SUMMIT LINK LLC
VULNERABLE CUSTOMER POLICY
Comprehensive Framework for the Identification, Support,
and Protection of Vulnerable Customers
Including Enhanced Measures for Customers Aged 60+
Effective Date: July 23, 2026 | Version 1.0
Approved by the Managing Members
CONFIDENTIAL — INTERNAL USE ONLY
1. Introduction, Policy Statement, and Strategic Objectives
1.1 Policy Statement
Summit Link LLC ("the Company", "Summit Link", "we", "our") is committed to ensuring that all customers are treated fairly, with dignity, respect, and care throughout every stage of their relationship with the Company. This Vulnerable Customer Policy ("the Policy") establishes the Company's comprehensive framework for the identification, assessment, classification, support, monitoring, and protection of customers who may be vulnerable, and for preventing the financial exploitation, abuse, and detriment of such customers.
The Company recognizes that vulnerability is not a binary or permanent state. Any customer may become vulnerable at any point due to changes in personal circumstances, health, cognitive capacity, life events, financial situation, or external pressures. Vulnerability exists on a spectrum, may be transient or enduring, and may affect a customer's ability to make informed financial decisions, access services, or protect their own interests. The Company's approach is therefore dynamic, adaptive, and customer-centric, ensuring that support is calibrated to the individual's specific needs and circumstances.
This Policy reflects Summit Link LLC's core institutional values of integrity, fairness, accountability, and customer protection. It has been approved by the Managing Members and is binding on all employees, officers, contractors, agents, and third-party service providers of Summit Link LLC.
1.2 Strategic Objectives
- Embed the fair treatment of vulnerable customers into the Company's culture, governance, operations, and decision-making processes at every level of the organization.
- Establish robust, systematic, and auditable processes for the early identification of customer vulnerability, including proactive screening, behavioral monitoring, and staff-led detection.
- Provide a structured classification framework that enables the Company to calibrate its response and support measures to the severity and nature of each customer's vulnerability.
- Implement comprehensive enhanced measures for customers at heightened risk of exploitation and fraud, with particular focus on customers aged 60 years and above.
- Ensure that the Company's products, services, communications, digital platforms, and physical premises are accessible and appropriate for customers with diverse needs and circumstances.
- Protect vulnerable customers from financial exploitation, scams, and fraud through targeted prevention, intervention, and recovery measures.
- Maintain a governance framework that provides effective management oversight of the vulnerable customer program, with clear accountability, reporting, and assurance mechanisms.
- Ensure full compliance with all applicable laws, regulations, and supervisory guidance relating to the treatment of vulnerable customers.
- Foster a culture of continuous improvement through regular training, competency assessment, lessons learned, and engagement with external stakeholders and advocacy organizations.
1.3 Relationship to Other Company Policies
This Policy should be read in conjunction with the following Summit Link LLC policies and documents, which together form the Company's customer protection framework:
- Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) Policy
- Customer Due Diligence (CDD) and Know Your Customer (KYC) Procedures
- Fraud Prevention and Detection Policy
- Data Protection and Privacy Policy
- Complaints Handling Policy and Procedures
- Product Governance and Suitability Policy
- Operational Risk Management Framework
- Whistleblowing Policy
- Code of Conduct and Ethics
- Business Continuity and Incident Management Framework
2. Scope, Application, and Jurisdictional Considerations
2.1 Organizational Scope
This Policy applies to all divisions, business units, and operational functions of Summit Link LLC. It extends to all activities conducted by or on behalf of the Company, whether performed by employees, officers, contractors, agents, outsourced service providers, or any other person acting under the Company's authority.
2.2 Product and Service Scope
This Policy covers all products and services offered by the Company, including but not limited to retail and personal financial services, corporate and commercial services, investment and wealth management, lending and credit facilities, digital and mobile services, payment services, and any other financial products or services provided directly or through intermediaries.
2.3 Customer Scope
This Policy applies to all existing and prospective customers of Summit Link LLC, including individual retail customers, joint account holders, authorized signatories and representatives, power of attorney holders, legal guardians and deputies, beneficiaries of trust and estate accounts, and any other person who interacts with the Company in connection with a customer's account or financial affairs.
2.4 Staff Obligations and Accountability
Every employee of Summit Link LLC has a personal and professional responsibility to comply with this Policy and to treat vulnerable customers with care, empathy, and respect. Staff members who fail to adhere to the requirements of this Policy may be subject to disciplinary action, up to and including termination. Senior management is accountable for ensuring that adequate resources, training, systems, and governance are in place to support effective implementation.
