Anti-Money Laundering (AML) Policy
Last updated 20 July 2026
FinStitch is committed to preventing the misuse of its platform for money laundering, terrorist financing, fraud, sanctions evasion and other financial crime. This policy describes the principles, controls and procedures we use to identify, assess, mitigate and report financial-crime risk.
1. Purpose
FinStitch Limited (“FinStitch”, “we”, “our” or “us”) is committed to preventing the misuse of its platform for money laundering, terrorist financing, fraud, sanctions evasion and other forms of financial crime.
This Anti-Money Laundering (“AML”) Policy describes the principles, controls and procedures adopted by FinStitch to identify, assess, mitigate and report financial-crime risks associated with its services. As a financial technology platform, we maintain high standards of integrity while protecting our users, partners and the wider financial ecosystem.
2. Scope
This policy applies to:
- all FinStitch employees;
- directors;
- contractors;
- consultants;
- temporary staff;
- third-party service providers, where applicable.
It applies to every customer using FinStitch's platform regardless of country of residence.
3. About FinStitch
FinStitch is a personal finance software platform that enables users to:
- monitor their net worth;
- track investments;
- manage financial accounts;
- analyse portfolio performance;
- monitor passive income;
- plan long-term financial goals;
- receive financial insights.
FinStitch is not a bank. We do not hold customer funds, execute investment transactions, or provide regulated investment advice.
Where Open Banking connectivity is offered, customer account access is facilitated through authorised third-party providers operating under applicable regulatory frameworks.
4. AML Principles
FinStitch adopts a risk-based approach to financial-crime prevention. Our objectives are to:
- prevent misuse of our platform;
- identify suspicious behaviour;
- comply with applicable legal obligations;
- protect customers;
- cooperate with authorised authorities where legally required.
5. Risk Assessment
FinStitch continually evaluates financial-crime risks, including:
Customer risk
- false identities;
- impersonation;
- sanctioned persons;
- politically exposed persons (PEPs);
- high-risk jurisdictions.
Product risk
- misuse of financial data;
- fraudulent account creation;
- synthetic identities;
- unauthorised access.
Geographic risk
Additional scrutiny may be applied where customers are associated with jurisdictions subject to sanctions or recognised as presenting elevated financial-crime risk.
Technology risk
- automated account creation;
- credential stuffing;
- account takeover attempts;
- compromised credentials.
6. Customer Due Diligence
FinStitch applies customer due diligence measures proportionate to the services provided. As a personal wealth-tracking platform that does not hold funds or execute transactions, our current services generally do not require formal identity verification. Depending on the product being used, our measures may include:
- email verification;
- confirmation of ownership of connected financial accounts;
- fraud prevention checks;
- risk assessment.
Where a future product or a legal obligation requires identity verification, sanctions screening or similar checks, these would be carried out by regulated third-party providers before access to that functionality is granted.
7. KYC and KYB
FinStitch maintains customer identification procedures appropriate to the nature of its services. These are described in our separate Customer Verification & Onboarding (KYC/KYB) Policy.
8. Politically Exposed Persons (PEPs)
FinStitch does not currently operate PEP screening, as our services do not require it. Where a future product or legal obligation requires it, PEP identification would be carried out through regulated third-party providers, and additional review measures may be applied where elevated risk is identified.
9. Sanctions Compliance
FinStitch does not knowingly provide services to individuals or organisations subject to applicable financial sanctions. We do not currently perform automated sanctions screening; where required by law or by a regulated partner for a given service, such screening would be carried out by that regulated provider. Accounts we become aware are associated with sanctioned individuals may be suspended, restricted or terminated.
10. Suspicious Activity
Examples of behaviour that may trigger investigation include:
- attempted identity fraud;
- use of stolen credentials;
- multiple accounts using false information;
- attempts to circumvent verification controls;
- suspicious use of Open Banking permissions;
- suspected criminal activity;
- attempts to compromise platform security.
Where appropriate, FinStitch may suspend or terminate access while investigations are conducted.
11. Reporting
Where FinStitch becomes aware of suspected criminal activity, it may:
- investigate internally;
- restrict account access;
- cooperate with authorised service providers;
- report matters to competent authorities where legally required.
12. Record Keeping
FinStitch maintains appropriate records relating to:
- customer onboarding;
- verification activities;
- security investigations;
- financial-crime incidents;
- compliance actions.
Records are retained in accordance with our Data Retention Policy and applicable legal requirements.
13. Staff Responsibilities
All personnel are expected to:
- understand this policy;
- report suspected financial crime immediately;
- protect customer information;
- comply with internal security procedures.
Failure to comply may result in disciplinary action.
14. Training
Personnel responsible for compliance, customer support, engineering or operations may receive periodic training covering:
- money laundering risks;
- fraud prevention;
- data protection;
- suspicious-activity identification;
- incident-reporting procedures.
15. Third-Party Providers
FinStitch works with carefully selected third-party providers to deliver certain services, including identity verification, Open Banking connectivity, infrastructure and payment processing. Where applicable, these providers maintain their own regulatory obligations and compliance programmes. See our Subprocessors page for who we work with.
16. Policy Review
This policy is reviewed at least annually and whenever there are significant changes to:
- applicable legislation;
- regulatory expectations;
- FinStitch's services;
- operational processes;
- financial-crime risks.
17. Contact
FinStitch Limited, registered in England & Wales (company number 17242791). Questions regarding this policy may be raised via the Support page in the FinStitch app or directed to support@finstitch.com.