1Introduction
EXICASH SDN BHD ("EXICASH", "we", "us", or "our") is committed to maintaining a safe, lawful, and trustworthy technology platform.
This AML/CFT & Sanctions Compliance Statement ("Statement") explains EXICASH's approach to anti-money laundering, countering financing of terrorism, countering proliferation financing, sanctions compliance, fraud prevention, prohibited business controls, suspicious activity escalation, merchant onboarding support, and cooperation with licensed payment partners.
EXICASH provides technology, integration, dashboard, API, payment link, QR payment integration, reconciliation, reporting, fraud monitoring tools, white-label frontend, onboarding assistance, and technical support.
Regulated payment processing, acquiring, settlement, payout, refund processing, chargeback handling, transaction reversal, transaction holding, and related regulated payment services are provided by licensed or registered third-party payment partners where applicable.
This Statement should be read together with EXICASH's Terms of Service, Privacy Policy, Partner / Third-Party Payment Provider Disclosure, Data Processing Agreement / Data Protection Addendum, Information Security Policy / Security Statement, Anti-Bribery / Anti-Corruption Policy, Referral Partner Agreement, and any other policies issued by EXICASH from time to time.
2Important Regulatory Position
EXICASH is a technology provider. EXICASH is not a bank, financial institution, licensed merchant acquirer, e-money issuer, remittance provider, money services business, deposit-taking institution, card issuer, card scheme, or regulated payment operator, unless expressly stated otherwise in writing and supported by the relevant regulatory approval.
This Statement does not represent that EXICASH is a regulated reporting institution unless required by applicable law or confirmed in writing by the relevant authority.
However, EXICASH applies internal risk controls and cooperates with licensed payment partners, regulators, law enforcement agencies, banks, acquirers, and other relevant parties to prevent misuse of its technology services.
3Purpose of This Statement
The purpose of this Statement is to:
- prevent misuse of EXICASH technology for money laundering, terrorism financing, proliferation financing, sanctions evasion, fraud, scams, illegal activity, or prohibited businesses;
- support merchant onboarding and verification processes;
- help licensed payment partners perform their compliance, risk, and regulatory obligations;
- identify and escalate suspicious activity;
- protect EXICASH, merchants, consumers, payment partners, and the wider payment ecosystem;
- define merchant obligations when using EXICASH services;
- allow EXICASH to reject, suspend, restrict, or terminate access where risk is unacceptable.
4Scope
This Statement applies to:
- merchants using EXICASH services;
- directors, shareholders, beneficial owners, office bearers, and representatives of merchants;
- authorised users of merchant accounts;
- referral partners;
- technology partners;
- service providers;
- consumers or payers where transaction data is processed through EXICASH technology;
- any person or entity using, accessing, integrating with, or benefiting from EXICASH services.
This Statement applies to all EXICASH services, including:
- merchant dashboard;
- APIs;
- webhooks;
- plugins;
- payment links;
- QR payment tools;
- FPX integration;
- DuitNow QR integration;
- credit and debit card integration;
- e-wallet integration;
- BNPL integration;
- payout or disbursement API connectivity;
- split payment configuration;
- subscription or recurring billing tools;
- reconciliation dashboard;
- settlement report display;
- fraud monitoring tools;
- white-label frontend;
- onboarding and KYB/KYC assistance;
- technical support.
5Definitions
For the purpose of this Statement:
"AML" means anti-money laundering.
"CFT" means countering financing of terrorism.
"CPF" means countering proliferation financing.
"Sanctions" means legal or regulatory restrictions imposed by Malaysia, the United Nations, or other applicable authorities relating to designated persons, entities, countries, activities, goods, services, or transactions.
"Licensed Payment Partner" means any licensed bank, registered merchant acquirer, e-money issuer, payment gateway, financial institution, card processor, e-wallet provider, BNPL provider, payout provider, payment network, or other regulated payment partner involved in payment processing, acquiring, settlement, refund, chargeback, payout, risk review, or related regulated services.
"Merchant" means a company, sole proprietor, partnership, association, NGO, organisation, or other accepted entity using EXICASH services.
"Beneficial Owner" means the natural person who ultimately owns or controls a merchant, directly or indirectly, or on whose behalf a transaction or activity is conducted.