3. Regulatory Framework and Legal Obligations
This Policy has been developed in compliance with all applicable federal, state, and local laws, regulations, and industry standards relating to the fair treatment of vulnerable customers. Summit Link LLC monitors legislative and regulatory developments on a continuous basis and updates this Policy as necessary to maintain compliance. Key regulatory considerations include:
- Consumer financial protection laws and regulations
- Anti-money laundering and counter-terrorism financing requirements
- Data protection and privacy legislation
- Elder abuse prevention and adult safeguarding laws
- Disability discrimination and accessibility requirements
- Financial industry conduct and licensing regulations
- Applicable state-level consumer protection statutes
4. Definitions and Interpretation
"Vulnerable Customer" means a person who, due to their personal circumstances, is especially susceptible to harm or detriment — particularly when the Company fails to act with appropriate levels of care. Vulnerability may arise from health conditions, disability, age-related factors, life events, financial circumstances, capability limitations, or any combination thereof.
"Age-Related Vulnerability" means vulnerability associated with advanced age, particularly for customers aged 60 years and above. While age alone does not determine vulnerability, the Company recognizes that older customers may face an increased risk of cognitive decline, social isolation, reduced digital confidence, financial dependence on third parties, and targeting by fraudsters.
"Financial Exploitation" means the unauthorized or improper use of a vulnerable person's funds, assets, property, or financial information for the benefit of another person, whether through theft, fraud, coercion, undue influence, manipulation, or the abuse of a position of trust.
"Vulnerability Assessment" means the Company's structured, documented process for evaluating whether a customer may be vulnerable, determining the nature and severity of the vulnerability, and identifying appropriate support and protection measures.
"Vulnerability Champion" means a designated senior staff member who has completed the Company's Advanced Vulnerability Training program and serves as a subject matter expert, mentor, and escalation point for staff in matters relating to vulnerable customers.
"Trusted Person" means an individual formally nominated by a customer to assist with the management or oversight of their financial affairs, whose identity has been verified by the Company, whose suitability has been assessed, and whose scope of involvement has been documented and agreed.
"Capacity" means a person's ability to understand, retain, and weigh information relevant to a financial decision, and to communicate that decision. Capacity is decision-specific and time-specific.
"Enhanced Measures" means additional controls, safeguards, verification steps, monitoring procedures, communication adjustments, and support arrangements applied to accounts and relationships involving identified vulnerable customers.
5. Drivers of Vulnerability: Comprehensive Taxonomy
Summit Link LLC has developed a comprehensive taxonomy of vulnerability drivers to inform staff training, identification processes, and risk assessment. Vulnerability is multi-dimensional and individuals may experience multiple, interacting drivers simultaneously.
5.1 Health and Physical Conditions
- Chronic, serious, or terminal illness
- Physical disability or mobility impairment
- Sensory impairment (hearing loss, vision impairment) affecting communication
- Mental health conditions (depression, anxiety disorders, bipolar disorder, PTSD)
- Cognitive impairment or neurodegeneration (dementia, Alzheimer's disease, acquired brain injury)
- Substance use disorders and addiction
- Neurodivergent conditions (autism spectrum disorder, ADHD, dyslexia)
- Medication effects that impair judgment, concentration, or communication
5.2 Life Events and Situational Factors
- Bereavement and grief, particularly the loss of a spouse or partner who managed finances
- Relationship breakdown, divorce, or separation
- Domestic abuse, coercive control, and economic abuse
- Job loss, redundancy, business failure, or enforced retirement
- Caring responsibilities for a dependent
- Immigration, refugee status, or displacement
- Victimization by fraud, scam, or exploitation (prior or ongoing)
- Natural disasters or other force majeure events
5.3 Financial Circumstances
- Over-indebtedness, problem debt, or insolvency
- Low, irregular, or unstable income
- Financial dependence on another person
- Sudden loss of wealth or unexpected windfall
- Lack of access to mainstream financial products
- Vulnerability to predatory lending or investment scams
5.4 Capability and Knowledge
- Low financial literacy or numeracy
- Limited English proficiency or communication in a non-native language
- Digital exclusion or lack of confidence with online services
- Limited educational attainment or learning difficulties
- Unfamiliarity with the financial system
5.5 Age-Related Vulnerability
Summit Link LLC gives particular and documented attention to customers aged 60 years and above. While age alone is not a determinant of vulnerability, it is an empirically established risk factor that correlates with a higher incidence of cognitive decline, social isolation, reduced digital engagement, financial dependence on third parties, and disproportionate targeting by fraud perpetrators. The Company's enhanced measures for customers aged 60+ are set out in Section 10 of this Policy.
