AML Policy

Anti-Money Laundering (AML) Policy

1.0 · Effective 2026-07-01

This Anti-Money Laundering (AML) Policy establishes the framework through which SENTINEL PEAK BANK detects, prevents, reports, and mitigates money laundering, terrorist financing, fraud, bribery, corruption, and other forms of financial crime.

Policy Version

Anti-Money Laundering (AML) Policy

Document Information

Policy Title: Anti-Money Laundering (AML) Policy. Policy Number: VBS-POL-004. Version: 1.0. Document Classification: Public. Document Status: Active. Effective Date: 01 July 2026. Publication Date: 26 June 2026. Approval Date: 26 June 2026. Next Review Date: 01 July 2027. Approved By: Board of Directors. Policy Owner: Compliance & Financial Crime Department.

1. Purpose

SENTINEL PEAK BANK ("the Bank") is committed to maintaining the highest standards of integrity, transparency, and regulatory compliance in all banking operations. This Anti-Money Laundering (AML) Policy establishes the framework through which the Bank detects, prevents, reports, and mitigates money laundering, terrorist financing, fraud, bribery, corruption, and other forms of financial crime. The Bank adopts a zero-tolerance approach toward the misuse of its products or services for illegal or unethical purposes.

2. Scope

This policy applies to individual customers, business customers, corporate entities, beneficial owners, directors and shareholders, employees, contractors, consultants, third-party service providers, correspondent banking relationships, and agents and intermediaries. This policy covers all products and services offered by SENTINEL PEAK BANK.

3. Objectives

The objectives of this policy are to prevent the Bank from being used for money laundering, detect suspicious financial activities, protect the Bank's reputation, meet applicable legal and regulatory obligations, promote a culture of ethical banking, and protect customers from financial crime.

4. Definitions

Money Laundering: any process intended to conceal, disguise, convert, transfer, acquire, possess, or use proceeds obtained through criminal activity. Terrorist Financing: the provision or collection of funds intended to support terrorist activities or organizations. Politically Exposed Person (PEP): an individual entrusted with a prominent public function, including their immediate family members and close associates. Beneficial Owner: the natural person who ultimately owns or controls a customer or legal entity.

5. AML Principles

SENTINEL PEAK BANK follows these core AML principles: Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Ongoing Monitoring, Risk-Based Approach, Record Keeping, Employee Awareness, Regulatory Reporting, and Continuous Improvement.

6. Risk-Based Approach

The Bank applies a risk-based methodology when establishing and maintaining customer relationships. Risk factors considered include customer type, country of residence, occupation, source of funds, source of wealth, transaction behavior, products used, delivery channels, geographic risk, and political exposure. Customers may be categorized as Low Risk, Medium Risk, or High Risk. Higher-risk customers receive enhanced monitoring and additional verification.

7. Customer Due Diligence (CDD)

Before establishing any banking relationship, the Bank shall verify full legal name, date of birth, residential address, nationality, government-issued identification, contact information, occupation, source of income, source of funds, and tax information where applicable. Business customers must provide Certificate of Incorporation, business registration documents, ownership structure, directors' details, beneficial ownership information, business activities, and tax registration.

8. Enhanced Due Diligence (EDD)

Enhanced Due Diligence shall be performed where customers present elevated risk. EDD may include additional identity verification, senior management approval, independent source verification, enhanced transaction monitoring, more frequent account reviews, verification of source of wealth, and verification of source of funds. EDD is generally applied to Politically Exposed Persons, high-risk jurisdictions, complex ownership structures, cash-intensive businesses, and cross-border relationships.

9. Ongoing Monitoring

The Bank continuously monitors customer relationships throughout their lifecycle. Monitoring includes large cash deposits, unusual transfers, rapid movement of funds, structuring transactions, dormant account activity, unexpected account behavior, high-risk jurisdictions, and sanctions exposure. Transactions inconsistent with customer profiles may be investigated.

10. Sanctions Screening

SENTINEL PEAK BANK screens customers and transactions against applicable sanctions lists. Accounts may be restricted, frozen, or reported where legally required.

11. Suspicious Activity Reporting

Employees must immediately report suspected financial crime through internal reporting procedures. Examples include unexplained wealth, false identification, suspicious cash activity, layering transactions, third-party account misuse, attempts to avoid reporting thresholds, and fraud indicators. Where required by law, the Bank will submit Suspicious Transaction Reports (STRs) or Suspicious Activity Reports (SARs) to the relevant authorities.

12. Record Retention

The Bank retains AML records for the period required by applicable law. Records include customer identification, account opening documents, transaction records, monitoring reports, internal investigations, regulatory filings, and risk assessments. Records are securely stored and protected against unauthorized access.

13. Employee Responsibilities

Every employee is responsible for understanding AML obligations, completing mandatory training, reporting suspicious activity, maintaining confidentiality, following internal procedures, and cooperating with investigations. Failure to comply may result in disciplinary action.

14. Employee Training

Mandatory AML training shall be provided during onboarding, annually, following regulatory changes, and following significant internal policy updates. Training includes money laundering risks, terrorist financing, fraud awareness, customer due diligence, sanctions compliance, and reporting obligations.

15. Internal Controls

The Bank maintains internal controls including segregation of duties, compliance monitoring, internal audit, independent testing, transaction monitoring systems, access controls, and risk assessments.

16. Confidentiality

Reports concerning suspicious activity are treated as strictly confidential. Employees must not disclose to customers that a report has been made where prohibited by law.

17. Non-Compliance

Failure to comply with this policy may result in account restrictions, transaction delays, account closure, employee disciplinary action, reporting to regulatory authorities, and civil or criminal penalties where applicable.

18. Policy Review

This policy will be reviewed at least annually, following regulatory changes, following significant financial crime incidents, and when operational changes require updates.

19. Contact Information

Compliance & Financial Crime Department, SENTINEL PEAK BANK. Email: compliance@sentinelpeakbank.com. Telephone: +000 000 000 000. Business Hours: Monday-Friday, 8:00 AM - 5:00 PM.

Revision History

Version 1.0. Effective Date: 01 July 2026. Description: Initial Release. Approved By: Board of Directors.

Document Control

Policy Number: VBS-POL-004. Version: 1.0. Status: Active. Last Reviewed: 26 June 2026. Next Review: 01 July 2027. Approved By: Board of Directors. Policy Owner: Compliance & Financial Crime Department. Copyright 2026 SENTINEL PEAK BANK. All Rights Reserved.