AML Policy
1. Purpose and Policy Statement
NEO Global Pty Ltd (“NEO”, “the Company”) is committed to preventing its platform, services and payment flows from being used for money laundering, terrorism financing, sanctions evasion, fraud, tax evasion or any other financial crime.
NEO operates a global employment infrastructure platform that connects clients with vetted local Employer of Record (EOR) providers and related workforce services across 150+ countries, and facilitates associated invoicing, deposits and cross-border settlement. The international, multi-party and funds-adjacent nature of this business creates inherent exposure to money laundering and terrorism financing (ML/TF) risk. This Policy sets out the minimum standards NEO applies to identify, mitigate and manage that risk.
This Policy applies to all directors, officers, employees, and contractors of NEO, in all jurisdictions in which NEO operates (“Personnel”). Compliance with this Policy is a condition of employment or engagement. Breaches may result in disciplinary action up to and including termination, and may expose individuals to personal civil or criminal liability.
2. Regulatory Framework
NEO Global Pty Ltd is incorporated in Australia. The primary legal framework relevant to this Policy includes:
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the AML/CTF Rules, as amended (including the AML/CTF Amendment Act 2024 reforms), administered by AUSTRAC;
- Criminal Code Act 1995 (Cth) — money laundering, terrorism financing and bribery offences;
- Autonomous Sanctions Act 2011 (Cth) and Charter of the United Nations Act 1945 (Cth) — the Australian sanctions regime administered by DFAT;
- Foreign and supranational regimes that may apply to NEO’s counterparties or payment corridors, including UN, EU, UK (OFSI) and US (OFAC) sanctions programs; and
- AML/CTF, sanctions and financial-crime laws applicable to NEO’s EOR partners and payment providers in their local jurisdictions.
Designated services assessment. NEO’s core marketplace and workforce services are not, on their face, financial services. However, certain activities — in particular handling or directing client funds, deposits, contractor payments under Contractor of Record (COR) arrangements, and cross-border value transfer — could constitute “designated services” under the AML/CTF Act depending on how they are structured. The AML Compliance Officer must (a) maintain a documented assessment, reviewed with legal counsel, of whether NEO provides designated services and must enrol/register with AUSTRAC, and (b) re-perform that assessment before launching any new product, funds flow or corridor. Regardless of the outcome, NEO applies the standards in this Policy as a matter of good governance and counterparty expectation.
3. Governance and Responsibilities
3.1 Board of Directors
- Approves this Policy and material changes to it;
- Sets NEO’s risk appetite for ML/TF and sanctions risk;
- Receives at least annual reporting on the AML/CTF program, material incidents, and suspicious matter reporting activity (in aggregate).
3.2 AML Compliance Officer (AMLCO)
The Board appoints an AML Compliance Officer at management level. Until a dedicated appointment is made, the Chief Executive Officer holds the role. The AMLCO:
- Owns and maintains this Policy, the ML/TF risk assessment, and supporting procedures;
- Approves high-risk customer and partner relationships and any exceptions to this Policy;
- Is the escalation point for internal suspicious activity reports and decides on external reporting (including Suspicious Matter Reports to AUSTRAC where applicable);
- Manages relationships with regulators, banks and payment providers (e.g. FX/settlement providers) on financial-crime matters;
- Ensures training is delivered and records are kept.
3.3 All Personnel
- Complete AML/CTF training as required;
- Follow the KYC/KYB, screening and payment procedures in this Policy;
- Escalate suspicions promptly to the AMLCO and never “tip off” a customer, partner or worker that they are under review or have been reported.
4. Risk-Based Approach and ML/TF Risk Assessment
NEO adopts a risk-based approach: the intensity of due diligence and monitoring is proportionate to the assessed risk. The AMLCO maintains a written enterprise ML/TF risk assessment, reviewed at least annually and upon material change (new markets, products, funds flows or partner types), covering:
- Customer risk: client type (staffing agencies, MSPs, EOR providers, direct employers), ownership complexity, industry, and whether beneficial owners or directors are politically exposed persons (PEPs);
- Counterparty/partner risk: EOR partners, screening vendors and other suppliers who deliver services or handle funds in local markets;
- Country/geographic risk: FATF high-risk and monitored jurisdictions, sanctioned countries and regions, and corridors with elevated corruption or opaque corporate registries;
- Product/service risk: deposits held or logged by NEO, COR contractor payment flows, payroll funding flows, FX conversion, and any white-label arrangements where NEO relies on a partner’s controls;
- Channel risk: fully remote, non-face-to-face onboarding of clients, partners and workers.