6. Identification of Vulnerable Customers
Summit Link LLC employs a multi-layered approach to identifying vulnerable customers, combining staff observation, systematic screening, automated analytics, customer self-disclosure, and external referrals.
6.1 Identification at Onboarding
- Structured observation using the Company's Vulnerability Indicators Checklist (Annex A)
- Direct questioning using empathetic, open-ended Vulnerability Screening Questions
- Environmental assessment of accompanying persons, physical and emotional state, and indicators of distress or pressure
- Document review for quality, consistency, and customer understanding
- Age-based screening with automatic vulnerability flag for customers aged 60+
6.2 Ongoing Identification
- Automated transaction monitoring with vulnerability-specific rules and alerts
- Behavioral analytics applied to digital sessions
- Staff observations during interactions across all channels
- Periodic due diligence reviews with vulnerability reassessment
- Customer self-disclosure through dedicated channels
- External referrals from law enforcement, social services, or advocacy organizations
- Complaints and feedback analysis for vulnerability-related patterns
6.3 Vulnerability Screening Questions
The Company's screening questions are designed to be asked sensitively and naturally. They include:
- "Are you comfortable managing your finances independently, or is there someone who helps you?"
- "Have there been any recent changes in your life that might affect your financial situation?"
- "Is anyone helping you with this application today? If so, what is their relationship to you?"
- "Do you feel under any pressure to open this account or make this transaction?"
- "Would you like information in a different format, or would you prefer more time to review?"
7. Vulnerability Assessment Framework
When a potential vulnerability indicator is identified, the Company conducts a structured assessment using the following five-stage framework:
| Stage | Activity | Responsible | Timeframe |
|---|---|---|---|
| 1. Detection | Identify vulnerability indicator through observation, screening, monitoring, disclosure, or referral | All staff / Automated systems | Immediate |
| 2. Triage | Assess urgency and severity; determine if immediate protective action is needed; classify as routine, priority, or emergency | Line manager / Vulnerability Champion | Within 4 hours |
| 3. Assessment | Conduct comprehensive vulnerability assessment; engage with customer; evaluate drivers, severity, duration, and impact | Vulnerability Champion / Compliance | Within 48 hours (24 hours for emergency) |
| 4. Action | Implement tailored support measures; activate account adjustments; notify relevant parties; communicate with customer | Relationship manager / Operations | Within 5 business days |
| 5. Review | Monitor effectiveness of support measures; reassess vulnerability status; adjust measures as circumstances change | Vulnerability Champion / Compliance | Ongoing (min. quarterly) |
8. Vulnerability Classification and Risk Levels
Following the Vulnerability Assessment, each customer is assigned a classification level that determines the intensity of support, monitoring, and governance oversight.
| Level | Description | Examples | Response and Controls |
|---|---|---|---|
| Level 1: Low | Minor, transient, or well-managed vulnerability indicators. Customer retains full capacity. | Temporary illness; minor financial difficulty; language barrier; age 60-65 with no other indicators | Standard care with heightened awareness; offer accessible formats; periodic check-in; Vulnerability Champion notified |
| Level 2: Medium | Moderate vulnerability indicators that may impair financial decision-making or increase susceptibility to exploitation. | Ongoing mental health condition; age 65-74 with early cognitive concerns; recent bereavement with financial dependency; digital exclusion | Assigned Vulnerability Champion; tailored communications; enhanced monitoring; restrictions on high-risk transactions; bi-annual welfare contact |
| Level 3: High | Significant vulnerability with elevated risk of exploitation, fraud, or financial detriment. Customer may have impaired capacity. | Moderate-to-severe cognitive decline; active domestic abuse; age 75+ with third-party dependency; significant debt crisis; known fraud victimization | Full enhanced due diligence; senior management oversight; mandatory cooling-off periods; proactive monthly welfare checks; dual authorization for large transactions |
| Level 4: Critical | Immediate, acute risk of serious financial harm, exploitation, or abuse. Emergency intervention may be required. | Active financial exploitation; complete loss of mental capacity; emergency safeguarding concern; imminent risk of destitution | Immediate account freeze if necessary; escalation to Compliance Officer; safeguarding referral; daily monitoring until stabilized |
Vulnerability classifications are reviewed at intervals determined by the level: Level 1 at each due diligence review; Level 2 bi-annually; Level 3 quarterly; Level 4 monthly or as circumstances require. Classifications may be escalated or de-escalated at any time based on new information.
