Anti-Money Laundering and Counter-Terrorist Financing Policy (AML/CTF)

Version 1.0In force since 2026-08-05

How jogodobicho identifies its bettors, monitors transactions, reports whatever is atypical to COAF and retains records, in compliance with Lei nº 9.613/1998 and Portaria SPA/MF nº 1.143/2024.

Some company details have not been provided yet and appear as “to be provided”. None were assumed: a made-up tax ID would be worse than a missing one.

1. Purpose, scope and who is bound

This Policy sets out the controls that [to be provided], registered with CNPJ nº [to be provided], with its seat at [to be provided], authorised by the Secretaria de Prêmios e Apostas of the Ministério da Fazenda (SPA/MF) under authorisation [to be provided] and operator of the jogodobicho brand on the jogodobicho.com domain, adopts in order to prevent its platforms from being used for money laundering, for concealing assets of unlawful origin or for terrorist financing.

This Policy binds all directors, employees, interns, service providers and commercial partners acting on behalf of the operator, including game suppliers, payment providers and affiliates. Breach of this Policy is serious misconduct and gives rise to the applicable disciplinary and contractual measures, without prejudice to statutory penalties.

It applies to every business relationship with economic value: opening and maintaining a bettor account, deposits, bets, prizes, withdrawals, bonuses and any movement of funds. Access to demonstration mode, in which play involves no financial contribution, no cash prize and no account movement, does not constitute a business relationship for these purposes and is therefore offered without prior registration.

Betting with real money, by contrast, requires an own account, opened in the name of the bettor and with identity verified as set out in section 6. There is no bet involving a financial contribution on an unverified account, nor in the name of a third party.

Legal basis: Lei nº 14.790/2023, art. 2º, I e VIII · Lei nº 9.613/1998, art. 9º · Portaria SPA/MF nº 1.143/2024

2. Applicable legal framework

This Policy gives effect to, among others, the following rules, which must be read together with it:

Legal basis: Lei nº 9.613/1998 · Lei nº 14.790/2023 · Portaria SPA/MF nº 1.143/2024

3. Governance and the officer designated before COAF

The operator maintains a prevention structure with formally assigned responsibility. Management approves this Policy, provides the function with resources, staff and unrestricted access to systems and information, and answers for its effectiveness.

An officer is designated before COAF and SPA/MF, whose name and credentials are reported to those bodies and kept up to date. That officer is responsible for compliance with this Policy, for the decision to report transactions, for the relationship with the authorities and for submitting periodic reports to management.

The designated officer acts independently: the role does not report to the commercial, marketing or customer acquisition functions, and its remuneration is not tied to the volume of deposits, of bets or of revenue. No business function may overturn a decision by that officer to report, to restrict or to close an account.

Questions, whistleblowing reports and internal communications concerning this Policy are received at [to be provided]. The channel accepts anonymous reports, and any retaliation against a person reporting in good faith is prohibited.

Legal basis: Lei nº 9.613/1998, art. 10, III · Portaria SPA/MF nº 1.143/2024

4. Internal risk assessment

The operator prepares and maintains a documented internal risk assessment, which identifies, measures and classifies the money laundering and terrorist financing risks to which its activity is exposed, and which describes the controls that mitigate them.

The assessment considers, as a minimum: the profile of bettors and their geographic distribution; the products, modalities and channels offered; the payment methods accepted; the volumes and velocity of transactions; reliance on third parties, such as game suppliers, payment providers and affiliates; and the typologies published by COAF, by SPA/MF and by international bodies.

Each identified risk receives a classification and an action plan, with an owner and a deadline. Residual risks that management decides to accept are recorded in writing, together with the reasoning.

The assessment is reviewed at least once a year and whenever there is a material change, such as a new product or modality, a new payment method, a new market, a regulatory change or an incident. Its conclusions feed the monitoring rules in section 9 and the training programme in section 15.

Legal basis: Portaria SPA/MF nº 1.143/2024 · Lei nº 9.613/1998, art. 10, III

5. Risk-based approach: customer classification

Controls are proportionate to risk. Every bettor receives, on account opening, a risk classification, which is reassessed periodically and whenever their behaviour changes materially.

The classification considers, among others, the following factors:

There are three bands: low, medium and high risk. High risk entails enhanced due diligence, as set out in section 7, approval by the designated officer to enter into or maintain the relationship, and monitoring at shorter intervals. The classification is recorded and versioned; no reclassification is made without a record of who made it, when and why.

Legal basis: Portaria SPA/MF nº 1.143/2024 · Lei nº 9.613/1998, art. 10, I e III

6. Know your customer: identification and verification

No anonymous account is opened, nor any account under a fictitious name or in the name of a third party. Registration is individual, non-transferable and linked to a single CPF.

The following are collected and kept up to date, as a minimum: full name, nationality, CPF, date of birth, gender, full address, country of domicile, telephone, email address, payment accounts held by the bettor and the prudential limits chosen. The IP address and the date and time of registration are also recorded.

