Belgeye genel bakış
How GRZ Gaming manages verification and financial-crime risk
Introduction
This Know Your Customer, Anti-Money Laundering and Counter-Terrorist Financing Policy (the “Policy”) sets out the customer-verification and financial-crime controls required by Grz Gaming Limited, trading as GRZ Gaming (“we”, “us” or “our”), company number 13086814, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
The Policy applies to purchases and account activity on grzgaming.com and any other GRZ Gaming portal that expressly adopts it. It covers individual customers, approved businesses and resellers, and the employees and authorised service providers performing relevant functions for GRZ Gaming. Management is responsible for implementing and enforcing these requirements.
Our covered products are direct game top-ups, in-game currency, digital gift cards, prepaid vouchers, wallet cards, gaming subscription cards and redeem codes. GRZ Gaming does not sell CD keys, game-activation keys or software licence keys.
GRZ Gaming prohibits the use of its services to launder criminal proceeds, finance terrorism or proliferation, evade applicable sanctions, commit fraud or conceal an unlawful payment source. Money laundering includes handling or disguising criminal property; terrorist financing may involve money from lawful or unlawful sources. A legitimate-looking purchase or successful payment does not resolve a financial-crime concern.
This Policy operates alongside our Terms and Conditions, Refund Policy & Disclaimer and Privacy Policy. It does not authorise confiscation of customer funds, remove mandatory consumer rights or exempt GRZ Gaming from its own legal responsibilities.
Legal framework and scope
Relevant UK requirements include the Proceeds of Crime Act 2002, the Terrorism Act 2000, applicable sanctions regulations under the Sanctions and Anti-Money Laundering Act 2018, and applicable data protection law, including the UK GDPR and Data Protection Act 2018, as amended.
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended, apply to activities within their legal scope. We apply their mandatory requirements where applicable and use risk-based due-diligence principles to inform additional business controls. Other jurisdictions’ laws apply where they legally govern the activity concerned. FATF standards inform our risk assessment; they are not a licence or a certification of GRZ Gaming.
This Policy does not represent that GRZ Gaming is an FCA-authorised financial institution, an AML-supervised business or a provider of regulated payment services. Regulatory obligations depend on the activities actually carried on and must be assessed accordingly.
The six policy areas are verification procedures; the Compliance Officer; sanctions and politically exposed persons screening; transaction monitoring; risk assessment; and confidentiality and personal data protection.
01Verification Procedures
1.1. Verification before fulfilment
Where identity, payment-ownership or enhanced due-diligence checks are required, GRZ Gaming will not release digital codes, process direct top-ups or enable use of the affected paid value until those checks are satisfactorily completed.
All orders are subject to baseline payment and risk checks. Additional documentary verification is risk-based: not every customer must provide every document listed in this Policy. Checks may be required before an initial purchase, for a subsequent order, when details change, or when new concerns arise. A previously verified account is not permanently exempt.
Payment authorisation, a payment-provider approval, a purchase receipt or a successful authentication step does not by itself establish that GRZ Gaming’s checks are complete. Where a concern arises after delivery, we may investigate and restrict further activity in accordance with Section 4; this does not imply that an already redeemed code or completed top-up can be reversed.
1.2. Customer information and identity verification
Customers must provide accurate information about their identity, contact details, location and payment arrangements when requested, and promptly correct material changes. Using an ordinary gaming username is permitted, but it must not be used to conceal the actual purchaser or payer from required checks.
Depending on the purpose and risk, we may request a legal name, date of birth, residential address, country of residence, verified contact details, or a valid government-issued identity document. Appropriate evidence may include a passport, national identity card, driving licence or equivalent document accepted for the relevant check. Recent proof of address may be requested where necessary.
Evidence must be genuine, legible and sufficient for the stated purpose. Fabricated documents, impersonation, synthetic identities, misleading alterations and deliberately false statements are prohibited. Privacy redactions specifically permitted by our submission instructions are not treated as falsification.
Verification may use documentary evidence, reliable independent sources, payment-provider information or an approved verification service. We may request a secure live identity check where proportionate. Biometric verification may only be used where the necessary legal basis, additional data protection conditions and safeguards have been established. Customers who cannot complete a particular method should contact support so that an appropriate alternative can be considered; this does not require us to accept inadequate evidence.
