Legal
AML, CTF & Sanctions Policy
Last updated: 24 August 2026
This Anti-Money Laundering (“AML”), Counter-Terrorist Financing (“CTF”), and Sanctions Compliance Policy explains the measures and procedures PPay applies to prevent, detect, and report money laundering, terrorist financing, sanctions violations, fraud, identity theft, and other unlawful financial activity. This Policy applies to all users, merchants, partners, and any individuals or entities accessing or using PPay’s services.
1. Purpose and scope
This Policy establishes the framework by which Prosper Digital Systems Ltd (RC 9227681), trading as PPay (“the Company”, “PPay”), prevents, detects, and reports money laundering, terrorist financing, proliferation financing, sanctions violations, fraud, and other financial crime across all products and services offered — including gift card trading, airtime/data top-up, virtual and physical card issuance, domestic and cross-border money transfer, savings products, virtual number provisioning, and crypto/fiat conversion (“the Services”). This Policy applies to all directors, employees, contractors, agents, and third-party service providers acting on behalf of PPay, and to all customers and merchants using the Services.
2. Governance and compliance oversight
Compliance Officer
The Board of Directors has appointed a Compliance Officer, who also acts as Money Laundering Reporting Officer (MLRO), responsible for the day-to-day operation of this Policy, receipt and evaluation of internal suspicious activity reports, filing of Suspicious Transaction Reports (STRs) with the Nigerian Financial Intelligence Unit (NFIU) and relevant regulators, and liaison with law enforcement and PPay's anchor bank partner.
Board and senior management oversight
This Policy is reviewed and approved by the Board of Directors (or, at the Company's current stage, the Director acting as governing authority) at least annually, or sooner if triggered by a material regulatory change or significant compliance event. The Compliance Officer provides the Board with periodic — at minimum quarterly — reporting covering the volume and nature of alerts generated, STRs filed, sanctions hits, training completion, and any regulatory correspondence.
Independent testing
The AML/CTF/Sanctions programme is subject to independent testing (internal audit or a qualified external reviewer) at least every 12–18 months to assess design and operating effectiveness. Findings and remediation actions are logged and reported to the Board.
3. Risk-based approach and enterprise-wide risk assessment
PPay applies a risk-based approach proportionate to the nature, size, and complexity of its business, through an Enterprise-Wide Risk Assessment (EWRA) reviewed at least annually and upon material change in products, geographies, or customer base, covering:
- —Client risk — customer type, occupation, source of funds/wealth, and PEP status.
- —Product risk — gift cards, cross-border transfers, virtual cards, crypto conversion.
- —Channel risk — mobile app, WhatsApp bot, and agent/merchant onboarding.
- —Geographic risk — countries of customer residence, transaction counterparties, and virtual number jurisdictions.
The EWRA also assesses control effectiveness across transaction monitoring, customer due diligence, PEP identification, transaction/sanctions screening, adverse media screening, training, governance, and management information. A documented Risk Tolerance Statement, approved by the Board, defines the boundaries of acceptable financial crime risk and is reviewed alongside the EWRA.
4. Customer due diligence (CDD) and KYC
Before or during onboarding, PPay collects and verifies:
- —Full legal name, residential address, and date of birth.
- —Phone number and email address.
- —Government-issued identification and selfie or biometric verification.
- —Proof of address.
- —BVN, NIN, or equivalent verification data where applicable.
- —Corporate registration documents for business or merchant accounts.
Identity verification and screening functions are supported by a licensed third-party verification provider (Dojah), engaged to perform BVN/NIN checks, document verification, and biometric matching under a data processing agreement consistent with NDPR requirements. PPay operates tiered verification limits — access to higher transaction volumes and premium features requires completion of additional verification steps, and re-verification is performed periodically and upon risk triggers.
5. Enhanced due diligence (EDD)
EDD is applied to customers, transactions, or relationships assessed as higher risk, including Politically Exposed Persons (PEPs) and their family members or close associates, customers linked to high-risk jurisdictions, unusually large or complex transactions, and customers flagged by adverse media screening. EDD measures include:
- —Source of funds and source of wealth verification.
- —Business activity review for merchant or corporate accounts.
- —Senior management sign-off prior to onboarding or continuing the relationship.
- —Enhanced, more frequent transaction monitoring.
6. PEP, sanctions, and adverse media screening
PEP screening
All customers are screened at onboarding and on an ongoing basis against Politically Exposed Person databases, covering domestic and foreign PEPs and their immediate family members and close associates. Matches trigger mandatory EDD before the relationship may proceed.
Sanctions screening
PPay screens all customers and transaction counterparties against applicable sanctions and watchlists — including UN, OFAC, and other relevant lists — prior to onboarding and on an ongoing, real-time basis for transactions. Confirmed matches result in the transaction being blocked and the account restricted pending investigation and, where required, regulatory reporting.
