> For the complete documentation index, see [llms.txt](https://admin-services.docs.intersectmbo.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://admin-services.docs.intersectmbo.org/governance/policies-and-guidance/due-diligence-policy.md).

# Due Diligence Policy

## Due Diligence Policy

**1. Policy Title:** Due Diligence Policy

**2. Version:** 1.2

**3. Effective Date:** 29/04/2026

**4. Review Date:**  April 2027

**5. Policy Owner:** Head of Operations

**6. Policy Sponsor:** Intersect Executive Director

*Updated on 8th May 2026*

***

#### **7. Purpose:**

The purpose of this Due Diligence Policy is to establish a structured, comprehensive, and iterative framework for thoroughly investigating and verifying information before Intersect commits to new contractual relationships, transactions, or projects with new individuals or businesses. This policy aims to identify, assess, and mitigate potential risks, ensuring that all critical aspects are understood. It provides a structured framework to ensure informed decision-making and uphold ethical and legal standards.

#### **8. Scope:**

This policy applies to the beneficiary, as defined below, who enters into contractual relationships, transactions, or projects with Intersect or with Cardano Development Holdings (CDH) where Intersect acts as Administrator.

#### **9. Principles:**

Intersect’s due diligence framework is guided by the following core principles:

**Risk‑Based Assessment**

Intersect applies a proportional, risk‑based approach to all beneficiaries. The depth of checks increases where higher risks are identified, ensuring resources are focused where they matter most.

**Legal and Regulatory Compliance**

All due diligence activities are designed to meet applicable AML, sanctions, fraud‑prevention, and data‑protection requirements (including, where applicable, the UK

Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer)

Regulations 2017 (as amended), the Proceeds of Crime Act 2002, the Terrorism Act

2000, applicable data protection legislation, and relevant FATF Recommendations).. Intersect makes all reasonable efforts to ensure beneficiaries meet these thresholds before engagement.

**Independent Verification via Sumsub**

Intersect conducts KYC and KYB checks through Sumsub, an independent third‑party provider offering identity verification, corporate registry checks, AML screening, and manual review for complex cases.

**Transparency and Full Disclosure**

Beneficiaries must provide complete, accurate, and timely information. Any omissions, inconsistencies, or refusal to cooperate may delay or prevent engagement.

**Prevention of Financial Crime**

Due diligence aims to identify and mitigate risks related to money laundering, terrorist financing, fraud, sanctions exposure, and misuse of funds, including crypto‑specific risks such as suspicious wallet activity.

**Ongoing Monitoring**

Due diligence continues throughout the relationship. Intersect performs periodic re‑screening and may request updated information if new risks emerge.

#### 10. Definitions:

* **Beneficiary:** An individual or company receiving funds or entering into a contractual relationship with Intersect or Cardano Development Holdings (CDH), where Intersect acts as Administrator.
* **Cardano Development Holdings (CDH):** A legal entity supporting the Cardano ecosystem by serving as the contracting counter party for approved proposals.
* **Intersect:** An Administrator within Cardano’s funding ecosystem responsible for due diligence, contracting, and on‑chain disbursements, operating under principles of transparency, decentralization, and adherence to the Cardano Constitution.&#x20;
* **Anti-Money Laundering (AML):** The body of laws, regulations, and procedures designed to prevent criminals from disguising illegally obtained funds as legitimate income.
* **Politically Exposed Person (PEP):** An individual who holds or has held a prominent public function (such as a head of state, senior politician, judicial or military official, or senior executive of a state-owned enterprise), and who may present elevated corruption or money laundering risk, together with their immediate family members and close associates.
* **Ultimate Beneficial Owner (UBO):** Any natural person who ultimately owns or controls more than 25% of the shares or voting rights of a legal entity, or who otherwise exercises effective control over the management of that entity.

#### 10.1 Know Your Customer (KYC)&#x20;

A full identity verification process designed to confirm an individual’s identity and assess financial crime risk. KYC includes:

* **Identity Verification:** Verification of personal information (name, date of birth, address) using government‑issued documents or approved non‑document methods.
* **Liveness & Deepfake Detection:** Facial biometrics and liveness checks to ensure the applicant is real and present.
* **Proof of Address Verification:** Review of documents such as utility bills or bank statements (typically <3 months old).
* **AML Screening:** Screening against sanctions lists, watchlists (including PEPs), and adverse media to identify financial crime risks.

Sumsub supports over 14,000 ID types from 220+ countries and performs these checks on Intersect’s behalf.

