BACK

TCI Financial Controls, Fraud & Cash-Handling Policy

Version 1.0 · Last Updated:

1. Purpose

This policy establishes the Group's control framework for money, purchasing, expenses, approvals, payment security, fraud prevention, cash handling, reconciliation, refunds, and financial incident escalation in or connected with Turks and Caicos Islands operations.

The purpose is to protect business funds, customer funds, suppliers, employees, assets, tax compliance, customs compliance, payment channels, and reputation while allowing practical local trading where it is properly authorised.

This policy does not publish internal financial limits, bank details, payment credentials, cash storage arrangements, alarm details, insurer values, or named approval holders. Those controls must remain in controlled internal documents.

2. Scope

This policy applies to Murzo Group Ltd and all subsidiaries, controlled entities, divisions, brands, branches, projects, premises, platforms, accounts, and operations carrying on business in or from the Turks and Caicos Islands.

It applies to directors, officers, employees, temporary personnel, contractors, consultants, agents, local representatives, authorised signatories, finance users, purchasing users, cash handlers, marketplace users, and any person handling money, assets, commitments, invoices, refunds, expenses, or payment information on behalf of the Group.

It covers TCI premises, online sales, marketplace activity, property activity, hospitality or tourism activity, food and farming activity, security activity, imports and exports, high-value goods, cultural property, events, fieldwork, remote work, customer sites, ports, airports, warehouses, vehicles, vessels, and third-party fulfilment channels.

3. TCI Legal and Regulatory Context

TCI operations may involve local business licensing, Financial Services Commission requirements, sector permissions, local tax or revenue registration, customs duties, import fees, insurance obligations, payment provider rules, sanctions controls, anti-money laundering obligations, and suspicious activity reporting where the activity falls within a regulated or supervised sector.

Activities involving real estate, high-value goods, company services, legal or accounting support, money transmission, financial services, insurance, cultural objects, luxury goods, cash-intensive trading, cryptoassets, or unusual customer funding may require enhanced checks before funds are accepted or released.

TCI local law applies to local conduct. UK duties, contractual obligations, bank requirements, platform rules, insurer terms, and Group governance may also apply where they have lawful cross-border effect.

4. Core Financial Control Principles

  • Only authorised people may commit, receive, spend, transfer, refund, reconcile, or write off money
  • Financial duties should be separated where practicable, especially approval, payment, receipt, and reconciliation
  • Purchases and payments must have a genuine business purpose and clear authority
  • Cash, cards, bank accounts, wallets, platforms, and payment tools must not be used for personal purposes
  • False invoices, side payments, kickbacks, hidden commissions, personal bank routing, and off-book activity are prohibited
  • Payment changes, new suppliers, emergency payments, refunds, chargebacks, cash variances, and unusual transactions require extra scrutiny
  • Financial controls must remain proportionate to the risk, value, urgency, location, and legal duties involved

5. Authority, Approvals and Delegations

The Group must maintain an internal authority matrix for TCI financial decisions. The matrix should set out who may approve purchases, contracts, expenses, refunds, discounts, write-offs, emergency spend, supplier onboarding, bank changes, payment provider changes, payroll actions, petty cash, cash float changes, asset disposal, insurance claims, and regulator payments.

Approval must be given by a person with sufficient authority, independence, and knowledge of the transaction. A person must not approve their own expenses, their own supplier, their own refund, their own cash variance, or a transaction in which they have a personal interest unless a higher authorised person has considered the conflict.

Financial commitments must not be split into smaller parts to avoid approval thresholds. Retrospective approval should be exceptional and should not be used to normalise poor control.

6. Segregation of Duties

Where practicable, no single person should control the full lifecycle of a financial transaction from request to approval, payment, receipt, and reconciliation.

Small-site or emergency conditions may make perfect separation impractical. Where that occurs, the Group should use compensating controls such as independent review, two-person cash counts, supervisor checks, payment alerts, access restrictions, supporting evidence, or post-event reconciliation.

7. Purchasing and Procurement

Purchases must be necessary, reasonable, connected to approved activity, and made through approved suppliers or authorised local purchasing routes where practicable.

Before committing to a supplier or purchase, the responsible person should consider licence status, competence, insurance, conflicts of interest, price reasonableness, delivery terms, tax and customs impact, sanctions risk, payment method, product safety, warranty, return terms, and whether the supplier is acting as an agent, broker, reseller, or direct provider.

