Luminpay

Legal

Luminpay Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy

Effective Date: February 2026Version: 1.0Approved by: Board of Directors

Disclaimer

This Policy is tailored for Luminpay, a crypto-fintech company with international reach operating as a bridge between cryptocurrency and traditional financial services (Web2 fintech). It must be updated as the Company incorporates, obtains licenses, scales operations, or as regulators provide guidance. The Company shall commence operations with primary focus on the Federal Republic of Nigeria and shall comply with applicable Nigerian frameworks, in addition to mandatory international standards.

Executive Summary

Luminpay ("the Company") is an international crypto-fintech company building an inclusive financial infrastructure bridging cryptocurrency and traditional financial services across various jurisdictions. This Policy outlines the Company's binding standards and procedures for preventing, detecting, and reporting money laundering, terrorist financing, and related financial crimes.

The Policy aspires towards international-first standards, in line with the Company's wide-reaching ambitions, and supplements these standards with applicable local laws and supervisory guidance from the select jurisdictions within which it will operate, commencing with Nigeria. It is a startup-phase, Board-approved document intended for immediate release and operationalization during pilot and early scale phases. Where a local legal or regulatory requirement imposes a higher standard, that requirement will take precedence.

As a Virtual Asset Service Provider (VASP), the Company is subject to specific regulatory requirements relating to virtual asset custody, exchange, and transfer services. This Policy ensures compliance with FATF Recommendations applicable to VASPs, including the Travel Rule for virtual asset transfers, and establishes robust frameworks for managing the unique risks associated with cryptocurrency and blockchain-based financial services.

1. POLICY STATEMENT

The Company has zero tolerance for facilitating illicit finance and will refuse or terminate relationships that present unacceptable AML/CFT risk. This Policy prescribes the minimum mandatory controls, governance, and procedures for AML/CFT and KYC across the Company's products, channels, and geographies.

This Policy integrates international AML/CFT obligations including but not limited to:

  • FATF Recommendations, particularly Recommendations 15 and 16 applicable to Virtual Asset Service Providers (VASPs)
  • EU AML Directives (AMLD-4/5/6) where applicable to EU data subjects or counterparties
  • Wolfsberg Principles for correspondent banking and payment systems
  • Industry best practices for virtual asset service providers and crypto-fintech platforms
  • ISO 31000 risk management framework
  • Basel Committee guidance on sound management of risks related to money laundering and financing of terrorism

These international standards are supplemented with applicable domestic laws in jurisdictions where the Company operates. The Company's primary operational jurisdiction is the Federal Republic of Nigeria, and the Company complies with all applicable Nigerian legal and regulatory requirements as detailed in Section 4 and Appendix A.

Where the General Data Protection Regulation (GDPR) applies (i.e., where EU data subjects are involved), the Company shall comply with GDPR requirements in addition to applicable local data protection laws.

2. SCOPE

This Policy applies to the Board, Management Committee, all directors, officers, employees, contractors, vendors, partners, agents, and any third parties acting for or on behalf of the Company or conducting business with the Company. It covers all Company products and services including:

  • Virtual asset custody and wallet services
  • Virtual asset exchange and conversion services (crypto-to-crypto, crypto-to-fiat, fiat-to-crypto)
  • Cross-border payment and remittance services
  • International money transfer services
  • Payment processing for merchants and businesses
  • Virtual account services
  • Payroll and disbursement services
  • Mobile and web-based financial interfaces
  • Agent networks and assisted onboarding channels
  • On-chain and off-chain transaction integrations
  • Settlement and clearing services for virtual assets

The Policy covers all customer types including:

  • Individual retail customers (natural persons)
  • Corporate entities and businesses
  • Trusts and foundations
  • Partnerships
  • Institutional clients and qualified investors
  • Virtual Asset Service Providers (VASPs) and other financial institutions as counterparties

The Company shall maintain a Regulatory Permissions Matrix (see Appendix B) mapping its licensed activities to the relevant regulators and shall only perform activities for which it has obtained the relevant licenses, registrations, or permissions in the operating jurisdiction. The Company shall not conduct any activities requiring VASP registration or licensing until such registration or licensing has been obtained from the competent authority in the relevant jurisdiction.

As the Company operates across multiple jurisdictions, this Policy is designed to be flexible and scalable to accommodate additional jurisdictional requirements as the Company expands its geographic footprint. However, the current operational focus is on Nigeria, and all specific compliance requirements referenced in this Policy relate to Nigerian law unless otherwise stated.

3. DEFINITIONS

AML/CFT: Anti-Money Laundering/Countering the Financing of Terrorism.

Anti-Money Laundering Compliance Officer (AMLCO): The senior officer responsible for the AML/KYC programme.

Beneficial Owner (BO): The natural person(s) who ultimately own or control a customer or legal entity, directly or indirectly, holding 25% or more ownership or control, or, where no such person exists, the senior managing official(s), in line with Nigerian AML regulations and FATF guidance.

Biometric Hash: An irreversible cryptographic hash generated from a biometric template, used to enable identity matching without storing or exposing raw biometric data.

Biometric Template: A processed digital representation of a biometric characteristic (such as fingerprint or facial data) suitable for secure comparison and verification.

CDD (Customer Due Diligence): The set of measures undertaken by the Company to identify, verify, and assess customers and beneficial owners, proportionate to the assessed level of money laundering or terrorist financing risk.

Consent Record: A time-stamped, auditable record evidencing an individual's explicit, informed, and freely given consent for the collection, processing, and storage of personal or biometric data.

Cross-Border Transaction: Any transaction where the originator and beneficiary are located in different countries, or where funds or virtual assets are transferred from one jurisdiction to another.

DPO (Data Protection Officer): An individual appointed by the Company to oversee data protection strategy and ensure compliance with the Nigeria Data Protection Act, 2023 and other applicable data protection laws.

DPIA (Data Protection Impact Assessment): A documented assessment conducted to identify, evaluate, and mitigate risks associated with the processing of personal or biometric data.

EDD (Enhanced Due Diligence): Additional risk-mitigating measures applied to high-risk customers, transactions, products, or jurisdictions, including deeper verification of identity, source of funds, and ongoing monitoring.

FATF: Financial Action Task Force, the international body that sets global AML/CFT standards, including requirements applicable to Virtual Asset Service Providers (VASPs).

FIU (Financial Intelligence Unit): The national authority responsible for receiving, analysing, and disseminating suspicious transaction and financial intelligence reports. In Nigeria, this function is performed by the Nigerian Financial Intelligence Unit (NFIU).

GDPR: General Data Protection Regulation of the European Union, applicable where the Company processes personal data of EU-based customers or counterparties.

goAML: An electronic reporting and case-management platform used by Financial Intelligence Units, including the NFIU, for the submission of Suspicious Transaction Reports (STRs).

HSM (Hardware Security Module): A secure physical device used to generate, store, and manage cryptographic keys and perform sensitive cryptographic operations.

IVMS-101: The global data standard for virtual asset transfers developed to support compliance with the FATF Travel Rule.

KYC/KYB: Know Your Customer / Know Your Business, processes for identifying, verifying, and assessing individuals and legal entities before and during a business relationship.

Luminpay User: Any individual or legal entity that has registered for, accessed, or used the Company's products or services, including wallets, payment cards, virtual accounts, payroll, or crypto-based services.

ML/TF: Money Laundering and Terrorist Financing.

NDPA: Nigeria Data Protection Act, 2023.

NDPC: Nigeria Data Protection Commission, the authority responsible for enforcing data protection laws in Nigeria.

NFIU: Nigerian Financial Intelligence Unit, the competent authority for receiving and analysing STRs in Nigeria.

On-chain Identity Badge: A non-transferable, non-PII blockchain-based token or marker used solely to indicate that an off-chain KYC or verification process has been completed, without revealing personal data.

PEP (Politically Exposed Person): An individual entrusted with a prominent public function, including senior public officials, their immediate family members, and close associates, as defined under Nigerian AML regulations and FATF guidance.

PII (Personally Identifiable Information): Any information that can directly or indirectly identify a natural person, including names, identification numbers, contact details, biometric data, or wallet addresses when linked to identity.

SDD (Simplified Due Diligence): Reduced CDD measures applied to customers assessed as presenting a low risk of money laundering or terrorist financing, where permitted by law and regulation.

Settlement Partner: A third-party financial institution, payment processor, or virtual asset service provider that facilitates the settlement, clearing, or custody of funds or virtual assets on behalf of the Company or its customers.

STR/SAR (Suspicious Transaction/Activity Report): A report filed by the Company with the NFIU or other competent authority concerning transactions or activities suspected to be linked to ML/TF or other financial crimes.

Travel Rule: FATF Recommendation 16, requiring Virtual Asset Service Providers to obtain, retain, and transmit required originator and beneficiary information for virtual asset transfers above applicable thresholds.

VASPs (Virtual Asset Service Providers): Entities engaged in the exchange, transfer, custody, administration, or issuance of virtual assets, subject to regulation by relevant authorities.

ZKP (Zero-Knowledge Proof): A cryptographic technique that allows one party to prove the validity of certain information without revealing the underlying data itself.

4. JURISDICTIONAL FRAMEWORK & REGULATORY COMPLIANCE

The Company operates in an international context while maintaining a primary operational focus on the Federal Republic of Nigeria. This section establishes the jurisdictional framework for the Company's AML/CFT compliance programme and identifies the key regulatory authorities and legal instruments applicable to the Company's operations.

