AML, CFT and KYC policy
SafeRemit moves money across borders. That makes the business attractive to people who need to move money whose origin they would rather not explain. This policy sets out how we keep them out, and how we recognise them when they are already in.
It is published in full because our customers, our partner banks and our regulators are all entitled to read it. It binds every director, employee, contractor and agent of SafeRemit without exception.
1. Scope and standing
This policy covers every customer relationship, product and channel we operate: individual and business accounts on the mobile and web applications, outbound cross-border transfers on every rail, inbound funding by bank transfer and by stablecoin, internal transfers, and card products from the date each card programme goes live.
Where this policy sets a standard higher than the law requires, the higher standard applies. Where a partner bank or scheme imposes a stricter requirement on a corridor, that requirement is followed for that corridor. No commercial objective, customer relationship or revenue target justifies a departure from this policy.
The rules we work under
- Money Laundering (Prevention and Prohibition) Act 2022: customer due diligence, record keeping, currency and suspicious transaction reporting, and the designation of a compliance officer.
- Terrorism (Prevention and Prohibition) Act 2022: screening against the Nigeria Sanctions List, freezing designated funds without delay, and reporting to the Nigerian Sanctions Committee.
- CBN AML/CFT/CPF Regulations: the risk-based approach, beneficial ownership, enhanced due diligence, and ongoing monitoring standards for financial institutions.
- Companies and Allied Matters Act 2020: verification of corporate customers against the Corporate Affairs Commission register, and identification of persons with significant control.
- Nigeria Data Protection Act 2023: lawful basis, minimisation, security and retention limits for the personal data this policy requires us to collect.
- FATF Forty Recommendations, in particular Recommendation 10 on due diligence, Recommendation 15 on virtual assets, and Recommendation 16 on wire transfers and the Travel Rule.
We also observe the sanctions programmes of the United Nations Security Council, the United States Office of Foreign Assets Control, the United Kingdom Office of Financial Sanctions Implementation and the European Union, to the extent our settlement currencies and correspondents make them apply.
2. Who is accountable
The Board of Directors owns our financial crime risk appetite, approves this policy and every material amendment to it, and receives a quarterly report on how the controls are performing. Accountability cannot be delegated, only the work.
A single named officer holds the roles of Chief Compliance Officer and Money Laundering Reporting Officer. That officer has unrestricted access to every customer and transaction record, authority to suspend an account or block a transfer immediately and without commercial sign-off, and sole authority to file a suspicious transaction report. No one may overrule, delay or commercially justify away that decision.
We separate duties on the way out. The person who approves a customer's verification is not the person who releases that customer's payout, and no individual can both create and approve a payment instruction. Every step is recorded with who did it and when.
3. The risk-based approach
Not every customer needs the same scrutiny, and treating them as if they did wastes the attention the risky ones need. Every customer carries a risk rating from onboarding onward, and that rating sets the depth of due diligence, the review cycle and the monitoring thresholds applied to the account.
- Low: standard due diligence, reviewed every 36 months.
- Medium: standard due diligence with source of funds corroborated, reviewed every 24 months.
- High: enhanced due diligence under section 7, approved by the Chief Compliance Officer, reviewed every 12 months.
- Prohibited: the relationship is refused, or exited.
The rating is driven by customer type, declared volume, destination countries, industry, PEP status, verification outcome, adverse media and source of funds. A confirmed sanctions match sets the rating to prohibited. PEP status, a high-risk jurisdiction nexus, or ownership that cannot be traced each set it to high regardless of anything else.
Any member of staff can raise a rating by escalating to Compliance. Only Compliance can lower one, only on written reasoning, and never inside twelve months of the event that raised it.
A country is treated as high risk where it appears on the FATF list of high-risk jurisdictions subject to a call for action or under increased monitoring, where it is comprehensively sanctioned, or where credible published assessments place it in the lowest band for control of corruption. We assess the customer's nationality and residence, the destination of the funds, and the jurisdiction of the beneficiary and of any intermediary.
4. Verifying an individual
You can open an account and fund it without verifying. Until verification is approved, nothing can be sent out and no card can be issued. Deposits are permitted, the funds remain yours, and they are returnable to their origin.
