Anti-Money Laundering, Sanctions and Know Your Customer (AML/KYC) Policy
Last updated: 14 May 2026 · Version 1.1 (Global)
Spotlight21 Ltd (“Spotlight21”, “we”, “us”, “our”) is committed to preventing money laundering, terrorist financing, sanctions evasion, fraud and other financial crime in connection with the sale and provision of eSIM and related connectivity products and services (the “Services”) to customers worldwide via spotlight21.com and any related applications.
1. Introduction and Purpose
While Spotlight21 is not at present a “relevant person” under the UK Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (as amended) (the “MLRs”), we voluntarily adopt and apply controls modelled on:
- The MLRs and the UK Proceeds of Crime Act 2002 (“POCA”) and Terrorism Act 2000;
- EU Anti-Money Laundering Directives (4AMLD–6AMLD) and the EU AML Regulation;
- US Bank Secrecy Act standards and FinCEN guidance (to the extent relevant to our merchant activity);
- Financial Action Task Force (“FATF”) Recommendations.
We screen against and comply with all applicable financial sanctions regimes, including those administered by the UK Office of Financial Sanctions Implementation (“OFSI”), the EU, the United Nations Security Council, the US Office of Foreign Assets Control (“OFAC”), and any other regime that has extraterritorial application to our business.
2. Scope
This Policy applies to:
- All customers (individuals, sole traders, partnerships or corporate entities) purchasing or using the Services, regardless of country of residence;
- All directors, officers, employees, contractors, agents and any third parties acting on Spotlight21’s behalf;
- All payment, marketing, distribution and reseller relationships entered into by Spotlight21.
3. Risk-Based Approach
Spotlight21 adopts a risk-based approach proportionate to the size, nature and global reach of its business. We periodically assess and document the money laundering, terrorist financing, sanctions and fraud risks arising from:
- Customer types and jurisdictions of origin;
- Geographic markets in which the Services are offered or used;
- Products and delivery channels (online-only, instant-activation eSIM products are inherently higher-risk for fraud and lower-risk for cash-based money laundering);
- Payment methods accepted (card, digital wallet, alternative payment methods, crypto if introduced);
- Transaction sizes, patterns and velocity.
Higher-risk situations attract enhanced controls; lower-risk situations may attract simplified measures, in each case documented in our internal risk register and reviewed at least annually.
4. Customer Due Diligence (CDD)
4.1 Standard Due Diligence
For ordinary retail purchases of eSIM products at standard price points, we apply the following baseline measures:
- Verified email address and (where collected) mobile number;
- Payment authentication via the customer’s payment service provider, including Strong Customer Authentication (“SCA”) under the EU PSD2 / UK PSR 2017 regimes where applicable;
- IP address, device fingerprinting and geolocation data collected for fraud-prevention and risk-screening purposes;
- Screening of transactional and payment data against sanctions and fraud databases by our payment service providers and our own systems.
4.2 Enhanced Due Diligence (EDD)
Enhanced measures apply where:
- The customer or beneficial owner is identified as a Politically Exposed Person (“PEP”), a family member or a known close associate of a PEP;
- The customer, the IP address, the payment instrument or the destination eSIM country is in a higher-risk jurisdiction as identified by FATF, the UK Government, the EU, OFAC or our internal risk assessment;
- Transactions are unusual in size, frequency or structure (including suspected “structuring” or “smurfing”), or are inconsistent with the customer’s apparent profile;
- There are reasonable grounds to suspect that the customer is acting on behalf of an undisclosed third party;
- The transaction appears designed to obscure identity, ownership or destination of funds.
EDD may include requesting government-issued ID, proof of address, source-of-funds information, additional payment verification, or declining the transaction.
4.3 Country-Specific eSIM/SIM Registration
Many destination countries require eSIMs to be registered with verified identity documentation under local telecoms law. The current non-exhaustive list includes:
- Europe: Germany, Spain, Italy, Hungary, Slovakia, Türkiye;
- Middle East: UAE, Saudi Arabia, Qatar, Oman, Bahrain, Egypt;
- Asia: China, India, Singapore, Thailand, Vietnam, South Korea, Japan (in some cases), Indonesia, Pakistan, Bangladesh;
- Africa: South Africa, Nigeria, Kenya, Tanzania, Ghana, Morocco;
- Americas: Mexico, Peru, Argentina, Venezuela;
- Oceania: in some carriers, Australia and New Zealand.
