This Policy on countering the legalisation (laundering) of proceeds of crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction, and on customer identification (the "AML/KYC Policy", the "Policy") sets out the principles, procedures and internal control measures applied by the BitMoment platform (the "Platform", the "Service", "BitMoment") with respect to users, transactions and counterparties.
This Policy forms an integral part of the User Agreement. By using the Service, you confirm that you have read this Policy, agree to it and undertake to comply with it. See also: User Agreement, Privacy Policy, Risk Disclosure, Fraud Warning.
1. General Information
1.1. BitMoment is an online venue for peer-to-peer (P2P) trading of cryptocurrencies (USDT, BTC) for fiat funds. The Platform provides a technical service for matching user orders, a cryptoasset escrow (conditional deposit) service and dispute-resolution mechanisms. Settlements in fiat funds are performed by users directly between themselves.
1.2. The Service is operated by BitMoment. The applicable law and the procedure for resolving disputes are determined by the User Agreement.
1.3. This Policy has been developed taking into account international standards in the field of anti-money laundering and countering the financing of terrorism ("AML/CFT"), including the Recommendations of the Financial Action Task Force (FATF), as well as the applicable law of the Platform's jurisdiction of regulation. The purpose of the Policy is to prevent the use of the Service for the laundering of criminal proceeds, the financing of terrorism, the circumvention of sanctions restrictions and other unlawful activity, and to protect bona fide users and the Platform's reputation.
1.4. This Policy establishes standards, principles and approaches to risk management when studying users and their transactions, the minimum identification requirements, enhanced control measures for higher-risk users and transactions, and the procedure for monitoring, detecting and responding to suspicious activity.
1.5. BitMoment develops and maintains internal confidential risk-assessment systems that determine the minimum verification requirements and the control measures applied. Specific threshold values, rules and signals of the risk models are not disclosed to users in order to prevent their circumvention.
1.6. The Platform is entitled to engage third-party service providers (providers of blockchain analytics and crypto-address scoring, providers of sanctions and other lists, document-verification services) to perform individual procedures under this Policy. The categories of third parties and the principles of their engagement are set out in Section 7.
1.7. All employees and engaged persons participating in the Platform's operation are obliged to comply with the requirements of this Policy to the extent applicable to them.
1.8. BitMoment's baseline control safeguards include: identification of users before granting them trading functionality; verification of data to an extent corresponding to the level of risk; automated and manual transaction monitoring; verification of deposit and withdrawal crypto-addresses using blockchain analytics; screening against sanctions and other lists; documenting and retaining information for the established period; staff training and the allocation of the resources necessary for investigations.
2. Terms and Definitions
The following terms are used in this Policy:
| Term | Meaning |
|---|---|
| Money laundering (legalisation of proceeds) | Actions aimed at giving a lawful appearance to the ownership, use or disposal of funds obtained as a result of the commission of a crime, including the transfer, concealment of the source or nature of the origin of such funds, or their acquisition or use. |
| Financing of terrorism | The provision or collection of funds with the knowledge that they will be used, in whole or in part, to carry out terrorist activity or for the benefit of persons or organisations involved in it. |
| Funds | Any assets — tangible and intangible, movable and immovable, in any form, including fiat money, cryptocurrency and other digital assets. |
| Proceeds of crime | Any funds derived, directly or indirectly, from the commission of a crime. |
| KYC (Know Your Customer) | A set of procedures for identifying and studying a user, aimed at establishing identity and understanding the nature of the user's activity. |
| CDD (Customer Due Diligence) | Due diligence of a user — study, verification and risk assessment to an extent corresponding to the risk profile. |
| PEP (Politically Exposed Person) | A public official, as well as persons related to such official; such users fall within the higher-risk category. |
| Beneficial owner | A natural person who ultimately controls a user or a transaction, or in whose interest a transaction is carried out. |
| Sanctions lists | Lists of persons and organisations subject to restrictive measures (including OFAC, the EU, the UN) and other applicable lists. |
| Suspicious transaction | A transaction which, by its nature, size, frequency or other characteristics, has no apparent economic sense or gives reasonable grounds to suspect a connection with AML/CFT concerns. |
| Escrow | A conditional-deposit service: when a trade is opened, the cryptoasset of the advertisement creator is locked by the Platform and held until performance of obligations is confirmed. See How escrow works. |
| Grey / white zone | Trading modes with different limits, requisite requirements and commission (see Section 4 and the Platform Rules). |
| Risk profile | The risk level assigned to a user (low / medium / high / critical) determining the scope of checks and control measures. |
Applicable awareness standard: for the Platform's obligation to respond to arise, actual knowledge of unlawfulness is not required — reasonable grounds for suspicion are sufficient.
