Loading…
KYC, Due Diligence & Compliance

KYC and Compliance Policy

Important information regarding customer verification, account opening procedures, due diligence, transaction monitoring, and compliance controls.

About This Policy

This KYC and Compliance Policy explains the customer-identification, due-diligence, screening, monitoring and related compliance requirements applied by GTC Global Trading Ltd when providing services through the GTCFX /en-intl website.

This is a client-facing summary and should be read together with the Client Agreement, Privacy Policy, Restricted Countries Notice, Deposit and Refund Policy and Complaint Handling Policy.

Key Notice

Identity, address, authority and beneficial ownership must be verified using reliable, independent information before services are made available.

KYC is continuous and updated information may be requested during the client relationship.

Enhanced due diligence may apply to higher-risk customers, transactions or relationships.

The Company may restrict, reject, suspend or terminate activity where verification or compliance requirements are not satisfied.

Never share passwords, PINs, one-time codes, CVV/CVC data, recovery phrases or private keys.

01

Company and Scope

Legal name: GTC Global Trading Ltd (the "Company", "we", "us" or "our")

Company number: 16283

Legal form and jurisdiction: A private limited company incorporated under the laws of the Autonomous Island of Anjouan, Union of the Comoros

Licence: Licence no. L16283/GTC issued by the Anjouan Offshore Finance Authority ("AOFA")

Registered address: Boulevard de Coalancanthe, Mutsamudu, Anjouan, Union of the Comoros

Website: https\://www\.gtcfx.com/en-intl/

This Policy applies only where the Client Agreement identifies GTC Global Trading Ltd as the contracting entity. "GTCFX" is a brand reference and is not a separate legal person. An account with another group entity is governed by that entity's documents and must not be represented as an account of the Company.

The Company's onboarding process assigns the contracting entity having regard to jurisdiction, client classification, product availability and applicable restrictions. An applicant may not select, substitute or route an application, account or payment through another GTC group entity to obtain less restrictive KYC, leverage, product or legal terms. KYC completed for another entity is not automatically portable to the Company unless lawful reliance requirements are met and the Company has prompt access to the required records.

The licence applies only to GTC Global Trading Ltd and only within the scope stated by AOFA. It does not extend to another group entity or jurisdiction and is not a guarantee that an applicant will be accepted, that a transaction will be processed, or that any financial-crime risk has been eliminated.

The Client Agreement governs the account and financial services. This Policy governs the client-facing KYC and compliance process. If there is an inconsistency, mandatory legal, sanctions, licence or authority requirements prevail; otherwise the Client Agreement prevails on contractual matters. Rights that cannot lawfully be excluded remain unaffected.

02

02

Core Principles and Risk-Based Approach

In this Policy, "Applicable Requirements" means the laws, regulations, licence conditions, regulatory or authority directions, court orders and binding sanctions applicable to the Company, relationship or transaction, together with payment-scheme and provider requirements that lawfully apply to the relevant channel.

The Company uses the Financial Action Task Force ("FATF") standards as an international risk-based benchmark where appropriate. FATF does not license or supervise the Company, and its standards do not themselves grant the Company a power or remove a client right; binding obligations arise from Applicable Requirements and the relevant contracts.

The Company applies a risk-based approach to money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud, corruption, market abuse, tax crime and other unlawful activity relevant to the services it provides. Controls are calibrated to the client, ownership structure, product, delivery channel, payment method, geography, expected activity and other reliable risk indicators.

Customer due diligence includes identifying and verifying the client and any person acting for the client; identifying and taking reasonable measures to verify each beneficial owner; understanding the purpose and intended nature of the relationship; establishing an expected activity profile; and conducting ongoing monitoring. Information must be reliable, current, proportionate and sufficient for the risk identified.

Simplified due diligence may be used only where applicable requirements permit it and the Company has documented a lower risk. It will not be used where there is suspicion of money laundering, terrorist financing or proliferation financing, doubt about previously obtained information, or another factor requiring enhanced review.

Enhanced due diligence is applied where risk is higher. It may include additional identity or ownership evidence, source-of-funds or source-of-wealth verification, senior management approval, corroboration from independent sources, more frequent review and enhanced transaction monitoring.

