AML POLICY — KYC — KYB

MyGold SpA

AML POLICY — KYC — KYB

Anti-Money Laundering — Customer Verification — Countering the Financing of Terrorism

pursuant to Legislative Decree 231/2007 · Law 7/2000 · Bank of Italy Regulations for Public Offers

Version:

OPO License: Bank of Italy No. 5008800

Contact: administration@mygold.world

Identity verification is a legal requirement and a protection tool for all our customers.

Law 7/2000

Authorized OPO

Bank of Italy No. 5008800

D. Lgs. 231/2007

Anti-money laundering

Italian AML legislation

KYC / KYB

Verify

Natural and legal persons

Risk-Based

Approach

Proportional to risk

1.

WHY THIS POLICY

MyGold SpA (hereinafter ” MyGold ” or “the Company”) is committed to fighting money laundering (AML ) and the financing of terrorism (CFT ) . This is a fundamental commitment, not just a regulatory obligation.

We believe that a healthy and transparent precious metals market requires responsible operators who adopt high standards of customer due diligence. This Policy transparently describes our approach to preventing financial crime, the procedures we use to verify customer identity, and the criteria we use to assess the risk associated with each business relationship.

Our commitment: MyGold guarantees that its physical gold trading and custody activities, including through qualified custodians, are conducted in full compliance with current legislation and are not used for illicit purposes, protecting our customers and the integrity of the gold market.

2.

REGULATORY REFERENCES

This Policy is drafted in accordance with the following regulatory framework:

Regulations

Description

Law 17 January 2000, n. 7

Gold trading regulations — establishment of the OPO register at the Bank of Italy; identification and registration requirements for gold transactions

EU Regulation 2024/1624 (AMLR)

New European regulatory framework on anti-money laundering, which will introduce harmonized rules at EU level, with progressive application starting from 2027

Legislative Decree 21 November 2007, n. 231 (AML)

Italian anti-money laundering legislation — customer due diligence, data retention, SOS reporting to the UIF

GDPR — EU Regulation 2016/679

Personal data protection — legal basis for processing KYC/KYB data

Bank of Italy Provisions for Public Offers

Supervisory provisions and operating instructions for Professional Gold Operators authorised under Law 7/2000

UIF Communications

Anomaly indicators for suspicious transactions in the precious metals and investment gold sector

FATF / FATF Standards (2021+2024)

International recommendations on risk- based approach for precious metals operators — methodological reference

3.

GLOSSARY

Below are the main definitions and acronyms used in this Policy:

Acronym

Term

Definition

AML

Anti-Money Laundering

Anti-money laundering: a set of measures to prevent and combat money laundering from illicit activities.

CFT

Combating the Financing of Terrorism

Combating the Financing of Terrorism

ML/TF

Money Laundering / Terrorist Financing

Money laundering and terrorist financing: the two main risks that AML/CFT procedures aim to prevent

KYC

Know Your Customer

Verification of the identity of the individual customer: collection and verification of identification data, documentary evidence and the source of funds

KYB

Know Your Business

In-depth verification of legal entity clients: collection and verification of corporate, director, and beneficial owner data.

CDD

Customer Due Diligence

Customer due diligence: standard procedure applied to all customers

EDD

Enhanced Due Diligence

Enhanced Due Diligence: A thorough process for high-risk customers

SDD

Simplified Due Diligence

Simplified due diligence: streamlined procedure for documented low-risk customers

PEP

Politically Exposed Person

Politically Exposed Person: a person who holds or has held important public offices

UBO

Ultimate Beneficial Owner

Beneficial Owner: natural person who owns or controls a legal entity (holding >25%)

AMLCO

AML Compliance Officer

Anti-Money Laundering Compliance Officer: oversees AML/CFT procedures

FIU

Financial Intelligence Unit

Italian authority that receives Suspicious Transaction Reports (SOS)

SOS

Suspicious Transaction Report

Communication sent to the UIF when a ML/TF operation is suspected

OPO

Professional Gold Operator

Entity authorized by the Bank of Italy pursuant to Law 7/2000 to operate in the gold trade

LBMA

London Bullion Market Association

International association that certifies gold and silver foundries — the gold standard for metal storage

4.

WHY WE VERIFY YOUR IDENTITY

Identity verification isn’t just a legal requirement: it’s the primary tool MyGold uses to protect its customers and ensure the integrity of the physical gold market. The primary risk for an OPO operator is being unwittingly involved in illicit activities.

These controls protect both MyGold and—most importantly—our customers, ensuring a safe and reliable environment for investing in physical gold.

5.

OUR APPROACH: RISK-BASED AND HUMAN-FIRST

The company adopts a risk-based approach (RBA), in accordance with the FATF/GAFI Recommendations for Precious Metals Operators (updated 2024) and the Bank of Italy’s supervisory provisions for OPOs. This means that:

  • We do not treat all customers the same: those with higher risk characteristics are subjected to more thorough checks;
  • Those with a documented low-risk profile can access services with more streamlined procedures;
  • Compliance resources are concentrated where risk is greatest, without unnecessarily burdening the experience of low-risk customers.