4.1 Primary Jurisdiction: Federal Republic of Nigeria

As the Company's primary operational jurisdiction, Nigeria provides the foundational legal and regulatory framework for the Company's AML/CFT programme. The Company shall comply with all applicable Nigerian laws, regulations, and supervisory guidance, including but not limited to:

  • Money Laundering (Prevention and Prohibition) Act, 2022
  • Terrorism (Prevention and Prohibition) Act, 2022
  • Economic and Financial Crimes Commission (Establishment) Act, 2004
  • The Advance Fee Fraud and Other Fraud Related Offences Act, 2006
  • Nigeria Data Protection Act, 2023
  • Central Bank of Nigeria Act, 2007
  • Banks and Other Financial Institutions Act (BOFIA), 2020
  • Securities and Exchange Commission Act, 2011 (as amended)
  • Nigerian Financial Intelligence Unit Act, 2018
  • Foreign Exchange (Monitoring and Miscellaneous Provisions) Act
  • All relevant Central Bank of Nigeria circulars, guidelines, and regulations
  • All relevant Securities and Exchange Commission rules and regulations
  • All relevant Nigerian Financial Intelligence Unit guidelines and directives

4.2 Competent Regulatory Authorities

The Company is subject to oversight by multiple Nigerian regulatory authorities depending on the nature of its licensed activities. The primary competent authorities include:

  • Central Bank of Nigeria (CBN): Primary regulator for payment systems, money transfer services, and foreign exchange operations. The CBN issues licenses for Payment Service Providers, Switching and Processing Companies, and Mobile Money Operators.
  • Securities and Exchange Commission (SEC): Regulator for virtual asset service providers (VASPs) in Nigeria. The SEC has regulatory authority over digital asset exchanges, platforms, and custodians under the SEC Rules on Issuance, Offering Platforms and Custody of Digital Assets, 2022.
  • Nigerian Financial Intelligence Unit (NFIU): The competent authority for receiving, analyzing, and disseminating financial intelligence and suspicious transaction reports. All reporting entities must file STRs with the NFIU through the goAML platform.
  • Economic and Financial Crimes Commission (EFCC): Law enforcement agency responsible for investigating and prosecuting economic and financial crimes, including money laundering and terrorist financing.
  • Nigeria Data Protection Commission (NDPC): Regulatory authority for data protection and privacy matters under the Nigeria Data Protection Act, 2023.

4.3 International Standards Compliance

In addition to Nigerian legal requirements, the Company commits to compliance with internationally recognized AML/CFT standards, including:

  • FATF 40 Recommendations, with particular emphasis on Recommendations 15 (New Technologies) and 16 (Wire Transfers / Travel Rule)
  • FATF Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers (updated June 2021)
  • Wolfsberg Group AML Principles for Correspondent Banking and Payment Channels
  • Basel Committee on Banking Supervision guidance on sound management of risks related to money laundering and financing of terrorism
  • OECD Common Reporting Standard (CRS) where applicable to tax information exchange
  • EU AML Directives (where processing EU data subjects or counterparties)
  • GDPR (where processing EU personal data)

A detailed Jurisdictional Compliance Matrix is provided in Appendix A, mapping specific requirements to relevant sections of this Policy and applicable legal instruments.

4.4 Digital Asset & VASP Compliance

LuminPay operates as a Virtual Asset Service Provider (VASP) facilitating digital asset payments, settlement, and cross-border transfers. Digital asset wallet infrastructure and MPC-based key management are provided by Turnkey. Turnkey provides wallet infrastructure for Crypto Payment Acceptance for Merchants, transaction signing, and secure private key management technology. Regulatory and AML/CFT responsibility remains fully with LuminPay.

LuminPay complies with:

  • Nigerian AML/CFT laws
  • Central Bank of Nigeria (CBN) guidance where applicable
  • FATF Recommendations
  • Travel Rule obligations
  • Cross-border transaction monitoring standards

5. GOVERNANCE STRUCTURE & KEY RESPONSIBILITIES

The Company's AML/KYC framework is implemented through clear governance lines, documented authorities, and well-defined responsibilities. Governance ensures the consistent application of policy, the timely escalation of issues, compliance with legal/regulatory obligations, and accountability for remedial actions. This Section describes the roles, delegated authorities and reporting relationships that substantively support the AML/KYC programme.

5.1 Board of Directors

The Board has ultimate responsibility for the adequacy, effectiveness and resourcing of the Company's AML/KYC arrangements. Specifically, the Board shall:

  • Approve and annually review the AML/KYC Policy, and any material amendments thereto.
  • Satisfy itself that the Company's AML/KYC programme is consistent with the Company's risk appetite and business strategy.
  • Ensure senior management implements the policy and provides sufficient resources for compliant operations.
  • Receive, at least quarterly, a comprehensive AML/KYC report from senior management that includes key risk indicators (KRIs), emerging AML/CFT threats, STR statistics, transaction monitoring performance metrics, remediation actions, and the status of outstanding audit recommendations.
  • Approve the appointment of the AMLCO and review the AMLCO's qualifications and independence periodically.
  • Approve the Company's AML risk appetite statement and tolerance thresholds.
  • Ensure adequate resources (human, technological, and financial) are allocated to the AML/CFT programme.
  • Review and approve significant changes to the Company's AML/CFT framework, including material changes to risk assessment methodologies, monitoring systems, or customer due diligence procedures.

5.2 Management Committee

A Management Committee (the "Committee"), chaired by the CEO or a delegated senior executive, shall be responsible for overseeing implementation of this AML/KYC Policy and for operational decision-making between Board cycles. The Committee's duties include:

  • Reviewing operational AML/KYC performance monthly and escalating strategic issues to the Board.
  • Reviewing and approving Standard Operating Procedures (SOPs), system configurations, and significant changes to risk assessment models or customer frameworks.
  • Reviewing and approving material changes to the Transaction Monitoring Rulebook.
  • Authorizing remediation plans for identified control weaknesses and monitoring their execution.
  • Reviewing significant STRs, sanctions hits, and regulatory engagement outcomes before submission to the Board (where Board visibility is required).
  • Approving relationships with high-risk customers, jurisdictions, or product offerings that exceed defined risk thresholds.
  • Monitoring compliance with VASP licensing conditions and regulatory commitments.
  • Reviewing settlement partner due diligence assessments and approving new settlement partnerships.
  • Overseeing the implementation of corrective actions arising from regulatory examinations or internal/external audits.

5.3 Anti-Money Laundering Compliance Officer (AMLCO)

The AMLCO is the senior compliance professional responsible for the day-to-day operation of the AML/KYC programme. The AMLCO shall:

  • Exercise operational authority over the AML program, subject to Board policy and management oversight.
  • Receive internal suspicious activity reports and allegations from staff, agents, and systems; conduct or commission investigations and determine whether an STR should be filed with the competent FIU(s) (e.g., the NFIU/goAML) or other competent authority.
  • Maintain and update the Company's enterprise risk assessments, customer risk ratings, and the transaction monitoring rulebook.
  • Provide regular reports to the Management Committee and the Board, including metrics on onboarding, transaction monitoring, STR volumes, regulatory developments, and audit findings.
  • Retain independent copies of CDD files, investigation documentation, and regulatory correspondence for the retention periods required under this Policy.
  • Be accessible to regulators and law enforcement and coordinate the Company's regulatory reporting obligations, including STR filings, regulatory notifications, and responses to information requests.
  • Have the authority to impose interim account restrictions or holds in circumstances that reasonably indicate ML/TF risk pending investigation.
  • Lead the design and delivery of AML/CFT training programmes for staff and agents.
  • Coordinate with the Data Protection Officer on matters involving the processing of personal data for AML/CFT purposes.
  • Serve as the primary point of contact for regulatory inquiries, examinations, and enforcement actions.
  • Maintain awareness of emerging AML/CFT risks, typologies, and regulatory developments, and recommend policy updates accordingly.
  • Approve all Travel Rule data transmission protocols and VASP counterparty relationships.
  • Review and approve enhanced due diligence measures for high-risk customers and transactions.

The AMLCO must have sufficient seniority, independence, and resources to effectively discharge these responsibilities. The AMLCO shall report directly to the Board or a designated Board committee and shall have unfettered access to senior management, the Board, and all Company records necessary for AML/CFT purposes.

5.4 Internal Operations Units

All internal functions of the Company have specific AML/CFT responsibilities:

  • Business and Product Teams: Embed risk-based CDD requirements into product design and user journeys; ensure product changes are reviewed for AML impacts before release; participate in business-wide risk assessments; ensure customer-facing materials communicate KYC requirements clearly.
  • Customer Operations: Execute CDD processes; manage remediation requests; maintain accurate customer records and evidence; conduct periodic customer reviews; escalate unusual activity or documentation concerns; respond to customer inquiries regarding KYC requirements.
  • IT/Security: Deploy and maintain transaction monitoring systems; secure identity and biometric data storage; implement logging and ensure encryption and access controls; maintain system uptime and data integrity; support implementation of Travel Rule technology solutions; ensure cybersecurity measures protect AML/CFT systems and data.
  • Compliance Analysts/Monitoring Team: Manage alerts generated by transaction monitoring systems; conduct investigations; make recommendations to the AMLCO; document outcomes; maintain case management records; support STR preparation; conduct sanctions and PEP screening.
  • Legal: Advise on sanctions, data protection, regulatory notifications, and relevant legal issues; coordinate with external counsel as required; review and approve customer terms and conditions from an AML/CFT perspective; support regulatory examinations and enforcement proceedings.
  • Finance: Ensure accurate recordkeeping of transaction data; support investigation of unusual transaction patterns; maintain audit trails for financial transactions; coordinate with external auditors on AML/CFT matters.
  • Human Resources: Conduct background checks on employees in accordance with this Policy; support AML/CFT training delivery and recordkeeping; implement whistleblower protection procedures.

