IVO
AML Policy
for anti-money laundering and counter-terrorist financing controls on the IVO platform
Version of 5 April 2026
Chapter I. General Provisions
1.1. Purpose and scope
This Policy on the Prevention and Combating of Money Laundering and Terrorist Financing (hereinafter the "AML/CFT Policy" or the "Policy") is developed by IVO Marketplace S.R.L. (hereinafter the "Company" or "IVO Marketplace") in accordance with the applicable legislation of the Republic of Moldova in this field, in particular:
Law No. 308/2017 on the prevention and combating of money laundering and terrorist financing (as subsequently amended, including by Law No. 66/2023);
Law No. 75/2020 on the procedure for establishing violations in the field of prevention of money laundering and terrorist financing and the manner of applying sanctions;
Law No. 25/2016 on the application of international restrictive measures;
Law No. 34/2024 on cash payments;
Government Decision No. 496/2018 approving the Methodology for identifying suspicious money laundering and terrorist financing activities and transactions;
Orders and Guidelines issued by the Service for the Prevention and Combating of Money Laundering (SPCSB);
The recommendations of the Financial Action Task Force (FATF);
Directive (EU) 2015/849, as amended by Directive (EU) 2018/843, insofar as it is relevant in light of the harmonization commitments of the Republic of Moldova.
This Policy establishes the Company's internal framework for preventing and combating money laundering, terrorist financing and the proliferation of weapons of mass destruction and applies to all operations, business relationships and transactions carried out through the ivo.md platform.
This Policy applies to the following categories of persons:
The Administrator and the managers of the Company;
All employees of the Company, regardless of position;
Merchants (vendors/sellers) registered on the IVO Marketplace platform;
Service providers, collaborators, contractors and agents acting in the name or on behalf of the Company.
1.2. Definitions and abbreviations
For the purposes of this Policy, the terms and abbreviations used have the following meanings:
1.3. Fundamental principles
The Company undertakes to comply with the following fundamental AML/CFT principles:
Risk-based approach: The Company identifies, evaluates and monitors money laundering and terrorist financing risks, applying measures proportionate to the identified level of risk.
Zero tolerance: The Company does not tolerate any form of money laundering, terrorist financing or proliferation of weapons of mass destruction.
Compliance: The Company undertakes to comply fully with applicable national legislation and international standards.
Cooperation: The Company cooperates fully with SPCSB, supervisory authorities and law enforcement authorities.
Confidentiality: The Company ensures the confidentiality of reported information and prohibits its disclosure, in accordance with Article 12 of Law No. 308/2017.
Chapter II. Risk Assessment
2.1. Risk assessment at Company level
In accordance with Article 6 of Law No. 308/2017, the Company periodically performs an internal assessment of money laundering and terrorist financing risks, taking into account:
The nature and specifics of the activity: an electronic commerce platform (marketplace) that intermediates transactions between merchants and buyers within the territory of the Republic of Moldova;
The profile of clients: natural persons and legal entities resident in the Republic of Moldova;
Distribution channels: exclusively online, through the ivo.md platform;
Accepted payment methods: card payments, bank transfers and other electronic payment methods;
Geographical area of operation: exclusively the Republic of Moldova;
The national risk assessment (NRA) in the AML/CFT field, published by the competent authorities.
2.2. Identified risk categories
The Company classifies risks into three categories:
Low risk: low-value transactions, properly identified individual customers, payments through regulated banking instruments, recurring transactions of constant value.
Medium risk: new merchants on the platform, transactions above the reporting threshold, customers with complex ownership structures.
High risk: unusual transactions or transactions without economic justification, customers from high-risk jurisdictions (according to FATF lists), politically exposed persons (PEPs), business relationships based on correspondence with entities from third countries.
2.3. Periodic review
The risk assessment is reviewed at least annually or whenever significant changes occur in the Company's activity, the legislative framework or the risk environment.
Chapter III. Customer Due Diligence Measures (CDD/KYC)
3.1. General identification obligations
In accordance with Article 5 of Law No. 308/2017, the Company applies customer due diligence measures in the following situations:
At the start of a business relationship (including the registration of a Merchant on the platform);
When carrying out an occasional transaction equal to or greater than 200,000 Moldovan lei or the equivalent in foreign currency;
Where there is a suspicion of money laundering or terrorist financing, regardless of the value of the transaction;
Where there are doubts as to the accuracy or current validity of previously obtained identification data.
