Home / AML & KYC
Last updated 26 August 2026. How we verify identity, which sanctions lists we screen against, what we watch for in payments, and what happens when something is found.
This is the anti-money-laundering (AML) and know-your-customer (KYC) policy of FDO Software LTD, registered in England & Wales under company number 17366935, operating FundedPortal. It describes the controls we actually run — not controls we aspire to. Where a section says we screen, verify or hold something, there is a system or a person doing exactly that.
Two honest framings before anything else. First, we operate simulated trading assessments: no client money is deposited with us, no real trades are placed, and the only money of yours we ever hold is the assessment fee. That makes our exposure to money laundering structurally narrower than a broker's or a bank's. Second, we are not a financial institution and not authorised by the FCA, and we are not within the class of businesses that the UK Money Laundering Regulations 2017 directly supervise. We say that plainly because a compliance page that implies regulated status would itself be misleading.
We still run the programme on this page, for three reasons that apply to us in full:
Money laundering is making money from crime look legitimate. Terrorist financing is moving money — clean or not — towards terrorism. A simulated-trading business meets both in specific, concrete shapes rather than in the abstract:
Every control on this page traces back to one of those shapes. We do not run theatre controls that exist only to be listed.
We size controls to risk, which is what the FATF recommendations and UK guidance both ask of any business, regulated or not. Our own assessment of this service:
| Structurally low risk | We take no deposits, hold no client money and offer no withdrawable balances. Account balances are virtual. The single product is a fixed, published fee in a low retail band, paid once per assessment. |
|---|---|
| Where the risk actually sits | Money leaves us in two ways only: refunds of the fee and reward payments to successful participants. Both routes carry every control in this policy. |
| Aggravating signals | Mismatched identities, third-party payment attempts, several accounts sharing one device or payout destination, activity from restricted jurisdictions, unusually large or unusually fast movements. |
We keep an internal, written risk assessment behind this table and revisit it when the product, the payment routes or the sanctions landscape change.
We apply two distinct tests. For most of the list the restriction is on location — residence and the network address you connect from. For countries under comprehensive embargo it also covers nationality, because dealing with those jurisdictions carries risk wherever the person lives.
We do not restrict nationalities beyond that group. Under UK law nationality is a protected characteristic and a blanket refusal on nationality alone is direct discrimination; UK sanctions law itself turns on residence and presence rather than on the passport held. Restricting more than the law requires would expose us rather than protect us.
| Comprehensive sanctions · FATF call for action location and nationality | Iran, North Korea, Myanmar, Syria, Cuba |
|---|---|
| Extensive financial-services sanctions location only | Russian Federation, Belarus |
| Occupied territories of Ukraine | Crimea (UA-43), Sevastopol (UA-40), and the occupied parts of Donetsk (UA-14), Luhansk (UA-09), Zaporizhzhia (UA-23) and Kherson (UA-65). Ukraine as a whole is not restricted. |
| Restricted for other reasons | United States and its territories (derivatives regulation); Belgium (national retail-product prohibition) |
The occupied territories share Ukraine's country code, so a country-level block cannot reach them — they are enforced at region level (ISO 3166-2), separately from the country list. The complete list with the reasoning for each entry is published at restricted jurisdictions, and it is held in one place in our systems: the country gate, the identity check and the reward gate all read the same version.
The check runs at sign-up, at payment, at verification and again before any reward is released. Network-address checks can be evaded with a VPN and we do not claim otherwise; that is why the identity and payment checks sit behind them. Giving false residence or nationality details to get past these checks is a prohibited practice and ends the assessment without refund.
Verification is staged where it protects money, not where it would merely collect documents:
| At registration | You give your name, email and phone number, and they must be accurate — the account is personal and may only be used by you. No documents are collected at this stage. |
|---|---|
| At purchase | Payment must come from a method in your own name. No documents are collected for the purchase itself. |
| Before any reward | Full verification is mandatory and blocking. No reward payment leaves us to an unverified person, without exception. |
Full verification means: a government-issued photo identity document (both sides where the document has two), a live selfie matched against it, and — where the documents leave doubt about residence — a proof of address. The details must match your registration details; a mismatch is investigated, not waved through. Verification must be completed by you personally: sending your documents through, or to, a third party is itself a ground for refusal.
Document authenticity and the liveness check — confirming that a live person, and not a photograph or a recording, is presenting the document — are performed by a specialist identity-verification provider. The provider carries out the biometric comparison between the selfie and the document portrait; the accept-or-decline decision remains ours, and responsibility for it cannot be delegated to a vendor.
The provider is named in the privacy policy, and in the KYC provider note supplied to our payment partners. Naming it there rather than here is deliberate: a change of vendor should update one row, not force a re-issue of this policy. Any new provider is named there before it processes its first document.
