Skip to main content
Gruv.ai logo

Anti-Money Laundering and Countering the Financing of Terrorism Policy

Version 1.0 · Last updated July 24, 2026 · Reviewed annually

This policy sets out how Gruv Pte. Ltd. checks customers and payment activity, works with licensed payment providers, and reports suspected financial crime.

Gruv Pte. Ltd. is not a bank and does not hold a payment services licence. Where a service uses a virtual account or payment rail, a licensed payment provider operates it and holds the funds. Gruv sends instructions and keeps operational and reconciliation records.

1. Purpose

Gruv Pte. Ltd. (“Gruv”, “we”, or “us”) uses the controls in this policy to keep its platform from being used for money laundering, terrorism financing, proliferation financing, sanctions evasion, or related financial crime.

Staff follow separate procedures for screening, investigations, and reporting. Those procedures and individual case records are confidential.

2. Who and what this policy covers

This policy binds Gruv’s directors, officers, employees, contractors, and anyone else acting for the company. It covers activity involving customers, sub-merchants, payees, contractors, creators, affiliates, and marketplace participants.

Gruv provides software, payment instructions, workflow controls, records, and reconciliation. Gruv Pte. Ltd. does not issue virtual accounts or hold customer funds. Licensed payment providers perform the regulated payment services under their own licences and terms.

A provider’s approval is not enough on its own. Gruv carries out its own checks and may refuse a customer or transaction.

3. Responsibility for this policy

Senior management approves this policy. The AML/CFT Compliance Officer runs the programme and has authority to stop onboarding, hold activity, request information, decline a transaction, or end a relationship.

No sales or commercial decision can override a compliance decision. Anyone working for Gruv must report suspected financial crime immediately through the internal compliance channel.

4. How we assess risk

Before accepting a customer, we review its business, owners and controllers, countries, products, payment methods, counterparties, expected volumes, and reason for using Gruv. We repeat the review when the customer or its activity changes.

We review Gruv’s overall financial-crime risk at least once a year and before adding a significant product, provider, country, payment method, or customer programme.

Higher-risk activity receives extra checks. Gruv may refuse activity even when it is not expressly prohibited by law.

5. Customer due diligence and beneficial ownership

We do not accept anonymous customers or false identities. Before enabling a financial feature, we identify the customer, establish who owns and controls it, and record how it intends to use Gruv.

  • For a business, we collect its legal name, registration or tax number, address, incorporation details, business activity, ownership and control structure, and authorised representatives.
  • We identify and verify the natural people who ultimately own or control the business.
  • For an individual payee or contractor, we collect the identity, contact, and payout details required for the payment route.
  • We record the expected purpose, countries, currencies, counterparties, frequency, and value of payments. We ask for evidence of source of funds when the risk calls for it.

6. When we carry out enhanced checks

Extra checks are required for higher-risk cases. Common triggers include a politically exposed person, a complex ownership structure, a link to a high-risk country, adverse information, unusual funding, a sanctions concern, or activity that does not fit the stated business.

Depending on the case, we may request more identity or company documents, verify information independently, ask for evidence of source of funds or wealth, seek senior-management approval, or monitor the relationship more closely.

If the risk remains unclear or too high, we decline the customer or transaction.

7. Sanctions screening

We screen customers, beneficial owners, controllers, representatives, payees, and relevant counterparties against applicable sanctions and terrorism-financing lists. Screening takes place at onboarding, before relevant payment activity, when key details change, and during the relationship.

We pause and investigate a possible match. Where required, we block the activity, work with the licensed payment provider, preserve the records, and notify the appropriate authority.

We do not knowingly serve a designated person or support prohibited activity. We do not tell a person that they are under review or that a report has been made.

8. Monitoring payment activity

Automated rules and manual reviews flag payments that do not fit the customer’s known business or have no clear lawful purpose. Monitoring is stricter where the risk is higher.

  • Transactions that are unusually large, complex, rapid, or repetitive.
  • Payments split into smaller amounts to avoid checks or limits.
  • Unexpected countries, counterparties, or third-party payments.
  • Names, account holders, invoices, contracts, or payment purposes that do not match.
  • Unusual refunds, reversals, failed payments, or rapid movement of newly received funds.
  • Activity that does not match the customer’s business, expected volumes, or stated source of funds.

9. Activity we do not allow

Gruv may pause, decline, return, restrict, or cancel activity. The platform must not be used for:

  • Handling proceeds of crime or supporting money laundering, terrorism financing, proliferation financing, or sanctions evasion.
  • Fraud, impersonation, false documents, or misleading payment information.
  • Concealing the true owner, controller, payer, payee, or purpose of a payment.
  • Unlicensed money transmission, open third-party collection, or payments unrelated to the customer’s own business.
  • Personal transfers, family remittances, peer-to-peer payments, or any use that has not been approved for the programme.
  • Avoiding due diligence, monitoring, reporting, provider rules, or applicable law.

10. Reporting suspicious activity

Staff must report any knowledge or suspicion of criminal property or terrorism financing immediately. Attempted transactions count, and there is no minimum amount.

The AML/CFT Compliance Officer reviews the facts and records the decision. Where a report is required, the officer files it with the Suspicious Transaction Reporting Office through SONAR.

Suspicious transaction reports and related investigations are confidential. Gruv also responds to lawful requests from regulators, law-enforcement agencies, courts, and licensed payment providers.

11. Record keeping

We keep the customer information, ownership records, risk assessments, screening results, transaction references, approvals, alerts, investigations, and reporting decisions needed to reconstruct a review or payment.

AML/CFT records are kept for at least five years after the relationship ends or the transaction is completed, unless a longer period is required. An investigation, legal hold, or request from an authority may require us to keep them longer.

12. Payment providers and compliance vendors

Before appointing a payment provider or compliance vendor, we check its role, regulatory status where relevant, controls, data handling, and support for investigations and reporting. The contract must state who is responsible for each part of the service.

Providers carry out their own KYC, KYB, sanctions screening, monitoring, source-of-funds checks, and regulatory reporting where required. Their checks do not replace Gruv’s. We share information with them where the law permits and the work requires it.

13. Staff training and conduct

Staff in relevant roles receive AML/CFT training when they join and refresher training afterwards. The training covers the risks, warning signs, checks, escalation routes, and confidentiality rules relevant to their work.

We screen candidates for sensitive roles. A deliberate or reckless breach of this policy may lead to disciplinary action, dismissal, or referral to an authority.

14. Testing the controls and reviewing this policy

Someone independent of the work under review tests these controls. Each problem found is assigned to an owner with a deadline to fix it.

We review this policy at least once a year. We review it sooner after a significant change in law, product, provider, country exposure, or risk, and after a serious control failure.

15. Contact

Email connect@gruv.ai with a question or compliance concern. Do not attach identity documents or other sensitive records; we will provide a secure channel if we need them.

Official references

We refer to the following Singapore sources. If this policy conflicts with the law or a provider requirement, the law or provider requirement takes priority.

You can also review our Privacy Policy and Terms of Service.