Skip to main content
Legal

Compliance Framework

The Vision Corporation Holdings Ltd (company number 16767315) operates a risk-based compliance framework covering AML/CTF, sanctions, digital-asset controls, market conduct, data protection, customer protection, and prudential obligations. We act as an agent and distributor under regulated partners. We do not directly hold an EMI or VASP licence. All regulated financial and crypto services are delivered through our licensed partner institutions. Product availability varies by jurisdiction.

Version
v1.0
Effective
12 July 2026
Last review
12 July 2026
Owner
Compliance Department
Reading time
~10 min

Section

01

Compliance Philosophy

The Vision Corporation Holdings Ltd (company number 16767315) treats compliance as a foundation of the business, not an obligation added on top of it. Our approach is risk-based, proportionate, and reviewed as products, markets, and regulation evolve.

We pair responsible financial innovation with strong customer protection and open cooperation with regulators. Where an activity carries higher risk, we invest in stronger controls before offering the service.

  • Responsible financial innovation
  • Customer protection at every touchpoint
  • Transparent regulatory cooperation
  • Risk management embedded in day-to-day operations

Section

02

Governance Structure

Compliance governance runs from the Board down to individual control owners. The Board sets the risk appetite and oversees the effectiveness of the compliance framework.

A dedicated Money Laundering Reporting Officer (MLRO) and Head of Compliance report to the Board. Policies are reviewed at least annually and after any material regulatory or business change.

  • Board oversight of the compliance framework and risk appetite
  • Compliance Committee reviewing controls, incidents, and regulatory change
  • Risk Committee overseeing prudential, operational, and financial-crime risk
  • Defined escalation processes for material issues, breaches, and near-misses

Section

03

Three Lines of Defence

We operate the widely recognised three-lines-of-defence model so that ownership, oversight, and assurance are clearly separated.

First line

Business and operations teams own the daily controls, from customer onboarding checks to payment approvals and access management.

Second line

Compliance and Risk independently set policy, monitor first-line execution, and challenge business decisions where controls or risk appetite are at stake.

Third line

Internal Audit provides independent assurance that the framework is designed and operating effectively, with material findings tracked to closure.

Section

04

AML & Financial Crime Prevention

Our anti-money-laundering (AML) and counter-terrorist-financing (CTF) programme is designed around the risks specific to digital assets, cross-border payments, and institutional custody.

Customer due diligence is proportionate to risk and refreshed on a defined cadence. Higher-risk relationships receive enhanced due diligence and senior sign-off.

  • Customer due diligence (CDD) and enhanced due diligence (EDD)
  • Ongoing transaction monitoring against typologies and behavioural baselines
  • Know-your-transaction (KYT) analytics on incoming and outgoing flows
  • Sanctions and adverse-media screening at onboarding and continuously
  • Suspicious activity reporting to the relevant financial intelligence unit
RelatedAML Policy

Section

05

Sanctions Compliance

We screen customers, counterparties, and blockchain addresses against consolidated sanctions lists including UK OFSI, EU, US OFAC, and UN designations. Lists are refreshed automatically and any positive match blocks the interaction pending review.

  • Onboarding screening against consolidated sanctions and PEP lists
  • Continuous re-screening as lists and customer data change
  • Geographic restrictions applied to prohibited or high-risk jurisdictions
  • Wallet-address and asset screening for on-chain activity

Section

06

Digital Asset Compliance

Digital assets sit at the core of our platform, so we treat on-chain controls with the same rigour as traditional financial-crime controls.

We combine blockchain analytics, wallet-risk assessment, and custody controls to keep illicit flows out of the platform and to give customers a clear picture of the assets they hold.

  • Blockchain analytics on inbound and outbound transfers
  • Wallet risk assessment covering direct and indirect exposure
  • Ongoing asset monitoring against emerging typologies
  • Transaction screening aligned with travel-rule readiness

Section

07

Information Security & Data Protection

Information security and data protection controls protect customer assets, personal data, and the integrity of the platform. Security is governed jointly by Compliance, Risk, and the security function.

