Risk Appetite Statement

From: 7/1/2026

Digital Assets d.o.o. (hereinafter: the “Company”), as an authorized provider of services related to crypto assets, hereby publishes this Risk Appetite Statement (hereinafter: the “Statement”) for the purpose of ensuring responsible business conduct, client protection, the stability of its business model, and compliance with applicable regulatory requirements.

The Company maintains a moderate risk appetite, in line with the dynamic developments of the crypto-asset market, while strictly adhering to the principles of risk management and internal controls. The Company is prepared to accept the risks necessary for developing innovative products and services, while actively limiting exposure to unacceptable and uncontrolled risks.

The Company is committed to preventing and mitigating financial crime, in accordance with applicable regulatory requirements and its own high internal standards.

The Company may choose not to support all client activities or transactions, even in cases where such activities are not locally prohibited or subject to restrictions under applicable laws and regulations.

This Statement defines:

  • the levels and types of risks that the Company is willing to accept during its ordinary business operations;
  • the framework for assessing and determining the acceptability of risks associated with crypto-asset exchange, custody, and transaction services;
  • the Company’s obligations to inform clients of identified risks and
  • the basis for the internal risk management system and compliance with regulatory obligations.

Trading in crypto-assets is considered a high-risk activity. Due to significant price volatility, there is a possibility of partial or total loss of invested funds:

  • Crypto-assets are not backed or guaranteed by any central bank or government deposit insurance scheme. Clients are not entitled to statutory compensation in the event of market instability, the insolvency of the Company, or the insolvency of any third-party service provider.
  • Client and Company assets are exposed to information security risks, including cyberattacks, software errors, technical failures, and the risk of permanent loss of access to private keys.
  • The client accepts the risks associated with engaging with third parties; irresponsible conduct by the Company or any external service provider may result in permanent and irreversible loss of funds.

Prior to using the Company’s services, each client must independently assess and carefully analyse their investment objectives and risk tolerance, acknowledging that this risk statement cannot cover all potential risks. The client is responsible for the final assessment of whether exposure to such risks is acceptable considering their individual circumstances and the possibility of a complete loss of funds.

Risk acceptance policy

Considering the nature of its activities, the Company adopts the following risk acceptance principles:

  • The Company accepts a high level of market volatility risk and the possibility of loss of funds as an inherent part of providing services related to crypto-assets.
  • A strict minimal tolerance applies to security, technological, and cyber risks. Efforts in IT security, infrastructure, and asset protection procedures are of critical importance; any failure in this area is considered unacceptable.
  • The Company’s operations are based on financial stability, with the continuous maintenance of a high level of liquidity and capital reserves. The Company’s strategy includes strict asset diversification and the limitation of exposure to external service providers, while ensuring the stability of its own capital.
  • The Company operates in full compliance with applicable legislation, including the implementation of anti-money laundering and counter-terrorist financing measures, as well as the protection of client rights. Any approach that undermines regulatory standards or the integrity of the financial system is considered unacceptable.

Fraud risk appetite

Any unlawful act by a client, employee, or third-party involving deception for personal gain and related to the Company’s services shall be considered fraud. Examples include, but are not limited to, bribery, forgery of documents or currency, misuse of insider or confidential information, theft, computer fraud, and the use of accounts for illegal activities.

The Company shall not carry out activities or approve transactions where it knows, suspects, or has reasonable grounds to suspect that such activities or transactions are associated with fraud. Based on complaints received and the analysis of suspicious transactions, the Company may perform additional checks, request further information or documentation, and reject transactions.

Risk appetite for money laundering and financing of terrorism

In accordance with client due diligence procedures, the Company shall periodically collect and update information regarding the nature of the client’s business, the source of funds, and the client’s activities and transactions.

The Company is required to establish a clear purpose and intended nature of the business relationship. Pending the completion of additional verification of information and documentation, the Company reserves the right to refuse to establish a business relationship, restrict the provision of services, or block client transactions.

The Company shall refrain from executing any transaction that it knows, suspects, or has reasonable grounds to suspect is related to money laundering or financing of terrorism and shall, without delay, report such transactions to the competent authorities.

Client information and transparency obligations

The Company undertakes to:

  • Provide clear, complete, and comprehensible information on all material risks, including market, operational, security, legal, liquidity, and other relevant risks.
  • Ensure that the client confirms their understanding and acceptance of the risks prior to using the Company’s services.
  • Clearly state that the risk statement cannot cover all possible risks and that the client must independently assess whether such exposure is acceptable in their individual circumstances.

Risk management within the Company – internal control system

The Company shall implement a structured and continuous risk management system, which includes:

  • regular identification, classification, and assessment of risks;
  • the definition of quantitative and qualitative methods for measuring and monitoring risks;
  • the establishment of internal exposure limits;
  • robust procedures for the security and protection of client assets (including encryption, wallet segregation, security protocols, and audits);
  • a transparent reporting process to senior management and regulatory authorities;
  • regular internal and external audits of the risk management and security systems.

This Statement serves as the basis for business decision-making and risk management within the Company. The Company undertakes to regularly review and update this Statement in line with developments in the market, technology, and applicable regulations.

Version history