1.3. Payment methods and payment ownership
Payments must come from the lawful payment-method holder or a documented authorised representative of the paying business. We may verify the connection between the purchaser, payer, billing information and intended recipient.
Using a friend’s, relative’s or unrelated person’s card or wallet is not accepted merely because the purchaser states that permission was given. The legitimate holder should purchase using their own identity and payment method. A parent or guardian may purchase in their own name for a child where the product terms and applicable law permit it. A business representative must be able to demonstrate authority to use the business payment method.
Permitted gifting is different from undisclosed third-party funding. Buying an eligible product for someone else using your own authorised payment method is not automatically prohibited; product restrictions, recipient checks and any approved reseller arrangement still apply.
For card payments, checks may include issuer or processor authentication, relevant billing information and redacted evidence linking the cardholder to the transaction. For PayPal, bank payments or other wallets, we may request evidence of the account holder and the corresponding payment reference. A forwarded email, screenshot or receipt alone may be insufficient to resolve a discrepancy. Additional cardholders, business cards and tokenised payment methods must be assessed using the relevant provider’s evidence rather than rejected solely because displayed details differ.
Payment providers may apply their own verification requirements. Their checks do not replace GRZ Gaming’s assessment of an unresolved concern.
Never send GRZ Gaming support your full card number, CVV/CVC, card PIN, banking password, one-time authentication code, cryptocurrency private key or seed phrase. Any approved card evidence must conceal every card-number digit except the last four and completely conceal the security code. Enter payment authentication information only directly into the legitimate payment provider’s authorised flow, never into a support conversation.
1.4. Businesses, resellers and beneficial ownership
Business purchasing and resale require GRZ Gaming’s approval where specified in our Terms or a separate agreement. Business verification must establish the entity’s existence, business activity, relevant operating locations, the authority of its representative, and the natural persons who ultimately own or control it.
Depending on the structure and risk, we may request registration documents, registry extracts, trading details, an ownership chart, director and beneficial-owner information, proof of representative authority, expected purchasing volumes, intended resale channels and evidence of legitimate business funding. Relevant ownership and control must be understood even where a simple shareholding threshold does not identify the person exercising control.
Undisclosed agency arrangements, concealed beneficial owners, unverifiable businesses and arrangements designed to bypass individual customer checks are not permitted. An approved reseller must disclose material changes to its ownership, activity or payment arrangements. Approval does not authorise prohibited products, sanctioned transactions or payment services outside the approved relationship.
1.5. Enhanced due diligence and source of funds
Enhanced due diligence (“EDD”) is required where applicable law requires it or our assessment identifies a higher risk that warrants additional controls. Relevant situations include materially unusual spending, inconsistent identity or payment information, complex funding arrangements, higher-risk geographic connections, concerns about the intended recipient, or relevant politically exposed person or adverse-information findings.
We may request an explanation of the purchase purpose, expected account activity, the relationship between the parties, and the source of funds used for the purchases. Where necessary and proportionate, we may also request the source of wealth, meaning how the customer accumulated the relevant overall wealth.
Supporting evidence may include relevant bank statements, salary or income records, business accounts, invoices, sale agreements, loan documentation or other reliable records appropriate to the explanation. Requests must be tailored to the concern. Customers may redact unrelated information where permitted, but must not conceal information necessary to establish ownership, the relevant transactions or the payment source.
A declaration alone may not resolve a material concern. High-risk approval requires a documented assessment by the Compliance Officer and senior-management approval before the affected activity proceeds. Commercial importance, repeat purchasing or pressure for immediate delivery cannot override an unresolved legal prohibition or mandatory check.
1.6. Cryptocurrency and other higher-risk payment arrangements
Where cryptocurrency is offered as a payment option, the same identity, sanctions and lawful-funding rules apply. We may require a transaction reference and proportionate evidence connecting the payer to the payment and its lawful origin, using an approved verification route. A wallet address or on-chain transfer alone is not conclusive proof of identity or lawful ownership.
Payments must not be deliberately structured to conceal the payer or unlawful source, evade restrictions, or defeat the checks required by GRZ Gaming or its provider. Only payment methods expressly made available for the order may be used. This Policy does not authorise GRZ Gaming accounts to be used for currency exchange, money transmission or undisclosed collection of third-party funds.