3. General Provisions and Prohibited Actions
3.1. The Service is intended exclusively for lawful use. The user is strictly prohibited from using the Platform for:
- the legalisation (laundering) of proceeds of crime;
- the financing of terrorism or extremist activity, or the financing of the proliferation of weapons of mass destruction;
- committing or facilitating fraud, theft, extortion or other crimes against property;
- transactions involving funds the origin of which is connected with trafficking in drugs, weapons, persons, counterfeit goods, or with corruption;
- circumventing sanctions restrictions or concealing a connection with persons included in sanctions lists;
- carrying out transactions in the interest of a third party without disclosing such party, or using third-party accounts and requisites without lawful grounds ("money muling");
- any activity directly prohibited by applicable law or by this Policy.
3.2. BitMoment applies a risk-based approach: enhanced verification and control measures, up to and including refusal of service, are applied to higher-risk users and transactions.
3.3. The Platform is entitled at any time to request additional documents and information from the user (including on the source of origin of funds), to suspend transactions, restrict functionality, freeze the withdrawal of funds or apply other measures provided for by this Policy and the User Agreement, without prior notice, where this is necessary to comply with AML/CFT requirements.
3.4. The Platform takes decisions on the application of AML control measures (including the refusal of a transaction, the freezing of funds, the restriction of functionality, the termination of the relationship) at its sole discretion. Such a decision is final and may be challenged solely through the Platform's internal procedure. The Platform is not obliged to disclose to the user the reasons, grounds, methodologies, algorithms, data sources, weights and threshold values of the risk assessment and of the decisions taken; a user's request for such disclosure may be rejected without explanation, including in order to prevent circumvention of control measures and in connection with the prohibition on disclosing information about AML/CFT measures. The Platform is entitled to refuse service to any person at any time without giving reasons. This clause applies to the maximum extent permitted by applicable law.
3a. Rights of the Platform in Implementing the AML/KYC Policy
3a.1. For the purposes of implementing this Policy, the Platform carries out the identification of users and the analysis of the nature, patterning and interconnection of their actions and transactions. The analysis of user and transaction data is a tool for risk assessment and management and is applied to the extent the Platform considers necessary.
3a.2. The Platform reserves the right, among other things, to:
- interact with law-enforcement, regulatory, supervisory and other competent authorities and report to them on suspicious activity and transactions in the manner set out in the [Procedure for Law-Enforcement Requests](/support/docs/external-requests);
- request from the user additional documents, explanations and information (including on the source of origin of funds and the nature of transactions) where suspicions or doubts arise;
- fully or partially suspend the user's access to the account and to the functionality of the Service where there are reasonable grounds to suspect a breach of this Policy or of applicable law;
- carry out additional verification, revise the risk profile and apply other response measures provided for in Section 9.
3a.3. The list of the Platform's rights set out in clause 3a.2 is non-exhaustive and not exhaustive. The Platform is entitled to apply other measures necessary to comply with AML/CFT requirements, including measures not expressly named in this Policy, to the maximum extent permitted by applicable law.
3a.4. The Platform independently develops, maintains and amends the mechanism for detecting suspicious activity, the system of risk signals (red flags), and the criteria and threshold values for determining risks. These mechanisms, systems, signals, criteria and threshold values are confidential and are not disclosed to users, including in order to prevent their circumvention (see also clauses 1.5 and 3.4).
