This Compliance Policy ("Policy") describes the compliance framework maintained by Norhart Pro, Inc. ("Norhart Pro," "we," "us," or "our") across its trading and investing platform. This Policy applies to all users, employees, contractors, agents, and third-party partners of Norhart Pro and should be read alongside our Terms of Service, Privacy Policy, and Risk Disclosures.
1. Overview
Norhart Pro is committed to the highest standards of regulatory compliance, ethical business conduct, and financial integrity. Our compliance programme is designed to:
- Prevent the platform from being used for money laundering, terrorist financing, or other financial crimes.
- Ensure all users are properly identified and verified before accessing financial services.
- Comply with applicable laws in each jurisdiction in which we operate, including financial services regulations, data protection law, and international sanctions regimes.
- Maintain robust internal controls, audit trails, and reporting mechanisms.
- Foster a culture of compliance throughout our organisation.
Our Chief Compliance Officer (CCO) is responsible for maintaining, enforcing, and periodically reviewing this Policy. All compliance-related concerns should be directed to compliance@norhartpro.com.
2. Anti-Money Laundering (AML)
Norhart Pro maintains a comprehensive Anti-Money Laundering programme consistent with the Financial Action Task Force (FATF) Recommendations, applicable local legislation, and international best practices.
2.1 AML Programme Components
- Written AML Policies: Documented policies reviewed annually and updated whenever regulations change.
- Independent Audit: Annual independent audit of our AML controls and procedures.
- Designated Compliance Officer: A named individual responsible for day-to-day AML oversight.
- Ongoing Monitoring: Continuous transaction monitoring for unusual activity patterns.
2.2 Customer Due Diligence (CDD)
We apply risk-based Customer Due Diligence to all users. The level of due diligence applied is proportionate to the assessed risk level:
- Standard CDD: Applied to all users at onboarding. Includes identity verification and address confirmation.
- Enhanced Due Diligence (EDD): Applied to higher-risk users, including politically exposed persons (PEPs), clients from high-risk jurisdictions, and those displaying unusual transaction behaviour.
- Simplified Due Diligence: Applied only where permitted by law and where risk is demonstrably low.
2.3 Transaction Monitoring
Our automated transaction monitoring system screens all activity against defined thresholds and behavioural rules. Alerts are reviewed by our compliance team within prescribed timeframes. We monitor for indicators including, but not limited to:
- Rapid cycling of funds without apparent economic purpose.
- Deposits immediately followed by withdrawal requests with no trading activity.
- Structured transactions designed to evade reporting thresholds.
- Unusual geographic patterns inconsistent with the user's profile.
3. Know Your Customer (KYC)
Before any user may deposit funds, execute a trade, or activate institutional features, Norhart Pro requires identity verification. Our KYC process is conducted at onboarding and at defined trigger events thereafter.
3.1 Identity Verification Requirements
All users must provide:
- Full legal name as it appears on a government-issued identity document.
- Date of birth.
- Residential address (not a P.O. box).
- A valid government-issued photo ID (passport, national identity card, or driver's licence).
- Proof of address dated within three months (utility bill, bank statement, or equivalent).
3.2 Enhanced Verification for Higher Tiers
Users accessing Pro or Elite tier strategies, the Norhart Pro Card, or large withdrawal thresholds (above $10,000 in a single transaction) must complete enhanced verification, which may include:
- Biometric liveness check.
- Source of funds declaration.
- Source of wealth documentation for deployments above $50,000.
- Video verification call at our compliance team's discretion.
3.3 Politically Exposed Persons (PEPs)
Norhart Pro applies enhanced scrutiny to individuals who are, or who are closely associated with, politically exposed persons. PEPs are required to undergo Enhanced Due Diligence and senior management approval before onboarding is completed. PEP status is continuously monitored throughout the client relationship.
3.4 Beneficial Ownership
Where a user is acting on behalf of a legal entity or trust, Norhart Pro requires disclosure and verification of all beneficial owners holding 25% or more of the entity, as well as the entity's ultimate controlling party.
4. Sanctions Screening
Norhart Pro screens all users, transactions, and counterparties against applicable sanctions lists maintained by international and national authorities, including:
- The United Nations Security Council Consolidated List.
- The US Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) List.
- The European Union Consolidated Sanctions List.
