AML and KYC Procedures
Version 2026-07-20 · Effective July 20, 2026
Issued by Ohana Capital AG
Effective date
July 20, 2026

Issued by
Ohana Capital AG
1. Status of this document
These AML and KYC Procedures describe controls as implemented in the Ohana Capital platform and CRM, plus planned enhancements required for a live funding environment. They operationalize parts of the Compliance Policy.
Sanctions / PEP screening is currently a policy and manual-review expectation; automated watchlist screening is not yet integrated as a production vendor workflow. That gap must be closed before live client-money onboarding in regulated markets.
2. Roles
| Role | Responsibility |
|---|---|
| Customer | Provides accurate identity and documents |
| Platform | Collects profile data, stores uploads, enforces age gate, sets KYC status |
| CRM operator (authorized staff) | Reviews documents, approves/rejects, may apply KYC overrides with audit |
| Compliance / management | Escalations, restrictions, policy updates |
3. Customer information collected
Profile and registration workflows may collect:
- Title, first name, last name
- Email, phone
- Country code and residential address (lines, city, region, postal code)
- Date of birth
- Account and support communications
Age gate: the database enforces a minimum age of 18 for account holders.
4. Document types accepted
Customers may upload (PDF / JPEG / PNG, size-limited):
| Type | Typical use |
|---|---|
passport |
Primary identity |
identity_card |
Primary identity |
selfie |
Likeness / liveness support |
proof_of_address |
Address verification |
bank_statement |
Address / funding corroboration |
other |
Additional evidence on request |
Uploads are stored in a private documents storage bucket and create a pending KYC review state.
5. Verification status model
Account KYC status uses:
unverifiedpendingverifiedrejected
Verified requires approved identity evidence and approved proof of address under the platform’s recomputation rules, unless a documented override is applied by authorized staff.
6. Review procedure (CRM)
Authorized operators:
- Open the document in the CRM documents queue.
- Preview the file and compare it to profile data.
- Approve or Reject via audited admin routes that call
review_document. - Record a rejection reason when rejecting.
- Customer notifications are generated by the review workflow.
Overrides of overall KYC status, where used, must be auditable and limited to authorized roles.
7. Ongoing monitoring (current vs target)
Current
- Manual document review
- Operator notes and account restrictions through CRM tools
- Transaction and funding workflows available for modeled / operator scenarios
- Customer external settlement disabled
Target before live client money
- Automated sanctions / PEP / adverse-media screening at onboarding and periodically
- Source-of-funds / source-of-wealth capture for higher-risk profiles
- Rule-based transaction monitoring on deposits, withdrawals, and rapid movement
- Case management for alerts with dual control on payouts
- Recorded escalation to compliance management
8. Escalation triggers
Escalate when any of the following appear:
- Document inconsistency, tampering indicators, or mismatch to profile
- Suspected third-party or mule activity
- Sanctions / PEP hits (once screening is live) or high-risk jurisdictions
- Unusual funding or withdrawal patterns
- Customer refusal to provide required information
Escalation path: operator → compliance lead → senior management / counsel as needed. See Insurance, Retention, and Escalation Schedule.
9. Record keeping
Retain identity files, review decisions, KYC status history, overrides, and related notifications according to the retention schedule. Access is role-restricted.
10. Related documents
Questions about this document?
Contact Ohana Capital AG and include the document title and version in your message.
Contact support