What we collect
- Identity: full legal name, date of birth, nationality, and a current government photo identity document.
- Registry identifiers: your BVN and your NIN, if you are Nigerian.
- Address: your residential address, with proof in your own name dated within three months.
- Activity: your occupation, your source of funds, your expected monthly volume, and the purpose of the account.
Source of funds is captured against a fixed list: salary or wages, business income, personal savings, investment returns, family support or gift, loan or financing, sale of property or assets, or other. A free-text answer cannot be compared across customers or aggregated for reporting, which is why the list is closed.
Bank Verification Number
The BVN is an eleven-digit identifier issued through the Nigeria Inter-Bank Settlement System and held against your biometric record across the Nigerian banking system. It is the strongest single identity signal available for a Nigerian customer, because it is issued once per person and enrolled with fingerprints and a facial image.
- The BVN you submit is looked up against the registry, and the name and date of birth it returns must match what you declared and what your identity document shows.
- A mismatch is a hard stop. It is not resolved by resubmitting; it goes to a compliance analyst who decides.
- A BVN already recorded against a different SafeRemit account is a hard stop, treated as a possible account takeover or nominee arrangement until proven otherwise.
- Your BVN is stored encrypted, masked in every operational interface, and visible in full only to Compliance with the access recorded. It is never used to initiate a debit and never displayed back to you in full.
National Identity Number
The NIN is an eleven-digit identifier issued by the National Identity Management Commission. It is verified against the NIMC registry on the same basis as the BVN, and the same mismatch and duplication rules apply. We collect both rather than treating them as alternatives: they are issued by different bodies from different enrolments, and agreement between them is a materially stronger signal than either alone.
Document and biometric checks
Identity document authentication, liveness detection and face matching are performed through Sumsub. The session covers:
- Document authenticity: the security features of the issuing template, signs of digital or physical alteration, consistency between the printed data and the machine-readable zone, and expiry.
- Data cross-check: name, date of birth, document number and expiry read from the document and compared against what you declared and what the registry returned.
- Liveness: an active check that a living person is present, rejecting a photograph of a photograph, a screen replay, a printed mask or an injected video stream.
- Face match: the live capture matched against the portrait on the document, with anything below the threshold referred to a person rather than auto-passed.
- Duplicate detection: the same face or document presented under a different name across accounts raises an alert.
We accept the international passport, the driver's licence, the voter's card and the national identity card. An expired document is not accepted, and where the document is two-sided we capture both sides.
An automated decision is an input, not the decision. A pass on a customer who is high risk, who returns a partial registry match, or who triggers any other flag in this policy is reviewed by a person before the account opens. A rejection is reviewable too, so that a poor camera or a worn document does not permanently exclude someone legitimate.
The BVN and the NIN are numbers checked against a registry. They tell us a real, enrolled person holds that identity. They do not tell us that the person holding the phone is that person. The document check and the liveness check answer the second question, and neither substitutes for the other.
5. Verifying a business
A business is a structure, and a structure can be built to hide a person. Know Your Business work is finished when we know which natural persons stand behind the entity and control it, not when the certificate has been filed.
The entity
We verify the registered legal name and any trading name, the registration type, the CAC registration number and date of incorporation, the registered address and principal place of business, the Tax Identification Number, and the nature of the business against the Corporate Affairs Commission register. What the register returns must match what was submitted. An entity that is dormant, delisted or in liquidation is not onboarded.
The documents
A business submission is incomplete without the certificate of incorporation or registration, a CAC status report dated within six months, and proof of the business address. The memorandum and articles, a board resolution authorising the account, the TIN certificate, an operating licence where the activity is licensed, a recent bank statement and a sample invoice are collected where the entity type or the risk rating calls for them. A SCUML certificate is required where the customer is a designated non-financial institution, and the account is not opened where it is required and absent.
Beneficial ownership
We identify every natural person who ultimately owns or controls the customer. The disclosure threshold is five per cent of shares, voting rights or economic interest, held directly or indirectly, in line with the persons-with-significant-control regime.