#### 10.2 Know Your Business (KYB)&#x20;

A verification process to confirm the legitimacy, structure, and risk profile of a company. KYB includes:

* **Corporate Registry Checks:** Automated retrieval and verification of legal existence, registration details, and management structure.
* **Corporate AML Screening:** Screening the company and its senior individuals against sanctions, watchlists, PEP databases, and adverse media.
* **Document Verification:** Authentication of uploaded documents such as incorporation certificates, articles of association, shareholder registers, and financial statements.
* **Ownership & UBO Review:** Mapping and validating shareholders, directors, and ultimate beneficial owners to ensure transparency.
* **Associated Individual Checks:** KYC verification of directors, UBOs, and other key persons.

#### **11. Additional Due Diligence Measures**&#x20;

In addition to standard KYC and KYB verification, Intersect applies the following comprehensive due diligence measures to ensure a comprehensive assessment of all individuals and entities entering into a business relationship with Intersect or CDH. These measures may be applied at any stage of the due diligence process where risk indicators, inconsistencies, or information gaps are identified.&#x20;

#### **11.1 Manual review by legal team**

Some cases require deeper scrutiny than automated verification can provide. When this occurs, Intersect may request Sumsub to conduct a manual legal review. This involves a detailed, human‑led assessment of complex or high‑risk cases, including the examination of unusual ownership structures, conflicting information, incomplete registry data, or legal documents that require expert interpretation. Manual reviewers may request additional documents to clarify business information, business purpose, or structural details to ensure risks are fully understood and mitigated. These reviews typically conclude within twenty‑four hours and provide an additional layer of assurance where automated checks alone are insufficient.&#x20;

#### **11.2 Ongoing Due Diligence (ODD)**

Due diligence continues throughout the duration of the relationship. Intersect reserves the right to perform periodic checks on any individual or entity entering into, or already engaged in, a business relationship with Intersect. These checks ensure that any changes in business activity, ownership, documentation, or risk profile are identified promptly. If new risks emerge, such as expired documents, adverse media, or changes in corporate structure, Intersect may request updated information or documentation to maintain compliance with regulatory requirements. Ongoing due diligence ensures that Intersect remains aware of evolving risks and can take appropriate action when necessary.&#x20;

In addition to risk-based triggers, Intersect reserves the right to rerun KYB verification on existing partners where Intersect materially updates its KYB process, standards, or screening criteria. In such cases, Intersect will notify affected partners and request any additional documentation required to complete re-verification under the updated process. Failure to cooperate with re-verification will be treated as a risk indicator and may result in suspension or termination of the relationship.&#x20;

#### **11.3 Enhanced Due Diligence (EDD)**

Enhanced Due Diligence is applied when elevated risks are identified during KYC or KYB checks.Specific triggers for EDD include:&#x20;

* The beneficiary or any associated individual is identified as a Politically Exposed Person (PEP).
* Adverse media screening returns material derogatory findings relating to financial crime, fraud, or corruption.
* The beneficiary is incorporated or resident in a jurisdiction designated as high-risk or subject to a call for action by the Financial Action Task Force (FATF).&#x20;
* Inconsistencies or gaps are identified in submitted documentation that cannot be resolved through standard automated verification.&#x20;
* The automated risk score returned by Sumsub exceeds the threshold designated as high-risk in Sumsub's internal scoring methodology.&#x20;
* Any other circumstance where the Operational Services Team or legal team determines that the standard KYC or KYB process is insufficient to adequately assess the risk profile of the beneficiary.&#x20;

This may occur when ownership structures are unclear, when adverse media or PEP exposure is detected, when inconsistencies appear in submitted documents, or when other concerns arise that require deeper investigation. EDD may involve requesting additional or alternative documents, conducting a Due Diligence Interview with the individual or business, or obtaining more detailed information about business activities and financial legitimacy. These cases are escalated internally for review by additional compliance officers to ensure that all regulatory obligations are met and that Intersect fully understands the risks before proceeding.&#x20;

#### **11.4 Wallet Checks**

For beneficiaries receiving funds from Cardano Development Holdings (CDH), Intersect performs wallet checks to verify wallet ownership, access, and legitimacy in line with crypto‑specific industry standards. This includes assessing the wallet’s age, transaction history, and any exposure to sanctioned, high‑risk, or illicit addresses. If wallet analysis reveals unusual patterns or additional risks, Intersect may escalate the case for further review, request additional information, or apply Enhanced Due Diligence before continuing the relationship.&#x20;