"Politically Exposed Person" or "PEP" means an individual who is or has been entrusted with a prominent public function, including their immediate family members or close associates, as determined by applicable law, partner requirements, or risk review standards.
"Suspicious Activity" means any transaction, behaviour, pattern, document, instruction, account activity, business model, or conduct that may indicate money laundering, terrorism financing, proliferation financing, sanctions evasion, fraud, scam activity, prohibited business activity, false information, unauthorised payment aggregation, or other unlawful conduct.
"Prohibited Business" means a business, activity, product, service, transaction, merchant type, or use case that EXICASH or its Licensed Payment Partners do not allow.
"Restricted Business" means a business, activity, product, service, transaction, merchant type, or use case that may require additional review, conditions, approval, documentation, limits, or rejection.
6Compliance Approach
EXICASH adopts a risk-based approach to prevent misuse of its technology services.
Depending on the merchant, business category, transaction pattern, payment method, payment partner requirements, risk indicators, and available information, EXICASH may apply different levels of review and controls.
These controls may include:
- merchant onboarding review;
- collection of KYB/KYC documents;
- beneficial ownership checks;
- business category review;
- website, social media, or store review;
- prohibited and restricted business screening;
- sanctions and watchlist screening support;
- PEP risk review support;
- fraud signal review;
- transaction pattern monitoring;
- API and webhook activity monitoring;
- support ticket review;
- licensed payment partner escalation;
- suspension or restriction of platform access;
- cooperation with lawful authority requests.
EXICASH may rely on information provided by merchants, licensed payment partners, verification providers, fraud monitoring tools, public sources, transaction data, API logs, webhook logs, and other relevant sources.
7Merchant Onboarding and Verification
Before a merchant is allowed to access certain EXICASH services, payment methods, dashboard functions, production APIs, or partner-supported payment flows, EXICASH may require onboarding and verification documents.
Required information may include, but is not limited to:
- SSM statutory documents;
- company profile;
- business registration information;
- director details;
- shareholder details;
- beneficial ownership information;
- NRIC or passport copies;
- bank statements;
- business bank account details;
- website, social media, or online store URL;
- nature of business;
- product and service information;
- licences, approvals, permits, or certificates;
- tax information;
- proof of business address;
- transaction volume estimates;
- refund, delivery, fulfilment, and chargeback information;
- any other information requested by EXICASH or a Licensed Payment Partner.
EXICASH may collect such documents for onboarding support, internal records, safe keeping, risk review, partner submission, audit, legal compliance, fraud prevention, and service operation.
Final merchant approval may be determined by the relevant Licensed Payment Partner. EXICASH does not guarantee that any merchant will be approved.
8Merchant Information Accuracy
Merchants must provide accurate, complete, current, and truthful information.
Merchants must immediately notify EXICASH of any change to:
- company name;
- business registration status;
- directors;
- shareholders;
- beneficial owners;
- authorised representatives;
- business address;
- bank account details;
- website or social media channels;
- product or service offering;
- nature of business;
- licensing or regulatory status;
- transaction volume;
- refund or chargeback risk;
- ownership or control structure.
EXICASH may reject, suspend, restrict, or terminate services if information provided is false, incomplete, outdated, misleading, suspicious, inconsistent, unverifiable, or not accepted by a Licensed Payment Partner.
9Beneficial Ownership and Control
Merchants may be required to disclose their ultimate beneficial owners, controllers, shareholders, directors, office bearers, or persons who exercise control over the business.
EXICASH may request supporting documents to verify ownership and control.
Merchants must not conceal beneficial ownership, use nominee arrangements to hide control, provide false ownership information, or use EXICASH services on behalf of an undisclosed third party.
If EXICASH or a Licensed Payment Partner is unable to verify beneficial ownership or control, services may be rejected, suspended, restricted, or terminated.
10Prohibited Use
Merchants must not use EXICASH services for any activity involving:
- money laundering;
- terrorism financing;
- proliferation financing;
- sanctions evasion;
- fraud;
- scams;
- phishing;
- mule account activity;
- unauthorised payment aggregation;
- illegal payment services;
- unlawful remittance;
- illegal e-money or wallet activity;
- illegal lending;
- illegal gambling;
- counterfeit goods;
- prohibited or restricted goods;
- misleading investment schemes;
- illegal fundraising;
- false documentation;
- impersonation;
- unauthorised third-party processing;
- any illegal, deceptive, abusive, or high-risk activity.
