Anti-Money Laundering & Counter-Terrorist Financing (AML/CTF) Policy
Last updated: June 5, 2026
Entity: Sketch Labs L.L.C-FZ (License No. 2420007.01), Meydan Free Zone, Dubai, UAE ("First Dollar", "we", "us"). Policy owner: Compliance (founder-designated MLRO).
1. Purpose
First Dollar operates a builder discovery and bounty distribution platform. Because the platform facilitates payouts to users, we maintain this AML/CTF program to prevent the platform from being used to launder money, finance terrorism, evade sanctions, or move illicit funds. This policy sets out the controls, responsibilities, and procedures we apply.
2. Scope
This policy applies to all First Dollar personnel, all Sponsors (bounty creators) who fund bounties, and all users who receive payouts. It covers onboarding, transaction monitoring, sanctions screening, recordkeeping, and reporting.
3. Risk-based approach
We apply controls proportionate to risk. Risk is assessed across:
- Customer risk — Sponsor type, jurisdiction, funding source, and history; payout recipient jurisdiction and verification status.
- Geographic risk — exposure to sanctioned, embargoed, or high-risk jurisdictions (FATF call-for-action and increased-monitoring lists).
- Product/channel risk — payouts are sent to embedded wallets (created via Privy) and settle in USDC on Base. Identity verification and screening controls are being built out as our payment integrations mature; until then, controls are applied manually and on a risk basis.
- Transaction risk — value, frequency, and patterns inconsistent with a user's expected activity.
Higher-risk relationships trigger enhanced due diligence (EDD) and senior review before funds move.
4. Roles and responsibilities
- A designated compliance lead (acting MLRO) owns this program, reviews escalations, files reports where required, and maintains records.
- All staff are responsible for identifying and escalating suspicious activity and may not "tip off" a subject under investigation.
- As our payment integrations mature, a third-party payments/identity-verification provider and its vendors will perform identity verification, sanctions/PEP screening, and document checks at the payout stage under their own regulated programs; First Dollar will rely on and supplement these controls. Until then, verification and screening are performed on a manual, risk-based basis.
5. Customer Due Diligence (CDD)
5.1 Users (payout recipients)
- At signup: verified email and optional linking of social/developer accounts (X, Farcaster, GitHub). An embedded wallet is created (via Privy) to receive any winnings when the user first takes an action that requires one, such as applying to a bounty or campaign.
- We do not currently perform government-ID identity verification. As payment integrations mature, identity verification will be required before payouts where applicable, capturing legal name, date of birth, residential address, country of residence, and a government-issued ID, with document/liveness checks performed by a third-party provider.
- Where identity verification and screening are required, no payout will be released until they clear.
5.2 Sponsors (bounty creators)
- Manual approval before posting — our team reviews the business email and the Sponsor's online/social presence (and on-chain wallet history where applicable) to confirm the organization is legitimate and authorized; only approved Sponsors can post bounties.
- Beneficial-ownership and source-of-funds information for higher-value or higher-risk funded relationships.
- Agreement to our Terms & Conditions and Acceptable Use Policy, which prohibit unlawful, fraudulent, and high-risk activity.
5.3 Enhanced Due Diligence (EDD)
EDD applies to PEPs, users/Sponsors in high-risk jurisdictions, unusually large or structured payouts, and any relationship flagged during monitoring. EDD includes additional identity/source-of-funds evidence and senior compliance sign-off.
6. Sanctions screening
- Where identity verification applies, payout recipients and Sponsors will be screened against applicable sanctions lists (UN, OFAC, UK HMT, EU, and UAE local lists) and PEP databases via a third-party provider before funds are released. Until automated screening is in place, screening is conducted on a manual, risk-based basis.
- We do not onboard, transact with, or pay any individual or entity that is sanctioned, located in a comprehensively sanctioned/embargoed jurisdiction, or owned/controlled by a sanctioned party.
- A positive or unresolved match halts the transaction pending review; confirmed matches are blocked and reported as required.
7. Transaction monitoring
We review platform and payout activity for red flags, including:
- Payouts inconsistent with a user's stated activity or the bounty completed.
- Structuring (splitting amounts to avoid thresholds) or rapid in-and-out movement.
- Multiple accounts that appear to share identity, device, or wallet fingerprints (collusion / self-dealing).
- Bounties that appear designed to disguise the true purpose of a payment.
- Connections to sanctioned or high-risk addresses.
Review is currently performed manually by our team, supported by the screening our payments partner performs at the payout stage; we may add automated monitoring controls as the platform scales. Where activity is flagged, it is escalated to the compliance lead, and we can freeze payouts and offboard the relationship pending review.
8. Suspicious activity reporting
Where activity is reasonably suspected to involve money laundering, terrorist financing, or sanctions evasion, the compliance lead files a Suspicious Activity / Suspicious Transaction Report with the UAE Financial Intelligence Unit (via the goAML portal) and/or supports our payments partner's reporting obligations. Reporting is confidential; tipping off is prohibited.
9. Recordkeeping
We retain CDD records, payout records, screening results, and investigation/escalation files for a minimum of five (5) years from the end of the business relationship or transaction, or longer where required by law. Records are stored securely with access limited to authorized personnel.
10. Training & governance
Relevant personnel receive AML/CTF awareness training on onboarding and periodically thereafter. This policy is reviewed at least annually, or upon material regulatory or product changes, and updated accordingly.
11. Cooperation with authorities
We cooperate fully with lawful requests from regulators, law enforcement, and our payments partners, including the production of records and freezing of funds where legally required.
12. Contact
Compliance: [email protected]
