SummitLink
  • Home
  • Products & Services
  • Banking Partnership
  • About SummitLink ▾
    Why Choose Us Compliance & Security About Us Contact
中文 Get Started
Customer Protection

Vulnerable Customer Policy

Summit Link LLC's framework for identifying, supporting, and protecting vulnerable customers.

SUMMIT LINK LLC

VULNERABLE CUSTOMER POLICY

Comprehensive Framework for the Identification, Support,

and Protection of Vulnerable Customers

Including Enhanced Measures for Customers Aged 60+

Effective Date: July 23, 2026 | Version 1.0

Approved by the Managing Members

CONFIDENTIAL — INTERNAL USE ONLY

1. Introduction, Policy Statement, and Strategic Objectives

1.1 Policy Statement

Summit Link LLC ("the Company", "Summit Link", "we", "our") is committed to ensuring that all customers are treated fairly, with dignity, respect, and care throughout every stage of their relationship with the Company. This Vulnerable Customer Policy ("the Policy") establishes the Company's comprehensive framework for the identification, assessment, classification, support, monitoring, and protection of customers who may be vulnerable, and for preventing the financial exploitation, abuse, and detriment of such customers.

The Company recognizes that vulnerability is not a binary or permanent state. Any customer may become vulnerable at any point due to changes in personal circumstances, health, cognitive capacity, life events, financial situation, or external pressures. Vulnerability exists on a spectrum, may be transient or enduring, and may affect a customer's ability to make informed financial decisions, access services, or protect their own interests. The Company's approach is therefore dynamic, adaptive, and customer-centric, ensuring that support is calibrated to the individual's specific needs and circumstances.

This Policy reflects Summit Link LLC's core institutional values of integrity, fairness, accountability, and customer protection. It has been approved by the Managing Members and is binding on all employees, officers, contractors, agents, and third-party service providers of Summit Link LLC.

1.2 Strategic Objectives

  • Embed the fair treatment of vulnerable customers into the Company's culture, governance, operations, and decision-making processes at every level of the organization.
  • Establish robust, systematic, and auditable processes for the early identification of customer vulnerability, including proactive screening, behavioral monitoring, and staff-led detection.
  • Provide a structured classification framework that enables the Company to calibrate its response and support measures to the severity and nature of each customer's vulnerability.
  • Implement comprehensive enhanced measures for customers at heightened risk of exploitation and fraud, with particular focus on customers aged 60 years and above.
  • Ensure that the Company's products, services, communications, digital platforms, and physical premises are accessible and appropriate for customers with diverse needs and circumstances.
  • Protect vulnerable customers from financial exploitation, scams, and fraud through targeted prevention, intervention, and recovery measures.
  • Maintain a governance framework that provides effective management oversight of the vulnerable customer program, with clear accountability, reporting, and assurance mechanisms.
  • Ensure full compliance with all applicable laws, regulations, and supervisory guidance relating to the treatment of vulnerable customers.
  • Foster a culture of continuous improvement through regular training, competency assessment, lessons learned, and engagement with external stakeholders and advocacy organizations.

1.3 Relationship to Other Company Policies

This Policy should be read in conjunction with the following Summit Link LLC policies and documents, which together form the Company's customer protection framework:

  • Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) Policy
  • Customer Due Diligence (CDD) and Know Your Customer (KYC) Procedures
  • Fraud Prevention and Detection Policy
  • Data Protection and Privacy Policy
  • Complaints Handling Policy and Procedures
  • Product Governance and Suitability Policy
  • Operational Risk Management Framework
  • Whistleblowing Policy
  • Code of Conduct and Ethics
  • Business Continuity and Incident Management Framework

2. Scope, Application, and Jurisdictional Considerations

2.1 Organizational Scope

This Policy applies to all divisions, business units, and operational functions of Summit Link LLC. It extends to all activities conducted by or on behalf of the Company, whether performed by employees, officers, contractors, agents, outsourced service providers, or any other person acting under the Company's authority.