5.5 Internal Audit and External Assurance

Internal Audit will perform independent and objective reviews of the AML/KYC programme at least annually. The internal audit shall assess:

  • The adequacy and effectiveness of AML/CFT policies and procedures
  • Compliance with regulatory requirements and internal policies
  • The effectiveness of customer due diligence procedures
  • The accuracy and completeness of STR filings
  • The performance and calibration of transaction monitoring systems
  • The adequacy of staff training and awareness
  • The security of customer data and biometric information
  • The effectiveness of sanctions screening procedures
  • Compliance with Travel Rule requirements for virtual asset transfers
  • Due diligence performed on settlement partners and third-party service providers

Where appropriate, the Company will engage an external specialist to undertake independent validation of the transaction monitoring system, risk assessment methodology, and data security model. Audit findings and remediation timelines are tracked by the Management Committee and reported to the Board.

5.6 Transaction Monitoring Rulebook

The Company shall maintain a controlled "Transaction Monitoring Rulebook" developed by the AMLCO in conjunction with Legal and Compliance functions. The Rulebook shall document:

  • All monitoring rules, scenarios, and thresholds deployed in the transaction monitoring system
  • The rationale for each rule, including relevant typologies and risk indicators
  • Threshold calibration methodology and periodic review results
  • Alert scoring and prioritization criteria
  • Expected alert volumes and acceptable false positive rates
  • Rule performance metrics and quality assurance procedures
  • Processes for rule tuning, back-testing, and validation

Material changes to the Rulebook require the approval of the AMLCO and the Management Committee. The Rulebook shall be reviewed and updated at least annually, or more frequently in response to emerging risks, regulatory guidance, or system performance issues.

5.7 Whistleblowing

The Company shall maintain a confidential reporting channel accessible to all staff, agents, and third parties for the submission of compliance concerns. Key features include:

  • Multiple reporting channels (email, hotline, online portal) to ensure accessibility
  • Anonymous reporting options where permitted by law
  • Strict non-retaliation policy ensuring that reports can be made without fear of adverse action
  • Clear escalation procedures for different types of concerns
  • Defined response timelines for acknowledging and investigating reports
  • Confidentiality protections for whistleblowers and reported information

All reports specifically related to potential AML/CFT violations or financial crime shall be immediately routed to the AMLCO for review. The AMLCO shall conduct an independent and prompt investigation of all substantive reports, escalating critical findings to the Board of Directors where necessary. Retaliation against whistleblowers is strictly prohibited and will result in disciplinary action up to and including termination of employment or contractual relationships.

6. RISK-BASED APPROACH (RBA)

The Company applies a documented Risk-Based Approach (RBA) consistent with FATF guidance and Nigerian regulatory requirements. This approach requires the Company to:

  • Identify and assess AML/CFT risks across customer types, products, channels, technologies, and geographies
  • Allocate resources proportionate to identified risks
  • Implement controls and procedures commensurate with the assessed risk levels
  • Periodically (at least annually or as needed) re-assess and adjust controls as the business evolves
  • Document risk assessments, risk treatment decisions, and the rationale for risk tolerance levels

6.1 Risk Assessment

The Company shall conduct comprehensive risk assessments at multiple levels:

  • Enterprise-Wide Risk Assessment: Annual assessment of the Company's overall exposure to ML/TF risk, considering the company's business model, products, customer base, geographic footprint, and operational environment.
  • Product and Service Risk Assessment: Evaluation of ML/TF risks associated with specific products and services, conducted before product launch and reviewed annually.
  • Customer Risk Assessment: Individual risk scoring for each customer based on defined risk factors.
  • Transaction Risk Assessment: Real-time or near-real-time evaluation of transaction risk through automated monitoring systems and manual review procedures.
  • Geographic Risk Assessment: Assessment of ML/TF risks associated with specific countries and jurisdictions, updated at least annually.

Customer risk assessments shall consider the following risk factors:

  • Customer type (individual/corporate/trust): Higher weight for complex legal entities and trust structures
  • Customer profile: Occupation, industry sector, source of wealth, business activities
  • Transaction profile: Expected transaction volumes, transaction patterns, use of products and services
  • Jurisdiction risk: Country of residence, incorporation, citizenship, principal place of business, and countries involved in customer's business or transaction patterns, based on the Company's jurisdictional risk matrix (reviewed annually)
  • Channel risk: Method of onboarding (remote vs. in-person, agent-assisted vs. self-service)
  • Product risk: Types of products and services used by the customer
  • Behavioral risk: Deviations from expected transaction patterns, velocity, geographic patterns
  • Crypto-specific risk: Use of privacy coins, mixing services, peer-to-peer platforms, unregulated exchanges, complex on-chain transaction patterns
  • Politically Exposed Person (PEP) status
  • Sanctions or adverse media exposure

The Company shall maintain a customer risk scoring model (numeric or categorical) used consistently by onboarding and monitoring workflows to assign customers to Low, Medium, or High risk categories. High-risk assignments trigger Enhanced Due Diligence (EDD) and require senior management approval before account activation.

6.2 Risk Treatment

For each identified risk, the Company shall select an appropriate treatment strategy:

  • Accept: Risk is within tolerance and no additional controls are required beyond standard procedures.
  • Mitigate: Additional controls are implemented to reduce risk to an acceptable level (e.g., enhanced monitoring, transaction limits, additional verification).
  • Transfer: Risk is transferred to a third party (e.g., through insurance, outsourcing with contractual protections).
  • Avoid: Relationship or activity is declined or terminated because risk cannot be adequately mitigated.

Product and Channel Risk: Different products and channels present differing risks. The Company shall maintain a product risk register that documents the AML risk rating and controls for each product:

  • Virtual asset wallets and custody services: Medium to High risk due to potential for anonymity and cross-border movement
  • Cross-border remittances: High risk due to jurisdictional complexity and potential for trade-based money laundering
  • Crypto-to-fiat exchange: High risk due to potential integration of illicit funds into the regulated financial system
  • Merchant payment processing: Medium risk depending on merchant risk profile
  • Agent-assisted onboarding: Higher risk than self-service due to potential for collusion or fraud

Crypto/On-Chain Risk: The Company's risk assessment shall explicitly include crypto-specific factors such as use of mixing or tumbling services, transactions involving privacy coins (Monero, Zcash, etc.), connections to darknet markets or sanctioned addresses, rapid movement across multiple chains or bridges, deposits from or withdrawals to unhosted wallets, patterns indicative of layering or structuring, and interaction with high-risk DeFi protocols or unregulated exchanges.

Where such risk indicators are present, the Company will adopt stricter monitoring, apply blockchain analytics tools, escalate for Enhanced Due Diligence, and potentially restrict or decline the relationship. The Company shall adhere to the Travel Rule (FATF R.16) for virtual asset transfers meeting applicable jurisdictional thresholds, using the IVMS-101 data standard.

6.3 Risk Appetite

The Board sets the overall AML risk appetite for the Company and provides guidance on risk tolerance thresholds. The Company's risk appetite statement includes:

  • Zero tolerance for relationships with sanctioned individuals, entities, or jurisdictions
  • Zero tolerance for knowingly facilitating money laundering or terrorist financing
  • Low tolerance for high-risk customers or jurisdictions unless mitigating controls are in place
  • Willingness to serve underbanked populations through tiered KYC frameworks, subject to appropriate risk controls
  • Commitment to financial inclusion balanced against sound AML/CFT risk management
  • Defined thresholds for declining or exiting customer relationships based on unmitigatable risk

Mitigating controls (EDD, transaction limits, enhanced monitoring) must be documented and tested. Transaction and account limits are set well below regulatory thresholds to ensure a margin of safety and regulatory defensibility.

7. CUSTOMER DUE DILIGENCE (CDD)

Customer Due Diligence (CDD) is the process of identifying and verifying customer identity, commonly referred to as KYC/KYB (Know Your Customer/Know Your Business). CDD must be performed in a manner that is risk-sensitive, auditable, and compliant with applicable laws. Depending on risk, the Company may apply:

  • Simplified Due Diligence (SDD): For clearly low-risk scenarios where permitted by law and regulation.
  • Standard CDD: For normal risk customers.
  • Enhanced Due Diligence (EDD): For high-risk customers, PEPs, high-risk jurisdictions, or unusual transactions.

7.1 Documentary CDD Onboarding Workflow

The standard documentary CDD workflow consists of the following steps:

Collection: Capture mandatory identity fields.