Those checks have been running since 25 August 2026. The gate in section 5 does not depend on the provider and never did: no reward payment is released to an unverified participant. If the provider were unavailable we would hold the payment rather than pretend a check happened.
Every verification decision is made or reviewed by a person.
What happens to the documents afterwards is deliberately conservative: the image of your document is deleted 90 days after the decision, and we keep the fact and outcome of the check — what was checked, by whom, when, and the result — for five years. The reasoning is in the privacy policy: a picture we no longer hold cannot leak.
We screen names against two official lists, refreshed weekly from their government sources:
| UK consolidated list (OFSI) | The list that legally binds us as a UK company. It also carries the UN designations as implemented in UK law. |
|---|---|
| US OFAC SDN list | Screened because our payment and banking routes touch US-dollar infrastructure, and because the terms exclude comprehensively US-sanctioned regions. |
Screening runs three times in an account's life: when you register, when a purchase is approved, and — decisively — before any reward payment is approved. A match at registration or purchase creates a compliance alert and is reviewed by a person; a match that is still open when a reward is requested blocks the payment until a person has resolved it. Matching is done on full names with safeguards against single-surname coincidences, and no account is refused by the software alone: a human looks at every match.
Where a sanctions match is involved we may be legally unable to tell you the detail, because disclosure can itself be unlawful. The complaints page explains what we can and cannot say in that situation, and how to appeal.
Payments and accounts are watched for the patterns that section 2 describes, and the watching produces alerts for a human queue — it does not silently close accounts:
| Large movements | Every reward payment is approved by a person, whatever the amount — there is no threshold below which one is released automatically. The assessment fee is a fixed published amount, so there is no payment size to monitor on the way in. |
|---|---|
| Rapid in-and-out | Money that arrives and asks to leave within a short window is flagged as a possible layering pattern. |
| Money in versus money out | Our systems carry the balance checks a broker-shaped platform needs — a withdrawal larger than what came in, or money that arrives and asks to leave again quickly, raises an alert. They are inherited safeguards rather than product features: the fee is the only money you send us, so in normal operation they have nothing to act on. |
| Linked accounts | Accounts sharing a device fingerprint, network address, phone number or payout destination are matched to each other and risk-scored. One person is entitled to one identity here. |
Alert thresholds and matching rules are reviewed against what actually gets caught, and the system keeps an audit trail of every alert, every review and every decision.
In order of severity, we can: ask you to explain — including evidence of the source of a payment where that is the doubt; hold a specific payment while we review; refuse the relationship, refund the fee and close the account; or, where the law requires or permits, report the matter to the authorities. Which of these happens is decided by a person reviewing the full record, and except where disclosure would be unlawful, you are told that a hold exists and what would lift it — that promise is in the complaints page, section 7, and it applies to compliance holds too.
Where we know or suspect that money touching the service is the proceeds of crime, we report to the UK National Crime Agency through a suspicious activity report, and where a payment cannot lawfully proceed without consent, we seek that consent before moving it. We are entitled to report even though we are outside the supervised sector, and we treat it as an obligation in substance. One report is not voluntary at all: where information arising in this business gives rise to a suspicion of terrorist financing, reporting it is a legal duty for any business, and we comply with it. Suspected dealings with a designated person are frozen and reported to OFSI.
We answer lawful requests from law enforcement and regulators, and we may be unable to tell you that a report or request exists — disclosure that prejudices an investigation is itself an offence, and silence in that situation is compliance, not discourtesy.
| Identity document images | 90 days after the verification decision, then deleted. |
|---|---|
| Verification and screening records | 5 years after the relationship ends — what was checked, the outcome, the reviewer and the sanctions-screening result. |
| Compliance alerts and reviews | 5 years — every alert, who reviewed it, what was decided and why. |
| Account and payment records | 6 years, matching the period in which a legal claim could still arise. |
These periods are enforced by a scheduled job, not by memory; the same table, with the data-protection reasoning, is in the privacy policy.
This policy has a single accountable owner: Furkan Doğanay Oğuz, Director and Nominated Officer at FDO Software LTD. Every reward payment is approved by a person, not a script; every compliance alert lands in a queue that a person clears; and the people doing both are trained on this policy and on the patterns in section 2 before they touch the queue. The policy is reviewed at least annually, and whenever the payment routes, the product or the law changes.
Breaking these is a prohibited practice under the terms: the assessment ends, the fee is not refunded where the breach is yours, and section 10 may apply.
Changes to this policy are published here with a new date at the top of the page. Material changes — a new verification stage, a new list screened, a new retention period — are announced to account holders before they take effect.
| Compliance questions | support@fundedportal.com |
|---|---|
| Post | FDO Software LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom |
| Appeals | The complaints and disputes process, including human review of automated decisions |