3.2. Identification and verification of the identity of Merchants
3.2.1. Individual Merchants (including sole traders)
When registering on the platform and starting the business relationship, the Company collects and verifies the following data:
Full first and last name;
Date and place of birth;
IDNP (personal identification number);
Residential address/place of residence;
Series, number and date of issuance of the identity document;
Contact details (telephone, e-mail);
Bank account number / IBAN;
Certificate of registration (for sole traders) and tax code.
3.2.2. Legal entity Merchants
For legal entity Merchants, the Company additionally collects:
Full name, legal form of organization and IDNO;
Registered office and actual business address;
Extract from the State Register of legal entities;
Identification data of the administrator/legal representative;
Identification data of the beneficial owner(s);
Ownership and control structure;
Authorization documents (powers of attorney, resolutions of governing bodies).
3.3. Identification of beneficial owners
In accordance with the provisions of Law No. 308/2017, the Company identifies the beneficial owners of all legal entity Merchants, taking reasonable measures to verify their identity, including by:
Verifying the ownership structure until the natural person(s) who directly or indirectly hold more than 25% of the ownership or voting rights are identified;
Identifying the natural person(s) who exercise effective control by other means;
Consulting available public registers (State Register, other official sources).
3.4. Identification of buyers
The IVO Marketplace platform carries out payments through authorized payment processors (financial institutions licensed in the Republic of Moldova). Buyers' identities are verified at the level of the financial institutions that issue the payment instruments. However, the Company collects the buyers' basic data when orders are placed (name, delivery address, contact details) and monitors transactions in order to identify suspicious patterns.
3.5. Enhanced due diligence measures (EDD)
In accordance with Article 8 of Law No. 308/2017, the Company applies enhanced due diligence measures in the following situations:
Merchants or beneficial owners are politically exposed persons (PEPs), family members of PEPs or close associates of PEPs, according to the SPCSB Guideline (Order No. 23/2023);
Complex or unusual transactions, without an apparent economic purpose;
Business relationships with persons or entities from high-risk jurisdictions identified by FATF or SPCSB;
Negative information from public sources or specialized databases;
Any other situation which, by its nature, presents an increased risk of money laundering.
Enhanced due diligence measures include:
Obtaining senior management approval for establishing or continuing the business relationship;
Additional verification of the source of funds and source of wealth;
Enhanced transaction monitoring;
Requesting additional documents and information.
3.6. Simplified due diligence measures (SDD)
Simplified due diligence measures may be applied only in the cases provided for by Article 7 of Law No. 308/2017, when the risk of money laundering is low and based on the criteria established by the supervisory authority. The Company documents the rationale for applying simplified measures.
3.7. Data updating
The Company updates its customers' identification data regularly, at least annually for high-risk customers and every two years for all other customers, as well as whenever there are indications that the existing data is no longer current or accurate.
Chapter IV. Transaction Monitoring
4.1. Monitoring system
The Company implements a system of continuous monitoring of transactions carried out on the IVO Marketplace platform, which includes:
Automated monitoring of the volume and frequency of transactions per Merchant and per buyer;
Setting thresholds and automatic alerts for unusual transactions;
Analysis of transaction patterns and identification of deviations from normal behavior;
Screening transactions against sanctions lists and designated persons/entities.
4.2. Suspicion indicators (red flags)
Without being exhaustive, the following list includes suspicion indicators specific to electronic marketplace activity that will trigger an in-depth review:
Transactions disproportionate in value to the Merchant's declared profile;
Unusual volumes of orders within a short period of time;
Frequent and systematic returns, without obvious commercial justification;
Repeated orders from the same buyer to the same Merchant, in round amounts;
Use of multiple accounts or identities by the same person;
The Merchant's refusal to provide information requested during the CDD procedure;
Listing products at prices significantly different from the market price;
Transactions that appear to have no commercial or economic purpose;
Requests for refunds to an account other than the one associated with the original order;
Negative information about the Merchant obtained from public sources.
