Last updated 22 August 2026

Anti-Money-Laundering and Sanctions Policy

A public summary of how we identify customers, screen against sanctions, monitor activity and meet reporting obligations — including the parts customers find frustrating, and why they exist.

Contact Compliance

This page is a summary written for customers. The full internal programme is a separate document maintained with our issuing partner and finalised before accounts open; where the two differ, the internal programme governs.

Our Commitment

NELVOI does not tolerate the use of its services for money laundering, terrorist financing, sanctions evasion or the proceeds of crime. We maintain a written anti-money-laundering and counter-terrorist-financing programme, appoint an officer responsible for it, and cooperate fully with regulators and law enforcement.

These obligations apply regardless of commercial impact. Where compliance and revenue conflict, compliance takes precedence — including where that means refusing a customer, refusing a transaction, or ending a relationship that was profitable.

This is not a formality we resent. A card programme that launders money loses its issuing partner, its banking access and its right to operate, usually in that order and usually within weeks. The controls below exist because they are the law, and they survive because they are also the only way this business continues to exist.

The Risk-Based Approach

Financial regulation does not require every customer to be treated identically. It requires the opposite: that we assess risk and apply effort proportionate to it. A salaried person topping up a hundred dollars a month and a company moving six figures through several jurisdictions present different risks, and treating them the same would mean either harassing the first or under-examining the second.

We assess risk across four dimensions — who the customer is, where they and their money are located, what they use the account for, and how they use it in practice. Each customer carries a risk rating that determines the depth of checks at onboarding, the thresholds that trigger a review, and how often the relationship is re-examined. Ratings are not fixed: behaviour that does not match the stated purpose of an account moves it up.

The Controls in Practice

Six mechanisms, each with a legal basis and each with a cost to us. They are described here in the terms a customer will actually encounter them.

Customer due diligence

Every customer is identified and verified before the account can be used: a government-issued identity document, a liveness check that the face matches it, and confirmation of residence. Business customers additionally have their ownership and control structure verified, including beneficial owners above the statutory threshold, because a company is only as identifiable as the people behind it.

Sanctions and PEP screening

Names are screened against international sanctions lists, terrorist financing lists and politically exposed person databases at onboarding and continuously afterwards — lists change, and a customer who was clear last year may not be today. A screening match is reviewed by a person before any action is taken, because name collisions are common and being called Ivan Petrov is not a finding.

Transaction monitoring

Automated rules flag patterns inconsistent with a customer's expected activity: sudden volume changes, structuring just below thresholds, rapid movement in and out, counterparties in high-risk jurisdictions. Flagged activity is reviewed by a human and not closed automatically. This is why a legitimate payment is occasionally held — an inconvenience we accept over the alternative.

Enhanced due diligence

Higher-risk customers, jurisdictions and transaction patterns require additional documentation and senior approval before the relationship continues. Politically exposed persons, their families and close associates always fall into this category — not as an accusation, but because the law treats their accounts as inherently higher-risk and requires the extra step.

Source of funds and source of wealth

We may ask you to evidence where money came from — a payslip, a sale contract, an exchange statement. This is a legal obligation above certain thresholds and applies to everyone who crosses them; it is not an accusation and it is not something support can waive. Answering it promptly with real documents is almost always the fastest route through.

Record keeping

Identity records, transaction records and the reasoning behind compliance decisions are retained for at least five years after a relationship ends, as required by law. This retention obligation overrides deletion requests: a request to erase your data does not extend to records we are legally required to keep, and any provider promising otherwise is describing something they cannot deliver.

Crypto-Specific Obligations

Funding an account in cryptocurrency adds obligations that a purely fiat provider does not carry, and they are worth setting out plainly because they surprise people.

Blockchain analytics. Incoming crypto transfers are screened against on-chain risk data before the funds are credited. Deposits traced to sanctioned addresses, darknet markets, known theft or mixing services are held for review. The blockchain is public and permanent, which cuts both ways: it means we can see where funds came from, and it means that history stays attached to those funds indefinitely.

The Travel Rule. International standards require that identifying information about the sender and recipient accompanies transfers of virtual assets above certain thresholds between regulated providers. In practice this means a transfer from an exchange may carry your details with it, and transfers to or from providers that cannot meet the requirement may be refused. This is not a policy we chose; it is the Financial Action Task Force standard as implemented in the jurisdictions we operate under.

Self-hosted wallets. Transfers to and from wallets you control yourself receive additional scrutiny in several jurisdictions, and above certain amounts we may need to confirm that the wallet is genuinely yours. The requirement varies by country and is one of the areas where regulation is still moving.

Prohibited Activity

The following will result in refusal or closure, and in defined circumstances in a report to the authorities. This list is not exhaustive; it covers what accounts for most of what we refuse.

