AML & Sanctions Statement
How Bolimber prevents money laundering, terrorist financing and sanctions breaches.
Version 2026-09-21 · Public summary of our internal programme.
Bolimber holds crypto assets for customers and moves them between accounts and on-chain. That makes us a regulated business in most countries where we operate (a crypto-asset service provider in the EU, a cryptoasset business in the UK, a money services business in the US, and a virtual-asset service provider in the UAE). We apply the same programme everywhere:
- Know your customer. Email verification and two-factor authentication for every account; identity verification once withdrawals exceed a threshold or when risk indicators appear; enhanced checks for business sellers, high-volume accounts and politically exposed persons.
- Sanctions screening. Customers, business owners and withdrawal beneficiaries are screened against the UN, OFAC, OFSI, EU and UAE lists at onboarding and on an ongoing basis. Access is blocked from comprehensively sanctioned countries and regions.
- Transaction monitoring. Deposits, purchases and withdrawals are monitored for unusual patterns (structuring, rapid pass-through, mismatched geographies, use of mixers or sanctioned addresses). Withdrawals above a threshold require manual approval.
- Travel rule. For withdrawals above the applicable threshold we collect information about the destination and its beneficiary and share it with the receiving provider where required (EU Transfer of Funds Regulation, UK MLRs, US FinCEN rule, UAE requirements).
- Record keeping. Identity, transaction and ledger records are kept for at least five years after the relationship ends.
- Reporting. We file suspicious-activity reports with the competent financial-intelligence unit and cooperate with law enforcement. We do not tip off customers.
- Governance. A designated compliance officer (MLRO) owns the programme; staff are trained; the programme is reviewed annually and audited independently.
Questions: compliance@bolimber.com.