Unauthorised verbal commitments, informal WhatsApp orders, personal-card purchasing, cash deposits, purchase splitting, inflated invoices, duplicate invoices, pressure payments, fake urgency, and undisclosed commissions are prohibited unless a genuinely urgent and approved exception applies.

8. Supplier Onboarding and Changes

New suppliers, material supplier changes, bank detail changes, payee name changes, unusual payment routes, cash requests, foreign accounts, crypto payment requests, agent commissions, and urgent payment requests must be checked before funds are sent.

Bank or payment detail changes must be verified through a trusted route that does not rely solely on the email, invoice, text message, or call requesting the change. Business email compromise, invoice redirection, impersonation, and fake supplier notices are material TCI payment risks.

A supplier must not be used to disguise an employee expense, related-party benefit, political payment, facilitation payment, bribe, unlicensed service, immigration breach, customs breach, or sanctionable transaction.

9. Expenses and Reimbursements

Expenses must be for a genuine business purpose, properly authorised, reasonable in value, and supported by proportionate evidence such as receipts, booking confirmations, travel details, business purpose, attendee details, or manager approval.

The Group may reject or reduce claims that are personal, excessive, unsupported, late, duplicated, inflated, outside policy, created to obtain cash, or connected to unlawful conduct.

Expenses must not be used for bribes, facilitation payments, political donations, hidden entertainment, personal gifts, fines, penalties, unauthorised alcohol or hospitality, personal travel, family expenses, work-permit circumvention, or private accommodation unless expressly approved and lawful.

10. Cards, Bank Accounts and Payment Tools

Company cards, bank accounts, merchant accounts, payment terminals, online banking, e-wallets, platform payment tools, marketplace payment accounts, crypto wallets, and refund tools may only be used by authorised users for approved business purposes.

Access must be based on role need, protected by strong authentication where available, and removed or changed promptly when a person leaves, changes role, loses authority, or becomes part of a financial investigation.

Personal bank accounts, personal payment links, personal card readers, private wallets, private marketplace accounts, or unapproved payment processors must not be used to receive customer money or pay suppliers on behalf of the Group.

11. Payment Security

Payment security controls must address phishing, invoice fraud, card misuse, account takeover, malware, device theft, remote access fraud, refund abuse, fake chargeback requests, QR-code scams, payment terminal tampering, and unauthorised changes to platform payout details.

No person may share passwords, reuse finance credentials, bypass multi-factor authentication, store card data outside approved systems, send payment credentials by insecure messages, approve payments on unknown devices, or ignore warning signs because a request appears urgent.

Cardholder data must be handled through approved payment processors and in line with payment provider and applicable PCI DSS requirements. The Group should avoid storing full card numbers, security codes, or unnecessary payment data.

12. Cash Acceptance

Cash may only be accepted where the activity, value, location, customer type, and legal risk make cash acceptance appropriate and the internal cash control requirements are met.

Cash-heavy trading, large cash payments, repeated small cash payments, third-party cash payments, foreign currency cash, unusual overpayments, cash refunds, anonymous customer requests, and payments inconsistent with the customer's profile must be escalated where they create fraud, AML, tax, safety, or sanctions risk.

The Group may refuse cash where it creates unreasonable risk, cannot be reconciled safely, breaches a platform or contract rule, appears connected to crime, cannot be supported by a lawful transaction, or would require the Company to hold unsafe levels of cash.

13. Cash Handling Rules

Cash must be received, counted, stored, transported, deposited, and reconciled only by authorised persons and only through approved procedures. Cash must be kept separate from personal funds and must not be used for personal borrowing, IOUs, informal loans, wage advances, private change-making, or side purchases.

Where practicable, cash counts should be witnessed by a second authorised person. Cash must be secured promptly and not left unattended, visible to the public, accessible to unauthorised persons, or carried unnecessarily.

Cash shortages must not be hidden, personally replaced without escalation, deducted from wages without lawful authority, or treated as proof of misconduct without a fair process.

14. Petty Cash and Cash Floats

Petty cash and cash floats may only be used where approved for the relevant site or activity. Float levels, storage points, authorised users, and replenishment arrangements must be kept in controlled internal documents.