For Individuals:

  • Full legal name (as appears on government-issued ID)
  • Date of birth
  • Nationality/citizenship
  • Residential address with proof of address (utility bill, bank statement, government correspondence dated within 3 months)
  • Government-issued photo ID (International Passport, National ID card, driver's license, or other valid local means of identification)
  • National ID number or equivalent unique identifier
  • Selfie + liveness check for remote onboarding
  • Contact information (phone number, email address)
  • Occupation and source of funds/wealth
  • Purpose of account and anticipated transaction activity

For Corporate Entities:

  • Full registered legal name of entity
  • Company registration number and certificate of incorporation from competent registry
  • Constitutional documents (Memorandum and Articles of Association, Partnership Agreement, Trust Deed, etc.)
  • Certificate of Good Standing or equivalent (if available)
  • Registered address and principal place of business
  • List of directors, authorized signatories, and senior management
  • Beneficial ownership information (see Section 10)
  • Business license or regulatory permits (where applicable)
  • Evidence of business activity (audited financial statements, business plan, website, commercial invoices)
  • Source of funds and anticipated transaction patterns
  • Resolution authorizing account opening and identifying authorized persons

Verification: Verify each identity element against independent sources, including:

  • Government databases and national ID verification systems (where accessible and reliable)
  • Electronic identity verification (eIDV) providers with data from credit bureaus, telecom providers, or government databases
  • Bank verification through reference letters or account statements
  • Corporate registry searches and certificates
  • Third-party databases (for PEP screening, sanctions lists, adverse media)
  • Document authentication (security features, forensic analysis where necessary)

When using electronic verification, the Company preserves vendor output, transaction IDs, and data sources used. All verification steps must be documented and retained.

Risk Rating: Apply the customer risk scoring model (see Section 6) and assign an initial risk category (Low, Medium, High).

File Assembly: Compile the complete CDD file including copies of all identity documents, verification reports and transaction logs, risk assessment and risk score, source of funds/wealth documentation, PEP and sanctions screening results, and approval records and sign-offs. All documentation must be retained in a secure, immutable format accessible to the AMLCO, compliance staff, auditors, and regulators.

Approval: Customers categorized as Medium or High risk require compliance or AMLCO approval before account activation. Low-risk customers may be approved through automated workflows, subject to periodic quality assurance review.

7.2 Remote/Non-Face-to-Face Onboarding Controls

Where remote onboarding is used (mobile app, web portal), additional safeguards are required:

  • Multi-factor identity verification combining document verification, biometric verification, and data verification
  • Liveness detection to prevent spoofing with photos or videos
  • Document verification using optical character recognition (OCR) and security feature detection
  • Device fingerprinting and behavioral biometrics
  • Geo-fencing to detect VPN use or location spoofing
  • National ID database linkage where available and permitted
  • Enhanced monitoring during initial transaction period
  • Transaction limits during probationary period

Any remote onboarding that cannot achieve the required verification confidence shall be temporarily restricted or require in-person verification. Video-based verification may be used where appropriate, with recordings retained as part of the CDD file.

7.3 Ongoing Verification and Update Triggers

CDD information must be kept current through periodic reviews and event-driven updates:

  • Material changes to customer profile (change in ownership, address, business activities, beneficial ownership)
  • Significant changes in transaction patterns or account behavior
  • Customer request to increase transaction limits or access new products
  • Detection of adverse information (sanctions listing, PEP designation, adverse media)
  • Periodic review based on risk category: High risk (annually), Medium risk (every 2 years), Low risk (every 3 years)
  • Regulatory changes affecting customer classification
  • Expiration of identity documents
  • Failed periodic screening (PEP, sanctions)

Where verification evidence becomes stale, inconsistent, or suspicious, re-verification is required. Temporary account restrictions may be imposed pending successful re-verification.

7.4 Identification Evidence & Source Hierarchy

The Company prefers primary and official sources of verification in the following order of reliability:

  • Government registries and national ID databases (where accessible, reliable, and legally permissible)
  • Government-issued identity documents (passport, national ID, driver's license)
  • Bank records and references from regulated financial institutions
  • Certified or notarized documents from competent authorities
  • Reputable electronic verification vendor outputs (retain vendor logs, response data, transaction IDs)
  • Secondary evidence (utility bills, employer letters, tax documents) only where higher standards are unavailable and risk is low

Documents from high-risk jurisdictions, those in non-Latin scripts, or those lacking standard security features require additional corroboration (certified translations, apostille, registry confirmations, enhanced verification). Documents that are forged, expired, damaged, or unverifiable must be rejected and shall result in refusal of onboarding or account restriction pending resolution.

8. TIERED CUSTOMER FRAMEWORK

The Company operates a tiered framework that balances financial inclusion objectives with robust AML/CFT controls. The tiered approach allows customers to access progressively higher daily transaction limits as they complete higher levels of verification.

8.1 Tier 0 - Basic Entry

Purpose: Entry-level tier assigned automatically to every new account, allowing basic account functionality with minimal barriers to entry.

Verification Requirements: Email verification and account PIN setup.

Daily Transaction Limit: ₦50,000.

Monitoring: Standard transaction monitoring, with escalation for velocity or pattern anomalies.

8.2 Tier 1 - Standard Verification

Purpose: Standard tier for identity-verified customers with moderate transaction needs.

Verification Requirements: Successful BVN and NIN identity verification.

Daily Transaction Limit: ₦500,000.

Upgrade Requirements: Complete BVN and NIN verification, pass PEP and sanctions screening.

8.3 Tier 2 - Business Verified

Purpose: Full-featured tier for verified business customers with significant or unlimited transaction needs.

Verification Requirements: Business verification, including confirmation of company registration (CAC) and supporting business documentation, in addition to completed Tier 1 identity verification.

Daily Transaction Limit: Unlimited, subject to ongoing monitoring and the Company's right to impose case-specific limits based on risk assessment.

Upgrade Requirements: Enhanced due diligence documentation, business verification, compliance review, and approval.

All tier limits are subject to regulatory maximums and may be adjusted based on regulatory guidance, risk appetite changes, or individual customer risk assessments. Customers may be downgraded to lower tiers, or have limits reduced on a case-by-case basis, if they fail to maintain current KYC information or if risk factors increase.

9. ONGOING MONITORING, ALERT MANAGEMENT & INVESTIGATION

The Company maintains a risk-based ongoing monitoring framework combining automated transaction monitoring systems with manual review to identify activity inconsistent with customer profiles, regulatory thresholds, or known money-laundering and terrorist-financing typologies.

9.1 Transaction Monitoring Framework

Transaction monitoring rules are documented in a formal Rulebook and are calibrated based on customer risk, product, channel, and jurisdiction. Monitoring covers fiat and virtual asset transactions and includes the following core controls:

Sanctions and PEP Screening: All customers, transactions, counterparties, and wallet addresses are screened in real time against applicable sanctions and PEP lists. Positive or potential sanctions matches trigger immediate transaction holds and escalation to the AMLCO. Transactions do not proceed until clearance is obtained.

Threshold and Velocity Monitoring: Automated rules identify single large transactions, cumulative transaction velocity, rapid succession activity, tier limit breaches, and structuring indicators, with lower thresholds applied to higher-risk customers.

Behavioral and Pattern Analysis: Monitoring detects anomalies such as unexpected geographic activity, dormant accounts followed by high activity, profile-inconsistent transactions, repeated failed transactions, beneficiary concentration, and circular transaction patterns indicative of layering.

Virtual Asset-Specific Monitoring: Enhanced controls address crypto-specific risks, including exposure to mixers, privacy coins, sanctioned or illicit addresses, rapid chain hopping, high-risk DeFi interactions, unhosted wallet activity, peel chains, and dusting patterns. Blockchain analytics tools support enhanced due diligence and escalation decisions.

Travel Rule Monitoring: Virtual asset transfers are monitored for compliance with Travel Rule requirements, including missing or inconsistent originator/beneficiary data, counterparty VASP failures, and structuring to evade reporting thresholds.

Agent and Channel Monitoring: Agent performance, onboarding patterns, device and biometric indicators, and geographic inconsistencies are monitored to identify agent misconduct, collusion, or account-farming risks.

9.2 Alert Management

Alerts are risk-rated, prioritized, and assigned to qualified analysts based on severity and required response times. Critical alerts (e.g., sanctions, terrorism financing) require immediate action, transaction holds, and AMLCO notification. High, medium, and low alerts are reviewed within defined timeframes, documented, and escalated where suspicion develops.

Alert volumes, resolution times, false positives, and STR conversion rates are tracked and reported to management and the Board.

9.3 Investigation Procedures

All alerts are investigated using a standardized, risk-based process. Investigations include review of customer CDD, transaction history, counterparties, sanctions/PEP/adverse media screening, and behavioral analysis against known typologies. External information may be obtained and customers contacted where appropriate, without tipping off.

Each investigation concludes with a documented outcome, including no further action, enhanced monitoring, account controls, STR filing, or account termination. All conclusions require supervisory or AMLCO review, with STR decisions made exclusively by the AMLCO.

9.4 Escalation and Governance

Defined escalation triggers require immediate AMLCO and senior management notification, including sanctions hits, terrorism financing indicators, large unexplained transactions, PEP breaches, systemic control failures, agent misconduct, regulatory inquiries, and reputational risk events.

Material incidents are reported to the Management Committee within 24 hours and to the Board, together with remediation plans and control enhancements.