2.2 Product and Service Scope

This Policy covers all products and services offered by the Company, including but not limited to retail and personal financial services, corporate and commercial services, investment and wealth management, lending and credit facilities, digital and mobile services, payment services, and any other financial products or services provided directly or through intermediaries.

2.3 Customer Scope

This Policy applies to all existing and prospective customers of Summit Link LLC, including individual retail customers, joint account holders, authorized signatories and representatives, power of attorney holders, legal guardians and deputies, beneficiaries of trust and estate accounts, and any other person who interacts with the Company in connection with a customer's account or financial affairs.

2.4 Staff Obligations and Accountability

Every employee of Summit Link LLC has a personal and professional responsibility to comply with this Policy and to treat vulnerable customers with care, empathy, and respect. Staff members who fail to adhere to the requirements of this Policy may be subject to disciplinary action, up to and including termination. Senior management is accountable for ensuring that adequate resources, training, systems, and governance are in place to support effective implementation.

3. Regulatory Framework and Legal Obligations

This Policy has been developed in compliance with all applicable federal, state, and local laws, regulations, and industry standards relating to the fair treatment of vulnerable customers. Summit Link LLC monitors legislative and regulatory developments on a continuous basis and updates this Policy as necessary to maintain compliance. Key regulatory considerations include:

  • Consumer financial protection laws and regulations
  • Anti-money laundering and counter-terrorism financing requirements
  • Data protection and privacy legislation
  • Elder abuse prevention and adult safeguarding laws
  • Disability discrimination and accessibility requirements
  • Financial industry conduct and licensing regulations
  • Applicable state-level consumer protection statutes

4. Definitions and Interpretation

"Vulnerable Customer" means a person who, due to their personal circumstances, is especially susceptible to harm or detriment — particularly when the Company fails to act with appropriate levels of care. Vulnerability may arise from health conditions, disability, age-related factors, life events, financial circumstances, capability limitations, or any combination thereof.

"Age-Related Vulnerability" means vulnerability associated with advanced age, particularly for customers aged 60 years and above. While age alone does not determine vulnerability, the Company recognizes that older customers may face an increased risk of cognitive decline, social isolation, reduced digital confidence, financial dependence on third parties, and targeting by fraudsters.

"Financial Exploitation" means the unauthorized or improper use of a vulnerable person's funds, assets, property, or financial information for the benefit of another person, whether through theft, fraud, coercion, undue influence, manipulation, or the abuse of a position of trust.

"Vulnerability Assessment" means the Company's structured, documented process for evaluating whether a customer may be vulnerable, determining the nature and severity of the vulnerability, and identifying appropriate support and protection measures.

"Vulnerability Champion" means a designated senior staff member who has completed the Company's Advanced Vulnerability Training program and serves as a subject matter expert, mentor, and escalation point for staff in matters relating to vulnerable customers.

"Trusted Person" means an individual formally nominated by a customer to assist with the management or oversight of their financial affairs, whose identity has been verified by the Company, whose suitability has been assessed, and whose scope of involvement has been documented and agreed.

"Capacity" means a person's ability to understand, retain, and weigh information relevant to a financial decision, and to communicate that decision. Capacity is decision-specific and time-specific.

"Enhanced Measures" means additional controls, safeguards, verification steps, monitoring procedures, communication adjustments, and support arrangements applied to accounts and relationships involving identified vulnerable customers.

5. Drivers of Vulnerability: Comprehensive Taxonomy

Summit Link LLC has developed a comprehensive taxonomy of vulnerability drivers to inform staff training, identification processes, and risk assessment. Vulnerability is multi-dimensional and individuals may experience multiple, interacting drivers simultaneously.