- Ownership is traced through every intervening layer until natural persons are reached. A corporate shareholder is not an answer, it is another question.
- Where no natural person meets the threshold, we identify those exercising control by other means, and failing that we record the senior managing official as such, with the reason it was necessary.
- Every beneficial owner, director, trustee, partner and authorised signatory is verified as an individual under section 4, screened under section 6, and asked the PEP question.
- A structure whose ownership cannot be traced to natural persons is refused. Opacity is not a neutral fact about a customer.
The people authorised to instruct us are named, verified and evidenced by a board resolution or equivalent authority. A change of signatory needs the same evidence as the original appointment, and is never actioned on an email alone.
6. Sanctions and watchlist screening
Sanctions are absolute. There is no risk appetite, no threshold below which a designated person may be dealt with, and no commercial argument that survives a true match.
Screening runs against the consolidated data maintained by OpenSanctions, which aggregates official designation lists and politically exposed person datasets from the issuing authorities. We screen against the UN Consolidated List, the Nigeria Sanctions List, the OFAC SDN and Consolidated lists, the UK OFSI Consolidated List, the EU Consolidated List, PEP datasets, and adverse media and enforcement records.
Screening covers the named party, known aliases and transliterations, date of birth where we hold it, nationality, and identifiers such as passport and registration numbers. Entity screening also covers ownership: an entity that is fifty per cent or more owned, or otherwise controlled, by a designated person is treated as designated whether or not it is separately listed.
When screening runs
- At onboarding: the customer, and for a business every director, beneficial owner, trustee, partner and signatory.
- Before every outbound transfer: the beneficiary, their institution, and any intermediary named on the instruction.
- On adding a beneficiary: before it can be paid.
- On any change of name or ownership: rescreened in full.
- On every list update: the entire customer and beneficiary book, rescreened against the changed entries.
- At periodic review: the customer and every connected party, at the cycle their risk rating sets.
Rescreening on a list update is what catches the customer who was clean when they joined. A designation published today applies to a relationship opened two years ago, so we rescreen the book rather than waiting for the next review.
What happens on a match
Matching is deliberately fuzzy, because an exact-string screen is defeated by a transliteration. The cost is false positives, and we work them rather than tuning them away.
- An alert holds the subject. A transfer does not proceed; an onboarding is not approved.
- A compliance analyst compares every identifier available. A clear discrimination on a strong identifier permits a documented discount.
- Anything not clearly discounted goes to the Chief Compliance Officer. Only the CCO may clear a potential sanctions match.
- On a true match the funds are frozen, the relationship is suspended, and the matter is reported. Funds are not returned to source, because returning them is itself a prohibited dealing.
A confirmed match against the Nigeria Sanctions List requires funds to be frozen without delay and without prior notice, and the freeze reported to the Nigerian Sanctions Committee and the NFIU. Frozen funds are not released, transferred or converted except on the written authority of the designating authority or a court.
Every alert, the evidence considered, the decision and the decision-maker are recorded, including the identifier that discounted a false positive, so the same alert is not re-worked from scratch and the reasoning can be tested by an examiner. Thresholds and the list set are reviewed at least annually, and tested by seeding known designated names to confirm they are caught.
7. Politically exposed persons and enhanced due diligence
A politically exposed person holds or has held a prominent public function, together with their immediate family and known close associates. The status is not an accusation. It says the position creates a higher risk that funds passing through the account are the proceeds of corruption, and it calls for more evidence, not for refusal.
We establish PEP status two ways, because neither is complete on its own: every customer, owner, director and signatory is screened against PEP datasets, and separately asked to declare the status. A declaration that contradicts the screening result is itself a risk indicator.
- A PEP relationship needs senior management approval before it is established or continued.
- Source of wealth, meaning how the person's overall wealth was accumulated, is established and evidenced. That is a higher requirement than source of funds for a single transaction.
- Domestic and foreign PEPs are treated identically, and international organisation officials are included.
- The status is not removed automatically when someone leaves office. It is reassessed on the influence they retain, and no earlier than twelve months after they leave.