Our approach combines on-site identification—performed by our resources—with in-depth document verification. This dual level of control ensures high standards for all clients. Clients are classified into three risk categories—LOW, MEDIUM, HIGH—based on factors such as country of residence, type of transaction, and whether they are a PEP or sanctioned entity. The level of verification required is proportionate to the assigned risk category.

6.

HOW WE VERIFY YOUR IDENTITY

6.1 The KYC Process for Individuals

The identity verification (KYC) process for individual customers always involves direct, in-person contact between the customer and the company. There is no option to complete the KYC process automatically or without human interaction.

The customer presents himself in person at the MyGold operational headquarters SpA or meet with an authorized MyGold consultant . The following documentation is collected for this purpose:

a) Valid identity document (identity card, passport, driving license);

b) Italian tax code or foreign equivalent;odice Fiscale italiano o equivalente estero;

c) Document certifying ownership of a current account in the customer’s name (for bank transfers);

d) Proof of residence (recent utility bill or bank statement, no older than 3 months);

e) Profession and employer;

f) Declaration of any PEP status;

g) Documentation on the source of the funds used to purchase the gold (income from employment, business, inheritance, sale of assets, existing liquidity — with supporting documentation).

6.2 Purpose and Nature of the Commercial Relationship

During the identity verification process, MyGold collects information directly from the customer to understand the purpose and nature of the business relationship. This information includes, but is not limited to:

  • Type of operations envisaged (spot purchase, installment plans, partial sales);
  • Origin of funds used to purchase gold;
  • Experience and general knowledge of precious metals investments.

This information is always collected through direct, in-person interaction with the customer and serves to ensure an adequate risk assessment tailored to the customer’s profile, in compliance with AML/KYC/KYB regulations.

6.3 The KYB Process for Legal Entities

For legal entity clients — companies, corporations, foundations, trusts — the KYB verification process requires additional documentation compared to individual KYC:

  1. a) Copy of the updated articles of association and articles of incorporation;
  2. b) LEI code, if available;
  3. c) Chamber of Commerce certificate or equivalent document (no older than 3 months);
  4. d) Latest approved financial statements;
  5. e) Identity documents of directors and members/shareholders with a shareholding of more than 25%;
  6. f) Complete ownership structure and identification of beneficial owners (UBO);
  7. g) Copy of the VAT certificate;
  8. h) Sector of activity and motivation for investing in physical gold.

Attention — In the absence of sufficient information to identify the Beneficial Owner (UBO), MyGold SpA will not proceed with the activation of the commercial relationship.

6.3.1 Identification of the Beneficial Owner (UBO)

Pursuant to Article 20 of Legislative Decree 231/2007, MyGold identifies the Beneficial Owner according to the following criteria:

  • For legal entities: the natural person who directly or indirectly owns or controls more than 25% of the capital or voting rights, or who exercises management control. In the absence of such identifiable persons, the beneficial owner is the legal representative;
  • For trusts and similar legal entities: the settlor , the trustee, the protector and the beneficiaries or class of beneficiaries.

For each identified Beneficial Owner, the company obtains a declaration signed by the legal representative, verifies the identity using the same criteria as for natural persons, and performs screening against PEP and international sanctions lists.

6.4 Absolute prohibition of anonymous relationships

Absolute Prohibition — MyGold does not establish or maintain business relationships with anonymous customers, those with fictitious identities, those who refuse to provide the information required for verification, or those who provide false or contradictory information. If verification is not possible, MyGold will refuse to establish a business relationship and will assess whether there are grounds for filing a Suspicious Transaction Report (SOS) with the FIU.

7.

HOW WE ASSESS EACH CLIENT’S RISK

Each client undergoes a risk assessment upon onboarding and periodically throughout the business relationship. The assessment takes into account the following key factors, in accordance with the FATF Recommendations and the Bank of Italy’s supervisory provisions:

Category

Risk factors analyzed

Customer-related factors

Residence/domicile; nationality; type (private, company, foundation, trust); any PEP status; previous reports or business relationships; consistency between declared profile and transactions carried out

Geographical factors

Country of residence/domicile; countries of origin of funds; countries classified as high risk by FATF (grey/black list); countries subject to EU, UN, OFAC sanctions

Operating factors

Amount and frequency of transactions; consistency with declared income and assets; source of funds; type of plan (installment vs. spot); anomalous variations compared to the initial profile

Factors related to the products and services offered

Origin of the gold delivered; LBMA certifications of the custodian smelters; any gold of unknown or uncertified origin; requests for cash conversion of large amounts

8.

CUSTOMER VERIFICATION

Based on the risk assessment, each customer is assigned a proportionate level of verification:

Level

When it applies

What does it entail?