Risk indicators are considered together and in context. Nationality, residence, a politically exposed person classification, the use of an offshore company, unusual trading losses or adverse media does not by itself establish wrongdoing. Equally, a reputable introducer, professional adviser, group relationship or bank reference does not replace the Company's own due diligence.

The Company maintains written controls, designated compliance responsibility, staff training, quality assurance and independent review arrangements proportionate to its business and applicable requirements. Exact internal rules and alert thresholds are confidential because publication could enable evasion.

03

03

When KYC Applies and Customer Acceptance

KYC and screening may apply to an applicant, client, beneficial owner, controller, director, partner, trustee, settlor, protector, beneficiary, authorised signatory, attorney, payer, payee, wallet owner, introducer and any other person relevant to the relationship or transaction.

The Company normally completes required identification and verification before activating a live account, permitting trading or accepting or releasing funds. If delayed verification is expressly permitted by applicable requirements and the risk can be effectively controlled, the Company may limit account functionality and must complete verification as soon as reasonably practicable. No client has a right to delayed verification.

KYC may also be required when an occasional transaction is proposed; a material account change occurs; ownership, control or authority changes; a document expires; the expected activity changes; the Company doubts the accuracy or adequacy of existing information; a sanctions or adverse-media alert arises; or suspicious or unusual activity is identified.

Acceptance is not based on document collection alone. The Company considers whether it understands the client, beneficial ownership, purpose, expected activity and funding, and whether the relationship is within the Company's risk appetite, licensing scope, product governance and jurisdictional restrictions.

The Company does not maintain anonymous, fictitious-name or undisclosed nominee accounts. A disclosed nominee, fiduciary or agency relationship may be considered only when the legal capacity, underlying principal, ownership, control, purpose and funding have been satisfactorily established.

04

04

Individuals

An individual applicant may be required to provide the full legal name, former or other names, date and place of birth, nationality or nationalities, permanent residential address, contact details, occupation or business, tax residence and tax identification number where applicable, account purpose, expected activity and other information reasonably required for verification and risk assessment.

Identity is normally verified using an unexpired passport, national identity card or other government-issued photographic identification from a reliable source. Address may be verified through an appropriate document or reliable electronic source. A document, source or combination of sources acceptable for one client may be insufficient for another where authenticity, recency, consistency or risk differs.

The Company may use electronic verification, database checks, document-authenticity review, a selfie or liveness check, video verification, device and network indicators, or another proportionate method. A certified copy or certified translation may be requested where necessary, but certification and an introduction are not substitutes for risk-based verification.

Documents must be complete, legible and genuine and must not be altered, fabricated or misleading. Information unrelated to the verification purpose may be redacted only where the Company permits it and the remaining information is sufficient. The Company may request the original, a clearer copy, a translation or additional corroboration.

A person acting for an individual must provide evidence of identity and authority. The Company may contact the client through verified details to confirm the mandate and may refuse or limit a power of attorney where its scope, authenticity, continuing validity or purpose is not satisfactory.

05

07

PEPs and Higher-Risk Relationships

A politically exposed person ("PEP") is an individual who is or has been entrusted with a prominent public function, including a relevant domestic, foreign or international-organisation function. Risk-based measures also apply to family members and close associates as defined by applicable requirements and Company procedures.

PEP status is a preventive risk classification and does not imply criminal conduct. Before establishing or continuing a higher-risk PEP relationship, the Company may require senior management approval, establish and corroborate source of wealth and source of funds, understand the purpose of the relationship and apply enhanced ongoing monitoring. Former status is assessed by continuing risk rather than removed automatically after a fixed period.

Other higher-risk factors may include material adverse information from reliable sources, complex or opaque ownership, unexplained third-party funding, high-risk products or payment methods, non-face-to-face risks that are not adequately mitigated, unusual cross-border activity, sanctions exposure, high-risk geography, a business vulnerable to corruption or financial crime, or activity inconsistent with the client profile.

Adverse media and screening results are assessed for relevance, reliability, seriousness, recency and identity match. An apparent match or allegation is not treated as conclusive without reasonable review. The Company may seek clarification and supporting evidence, subject to legal restrictions on disclosure.