Before any deposit or real-money bet, identity is verified: validation of the CPF against official databases, verification of a photographic identity document and facial recognition with liveness proof. Only persons who are at least 18 years of age are accepted.

Applicable restrictive and sanctions lists are screened at registration and periodically thereafter, including those arising from United Nations Security Council resolutions, as well as the lists of persons barred from betting under the legislation. Where a match against a sanctions list is confirmed, the relationship is not entered into, assets are frozen as required by law and the matter is reported to the competent authorities.

Registration data is kept up to date throughout the relationship. Data changes are versioned with date, time and IP address, and sensitive changes, such as payment account, ownership or address, may require fresh verification.

Demonstration mode, because it involves neither a financial contribution nor a cash prize, is accessible without registration. It opens no account, moves no funds and is not treated as a business relationship for the purposes of this Policy.

Legal basis: Lei nº 9.613/1998, art. 10, I · Lei nº 14.790/2023, arts. 23 a 25 · Portaria SPA/MF nº 1.231/2024, arts. 31 e 32 · Lei nº 13.810/2019

7. Enhanced due diligence: politically exposed persons, high value and restrictive lists

Certain situations call for more than ordinary due diligence. Enhanced due diligence applies, as a minimum, to the following cases:

Enhanced due diligence comprises: approval of the entry into or continuation of the relationship by the designated officer or by a higher instance; collection and documentary evidence of the source of funds and of wealth; searches of public sources and adverse media; and monitoring at shorter intervals, with review of the risk classification on shorter cycles.

Being a politically exposed person does not, in itself, bar the relationship: it subjects the relationship to stricter control. What does bar it is refusal to provide the required information, provision of false information or the impossibility of completing verification.

Legal basis: Lei nº 9.613/1998, art. 10, I e III · Portaria SPA/MF nº 1.143/2024

8. Source of funds and ownership of payment methods

Deposits and withdrawals pass only through institutions authorised to operate by the Banco Central do Brasil and through payment accounts held by the bettor, with the CPF match verified. Funds received from a third-party account are returned to source, and the fact is recorded and analysed.

Prizes and balances are paid solely into an account held by the bettor, never to a third party, even at the request of the bettor.

Cash, crypto-assets, credit cards and boleto are not accepted for funding, in accordance with the sector regulations.

Balance transfers between bettor accounts are prohibited. A bettor account is not a payment instrument, is not an investment account and may not be used as custody for funds: amounts deposited are intended for betting.

Legal basis: Lei nº 14.790/2023 · Portaria SPA/MF nº 1.143/2024 · Normas da SPA/MF sobre meios de pagamento e movimentação de recursos · Lei nº 9.613/1998, art. 10, II

9. Ongoing transaction monitoring

All transactions are monitored on an ongoing and automated basis, throughout the relationship and not only at registration. Monitoring correlates account, payment, betting, prize, device, IP address and behavioural data.

Alert rules derive from the internal risk assessment and combine value, frequency and pattern parameters. They are reviewed periodically for effectiveness: a rule that produces only unproductive alerts is adjusted, and each newly identified typology gives rise to a new rule.

Alerts are routed to a human analysis queue, with handling deadlines and a record of who analysed them, when and with what conclusion. No alert is closed without a record of its reasoning.

Monitoring also interacts with responsible gambling controls: indicators of risky behaviour and indicators of possible laundering can coexist on the same account and are handled by both functions, neither analysis dispensing with the other.

Legal basis: Lei nº 9.613/1998, arts. 10 e 11, I · Portaria SPA/MF nº 1.143/2024 · Portaria SPA/MF nº 1.231/2024

10. Red flags specific to the sector

The indicators below do not prove wrongdoing: they trigger analysis. It is the absence of a reasonable explanation, and not the indicator itself, that leads to a report.

The list is illustrative and is updated in line with the typologies published by COAF and by SPA/MF and in line with the experience of the monitoring function itself.

Legal basis: Lei nº 9.613/1998, art. 11, I · Portaria SPA/MF nº 1.143/2024

11. Internal analysis, decision and measures on the account

Every alert is analysed by a trained professional, who gathers the account history, the related transactions, the available documents and, where relevant, additional information requested from the bettor. The analysis is recorded with reasoning, even where the conclusion is to close the case.

Where no explanation dispels the suspicion, the case is escalated to the designated officer, to whom the decision to report to COAF belongs. That decision does not depend on certainty that an offence has occurred and is not replaced by a commercial measure.

Irrespective of any report, the operator may adopt, proportionately: requests for supporting documentation; temporary suspension of withdrawals or of betting; restriction of payment methods; refusal of further deposits; and termination of the relationship.

Where a report is made, termination is not automatic: keeping the account under monitoring may be necessary so as not to frustrate the work of the authorities. That decision rests with the designated officer and is recorded.

