZ) verification;
• Electronic identity verification against government databases;
• Video-based identity verification with trained operators.
Digital identity verification results are used in conjunction with, and do not replace, documentary verification. Where digital verification results are inconclusive, additional verification measures are applied.
43. Electronic Verification
Electronic verification involves using independent electronic data sources to verify a Customer's identity. Sources may include:
• Credit reference agencies;
• Electoral registers;
• Government tax databases;
• Utility company records;
• Financial institution databases.
Electronic verification is not used as the sole method of identity verification unless the electronic source is sufficiently comprehensive and reliable. The Company requires at least two independent electronic data sources for verification purposes.
44. AI-Assisted Fraud Detection
The Company uses artificial intelligence ("AI") and machine learning technologies to assist in the detection of fraudulent documents, suspicious activities, and unusual transaction patterns.
AI-assisted fraud detection may be used for:
• Automated document analysis to detect alterations, forgeries, and counterfeit documents;
• Facial recognition and liveness detection for identity verification;
• Pattern analysis to identify unusual transactions or behaviors;
• Risk scoring and automated alerts for compliance review.
AI-assisted fraud detection operates under human oversight. All AI-generated alerts are reviewed by trained compliance personnel before any action is taken. AI technologies are used in compliance with Applicable Law, including data protection requirements and anti-discrimination principles.
45. Fraud Prevention Measures
The Company implements the following fraud prevention measures:
• Multi-layered identity verification combining documentary, biometric, and electronic methods;
• Real-time sanctions, PEP, and adverse media screening;
• Document authentication using security feature detection;
• Transaction monitoring and pattern analysis;
• Regular review and updating of fraud detection algorithms and rules;
• Employee training on fraud detection and prevention;
• Secure storage and handling of Customer documents;
• Access controls and audit trails for all AML/KYC systems.
46. Anti-Bribery and Anti-Corruption Commitment
The Company has a zero-tolerance policy towards bribery and corruption. The Company complies with all applicable anti-bribery and anti-corruption laws, including the UAE Penal Code and Federal Decree-Law No. 20 of 2018.
The Company prohibits:
• Offering, promising, giving, or authorizing any bribe, kickback, or improper payment to any person;
• Soliciting or accepting any bribe, kickback, or improper payment from any person;
• Using intermediaries, agents, or third parties to engage in bribery or corruption;
• Facilitating payments, regardless of local customs or practices.
Any employee found to have engaged in bribery or corruption will be subject to immediate termination and may be reported to law enforcement authorities.
47. Customer Responsibilities
All Customers have the following responsibilities under this Policy:
• Provide accurate, complete, and truthful information and documentation;
• Promptly notify the Company of any changes to their identification information, address, or circumstances;
• Cooperate with the Company's AML/KYC procedures, including providing additional information and documentation upon request;
• Ensure that all beneficial owners, directors, and authorized signatories cooperate with verification procedures;
• Not use the Company's Services for any illegal purpose, including money laundering or terrorism financing;
• Comply with all applicable sanctions laws and regulations.
48. False Declarations
Any false declaration, misrepresentation, or omission of material information by a Customer is a serious breach of this Policy and may constitute a criminal offense under UAE law.
Consequences of false declarations include:
• Immediate refusal, suspension, or termination of Services;
• Forfeiture of all fees paid;
• Filing of a Suspicious Activity Report with the FIU;
• Reporting to law enforcement authorities;
• Civil and criminal liability under UAE law.
The Company reserves the right to recover all costs and losses incurred as a result of false declarations through legal proceedings.
49. Limitation of Liability
To the maximum extent permitted by Applicable Law, the Company shall not be liable for any loss, damage, delay, or adverse outcome arising from:
• The Company's compliance with its AML/CFT obligations;
• The refusal, suspension, or termination of Services for AML/CFT reasons;
• The reporting of suspicious activities to the FIU or other authorities;
• Delays caused by AML/KYC verification procedures;
• The use of third-party verification providers.
Nothing in this Policy shall exclude or limit the Company's liability for fraud, willful misconduct, gross negligence, or any other liability that cannot be excluded or limited under Applicable Law.
50. Regulatory Cooperation
The Company is committed to full cooperation with all regulatory authorities, including the Ministry of Economy, RAKEZ, the FIU, the Executive Office for Control and Non-Proliferation, and other competent authorities.
The Company:
• Submits to regulatory inspections and examinations without obstruction;
• Implements corrective measures identified by regulators in a timely manner;
• Provides regular compliance reports to supervisory authorities as required;
• Maintains an open and transparent relationship with regulators.
51. Changes to this Policy
The Company reserves the right to modify, amend, or update this Policy at any time to reflect changes in laws, regulations, business operations, or risk appetite. Material changes will be notified to Customers by posting a prominent notice on the Website or by sending an email at least fifteen (15) days before such changes take effect.
The version of this Policy in force at the time of the engagement governs the AML/KYC obligations for that engagement.
52. Contact Information
For questions or concerns regarding this Policy, or to submit AML/KYC documentation, please contact:
| Email: | legal@zenvisa.net |
|---|---|
| Address: | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE |
| Website: | https://www.zenvisa.net |
| Response Time: | Within five (5) Business Days |
53. Governing Law
This Policy shall be governed by and construed in accordance with the laws of the United Arab Emirates, as applied in the Emirate of Ras Al Khaimah, without regard to its conflict of law principles.
54. Jurisdiction
The courts of the United Arab Emirates, and specifically the courts of the Emirate of Ras Al Khaimah, shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy, subject to the arbitration provisions set out in the Terms of Use.
55. Severability
If any provision of this Policy is held to be invalid, illegal, or unenforceable, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if modification is not possible, severed from this Policy. The remaining provisions shall continue in full force and effect.
56. Entire Policy
This Policy, together with the Terms of Use, Privacy Policy, Cookie Policy, Refund & Cancellation Policy, and Website Disclaimer, constitutes the entire framework of policies governing the Company's operations. This Policy supersedes all prior or contemporaneous AML/KYC policies, procedures, and understandings.
--- END OF AML/KYC POLICY ---
ZenVisa International
Your Trusted Partner in Business Documentation
Zenway International FZ-LLC | Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE
<www.zenvisa.net> | legal@zenvisa.net
Licensed by Ras Al Khaimah Economic Zone Authority (RAKEZ)
© 2026 Zenway International FZ-LLC. All Rights Reserved.