#### **12. System Capabilities and Data Sources**

* Editable and transparent company structure: Intersect’s due diligence processes are supported by verification tools that provide clear, accurate, and up‑to‑date information about individuals and businesses. These tools include features that allow for an editable and transparent representation of a company’s ownership and management structure. This ensures that changes in shareholders, directors, or beneficial owners can be easily updated, clearly displayed, and continuously monitored, supporting ongoing compliance and risk assessment.&#x20;
* Support for complex compliance needs: SumSub also supports complex compliance needs by accommodating multi‑layered ownership structures, international regulatory variations, and non‑standard business arrangements. This capability enables Intersect to assess entities operating across different jurisdictions, industries, and regulatory environments, including those with intricate or high‑risk profiles that require deeper analysis beyond standard automated checks.&#x20;

Sumsub performs AML screening using data provided by ComplyAdvantage. ComplyAdvantage returns matches based on sanctions lists, watchlists, PEP databases, and adverse media sources. Sumsub’s internal tools then assess the accuracy, relevance, and severity of each match to ensure that Intersect receives a reliable and proportionate risk evaluation for every beneficiary.&#x20;

#### **13. Policy statements:**

* Any individual or entity entering into a business relationship with Intersect or Cardano Development Holdings (CDH), including vendors, suppliers, employees, and contractors, must complete either a KYC or KYB verification, depending on the nature of the engagement. Completion of these checks is a mandatory requirement and forms the basis of Intersect’s risk assessment process.
* Intersect will not engage with any beneficiary who appears on a sanctions list. Sanctions screening is a non‑negotiable component of the due diligence process, and any confirmed sanctions match results in an automatic rejection of the proposed relationship. Similarly, Intersect will not proceed with any individual or entity that refuses to provide the information or documentation required to complete a full KYC or KYB assessment. Failure to cooperate, incomplete submissions, or attempts to withhold relevant information are treated as risk indicators and may result in termination of the onboarding process.
* Where a beneficiary who is already engaged in an active business relationship with Intersect or CDH is subsequently identified as matching a confirmed sanctions entry, Intersect will immediately suspend all disbursements and contractual activity with that beneficiary pending a formal review. The relationship will be terminated in accordance with applicable legal obligations and internal escalation procedures. Where required by law, Intersect will report the matter to the relevant competent authority without delay and without notifying the beneficiary if doing so would constitute a tipping-off offence under applicable legislation.
* Where watchlist entries, adverse media, PEP exposure, or other negative information is identified, Intersect retains full discretion to determine whether the level of risk is acceptable. These cases are assessed individually, taking into account the severity, relevance, and context of the findings, as well as any mitigating information provided by the beneficiary.
* In addition to identity and AML checks, Intersect assesses the jurisdictional risk associated with each beneficiary. Intersect will verify that the country of incorporation or residence is not located in a jurisdiction where cryptocurrency is illegal. Intersect uses multiple reputable sources, including industry‑recognised publications such as CCN, to maintain an up‑to‑date understanding of global crypto regulations. Intersect will not engage with any beneficiary based in a country where cryptocurrency is prohibited.
* Intersect will confirm that the beneficiary is not incorporated or resident in any jurisdiction listed as grey‑listed or blacklisted by the Financial Action Task Force (FATF). Engagement with entities in these jurisdictions presents elevated financial crime risks and is therefore not permitted under this policy.

#### **14. Roles and responsibilities:**

* **Intersect Operational Services Team:** The Intersect Operational Services Team is responsible for ensuring that any individual or entity seeking to enter into a business relationship with Intersect or CDH has undergone the appropriate due diligence checks. The team is accountable for reviewing verification outcomes, identifying potential risks, and ensuring that all necessary checks are completed before any contractual relationship, transaction, or project is established. Their role includes coordinating with third‑party providers, assessing the completeness and accuracy of submitted information, and escalating cases where additional scrutiny is required.
* **Beneficiary:** Beneficiaries are responsible for complying with Intersect’s due diligence policy and must act with transparency throughout the verification process. They are expected to provide full disclosure by proactively sharing all relevant information, including details that may be perceived as unfavourable. All information submitted must be truthful, accurate, and verifiable. Beneficiaries must also ensure completeness by providing all requested documents and data without omission, delay, or misrepresentation. Failure to meet these responsibilities may result in delays, escalation to enhanced due diligence, or termination of the onboarding process.
* **Ownership of the Verification Process:** Intersect holds full ownership of the due diligence process and is responsible for ensuring that all verification activities are carried out to a consistently high standard. Although Intersect engages trusted third‑party providers, including Sumsub, to perform identity, business, and AML checks, this delegation does not diminish Intersect’s overall accountability. Intersect remains responsible for the integrity, accuracy, and completeness of the due diligence process from start to finish. Where a third‑party provider’s output is incomplete, unclear, or does not meet the standard required under this policy, Intersect will intervene to provide the additional assurance necessary. This may include conducting further internal review, requesting additional documentation, or escalating the case for enhanced assessment. Intersect acts as the primary point of accountability for all due diligence outcomes and is committed to ensuring that every verification is conducted thoroughly, fairly, and in alignment with regulatory and organisational expectations.

