Super Save Protocol operates a fraud-prevention registry for financial institutions. Although we do not hold client funds, take deposits or extend credit, we hold ourselves to standards proportionate to the sector we serve. This policy explains how we screen the institutions we admit, what we monitor, and how we handle sanctions and reporting obligations.
01 Scope and position
Super Save Protocol Ltd is a technology provider. We are not a bank, payment institution, money services business or credit institution, and we do not hold, transmit or control client money.
Our financial crime exposure is therefore indirect: it arises from who we admit as Members, and from the risk that the registry is misused to facilitate rather than prevent fraud. This policy addresses both.
02 Know Your Business (KYB) on admission
No institution obtains registry access before due diligence completes. We verify:
- Legal existence — incorporation documents, registration number, registered address, and current standing from the relevant registry.
- Regulatory status — the licence or authorisation under which the institution carries on its activity, verified against the regulator's public register where one exists.
- Ownership and control — beneficial owners holding 25% or more, and the directors and senior managers who control the business.
- Authorised representatives — identity and authority of the individuals who will act as registry administrators.
- Adverse media and PEP status — screening of the entity, its beneficial owners and its senior officers.
- Purpose — the instruments the institution finances and why registry access is appropriate for it.
Enhanced due diligence applies where the institution is established in a higher-risk jurisdiction, has a complex ownership structure, involves politically exposed persons, or where screening produces an adverse result. Enhanced cases require sign-off by our compliance function.
03 Sanctions screening
We screen applicant and existing Members, their beneficial owners and their senior officers against the consolidated lists maintained by, at minimum:
- the United Nations Security Council;
- the Office of Foreign Assets Control of the United States Treasury;
- the European Union;
- His Majesty's Treasury, United Kingdom;
- lists applicable under Indian law.
Screening runs at onboarding and on an ongoing basis against list updates. A confirmed match results in immediate suspension of access, a freeze on any relevant relationship, and reporting to the competent authority. We do not tip off the subject where the law prohibits it.
04 Ongoing monitoring
- Member records are refreshed on a risk-based cycle — annually for higher-risk Members, every three years otherwise, and immediately on a trigger event.
- Members must notify us within 30 days of a change in ownership, control, licensing status or regulatory standing.
- Registry activity is monitored for patterns consistent with misuse, including submissions that appear engineered to evade duplicate detection.
- Failure to keep records current is grounds for suspension.
05 Suspicious activity and reporting
Staff are trained to escalate anything that suggests money laundering, terrorist financing, sanctions evasion or fraud to the compliance function without delay. The compliance function assesses each escalation and, where the threshold is met, reports to the competent financial intelligence unit.
Escalation is internal and confidential. Staff must not discuss a report with the Member concerned or with anyone outside the escalation path.
Members retain their own reporting obligations. Nothing in the registry, and no output from it, discharges a Member's duty to file its own suspicious activity report.
06 Record keeping
Due diligence records, screening results, escalations and reports are retained for at least five years from the end of the Member relationship, or longer where the law requires. Records are held securely with access limited to the compliance function.
07 Governance, training and independence
- A named compliance officer owns this policy and has direct access to the board.
- The compliance function is independent of commercial targets and cannot be overruled on a screening decision by a sales objective.
- All staff receive financial crime training on joining and annually thereafter, with role-specific training for those in compliance and onboarding.
- The policy is reviewed at least annually and after any material regulatory change.
- Periodic independent testing of controls is commissioned by the board.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.