10. BENEFICIAL OWNERSHIP

The Company maintains a robust framework to identify, verify, and monitor the natural persons who ultimately own or control legal entity customers, in order to prevent the misuse of corporate structures, trusts, and similar arrangements for financial crime.

A Beneficial Owner is any natural person who owns or controls 25% or more of ownership or voting rights, directly or indirectly; exercises control through other means; or, where no such person exists, is a senior managing official. Lower ownership thresholds may be applied for higher-risk customers or jurisdictions.

10.1 Identification and Verification

Beneficial ownership is established through:

  • Formal declarations certified by authorized officers.
  • Identity verification of each beneficial owner to individual-customer standards, including sanctions and PEP screening.
  • Verification of ownership structures using reliable documentary evidence.
  • Assessment of control mechanisms beyond ownership.
  • Tracing ownership chains to natural persons, with a maximum acceptable depth of four layers (subject to AMLCO approval for exceptions).

Special arrangements such as publicly listed companies, government-owned entities, trusts, foundations, and nominee structures are addressed using tailored procedures.

10.2 Documentary Evidence

The Company relies on reliable, independent, and verifiable sources, prioritizing official corporate registry records. Enhanced corroboration is required for jurisdictions with weak transparency or elevated corruption risk.

10.3 Ongoing Monitoring and Re-Verification

Beneficial ownership information is kept accurate and up to date through:

  • Customer obligations to notify material changes within 30 days
  • Periodic re-verification based on risk (annual for high risk, biennial for medium, triennial for low)
  • Event-driven reviews triggered by changes in risk profile, ownership, transaction behavior, or adverse information

10.4 Escalation and Risk Mitigation

Inability to reasonably identify or verify beneficial owners is escalated to the AMLCO and may result in:

  • Enhanced Due Diligence
  • Transaction restrictions or limits
  • Risk re-rating
  • Refusal of onboarding or relationship exit
  • Consideration of STR filing where concealment appears deliberate

Attempts to obscure ownership through complex or nominee arrangements are treated as high-risk indicators.

10.5 Trusts and Foundations

Trusts and foundations are generally classified as high risk. The Company identifies and verifies all relevant parties (settlors, trustees, protectors, founders, governing bodies, and beneficiaries) and applies Enhanced Due Diligence proportionate to the elevated risk.

11. POLITICALLY EXPOSED PERSONS (PEPs)

Politically Exposed Persons (PEPs) are individuals entrusted with prominent public functions who, by virtue of their position and influence, may present higher risk for potential involvement in bribery, corruption, and money laundering. The Company applies enhanced scrutiny and risk mitigation measures to all PEP relationships.

11.1 PEP Definition and Categories

For the purposes of this Policy, Politically Exposed Persons (PEPs) include individuals who are or have been entrusted with prominent public functions. This includes Foreign PEPs, Domestic PEPs (within Nigeria), and PEPs associated with international organizations. Categories cover senior political, governmental, judicial, military, and state-owned enterprise roles, as well as senior officials of international organizations.

PEPs also include family members and close associates (RCAs), such as spouses, children, parents, siblings, and individuals with close business relationships or beneficial ownership arrangements linked to a PEP.

11.2 PEP Identification and Screening

The Company identifies PEPs through a combination of initial onboarding screening, ongoing and event-driven screening, and periodic comprehensive re-screening of the customer base using reputable commercial PEP databases. Screening results, including negative findings, are documented.

Enhanced screening is applied to higher-risk customers through manual adverse media reviews, public record checks, and verification against official government sources. Customers are required to self-declare PEP status at onboarding, notify the Company of any subsequent changes, and annually reconfirm their PEP status.

11.3 Risk Assessment of PEPs

The Company applies a risk-based approach to PEP relationships, recognizing that not all PEPs present the same level of risk. Risk assessments consider factors such as level of authority, function type, country corruption risk, time elapsed since leaving office, nature of the relationship, source of wealth and funds, expected activity, adverse media, and sectoral exposure.

Based on these factors, PEPs are classified as high, medium, or lower risk. Higher-risk classifications typically include foreign PEPs, PEPs from high-corruption jurisdictions, and those with adverse media or corruption allegations, while lower-risk classifications may apply to long-former PEPs or RCAs with independent and transparent sources of wealth.

11.4 Enhanced Due Diligence for PEPs

All PEP relationships are subject to Enhanced Due Diligence (EDD) proportionate to assessed risk. This includes documented approval by the AMLCO and senior management prior to onboarding, with Board approval for higher-risk cases.

EDD measures include enhanced verification of source of wealth and source of funds, intensified ongoing monitoring with lower thresholds, continuous adverse media surveillance, periodic comprehensive relationship reviews, and restrictions on access to higher-risk products or services. Comprehensive records are maintained to evidence screening results, approvals, monitoring activities, and investigative findings.

11.5 Escalation and Exit Procedures

The Company shall escalate and exit PEP relationships where credible corruption risks, sanctions exposure, refusal to provide required information, or unacceptable reputational or regulatory risk is identified. Prior to exit, the AMLCO assesses whether an STR filing is required.

Relationship termination is conducted in accordance with applicable laws and in a manner that avoids tipping off where suspicious activity is suspected.

12. ENHANCED DUE DILIGENCE (EDD)

Enhanced Due Diligence (EDD) consists of additional risk-mitigating measures applied to customers, transactions, products, or jurisdictions that present higher money laundering or terrorist financing risk. EDD supplements standard CDD with deeper verification, more intensive monitoring, and additional approvals.

12.1 When EDD is Required

Enhanced Due Diligence is mandatory where the customer, beneficial owner, transaction, or relationship presents elevated ML/TF or sanctions risk. This includes PEPs and their relatives or close associates, customers linked to high-risk jurisdictions, complex or opaque ownership structures, high-risk sectors, adverse media or regulatory exposure, unusual or inconsistent transactions, high-value service upgrades, correspondent banking or VASP relationships, non-face-to-face onboarding with insufficient verification, unexplained wealth indicators, refusal or inconsistency in information provided, and unresolved sanctions screening matches.

12.2 EDD Measures

EDD measures are applied proportionately to the identified risks and may include enhanced verification, deeper understanding of the business relationship, intensified monitoring, senior management oversight, and restrictions on products, services, or transactions.

12.2.1 Enhanced Identity Verification

The Company applies strengthened identity controls, including certified identification documents, in-person or video verification, biometric and multi-source verification, background checks (where lawful), and independent verification of employment, credentials, and business activities.

12.2.2 Source of Wealth and Source of Funds Verification

The Company establishes and verifies the legitimate origin of both the customer's overall wealth and specific transaction funds using reliable documentation such as tax records, audited financials, employment income, asset ownership and sale records, inheritance or gift documentation, investment statements, loan agreements, and customer explanations supported by evidence.

12.2.3 Enhanced Business Relationship Understanding

EDD includes obtaining a detailed understanding of the purpose and intended use of the account, expected transaction behavior, geographic exposure, counterparties, business model, and economic rationale for complex or unusual structures.

12.2.4 Enhanced Ongoing Monitoring

EDD relationships are subject to lower monitoring thresholds, more frequent reviews, real-time or near-real-time transaction scrutiny, deeper transaction and counterparty analysis, continuous adverse media monitoring, and regular reporting to the AMLCO.

12.2.5 Senior Management Involvement

EDD relationships require documented AMLCO approval and, for the highest-risk cases, senior management or Board approval. Significant transactions may require pre-approval, and relationships are subject to periodic senior management review and escalation protocols.

12.2.6 Restrictions and Limits

Risk mitigation measures may include reduced transaction limits, restrictions or prohibitions on certain products or services, geographic limitations, cooling-off periods, prior notification requirements, and enhanced controls on transaction types.

12.3 Documentation and Record Keeping

EDD cases require comprehensive documentation, including the rationale for EDD, information collected, verification steps, risk assessments, approval records, tailored monitoring plans, review outcomes, customer explanations, adverse media findings, and exit analyses. EDD files are maintained securely with restricted access.

12.4 Special EDD Scenarios

Specific enhanced measures apply to certain high-risk contexts.

12.4.1 High-Risk Jurisdictions

EDD includes verification of legitimate business rationale, enhanced sanctions and PEP screening, confirmation of required licenses, review of supporting commercial documentation, enhanced correspondent banking due diligence, and lower thresholds for STR consideration.

12.4.2 Non-Face-to-Face / Remote Onboarding EDD

EDD measures include enhanced biometric and video verification, multi-database checks, lower initial limits with graduated increases, intensified early-stage monitoring, and possible in-person verification for high-value relationships.

12.4.3 Crypto-Specific EDD

For virtual asset activity, EDD includes blockchain analysis, source tracing, verification of asset acquisition, scrutiny of privacy-enhancing assets, wallet disclosure requirements, restrictions on high-risk protocols, and enhanced Travel Rule compliance.

13. SANCTIONS, WATCHLISTS & BLOCKING PROCEDURES

13.1 Applicable Sanctions Regimes

The Company complies with all applicable international and national sanctions regimes, including UNSC, OFAC, EU, UK, Nigerian sanctions, terrorism lists, and other relevant jurisdictional sanctions.

13.2 Screening Scope and Frequency

Sanctions screening applies to customers, beneficial owners, directors, counterparties, correspondents, third parties, virtual asset addresses, and relevant trade-related assets. Screening is conducted in real time for transactions, continuously against updated lists, on an event-driven basis, and through periodic full re-screening.

