AML Policy
1. INTRODUCTION
Coingalaxy Pty Ltd (“Coingalaxy”, “we”, “us”, “our”) is committed to preventing financial crime, including money laundering and terrorism financing, in all jurisdictions where we operate. As a registered reporting entity with the Australian Transaction Reports and Analysis Centre (AUSTRAC), we maintain strict compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
In addition, we adhere to equivalent laws and standards in jurisdictions including the European Union, where we align with the EU Anti-Money Laundering Directives (AMLDs), and in Mexico under the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI) and the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).
We recognise that our financial products and services could be misused for money laundering, terrorism financing, or financial fraud. To mitigate this risk, we implement robust processes, staff training, and systems that meet and exceed the expectations of regulators in all applicable jurisdictions.
Failure to comply with these obligations may result in serious penalties, legal or regulatory enforcement, and reputational damage. Coingalaxy is therefore committed to continuous improvement, vigilance, and high standards of ethical business conduct.
2. POLICY OBJECTIVES
Coingalaxy’s AML/CTF Policy aims to:
- Comply with all relevant AML/CTF legislation in Australia, the EU, Mexico, and other jurisdictions where we operate;
- Prevent, detect, and report suspicious or illegal activity;
- Foster a culture of compliance and accountability;
- Provide clear guidelines to all employees, contractors, and service providers;
- Align with international standards, including the Financial Action Task Force (FATF) Recommendations.
3. OUR AML/CTF FRAMEWORK
Coingalaxy implements the following controls:
- Compliance Measures: Designed to meet obligations under the AML/CTF Act and equivalent laws in the EU and Mexico;
- Employee Training: Mandatory onboarding and ongoing training for all employees, contractors, and third-party providers;
- Risk-Based Customer Due Diligence: Tailored verification and monitoring based on customer risk profile;
- Ongoing Monitoring: Transactional surveillance and behavioural monitoring;
- Reporting: Mandatory reporting of Suspicious Matter Reports (SMRs), Threshold Transaction Reports (TTRs), and International Funds Transfer Instructions (IFTIs), as required by AUSTRAC and applicable regulators abroad.
4. DEFINITIONS
- Money Laundering: The process of concealing the origins of illegally obtained funds to make them appear legitimate.
- Terrorism Financing: Funding terrorist activities, often involving smaller sums than money laundering, which may be sourced from both legal and illegal origins.
- Politically Exposed Persons (PEPs): Individuals entrusted with prominent public functions, including their close associates and family members.
5. CUSTOMER DUE DILIGENCE (CDD) & KNOW YOUR CUSTOMER (KYC)
We employ a risk-based CDD and KYC framework consistent with global best practices and local laws:
- Identity Verification: Valid government-issued documents and proof of address;
- Beneficial Ownership: Identifying ultimate controllers or shareholders;
- Enhanced Due Diligence (EDD): For high-risk customers, including PEPs, high-risk jurisdictions, or complex structures;
- Ongoing Monitoring: Dynamic assessments to detect unusual activity or changes in risk.
We perform CDD on all client types:
- Individuals (any nationality);
- Sole Traders;
- Australian and foreign-incorporated companies;
- Partnerships, Trusts, and Associations (incorporated or unincorporated);
- Cooperatives and Government bodies (domestic and foreign).
6. PRIVACY & DATA PROTECTION
In accordance with Australia’s National Privacy Principles, the GDPR (Europe), and LFPDPPP (Mexico), Coingalaxy ensures:
- Only relevant data is collected;
- Personal data is used solely for regulatory and compliance purposes;
- Adequate safeguards are in place to protect personal and sensitive data;
- Data subjects are informed of their rights and can access, correct, or request deletion of personal information as required by law.
For further information, refer to our Privacy Policy available on our website.
7. FIVE KEY AML/CTF PRINCIPLES
- Compliance: Meet legal obligations across all jurisdictions.
- International Alignment: Follow FATF Recommendations and local regulator guidance.
- Cooperation: Work with AUSTRAC, CNBV (Mexico), EU authorities, and law enforcement.
- Risk-Based Approach: Restrict or deny services where ML/TF risk is high.
- Program Governance: Maintain an auditable and adaptive compliance framework.
8. ROLES AND RESPONSIBILITIES
- Board and Senior Management: Oversee program design, resource allocation, and governance.
- MLRO (Money Laundering Reporting Officer): Appointed as the Group AML/CTF Officer, responsible for implementation, oversight, and reporting of AML/CTF measures.
- Compliance Staff: Ensure day-to-day adherence, training delivery, and support internal audits and regulator interactions.
All staff must complete AML/CTF training relevant to their role and report any unusual activity immediately.
9. COINGALAXY'S AML/CTF PROGRAM
Our program includes:
- ML/TF Risk Assessments: Reviewed regularly based on business model, customers, and geographies.
- Staff Training: Comprehensive learning modules and refresher sessions.
- Transaction Monitoring Systems: AI-assisted flagging of suspicious behaviour.
- Record Keeping: Data retention practices aligned with local laws (5+ years where required).
10. REPORTING OBLIGATIONS
Coingalaxy is committed to timely and accurate reporting, including:
- Transactions with cash components ≥ AUD 10,000;
- International fund transfers;
- Any suspicious activity or structuring behaviour;
- Reports to local regulators in the EU or Mexico where required by law.
11. PENALTIES FOR NON-COMPLIANCE
Non-compliance may result in:
- Regulatory fines and civil penalties;
- Criminal prosecution or custodial sentences;
- Revocation of licences or registration;
- Reputational harm;
- Loss of customer trust and business partnerships.
All employees are required to immediately report suspected non-compliance to the MLRO or a designated compliance officer.