Adverse media / negative news screening
Customers are screened against adverse media sources for association with financial crime, terrorism, corruption, or other predicate offences, to inform risk rating and EDD decisions.
Internal watchlists
PPay maintains an internal watchlist of individuals and entities previously subject to account closure, confirmed fraud, or sanctions/law enforcement action, to prevent re-onboarding under the Company's control.
7. Prohibited relationships
PPay's policies and onboarding controls prohibit:
- —Anonymous or fictitiously named accounts — identity verification is mandatory before account activation.
- —Accounts or relationships with unlicensed banks and non-bank financial institutions (NBFIs).
- —Dealing with entities that provide banking services to unlicensed banks.
- —Accounts or relationships with shell banks (banks with no physical presence and no affiliation with a regulated financial group).
- —Dealing with entities that provide services to shell banks.
- —Accounts for unlicensed or unregulated remittance agents, exchange houses, casas de cambio, bureaux de change, or money transfer agents.
PPay does not act as a correspondent bank and does not hold accounts on behalf of other financial institutions; these prohibitions are enforced through onboarding screening and merchant category restrictions.
8. Ongoing transaction monitoring
PPay monitors transactions, account activity, and user behaviour on an ongoing basis using:
- —Transaction pattern analysis, velocity and frequency checks.
- —Device and IP monitoring with risk scoring.
- —Geolocation analysis and fraud detection screening.
- —Structuring or layering detection.
- —Blockchain or crypto transaction analysis where applicable.
- —Sanctions and watchlist screening at the point of transaction.
9. Escalation, investigation, and suspicious activity reporting
Internal escalation
Any employee who identifies activity that appears unusual or suspicious must escalate immediately to the Compliance Officer via the internal escalation channel, without alerting the customer (“tipping off”).
Investigation
The Compliance Officer reviews escalations, gathers supporting information, and determines within a defined timeframe whether the activity warrants a Suspicious Transaction Report (STR).
Regulatory reporting
Where warranted, STRs are filed with the NFIU and other applicable authorities. Reports may be filed without notifying the affected customer where legally permitted.
Relationship termination
Where financial crime risk cannot be adequately mitigated, or a customer fails to respond to verification or EDD requests, the Compliance Officer may authorise suspension, restriction, or termination of the account, with the rationale documented.
10. Third-party reliance
PPay engages trusted third parties to perform components of its AML/CTF/Sanctions programme, including Dojah for identity verification, BVN/NIN checks, and document and biometric verification.
Reliance on third parties does not remove PPay's ultimate responsibility for compliance. Due diligence is performed on third-party providers prior to engagement, and their performance is periodically reviewed.
11. Training and education
All employees receive AML/CTF/Sanctions training at onboarding and at least annually thereafter, covering red flags, escalation procedures, and regulatory obligations. Training records are maintained by the Compliance Officer. Role-specific training is provided to staff with direct customer-facing or transaction-review responsibilities.
12. Record retention
- —Customer identification records and transaction records.
- —Compliance reviews and risk assessments.
- —Investigation materials.
Records are retained for the period required under applicable Nigerian law and any longer period required by contractual obligations with partner institutions, in accordance with the Nigeria Data Protection Regulation (NDPR).
13. Data protection
Information collected for AML and KYC purposes is processed in accordance with PPay's Privacy Policy and the Nigeria Data Protection Regulation (NDPR). Reasonable administrative, technical, and organisational safeguards are applied to protect customer information against unauthorized access, misuse, disclosure, or loss.
14. Alignment with international standards
PPay intends to periodically benchmark this Policy against international standards, including the FATF Recommendations, the US Bank Secrecy Act / USA PATRIOT Act framework, and EU AML Directives, to ensure alignment with the expectations of correspondent and anchor banking partners operating cross-border.
A formal gap analysis against these frameworks has not yet been completed; this is scheduled as part of onboarding with PPay's anchor bank partner.
15. Policy review and amendment
This Policy is reviewed at least annually by the Compliance Officer and approved by the Board, and may be updated more frequently to reflect regulatory change, audit findings, or evolving risk. Updated versions take effect upon Board approval and publication.
16. Anti-bribery and corruption
PPay also maintains a dedicated Anti-Bribery & Corruption Policy, applicable to all directors, employees, and third parties acting on the Company’s behalf, covering PPay’s zero-tolerance stance on bribery, enhanced requirements for interactions with public officials, and gifts and hospitality standards.
Contact us
For questions, compliance concerns, or verification-related inquiries, contact the PPay Compliance Team at use@ppayglobal.com or visit ppayglobal.com.