4.3. Internal review procedure
Upon detection of a suspicion indicator, the person assigned with AML duties performs an internal review that includes:
Verification of the completeness and up-to-date nature of the identification data;
Analysis of the customer's previous transactions;
Assessment of the economic justification of the transaction(s);
Consultation of open sources of information;
Documentation of the conclusions and of the decision to report or not to report.
Chapter V. Reporting to SPCSB
5.1. Reporting obligations
In accordance with Article 11 of Law No. 308/2017, the Company is required to report to the Service for the Prevention and Combating of Money Laundering (SPCSB):
Suspicious activities or transactions: Any activity or transaction in respect of which there are suspicions of money laundering, predicate offences, terrorist financing or proliferation of weapons of mass destruction - immediately, but no later than 24 hours from the emergence of the suspicion;
Cash transactions: Cash transactions equal to or greater than 100,000 Moldovan lei or the equivalent in foreign currency;
High-value transactions: Transactions of at least 200,000 Moldovan lei or the equivalent in foreign currency, carried out by bank transfer;
Reporting shall be performed by completing the special forms and transmitting them to SPCSB through the secure channel, in accordance with the Methodology approved by SPCSB Order No. 20/2023.
5.2. Tipping-off prohibition
In accordance with Article 12 of Law No. 308/2017, the Company, its employees and persons holding positions of responsibility are required NOT to disclose to customers or third parties that information has been transmitted to SPCSB or that reviews or financial investigations are being carried out regarding actions of money laundering or terrorist financing.
Failure to comply with this prohibition constitutes a serious breach and entails disciplinary, administrative and/or criminal sanctions, as applicable.
5.3. Refraining from executing the transaction
Where grounds for suspicion exist and SPCSB orders the suspension of the transaction, or where the designated person considers abstention necessary, the Company shall interrupt the processing of the relevant transaction until SPCSB's instructions are received or until the situation is clarified, in accordance with Article 9 of Law No. 308/2017.
Chapter VI. Data and Document Retention
In accordance with Article 9 of Law No. 308/2017, the Company retains:
All documents and information on customers and beneficial owners obtained within the customer due diligence measures, including copies of identification documents, for the duration of the business relationship and for 5 years after its termination;
Records and primary documents, business correspondence, the results of reviews performed to identify complex or unusual transactions, for a period of 5 years from the date of the transaction;
Information regarding reports submitted to SPCSB, for a period of 5 years from the reporting date;
The retained data must be sufficient to enable the reconstruction of each transaction to the extent necessary for use as evidence in criminal, administrative or other judicial proceedings.
Data retention is carried out in compliance with the provisions of Law No. 133/2011 on the protection of personal data and the General Data Protection Regulation (GDPR), insofar as it is applicable.
Chapter VII. International Sanctions and Restricted Lists
In accordance with Law No. 25/2016 on the application of international restrictive measures and Article 34 of Law No. 308/2017, the Company:
Verifies all Merchants, beneficial owners and, where appropriate, buyers, against consolidated sanctions lists, including UN, EU and national lists;
Refuses registration on the platform or execution of transactions for the benefit of persons, groups or entities included on sanctions lists;
Blocks and immediately reports to SPCSB and the Intelligence and Security Service (SIS) any funds or assets identified as belonging to designated persons/entities;
Updates screenings whenever sanctions lists are amended.
The sanctions lists screened include, without limitation:
The consolidated list of the UN Security Council;
The European Union restrictive measures lists;
The list of entities involved in terrorist activities, published by SIS;
The lists of high-risk jurisdictions designated/monitored by FATF.
Chapter VIII. Organizational Structure and Responsibilities
8.1. Person designated with AML/CFT duties
In accordance with Article 13 of Law No. 308/2017, the Administrator of the Company appoints a person with duties in the field of prevention and combating of money laundering and terrorist financing (hereinafter the "Designated AML Person").
The Designated AML Person has the following main responsibilities:
Coordinating the implementation of this Policy;
Performing the review of suspicious transactions and making decisions regarding reporting to SPCSB;
Communicating with SPCSB and the supervisory authorities;
Organizing periodic staff training;
Updating the risk assessment periodically;
Ensuring ongoing compliance with AML/CFT legislation.