5.1 Health and Physical Conditions

  • Chronic, serious, or terminal illness
  • Physical disability or mobility impairment
  • Sensory impairment (hearing loss, vision impairment) affecting communication
  • Mental health conditions (depression, anxiety disorders, bipolar disorder, PTSD)
  • Cognitive impairment or neurodegeneration (dementia, Alzheimer's disease, acquired brain injury)
  • Substance use disorders and addiction
  • Neurodivergent conditions (autism spectrum disorder, ADHD, dyslexia)
  • Medication effects that impair judgment, concentration, or communication

5.2 Life Events and Situational Factors

  • Bereavement and grief, particularly the loss of a spouse or partner who managed finances
  • Relationship breakdown, divorce, or separation
  • Domestic abuse, coercive control, and economic abuse
  • Job loss, redundancy, business failure, or enforced retirement
  • Caring responsibilities for a dependent
  • Immigration, refugee status, or displacement
  • Victimization by fraud, scam, or exploitation (prior or ongoing)
  • Natural disasters or other force majeure events

5.3 Financial Circumstances

  • Over-indebtedness, problem debt, or insolvency
  • Low, irregular, or unstable income
  • Financial dependence on another person
  • Sudden loss of wealth or unexpected windfall
  • Lack of access to mainstream financial products
  • Vulnerability to predatory lending or investment scams

5.4 Capability and Knowledge

  • Low financial literacy or numeracy
  • Limited English proficiency or communication in a non-native language
  • Digital exclusion or lack of confidence with online services
  • Limited educational attainment or learning difficulties
  • Unfamiliarity with the financial system

5.5 Age-Related Vulnerability

Summit Link LLC gives particular and documented attention to customers aged 60 years and above. While age alone is not a determinant of vulnerability, it is an empirically established risk factor that correlates with a higher incidence of cognitive decline, social isolation, reduced digital engagement, financial dependence on third parties, and disproportionate targeting by fraud perpetrators. The Company's enhanced measures for customers aged 60+ are set out in Section 10 of this Policy.

6. Identification of Vulnerable Customers

Summit Link LLC employs a multi-layered approach to identifying vulnerable customers, combining staff observation, systematic screening, automated analytics, customer self-disclosure, and external referrals.

6.1 Identification at Onboarding

  • Structured observation using the Company's Vulnerability Indicators Checklist (Annex A)
  • Direct questioning using empathetic, open-ended Vulnerability Screening Questions
  • Environmental assessment of accompanying persons, physical and emotional state, and indicators of distress or pressure
  • Document review for quality, consistency, and customer understanding
  • Age-based screening with automatic vulnerability flag for customers aged 60+

6.2 Ongoing Identification

  • Automated transaction monitoring with vulnerability-specific rules and alerts
  • Behavioral analytics applied to digital sessions
  • Staff observations during interactions across all channels
  • Periodic due diligence reviews with vulnerability reassessment
  • Customer self-disclosure through dedicated channels
  • External referrals from law enforcement, social services, or advocacy organizations
  • Complaints and feedback analysis for vulnerability-related patterns

6.3 Vulnerability Screening Questions

The Company's screening questions are designed to be asked sensitively and naturally. They include:

  • "Are you comfortable managing your finances independently, or is there someone who helps you?"
  • "Have there been any recent changes in your life that might affect your financial situation?"
  • "Is anyone helping you with this application today? If so, what is their relationship to you?"
  • "Do you feel under any pressure to open this account or make this transaction?"
  • "Would you like information in a different format, or would you prefer more time to review?"

7. Vulnerability Assessment Framework

When a potential vulnerability indicator is identified, the Company conducts a structured assessment using the following five-stage framework:

StageActivityResponsibleTimeframe
1. DetectionIdentify vulnerability indicator through observation, screening, monitoring, disclosure, or referralAll staff / Automated systemsImmediate
2. TriageAssess urgency and severity; determine if immediate protective action is needed; classify as routine, priority, or emergencyLine manager / Vulnerability ChampionWithin 4 hours
3. AssessmentConduct comprehensive vulnerability assessment; engage with customer; evaluate drivers, severity, duration, and impactVulnerability Champion / ComplianceWithin 48 hours (24 hours for emergency)
4. ActionImplement tailored support measures; activate account adjustments; notify relevant parties; communicate with customerRelationship manager / OperationsWithin 5 business days
5. ReviewMonitor effectiveness of support measures; reassess vulnerability status; adjust measures as circumstances changeVulnerability Champion / ComplianceOngoing (min. quarterly)

8. Vulnerability Classification and Risk Levels

Following the Vulnerability Assessment, each customer is assigned a classification level that determines the intensity of support, monitoring, and governance oversight.