3a.5. The Platform is entitled, without any obligation to obtain the user's approval and without any obligation to notify the user in advance or subsequently, to notify regulatory, supervisory and law-enforcement authorities of the user, the user's transactions and related activity, and to provide such authorities with information upon their requests, in the cases and in the manner provided for by applicable law. The procedure for interaction with competent authorities and the prohibition on disclosing information to the user ("tipping-off") are set out in the Procedure for Law-Enforcement Requests; this clause does not duplicate but supplements that document.
3a.6. Where an unacceptably high level of risk is identified in respect of the user or the user's transactions, the Platform is entitled to refuse the user further service. Such a refusal is applied at the Platform's sole discretion, is final and does not give rise to any claim by the user, save for the right to the return of funds in accordance with clause 9.3.
3a.7. The Platform is entitled to suspend or terminate the operation of the user's account, to suspend the turnover of funds in it and to freeze the user's assets pending the clarification of circumstances and the completion of the necessary checks. Suspension, termination and freezing are applied as precautionary control measures; they do not constitute a confiscation and do not extinguish the user's rights to the funds. The return of funds is carried out in the manner and with the reservations established by clause 9.3, unless otherwise follows from the instructions of competent authorities or from applicable law.
3a.8. The provisions of this section apply "to the maximum extent permitted by applicable law" and are to be construed together with Sections 8, 9 and clause 9.3.
4. Verification Levels (KYC) and Limits
4.1. Access to the Platform's functionality is granted incrementally depending on the verification level completed. The levels and the corresponding limits:
| Level | What is required | Access and limit |
|---|---|---|
| Level 0 | Registration (email) | Viewing of the marketplace only. Trading is unavailable. |
| Level 1 | Phone-number confirmation | Trading in the grey zone. Limit up to RUB 100,000 per day. |
| Level 2 | Verification of an identity document | Grey zone. Limit up to RUB 500,000 per day. |
| Level 3 | Extended verification | Access to the white zone. Limit up to RUB 3,000,000 per trade. |
4.2. Grey zone: trading at a rate within the permitted deviation from the market rate, a minimum trade amount of RUB 5,000, a commission of 1% charged to the advertisement creator upon a successful trade. White zone: a narrowed rate corridor, increased minimum amounts and a requirement that the requisites match the user's data. For details, see the Platform Rules and the "General questions" section.
4.3. The Platform is entitled to establish additional threshold values upon reaching which a higher verification level, the provision of information on the source of funds or a manual review of the transaction is required, irrespective of the user's formal KYC level.
4.4. Failure to complete the required verification level, refusal to provide documents or the provision of inaccurate information constitutes grounds for restricting access, suspending transactions or terminating the relationship with the user.
5. Identification and Due Diligence Procedures (KYC / CDD)
5.1. User identification is carried out before granting access to the trading functionality and comprises three components: (a) collection of identification and other information; (b) screening of the user against sanctions and other lists; (c) verification on the basis of the documents provided and/or data from independent sources.
5.2. As part of identification, the Platform is entitled to request, among other things:
- full name, date of birth, citizenship, country of residence;
- contact details (telephone number, email address);
- a copy of an identity document and other documents to confirm identity and address;
- information on politically-exposed-person (PEP) status;
- information on the nature of activity, the expected volumes and purposes of transactions, and the source of origin of funds;
- information on the beneficial owner and/or the person in whose interest the transaction is carried out;
- a selfie (photograph of the face) to confirm that the face matches the document presented, where this is provided for by the applicable verification procedure.
5.3. Screening. The user's data is checked against sanctions lists (including OFAC, the EU, the UN), lists of persons connected with AML/CFT concerns, and registers of public officials. Where a match is identified, the measures provided for in Section 8 and Section 9 are applied.
5.4. User profile and risk assessment. On the basis of the information collected, the Platform forms a user profile, determines the user's risk profile and applies the corresponding control measures (see Section 6).