13.3 Screening Methodology

The Company uses automated screening systems with reputable databases, blockchain analytics, fuzzy matching, configurable thresholds, and multiple identifiers to balance false-positive management with detection effectiveness.

13.4 Hit Investigation and Disposition

All sanctions hits are promptly investigated. Transactions are immediately held, accounts restricted, and cases escalated to the AMLCO. Investigations assess identifiers, sanctions list details, ownership and control, adverse media, and supporting research. Outcomes are classified as true positives, false positives, or indeterminate cases requiring escalation.

13.5 Blocking Procedures for Confirmed Matches

Confirmed sanctions matches result in immediate asset freezing, transaction rejection, regulatory notification, legal consultation, strict non-tipping-off controls, detailed recordkeeping, and ongoing compliance until authorized release.

13.6 False Positive Management

The Company documents false positives, applies quality assurance reviews, optimizes screening parameters, trains investigators, and seeks to minimize customer impact while maintaining robust compliance.

13.7 Ownership and Control Sanctions Screening

The Company screens ownership and control structures and applies the OFAC 50% rule, tracing multi-layer ownership to identify sanctioned persons and blocking entities that meet sanctions thresholds.

13.8 Virtual Asset Address Screening

All virtual asset addresses are screened against sanctioned lists and analyzed for indirect exposure using blockchain analytics. Transactions involving sanctioned or high-risk addresses are blocked or escalated, with full documentation maintained.

13.9 Training and Awareness

Staff receive sanctions training at onboarding and annually thereafter, covering legal obligations, screening and investigation procedures, blocking requirements, tipping-off prohibitions, and emerging sanctions risks.

14. CROSS-BORDER TRANSACTIONS & TRAVEL RULE COMPLIANCE

As a provider of cross-border payment and remittance services, including virtual asset transfers, the Company is subject to enhanced regulatory requirements for international transactions.

14.1 Cross-Border Transaction Identification

A cross-border transaction is any transaction where the originator and beneficiary are located in different countries, funds or virtual assets are transferred from one jurisdiction to another, the transaction involves a foreign currency exchange, or the transaction involves a counterparty institution in a foreign jurisdiction.

14.2 Enhanced Due Diligence for Cross-Border Transactions

Cross-border transactions require additional due diligence, including purpose of transaction and relationship between originator and beneficiary, source of funds for the transaction, expected frequency and volume of cross-border transactions, jurisdiction risk assessment for both originating and destination countries, compliance with foreign exchange regulations in both jurisdictions, sanctions screening of all parties involved in the transaction chain, and correspondent banking due diligence where applicable.

14.3 Travel Rule Compliance (FATF Recommendation 16)

For virtual asset transfers meeting applicable thresholds, the Company is committed to complying with the FATF Travel Rule by obtaining, retaining, and transmitting required originator and beneficiary information. This section describes the Company's target operating model for Travel Rule compliance.

Implementation Status: Automated Travel Rule data exchange with counterparty VASPs, using a dedicated Travel Rule messaging solution, is not yet operational. Until such a solution is selected and integrated, the Company applies enhanced manual review and enhanced due diligence (see Section 12) to cross-border virtual asset transfers meeting or exceeding the applicable threshold, as a compensating control. Selection and integration of a dedicated Travel Rule solution provider is a near-term compliance priority and shall be reflected in this Policy once operational.

Data Collection Requirements (target model): For Originator: Full name, wallet address or account number, physical address. For Beneficiary: Full name, wallet address or account number. Additionally: transaction amount and virtual asset type, date and time of transaction, and transaction identifier (hash or reference number).

Threshold Application: The Travel Rule applies to virtual asset transfers meeting or exceeding USD $1,000 (or equivalent in other currencies) or as otherwise specified by applicable law in the relevant jurisdiction.

Data Transmission Standards (target model): Once implemented, the Company shall utilize the IVMS-101 data model for structuring and transmitting Travel Rule information using secure, encrypted messaging protocols compatible with counterparty VASPs.

Counterparty VASP Procedures (target model): Once implemented, the Company shall maintain a list of approved VASP counterparties, conduct due diligence on counterparty VASPs, establish secure communication channels for Travel Rule data exchange, monitor counterparty compliance, and retain records of all Travel Rule data transmissions and confirmations.

14.4 Unhosted Wallet Procedures

Transfers to or from unhosted (self-hosted, private) wallets present elevated ML/TF risk. The Company shall require enhanced customer due diligence for customers regularly transacting with unhosted wallets, implement lower transaction limits for unhosted wallet transactions, apply enhanced monitoring and blockchain analytics to unhosted wallet transactions, require customer attestation of beneficial ownership of the unhosted wallet, conduct blockchain analysis to identify risk indicators (mixing services, sanctioned addresses, darknet exposure), escalate all unhosted wallet transactions above specified thresholds to AMLCO for review, and consider prohibition of unhosted wallet transactions above certain risk or volume thresholds.

14.5 Foreign Exchange Controls Compliance

Where the Company operates in jurisdictions with foreign exchange controls (including Nigeria), the Company shall comply with all foreign exchange regulations, verify cross-border transactions comply with permitted purposes, maintain documentation of foreign exchange approvals where required, report cross-border transactions to regulatory authorities as required, implement controls to prevent evasion of foreign exchange regulations through cryptocurrency, and monitor for structured transactions designed to circumvent reporting thresholds.

14.6 Correspondent Banking and Payment Channel Due Diligence

Where the Company maintains correspondent banking relationships or utilizes payment channels for cross-border transactions, the Company shall conduct and document due diligence on each correspondent, including verification of regulatory licenses and good standing, assessment of AML/CFT controls and compliance history, review of ownership and management structure, evaluation of jurisdictional risk, understanding of customer base and business model, assessment of financial stability and reputation, contractual provisions requiring AML/CFT compliance and cooperation, ongoing monitoring of the correspondent relationship, and periodic reviews (at least annually for high-risk correspondents).

15. SUSPICIOUS TRANSACTION REPORTING (STR)

The Company is legally required under Nigerian AML/CFT laws to file Suspicious Transaction Reports (STRs) with the NFIU where there are reasonable grounds to suspect money laundering, terrorist financing, sanctions exposure, evasion of legal requirements, or transactions lacking lawful or economic purpose. The obligation arises based on suspicion, not proof, and applies even where transactions are attempted or incomplete.

15.2 Indicators of Suspicious Activity

The Company maintains a risk-based set of red flags covering general customer behavior, transaction anomalies, virtual asset activity, and cross-border transactions. Indicators include refusal or inconsistency in customer information, unusual transaction patterns, structuring, third-party involvement, complex or obfuscated virtual asset movements, darknet or mixer exposure, Travel Rule evasion, and unexplained cross-border flows. The presence of indicators triggers investigation but does not automatically require STR filing; assessment is based on the totality of circumstances.

15.3 Internal Reporting Procedures

All staff and relevant third parties must promptly report suspected suspicious activity through internal channels to their supervisor and the AMLCO. Reports must include relevant customer, transaction, and contextual details with supporting documentation. Reporting should not be delayed achieving certainty, and anonymous reporting is permitted where necessary.

15.4 Investigation Process

The AMLCO or designated compliance staff investigate all internal reports through a structured process, including CDD review, transaction and pattern analysis, sanctions and PEP screening, adverse media review, blockchain analysis where applicable, and customer engagement where appropriate without tipping off. Investigations are documented and concluded promptly, with urgent cases escalated immediately and standard cases completed within defined timelines.

15.5 STR Filing Procedures

Where suspicion is confirmed, STRs are prepared and submitted by the AMLCO via the NFIU goAML system. Reports include a clear narrative, relevant transaction details, supporting documentation, and urgency classification. STRs are filed within regulatory timelines, logged internally, and the affected accounts are flagged for enhanced monitoring, with periodic reporting to senior management and the Board.

15.6 Tipping-Off Prohibition

It is a criminal offense to disclose that an STR has been filed or is under consideration. Disclosure is strictly limited to authorized internal parties, legal counsel, competent authorities, and others permitted by law. Breaches may result in criminal, disciplinary, and contractual consequences.

15.7 Account Handling After STR Filing

STR filing does not automatically require account closure. Post-STR actions are risk-based and may include enhanced monitoring, transaction restrictions, gradual or immediate account closure, or continued operation, depending on risk, legal guidance, and potential facilitation of crime. Decisions are made by the AMLCO with legal and senior management input.

15.8 Regulatory Cooperation and Follow-Up

The Company cooperates fully with the NFIU and law enforcement following STR submission, responds to information requests, preserves records, continues monitoring, files supplemental STRs where necessary, and complies with lawful restraint or asset-freezing orders.

15.9 Record Retention

All STR-related records are retained securely for at least five years, with access restricted to authorized personnel. Records include STR filings, investigation materials, supporting evidence, regulatory correspondence, approvals, and post-STR monitoring documentation.

15.10 Staff Protection and Non-Retaliation

Staff who report suspicious activity in good faith are protected from retaliation, liability, or adverse treatment. The Company enforces strict non-retaliation measures and provides legal defense and indemnification where reports are made honestly and without malice.

16. THIRD-PARTY SERVICE PROVIDERS & SETTLEMENT PARTNERS

The Company relies on various third-party service providers and settlement partners to deliver its products and services. These relationships present potential AML/CFT risks that must be identified, assessed, and mitigated through robust third-party risk management procedures.