CDD Standard

Customers with a medium/low risk profile

Full identity verification (KYC/KYB), understanding the purpose of the relationship, periodic monitoring

Strengthened EDD

High-risk customers

Thorough verification of source of funds and assets, management approval, continuous and intensive monitoring

9.

POLITICALLY EXPOSED PERSONS (PEP)

Pursuant to Article 1, paragraph 2, letter dd ) of Legislative Decree 231/2007, a Politically Exposed Person (PEP) is a natural person who holds or has held important public offices. Examples include, but are not limited to:

  • Heads of State and Government; Ministers and Deputy Ministers
  • Heads of State and Government; Ministers and Deputy Ministers
  • Members of governing bodies of political parties
  • Members of governing bodies of political parties
  • Ambassadors, chargés d’affaires and high-ranking military officers
  • Members of the administrative bodies of public enterprises
  • Close relatives and persons known to be associated with the above-mentioned individuals

MyGold , while recognizing the possibility of establishing relationships with PEPs pursuant to current legislation, adopts a prudential policy that provides, in most cases, for the refusal or termination of the relationship, unless otherwise determined by the Compliance Officer.

10.

GEOGRAPHICAL RESTRICTIONS

MyGold does not accept onboarding customers who are residents, domiciled, or citizens of countries subject to international restrictive measures by the United States, the European Union, or the UN, nor customers who are on OFAC sanctions lists.

Excluded countries (examples) — By way of example and not limited to, the following currently fall into this category: Cuba, Iran, North Korea, Syria, Russia (sanctioned entities), as well as any other country subject to equivalent sanctions regimes by the competent international authorities.

For customers residing in countries on the FATF gray list or in high-risk countries, MyGold applies enhanced diligence measures (EDD). The establishment of a business relationship is subject to the Compliance Officer’s assessment.

The lists of high-risk and sanctioned countries are consulted and updated on the basis of official publications by:

  • FATF — Financial Action Task Force (grey and black lists);
  • European Union — European Council Regulations on sanctions;
  • UN — Security Council Resolutions (UNSCR);
  • OFAC — Office of Foreign Assets Control (SDN List and Blocked Persons List);
  • UIF — Communications from the Financial Intelligence Unit for Italy.

11.

PERIODIC CUSTOMER PROFILE UPDATE

Identity verification does not end with onboarding . During the course of the business relationship, MyGold may request updates to customer data and documents in the following circumstances:

  • Expiry of the identity documents provided;
  • Significant change in the operating profile (e.g. significant increase in invested amounts);
  • Changes in ownership structure, for legal entity clients;
  • Changes in ownership structure, for legal entity clients;
  • Reports of anomalies or unusual operations compared to the declared profile.

In such cases, MyGold may temporarily suspend access to certain services until the verification update is completed. The customer is always informed in advance and transparently of the information requested and the reasons for this.

12.

SUSPICIOUS TRANSACTIONS AND REPORTING OBLIGATIONS

The company is required by law (Articles 35-39 of Legislative Decree 231/2007) to report to the UIF any transactions for which it suspects, or has reasonable grounds to suspect, that money laundering or terrorist financing operations are underway.

Confidentiality obligation ( Tipping Off)

In the event of a report, it is absolutely forbidden to inform the customer of its existence (confidentiality obligation – tipping off – art. 38 Legislative Decree 231/2007). Therefore, if MyGold SpA should proceed with a report regarding a customer, it will not be able to communicate it to the customer.

Submitting an SOS to the FIU does not in itself constitute an accusation against the customer. The assessment is carried out by the competent authorities.

13.

YOUR RIGHTS

As part of AML/KYC/KYB procedures, customers may have questions about the data collected and how it is used. For any information, please contact MyGold ‘s Compliance Officer . However, please remember that:

GDPR Law

Applicability in the AML field

Right to erasure (Article 17 of the GDPR)

NOT applicable to data processed in compliance with AML obligations, which must be retained for 10 years after termination of the relationship (Article 31 of Legislative Decree 231/2007).

Right to object to processing (Article 21 GDPR)

NOT applicable to processing based on legal obligation (KYC/KYB/AML).

Right of access, rectification, portability (Articles 15-20 GDPR)

May be exercised within the limits of AML regulations. Contact: administration@mygold.world

Complaint to the Supervisory Authority

Always available: Italian Data Protection Authority — www.garanteprivacy.it — Piazza Venezia 11, 00187 Rome.

Compliance / Privacy Contact

administration@mygold.world

Website

www.mygold.world — Privacy section

Registered office

MyGold SpA — Piazzale Cadorna Luigi 9, 20123 Milan (MI)

Privacy Guarantor (complaints)

www.garanteprivacy.it — Piazza Venezia 11, 00187 Rome

14.

POLICY UPDATES

This Policy is subject to annual review by the Compliance Officer and MyGold management. SpA , or upon the occurrence of significant regulatory changes (updates to Law 7/2000, Legislative Decree 231/2007, Bank of Italy provisions, UIF communications).

The updated version is always available on www.mygold.world in the section dedicated to compliance and transparency.