8.2. Responsibilities of the Administrator
The Administrator of the Company:
Approves and updates this Policy;
Ensures the resources necessary for implementing AML/CFT measures;
Supervises the activity of the Designated AML Person;
Decides in exceptional situations (acceptance/refusal of high-risk customers).
8.3. Responsibilities of employees
All employees of the Company are required to:
Know and comply with the provisions of this Policy;
Immediately report to the Designated AML Person any suspicious activity or transaction;
Participate in the training programs organized by the Company;
Not disclose information relating to reports submitted to SPCSB or to ongoing investigations.
Chapter IX. Staff Training
In accordance with Article 13(3) of Law No. 308/2017, the Company implements an ongoing staff training program that includes:
Initial training: Upon hiring, each employee is trained on this Policy, the legal AML/CFT obligations and the internal reporting procedures;
Periodic training: At least annually, staff participates in update sessions on legislative changes, new money laundering typologies and best practices in the field;
Specialized training: The Designated AML Person participates in the trainings organized by SPCSB and other competent authorities, in accordance with Article 4 of Law No. 308/2017;
Training documentation: The Company keeps records of all training sessions, participants and the content presented.
Chapter X. Specific Measures for Marketplace Operations
10.1. Merchant onboarding
The process of registering Merchants on the IVO Marketplace platform includes mandatory AML compliance steps in the following sequence:
Completion of the registration form with all required identification data;
Provision of copies of identification and registration documents;
Verification by the Company of identity and beneficial owners;
Screening against sanctions lists;
Assessment of the risk associated with the Merchant;
Approval or refusal of registration, with reasons provided for refusal;
Execution of the Merchant Agreement, which contains AML/CFT clauses.
10.2. Control of listed products
The Company monitors the listing of products on the platform in order to prevent the use of the marketplace for illicit purposes, including:
Prohibiting the listing of products whose sale is prohibited or restricted under the legislation of the Republic of Moldova;
Monitoring abnormal prices (prices significantly below or above market value);
Verifying product descriptions in order to identify indications of illicit activities.
10.3. Payment processing and settlement
All transactions on the IVO Marketplace platform are processed exclusively through authorized payment processors. The Company:
Does not accept direct cash payments;
Ensures full traceability of all financial flows;
Reserves the right to delay or block settlement to Merchants where money laundering suspicions exist or pending SPCSB instructions;
Processes refunds exclusively to the account associated with the original order, in accordance with the Company's refund policy.
10.4. Suspension and termination of the business relationship
The Company reserves the right to suspend or terminate the business relationship with a Merchant in the following cases:
Refusal to provide the information or documents requested during the CDD/EDD process;
Provision of false or incomplete information;
Identification of suspicious activities or transactions that have not been remedied;
Inclusion in international sanctions lists;
Any other serious breach of this Policy or of AML/CFT legislation.
Chapter XI. Sanctions for Non-Compliance
Failure by the Company's employees to comply with the provisions of this Policy may result in:
Disciplinary sanctions, in accordance with labor legislation and the Company's internal regulations;
Administrative liability, in accordance with Law No. 75/2020;
Criminal liability, in accordance with the Criminal Code of the Republic of Moldova, including Article 243 (money laundering).
According to Law No. 75/2020, the sanctions applicable to the reporting entity for violations of AML/CFT legislation may include mandatory prescriptions, financial fines and other remedial measures established by SPCSB or by the competent supervisory authority.
Chapter XII. Final Provisions
12.1. Entry into force
This Policy enters into force on the date of its approval by the Company's Administrator and is binding on all persons mentioned in section 1.1.
12.2. Review
This Policy is reviewed at least annually or whenever significant changes occur in the legislative framework or in the Company's activity. Any amendment to this Policy shall be approved by the Company's Administrator.
12.3. Communication
This Policy is brought to the attention of all employees by acknowledgment signature. A relevant excerpt from this Policy shall be communicated to Merchants at the moment of their registration on the platform, as an integral part of the Merchant Agreement.
12.4. Contact
For any reports, questions or clarifications regarding this Policy, the responsible person may be contacted at the following e-mail address: [email protected].
Contact Information
IVO Marketplace S.R.L.
IDNO: 1024602014330
Registered office: Bălți, Filip Nicolae str. 2, Republic of Moldova
This AML Policy was last updated on 5 April 2026 and takes effect from the date of publication on the Platform.