Dasar AML/CFT
Berkuat kuasa / Dikemas kini: 3 September 2026 · Karya — peniaga barangan digital, berdaftar di Malaysia.
1. Abbreviations & Definitions
This Policy uses the following abbreviations and defined terms.
| Abbreviation | Definition |
|---|---|
| AMLA / the Act | The Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 |
| AML/CFT | Anti-Money Laundering and Counter Financing of Terrorism |
| BNM | Bank Negara Malaysia |
| FATF | Financial Action Task Force |
| CDD | Customer Due Diligence |
| EDD | Enhanced Due Diligence |
| ODD | Ongoing Due Diligence |
| CO | Compliance Officer |
| STR | Suspicious Transaction Report |
| PEP | Politically Exposed Person |
| UNSC | United Nations Security Council |
| MOHA | Malaysian Ministry of Home Affairs |
| Policy | This AML/CFT policy of Karya, including all related procedures, documents and instruments |
In this Policy, "we", "us" and "our" refer to Karya (Company No. 1234567-X), trading as Karya, the operator of the website at https://karya.rizen.space/ (the "Website") and the seller of digital goods, including vouchers, e-codes, software licences and top-up codes delivered electronically or instantly.
Role of the Payment Processor
Payments made on the Website are processed by Bayarcash Sdn. Bhd. (Company No. 202201040365) of Kota Bharu, Kelantan, Malaysia (the "Payment Processor"). The Payment Processor acts solely as an independent third-party provider of payment-processing services. It is not the seller, supplier, merchant of record or counterparty to any purchase, and it does not own, control or operate the Website.
Karya, and not the Payment Processor, is the seller of record and your sole counterparty in respect of any purchase and the supply of digital goods. This Policy describes the AML/CFT measures adopted by Karya. The Payment Processor maintains its own AML/CFT programme as a regulated payment service provider, and may independently screen, hold, delay, decline, cancel or report transactions in accordance with its own obligations under the Act and BNM requirements.
2. Statement of Commitment
Karya is committed to conducting its business with integrity and in full compliance with the Act and all applicable AML/CFT requirements and BNM guidelines. We adopt proactive and preventive measures by implementing this Policy as a testament of our commitment to combat any form of money laundering and terrorism financing in connection with the sale and electronic delivery of digital goods.
3. Money Laundering & Terrorism Financing
It is our policy to prohibit and actively prevent money laundering and any activity that facilitates money laundering or the funding of terrorist or criminal activities through our business.
Money laundering generally occurs in three stages.
| Stage | Description |
|---|---|
| Placement | Cash from criminal activity enters the financial system. |
| Layering | Funds are moved between accounts or institutions to separate them from their criminal origin. |
| Integration | Funds are reintroduced into the economy as apparently legitimate assets. |
Terrorism financing may involve funds from legitimate or illegitimate sources; the key concern is concealing the origin or intended use of the funds. The methods used may mirror those of traditional money launderers.
4. Compliance Officer (CO)
Karya designates a Compliance Officer with full responsibility and authority to enforce the AML/CFT programme. The CO must be competent, knowledgeable and fit and proper to perform the duties impartially. The CO's responsibilities include the development, implementation, documentation, advisory, review and monitoring of compliance, overseeing training, maintaining records, and acting as the reporting officer to the relevant authorities.
5. Risk Assessment & Risk Register
We maintain a risk register based on a risk assessment across our customers, partners and counterparties, which is reviewed and improved to reflect the current situation. To avoid unnecessary risk, we will not knowingly enter into a business relationship with parties located in high-risk jurisdictions that are subject to international sanctions, and we apply additional controls where the nature, value or pattern of a transaction in digital goods presents an elevated risk.
6. Customer Due Diligence (CDD)
Where required by the nature of a relationship or transaction, and before establishing any business relationship, collaboration or partnership, we conduct CDD to verify identity and ascertain the source of funds. CDD is also performed whenever there is suspicion or doubt as to previously obtained information, regardless of any transaction threshold. Sanction screening is conducted against the UNSC and MOHA lists. Documents that may be obtained include the following.
| Subject | Documents that may be required |
|---|---|
| Individuals | NRIC or government-issued identity card, or foreign passport / identity document. |
| Legal persons | Name and legal form, business / company registration number, company profile, business and registered address, certificate of incorporation, constitution, and authorised representative details. |
| Clubs, societies & charities | Certificate of approval / registration. |
7. Enhanced Due Diligence (EDD)
In addition to standard CDD, we conduct EDD in higher-risk situations, including persons or transactions involving higher-risk or sanctioned jurisdictions, or any other situation representing an elevated risk of money laundering or terrorism financing. The objective is to obtain deeper insight into the source of funds and wealth.
8. Politically Exposed Persons (PEP)
We adopt the FATF definition of PEPs, covering foreign, domestic and international-organisation PEPs, as well as their family members and close associates. Where a PEP is identified, the matter is escalated to the Compliance Officer and management for assessment.
9. Ongoing Due Diligence (ODD)
CDD and EDD are not one-time exercises. We conduct ODD on regular customers and on transactions that exceed defined thresholds or otherwise warrant continued monitoring, so that customer information remains current and transaction patterns continue to make economic sense.
10. Suspicious Transaction Reporting (STR)
A suspicious transaction is any transaction (including any attempted or proposed transaction), regardless of amount, that appears unusual, has no clear economic purpose, appears illegal, does not commensurate with the customer's profile, or indicates involvement in money laundering or terrorism financing.
All employees must report any suspicious activity to the Compliance Officer immediately. The Compliance Officer will complete the STR form and submit it to the Financial Intelligence and Enforcement Department (FIED) of Bank Negara Malaysia. All STRs are strictly confidential and shall not be disclosed except as required by law. We may hold, delay, decline or cancel any transaction we reasonably consider suspicious, high-risk or non-compliant with AML/CFT requirements.
11. Record Keeping
All information and records collected through CDD, EDD and STR exercises, together with the related accounting and human-resources records, are kept securely in both hardcopy and digital form, and retained for at least seven (7) years from the closure of the respective engagement, or for such longer period as may be required by law.
12. Training & Circulation of Policy
The finalised and updated Policy is circulated and made known to all employees and workers, supported by awareness and training sessions conducted from time to time. The Policy is made accessible in both hardcopy and softcopy.
13. Review
This Policy shall undergo a mandatory review at least annually. We may appoint an external party to conduct an independent review of the Policy for the purpose of enhancement. This Policy takes effect on the effective date stated above and remains in force until amended or replaced.
14. Contact Information
If you have any questions or concerns about this AML/CFT Policy, please contact us:
Karya (trading as Karya) —
| Field | Detail |
|---|---|
| Merchant | Karya (trading as Karya) |
| Registration No. | 1234567-X |
| Address | No 27 Jalan Kebun Nenas 1K/KS7, Bandar Putera, 41000 Klang, Selangor |
| Website | https://karya.rizen.space |
| Support Email | naz.fazriq@gmail.com |
For matters relating specifically to payment processing, the Website's payments are handled by the Payment Processor:
| Field | Detail |
|---|---|
| Payment Processor | Bayarcash Sdn. Bhd. (Company No. 202201040365) |
| Address | Kota Bharu, Kelantan, Malaysia |
| trust-center@bayarcash.com |