16.1 Scope of Third-Party Relationships

This section applies to all third parties that provide settlement, clearing, or custody services for customer funds or virtual assets; process payments or execute transactions on behalf of the Company or its customers; perform customer onboarding, identity verification, or KYC services; provide transaction monitoring, sanctions screening, or compliance technology; act as agents or representatives of the Company in customer-facing capacities; provide banking, financial, or liquidity services to the Company; serve as blockchain infrastructure providers, node operators, or oracle services; or provide fiat-crypto on/off-ramp services.

16.2 Third-Party Due Diligence Requirements

Before engaging any third-party service provider or settlement partner, the Company shall conduct comprehensive due diligence including corporate verification (certificate of incorporation, registration number, corporate structure, beneficial ownership, directors and officers, regulatory licenses and approvals), regulatory compliance (evidence of relevant regulatory licenses, compliance with applicable AML/CFT laws, regulatory examination history, enforcement actions or sanctions), AML/CFT program assessment (documented AML/CFT policies and procedures, KYC practices and standards, transaction monitoring capabilities, STR filing history, sanctions screening procedures, staff training programs), financial stability (financial statements, creditworthiness assessment, insurance coverage, business continuity and disaster recovery plans), operational capability (technical infrastructure and security measures, data protection and privacy controls, incident response procedures, service level agreements and performance metrics), reputation and integrity (adverse media screening, litigation history, beneficial owner and key management background checks, references from other clients or partners), and jurisdictional risk (assessment of the jurisdiction in which the third party is incorporated and operates, compliance with local AML/CFT requirements, ability to cooperate with regulatory requests).

16.3 Settlement Partner-Specific Requirements

Settlement partners (banks, payment processors, virtual asset exchanges, custodians) require enhanced due diligence due to their direct handling of customer funds or assets. Additional requirements include proof of segregation of client funds, evidence of adequate insurance, audit reports on internal controls (e.g., SOC 2, ISO 27001), procedures for handling customer complaints and disputes, reconciliation procedures and reporting capabilities, business continuity and disaster recovery testing results, cybersecurity assessment and penetration testing reports, proof of reserves or attestations for custodial services, and clear policies on handling of insolvent or defaulting customers.

16.4 Contractual Provisions

All third-party contracts shall include explicit requirements to comply with all applicable AML/CFT laws and regulations, obligations to maintain and provide evidence of adequate AML/CFT controls, right of the Company to audit or review third-party AML/CFT controls, requirements to promptly notify the Company of any regulatory action, breach, or material compliance issue, cooperation with regulatory or law enforcement requests, data protection and confidentiality obligations, right to terminate for AML/CFT compliance failures, indemnification for losses arising from third-party AML/CFT failures, and prohibition on sub-contracting critical functions without Company approval.

16.5 Ongoing Monitoring and Review

Third-party relationships require ongoing monitoring: annual review of high-risk third parties, biennial review of medium-risk third parties, triennial review of low-risk third parties, and event-driven reviews triggered by adverse media, regulatory actions, material breaches, service failures, or changes in ownership or management.

16.6 Termination and Transition

The Company shall maintain documented procedures for terminating third-party relationships and transitioning services, including criteria for mandatory termination, notice periods and transition planning, customer communication and service continuity measures, data return or destruction procedures, settlement of outstanding obligations, retention of records for regulatory compliance, and reporting to regulators where required.

17. DATA PROTECTION & RECORDS MANAGEMENT

The Company processes personal and sensitive data for AML/CFT purposes in compliance with the Nigeria Data Protection Act 2023 and, where applicable, GDPR. Processing is primarily based on legal obligation, supplemented by legitimate interests for fraud prevention and risk management. Consent is used only where processing is optional. Biometric data is treated as special category data and processed based on legal obligation.

17.2 Data Protection Principles

All AML/CFT data processing complies with core data protection principles, including lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation, security, and accountability. The Company can demonstrate compliance through documented controls and governance.

17.3 Data Security Measures

The Company implements robust technical and organizational safeguards, including encryption of personal data in transit and at rest, strict role-based access controls, multi-factor authentication, comprehensive logging and monitoring, network and physical security controls, and tested incident response procedures.

17.4 Biometric Data Handling

Enhanced safeguards apply to biometric data. Raw images are not stored; only irreversible cryptographic templates are retained. Biometric data is segregated, access-restricted, subject to DPIAs, reviewed regularly, and deleted upon account closure subject to legal retention requirements.

17.5 Data Subject Rights

The Company enables data subject rights under NDPA and GDPR, including access, rectification, restriction, objection, and erasure, subject to AML/CFT legal retention obligations. Statutory AML/CFT recordkeeping requirements take precedence over deletion requests.

Where consent is relied upon, it is explicit, informed, freely given, documented, and easily withdrawable. Withdrawal does not affect processing required by law. Biometric consent is obtained using standardized scripts and recorded.

17.7 Data Protection Officer

A designated Data Protection Officer (DPO) oversees compliance with data protection laws, advises on DPIAs, liaises with regulators, manages data subject requests, leads breach response, and works closely with the AMLCO.

17.8 Data Protection Impact Assessments

DPIAs are conducted for high-risk processing activities, including biometric verification, large-scale sensitive data processing, automated decision-making, and new technologies. DPIAs are approved by the DPO prior to implementation.

17.9 Cross-Border Data Transfers

Cross-border transfers are permitted only where appropriate safeguards exist, including adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or equivalent protections, supported by documented transfer risk assessments.

17.10 Data Breach Response

The Company maintains a structured breach response process covering detection, containment, assessment, regulatory notification within statutory timelines, customer notification where required, documentation, remediation, and Board escalation for material incidents.

18. STAFF TRAINING & MANAGEMENT

18.1 Training Framework

The Company operates a mandatory AML/CFT training program covering onboarding, role-specific training, annual refreshers, and specialized training for new products, jurisdictions, or incidents. Completion and competency are assessed and reported to the Board.

18.2 Training Content

Training covers AML/CFT laws, Company policy, CDD, PEPs, suspicious activity recognition, STR reporting, sanctions compliance, data protection, recordkeeping, and practical case studies.

18.3 Training Delivery Methods

Training is delivered through e-learning, workshops, webinars, on-the-job training, and external programs, ensuring accessibility and effectiveness across roles.

18.4 Assessment and Competency

All training includes assessments with defined pass marks. Failures trigger remedial training, escalation, and potential role restrictions until competency is demonstrated.

18.5 Training Records

Comprehensive training records are maintained for at least five years post-employment and made available for regulatory review.

18.6 Background Checks and Screening

All staff undergo pre-employment screening, including identity, employment history, criminal checks (where lawful), sanctions and PEP screening. Enhanced checks apply to high-risk roles.

18.7 Ongoing Staff Monitoring

The Company conducts periodic integrity monitoring, including sanctions screening, conflict-of-interest reviews, and investigation of credible misconduct allegations.

18.8 Consequences of Non-Compliance

Disciplinary actions for AML/CFT breaches are proportionate to severity and may include retraining, suspension, termination, and regulatory or law enforcement reporting.

18.9 Agent Training

Agents receive mandatory AML/CFT and data protection training prior to onboarding customers, with quarterly refreshers and ongoing quality assurance.

19. ASSURANCE & CONTINUOUS IMPROVEMENT

19.1 Internal Audit

Independent internal audits assess AML/CFT governance, risk assessment, CDD, monitoring, STRs, sanctions, training, data protection, and third-party management at least annually.

19.2 External Assurance

The Company engages independent external reviewers for AML audits, system validations, penetration testing, blockchain analytics reviews, and data protection audits at defined intervals.

19.3 Quality Assurance Reviews

Ongoing QA reviews test CDD quality, investigations, agent onboarding, high-risk relationships, and STR handling, with findings tracked and remediated.

19.4 Regulatory Examinations

The Company cooperates fully with regulators, responds promptly to findings, implements remediation plans, and reports progress to senior management and the Board.

19.5 Continuous Improvement Process

Issues identified through audits, incidents, regulatory feedback, or monitoring are assessed, prioritized, remediated, validated, documented, and reported through a structured process.

19.6 Technology Enhancement

AML/CFT technology is continuously evaluated and upgraded to improve monitoring effectiveness, analytics, screening accuracy, automation, and data integration.

19.7 Industry Engagement

The Company participates in industry forums, regulatory consultations, and information-sharing initiatives to stay aligned with emerging risks and best practices.

19.8 Lessons Learned

Insights from incidents, STRs, audits, enforcement actions, and operational issues are documented, reviewed, embedded into controls, and used for training and policy updates.

19.9 Performance Metrics and KRIs

The Company tracks operational, quality, risk, and compliance metrics, trends them over time, and reports them quarterly to management and the Board, with adverse trends triggering corrective action.

20. RECORD RETENTION, AUDIT TRAIL & E-DISCOVERY READINESS

The Company maintains comprehensive records to support regulatory compliance, facilitate audits and examinations, respond to law enforcement requests, and defend against potential litigation.