5.5. Enhanced due diligence (EDD). For higher-risk users, public officials, and where risk factors are identified, in-depth study is applied, including additional verification of the source of origin of funds and the engagement of independent data sources.
5.6. Ongoing monitoring. Users' transactions are subject to continuous automated and selective manual monitoring for consistency with the user profile and risk profile and for the detection of atypical or suspicious activity. The Platform is entitled to revise a user's risk profile on the basis of monitoring results, new information or staff reports.
5.7. Verification of crypto transactions. When a deposit address is created, when cryptocurrency is credited and when funds are withdrawn, the Platform analyses crypto-addresses and transactions using blockchain analytics. Based on the analysis, a risk score is assigned to the address:
| Risk level | Score | Consequences |
|---|---|---|
| Low | 0–25 | The transaction is processed in the ordinary course. |
| Medium | 26–50 | Enhanced monitoring; additional information may be requested. |
| High | 51–75 | Reduced limits, manual review, placement of the transaction in a review queue. |
| Critical | 76–100 | Freezing of funds, immediate escalation, possible refusal to credit or withdraw. |
5.8. The Platform is entitled not to credit a deposit, to freeze funds or to refuse a withdrawal if the address or transaction is connected with unlawful activity or sanctions restrictions or has an unacceptable level of risk. Decisions on such transactions and the appeal procedure are governed by Section 9 and the Platform Rules.
5.9. The escrow mechanism is not a means of settlement and does not relieve the user of the obligation to confirm the lawfulness of the origin of funds. The use of escrow does not prevent the Platform from suspending a trade, initiating a dispute or applying other control measures.
6. Risk Assessment and Risk Profiles
6.1. BitMoment applies a risk-based approach: it identifies, assesses and understands AML/CFT risks and applies verification measures to an extent corresponding to the level of risk. Where it is impossible to complete the required measures or where doubts arise, the user's risk profile is automatically increased.
6.2. Risk assessment takes into account, among others, the following groups of factors:
- User-related factors: opacity of identity, public-official status, country of residence, inclusion in sanctions or other lists, unclear origin of funds, atypical nature of transactions, problems during identification.
- Transaction-related factors: size, frequency, structure of transactions, signs of structuring, absence of apparent economic sense, use of third-party requisites.
- Geographic factors: jurisdictions with elevated risks, a low level of compliance with AML/CFT standards, a high level of corruption, or included in sanctions lists.
- Interaction-channel factors: the remote nature of the service, signs of anonymisation, the use of identification-circumvention tools.
6.3. Classification of risk profiles:
| Profile | Characteristics | Measures |
|---|---|---|
| Low | Absence of significant risk factors; transparent user and transactions. | Standard verification. |
| Medium | Presence of one or more atypical factors with an understandable nature of transactions. | Enhanced monitoring, additional verification. |
| High | Several risk factors and/or an unclear nature of transactions; doubts as to identity or transparency. | Reduced limits, in-depth verification, individual review. All public officials are classified as high risk. |
| Critical | Signs of a direct connection with AML/CFT concerns, sanctions or other unlawful activity. | Freezing of funds, immediate escalation, refusal of service, notification of competent authorities in the cases established. |
6.4. The Platform documents the determination of the risk profile, updates it when new information emerges, and provides data to competent authorities in the cases provided for by applicable law.
6.5. The scope of verification (checking the validity and authenticity of documents, engaging independent sources, notarised copies, etc.) is determined by the level of the risk profile: the higher the risk, the stricter the measures applied.
7. Third Parties (Service Providers)
7.1. Before engaging third-party service providers (blockchain analytics and address scoring, providers of sanctions lists, document-verification services, payment infrastructure), the Platform studies their reputation, the presence of licences and permits, and the absence of connections with unlawful activity.
7.2. The Platform does not enter into relationships with persons included in sanctions lists, controlled by such persons, or registered in prohibited jurisdictions.