Each client and partner relationship is assigned a risk rating (Low / Medium / High) at onboarding, recorded in NEO’s systems, and refreshed on trigger events or at periodic review.
5. Customer and Partner Due Diligence (KYC / KYB)
5.1 When due diligence is required
Before entering a commercial relationship or moving any funds, NEO performs due diligence on:
- Clients (companies purchasing EOR, COR, payroll or related services through NEO);
- EOR partners and other service partners onboarded to the NEO marketplace;
- Contractors engaged under COR arrangements through NEO Global Pty Ltd;
- Any other counterparty to whom NEO sends, or from whom NEO receives, funds.
5.2 Standard due diligence — entities (KYB)
- Full legal name, registration number, registered address and country of incorporation, verified against an official or reliable independent registry;
- Nature of business and purpose of the relationship;
- Identification of directors and of each beneficial owner holding 25% or more (or otherwise exercising control), with identity verification of beneficial owners on a risk basis;
- Screening of the entity, its directors and beneficial owners against sanctions, PEP and adverse-media lists (Section 6);
- For EOR partners: evidence of any required local licences/registrations (e.g. employment agency, PEO, umbrella or payroll licences), confirmation the partner operates its own AML/sanctions controls where relevant, and bank account ownership verification before first payment.
5.3 Standard due diligence — individuals (KYC)
- Full name, date of birth and residential address, verified against a government-issued photo ID and, on a risk basis, an independent data source or biometric/liveness check;
- Bank account details verified as belonging to the individual before first payout (COR contractors);
- Sanctions and PEP screening.
5.4 Enhanced due diligence (EDD)
EDD applies where risk is High, including: PEP involvement; FATF high-risk or DFAT/OFAC-sanctioned jurisdictions touched by the relationship or funds flow; complex or opaque ownership (nominees, bearer arrangements, multi-layer offshore structures); adverse media indicating financial crime; unusual payment instructions; or any relationship the AMLCO designates. EDD includes senior management (AMLCO) approval, source-of-funds/source-of-wealth inquiries where warranted, additional verification of beneficial owners, and more frequent review.
5.5 Refusal and exit
NEO will not onboard, and will exit, any relationship where: identity or ownership cannot be satisfactorily established; the counterparty is subject to sanctions; the counterparty refuses to provide required information; or ML/TF risk cannot be mitigated to within NEO’s risk appetite. Exits involving suspicion must be coordinated with the AMLCO to avoid tipping off.
6. Sanctions and Watchlist Screening
- All clients, partners, COR contractors, their directors and beneficial owners, and payee bank accounts are screened at onboarding against, at minimum: the DFAT Consolidated List (Australia), UN Security Council lists, US OFAC SDN list, EU and UK sanctions lists;
- Counterparties are re-screened on an ongoing basis (at minimum when lists are updated by NEO’s screening provider, and at periodic review);
- NEO does not conduct business involving comprehensively sanctioned countries or regions, or with listed persons or entities owned or controlled by them;
- Potential matches are escalated to the AMLCO; funds and onboarding are frozen pending resolution. Confirmed matches are rejected/blocked and assessed for mandatory reporting obligations (e.g. to DFAT/AFP);
- Payment routing must not be structured to obscure the involvement of a sanctioned party or jurisdiction.
7. Payments, Deposits and Funds-Flow Controls
Because NEO invoices clients, logs and may hold client deposits, funds payroll and contractor payments, and converts currency through regulated providers, the following controls apply:
- Client funds are accepted only by bank transfer from an account in the name of the contracted client entity. Cash, cryptocurrency, and third-party payments (funds from an entity that is not the contracted client) are not accepted, absent documented AMLCO approval of a legitimate rationale (e.g. a disclosed group treasury entity);
- Outbound payments are made only to verified accounts in the name of the contracted partner, contractor or refund recipient. Requests to redirect payments to new or third-party accounts require call-back verification to a known contact and are treated as fraud red flags;
- Refunds and deposit returns are made to the originating account wherever possible; early-termination refunds shortly after funding are reviewed for potential layering;
- FX conversion and cross-border settlement are executed only through regulated, licensed payment institutions (e.g. NEO’s approved providers such as Corpay and Airwallex) which apply their own AML/CTF controls; NEO cooperates fully with their compliance inquiries;
- Invoicing follows NEO’s agent/net-revenue model with amounts reconciled to underlying employment or engagement records — payments must correspond to genuine, documented work arrangements;
- Over-payments, round-dollar structuring, rapid in-and-out movements and payments materially inconsistent with the client’s profile are escalated.