9. Support Measures and Customer Care
9.1 Communication and Accessibility
- Plain language standards applied to all customer-facing documents
- Alternative formats available on request: large print, audio, easy-read, and screen-reader-compatible digital formats
- Professional interpretation and translation services for customers with limited English proficiency
- Staff trained in adaptive communication techniques: clear speech, repetition, visual aids, written summaries, and additional processing time
- Dedicated vulnerability telephone line and email address staffed by trained personnel
- Private consultation spaces for sensitive discussions
- Accessible premises design: wheelchair access, hearing loops, adjustable counters, tactile signage
9.2 Product and Service Adjustments
- Fee and charge waivers or reductions where financial hardship is documented
- Forbearance and flexible repayment arrangements for lending products
- Simplified account structures with reduced complexity and enhanced controls
- Suitability restrictions on high-risk or complex products where appropriate
- Extended cooling-off periods (minimum 72 hours) for significant financial decisions
- Additional verification steps for high-value transactions
- Suspension of marketing communications and cross-selling to customers classified as Level 3 or Level 4
9.3 Trusted Person Framework
- Customers may nominate one or more Trusted Persons to provide support in managing their financial affairs. Nominations must be made voluntarily, in writing, and in the absence of the nominated person.
- The Company conducts standard due diligence on all nominated Trusted Persons, including identity verification, screening, and assessment of potential conflicts of interest.
- The scope of the Trusted Person's involvement is defined in a Trusted Person Agreement signed by the customer and the Trusted Person.
- Trusted Persons may not alter beneficial ownership, add signatories, close the account, or override account restrictions without the Company's separate authorization.
- All interactions and transactions involving Trusted Persons are recorded and subject to enhanced monitoring.
- The Company reserves the right to restrict or revoke Trusted Person access at any time if there are concerns about exploitation or conflict of interest.
- The customer may revoke the Trusted Person nomination at any time by written notice.
9.4 Welfare Checks and Proactive Engagement
- Monthly welfare check by the assigned Vulnerability Champion for Level 3 and Level 4 customers
- Quarterly in-person or video welfare review for Level 4 customers
- Review of account activity for anomalous patterns including dormancy, sudden increases, or inconsistent transactions
- Engagement with the customer's Trusted Person, legal representative, or social worker as appropriate
- Documentation of all welfare check outcomes in the customer's vulnerability file
- Escalation within 48 hours where a welfare check cannot be completed
10. Enhanced Measures for Customers Aged 60 and Above
10.1 Enhanced Onboarding
- A dedicated vulnerability-trained onboarding officer must be assigned to every account opening for a customer aged 60+.
- Face-to-face or video meeting is mandatory. Fully automated onboarding is not permitted without prior written approval from the Compliance Officer.
- The onboarding officer must conduct a comprehensive understanding assessment to confirm the customer understands the nature, features, risks, fees, and terms of the product or service.
- The onboarding officer must specifically ask whether any third party has assisted, directed, or influenced the customer's decision, in a private setting.
- Where a third party is present, the Company must conduct a separate private conversation with the customer.
- Source of funds and source of wealth documentation must be obtained and verified with heightened care.
- A non-clinical cognitive awareness screening must be conducted using the Company's standardized checklist (Annex C).
- The completed Enhanced Onboarding Form (Annex D) must be signed by the onboarding officer and reviewed by the Vulnerability Champion within 5 business days.
- Customers aged 75 and above are automatically classified as minimum Level 2 vulnerability.
