AML/CTPF Policy

Policy version: 2025

T-BOX (Thailand) Co., Ltd., as a digital token offering system provider (ICO Portal) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018), is a financial institution under Thai anti-money-laundering law. The Company maintains an operating guideline on Anti-Money Laundering and Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing (AML/CTPF) so that its business is never used as a channel for money laundering or terrorism financing.

This page summarises the key substance of the full guideline in an easy-to-read format. The guideline is prepared by the Company’s Legal and Compliance Department.

1. Roles and responsibilities

Every level of the organisation has a defined duty in preventing money laundering.

  • Senior management approves the guideline, approves high-risk customer relationships, and makes the final decision to reject or terminate a business relationship.
  • The Operations Department verifies customer information and documents, including approval of account openings.
  • The Legal and Compliance Department advises, reviews operations, trains staff, and submits reports to the Anti-Money Laundering Office (AMLO).

2. Know Your Customer (KYC)

Every customer must identify themselves before a business relationship begins.

  • Individual customers verify their identity through the Versa application using their national ID card with face recognition and liveness detection.
  • Juristic persons, institutional investors, and high-net-worth investors identify themselves by submitting information and supporting documents via email.
  • Collected data covers full name, date of birth, ID numbers, addresses, occupation and workplace, purpose of the relationship, source of income, and country of origin of funds.

3. Customer Due Diligence (CDD)

Before accepting any customer, the Company screens them against official databases.

  • Screening against designated-person lists (UN List and Thailand List), AMLO high-risk lists, and lists of persons subject to transaction suspension or asset freezes — a match means the Company will not transact.
  • Politically Exposed Person (PEP) screening — foreign PEPs are always treated as high risk, and PEP lists are reviewed annually.
  • Identification of the Ultimate Beneficial Owner of juristic customers by tracing shareholders holding 25% or more.
  • The Company may rely on regulated third parties to perform due diligence, while remaining fully responsible for the outcome.

4. Customer risk classification

Every customer is risk-rated under a risk-based approach before using the service.

  • Assessment factors include the customer (occupation, source of income), geographic area or country, products and services, and the service channel.
  • Combined scores map to three levels: low risk at 6–11 points, medium at 12–17, and high at 18–24.
  • Certain occupations, business types, and countries (for example casino businesses or sanctioned countries) are rejected outright.

5. High-risk customers (ECDD)

High-risk customers undergo enhanced due diligence.

  • Additional information is required, such as source of funds or assets, source of wealth, and supporting evidence.
  • Accepting or continuing a high-risk relationship requires approval from senior management or their authorised delegate.

6. Ongoing review and transaction monitoring

Customer information is reviewed and transactions are monitored throughout the relationship.

  • Review cycles: high-risk customers every year, medium risk every 3 years, and low risk every 5 years.
  • Transaction movements are monitored for consistency with the customer’s stated purpose, risk level, and income profile.
  • If the risk profile changes, the Company adjusts the risk level with countermeasures such as transaction limits or a relationship review.

7. Designated persons

When a customer is found to be a designated person, the Company acts immediately as required by law.

  • Transactions are suspended and dealings with the person’s assets are frozen.
  • AMLO is notified using Forms Por Kor Ror 03 and 04 within 10 business days.
  • Business relationships with designated persons are refused or terminated.

8. Reporting to AMLO

Suspicious transactions are reported to the regulator within statutory deadlines.

  • Suspicious Transaction Reports (STR) are filed on Form 1-03 within 7 days of the suspicion arising.
  • Reporting channels include in-person filing, registered mail, and AMLO’s electronic AERS system.

9. Record keeping

Records are stored securely and retrievable whenever AMLO requests an inspection.

  • Identification records and transaction records are retained for 5 years from account closure or the end of the relationship.
  • Customer due diligence records are retained for 10 years, extendable by up to 5 more years at AMLO’s direction.

10. Confidentiality

Customer information and regulatory reporting are confidential.

  • Employees must not disclose customer information to any other person, directly or indirectly, except where disclosure is a legal right or obligation.
  • Customers are never informed that their transactions have been reported to AMLO.

11. Internal controls and training

Internal controls keep this guideline enforced across the organisation.

  • Employees are screened before hiring against designated-person lists and criminal records.
  • New employees receive AML/CTPF training within 30 days of starting work; current employees train at least once a year.
  • An independent internal audit function reviews compliance and reports to senior management.
  • The Company assesses its internal risk and reviews this guideline at least once a year, or whenever the law changes.