LevelDescriptionExamplesResponse and Controls
Level 1: LowMinor, transient, or well-managed vulnerability indicators. Customer retains full capacity.Temporary illness; minor financial difficulty; language barrier; age 60-65 with no other indicatorsStandard care with heightened awareness; offer accessible formats; periodic check-in; Vulnerability Champion notified
Level 2: MediumModerate vulnerability indicators that may impair financial decision-making or increase susceptibility to exploitation.Ongoing mental health condition; age 65-74 with early cognitive concerns; recent bereavement with financial dependency; digital exclusionAssigned Vulnerability Champion; tailored communications; enhanced monitoring; restrictions on high-risk transactions; bi-annual welfare contact
Level 3: HighSignificant vulnerability with elevated risk of exploitation, fraud, or financial detriment. Customer may have impaired capacity.Moderate-to-severe cognitive decline; active domestic abuse; age 75+ with third-party dependency; significant debt crisis; known fraud victimizationFull enhanced due diligence; senior management oversight; mandatory cooling-off periods; proactive monthly welfare checks; dual authorization for large transactions
Level 4: CriticalImmediate, acute risk of serious financial harm, exploitation, or abuse. Emergency intervention may be required.Active financial exploitation; complete loss of mental capacity; emergency safeguarding concern; imminent risk of destitutionImmediate account freeze if necessary; escalation to Compliance Officer; safeguarding referral; daily monitoring until stabilized

Vulnerability classifications are reviewed at intervals determined by the level: Level 1 at each due diligence review; Level 2 bi-annually; Level 3 quarterly; Level 4 monthly or as circumstances require. Classifications may be escalated or de-escalated at any time based on new information.

9. Support Measures and Customer Care

9.1 Communication and Accessibility

  • Plain language standards applied to all customer-facing documents
  • Alternative formats available on request: large print, audio, easy-read, and screen-reader-compatible digital formats
  • Professional interpretation and translation services for customers with limited English proficiency
  • Staff trained in adaptive communication techniques: clear speech, repetition, visual aids, written summaries, and additional processing time
  • Dedicated vulnerability telephone line and email address staffed by trained personnel
  • Private consultation spaces for sensitive discussions
  • Accessible premises design: wheelchair access, hearing loops, adjustable counters, tactile signage

9.2 Product and Service Adjustments

  • Fee and charge waivers or reductions where financial hardship is documented
  • Forbearance and flexible repayment arrangements for lending products
  • Simplified account structures with reduced complexity and enhanced controls
  • Suitability restrictions on high-risk or complex products where appropriate
  • Extended cooling-off periods (minimum 72 hours) for significant financial decisions
  • Additional verification steps for high-value transactions
  • Suspension of marketing communications and cross-selling to customers classified as Level 3 or Level 4

9.3 Trusted Person Framework

  • Customers may nominate one or more Trusted Persons to provide support in managing their financial affairs. Nominations must be made voluntarily, in writing, and in the absence of the nominated person.
  • The Company conducts standard due diligence on all nominated Trusted Persons, including identity verification, screening, and assessment of potential conflicts of interest.
  • The scope of the Trusted Person's involvement is defined in a Trusted Person Agreement signed by the customer and the Trusted Person.
  • Trusted Persons may not alter beneficial ownership, add signatories, close the account, or override account restrictions without the Company's separate authorization.
  • All interactions and transactions involving Trusted Persons are recorded and subject to enhanced monitoring.
  • The Company reserves the right to restrict or revoke Trusted Person access at any time if there are concerns about exploitation or conflict of interest.
  • The customer may revoke the Trusted Person nomination at any time by written notice.