1.7. Incomplete, refused or unsuccessful verification
Customers must respond to reasonable, relevant verification requests within the timeframe communicated for the case. We may decline further purchases, cancel an unfulfilled order or restrict or close an account where required checks cannot be completed, evidence is materially unreliable, or the remaining risk is unacceptable.
Refusing a request or being unable to provide a particular document does not, by itself, prove criminal conduct. Where appropriate, we will explain the requirement and consider suitable alternative evidence. We are not obliged to fulfil an order while a required check remains unresolved.
A missed deadline or failed check does not automatically forfeit the customer’s money. Cancellation, refunds, restrictions and any legally required hold are governed by Section 4 and applicable law.
02Compliance Officer
2.1. Responsibility and authority
Senior management must designate a suitably competent Compliance Officer and deputy or documented cover arrangement. The role is responsible for overseeing this Policy, assessing escalated cases, maintaining the risk framework, coordinating lawful reporting, and ensuring that relevant records, training and review procedures are maintained.
The Compliance Officer must have access to necessary records and authority to stop fulfilment, require further checks and escalate concerns to senior management. If an additional statutory nominated-officer or money-laundering reporting appointment is required, management must make and document that appointment.
2.2. Approval, escalation and accountability
Employees must promptly escalate suspected fraud, money laundering, terrorist financing, sanctions concerns and attempts to bypass controls. Support and sales staff must not remove a compliance restriction without the required approval. Where the authorised reviewer is unavailable, an unresolved restricted order must not be released merely to meet a delivery target.
High-risk decisions, material exceptions to discretionary controls and release of restricted activity must have a recorded rationale and appropriate approval. No employee or manager may approve an exception to a legal prohibition. Case handling must preserve confidentiality and avoid unlawful disclosure or prejudicing an investigation.
Management must review the effectiveness of these controls and address identified deficiencies. Outsourcing a check does not remove GRZ Gaming’s responsibility for its own obligations.
03Sanctions and Politically Exposed Persons Screening
3.1. Sanctions screening
GRZ Gaming requires screening against applicable sanctions before accepting a customer relationship or fulfilling an order. Controls must address the customer, payer and relevant business owners or controllers, and the recipient or other connected parties where necessary. Current, still-reliable verification information may be reused, but a historical screening result is not sufficient where a material change or updated designation requires a new check.
The UK Sanctions List is the source for UK sanctions designations. Relevant sanctions regulations, ownership and control rules, and other applicable restrictions must also be considered; a name absent from a list is not automatically clear. UN, EU, US OFAC or other measures must be considered where legally applicable or required by the relevant payment-provider arrangement, subject to applicable law.
Potential matches must be assessed using available identifiers rather than treated as confirmed solely because of a similar name. Until a material unresolved match is cleared, the affected activity must not proceed.
GRZ Gaming must not supply products, transfer value or issue a refund where doing so would breach an applicable prohibition. Where an asset freeze or other restriction applies, we will comply with the relevant legal requirements and any necessary reporting or licensing process. A freeze does not transfer ownership of the customer’s property to GRZ Gaming.
3.2. Politically exposed persons
A politically exposed person (“PEP”) is someone entrusted with a prominent public function. Relevant family members and known close associates may also require assessment under applicable rules.
PEP status is not evidence of wrongdoing and is not a sanctions designation. Confirmed PEP connections require a documented assessment and the enhanced measures applicable to the actual risk and legal framework. Where required, these include source-of-funds or source-of-wealth enquiries, senior approval and enhanced ongoing review. Where the UK lower-risk treatment for domestic PEPs and their relevant associates applies, it must be respected unless additional risk factors justify greater scrutiny.
3.3. Ongoing review
Screening must be refreshed in response to relevant list changes, changed customer or ownership details, new information or suspicious activity, and at risk-based intervals for ongoing relationships. Credible adverse information must be assessed for relevance, reliability and the correct identity; an allegation or automated alert is not a finding of guilt.
04Monitoring Transactions
4.1. Monitoring and case identification
Transaction monitoring must consider orders and payments before and after fulfilment, and assess connected activity rather than viewing each purchase in isolation. Relevant information may include order history, payment outcomes, aggregate spending, product and denomination choices, account or device associations, location indicators, delivery details and recipient identifiers, where lawfully available.
Examples requiring review include unexplained changes in spending; repeated payment failures or attempts involving multiple payment methods; materially inconsistent identities or locations; linked accounts used to avoid controls; unexplained bulk purchasing; and requests to return money through an unrelated payment route. A legitimate business explanation must be considered before reaching a conclusion.