7.3. The engagement of third parties does not relieve the Platform of responsibility for compliance with this Policy. The transfer of personal data to third parties is carried out in accordance with the Privacy Policy.
8. Detection of and Reporting on Suspicious Transactions
8.1. Where suspicions arise, the Platform's employees immediately report them to the person responsible for AML/CFT compliance, irrespective of the degree of confidence in the validity of the suspicion and of the availability of conclusive evidence.
8.2. The responsible person immediately reviews the report received, assesses its validity and decides on further actions, which may include: no action; additional verification; revision of the risk profile; suspension or termination of the relationship with the user; freezing of funds; notification of competent authorities.
8.3. In the cases provided for by applicable law, the Platform submits a report to the competent authority within the established time where it identifies funds presumed to be proceeds of crime, connected with AML/CFT concerns or subject to sanctions restrictions. This applies irrespective of whether the suspicion arose before or after the start of the relationship with the user.
8.4. Where the Platform receives information from competent authorities on a person matching a user, beneficial owner or representative, the Platform is entitled to immediately freeze the related funds and transactions until the relevant instructions of the competent authority are received, within the time established by applicable law.
8.5. The Platform does not notify the user of the fact of submitting a report to a competent authority where such notification is prohibited by applicable law or may impede an investigation.
9. Response Measures and Consequences for the User
9.1. Based on the results of checks and monitoring, the Platform is entitled to apply one or more measures:
- a request for additional documents and information, including on the source of origin of funds;
- suspension of individual transactions or restriction of functionality;
- switching the account to read-only mode while retaining access to history and correspondence;
- freezing of cryptocurrency funds in the account, refusal to credit a deposit or to withdraw funds;
- initiation of a dispute over a trade and engagement of a moderator;
- termination of the relationship with the user (blocking of the account);
- notification of competent authorities in the cases provided for by applicable law.
9.2. Measures are applied to the extent necessary and sufficient to comply with AML/CFT requirements and may be applied without prior notice where notice is capable of impeding the achievement of the control objectives.
9.3. The freezing or retention of funds in connection with a suspicion of unlawful origin is not a confiscation. The return of funds is possible after the grounds for retention have been eliminated and upon confirmation of the lawfulness of their origin, unless otherwise follows from the instructions of competent authorities or from applicable law.
9.4. The procedure for conducting disputes, the actions of the moderator and the possible decisions are governed by the Platform Rules and the materials of the "Disputes and moderation" section.
10. Technical Nature of the Service
10.1. The Platform provides a technical capability for peer-to-peer (P2P) interaction between users and a conditional-deposit (escrow) service for cryptoassets. The Platform is not a bank, credit institution, payment agent, investment or financial adviser, trustee or party to the transactions concluded by users between themselves. Settlements in fiat funds are performed by users directly.
10.2. The technical nature of the Service does not cancel the Platform's actual AML/CFT role: the Platform carries out identification, monitoring, screening and other control measures provided for by this Policy, and is entitled to apply the response measures set out in Section 9. The scope of obligations attributable to the Platform is limited to its actual role as a technical intermediary and operator of an escrow service, to the maximum extent permitted by applicable law.
10.3. The Platform provides no warranties as to the actions, good faith or solvency of a user's counterparties and is not responsible for their conduct.
11. Limitation of Liability and Indemnification
11.1. To the maximum extent permitted by applicable law, the Platform is not liable for any losses, lost profit, loss of the ability to use funds or other adverse consequences caused by the application of AML control measures, including a request for information, suspension of transactions, restriction of functionality, freezing or retention of funds, refusal to credit a deposit or to withdraw, termination of the relationship with the user, or the temporary or permanent unavailability of the Service.
11.2. The Platform's application of the measures provided for by this Policy is lawful and does not give rise to any claim by the user where such measures are taken in connection with compliance with AML/CFT requirements or on the basis of reasonable grounds for suspicion.