9.4 Welfare Checks and Proactive Engagement

  • Monthly welfare check by the assigned Vulnerability Champion for Level 3 and Level 4 customers
  • Quarterly in-person or video welfare review for Level 4 customers
  • Review of account activity for anomalous patterns including dormancy, sudden increases, or inconsistent transactions
  • Engagement with the customer's Trusted Person, legal representative, or social worker as appropriate
  • Documentation of all welfare check outcomes in the customer's vulnerability file
  • Escalation within 48 hours where a welfare check cannot be completed

10. Enhanced Measures for Customers Aged 60 and Above

10.1 Enhanced Onboarding

  • A dedicated vulnerability-trained onboarding officer must be assigned to every account opening for a customer aged 60+.
  • Face-to-face or video meeting is mandatory. Fully automated onboarding is not permitted without prior written approval from the Compliance Officer.
  • The onboarding officer must conduct a comprehensive understanding assessment to confirm the customer understands the nature, features, risks, fees, and terms of the product or service.
  • The onboarding officer must specifically ask whether any third party has assisted, directed, or influenced the customer's decision, in a private setting.
  • Where a third party is present, the Company must conduct a separate private conversation with the customer.
  • Source of funds and source of wealth documentation must be obtained and verified with heightened care.
  • A non-clinical cognitive awareness screening must be conducted using the Company's standardized checklist (Annex C).
  • The completed Enhanced Onboarding Form (Annex D) must be signed by the onboarding officer and reviewed by the Vulnerability Champion within 5 business days.
  • Customers aged 75 and above are automatically classified as minimum Level 2 vulnerability.

10.2 Transaction Monitoring

  • Lower transaction alert thresholds (50% of standard thresholds)
  • Automatic flagging of all transactions to new payees with mandatory review before release for amounts exceeding defined thresholds
  • Enhanced scrutiny of large cash withdrawals and deposits that deviate from established patterns
  • Automatic alerts for changes to standing orders, direct debits, or regular payment patterns
  • Mandatory telephone callback verification for wire transfers and international payments exceeding set thresholds
  • Quarterly review of transaction patterns by the Vulnerability Champion
  • Annual comprehensive account review by the Compliance Department

10.3 Digital Safeguards

  • Simplified digital interface option with larger fonts, high contrast, and clearer navigation
  • In-person and telephone assistance for digital setup, password resets, and security settings
  • Customer-configurable daily transaction limits for online and mobile platforms
  • Enhanced multi-factor authentication for high-value transactions
  • Automatic notifications for all transactions regardless of value
  • Option to designate a Trusted Person to receive real-time transaction alerts
  • Regular digital literacy sessions and fraud awareness materials designed for older users

11. Fraud Prevention and Scam Protection

11.1 Scam Intervention Protocol (SIP)

The SIP is activated when there are reasonable grounds to suspect a vulnerable customer is being targeted:

  • Immediate suspension of the suspect transaction.
  • Trained staff member conducts a structured scam awareness conversation.
  • If the staff member reasonably believes the customer is being scammed: the transaction is blocked, the customer is informed, and the incident is escalated to the Fraud Prevention Team and Vulnerability Champion.
  • Where appropriate, the Trusted Person or legal representative is notified.
  • A suspicious activity report is filed where required by law.
  • Temporary account restrictions may be imposed to prevent further loss.
  • Follow-up contact is made within 48 hours to check on the customer's welfare.
  • All SIP activations are logged and reported monthly.

11.2 Scam Awareness Program

  • Quarterly educational communications tailored by vulnerability type and age group
  • Targeted awareness campaigns for emerging scam typologies
  • Staff scam identification training updated quarterly
  • Collaboration with industry bodies and consumer protection organizations
  • Community outreach program targeting senior centers and community groups

12. Mental Capacity Framework

12.1 Guiding Principles

  • Every customer is presumed to have capacity unless there is evidence to the contrary.
  • Capacity is decision-specific and time-specific.
  • All practicable steps must be taken to help a customer make their own decision before concluding they lack capacity.
  • An unwise decision does not, by itself, indicate lack of capacity.
  • Any action taken on behalf of a person lacking capacity must be in their best interests and be the least restrictive option.

