Anti-Money Laundering and Countering the Financing of Terrorism Policy
Version 1.0 · Last updated July 24, 2026 · Reviewed annually
Gruv Pte. Ltd. is a Singapore company. This policy explains how we check customers, review payment activity, work with licensed payment providers, and report suspected financial crime.
Gruv is not a bank or licensed payment institution. The MAS notices listed below apply to regulated institutions within their stated scope. We refer to them as relevant standards; citing them does not mean that Gruv holds a payment services licence.
1. Purpose
This policy explains how Gruv Pte. Ltd. (“Gruv”, “we”, “our”, or “us”) works to prevent money laundering, terrorism financing, proliferation financing, sanctions evasion, and related financial crime.
It sets the minimum standard for our business. Our compliance and operations teams use more detailed procedures for screening, reviews, investigations, and reporting. Those procedures and individual case records are confidential.
2. Who and what this policy covers
This policy applies to every director, officer, employee, contractor, and other person acting for Gruv. It covers the customers, sub-merchants, payees, contractors, creators, affiliates, and marketplace participants whose information or payment activity passes through our platform.
Gruv provides software, payment instructions, workflow controls, records, and reconciliation. We do not issue virtual accounts or hold customer funds. Licensed payment providers carry out the regulated payment activity under their own licences and terms.
A provider’s approval does not replace our own checks. We decide whom we serve and what activity we allow on Gruv.
3. Responsibility for this policy
Senior management approves this policy and must give the compliance function enough authority, information, and resources to apply it. Our designated AML/CFT Compliance Officer runs the day-to-day program.
The Compliance Officer may stop an onboarding, place activity on hold, ask for more information, decline a transaction, or end a relationship. A sales or commercial decision cannot override a compliance decision.
Anyone working for Gruv who sees possible financial crime must report it immediately through the internal compliance channel.
4. How we assess risk
We assess risk before accepting a customer and while the relationship continues. We look at the customer’s business, owners and controllers, countries, products, payment methods, counterparties, expected volumes, transaction patterns, and reason for using Gruv.
We review the company-wide risk assessment at least once a year. We also review it before launching a material new product, provider, country, payment method, or customer program.
Higher-risk activity receives closer review and stronger controls. We may decline activity even when it is not expressly prohibited by law.
5. Customer due diligence and beneficial ownership
We do not accept anonymous customers or customers using a false identity. Before enabling a financial feature, we collect and verify enough information to understand who the customer is, who controls it, and how it intends to use Gruv.
- For a business, this normally includes its legal name, registration or tax number, addresses, incorporation details, business activity, ownership and control structure, and authorised representatives.
- We identify the natural people who ultimately own or control the business and verify their identities using reliable information or documents.
- For an individual payee or contractor, we collect the identity, contact, and payout information required for the service and payment route.
- We record the expected payment purpose, countries, currencies, counterparties, frequency, and volume. We ask about the source of funds when needed.
6. When we carry out enhanced checks
Some customers and transactions need a closer review. Examples include politically exposed persons and their close family members or associates, complex ownership structures, links to high-risk countries, adverse information, unusual funding, sanctions concerns, or activity that does not fit the stated business.
We may ask for additional identity or company documents, evidence of source of funds or wealth, independent verification, or senior-management approval. We may also review the relationship more often and monitor it more closely.
If we cannot understand the risk or reduce it to an acceptable level, we will not proceed.
7. Sanctions screening
We screen customers, beneficial owners, controllers, representatives, payees, and relevant counterparties against the sanctions and terrorism-financing information that applies to the relationship. Screening takes place during onboarding, before relevant payment activity, after material changes, and during the relationship.
If screening produces a possible match, we pause the activity and review it. We do not knowingly provide services or resources to a designated person or support prohibited activity.
Where required, we hold or block the activity, work with the licensed payment provider, keep the relevant records, and notify the proper authority. We do not alert the person who is being reviewed.
8. Monitoring payment activity
We use system rules and manual reviews to identify payment activity that does not fit the customer’s profile or has no clear business or lawful purpose. The level of monitoring depends on the service and the risk.