- His Majesty's Treasury (HMT) UK Consolidated List of Targets.
- Other applicable national and regional sanctions lists.
4.1 Restricted Jurisdictions
Norhart Pro does not onboard users or process transactions where doing so would violate applicable sanctions. Users located in or connected to comprehensively sanctioned jurisdictions are not permitted to use the platform. This list is reviewed and updated on a rolling basis to reflect regulatory changes.
4.2 Ongoing Sanctions Monitoring
Sanctions screening is not a one-time event. All existing users are re-screened against sanctions lists in real time whenever lists are updated, and automatically when they initiate significant transactions. Any match triggers an immediate account freeze pending compliance review.
5. Counter-Terrorism Financing (CTF)
Norhart Pro takes seriously its obligations to prevent the financing of terrorism. Our CTF controls are integrated into our broader AML framework and include:
- Screening of all users against terrorism financing watch lists maintained by OFAC, the UN, EU, and HMT.
- Behavioural rules specifically tuned to identify patterns associated with terrorist financing, such as small, frequent cross-border transfers and sudden account activity after prolonged dormancy.
- Zero tolerance for any association with designated terrorist organisations or individuals.
- Mandatory reporting of any known or suspected terrorist financing activity to the relevant Financial Intelligence Unit (FIU) without tipping off the subject.
6. Suspicious Activity Reporting (SAR)
Where Norhart Pro knows, suspects, or has reasonable grounds to suspect that a transaction involves the proceeds of criminal conduct or is connected to terrorist financing, we are obligated to file a Suspicious Activity Report (SAR) or equivalent report with the appropriate FIU without delay, and without notifying the subject of the report.
6.1 Tipping-Off Prohibition
Users must be aware that once an internal SAR process has been initiated, we may be legally prohibited from processing your transaction, closing your account, or discussing the reasons for our actions with you. This is a legal requirement, not a discretionary decision, and no inference of wrongdoing should be drawn from our inability to explain account restrictions in certain circumstances.
6.2 Currency Transaction Reporting
Where required by applicable law, Norhart Pro files Currency Transaction Reports (CTRs) for transactions meeting or exceeding applicable thresholds. Structuring transactions to avoid reporting thresholds is a criminal offence and will result in immediate account suspension and regulatory referral.
7. Data Protection & GDPR Compliance
Norhart Pro processes personal data in accordance with all applicable data protection legislation, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent laws in other jurisdictions. Full details of how we collect, use, store, and share your personal data are set out in our Privacy Policy.
7.1 Data Minimisation
We collect only the personal data strictly necessary for our compliance, operational, and contractual obligations. We do not sell personal data to third parties for marketing purposes.
7.2 Retention Periods
We retain KYC and transaction records for a minimum of five years from the end of the customer relationship, or longer where required by applicable law. Retention schedules are reviewed annually.
7.3 Cross-Border Data Transfers
Where personal data is transferred outside the European Economic Area or the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the relevant supervisory authority.
8. Payment Card Industry (PCI DSS) Compliance
Norhart Pro and its card processing partners maintain compliance with the Payment Card Industry Data Security Standard (PCI DSS) at the applicable level. This includes:
- Encryption of cardholder data at rest and in transit using TLS 1.2 or higher.
- Annual penetration testing and quarterly vulnerability scans.
- Strict access controls limiting cardholder data to authorised personnel only.
- Tokenisation of card data so that full card numbers are never stored on our servers.
Users should report any suspected compromise of their payment card data linked to Norhart Pro activity to our compliance team immediately.
9. Internal Controls
Norhart Pro operates a layered control environment designed to detect and prevent financial crime, errors, and misconduct.
9.1 Segregation of Duties
Key functions — onboarding, transaction approval, compliance review, and reporting — are performed by separate individuals or teams to prevent conflicts of interest and reduce the risk of undetected error or fraud.
9.2 Four-Eyes Principle
All high-value or high-risk transactions, account approvals, and compliance exceptions require sign-off by two authorised individuals before processing.
9.3 Audit Logging
All significant platform actions — logins, fund movements, strategy deployments, KYC decisions, and compliance overrides — are logged in tamper-evident audit trails retained for a minimum of seven years.
9.4 Independent Audit
Our compliance programme is subject to annual independent review by qualified external auditors. Audit findings are reported to senior management and the Board, and remediation timelines are tracked and enforced.