12.2 Capacity Assessment Procedures

  • Document the specific concerns and the factual basis for questioning capacity.
  • Escalate to the Vulnerability Champion for initial assessment using the Capacity Assessment Checklist (Annex C).
  • If concerns are confirmed, request medical evidence or arrange an independent assessment with the customer's consent.
  • Pending the outcome, the Company may restrict the account to essential transactions to protect the customer.
  • If the customer is found to lack capacity, the Company will work with their legal representative to protect their interests.
  • All assessments, decisions, and communications are documented and reviewed at least annually.

13. Staff Training, Competency, and Culture

13.1 Mandatory Training Program

  • All new employees: Vulnerable Customer Awareness training within 30 days of start date
  • Annual refresher training for all customer-facing, compliance, risk, and operations staff
  • Content includes: recognizing vulnerability indicators, communication techniques, escalation procedures, data protection, fraud awareness, age-specific measures, cultural sensitivity, mental capacity, and regulatory obligations
  • Training delivered through e-learning, workshops, case studies, and role-play scenarios

13.2 Specialist Training

  • Vulnerability Champions: Advanced Vulnerability Program covering assessment methodology, safeguarding, mental capacity, and crisis intervention. Annual re-certification required.
  • Onboarding officers: Enhanced Onboarding Training covering coercion detection, undue influence, and elderly customer interaction.
  • Fraud prevention staff: Scam Typology and Intervention Training covering interview techniques and vulnerable victim support.
  • Senior management: Governance and Regulatory Training covering oversight responsibilities and emerging risks.

13.3 Competency and Culture

All training includes competency assessments with a minimum pass rate of 80%. Staff who do not meet the standard receive additional support and must retake within 30 days. The Company fosters a culture of proactive vulnerability identification through recognition programs, case study sharing, and regular staff forums. Staff are encouraged to escalate concerns without fear of criticism or repercussion.

14. Governance, Oversight, and Accountability

14.1 Management Responsibility

The Managing Members of Summit Link LLC bear ultimate responsibility for the fair treatment of vulnerable customers. Management receives quarterly reports on the vulnerable customer program and approves this Policy and any material amendments. A designated senior officer holds delegated responsibility for the Company's vulnerable customer strategy.

14.2 Key Performance Indicators

KPITargetReporting
Vulnerability identification rate≥ 95% identified within 30 days of indicator detectionMonthly
Mandatory training completion100% within 30 days of hireMonthly
Specialist training completion100% of designated roles within 60 daysQuarterly
Welfare check completion≥ 95% completed on scheduleMonthly
Complaint resolution (vulnerable)≥ 90% within 15 business daysMonthly
Fraud interception rate≥ 85% of suspected scam transactions interceptedMonthly
Age 60+ onboarding compliance100% adherence to enhanced proceduresQuarterly
Trusted Person verification100% verified within 10 business daysMonthly
Internal audit findings remediation100% critical findings within 30 daysQuarterly

15. Complaints Handling

  • Immediate priority flagging for all complaints from or about vulnerable customers
  • Assignment to specialist vulnerability-trained complaints handlers
  • Flexible submission channels: telephone, in-person, email, letter, or via Trusted Person
  • Assistance for customers who need help articulating their complaint
  • Escalation to Vulnerability Champion and Compliance for complaints involving exploitation or safeguarding
  • Root cause analysis on all vulnerability-related complaints
  • Target resolution: 15 business days (30 days maximum)
  • Post-resolution follow-up to confirm customer satisfaction and wellbeing

16. Incident Management and Safeguarding Referrals

A vulnerable customer incident is any event that has caused, or has the potential to cause, financial or non-financial harm to a vulnerable customer. All incidents must be reported within 24 hours of detection and triaged by the Vulnerability Champion. The Company conducts thorough investigations, takes immediate protective action, documents findings, and incorporates lessons learned into training and process improvements.