A client may be accepted, restricted, subject to enhanced controls or declined according to the total risk and the availability of effective mitigation. The Company will not use simplified procedures merely because the client is known to staff, introduced by an existing client or associated with another group entity.

08

08

Sanctions and Restricted Jurisdictions

The Company screens relevant persons, entities, payment parties and transactions against United Nations Security Council sanctions and other sanctions, asset-freeze measures and restrictions legally binding on the Company or relevant transaction. Banks, liquidity providers, payment providers and counterparties may also apply lawful restrictions that affect whether a service or transaction can proceed.

Screening may cover names, aliases, dates of birth, nationalities, identification numbers, addresses, ownership, control, directors, authorised persons, payers, payees, banks, wallet addresses and other available identifiers. Screening is performed at onboarding, on a risk-based ongoing basis and when relevant lists or client information changes.

A potential match may require a temporary hold while identity and legal obligations are assessed. Where a confirmed match or applicable restriction requires it, the Company may reject, block, freeze, return or refrain from dealing with funds or assets and may report to or seek direction from a competent authority. The Company will not release or redirect restricted funds merely at the client's request.

The Restricted Countries Notice and onboarding controls determine where services are unavailable. FATF high-risk and increased-monitoring statements, national risk information and other credible sources inform the Company's risk assessment, but a country appearing on a monitoring list does not by itself require automatic rejection unless a legal, regulatory, provider or Company restriction applies.

The Company does not permit a client to use a proxy, VPN, false address, intermediary, nominee or alternate group entity to evade a geographic, sanctions, eligibility or product restriction. Location and device information may be used proportionately to detect attempted circumvention and fraud.

09

09

Source of Funds, Source of Wealth and Payments

Source of funds describes the origin of money or other value used for a particular deposit or relationship. Source of wealth describes how the client or beneficial owner accumulated overall wealth. The Company may request one or both where necessary for the risk, transaction, account activity or applicable requirements.

Evidence may include employment or business income records, audited accounts, tax records, bank or investment statements, sale agreements, inheritance or probate records, dividend or loan documentation, wallet transaction history, provider confirmations or other reliable evidence. A description without reasonable corroboration may be insufficient for higher-risk activity.

Funding must normally come from a payment method held in the verified client's name. Joint, corporate, trust or other non-individual funding requires prior approval and verification of ownership, authority, beneficial ownership and purpose. Anonymous, undisclosed third-party, cash-equivalent or pass-through funding is not accepted unless specifically supported and approved under applicable controls.

The Company may compare the payer, payment account, merchant or statement descriptor, funding currency, country, transaction reference and amount against the verified profile. A mismatch may result in a request for evidence, a hold, rejection, reversal or return to the verified source under the Deposit and Refund Policy.

The Company will not accept an explanation or document merely because it was supplied by a group company, introducer, payment provider or professional adviser. It may independently verify material information and examine whether a loan, gift, sale, business revenue or digital-asset transfer is genuine, lawful and economically consistent.

10

10

Remote Onboarding and Account Security

Remote onboarding is not treated as inherently unacceptable, but the Company applies controls to address impersonation, synthetic identity, forged or stolen documents, account takeover, automated abuse and the absence of physical presence. The combination of controls depends on the client, document, jurisdiction, device, delivery channel and risk.

Controls may include secure document capture, authenticity and data-consistency checks, trusted electronic data, biometric comparison or liveness, video contact, verified phone or email, multi-factor authentication, device and network analysis, duplicate-account detection and manual review. Where biometric or comparable sensitive data is used, the purpose, legal basis, provider and retention treatment must be addressed in the Privacy Policy or an appropriate notice.

Automated screening or verification may produce false matches or require manual review. The Company may request additional information before making a final decision where appropriate, but it is not required to disclose confidential models, vendor data, fraud indicators, sanctions-screening logic or information whose disclosure is legally restricted.

Clients must use only the authenticated MyGTC portal or another verified Company channel to upload documents. Company staff will not ask for an account password, online-banking password, PIN, full card security code, one-time authentication code, recovery phrase or digital-wallet private key. A full card number and CVV/CVC may be entered only into a verified secure payment page, and an authentication challenge only into the issuer's verified authentication page.