Petty cash must not be used to avoid purchasing controls, split expenditure, pay wages, pay unapproved contractors, make political or charitable payments, settle personal expenses, pay cash commissions, or make payments that should go through payroll, banking, or approved procurement channels.

15. Cash Reconciliation

Cash takings, floats, deposits, receipts, refunds, voids, discounts, tips or service charges where applicable, and variances must be reconciled at an interval proportionate to the site, activity, and risk.

Reconciliation should compare expected cash against actual cash, receipt evidence, point-of-sale reports, manual logs, deposit evidence, platform reports, refund entries, and approved variances where relevant.

Unexplained shortages, overages, repeated small variances, missing receipts, altered receipts, delayed deposits, unapproved voids, unusual discounts, cash refunds, or refusal to cooperate with reconciliation must be escalated.

16. Refunds, Chargebacks, Discounts and Write-Offs

Refunds, chargeback responses, customer credits, goodwill credits, compensation, discounts, voids, write-offs, and cancellation credits must be authorised and supported by the underlying customer, platform, contract, or legal position.

Refunds should normally be returned to the original payment method where practicable and lawful. Cash refunds for non-cash payments, refunds to third parties, refund splitting, refund inflation, and refunds to personal accounts require enhanced approval.

Where a marketplace, third-party seller, producer, fulfilment partner, card provider, or booking platform is responsible for returns or refunds, the Group should not voluntarily assume liability unless authorised in writing.

17. Sales, Invoicing and Revenue Integrity

Sales, invoices, receipts, customer deposits, marketplace reports, booking reports, commission statements, agent statements, and platform payouts must reflect the real transaction, correct entity, correct customer, correct product or service, correct location, correct taxes or duties where applicable, and correct payment route.

Side invoices, false descriptions, under-invoicing, over-invoicing, undeclared discounts, hidden commissions, off-platform sales, unauthorised cash deals, and invoice descriptions designed to avoid tax, customs, sanctions, product controls, or licensing requirements are prohibited.

18. TCI Taxes, Revenue Streams and Customs Payments

TCI operations may involve business licence fees, hotel and tourism tax, vehicle hire stamp duty, domestic financial services sales tax, insurance premium sales tax, telecommunications tax, seaport or customs-related charges, import duties, concessions, exemptions, and other local revenue obligations depending on the activity.

Pricing, invoicing, receipts, marketplace arrangements, refunds, customs declarations, and customer terms must be structured so that applicable TCI taxes, duties, fees, and remittances can be handled accurately.

Goods imported into TCI must be properly classified, declared, supported by required permits where applicable, and released only after duties, taxes, and customs requirements have been satisfied.

19. Payroll, Wages, Tips and Deductions

Payroll, wages, overtime, holiday pay, tips, service charges, allowances, expenses, advances, deductions, restitution, and termination payments must be handled lawfully and consistently with the TCI Employment and Workplace Policy.

No unauthorised deduction, fine, penalty, cash shortage charge, equipment charge, uniform charge, damage charge, or restitution arrangement may be imposed merely because a manager believes money is owed. Any deduction must be lawful, supported, proportionate, and authorised.

20. Fraud, Theft and Economic Crime Red Flags

Red flags include duplicate invoices, altered bank details, urgent payment pressure, supplier refusal to provide basic details, excessive cash requests, repeated missing receipts, unusual refund patterns, unauthorised discounts, unexplained cash variances, related-party suppliers, personal bank accounts, fake customs charges, fake regulator demands, impersonation of directors, suspicious customer funding, unexplained wealth, and resistance to basic checks.

Other red flags include payments linked to politically exposed persons, sanctioned parties, high-risk jurisdictions, anonymous intermediaries, shell entities, real estate funds of unclear origin, high-value goods with unclear provenance, cultural objects with poor documentation, and customers who ask the Group to misdescribe goods or services.

21. Anti-Money Laundering and Sanctions Controls

Where the activity falls within a supervised or higher-risk category, the Group must apply appropriate customer, supplier, counterparty, source-of-funds, beneficial ownership, sanctions, and suspicious activity controls before accepting or releasing money.

Employees and representatives must not tip off a customer or third party where a suspicion has been escalated and tipping off would be unlawful. Suspicious activity should be handled through the appointed internal route and, where required, through the competent TCI reporting channel.

