This is the public summary of Target’s anti-money-laundering programme. It tells merchants and partners which checks to expect, why a payment can be held and how to reach the compliance team. If anything is unclear, write to compliance@target.co.uk.
01Purpose and scope
Target Financial Services Ltd (“Target”, “we”) is an Electronic Money Institution authorised by the Financial Conduct Authority under Firm Reference Number 900847. This policy describes the controls we operate to prevent money laundering, terrorist financing and proliferation financing, and explains what they mean for you as a merchant or partner: which documents we ask for, why a payment can be held, and why some questions go unanswered.
It applies to every Target office — London, Riga and Limassol — to every employee, contractor and agent, and to every product we offer: online acquiring, multi-currency processing, payouts, recurring payments, payment links and invoicing. Where the law of a country we operate in is stricter than this policy, the law applies. The board approves the policy, reviews it at least once a year and whenever the rules change, and publishes it here in summary; the full internal version, with risk-appetite thresholds and rule parameters, is available to regulators and auditors on request.
02Regulatory framework
Our programme is built on the following instruments and is mapped against each of them at every annual review:
- United Kingdom. The Proceeds of Crime Act 2002, the Terrorism Act 2000, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 as amended (MLR 2017), the Sanctions and Anti-Money Laundering Act 2018 and the FCA Handbook (SYSC 6.3), read together with the Joint Money Laundering Steering Group guidance for the payments sector.
- European Union. The Fifth and Sixth Anti-Money Laundering Directives (Directive (EU) 2018/843 and Directive (EU) 2018/1673) as transposed in Latvia and Cyprus, the recast Transfer of Funds Regulation (Regulation (EU) 2023/1113) and the EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), which applies from July 2027 and against which we are already aligning our controls.
- International. The FATF 40 Recommendations and the FATF lists of high-risk and monitored jurisdictions, the Wolfsberg Group principles for payment relationships, and the Visa and Mastercard rules on merchant acceptance and prohibited business.
03Governance
The board owns money-laundering risk: it approves this policy and our risk appetite every year and receives a standing quarterly compliance report. Day-to-day responsibility sits with the Money Laundering Reporting Officer (MLRO), Charlotte Ashworth, Head of Compliance, who is the nominated officer under regulation 21 of MLR 2017 and reports directly to the board, not to sales or operations. A deputy MLRO based in Riga covers absences and the EU working day.
We operate three lines of defence. The first is the onboarding, sales and support teams who know the customer and raise the first flag. The second is the compliance and risk team — independent from sales, with no revenue targets — which sets the rules, reviews alerts and makes the final onboarding decision. The third is an annual independent audit of the programme by an external firm, whose findings go to the board with a dated remediation plan. Compliance can decline or exit any relationship without commercial sign-off; the reverse is not true.
04Customer due diligence
Before we open a merchant account we establish who you are, who owns you and what you intend to sell. Every applicant is rated low, medium or high risk on the basis of country, industry, ownership structure, expected volumes and delivery channel, and the rating decides how deep the checks go. Standard due diligence usually completes inside our 2–5 business day onboarding window; enhanced due diligence takes longer because it asks for more evidence.
| Measure | Standard due diligence | Enhanced due diligence |
|---|---|---|
| When it applies | Low- and medium-risk businesses established in the UK, the EEA or an equivalent jurisdiction | High-risk industries, high-risk or non-cooperative jurisdictions, politically exposed persons, complex or opaque ownership, adverse media |
| Company identity | Registry extract, registered address, company number, articles of association | As standard, plus certified copies where documents are issued outside the UK or EEA |
| Beneficial owners | Every person holding 25% or more, verified against an identity document and a proof of address | Threshold lowered to 10%; full ownership chart down to natural persons; each owner screened and interviewed where needed |
| Directors and signatories | Identity verification of all directors and the account signatory | As standard, plus verification of the senior manager who will be our point of contact |
| Business purpose | Website or app review, product list, expected monthly volume and average ticket | Detailed business model, supplier contracts and licences, processing history from previous providers |
| Source of funds | Settlement account in the company’s name, verified by micro-deposit | Documented source of funds and, for the owners, source of wealth |
| Approval | Compliance analyst | MLRO and a member of senior management |
| Review cycle | Every 12 months or on a trigger event | Every 6 months or on a trigger event |
Whatever the rating, we do not open anonymous or numbered accounts, do not onboard shell banks and do not rely on a third party’s checks without seeing the underlying documents. If we cannot complete due diligence we do not start the relationship; if it lapses during one, we suspend settlement until it is restored.
05Ongoing monitoring and transaction rules
Due diligence is a snapshot; monitoring is the film. Every transaction passes through our rules engine and machine-learning scoring in real time, and every account is measured against its own profile. The rules that matter most for money-laundering risk are:
- Velocity and ticket size. A shift in volume, average ticket or transaction count of more than 200% against the trailing 30-day baseline.
- Structuring. Repeated payments just below the €1,000 and €10,000 thresholds, or refunds sent to a card other than the one charged.