20.1 Retention Periods

The following minimum retention periods apply:

  • Customer Identity Records: 5 years after account closure or termination of business relationship
  • Beneficial Ownership Records: 5 years after account closure or termination
  • Transaction Records: 5 years after transaction date
  • Account Statements and Correspondence: 5 years after creation date
  • Suspicious Transaction Reports (STRs): 5 years after filing
  • Investigation Files: 5 years after case closure
  • Sanctions Screening Records: 5 years after screening date
  • Training Records: 5 years after training completion
  • Audit Reports and Findings: 7 years after report date
  • Regulatory Correspondence: 7 years after correspondence date
  • Contracts with Third Parties: 7 years after contract termination
  • Travel Rule Data: 5 years after transmission
  • Board and Committee Minutes: Permanent retention

Where law requires longer retention, the longer period applies. Records subject to legal hold or ongoing investigation shall be retained until the hold is lifted or the matter is resolved.

20.2 Audit Trail Requirements

The Company maintains comprehensive audit trails documenting user access to customer records and systems (who, what, when, where), changes to customer information or risk ratings (before/after states, approver, timestamp), transaction approvals and overrides, alert generation, investigation, and disposition, STR decisions and filings, system configuration changes, policy and procedure updates, training completion and assessment results, and third-party due diligence and reviews.

Audit trails must be tamper-evident, with controls preventing unauthorized deletion or modification. Access to audit logs is restricted to authorized personnel and monitored for suspicious activity.

20.3 E-Discovery Readiness

The Company maintains procedures for responding to lawful data requests from regulators, law enforcement, and courts, including a legal hold process to suspend normal deletion for records relevant to litigation, investigation, or regulatory action, centralized tracking of legal holds and affected data sets, defined roles and responsibilities for data production, search and retrieval capabilities across all data repositories, data export capabilities in commonly accepted formats, chain of custody documentation for produced records, privilege review procedures, and response time commitments based on request type and urgency.

21. POLICY REVIEW

This Policy shall be reviewed and updated regularly to ensure continued effectiveness and compliance:

  • Annual comprehensive review by the AMLCO and Management Committee
  • Ad hoc reviews triggered by material regulatory changes, significant business expansion or product launches, serious compliance incidents, regulatory examination findings, significant changes to ML/TF risk environment
  • Material changes require Board approval before implementation
  • All changes documented with version control and change logs
  • Updated policy distributed to all staff, agents, and relevant third parties
  • Training provided on material changes
  • The AMLCO maintains a Policy Change Log documenting the date, nature, and rationale for all amendments.

Appendix A: Jurisdictional Compliance Matrix

The following matrix maps the Company's primary operational jurisdictions to applicable legal and regulatory requirements.

Nigeria (Primary Jurisdiction): Applicable Laws include the Money Laundering (Prevention & Prohibition) Act 2022, Terrorism (Prevention) Act 2022, EFCC Act 2004, NFIU Act 2018, NDPA 2023, CBN Guidelines, and SEC Rules on Digital Assets. Competent Authorities include the Central Bank of Nigeria (CBN), Securities & Exchange Commission (SEC), Nigerian Financial Intelligence Unit (NFIU), Economic & Financial Crimes Commission (EFCC), and Nigeria Data Protection Commission (NDPC). Key Requirements include VASP licensing (SEC), Payment service provider license (CBN), STR filing via goAML, Travel Rule compliance, and Data protection compliance.

Note: As the Company expands to additional jurisdictions, this matrix will be updated to reflect applicable requirements in each operational jurisdiction.

Appendix B: Virtual Asset Service Provider (VASP) License Requirements

As a Virtual Asset Service Provider, the Company is subject to specific licensing requirements in each jurisdiction where it operates.

B.1 Nigeria VASP Regulatory Framework

In Nigeria, virtual asset service providers are regulated by the Securities and Exchange Commission (SEC) under the SEC Rules on Issuance, Offering Platforms and Custody of Digital Assets, 2022. The Company's VASP activities in Nigeria include digital asset custody, digital asset exchange, digital asset transfer, and fiat-crypto services.

SEC Registration Requirements include application for registration as a Digital Asset Exchange or Digital Asset Custodian, minimum paid-up capital requirements as specified by SEC, fit and proper assessment of directors and key management, demonstration of adequate technology infrastructure and cybersecurity measures, evidence of professional indemnity insurance, AML/CFT compliance program documentation, data protection and customer privacy policies, business continuity and disaster recovery plans, and customer complaint handling procedures.

B.2 Ongoing Compliance Obligations

Ongoing obligations include annual renewal of registration, quarterly financial reporting to SEC, prompt notification of material changes, submission of annual audited financial statements, maintenance of minimum capital requirements, periodic AML/CFT audit reports, cyber incident reporting within specified timeframes, customer complaint reporting, and compliance with SEC directives and guidance notes.

B.3 Permitted and Prohibited Activities

Permitted VASP Activities (subject to appropriate licensing) include custody and safekeeping of digital assets, exchange between different digital assets, exchange between digital assets and fiat currency, transfer and transmission of digital assets, and issuance of proprietary digital assets or tokens (subject to separate approval).

Prohibited or Restricted Activities include offering banking services without appropriate license, providing insurance services without appropriate license, operating betting or gambling platforms, facilitating transactions involving prohibited digital assets, operating outside the scope of license or registration, and serving customers from prohibited jurisdictions without appropriate approvals.

Appendix C: Cross-Border Transaction Workflow

This appendix provides a detailed workflow for processing cross-border transactions in compliance with AML/CFT requirements, including the Travel Rule for virtual asset transfers.

C.1 Pre-Transaction Checks

Pre-transaction checks include customer verification, sanctions screening, PEP check, jurisdiction risk, purpose verification, source of funds, Travel Rule threshold determination, and beneficiary VASP verification.

C.2 Travel Rule Data Collection

This step involves collecting required data (originator: full name, wallet address, physical address; beneficiary: full name, wallet address; transaction details: amount, asset type, date/time), validating data accuracy, formatting data per the IVMS-101 standard, identifying the counterparty, establishing communication, transmitting data, receiving confirmation, and documenting the exchange.

C.3 Transaction Execution

Transaction execution includes final authorization, execution of the transfer, real-time monitoring, confirmation, and customer notification.

C.4 Post-Transaction Procedures

Post-transaction procedures include reconciliation, record retention, regulatory reporting, monitoring, and pattern analysis.

C.5 Enhanced Procedures for High-Risk Cross-Border Transactions

Enhanced procedures apply when transactions involve high-risk jurisdictions, PEPs, amounts exceeding USD $10,000 equivalent, unusual transaction patterns, possible sanctions screening matches, or counterparty VASPs lacking Travel Rule capability. Enhanced procedures include AMLCO review and approval, enhanced source of funds verification, enhanced purpose documentation, possible customer interview, monitoring of subsequent related transactions, and lower thresholds for STR filing.

Appendix D: Settlement Partner Due Diligence Requirements

Settlement partners handle customer funds or virtual assets and present significant operational and compliance risks. This appendix details the enhanced due diligence requirements for settlement partner relationships.

D.1 Initial Due Diligence Checklist

Legal and Regulatory items include certificate of incorporation and registration number, regulatory licenses and permissions for relevant activities, evidence of good standing with regulators, recent regulatory examination reports, list of jurisdictions where the partner is licensed or operating, and confirmation of no material regulatory actions or sanctions.

Ownership and Management items include beneficial ownership disclosure and verification, organizational chart and corporate structure, directors and senior management list with CVs, background checks on beneficial owners and key management, and related party disclosures.

AML/CFT Program items include AML/CFT policies and procedures, evidence of risk assessment methodology, customer due diligence standards, transaction monitoring capabilities and thresholds, STR filing history and statistics, sanctions screening procedures and systems, staff training program documentation, and recent AML audit report.

Financial Soundness items include audited financial statements, evidence of minimum capital requirements, professional indemnity insurance coverage, fidelity bond or crime insurance, credit ratings (if available), client fund segregation procedures, and proof of reserves or asset backing for custodians.

Operational Capabilities items include technology infrastructure and security measures, data protection and privacy controls, business continuity and disaster recovery plans, incident response procedures, service level agreements and performance metrics, reconciliation and reporting capabilities, and API documentation and technical integration requirements.

D.2 Risk Assessment

Based on the due diligence findings, the Company assigns a risk rating to the settlement partner considering regulatory framework quality, AML/CFT program robustness, financial stability, services provided and associated risks, customer base and transaction profiles, technology infrastructure and cybersecurity posture, track record and history of compliance issues, and volume and value of customer funds or assets handled.

D.3 Ongoing Monitoring Requirements

Quarterly reviews cover transaction reconciliation, service level agreement compliance, and incident reporting. Semi-annual reviews cover financial performance, regulatory status, and insurance coverage verification. Annual reviews cover comprehensive due diligence refresh, AML/CFT program review, management changes, and audit report review. Event-driven reviews are triggered by adverse media alerts, regulatory actions, significant service disruptions, ownership or management changes, and material contract breaches.

D.4 Red Flags and Escalation

The following circumstances require immediate escalation to the AMLCO and possible suspension or termination of the relationship: regulatory action, license suspension, or material enforcement action; insolvency, bankruptcy, or significant financial distress; discovery of material misrepresentation in due diligence information; failure to cooperate with regulatory or law enforcement requests; significant data breach or cybersecurity incident; repeated service failures or material contract breaches; discovery of sanctions violations or significant AML failures; unwillingness to provide required due diligence updates; and evidence of involvement in fraudulent activities or financial crime.