The Group may delay, reject, freeze, reverse, suspend, or escalate a transaction where necessary to comply with AML, sanctions, court order, law enforcement, regulator, bank, insurer, or platform requirements.

22. Cryptoassets, Foreign Currency and Non-Standard Payments

Cryptoasset payments, foreign currency payments, money transfer services, prepaid cards, vouchers, gift cards, informal value transfer, third-party payer arrangements, escrow arrangements, and unusual settlement methods require enhanced approval before use.

Non-standard payments must not be accepted to avoid sanctions, tax, customs duties, consumer protections, refunds, chargebacks, platform rules, source-of-funds checks, or payment provider requirements.

23. Financial Controls During Hurricanes and Disasters

During hurricanes, shutdowns, outages, emergency accommodation, fuel shortages, transport disruption, port closures, cyber disruption, or other emergencies, designated management may approve proportionate emergency spend needed to protect life, welfare, property, continuity, product safety, data, environmental protection, or lawful reopening.

Emergency conditions do not permit fraud, bribery, price manipulation, fake invoices, unsupported claims, unauthorised cash withdrawals, personal enrichment, hidden commissions, or unsafe cash storage. Exceptions should be reconciled and reviewed once normal controls resume.

24. Third Parties, Agents and Platforms

Agents, brokers, landlords, property managers, customs brokers, marketplace operators, fulfilment providers, payment processors, contractors, distributors, and local representatives may only handle money, commitments, refunds, or customer charges where their authority is clear.

A third party must not collect cash, change bank details, accept customer deposits, approve refunds, offer discounts, commit the Group to a purchase, or represent that it has financial authority unless this has been approved in writing.

Where a third-party platform controls customer payment, fulfilment, refund, or chargeback processes, the Group should follow the platform allocation of responsibility unless a separate written agreement states otherwise.

25. Reporting, Investigation and Evidence Preservation

Suspected fraud, theft, corruption, cash loss, payment fraud, supplier fraud, customer fraud, cyber payment compromise, invoice redirection, unauthorised bank change, material cash variance, or suspicious transaction must be reported promptly through the internal escalation route.

Relevant evidence should be preserved proportionately, including invoices, receipts, cash count sheets, payment confirmations, emails, system logs, CCTV, device records, refund entries, delivery evidence, supplier messages, and banking alerts where available and lawful.

The Group may restrict access, suspend payment authority, contact banks or payment providers, notify insurers, seek legal advice, report to TCI authorities, recover funds, discipline employees, terminate contracts, or take civil or criminal action where appropriate.

26. Confidentiality and Non-Retaliation

Financial investigations must be handled discreetly and only shared with people who need to know. No person may destroy evidence, warn a suspect improperly, interfere with witnesses, pressure a cash handler, or retaliate against a person who reports a concern in good faith.

Making a deliberately false allegation, concealing a known issue, or obstructing an investigation may itself be treated as misconduct or a contractual breach.

27. Accountability

Failure to comply with this policy may result in removal of financial authority, system access restriction, refused reimbursement, contract remedies, disciplinary action, recovery action, insurer notification, regulator notification, law enforcement referral, or other lawful action.

Managers are responsible for making sure TCI financial controls are practical for the operation they supervise and that higher-risk activity is escalated before money moves.

28. Relationship With Other Policies

This policy should be read with the TCI Legal and Regulatory Compliance Policy, TCI Business Licensing and Corporate Compliance Procedure, TCI Employment and Workplace Policy, TCI Hurricane, Disaster and Business Continuity Policy, Fraud Prevention and Economic Crime Policy, Anti-Bribery and Corruption Policy, High-Value Goods, Anti-Money Laundering and Source of Funds Policy, Tax Governance and Compliance Policy, Failure to Prevent Facilitation of Tax Evasion Policy, Contract Approval, Signing Authority and Delegations Policy, Supplier Approval, Procurement and Due Diligence Policy, Customs Import/Export Policy, Cybersecurity and Data Breach Policy, Records Retention Policy, Returns, Refunds and Distance Selling Policy, and Insurance and Liability Disclosure Statement.

Detailed approval limits, cash thresholds, bank details, key contacts, security arrangements, system permissions, and payment credentials must remain in controlled internal documents.

Murzo Group signature