- Geography. Card country, IP country and delivery country that do not fit the business, or activity from a jurisdiction on the FATF or HM Treasury high-risk lists.
- Card testing and account takeover. Many small authorisations from one device, IP range or BIN range in a short window.
- Ratios. Refunds above 5% and chargebacks above 0.9% of volume, or refunds that exceed the original sale.
- Product drift. A website that starts selling something other than what was approved, or a merchant category code that no longer fits.
An alert is reviewed by a risk analyst within two business days, and a rule can hold settlement automatically while it is looked at. Accounts are re-rated on every material change — a new owner, a new country, a new product line — and formally reviewed on the cycle in section 04. We monitor our own payout and settlement flows to the same standard, because a merchant’s outgoing money is as informative as the incoming.
06Sanctions and PEP screening
At onboarding, and every day thereafter, we screen every legal entity, beneficial owner, director and signatory against the UK Sanctions List published by OFSI, the EU consolidated financial sanctions list, the UN Security Council list and the US OFAC SDN list, as well as against lists of politically exposed persons, their family members and known close associates, and adverse media. Screening uses fuzzy matching on names, dates of birth and identifiers; potential hits are cleared or confirmed by an analyst, never by the system alone.
A confirmed sanctions match means we do not open the account or, for an existing one, we freeze funds and settlement immediately and report to OFSI and the relevant EU authority without delay. A PEP is not a bar to doing business, but it always triggers enhanced due diligence, senior management approval and source-of-wealth evidence, and the relationship stays high-risk for at least twelve months after the person leaves office.
07Suspicious activity reporting
Every employee must report knowledge or suspicion of money laundering to the MLRO through the internal reporting form on the day it arises; the obligation is personal and cannot be delegated. The MLRO reviews the report, records the decision with reasons and, where suspicion stands, files a Suspicious Activity Report with the UK National Crime Agency — or with the Financial Intelligence Unit of Latvia or MOKAS in Cyprus where the activity is handled there. Where a transaction still needs to proceed we request a defence against money laundering and wait for consent: up to seven working days, extendable by a 31-day moratorium.
We never tell a customer that a report has been made or is being considered. Tipping off is a criminal offence and grounds for dismissal. A request for more documents, a delay in settlement or the closure of an account should not be read as confirmation of anything.
08Record keeping
We keep due-diligence documents, the record of every transaction, screening results, alert reviews, internal reports and the MLRO’s decisions for five years from the end of the business relationship or the date of an occasional transaction, as MLR 2017 requires. Records are stored encrypted in UK and EU data centres, every access is logged, and they can be produced to a regulator or a court within the deadline requested. After five years they are deleted unless a legal hold, an open investigation or another law requires longer, and never beyond ten years in total. Personal data in these records is processed under our Privacy policy; the lawful basis is our legal obligation, and the right to erasure does not apply while the retention period runs.
09Training
Every new joiner completes anti-money-laundering training in their first two weeks and before they can access customer data; every employee repeats it annually and must score 80% or more to pass. Onboarding, risk, support and finance teams receive role-specific modules — how to read a corporate structure, what structuring looks like in a dashboard, how to handle a customer who asks whether they have been reported. Completion is tracked and reported to the board, and an overdue record suspends system access until it is cleared.
10Prohibited and restricted business
We do not process payments for the following, regardless of licence or jurisdiction:
- Unlicensed gambling, lotteries and betting
- Narcotics, controlled substances and drug paraphernalia
- Weapons, ammunition and explosives
- Counterfeit goods and infringement of intellectual property
- Adult content that is non-consensual or involves minors
- Pyramid and Ponzi schemes, unregistered securities and unlicensed investment products
- Shell banks, anonymous accounts and prepaid instruments without a KYC layer
- Businesses established in, or controlled from, a jurisdiction under comprehensive sanctions or on the FATF “call for action” list
The following are restricted: they can be onboarded only after enhanced due diligence, with a valid licence where one is required, and remain high-risk for the life of the relationship:
- Licensed gambling and fantasy sports
- Crypto-asset exchanges, wallets and brokers registered with a competent authority
- Forex, CFD and binary-option brokers
- Tobacco, vape and CBD products
- Nutraceuticals, dating and subscription services with negative-option billing
- Dealers in precious metals, stones and other high-value goods
- Charities and crowdfunding platforms
- Debt collection, credit repair and money-service businesses
11Contact
Questions about this policy, requests from regulators and law-enforcement agencies, and reports of suspected misuse of the platform go to the compliance team at compliance@target.co.uk. We answer compliance queries within five business days and law-enforcement requests within the statutory period. Anything reported to us in confidence stays confidential, including the identity of the person reporting it.
Money Laundering Reporting OfficerTarget Financial Services Ltd
1 Poultry, London EC2R 8EJ, United Kingdom
compliance@target.co.uk
Merchants with a question about their own onboarding should contact their personal manager or support first — they can see the status of your review and tell you which document is outstanding.