#### **15. Procedures:**

* The Operational Services Team issues the appropriate Sumsub verification link:
* KYC/AML for individuals
* KYB for companies
* The beneficiary completes the verification process and uploads all required documents through Sumsub.
* Sumsub conducts the checks described in Section 10.
* Verification may be instant or take up to 72 hours, depending on case complexity.
* If documentation is incomplete or unclear, Sumsub may request resubmission or additional information.
* Intersect may conduct its own manual verification if the automated outcome is insufficient or if further assurance is required.
* Once checks are completed, the Operational Services Team informs the beneficiary of the outcome.
* If the beneficiary fails KYC or KYB, they may review the Sumsub report and challenge any inaccuracies. This does not create any obligation on Intersect to proceed with the relationship following the review.
* If Intersect identifies legitimate concerns; such as sanctions matches or other significant risk factors, the beneficiary will be deemed too high‑risk and the relationship will not proceed.

#### **16. Monitoring and Compliance:**

**Monitoring:** Intersect conducts ongoing monitoring of all beneficiaries who remain in an active business relationship. Repeat screening is carried out on a quarterly, bi‑annual, or annual basis, depending on the assessed level of business risk. The following criteria determine the applicable monitoring frequency:&#x20;

* Annual screening applies to low-risk beneficiaries with no adverse findings, stable corporate structures, and no material changes in circumstances since the last review.
* Bi-annual screening applies to medium-risk beneficiaries, including those with historic PEP exposure that has been mitigated, those operating in jurisdictions subject to enhanced scrutiny, or those with prior adverse media findings that were satisfactorily resolved.&#x20;
* Quarterly screening applies to high-risk beneficiaries, including those currently subject to Enhanced Due Diligence, those receiving high-value or recurring disbursements above agreed thresholds, or those with previously identified adverse findings that remain under active monitoring. These periodic checks ensure that any changes in circumstances; such as new adverse media, sanctions updates, expired documents, or changes in business activity are identified promptly and addressed in line with Intersect’s risk management framework.&#x20;

**Compliance:** Intersect maintains compliance by utilizing Sumsub, a reputable third‑party due diligence provider whose verification processes align with recognized ISO standards for security, risk management, and quality assurance. This ensures that Intersect’s due diligence activities remain robust, consistent, and aligned with industry best practices. [ISO standards for Security, Risk and Quality Management.](https://sumsub.com/sumsub-trust-center/)

#### **17. Review and Amendment:**

To ensure this policy remains current, effective, and aligned with regulatory expectations, it will be reviewed at least annually. Intersect’s Operational Services Team is responsible for initiating updates in response to significant organisational changes, regulatory developments, or enhancements to internal processes. Any amendments to the policy must be approved by the Intersect Executive Team before publication and implementation.&#x20;

#### **18.  Records Retention:**

Intersect retains all due diligence records, including KYC and KYB documentation, screening results, risk assessments, correspondence with beneficiaries, and records of decisions taken, for a minimum period of five 5 years from the date of the last transaction or the termination of the business relationship, whichever is the later. This retention period is consistent with applicable AML regulatory requirements. Where a specific regulatory obligation requires a longer retention period, that longer period shall apply. All records are stored securely with access restricted to authorized personnel only. Upon expiry of the applicable retention period, records shall be disposed of securely and in accordance with Intersect's Data Protection and Records Retention Policy.&#x20;

#### **19. Related documents and References:**

This policy should be read in conjunction with the following documents, guidelines and regulatory frameworks:

* Governance and policy documents
* [Intersect as an Administrator](https://docs.intersectmbo.org/cardano/cardano-budget-submission/intersect-as-an-administrator)
* Transparency Policy
* External regulation and best practices
* [SumSub](https://sumsub.com/)
* [Sumsub Trust Centre ](https://sumsub.com/sumsub-trust-center/)
* [CCN.com](https://www.ccn.com/education/crypto/10-countries-where-crypto-remains-banned/) - Owned and operated by Find.co, is a media outlet dedicated to cryptocurrencies, business, finance and technology.&#x20;


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://admin-services.docs.intersectmbo.org/governance/policies-and-guidance/due-diligence-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