Splitting purchases, accounts or payments to avoid verification is prohibited. There is no transaction value that guarantees exemption from review. Detailed detection rules and thresholds are confidential, but confidentiality does not justify withholding information that customers are legally entitled to receive.
4.2. Case management, restrictions and review
A material concern must be recorded and assigned to an authorised reviewer. Actions may include pausing an order, withholding an unissued code, stopping a top-up before processing, requesting further evidence, restricting affected account functions, declining a payment or ending the relationship.
The reviewer must document the concern, evidence requested and received, assessment, decision, approvals and outcome. Restrictions must be relevant to the risk and reviewed promptly and regularly. They must not continue indefinitely without a continuing lawful justification. We will communicate appropriate status information where lawful and practicable, without revealing protected reports or compromising an investigation.
Confirmed deliberate misuse may result in permanent refusal of future service, subject to applicable law. Suspicion alone does not create a right to confiscate paid balances or automatically invalidate unrelated, legitimately purchased products.
4.3. Cancelled orders, refunds and restricted funds
Where an order is cancelled before fulfilment, any refund due must be processed without undue delay and within applicable legal deadlines. Verification must not be used as a pretext to withhold a refund that can lawfully be made.
Refunds are to be returned to the original payment method and legitimate original payer wherever possible. We do not redirect refunds to an unrelated person, substitute wallet, different card or other destination merely on request. Where the original route is genuinely unavailable, an alternative requires verification of the person legally entitled to receive it, customer agreement where required, documented Compliance Officer approval and compliance with the payment provider’s rules and applicable law.
An applicable sanctions restriction, court order or other legal prohibition may prevent or delay a payment. Such cases require assessment of the particular restriction, not a generic “AML hold”. We will not transfer or refund suspected criminal property in a way that would itself be unlawful.
Account closure or refusal to complete checks does not automatically extinguish a refund or paid-balance entitlement. Store Credit and promotional rewards remain subject to the distinctions in our Terms. A compliance review does not remove legitimate complaint, cancellation or payment-dispute rights, and a customer must not be required to withdraw a valid dispute merely to receive money lawfully due.
4.4. Suspicious activity and external reporting
The Compliance Officer must assess whether the circumstances require or justify a report to a competent authority. This may include a Suspicious Activity Report to the UK Financial Intelligence Unit at the National Crime Agency, a report to the Office of Financial Sanctions Implementation, or information to law enforcement, according to the applicable legal framework.
Not every declined payment, verification failure or commercial dispute warrants an external report. Reports must be based on the relevant information and legal threshold. Where dealing with funds may require a statutory defence, licence or other lawful authority, the appropriate process must be followed before the affected act proceeds.
We may be unable to confirm whether a report has been made or disclose details where the law prohibits disclosure or an investigation could be prejudiced.
05Risk Assessment
5.1. Risk-based approach
GRZ Gaming’s assessment must consider customer, country, product, payment, delivery-channel and transaction risks together. Higher-risk activity requires stronger evidence, appropriate approval and closer review. Low apparent risk does not justify ignoring a legal prohibition or a specific warning sign.
The business-wide assessment must be reviewed at least annually and sooner after material changes to products, markets, payment methods, fraud patterns, providers or legal requirements. New activities must not launch before their regulatory implications and necessary controls have been assessed.
5.2. Country and geographic risk
Geographic assessment must distinguish applicable sanctions, FATF risk information, provider restrictions and GRZ Gaming’s own commercial risk limits. Relevant connections may include residence, business establishment, payment origin, recipient location and material business activity. Nationality or birthplace alone is not proof of unlawful conduct.
As a GRZ Gaming business-risk restriction, we do not accept orders from customers resident or businesses established in jurisdictions on FATF’s current “High-Risk Jurisdictions subject to a Call for Action” list, or transactions originating in, destined for, or knowingly conducted on behalf of persons in those jurisdictions. This is our commercial restriction; it is not a statement that FATF universally prohibits all such transactions. Any existing payment or balance must still be handled lawfully under Section 4.
A jurisdiction on FATF’s separate “Jurisdictions under Increased Monitoring” list is not automatically subject to a blanket ban under this Policy. Such connections must be included in the risk assessment, with EDD where required by current applicable law or the assessed risk. Other applicable sanctions, product or payment-provider restrictions may independently prevent service.