Where the Company identifies or suspects that a vulnerable customer is at risk of abuse, exploitation, or neglect, a safeguarding referral is made to the appropriate external authority, including law enforcement, social services, or other relevant agencies. The customer's consent is sought where possible, but the Company may make a referral without consent where there is an overriding concern for safety.

17. Technology, Innovation, and Analytics

  • Transaction pattern analysis for exploitation, fraud, and financial distress indicators
  • Digital session analytics for navigation difficulties and potential third-party access
  • Real-time risk scoring integrated into vulnerability assessment workflows
  • Continuous model validation and bias testing to prevent discriminatory outcomes
  • WCAG 2.1 AA compliance for all digital platforms, audited annually
  • Assistive technology support including screen readers, voice navigation, and adjustable display

18. Data Protection and Confidentiality

Vulnerability data, including health-related sensitive information, is processed in accordance with all applicable data protection laws. Access is restricted to authorized personnel on a strict need-to-know basis. All vulnerability records are encrypted, access-logged, and retained for the duration of the customer relationship plus seven (7) years. Customers may exercise their data protection rights by contacting the Company's designated data protection contact.

19. Internal Audit and Assurance

An annual risk-based audit of the vulnerable customer program covers identification, support, monitoring, training, governance, and compliance. Findings are reported to management with remediation timelines of 30 days (critical), 60 days (high), and 90 days (medium). An independent external review is commissioned at least every three years.

20. External Partnerships and Community Engagement

Summit Link LLC maintains active partnerships with external organizations to support vulnerable customers. These include age-related advocacy organizations, mental health charities, debt counseling services, domestic abuse support organizations, law enforcement agencies, regulatory bodies, and academic institutions conducting research into financial vulnerability and elder abuse prevention.

21. Record Keeping and Documentation

  • A dedicated vulnerability record is created for each identified vulnerable customer containing the full assessment, classification, support plan, welfare check records, and all related correspondence.
  • All customer interactions relating to vulnerability are documented.
  • All decisions regarding account restrictions, product suitability, Trusted Person approvals, capacity assessments, and escalations are documented with clear rationale.
  • Training records are maintained for all staff.
  • Incident reports, investigation findings, and remediation actions are documented and retained.
  • All records are retained for the customer relationship duration plus a minimum of seven (7) years post-closure, or longer where required by law.
  • Records are stored securely with encryption, role-based access controls, and comprehensive audit logging.

22. Sanctions for Policy Breaches

SeverityExamplesDisciplinary ActionRemediation
MinorIncomplete documentation; late welfare check; minor training delayVerbal warning; mandatory retraining within 14 daysProcess reminder; additional supervision
ModerateFailure to escalate; inadequate support plan; improper data disclosureWritten warning; competency reassessment; enhanced supervisionCase review; process improvement; retraining within 30 days
SeriousFailure to identify/protect resulting in customer loss; discriminatory treatment; deliberate non-complianceFinal warning; potential suspension; regulatory notificationFull investigation; systemic review; customer remediation
GrossDeliberate exploitation; facilitation of fraud; willful misconductSummary dismissal; law enforcement referralFull investigation; customer restitution; regulatory reporting

Annex A — Vulnerability Indicators Checklist

#Indicator CategorySpecific Indicators
1BehavioralConfusion, distress, inconsistent statements, deference to accompanying person, inability to explain purpose of transaction
2CognitiveDifficulty understanding information, inability to retain or weigh options, repetitive questions, disorientation
3PhysicalFrailty, visible injuries, sensory impairment, mobility limitations, signs of self-neglect
4FinancialSudden changes in transaction patterns, large unexplained withdrawals, new payees inconsistent with profile, apparent financial distress
5Third-PartyOverbearing companion, person speaking on customer's behalf, customer isolated from private conversation, signs of coercion or undue influence
6DigitalRepeated failed authentication, unusual login patterns, session anomalies suggesting third-party access, navigation difficulties
7DocumentaryInconsistent or incomplete documentation, customer unable to explain submitted documents, signs of document manipulation