10. Staff Training
All Norhart Pro employees and contractors with access to customer data or financial systems receive mandatory compliance training on joining and annually thereafter. Training covers:
- Recognising and escalating suspicious activity.
- AML and CTF typologies relevant to digital asset and trading platforms.
- Sanctions obligations and tipping-off restrictions.
- Data protection responsibilities under GDPR and equivalent laws.
- Insider trading and market manipulation prohibitions.
- Whistleblower procedures and non-retaliation policy.
Training completion is tracked and non-completion may result in restricted system access until training is up to date.
11. Record-Keeping
We maintain complete and accurate records of all customer identification information, transaction history, compliance decisions, SAR filings, and audit results. Records are:
- Retained for a minimum of five years from the end of the customer relationship, or longer where required by law.
- Stored in secure, access-controlled environments with encryption at rest.
- Available to authorised regulatory bodies and law enforcement upon lawful request.
- Backed up to geographically separate locations to prevent loss.
12. Third-Party Due Diligence
Norhart Pro extends its compliance standards to third-party service providers, liquidity providers, custodians, and technology partners. Before entering into any material relationship, we conduct due diligence to assess:
- The third party's regulatory status and licensing in relevant jurisdictions.
- Their AML and sanctions compliance posture.
- Data protection practices and certifications.
- Financial stability and operational resilience.
Material third-party relationships are subject to ongoing monitoring and periodic re-due diligence. Contracts with third parties include provisions requiring compliance with our standards and the right to audit.
13. Whistleblower Policy
Norhart Pro is committed to a culture where concerns about non-compliance, misconduct, or financial crime can be raised without fear of retaliation. Our whistleblower framework provides:
- Confidential Reporting: Concerns may be raised anonymously via our dedicated compliance email or through our external third-party whistleblowing hotline.
- Non-Retaliation: Any individual who reports a genuine concern in good faith is protected from retaliation, dismissal, or adverse treatment, regardless of the outcome of any investigation.
- Independent Investigation: All reports are investigated by personnel independent of the subject of the concern.
- External Reporting: Users also have the right to report concerns directly to relevant regulatory authorities at any time.
To raise a concern confidentially, email whistleblower@norhartpro.com.
14. Enforcement & Penalties
Breach of this Compliance Policy or applicable laws may result in one or more of the following actions:
- Immediate suspension or permanent termination of the user's account.
- Freezing of funds pending regulatory investigation.
- Referral of information to law enforcement agencies, financial intelligence units, or regulators without prior notice to the user.
- Civil or criminal proceedings as appropriate.
- Forfeiture of any profits derived from non-compliant activity.
Norhart Pro reserves the right to withhold funds in any account under investigation for as long as required by applicable law or regulatory guidance. We are not liable for losses arising from account restrictions applied in compliance with our legal obligations.
15. Regulatory Relationships
Norhart Pro maintains open and cooperative relationships with relevant regulatory authorities. We are committed to:
- Responding promptly and fully to regulatory enquiries, examinations, and information requests.
- Filing all required regulatory reports accurately and on time.
- Proactively engaging with regulators on emerging compliance matters relevant to our business model.
- Registering and maintaining applicable licences in each jurisdiction where required.
If you are a regulator seeking information about Norhart Pro's compliance programme or a specific matter, please contact our compliance team at regulatory@norhartpro.com.
16. Policy Updates
This Compliance Policy is reviewed at least annually and updated whenever there is a material change in applicable law, regulatory guidance, or our business activities. We will notify users of material changes by posting an updated version on our website and, where required, by direct communication. Continued use of the platform following notification of a material policy change constitutes acceptance of the revised Policy.
The version history of this Policy is maintained internally and is available to regulators upon request.
17. Contact Compliance
If you have questions about this Policy or wish to raise a compliance concern, please contact our Compliance team:
- Email: compliance@norhartpro.com
- Whistleblower (confidential): whistleblower@norhartpro.com
- Regulatory enquiries: regulatory@norhartpro.com
- Post: Norhart Pro, Inc., Compliance Department, [Registered Address]
We aim to acknowledge all compliance enquiries within two business days and to provide a substantive response within ten business days.
Also read: Terms of Service · Privacy Policy · Risk Disclosures