  • Least-privilege access controls and role-based permissions
  • Security governance covering change, incident, and vulnerability management
  • Data protection processes aligned with UK GDPR and equivalent regimes
  • Encryption in transit and at rest for sensitive data

Section

08

Customer Protection

Customer protection means giving clients the information, controls, and support they need to use the platform safely and to understand the risks they take.

  • Transparent fees disclosed before every transaction
  • Clear risk disclosures for digital-asset and cross-border products
  • Account security tools including MFA, session controls, and withdrawal safeguards
  • Structured complaint handling with defined response times

Section

09

Market Conduct

We operate to high market-conduct standards even where products fall outside a specific regulated perimeter. Our objective is fair, orderly, and transparent activity for every client.

  • Prevention of market manipulation and abusive trading patterns
  • Fair-dealing standards across quoting, execution, and settlement
  • Conflicts management between desks, clients, and the firm
  • Employee trading controls including pre-clearance and holding periods

Section

10

Conflicts of Interest

Conflicts of interest are identified, disclosed, mitigated, and, where necessary, avoided. A conflicts register is maintained and reviewed by Compliance.

  • Employee personal-account-dealing rules with pre-approval
  • Gifts and hospitality register with monetary thresholds
  • Related-party transaction review and Board escalation
  • Client-first principles embedded in incentive and governance frameworks

Section

11

Training & Awareness

Every employee is trained to recognise financial-crime, conduct, and information-security risks in their role. Training is refreshed annually and after material regulatory change.

  • Structured onboarding for all new joiners
  • Annual refresher training across AML, sanctions, data protection, and conduct
  • Role-specific training for onboarding, monitoring, and customer-facing teams
  • Compliance testing to confirm understanding and identify gaps

Section

12

Independent Testing & Audits

Independent testing confirms that controls work as designed and identifies areas to strengthen before issues escalate.

  • Internal control reviews on a risk-based cadence
  • External assessments of AML controls, custody operations, and information security
  • Remediation tracking with clear owners, target dates, and closure evidence

Section

13

Whistleblowing

Staff and external parties can raise concerns about potential misconduct in confidence. Reports are handled by a designated Whistleblowing Officer and, where appropriate, escalated to the Board.

  • Confidential reporting channels available in and outside working hours
  • Non-retaliation commitment protecting anyone who raises a concern in good faith
  • Structured investigation process with independent oversight of outcomes

Section

14

Regulatory Cooperation

We respond to lawful information requests from competent authorities in accordance with applicable law and data-protection safeguards.

  • Financial-services and prudential regulators
  • Law-enforcement agencies with proper legal process
  • Tax authorities under applicable reporting obligations
  • Financial intelligence units for suspicious-activity reporting

Section

15

Complaints Handling

Complaints are treated as a valuable signal about the customer experience and control environment. They are logged, investigated, and used to drive improvement.

  • Submit a complaint via your account or by email to complaints@thevisionbank.io
  • Acknowledged within 5 business days of receipt
  • Resolved within statutory timeframes for the applicable jurisdiction
  • Unresolved complaints can be escalated to the relevant ombudsman or authority

Section

16

Third-Party Risk Management

Our third-party programme covers the providers we depend on to deliver the service — from custody and banking partners to core technology vendors. Providers are assessed before onboarding and reviewed regularly.

  • Custody providers assessed for segregation, controls, and financial strength
  • Banking partners reviewed for AML, sanctions, and operational resilience
  • Technology providers evaluated for security posture and data-handling
  • Ongoing vendor reviews with defined escalation for material issues

Section

17

Business Continuity & Operational Resilience

Operational resilience protects the services customers rely on. We plan for disruption, test our response, and learn from every incident.

  • Business-continuity plans covering people, technology, and third parties
  • Disaster-recovery arrangements with defined recovery objectives
  • Incident-response playbooks with clear roles and communication paths
  • Regular resilience testing and post-incident reviews

Section

18

Compliance Commitments

These are the ongoing commitments we make to customers, partners, and regulators. They describe how the framework operates rather than one-off achievements.

Contact

How to reach compliance

For compliance, data-protection, or complaints matters, use the channel best suited to your question. All addresses are monitored during business hours.

Data Protection
dpo@thevisionbank.io
Questions

Talk to compliance.

This document is informational and does not constitute legal advice. For clarifications, email compliance@thevisionbank.io or open a ticket from your account.