Annex B — Vulnerability Screening Questions

#Screening QuestionPurpose
1Are you comfortable managing your finances independently, or is there someone who helps you?Identify dependency or support needs
2Have there been any recent changes in your life that might affect your financial situation?Detect life event triggers
3Is anyone helping you with this application today? What is their relationship to you?Identify third-party influence
4Do you feel under any pressure to open this account or make this payment?Detect coercion or undue influence
5Would you like information in a different format, or would you prefer more time?Identify accessibility needs
6Is there anything about your health or personal situation we should be aware of to support you better?Encourage self-disclosure
7Do you understand the fees, risks, and terms associated with this product?Assess product understanding
8Would you like to nominate someone we can contact on your behalf if needed?Introduce Trusted Person option

Annex C — Mental Capacity Assessment Checklist

Non-clinical screening tool for Vulnerability Champions:

#Assessment QuestionOutcome
1Can the customer understand the information relevant to the financial decision?Y / N / Concerns
2Can the customer retain the information long enough to make the decision?Y / N / Concerns
3Can the customer use or weigh the information in making the decision?Y / N / Concerns
4Can the customer communicate their decision (by any means)?Y / N / Concerns
5Does the customer understand the consequences of the decision?Y / N / Concerns
6Is the decision consistent with the customer's known values and interests?Y / N / Concerns
7Is there any indication of third-party influence, coercion, or direction?Y / N / Concerns
8Have all practicable steps been taken to help the customer decide for themselves?Y / N / Concerns

If answers to questions 1–4 raise concerns, escalate to the Compliance Officer and consider requesting medical evidence of capacity.

Document Control and Version History

VersionDateApproved BySummary of Changes
1.0July 2026Managing MembersInitial policy release: comprehensive vulnerable customer framework; 4-level classification system; Trusted Person framework; enhanced measures for customers aged 60+; scam intervention protocol; mental capacity framework; staff training program; governance and KPI structure; annexes

© 2026 Summit Link LLC. All rights reserved. This document is the proprietary and confidential property of Summit Link LLC and may not be reproduced, distributed, or disclosed without the Company's prior written consent.

Document Sign-Off

By signing below, the undersigned confirm that they have reviewed, approved, and authorized this Vulnerable Customer Policy for implementation across Summit Link LLC. This Policy is effective as of the date of the last signature below.

RoleName, Signature, and DateTitle
Prepared By
Reviewed By
Approved By (Managing Member)
Approved By (Managing Member)
Compliance Officer

Signatures:

Prepared By:

Name / Signature / Date

Reviewed By:

Name / Signature / Date

Approved By (Managing Member):

Name / Signature / Date

Approved By (Managing Member):

Name / Signature / Date

Compliance Officer:

Name / Signature / Date

END OF DOCUMENT

SummitLink

SummitLink is a global fintech platform committed to building accessible and reliable financial infrastructure.

Quick Links

Home Products & Services Banking Partnership Why Choose Us Compliance & Security

Company

About Us Contact Privacy Policy Disclaimer VCP

Contact

info@summitlink.us (+1) 3322601188

Registered with FinCEN as a Money Services Business. Partners with licensed financial institutions for services and fund custody.

Direct Onboarding Only: SummitLink does not accept onboarding instructions, representations, or submissions made by any Third Party. All clients must handle onboarding directly through designated internal signatories. Third parties cannot submit documents, communicate on behalf of clients, or attend verification calls. SummitLink may suspend onboarding if third-party involvement is detected.

MSB Registration Number: 31000325254640

Registration Type: Initial Registration

Legal Name: Summit Link LLC

Street Address: 1837 Austin Bluffs Pkwy # 200
City: Colorado Springs   State: COLORADO   Zip: 80918

© 2025 SummitLink INC. All rights reserved.

Privacy Policy Disclaimer VCP