Compliance & Regulatory

TaqFlow's compliance framework, built on the AML/CFT and data protection laws of every jurisdiction where we operate.

Last updated: July 2026

Regulatory Framework

TaqFlow operates in accordance with the regulatory frameworks of every jurisdiction where we collect user data, maintain physical operations, or actively target customers. Our compliance program is designed to satisfy the requirements of each applicable regime simultaneously, applying the highest standard where requirements overlap. Key frameworks include:

  • United Arab Emirates: Federal Decree-Law No. 20 of 2018 on AML/CFT; Cabinet Decision No. 10 of 2019; CBUAE standards; Federal Decree-Law No. 45 of 2021 (PDPL); guidance from the UAE Financial Intelligence Unit (FIU) and EOCN.
  • European Union / EEA: EU AML Directives (AMLD); General Data Protection Regulation (GDPR); applicable national transpositions in each member state.
  • United States: Bank Secrecy Act (BSA) and FinCEN regulations; OFAC sanctions programs; applicable state money transmitter licensing; state-level privacy laws (CCPA/CPRA).
  • Kazakhstan: Law No. 94-V on Personal Data; AML/CFT Law No. 191-IV; National Bank of Kazakhstan regulations.
  • Uzbekistan: Law on Personal Data; AML/CFT Law; Central Bank of Uzbekistan regulations.
  • Georgia: Law on Personal Data Protection; AML/CFT Law; National Bank of Georgia regulations.
  • Azerbaijan: Law on Personal Data; AML/CFT Law; Central Bank of Azerbaijan regulations.
  • Armenia: Law on Protection of Personal Data; AML/CFT Law; Central Bank of Armenia regulations.
  • Kyrgyz Republic, Tajikistan & Turkmenistan: Applicable national AML/CFT legislation, personal data protection laws, and central bank regulations in each respective jurisdiction.

We also align with international standards set by the Financial Action Task Force (FATF) and implement recommendations adopted by FATF-style regional bodies covering our operating jurisdictions.

KYC & KYB

Full business verification including trade licence, beneficial ownership, and UBO disclosure.

Sanctions Screening

Real-time screening against UN, UAE, EU, UK, US OFAC, and other global sanctions lists.

Transaction Monitoring

Automated and manual monitoring for suspicious patterns and reportable activity.

SAR Reporting

Suspicious Activity Reports filed with the relevant Financial Intelligence Unit in each jurisdiction.

Data Protection

AES-256 encryption, access controls, and compliance with each jurisdiction's data protection law.

Audit Trails

Full immutable audit trails on every transaction, approval, and system action.

Customer Due Diligence (CDD)

We conduct risk-based customer due diligence at onboarding and on an ongoing basis, consistent with FATF recommendations and local AML/CFT laws in every operating jurisdiction. This includes:

  • Identification and verification of the legal entity, directors, and authorised signatories.
  • Identification of Ultimate Beneficial Owners (UBOs) holding 25% or more ownership or control (or the lower threshold mandated by local law).
  • Understanding the nature of your business and expected transaction patterns.
  • Risk rating based on geography, industry, ownership structure, and transaction volume.

For higher-risk customers, we apply Enhanced Due Diligence (EDD), including additional documentation, senior management approval, and enhanced monitoring.

Sanctions & PEP Screening

All customers, counterparties, and transactions are screened in real time against:

  • United Nations Security Council (UNSC) consolidated sanctions list.
  • UAE Local Terrorist List and other national designated persons/entities lists.
  • European Union, United Kingdom HM Treasury, and US OFAC (SDN) sanctions lists.
  • Sanctions lists maintained by Kazakhstan, Uzbekistan, Georgia, Azerbaijan, Armenia, and other operating jurisdictions.
  • Politically Exposed Persons (PEP) databases, with enhanced review for PEP-related parties.

Any match triggers an immediate hold pending compliance review. We are prohibited from processing payments to or from sanctioned individuals, entities, or jurisdictions under any applicable regime.

Transaction Monitoring & Reporting

Our transaction monitoring system continuously analyses payment patterns for indicators of money laundering, terrorist financing, or fraud. Suspicious transactions are escalated to our Compliance Officer for review and, where required, a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) is filed with the relevant Financial Intelligence Unit in the applicable jurisdiction within the regulatory timeframe.

Record Keeping

In accordance with the AML/CFT laws of each operating jurisdiction, we retain all customer identification documents, transaction records, and compliance documentation for the minimum period required by local law — generally five (5) years from the end of the business relationship or the date of the relevant transaction, whichever is later. Longer retention periods apply where mandated by specific jurisdictions.

Cross-Border Data Transfers

Because TaqFlow operates across multiple jurisdictions, personal data may be transferred between countries. We ensure that all cross-border transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) for transfers from the EU/EEA, adequacy decisions where applicable, and equivalent transfer mechanisms for other jurisdictions.

Reporting Misconduct

If you suspect fraudulent activity, sanctions violations, or any misuse of the TaqFlow platform, please report it immediately to sales@taqflow.io. All reports are treated confidentially and, where applicable, whistleblower protections apply under the laws of the relevant jurisdiction.

Contact

For compliance enquiries, contact our Chief Compliance Officer at sales@taqflow.io with the subject line "Compliance Enquiry" or send correspondence to TaqFlow, 304 Saaha Offices B Souk Al Bahar, Dubai, United Arab Emirates.