Termination on the basis of this Policy does not affect the right of the bettor to withdraw a balance of demonstrably lawful origin, subject to any holds ordered by a competent authority.

Legal basis: Lei nº 9.613/1998, arts. 10 e 11 · Portaria SPA/MF nº 1.143/2024

12. Reporting to COAF through SISCOAF and the nil report

Reports are made to COAF through the Sistema de Controle de Atividades Financeiras (SISCOAF), within the period laid down by law and by sector regulation, counted from the conclusion of the analysis that established the suspicion, and in no case later than the following business day.

Reportable items are transactions and proposed transactions that may constitute an indication of money laundering or terrorist financing, as well as those that the regulations require to be reported by reason of their value or nature, irrespective of any suspicion analysis.

If, over the course of an entire calendar year, no transaction or proposal requiring a report has occurred, the operator submits a nil report, within the period and through the channel set by the regulations. Silence does not substitute for that declaration: reporting nothing and declaring that nothing occurred are distinct acts, and only the latter discharges the obligation.

The operator keeps itself registered, and its registration current, with COAF and SPA/MF, and provides the information and access that those authorities require, including through SIGAP.

Reports are made in good faith and, under the terms of the law, give rise to no civil or administrative liability for the operator, for its officers or for its employees.

Legal basis: Lei nº 9.613/1998, art. 10, IV · Lei nº 9.613/1998, art. 11, II e § 2º · Portaria SPA/MF nº 1.143/2024 · Portaria SPA/MF nº 722/2024 · Atos normativos do COAF

13. Prohibition on tipping off and duty of confidentiality

It is absolutely prohibited to disclose a report, or its imminence, to any person, including the bettor to whom it relates. The prohibition covers every form of tipping off: direct, indirect, by innuendo, by an unexplained change of conditions or by any conduct from which the existence of a report could be inferred.

Where it is necessary to request documents or explanations from the bettor, the request is made on the ordinary terms of the registration policy, with no mention whatsoever of a suspicion analysis, of a report or of the authorities.

Access to alerts, analyses and reports is restricted to those who need it to perform their role, is logged and is auditable. Breach of this section is serious misconduct and may constitute an administrative infringement and a criminal offence.

Legal basis: Lei nº 9.613/1998, art. 11, II · Lei nº 9.613/1998, art. 12

14. Record retention and immutability

Registration data, verification documents, transaction records, alerts, analyses, decisions and reports made to COAF are retained for a minimum period of five years. The period runs from the end of the business relationship or from the conclusion of the transaction, whichever is later, and is extended by order of a competent authority.

Records are kept complete, traceable and legible throughout the period, so as to allow the transaction and the analysis performed on it to be reconstructed. Audit records are append-only: corrections are made by a new entry that preserves the previous one, and no user, including an administrator, may delete or rewrite a record.

Data is transmitted to SPA/MF in the manner and at the intervals required and remains available for inspection at any time, in an environment that meets the information security requirements of the regulations.

Legal basis: Lei nº 9.613/1998, art. 10, II e III · Portaria SPA/MF nº 1.143/2024 · Portaria SPA/MF nº 722/2024

15. Training, staff integrity and independent audit

Everyone acting on behalf of the operator receives AML/CTF training on joining and, as a minimum, once a year, with content proportionate to their role. The training covers the legal framework, the red flags of the sector, the internal reporting procedure and the prohibition on tipping off.

Attendance and results are recorded and form part of performance review. Those working in customer support, in payments, in fraud prevention and in compliance receive specific and in-depth training.

The integrity of candidates and the suitability of their profile for the role are verified at hiring and periodically for sensitive roles, subject to employment and data protection law.

The effectiveness of the controls is assessed by an audit independent of the function responsible for operating them, at least annually. Deficiencies identified give rise to an action plan, with an owner and a deadline, and its follow-up is reported to management.

Legal basis: Lei nº 9.613/1998, art. 10, III · Portaria SPA/MF nº 1.143/2024

16. Personal data protection, effect, review and contact

The processing of personal data described in this Policy is carried out to comply with a legal and regulatory obligation to which the operator is subject. For that reason it does not depend on consent, and the data subject may neither object to it nor obtain erasure of the data while the statutory retention period runs.

Data collected for AML/CTF purposes is not used for commercial, advertising or marketing profiling purposes, and access to it is restricted to those who need it. Further information on data processing, data subject rights and periods is set out in the Privacy Policy.

This Policy is reviewed at least once a year and whenever there is a material regulatory change, a change in the risk profile or a recommendation from an audit or an authority. The version in force, with its effective date, is always published at jogodobicho.com.

Contacts: anti-money-laundering matters, [to be provided]; personal data protection and data protection officer, [to be provided]; complaints not resolved by customer support, ouvidoria, [to be provided].

Legal basis: Lei nº 13.709/2018, arts. 7º, II, 11, II, e 16, I · Lei nº 9.613/1998, art. 10, II · Portaria SPA/MF nº 1.231/2024

All legal documents