Trust Centre

Anti-Money Laundering

Upstream BPO maintains a standalone anti-money laundering policy. We conduct customer due diligence at contract onboarding and screen customers, vendors and staff against applicable sanctions lists and for politically exposed persons.

Key information

At-a-glance governance context

These points summarise the public scope of this page and the main contact or review context around it.

Customer due diligence

Conducted at contract onboarding

Screening

Sanctions and politically exposed persons

Screened parties

Customers, vendors and staff

Policy enquiries

dpo@upstreambpo.com

Section 1

Customer due diligence

Upstream BPO conducts know-your-customer due diligence at contract onboarding. Due diligence is completed before the engagement starts rather than during delivery.

Section 2

Sanctions and PEP screening

We screen customers, vendors and staff against the applicable sanctions lists across our operating jurisdictions. We also screen for politically exposed persons.

Vendor screening connects to subprocessor onboarding: a vendor that fails screening does not enter the subprocessor set, and screening is part of the assessment we run before a subprocessor is engaged.

Section 3

Suspicious activity reporting

Suspicious transactions and suspicious activity follow a defined escalation to our compliance function. Where applicable law requires a report to regulators, we make that report.

The escalation path is documented, so that a member of staff who identifies suspicious activity follows a defined route rather than exercising individual judgement about who to tell.

Section 4

Training

Anti-money laundering training runs at onboarding and annually thereafter, and completion is tracked. The cadence and tracking mirror our anti-bribery training.

During 2025, 100% of Upstream BPO employees completed anti-money laundering training.

Section 5

Policy availability

Our anti-money laundering policy is a contract-level document. We provide it on request under NDA rather than publishing it here.

Reviewer questions

Questions we are asked in security review

Answers are stated in full here so they are quotable directly into a security questionnaire.

Do you perform KYC on customers?

Yes. Upstream BPO conducts customer due diligence at contract onboarding, before the engagement starts.

Who do you screen against sanctions lists?

Customers, vendors and staff, against the applicable sanctions lists across our operating jurisdictions. We also screen for politically exposed persons.

What happens when suspicious activity is identified?

It follows a defined escalation to our compliance function. Where applicable law requires a report to regulators, we make that report.

Can we review your AML policy?

Yes. The AML policy is a contract-level document provided on request under NDA. Request it from dpo@upstreambpo.com.

Contact & Escalation

Anti-money laundering policy enquiries and NDA-gated policy requests route to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.

Next Step

Need a deeper governance review?

Send certificate requests, subprocessor list requests, incident reports and vulnerability disclosures to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.