When enhanced due diligence applies
Enhanced due diligence is applied to any PEP relationship, any nexus with a high-risk jurisdiction, declared or actual monthly volume above the equivalent of USD 250,000, complex or nominee ownership structures, higher risk sectors including precious metals and stones, unlicensed money services, gambling, arms and dual-use goods and virtual asset services, adverse media or an enforcement record, an unresolved monitoring alert, or a reapplication by someone we previously refused or exited.
It adds evidenced source of wealth, independent corroboration from registers and published records rather than from the customer alone, written approval by the Chief Compliance Officer at onboarding and at each annual review, a documented understanding of the purpose of the relationship, reduced monitoring thresholds, and a twelve-month review cycle.
Where due diligence cannot be completed, the relationship is not established; where it already exists, it is terminated. Funds are not transferred onward, and the circumstances are considered for a report. An incomplete file is a decision, not a pending item to carry forward.
8. Ongoing monitoring
Due diligence at onboarding describes a customer on one day. Monitoring is how the file stays true, and it is the control most likely to catch someone who was honest when they joined.
Every transaction is screened before release and scored against a scenario register covering structuring, volume breaches, velocity spikes, dormancy followed by activity, rapid pass-through, high-risk corridors, beneficiary bank detail changes, invoice mismatches, document reuse, round amounts, beneficiary concentration, unrelated customers paying a common beneficiary, virtual asset exposure, departure from the declared business, and abandonment when source of funds is requested.
Activity is tested against your declared profile: expected monthly volume, stated purpose, and usual counterparties and corridors. Departure from the profile is the signal, and absolute size is only one of the ways to depart from it.
An alert is worked by a compliance analyst within one business day. We may ask you for information about a source of funds; that request is not a sign that a report has been made, and staff are not permitted to tell you one way or the other. Every alert is closed as cleared, escalated to enhanced due diligence, or escalated to the MLRO, and the reasoning is recorded in each case.
Files are refreshed at the cycle the risk rating sets, and out of cycle on any trigger: a sanctions or PEP hit, a change of ownership or control, a material change in activity, adverse media, a regulatory request, or a report filed.
The controls running underneath
- A six-digit transaction PIN approves every transfer. It is stored hashed and checked on our servers; five wrong attempts lock the account for fifteen minutes.
- Sign-in attempts are rate limited, with a lockout after five failures inside fifteen minutes.
- Every signed-in device is listed to you and can be revoked individually.
- Card number, expiry and security code are revealed only after the transaction PIN is verified, and hidden again when you navigate away.
- Customer instructions, reviewer decisions and payout state changes are recorded with the actor and the timestamp.
9. Every transfer answers a document
You cannot create an outbound transfer without attaching the invoice, contract or other commercial document the payment answers. This is our principal control against trade-based money laundering and against business email compromise, and it applies to every transfer rather than above a threshold.
The document is read, and the payee, bank details, amount, currency and document type are extracted and held with the transfer. The instruction is pre-filled from the document rather than typed freely, so what you send and what the document says start from the same place. We then check:
- Payee against beneficiary: payment to a party other than the one the document names, which is the signature of an intercepted invoice.
- Bank details against history: a supplier's account number or IBAN that has changed since the last payment, which is the signature of business email compromise.
- Amount against document: over-invoicing and under-invoicing, the two classic ways to move value through trade.
- Document type: a proforma invoice is a quotation rather than a bill, and we say so before you pay it.
- Goods against declared business: a trade unrelated to anything you told us you do.
- Reuse: the same document presented against more than one payment.
A warning stays on the document for its life. A reason to doubt an invoice does not expire when the first payment against it clears, and a warning that vanished after the first payment would be a warning shown at the least useful moment.
The document as you supplied it is retained unaltered, with the extracted details and every warning raised.
10. Stablecoins and virtual assets
We accept stablecoin funding and settle some corridors in stablecoin. Virtual assets carry risks that fiat rails do not.
- Only assets and networks on an approved list may be used. A network that is not open is shown as unavailable rather than hidden, so nobody is walked into a dead end. Anonymity-enhanced coins and privacy-preserving networks are not accepted in any circumstances.