10.2 Transaction Monitoring
- Lower transaction alert thresholds (50% of standard thresholds)
- Automatic flagging of all transactions to new payees with mandatory review before release for amounts exceeding defined thresholds
- Enhanced scrutiny of large cash withdrawals and deposits that deviate from established patterns
- Automatic alerts for changes to standing orders, direct debits, or regular payment patterns
- Mandatory telephone callback verification for wire transfers and international payments exceeding set thresholds
- Quarterly review of transaction patterns by the Vulnerability Champion
- Annual comprehensive account review by the Compliance Department
10.3 Digital Safeguards
- Simplified digital interface option with larger fonts, high contrast, and clearer navigation
- In-person and telephone assistance for digital setup, password resets, and security settings
- Customer-configurable daily transaction limits for online and mobile platforms
- Enhanced multi-factor authentication for high-value transactions
- Automatic notifications for all transactions regardless of value
- Option to designate a Trusted Person to receive real-time transaction alerts
- Regular digital literacy sessions and fraud awareness materials designed for older users
11. Fraud Prevention and Scam Protection
11.1 Scam Intervention Protocol (SIP)
The SIP is activated when there are reasonable grounds to suspect a vulnerable customer is being targeted:
- Immediate suspension of the suspect transaction.
- Trained staff member conducts a structured scam awareness conversation.
- If the staff member reasonably believes the customer is being scammed: the transaction is blocked, the customer is informed, and the incident is escalated to the Fraud Prevention Team and Vulnerability Champion.
- Where appropriate, the Trusted Person or legal representative is notified.
- A suspicious activity report is filed where required by law.
- Temporary account restrictions may be imposed to prevent further loss.
- Follow-up contact is made within 48 hours to check on the customer's welfare.
- All SIP activations are logged and reported monthly.
11.2 Scam Awareness Program
- Quarterly educational communications tailored by vulnerability type and age group
- Targeted awareness campaigns for emerging scam typologies
- Staff scam identification training updated quarterly
- Collaboration with industry bodies and consumer protection organizations
- Community outreach program targeting senior centers and community groups
12. Mental Capacity Framework
12.1 Guiding Principles
- Every customer is presumed to have capacity unless there is evidence to the contrary.
- Capacity is decision-specific and time-specific.
- All practicable steps must be taken to help a customer make their own decision before concluding they lack capacity.
- An unwise decision does not, by itself, indicate lack of capacity.
- Any action taken on behalf of a person lacking capacity must be in their best interests and be the least restrictive option.
12.2 Capacity Assessment Procedures
- Document the specific concerns and the factual basis for questioning capacity.
- Escalate to the Vulnerability Champion for initial assessment using the Capacity Assessment Checklist (Annex C).
- If concerns are confirmed, request medical evidence or arrange an independent assessment with the customer's consent.
- Pending the outcome, the Company may restrict the account to essential transactions to protect the customer.
- If the customer is found to lack capacity, the Company will work with their legal representative to protect their interests.
- All assessments, decisions, and communications are documented and reviewed at least annually.
13. Staff Training, Competency, and Culture
13.1 Mandatory Training Program
- All new employees: Vulnerable Customer Awareness training within 30 days of start date
- Annual refresher training for all customer-facing, compliance, risk, and operations staff
- Content includes: recognizing vulnerability indicators, communication techniques, escalation procedures, data protection, fraud awareness, age-specific measures, cultural sensitivity, mental capacity, and regulatory obligations
- Training delivered through e-learning, workshops, case studies, and role-play scenarios
13.2 Specialist Training
- Vulnerability Champions: Advanced Vulnerability Program covering assessment methodology, safeguarding, mental capacity, and crisis intervention. Annual re-certification required.
- Onboarding officers: Enhanced Onboarding Training covering coercion detection, undue influence, and elderly customer interaction.
- Fraud prevention staff: Scam Typology and Intervention Training covering interview techniques and vulnerable victim support.
- Senior management: Governance and Regulatory Training covering oversight responsibilities and emerging risks.
13.3 Competency and Culture
All training includes competency assessments with a minimum pass rate of 80%. Staff who do not meet the standard receive additional support and must retake within 30 days. The Company fosters a culture of proactive vulnerability identification through recognition programs, case study sharing, and regular staff forums. Staff are encouraged to escalate concerns without fear of criticism or repercussion.
14. Governance, Oversight, and Accountability
14.1 Management Responsibility
The Managing Members of Summit Link LLC bear ultimate responsibility for the fair treatment of vulnerable customers. Management receives quarterly reports on the vulnerable customer program and approves this Policy and any material amendments. A designated senior officer holds delegated responsibility for the Company's vulnerable customer strategy.