For these destinations, additional KYC information (passport scan, full name, date of birth, nationality and sometimes a selfie or video verification) will be collected at the point of purchase or activation and transmitted to the relevant upstream network operator or aggregator. Customers who decline are unable to activate.
The list above is indicative and subject to change as local laws evolve.
5. Sanctions Screening
Spotlight21 screens customers, transactions and counterparties against:
- The UK Sanctions List (OFSI);
- The EU Consolidated List of persons, groups and entities subject to financial sanctions;
- The UN Security Council Consolidated Sanctions List;
- The US OFAC Specially Designated Nationals (SDN) List and sectoral sanctions lists, including SSI, FSE and 50% Rule analysis;
- Such other national or regional sanctions or watch lists as we may consider appropriate.
Spotlight21 will not knowingly provide Services:
- to any individual or entity designated under any applicable sanctions regime;
- in or to any comprehensively sanctioned jurisdiction, currently including (without limitation) Cuba, Iran, North Korea, Syria and the Russian-occupied regions of Ukraine (Crimea, Donetsk, Luhansk, Kherson, Zaporizhzhia);
- in a manner that would breach US secondary sanctions even where Spotlight21 itself is not a US person.
We apply geo-blocking at checkout and IP-level controls to enforce these restrictions. Any positive match results in immediate suspension of the transaction, freezing of associated funds where required by law, and reporting to the relevant competent authority.
6. Export Controls
eSIMs and related connectivity services are generally treated as services (rather than controlled goods) under UK and US export control regimes, but encryption-related licensing and country-specific restrictions may apply. We do not provide eSIMs for delivery or activation in jurisdictions where doing so would breach applicable export controls.
7. Suspicious Activity and Internal Reporting
All employees and contractors must report any knowledge or reasonable suspicion of money laundering, terrorist financing, sanctions breach or fraud to Spotlight21’s nominated officer (the “Nominated Officer”), being Andrew Folson, Compliance Lead, of Elpidas 14, 4529, Pyrgos Limassol, Cyprus, contactable at hello@spotlight21.com.
The Nominated Officer is responsible for:
- Assessing internal reports;
- Filing Suspicious Activity Reports (“SARs”) with the UK National Crime Agency under POCA and the Terrorism Act 2000;
- Filing equivalent reports with foreign competent authorities where required (e.g., FinCEN SARs in the US, AUSTRAC SMRs in Australia, FINTRAC STRs in Canada) — recognising that such obligations only arise if Spotlight21 falls within those regimes;
- Liaising with OFSI and other sanctions authorities in respect of suspected sanctions breaches;
- Maintaining a confidential register of all internal disclosures and external reports.
Employees must not “tip off” customers or any third party that a SAR has been made or contemplated. Tipping off is a criminal offence in many jurisdictions (e.g., section 333A of POCA in the UK).
8. Record Keeping
Spotlight21 retains records of customer identification, transaction history, risk assessments, internal disclosures, SARs and training for a minimum of five (5) years from the end of the customer relationship or completion of the relevant transaction. Records will be securely destroyed thereafter unless retention is required by law or for legitimate legal, accounting or regulatory purposes.
9. Fraud Prevention
In addition to AML controls, Spotlight21 operates the following fraud-prevention measures:
- Velocity limits and transaction caps per customer, payment instrument, IP address and device;
- Manual review of flagged transactions;
- Third-party fraud-scoring tools;
- Co-operation with card schemes, payment processors and law enforcement in respect of chargebacks and disputed transactions.
Confirmed fraudulent purchases are voided, refunded to the legitimate cardholder, and may be reported to Action Fraud (UK), the FBI IC3 (US), or other competent authorities as appropriate.
10. Training
All relevant personnel receive AML, sanctions and fraud-awareness training on induction, annually thereafter, and following any material change in applicable law, internal policy or risk profile.
11. Governance and Review
This Policy is owned by Spotlight21’s board of directors and is reviewed at least annually, and additionally upon any material change in law, regulation, business model or risk profile.
12. Customer Inquiries
Questions about this Policy or Spotlight21’s compliance practices: hello@spotlight21.com.
This Policy is an internal compliance document and a public-facing statement of standards. It does not create third-party rights or contractual obligations beyond those in Spotlight21’s Terms of Service.