11.3. The user shall indemnify the Platform and its related persons for documented losses, costs and expenses (including reasonable legal, investigation and authority-liaison costs), and shall satisfy third-party claims, arising from the user's breach of this Policy, the user's provision of inaccurate information or the user's commission of prohibited actions.
11.4. The provisions of this section are not intended to exclude liability to the extent that such exclusion is not permitted by applicable law; to that extent, the provisions apply to the maximum permissible degree.
12. Acceptance of Risks and Waiver of Claims
12.1. By using the Service, the user confirms that the user has read this Policy and the risks associated with transactions (including those set out in the Risk Disclosure), accepts them and agrees to the Platform's application of the AML control measures set out in this Policy.
12.2. The user waives in advance any claims against the Platform in respect of the discretionary powers and control measures lawfully exercised by it under this Policy, to the maximum extent permitted by applicable law. This clause does not affect the user's right to the return of funds after the grounds for retention have been eliminated, in accordance with clause 9.3.
13. Data Retention
13.1. Information obtained in the course of identification and due diligence, as well as information on the decisions taken, is recorded in the Platform's internal systems.
13.2. Documents identifying the user and information on transactions are retained for no less than the period established by applicable law (as a rule, no less than five years from the termination of the relationship with the user or the completion of the transaction), unless applicable law provides for a different period.
13.3. The processing of personal data, including the legal bases, purposes, data-subject rights and the procedure for their exercise, is governed by the Privacy Policy.
14. User Obligations
14.1. The user represents and warrants that the user does not use the Service to commit the prohibited actions listed in Section 3 and that the information provided by the user is accurate, complete and current.
14.2. The user undertakes, upon the Platform's request, to provide in a timely manner the documents and information necessary for identification, due diligence and confirmation of the source of origin of funds, and to cooperate with the checks and investigations conducted.
14.3. The user undertakes to independently keep their identification data current and to immediately notify the Platform of any change thereto.
14.4. A user's refusal to provide the requested information, the provision of inaccurate information or the failure to pass verification constitutes grounds for the suspension or termination of service, the freezing of funds and the application of other measures provided for by this Policy.
14.5. The user is responsible for breach of this Policy in accordance with the User Agreement and applicable law.
15. Governing Law, Dispute Resolution and Severability
15.1. This Policy and the relations arising in connection with its application are governed by the law of the Operator's country of registration. Disputes are resolved in the manner established by the User Agreement, including the mandatory pre-action (pre-trial) procedure and the subsequent resolution of the dispute by arbitration at the agreed seat of arbitration. The user and the Platform agree on jurisdiction (prorogation clause) in the manner established by the User Agreement.
15.2. The recognition of any provision of this Policy as invalid, unlawful or unenforceable does not entail the invalidity of the remaining provisions. An invalid or unenforceable provision is applied and construed to the maximum extent permitted by applicable law so as to achieve, as far as possible, its original legal and economic purpose; in all other respects the Policy remains in force.
15.3. All strict and discretionary provisions of this Policy apply "to the maximum extent permitted by applicable law". The Platform's failure to exercise, or delay in exercising, any right or measure does not constitute a waiver thereof.
16. Amendments to the Policy
16.1. BitMoment is entitled, at its discretion, to amend this Policy in connection with the emergence of new risks, products or services, changes in applicable law or on other grounds.
16.2. The current version of the Policy is published at /support/docs/aml-policy. The version history is available at /support/docs/aml-policy/history.
16.3. The procedure for accepting this document and the legal consequences of its amendment are determined by the User Agreement, of which this document forms an integral part. Consent is expressed in the manner established by the User Agreement and does not require separate confirmation for each version.
17. Contacts
For matters relating to this Policy, identification, verification of the source of funds, the freezing of funds and official requests, please contact:
- Email (AML/KYC, official requests): legal@bitmoment.pro
- Email (general support): support@bitmoment.pro
- Telegram support: @BitMomentSupportBot
The procedure for handling requests from competent authorities is set out in the document "Procedure for Law-Enforcement Requests".
Operator: BitMoment.