EXICASH may reject, suspend, restrict, or terminate access where prohibited use is suspected or identified.
11Prohibited and Restricted Businesses
EXICASH does not support high-risk merchants.
The following categories are prohibited or restricted and may be rejected, suspended, terminated, or subject to enhanced review by EXICASH or Licensed Payment Partners.
This list is non-exhaustive and includes, but is not limited to:
11.1 Prohibited Businesses
- illegal goods or services;
- drugs, narcotics, controlled substances, illegal pharmaceuticals, or drug paraphernalia;
- gambling, betting, casino services, lottery, sweepstakes, gaming with cash-out value, or games of chance;
- pornography, adult entertainment, escort services, sexual services, or obscene content;
- firearms, ammunition, explosives, weapons, or regulated defence items;
- counterfeit, pirated, replica, stolen, or unauthorised branded goods;
- products or services that infringe intellectual property rights;
- cryptocurrency, NFTs, token sales, digital asset exchange, mining, staking, virtual asset investment, or unapproved digital asset activity;
- payment aggregation, sub-merchant processing, money transmission, remittance, e-money, wallet, payment facilitation, or payment services without proper approval;
- unlicensed lending, loan sharking, payday loans, debt collection, or unlawful credit services;
- investment schemes, get-rich-quick schemes, pyramid schemes, Ponzi schemes, or misleading wealth programmes;
- unregulated charities, donation campaigns, crowdfunding, or fundraising without proper approval;
- scams, fake documents, fake certificates, fake accounts, impersonation services, or fraudulent schemes;
- hacking tools, malware, spyware, botnets, phishing services, cybercrime tools, or unlawful surveillance tools;
- hate, violence, terrorism, extremism, harassment, or discriminatory activity;
- sanctioned persons, sanctioned entities, sanctioned countries, or transactions prohibited by sanctions requirements;
- any business prohibited by banks, acquirers, card schemes, e-wallet providers, BNPL providers, payment networks, regulators, law enforcement agencies, Licensed Payment Partners, or applicable law.
11.2 Restricted Businesses
The following businesses may require additional review, documents, approvals, conditions, limits, or rejection:
- insurance products or services;
- financial services, investment advisory, brokerage, securities, trading, or wealth products;
- medical, telemedicine, health-related, pharmaceutical, or wellness services;
- online pharmacy or health supplement sales;
- alcohol-related products;
- tobacco, vape, nicotine, or smoking-related products;
- charity, NGO, donation, religious, or fundraising activities;
- travel, ticketing, event, hotel, or tour services;
- education, training, membership, coaching, or subscription businesses with advance payment risk;
- digital goods, software, online courses, downloadable products, or intangible services;
- marketplace, platform, aggregator, reseller, or multi-vendor business models;
- high-value goods such as jewellery, gold, luxury goods, collectibles, or electronics;
- prepayment, stored value, credit, voucher, points, or wallet-like business models;
- businesses with high refund, chargeback, fraud, consumer complaint, or delivery risk;
- businesses requiring licences, permits, or regulatory approval;
- any business category identified as higher risk by EXICASH or Licensed Payment Partners.
EXICASH and Licensed Payment Partners may request additional information, impose limits, reject payment methods, suspend access, or terminate services for any prohibited or restricted business concern.
12Sanctions Compliance
Merchants must not use EXICASH services for transactions involving sanctioned persons, sanctioned entities, sanctioned countries, sanctioned goods, sanctioned services, or activities prohibited under applicable sanctions requirements.
Merchants must not attempt to evade sanctions controls by:
- hiding true ownership;
- using false identities;
- using nominee arrangements;
- routing transactions through third parties;
- concealing the location of parties;
- misdescribing goods or services;
- splitting transactions;
- using alternative websites or accounts;
- using EXICASH services for another undisclosed party.
EXICASH may screen or support screening of merchants, beneficial owners, authorised users, transactions, business categories, or related parties against sanctions lists, watchlists, or partner-provided databases.