Anonymity and third-party use. We cannot open anonymous or pseudonymous accounts, accept an account opened in someone else's name, or allow one person to operate another person's account. An account opened for a person who wishes to stay hidden behind it is the textbook definition of what these rules exist to prevent.

Sanctioned jurisdictions and parties. We cannot serve customers or process transactions involving jurisdictions subject to comprehensive international sanctions, or any party designated on an applicable sanctions list. No commercial consideration overrides this and no appeal to us can change it — the designation is made by governments, not by us.

Proceeds of crime and illegal goods. Funds derived from criminal activity, and payments for goods or services that are illegal in the relevant jurisdiction, including controlled substances, weapons, stolen data, child sexual abuse material and services offering deliberate evasion of financial controls.

Structuring. Deliberately breaking transactions into smaller amounts to stay below reporting or verification thresholds is itself an offence in most jurisdictions, and is one of the specific patterns transaction monitoring is designed to detect.

What Happens If Your Account Is Reviewed

Most reviews end with the account continuing exactly as before. Knowing the sequence in advance makes the process considerably less alarming.

Activity is flagged

Either by an automated rule or by a person. A flag is not a finding and the large majority resolve without any contact with you at all.

We may ask you for information

Usually source of funds, sometimes clarification of what a payment was for. Requests come by email from our own domain and never ask for your password, your two-factor code or your full card number. Answer with actual documents; explanations without evidence rarely close a review.

The account may be restricted while the review runs

In some cases this is a legal requirement rather than our choice. We aim to resolve reviews in days, not weeks, and complex source-of-funds cases take longer because the underlying documents take longer to obtain and check.

The review concludes

The account continues normally, or restrictions are lifted with conditions, or the relationship is ended and your funds are returned through the applicable process. Where a report has been filed with the authorities we are prohibited by law from telling you, which brings us to the next section.

What We Cannot Tell You, and Why

Where a suspicious activity report is filed with a financial intelligence unit, we are prohibited by law from informing the customer that it happened. This is called the tipping-off prohibition, it exists in essentially every jurisdiction with an AML regime, and breaching it is a criminal offence for the individual employee as well as the firm.

The practical consequence is the part people find hardest, and it deserves stating without euphemism: if your account is restricted and support tells you they cannot explain why, this is the most likely reason. It is not a stalling tactic, it is not something a senior person can override, and pressing support harder cannot produce an answer they are legally forbidden to give. We are sorry for how that feels; we are not able to change it.

What you can always do: ask what documents would help, provide them, and ask for the review to be escalated. Those levers work. You can also complain formally, and in most jurisdictions you can complain to the relevant financial regulator or data protection authority independently of us.

Questions About Compliance

Because a regulated card programme cannot legally issue a card to an unidentified person. It is also what makes the card work: verified cards are accepted by merchants and banks that decline anonymous prepaid cards outright, and verification is what allows us to return your money if you lose access to your device. An anonymous card avoids the paperwork by being worse at the job.

No. Identity verification confirms that you are who you say you are and that you are not on a sanctions list. It does not assess creditworthiness, is not reported to credit bureaus, and leaves no mark on your credit file.

Because above certain thresholds the law requires it of everyone, regardless of suspicion. It is genuinely not an accusation — a firm that only asked suspicious customers would be tipping them off, which is itself prohibited. The fastest route through is documents rather than explanation: a payslip, a contract, an exchange statement showing where the money came from.

As long as the review takes, and where a legal hold applies, as long as the authorities require. We aim for days. Complex source-of-funds cases run longer, mostly because obtaining and verifying the underlying documents takes time. We will tell you what we are waiting for whenever we are permitted to.

Yes. Write to [email protected] and ask for the decision to be reviewed, setting out what you think was missed and attaching anything that supports it. Where we are permitted to explain, we will. In most jurisdictions you can also complain to the relevant financial regulator, and to the data protection authority about how your data was handled, independently of anything we say.

Regulated financial providers are subject to automatic exchange of information regimes in many jurisdictions, and where those apply we comply with them. We do not volunteer information beyond what the law requires, and we do not provide tax advice — what you owe and where is between you and your own adviser.

You can hold an account, and you will go through enhanced due diligence, with senior approval and more frequent review. The category also covers family members and close associates. It is not an allegation of anything: the law simply treats these accounts as higher-risk and requires the extra step, and providers who quietly refuse rather than do the work are the reason this needs saying.

[email protected]. Requests should come on official letterhead with the legal basis stated. We respond to properly constituted requests and we do not hand over customer data on an informal approach.

Compliance enquiries

Law enforcement requests, regulatory correspondence and questions about this policy go to [email protected]. We answer compliance mail within five business days.

Contact Compliance