The client must protect credentials, devices and contact channels and must notify the Company promptly of suspected compromise, unauthorised access, a SIM swap, a changed email or phone number, loss of an identity document or any instruction not genuinely authorised by the client.

11

11

Ongoing Due Diligence and Monitoring

KYC does not end when an account is opened. The Company reviews the relationship and activity to determine whether they remain consistent with the verified identity, beneficial ownership, purpose, expected activity, source of funds, risk profile and information held by the Company.

Monitoring may consider deposits, withdrawals, payment ownership, transfers, trading and account behaviour, use of multiple instruments or accounts, transaction size and frequency, rapid movement of value, linked parties, device or location indicators, blockchain or wallet-risk information where relevant, and other patterns reasonably connected to financial-crime or fraud risk.

An unusual transaction is not automatically suspicious. The Company considers its commercial or lawful purpose, the client's known circumstances, market activity and available explanation. Excessive trading, losses, profitability, frequent transactions or the use of an offshore entity is not treated as conclusive in isolation.

The Company may conduct scheduled or event-driven KYC refreshes and may require renewed identification, proof of address, ownership or control records, corporate documents, financial information or an explanation and evidence for activity. Higher-risk relationships are reviewed more frequently and in greater depth.

Relevant material changes must be reflected in the client file without undue delay. If the Company cannot confirm that information remains accurate, complete and current, it may limit new activity, deposits, withdrawals or account instructions until remediation is complete.

The Company may review linked accounts or relationships where reasonably necessary to identify common ownership, control, devices, payment sources, beneficiaries, fraud or evasion. Such review must be based on a legitimate compliance, security or contractual purpose and handled under the Privacy Policy.

12

12

Digital-Asset Payment Channels

Where the Company makes a digital-asset payment channel available, KYC and transaction controls may cover the wallet owner, wallet address, asset, network, transaction hash, sending or receiving provider, originator and beneficiary information, source of the asset, transaction history and sanctions or illicit-finance exposure. The exact evidence required depends on the channel and risk.

The Company may use a specialist blockchain-analytics or payment provider and may request a wallet-ownership check, a small verification transaction, exchange statement, purchase history, wallet screenshot or other evidence. A wallet address supplied by the client is not treated as verified ownership merely because the client can copy or nominate it.

A digital-asset transaction may be delayed, rejected or returned where the asset, network, wallet, provider, originator or beneficiary information is unsupported, incomplete or inconsistent; where required confirmations are absent; or where sanctions, fraud, stolen-funds, mixer, darknet, ransomware or other material illicit-finance exposure cannot be satisfactorily resolved.

Where applicable to an involved provider or transaction, additional payment-transparency or originator and beneficiary information may be required. The client must not structure, split or route transactions to avoid information requirements, monitoring or provider controls.

Availability of a digital-asset payment rail does not by itself mean that the Company provides a separate virtual-asset exchange, custody, transfer or investment service. Trading a Crypto CFD does not give the client ownership of the referenced virtual asset. The Deposit and Refund Policy governs payment denomination, conversion and return mechanics.

13

13

Incomplete Verification and Compliance Actions

If required due diligence cannot be completed, information is materially inconsistent or unreliable, or the Company cannot understand the ownership, control, purpose or funding of a relationship, the Company will not establish or carry out the affected relationship or transaction except to the limited extent permitted by applicable requirements. It may restrict or terminate an existing relationship and consider whether a report to a competent authority is required.

Where there is a reasonable compliance, sanctions, fraud, security, payment-provider or legal basis, the Company may request additional information; delay or reject onboarding; refuse, cancel, reverse or return a transaction; place funds or account functionality on hold; restrict deposits, trading or withdrawals; close positions where permitted by the Client Agreement and necessary to manage risk; suspend or close the account; or make a report or disclosure to a competent authority.

A discretionary hold will be reviewed at reasonable intervals and released, varied or followed by an appropriate return or account action when its basis ends. A legal freeze, court order, sanctions restriction, provider hold or authority direction may continue for the period required by that measure. Nothing in this Policy gives the Company unrestricted discretion to retain client funds.