8. Ongoing Monitoring
- Transaction activity is monitored against the customer’s expected profile (headcount, markets, invoice values, payment patterns);
- Periodic KYC/KYB refresh: High risk — at least annually; Medium — every 2 years; Low — every 3 years, and always on trigger events (change of ownership or control, new high-risk market, adverse media, unusual instructions);
- Partner reviews additionally cover continued licensing, solvency indicators relevant to deposit protection, and complaints or incidents raised by clients or workers.
9. Red Flags
Personnel must escalate to the AMLCO, without alerting the counterparty, on indicators including:
- Reluctance to provide KYC/KYB information, use of nominees, or ownership structures with no commercial rationale;
- Requests to pay or be paid via unrelated third parties, personal accounts for corporate obligations, or accounts in unrelated jurisdictions;
- “Employees” or contractors who cannot be verified, do not appear to perform genuine work, or whose roles are inconsistent with the client’s business (potential ghost-employee laundering or visa fraud);
- Salaries or contractor rates grossly inconsistent with the role or market;
- Funding significantly in excess of invoiced amounts, followed by refund requests;
- Urgent pressure to bypass onboarding, verification or payment controls;
- Connections to sanctioned or high-risk jurisdictions that were not disclosed at onboarding;
- Adverse media alleging fraud, corruption, sanctions evasion or money laundering.
10. Reporting
10.1 Internal reporting
Any Person who knows or suspects ML/TF, sanctions breaches or related financial crime must report promptly to the AMLCO. Reports are handled confidentially; no Person will suffer retaliation for a good-faith report.
10.2 External reporting
Where NEO is (or becomes) a reporting entity under the AML/CTF Act, the AMLCO ensures NEO enrols with AUSTRAC and files required reports within statutory timeframes, including Suspicious Matter Reports (SMRs), threshold transaction reports and international funds transfer instruction reports as applicable. Irrespective of reporting-entity status, the AMLCO assesses whether suspected criminal conduct must or should be reported to AUSTRAC, the Australian Federal Police, DFAT (sanctions) or foreign authorities, taking legal advice as needed.
10.3 Tipping off
Personnel must never disclose to a customer, partner, worker or any third party that a suspicion has been formed, a report made or is contemplated, or an investigation is underway. Tipping off is a criminal offence.
11. Record Keeping
NEO retains, in retrievable form and in accordance with applicable privacy law: identification and verification records, screening results and match resolutions, risk assessments and ratings, transaction and settlement records, internal escalations and reporting decisions, and training records — for at least seven (7) years after the end of the relationship or the date of the transaction, whichever is later.
12. Training
All Personnel receive AML/CTF and sanctions awareness training at induction and at least annually thereafter. Personnel in onboarding, payments, finance and partner-management roles receive role-specific training covering KYC/KYB procedures, screening, red flags and escalation. Completion is recorded.
13. Reliance on Third Parties and White-Label Arrangements
EOR partners perform local employment onboarding and may perform elements of identity verification on workers. NEO may take such work into account but remains responsible for its own risk assessment of the relationships it onboards and the funds it moves. Where NEO provides white-label infrastructure to staffing agencies, MSPs or EOR providers, contractual terms must allocate AML/CTF, KYC and sanctions responsibilities explicitly, and NEO must satisfy itself that the partner’s controls are adequate for the reliance placed on them. Background-check and screening vendors are themselves subject to vendor due diligence.
14. Policy Review, Exceptions and Independent Evaluation
- This Policy is reviewed at least annually by the AMLCO and re-approved by the Board on material change;
- Exceptions require written AMLCO approval, a documented rationale and compensating controls, and are logged and reported to the Board;
- The AML/CTF program is subject to periodic independent evaluation (internal audit or external reviewer) proportionate to NEO’s size and risk, and in any event as required by law if NEO is a reporting entity.
15. Related Documents
Enterprise ML/TF Risk Assessment
Partner Onboarding & Vetting Procedure (KYC/KYB)
Client Onboarding Procedure
Sanctions Screening Procedure
Payments & Treasury Procedure (including call-back verification)
Anti-Bribery & Corruption Policy
Whistleblower Policy
Data Protection & Privacy Policy