If a sanctions concern is identified, EXICASH may reject, suspend, restrict, terminate, escalate, or report the activity where appropriate or required.
13Politically Exposed Persons and Higher-Risk Relationships
EXICASH or Licensed Payment Partners may identify certain merchants, directors, shareholders, beneficial owners, representatives, or related parties as politically exposed persons, close associates, higher-risk persons, or higher-risk entities.
Where higher risk is identified, EXICASH or Licensed Payment Partners may require:
- additional documents;
- source of funds information;
- source of wealth information;
- ownership clarification;
- business justification;
- transaction explanation;
- enhanced review;
- management approval;
- partner approval;
- transaction limits;
- ongoing monitoring.
EXICASH may reject, suspend, restrict, or terminate services where the risk is unacceptable.
14Transaction and Activity Monitoring
EXICASH may monitor transaction activity, API activity, webhook activity, dashboard activity, payment link usage, fraud signals, IP data, device data, and support information for risk and security purposes.
Monitoring may be used to detect:
- suspicious transaction patterns;
- unusual transaction volume;
- multiple failed payment attempts;
- abnormal refund or chargeback patterns;
- transactions inconsistent with the merchant's declared business;
- prohibited business activity;
- unauthorised payment aggregation;
- suspicious IP or device signals;
- API misuse;
- credential compromise;
- false payment confirmations;
- consumer complaints;
- partner alerts;
- potential fraud, scam, AML/CFT, sanctions, or security risks.
EXICASH may use internal tools, third-party tools, partner information, manual review, or automated indicators to support monitoring.
Monitoring does not guarantee that all suspicious activity, fraud, sanctions risk, money laundering, terrorism financing, or prohibited activity will be detected.
15Suspicious Activity Indicators
Examples of suspicious activity may include, but are not limited to:
- merchant refuses to provide required documents;
- merchant provides false, inconsistent, or altered documents;
- merchant conceals beneficial ownership;
- merchant changes business activity after approval;
- merchant processes transactions unrelated to declared business;
- merchant processes for another undisclosed business or third party;
- merchant uses payment links for unknown or unverifiable goods or services;
- unusual spike in transaction volume;
- repeated small transactions followed by large transactions;
- high failed-payment attempts;
- high refund or chargeback ratio;
- repeated consumer complaints;
- unusual cross-border indicators;
- use of multiple accounts to avoid review;
- transaction splitting;
- use of personal bank accounts for business activity where not approved;
- mismatch between business name, bank account, website, and product offering;
- suspicious IP, device, or location pattern;
- requests to bypass verification;
- requests not to record or report activity;
- suspicious use of payout or disbursement tools;
- signs of scam, phishing, impersonation, mule account activity, or unlawful fundraising.
If suspicious activity is identified, EXICASH may take action under this Statement and the Terms of Service.
16Actions EXICASH May Take
If EXICASH suspects money laundering, terrorism financing, proliferation financing, sanctions evasion, fraud, prohibited business activity, unauthorised payment aggregation, illegal activity, or breach of this Statement, EXICASH may:
- request additional documents or explanations;
- restrict dashboard access;
- suspend API keys;
- rotate or revoke credentials;
- disable payment links;
- suspend plugins or integrations;
- suspend production access;
- restrict certain payment methods;
- escalate the matter to Licensed Payment Partners;
- cooperate with partner investigations;
- support refund, chargeback, or dispute investigation where applicable;
- preserve records;
- reject onboarding;
- terminate the merchant account;
- report or disclose information to relevant parties where required or appropriate;
- take legal action where necessary.
Any settlement hold, payout delay, transaction reversal, refund, chargeback, or settlement restriction will generally be handled by the relevant Licensed Payment Partner, bank, acquirer, payment provider, scheme, or authority.
17Cooperation with Licensed Payment Partners
Merchants acknowledge that Licensed Payment Partners may be responsible for regulated payment processing, acquiring, settlement, payout, refund processing, chargeback handling, transaction reversal, transaction monitoring, regulatory reporting, and related payment obligations.