14.2 Key Performance Indicators
| KPI | Target | Reporting |
|---|---|---|
| Vulnerability identification rate | ≥ 95% identified within 30 days of indicator detection | Monthly |
| Mandatory training completion | 100% within 30 days of hire | Monthly |
| Specialist training completion | 100% of designated roles within 60 days | Quarterly |
| Welfare check completion | ≥ 95% completed on schedule | Monthly |
| Complaint resolution (vulnerable) | ≥ 90% within 15 business days | Monthly |
| Fraud interception rate | ≥ 85% of suspected scam transactions intercepted | Monthly |
| Age 60+ onboarding compliance | 100% adherence to enhanced procedures | Quarterly |
| Trusted Person verification | 100% verified within 10 business days | Monthly |
| Internal audit findings remediation | 100% critical findings within 30 days | Quarterly |
15. Complaints Handling
- Immediate priority flagging for all complaints from or about vulnerable customers
- Assignment to specialist vulnerability-trained complaints handlers
- Flexible submission channels: telephone, in-person, email, letter, or via Trusted Person
- Assistance for customers who need help articulating their complaint
- Escalation to Vulnerability Champion and Compliance for complaints involving exploitation or safeguarding
- Root cause analysis on all vulnerability-related complaints
- Target resolution: 15 business days (30 days maximum)
- Post-resolution follow-up to confirm customer satisfaction and wellbeing
16. Incident Management and Safeguarding Referrals
A vulnerable customer incident is any event that has caused, or has the potential to cause, financial or non-financial harm to a vulnerable customer. All incidents must be reported within 24 hours of detection and triaged by the Vulnerability Champion. The Company conducts thorough investigations, takes immediate protective action, documents findings, and incorporates lessons learned into training and process improvements.
Where the Company identifies or suspects that a vulnerable customer is at risk of abuse, exploitation, or neglect, a safeguarding referral is made to the appropriate external authority, including law enforcement, social services, or other relevant agencies. The customer's consent is sought where possible, but the Company may make a referral without consent where there is an overriding concern for safety.
17. Technology, Innovation, and Analytics
- Transaction pattern analysis for exploitation, fraud, and financial distress indicators
- Digital session analytics for navigation difficulties and potential third-party access
- Real-time risk scoring integrated into vulnerability assessment workflows
- Continuous model validation and bias testing to prevent discriminatory outcomes
- WCAG 2.1 AA compliance for all digital platforms, audited annually
- Assistive technology support including screen readers, voice navigation, and adjustable display
18. Data Protection and Confidentiality
Vulnerability data, including health-related sensitive information, is processed in accordance with all applicable data protection laws. Access is restricted to authorized personnel on a strict need-to-know basis. All vulnerability records are encrypted, access-logged, and retained for the duration of the customer relationship plus seven (7) years. Customers may exercise their data protection rights by contacting the Company's designated data protection contact.
19. Internal Audit and Assurance
An annual risk-based audit of the vulnerable customer program covers identification, support, monitoring, training, governance, and compliance. Findings are reported to management with remediation timelines of 30 days (critical), 60 days (high), and 90 days (medium). An independent external review is commissioned at least every three years.
20. External Partnerships and Community Engagement
Summit Link LLC maintains active partnerships with external organizations to support vulnerable customers. These include age-related advocacy organizations, mental health charities, debt counseling services, domestic abuse support organizations, law enforcement agencies, regulatory bodies, and academic institutions conducting research into financial vulnerability and elder abuse prevention.
21. Record Keeping and Documentation
- A dedicated vulnerability record is created for each identified vulnerable customer containing the full assessment, classification, support plan, welfare check records, and all related correspondence.
- All customer interactions relating to vulnerability are documented.
- All decisions regarding account restrictions, product suitability, Trusted Person approvals, capacity assessments, and escalations are documented with clear rationale.
- Training records are maintained for all staff.
- Incident reports, investigation findings, and remediation actions are documented and retained.
- All records are retained for the customer relationship duration plus a minimum of seven (7) years post-closure, or longer where required by law.
- Records are stored securely with encryption, role-based access controls, and comprehensive audit logging.