The Company may submit a suspicious transaction or activity report, sanctions report or other required disclosure to the relevant financial intelligence unit, regulator, law-enforcement body or competent authority where required or permitted. The Company, its staff and service providers may be prohibited from informing the client that a report, review or investigation exists or from disclosing related information.

A request for information, review or restriction does not by itself establish that the client has committed wrongdoing. However, the Company is not obliged to process an instruction, disclose confidential control information or give a reason where doing so would breach law, facilitate evasion, prejudice an investigation or violate a lawful authority or provider restriction.

14

14

Records, Privacy, Sharing and Outsourcing

The Company retains identification, verification, beneficial-ownership, risk-assessment, screening, account, transaction and relevant communication records sufficient to reconstruct the relationship and transactions and to respond to a lawful request. Records are normally retained for at least five years after the relationship ends or an occasional transaction is completed, and longer where required by law, a licence condition, litigation, an investigation, an authority direction or another valid legal hold.

Personal data is collected and used for identity verification, compliance, fraud prevention, security, service administration, legal claims and other purposes described in the Privacy Policy. Collection must be proportionate to the purpose. Data will be deleted, anonymised or securely disposed of when applicable retention requirements end, subject to technical and legal limitations.

The Company may share necessary information with identity-verification, screening, fraud, cybersecurity, cloud, payment, banking, liquidity, professional-adviser and record-storage providers, other parties involved in a transaction, and regulators, financial intelligence units, law-enforcement bodies, courts or other competent authorities where there is a lawful and necessary basis.

Information is not exchanged with another financial institution or group entity merely because it may be useful. Group or third-party sharing must have a legitimate purpose, appropriate authority, access controls, confidentiality and data-protection safeguards. Cross-border transfers and provider processing must be addressed by the Privacy Policy and applicable contractual or legal safeguards.

The Company may rely on or outsource elements of due diligence only where permitted and subject to risk-based oversight, access to required information and records, confidentiality, service continuity and audit or assurance arrangements. Outsourcing does not transfer the Company's responsibility for compliance decisions made on its behalf.

A bank, payment provider, verification vendor, introducer or other service provider does not become the client's contracting entity merely because it performs a KYC, screening or payment function. The relevant account and services remain contracted with GTC Global Trading Ltd where the Client Agreement says so.

15

15

Client Duties, Complaints, Changes and Contact

Clients must provide complete, accurate, current and non-misleading information; answer reasonable requests within the stated timeframe; disclose the true beneficial owners, controllers, persons acting on the account and funding parties; and notify the Company promptly of a material change. A client must not submit forged or altered evidence, impersonate another person, conceal nominee or agency capacity, permit unauthorised account use or structure activity to evade controls.

A client's refusal or failure to provide information may prevent onboarding or activity even if the client believes the request is unnecessary. The Company should explain the general category and purpose of a request where lawful and practicable, but is not required to reveal confidential detection methods, third-party risk data or information subject to a tipping-off or other disclosure restriction.

A complaint about a KYC request, delay, data handling or account restriction may be sent from the client's registered email address to support\@gtcfx.com. It should identify the account, relevant date, request or transaction and the issue, but must not include passwords, authentication codes, private keys or unmasked card-security data.

The Company will handle a complaint under its Complaint Handling Policy, acknowledge receipt, provide a complaint reference where available and give reasonable status updates. A complaint does not require the Company to process an activity that remains legally or operationally restricted and does not override a sanctions freeze, reporting prohibition or authority direction. Mandatory rights to contact a competent authority remain unaffected.

The Company may update this Policy to reflect changes in law, licence conditions, FATF standards, sanctions, products, payment channels, technology, providers or risk. The revised Policy will display its last-updated date and take effect when published or on a later stated date. Material changes will be notified where required by applicable law.

The English version controls if a translation is inconsistent, to the extent permitted by applicable law. Questions about verification or document requirements may be sent to support\@gtcfx.com or raised through the authenticated MyGTC portal. Clients should confirm that a communication channel is genuine before sending documents.

Need Assistance?

Contact support for KYC or compliance questions

If you need clarification regarding customer verification, required documentation, beneficial ownership, or account compliance procedures, please contact the support team before proceeding.

GTC Go

GTCFX: GTC Go – Trade & Invest