EXICASH may share relevant merchant information, KYB/KYC documents, transaction data, API logs, webhook logs, fraud signals, support tickets, and risk information with Licensed Payment Partners where necessary for:
- onboarding;
- merchant approval;
- payment method approval;
- risk review;
- compliance checks;
- fraud prevention;
- transaction monitoring;
- chargeback handling;
- refund support;
- dispute review;
- AML/CFT review;
- sanctions screening;
- investigation;
- legal or regulatory obligations.
Merchants must cooperate with EXICASH and Licensed Payment Partners by providing documents, explanations, transaction evidence, consumer information, fulfilment records, invoices, delivery proof, refund records, business records, and any other information reasonably requested.
Failure to cooperate may result in suspension, restriction, rejection, or termination of EXICASH services or payment partner services.
18Law Enforcement and Regulatory Cooperation
EXICASH may cooperate with regulators, law enforcement agencies, government authorities, courts, banks, acquirers, payment networks, Licensed Payment Partners, and other relevant parties where legally required or reasonably necessary.
This may include disclosure of:
- merchant information;
- beneficial ownership information;
- KYB/KYC documents;
- transaction records;
- payment references;
- API logs;
- webhook logs;
- IP and device data;
- fraud signals;
- support tickets;
- communications;
- risk review notes;
- other relevant information.
EXICASH may be restricted from notifying the Merchant about certain disclosures, investigations, or requests if prohibited by law, regulator instruction, partner instruction, court order, or investigation requirements.
19No Tipping-Off or Interference
Merchants must not interfere with investigations, destroy evidence, falsify documents, conceal information, warn suspected wrongdoers where prohibited, or obstruct EXICASH, Licensed Payment Partners, regulators, law enforcement agencies, or authorities.
Merchants must not instruct employees, contractors, consumers, or third parties to provide false information, hide records, delete communications, or mislead EXICASH or Licensed Payment Partners.
Any attempt to interfere with an investigation may result in immediate suspension or termination.
20Merchant Obligations
Merchants must:
- use EXICASH services only for lawful business purposes;
- provide accurate, complete, and current onboarding information;
- disclose true beneficial ownership and control;
- comply with all applicable laws, regulations, payment partner rules, card scheme rules, bank requirements, e-wallet requirements, BNPL provider requirements, and EXICASH policies;
- maintain valid licences, permits, registrations, and approvals required for their business;
- ensure their products and services are lawful;
- maintain clear refund, delivery, cancellation, and consumer support policies where applicable;
- monitor their own transactions and consumer complaints;
- protect API keys, credentials, dashboard access, and systems;
- report suspicious activity or security incidents promptly;
- cooperate with EXICASH and Licensed Payment Partners;
- not use EXICASH services for prohibited or restricted activity;
- not process transactions for undisclosed third parties;
- not act as a payment aggregator, payment facilitator, e-money provider, wallet provider, remittance provider, or payment service provider without proper approval.
21Referral Partner Obligations
Referral partners must not refer merchants that they know or suspect to be involved in illegal, prohibited, fraudulent, sanctioned, or high-risk activities.
Referral partners must not:
- misrepresent EXICASH's services or regulatory status;
- promise merchant approval;
- promise settlement timelines;
- hide merchant business information;
- submit false documents;
- refer merchants using nominee structures;
- encourage merchants to avoid verification;
- accept improper benefits for approval;
- refer merchants for prohibited or restricted activity.
Referral commissions, incentives, or fees may be withheld, clawed back, suspended, or cancelled if the referred merchant is rejected, suspended, terminated, fraudulent, prohibited, or involved in suspicious activity.
22Record Keeping
EXICASH may retain records for legal, compliance, audit, tax, accounting, fraud prevention, partner, dispute, investigation, and security purposes.
Records may include:
- onboarding documents;
- KYB/KYC documents;
- beneficial ownership records;
- merchant account records;
- transaction records;
- payment references;
- API logs;
- webhook logs;
- fraud signals;
- support tickets;
- risk review notes;
- partner communications;
- suspension or termination records;
- referral records;
- billing records.
Records may be retained for up to seven (7) years or such longer period as may be required or permitted by law, partner requirements, regulatory requirements, audit requirements, tax obligations, dispute handling, or legal proceedings.
23Data Protection
EXICASH processes personal data in accordance with its Privacy Policy and Data Processing Agreement / Data Protection Addendum.