22. Sanctions for Policy Breaches
| Severity | Examples | Disciplinary Action | Remediation |
|---|---|---|---|
| Minor | Incomplete documentation; late welfare check; minor training delay | Verbal warning; mandatory retraining within 14 days | Process reminder; additional supervision |
| Moderate | Failure to escalate; inadequate support plan; improper data disclosure | Written warning; competency reassessment; enhanced supervision | Case review; process improvement; retraining within 30 days |
| Serious | Failure to identify/protect resulting in customer loss; discriminatory treatment; deliberate non-compliance | Final warning; potential suspension; regulatory notification | Full investigation; systemic review; customer remediation |
| Gross | Deliberate exploitation; facilitation of fraud; willful misconduct | Summary dismissal; law enforcement referral | Full investigation; customer restitution; regulatory reporting |
Annex A — Vulnerability Indicators Checklist
| # | Indicator Category | Specific Indicators |
|---|---|---|
| 1 | Behavioral | Confusion, distress, inconsistent statements, deference to accompanying person, inability to explain purpose of transaction |
| 2 | Cognitive | Difficulty understanding information, inability to retain or weigh options, repetitive questions, disorientation |
| 3 | Physical | Frailty, visible injuries, sensory impairment, mobility limitations, signs of self-neglect |
| 4 | Financial | Sudden changes in transaction patterns, large unexplained withdrawals, new payees inconsistent with profile, apparent financial distress |
| 5 | Third-Party | Overbearing companion, person speaking on customer's behalf, customer isolated from private conversation, signs of coercion or undue influence |
| 6 | Digital | Repeated failed authentication, unusual login patterns, session anomalies suggesting third-party access, navigation difficulties |
| 7 | Documentary | Inconsistent or incomplete documentation, customer unable to explain submitted documents, signs of document manipulation |
Annex B — Vulnerability Screening Questions
| # | Screening Question | Purpose |
|---|---|---|
| 1 | Are you comfortable managing your finances independently, or is there someone who helps you? | Identify dependency or support needs |
| 2 | Have there been any recent changes in your life that might affect your financial situation? | Detect life event triggers |
| 3 | Is anyone helping you with this application today? What is their relationship to you? | Identify third-party influence |
| 4 | Do you feel under any pressure to open this account or make this payment? | Detect coercion or undue influence |
| 5 | Would you like information in a different format, or would you prefer more time? | Identify accessibility needs |
| 6 | Is there anything about your health or personal situation we should be aware of to support you better? | Encourage self-disclosure |
| 7 | Do you understand the fees, risks, and terms associated with this product? | Assess product understanding |
| 8 | Would you like to nominate someone we can contact on your behalf if needed? | Introduce Trusted Person option |
Annex C — Mental Capacity Assessment Checklist
Non-clinical screening tool for Vulnerability Champions:
| # | Assessment Question | Outcome |
|---|---|---|
| 1 | Can the customer understand the information relevant to the financial decision? | Y / N / Concerns |
| 2 | Can the customer retain the information long enough to make the decision? | Y / N / Concerns |
| 3 | Can the customer use or weigh the information in making the decision? | Y / N / Concerns |
| 4 | Can the customer communicate their decision (by any means)? | Y / N / Concerns |
| 5 | Does the customer understand the consequences of the decision? | Y / N / Concerns |
| 6 | Is the decision consistent with the customer's known values and interests? | Y / N / Concerns |
| 7 | Is there any indication of third-party influence, coercion, or direction? | Y / N / Concerns |
| 8 | Have all practicable steps been taken to help the customer decide for themselves? | Y / N / Concerns |
If answers to questions 1–4 raise concerns, escalate to the Compliance Officer and consider requesting medical evidence of capacity.
Document Control and Version History
| Version | Date | Approved By | Summary of Changes |
|---|---|---|---|
| 1.0 | July 2026 | Managing Members | Initial policy release: comprehensive vulnerable customer framework; 4-level classification system; Trusted Person framework; enhanced measures for customers aged 60+; scam intervention protocol; mental capacity framework; staff training program; governance and KPI structure; annexes |
© 2026 Summit Link LLC. All rights reserved. This document is the proprietary and confidential property of Summit Link LLC and may not be reproduced, distributed, or disclosed without the Company's prior written consent.
Document Sign-Off
By signing below, the undersigned confirm that they have reviewed, approved, and authorized this Vulnerable Customer Policy for implementation across Summit Link LLC. This Policy is effective as of the date of the last signature below.
| Role | Name, Signature, and Date | Title |
|---|---|---|
| Prepared By | ||
| Reviewed By | ||
| Approved By (Managing Member) | ||
| Approved By (Managing Member) | ||
| Compliance Officer |
Signatures:
Prepared By:
Name / Signature / Date
Reviewed By:
Name / Signature / Date
Approved By (Managing Member):
Name / Signature / Date
Approved By (Managing Member):
Name / Signature / Date
Compliance Officer:
Name / Signature / Date
END OF DOCUMENT