- Transactions that are unusually large, complex, rapid, or repetitive.
- Payments split into smaller amounts to avoid checks or limits.
- Unexpected countries, counterparties, or third-party payments.
- Names, account holders, invoices, contracts, or payment purposes that do not match.
- Unusual refunds, reversals, failed payments, or rapid movement of newly received funds.
- Activity that does not match the customer’s business, expected volumes, or stated source of funds.
9. Activity we do not allow
We may pause, decline, return, restrict, or cancel activity when the law, a provider requirement, or our risk assessment calls for it. Gruv must not be used for:
- Handling proceeds of crime or supporting money laundering, terrorism financing, proliferation financing, or sanctions evasion.
- Fraud, impersonation, false documents, or misleading payment information.
- Concealing the true owner, controller, payer, payee, or purpose of a payment.
- Unlicensed money transmission, open third-party collection, or payments unrelated to the customer’s own business.
- Personal transfers, family remittances, peer-to-peer payments, or another use that has not been approved for the program.
- Avoiding due diligence, monitoring, reporting, provider rules, or applicable law.
10. Reporting suspicious activity
Anyone working for Gruv must raise a concern immediately if they know, suspect, or have reasonable grounds to suspect that property or a transaction may be linked to criminal conduct or terrorism financing. This includes attempted transactions. There is no minimum amount for making an internal report.
The AML/CFT Compliance Officer reviews the facts, records the decision, and files a Suspicious Transaction Report with the Suspicious Transaction Reporting Office through SONAR when required. We cooperate with lawful requests from regulators, law-enforcement agencies, courts, and licensed providers.
No one may tell a customer or counterparty that a report is being considered or has been filed. Reports, supporting information, and investigations must be kept confidential.
11. Record keeping
We keep enough information to show who we checked, what we found, what decisions we made, and how a payment was handled. Records include due-diligence information, ownership and representative details, risk assessments, screening results, transaction and provider references, approvals, alerts, investigations, and reporting decisions.
Unless a longer period is required, we keep relevant AML/CFT records for at least five years after the relationship ends or the transaction is completed. Records linked to an investigation, legal hold, or request from an authority are kept for as long as required.
12. Payment providers and compliance vendors
Before we use a payment provider or compliance vendor, we review its role, regulatory status where relevant, controls, data handling, and ability to support investigations and reporting. Our agreements should make clear who is responsible for each part of the service.
Providers may carry out their own KYC, KYB, sanctions screening, monitoring, source-of-funds checks, and regulatory reporting. Their checks do not replace ours. Where the law allows, we share the information needed to investigate risk and prevent financial crime.
13. Staff training and conduct
People in relevant roles receive AML/CFT training when they join and regular refresher training after that. The training covers customer checks, beneficial ownership, sanctions, politically exposed persons, warning signs, internal escalation, suspicious transaction reports, confidentiality, and the controls used in their role.
We apply appropriate screening when hiring for sensitive roles. A deliberate or reckless breach of this policy may lead to disciplinary action, dismissal, or referral to the authorities.
14. Testing the controls and reviewing this policy
We test whether the controls in this policy are working. The reviewer must be sufficiently independent from the work being tested. Any problem found must have a named owner and a deadline for fixing it.
We review this policy at least once a year and sooner if the law, our products, providers, countries, or risks change materially. We also review it after a serious control failure.
15. Contact
For questions about this policy or to raise a compliance concern, email [email protected]. Do not send identity documents or other sensitive records by ordinary email; we will provide a secure channel if they are needed.
Official references
This policy was reviewed against the following official Singapore sources. The applicable law and provider-specific requirements always take priority.
- MAS Notice PSN01 on AML/CFT for specified payment services
- MAS Guidelines to Notice PSN01
- Singapore Police Force: Suspicious Transaction Reporting
- Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992
- Terrorism (Suppression of Financing) Act 2002
- MAS: Targeted Financial Sanctions
You can also review our Privacy Policy and Terms of Service.