Merchants are responsible for ensuring that personal data provided to EXICASH has been collected and disclosed lawfully.
Merchants must provide appropriate privacy notices and obtain required consents from directors, shareholders, beneficial owners, authorised users, representatives, employees, consumers, payers, and other individuals whose personal data is provided to EXICASH or Licensed Payment Partners.
EXICASH may share personal data and transaction information with Licensed Payment Partners, verification providers, fraud monitoring providers, regulators, law enforcement agencies, professional advisers, and service providers where necessary for the purposes described in this Statement.
24Confidentiality
EXICASH will treat merchant information, onboarding documents, transaction records, and risk review information as confidential, subject to disclosure permitted under this Statement, the Terms of Service, Privacy Policy, Data Processing Agreement, partner requirements, and applicable law.
Merchants must also keep confidential any information relating to EXICASH systems, APIs, credentials, risk controls, compliance review, investigations, partner requirements, and security procedures.
Confidentiality obligations survive termination of EXICASH services.
25Suspension, Restriction, and Termination
EXICASH may suspend, restrict, disable, or terminate access to its services immediately, with or without notice, if:
- the Merchant breaches this Statement;
- suspicious activity is detected;
- prohibited or restricted business activity is identified;
- false or misleading information is provided;
- beneficial ownership cannot be verified;
- API keys or credentials are compromised;
- a Licensed Payment Partner instructs suspension or termination;
- a regulator, authority, or law enforcement agency requests action;
- the Merchant fails to cooperate with review or investigation;
- continued service may expose EXICASH, consumers, partners, or the payment ecosystem to unacceptable risk.
Termination does not affect obligations relating to fees, data retention, confidentiality, indemnity, cooperation, investigation, dispute handling, or legal compliance.
26Limitation of EXICASH's Role
EXICASH's role under this Statement is limited to technology, onboarding support, communication support, risk controls, fraud monitoring tools, partner cooperation, and platform protection.
EXICASH does not guarantee that:
- all suspicious activity will be detected;
- all fraud will be prevented;
- all sanctions risks will be identified;
- all merchants approved by partners are risk-free;
- all partner investigations will be resolved in favour of the Merchant;
- all transactions will be processed or settled;
- payment partners will approve, maintain, or continue services for any Merchant.
Merchants remain responsible for their own business, products, services, consumers, transactions, legal compliance, refund obligations, chargeback evidence, and conduct.
27Indemnity
The Merchant agrees to indemnify and hold harmless EXICASH, its directors, officers, employees, agents, service providers, partners, and affiliates from and against any claims, losses, damages, penalties, fines, costs, liabilities, chargebacks, disputes, regulatory actions, partner claims, consumer claims, and expenses arising from:
- breach of this Statement;
- money laundering, terrorism financing, proliferation financing, sanctions evasion, fraud, scam activity, or illegal activity;
- prohibited or restricted business activity;
- false, incomplete, misleading, or outdated information;
- failure to disclose beneficial ownership;
- unauthorised payment aggregation or third-party processing;
- violation of payment partner rules;
- violation of applicable law;
- consumer disputes;
- chargebacks, refunds, reversals, or fraud claims;
- misuse of EXICASH services;
- leaked or compromised API keys caused by the Merchant;
- failure to cooperate with investigations;
- claims by Licensed Payment Partners, consumers, regulators, banks, acquirers, law enforcement agencies, or other third parties.
28Review and Updates
EXICASH may review and update this Statement from time to time to reflect changes in law, regulation, payment partner requirements, business operations, risk environment, prohibited business categories, sanctions requirements, payment methods, or internal controls.
The latest version may be published on www.exicash.com or made available through the dashboard, email, or other communication channels.
Continued use of EXICASH services after updates means that the Merchant acknowledges the revised Statement.
29Contact
For AML/CFT, sanctions, suspicious activity, fraud, prohibited business, or compliance-related matters, please contact:
EXICASH SDN BHD
Company Registration No.: 202601015752 (1677849-M)
Address: 16-19, Menara Mutiara Sentral, No. 2, Jalan Desa Aman 1, Cheras Business Centre, 56000 Kuala Lumpur, Malaysia
Email: support@exicash.com
Website: www.exicash.com