The relevant official lists and restrictions must be checked as they change. We may impose additional lawful geographic service restrictions where risks cannot be acceptably managed, and make applicable availability restrictions clear before purchase where reasonably practicable. We do not rely on a fixed historical country list as a substitute for current assessment.
5.3. Customer, product and payment risk
Customer assessment must consider the transparency of identity and ownership, purchase purpose, expected volume, payment-source consistency, relevant PEP exposure and credible evidence of misuse. It must distinguish consumers buying permitted gifts from undisclosed intermediaries and approved business resale from concealed third-party payment collection.
Product assessment must consider prepaid value, transferability, redemption arrangements, speed of delivery, reversibility, denomination, volume and potential resale or misuse. Digital products must not be assumed to be free of financial-crime risk simply because they are gaming-related.
Payment and channel assessment must consider remote onboarding, payment authentication, third-party involvement and the reliability of available information. If the remaining risk cannot be acceptably managed, the activity must not proceed.
06Confidentiality and Personal Data Protection
6.1. Purpose and lawful handling
Information collected under this Policy must be necessary and proportionate for verification, payment security, financial-crime prevention, investigation or applicable legal obligations. Processing must have a valid legal basis. This Policy is not blanket consent to unlimited collection, monitoring or sharing.
Where an additional condition is required for biometric, special-category or criminal-offence information, that condition and the necessary safeguards must be established before the processing begins. Our Privacy Policy and any verification notice must explain the relevant purposes, information used, lawful bases, recipients, retention arrangements and rights.
6.2. Secure submission and access
Identity documents and financial evidence must be submitted only through a secure verification route approved by GRZ Gaming. Do not send them through ordinary email, public reviews, social media or general live-chat attachments. Contact support for the approved submission instructions.
Access must be restricted to authorised people with a legitimate need. Appropriate security measures must protect information during transmission and storage, with access records and controls appropriate to its sensitivity. Staff must not keep verification documents in personal accounts, on unmanaged devices or in publicly accessible storage.
6.3. Sharing and confidentiality
Information may be shared with approved verification or fraud-prevention providers, relevant payment processors, professional advisers or competent authorities only where lawful and necessary. Appropriate contractual, security and international-transfer safeguards must be in place where required. Verification information must not be repurposed for unrelated marketing without a separate lawful basis and required notice.
Employees and service providers must protect confidential case information. Unlawful tipping off and disclosures that prejudice an investigation are prohibited. These restrictions must not be used as a blanket reason to disregard lawful customer information rights.
6.4. Record retention
Records must be retained under a documented schedule for no longer than necessary for the applicable purpose, subject to legal obligations and properly documented preservation requirements. Relevant records may include verification outcomes and necessary supporting evidence, risk assessments, screening results, transaction records, case decisions and reports.
Where the statutory AML record-keeping rules apply, their prescribed retention requirements must be followed. We do not treat those requirements as a universal mandate to keep every customer’s identity documents indefinitely. Other records must have a justified retention period or criteria, explained in the applicable privacy information. Data must be securely deleted or anonymised when no longer required, subject to lawful preservation obligations.
6.5. Training, oversight and policy review
Relevant staff must receive training before performing verification or financial-crime review duties, with refresher training at least annually and additional training after material changes. Training must cover suspicious activity, sanctions, document handling, escalation, confidentiality and customer communication.
Management must arrange proportionate checks of compliance with this Policy, maintain records of findings and corrective action, and review the Policy at least annually. Material changes will be published with a revised version date and communicated where appropriate. Changes do not retrospectively remove accrued customer rights, although legally required or necessary security controls may apply to ongoing activity.
6.6. Questions, review requests and complaints
For verification questions, suspected account misuse or a request to review a decision, contact support@grzgaming.com or Live Support through grzgaming.com. Ask for the matter to be referred to the Compliance Officer where appropriate. These channels are for enquiries; sensitive documents must use the approved secure verification route.
Customers may provide correcting information and request human review of a verification or account-restriction decision. We will consider relevant evidence, subject to lawful confidentiality requirements. A review request does not guarantee approval or require us to release an order while necessary checks remain incomplete.
Data protection requests may be sent through the same contact route for referral to the responsible person. Nothing in this Policy restricts any applicable right to complain to a competent regulator, data protection authority, payment provider or court.