- A deposit address is only ever shown where we hold the key to it, and addresses are derived per customer, so an inbound transfer is attributable to a named, verified person rather than to a shared pool. Key material is encrypted with a key held outside the database it protects.
- Inbound transfers are screened for exposure to sanctioned addresses, darknet markets, ransomware proceeds, mixing services and unlicensed exchanges. A deposit with material exposure is held pending review, and frozen and reported where exposure is confirmed or origin cannot be evidenced.
- A deposit is credited on what the chain shows, not on what a customer states. Where you submit a transaction hash to have a deposit located, the amount, asset and recipient are read from the chain record.
- For transfers to and from other virtual asset service providers, originator and beneficiary information travels with the transfer in line with FATF Recommendation 16. A transfer arriving without the required information is treated as an indicator and is not passed on incomplete.
11. Who we will not do business with
The following are outside our risk appetite. They are refused at onboarding and exited if discovered later.
- Any person or entity on a sanctions list we screen against, and any entity owned or controlled by one.
- Accounts in false, fictitious or numbered names, and any account whose holder cannot be identified.
- Entities with no economic purpose or operating substance, or ownership that cannot be traced to natural persons.
- Any correspondent relationship with a bank that has no physical presence and no affiliation with a regulated group.
- Accounts operated for an undisclosed third party, including an account opened in one person's name for another's use.
- Unlicensed money services, unlicensed exchanges, and payment aggregation for undisclosed third parties.
- Arms and munitions, dual-use goods without licence, narcotics, endangered species, cultural property of uncertain provenance, and counterfeit goods.
- Customers resident in, and payments to or from, comprehensively sanctioned jurisdictions.
- Anyone who will not provide information this policy requires, or who provides information we find to be false.
12. Reporting
Any member of staff who suspects, or has reasonable grounds to suspect, that funds are the proceeds of crime or relate to terrorist financing must escalate to the MLRO immediately. Suspicion is a low threshold: more than speculation, considerably less than proof, and it does not require anyone to identify the underlying offence. Staff do not investigate on their own and do not raise it with the customer.
The MLRO evaluates the escalation and records the decision with its reasoning whether or not a report follows. A decision not to report is documented as fully as a decision to report, because it is the decision an examiner will test.
- Suspicious Transaction Report, filed with the NFIU within 24 hours of forming a suspicion, whether or not the transaction proceeded, and including attempted transactions.
- Currency Transaction Report, within 7 days, on cash transactions above NGN 5,000,000 for an individual or NGN 10,000,000 for a body corporate.
- Foreign transfer report, within 7 days, on transfers to or from a foreign jurisdiction above USD 10,000 or the equivalent.
- Sanctions freeze report, without delay, to the Nigerian Sanctions Committee and the NFIU.
Reports are filed by the MLRO or the named deputy and by nobody else. After a report the relationship is reviewed and a decision taken on whether to continue it, with enhanced monitoring where it continues.
Disclosing to a customer or anyone else that a report has been made or is contemplated, or that they are under investigation, is an offence. No member of staff may do it, and customer-facing staff are given a form of words that is true and neutral rather than improvising past it. A member of staff who escalates a suspicion in good faith is protected, and no detriment follows from an escalation that turns out to be unfounded.
13. Records and your data
We keep identification data and verification evidence, transaction records, invoices and supporting documents, screening results and alert dispositions, and reports and their supporting analysis for five years after the relationship ends or the transaction occurs, and longer where an investigation or a law enforcement request requires it.
Records are kept so that an individual transaction can be reconstructed and produced to the NFIU, the CBN or a court without undue delay. Documents are stored behind authenticated access rather than at public URLs, and identity documents are served only through a view that checks the requester's authority.
The personal data this policy requires is processed to comply with a legal obligation, which is the lawful basis we rely on under the Nigeria Data Protection Act 2023. We collect only what the purpose needs. Your BVN and NIN are encrypted at rest, masked in operational interfaces, and accessible in full only to Compliance with the access recorded. Access is granted by role and reviewed at least annually. A right to erasure does not override the retention obligations above, and where a request conflicts with them we will explain the obligation. Our privacy policy covers your data rights in full.
14. Training and independent testing
Controls are applied by people, and a control nobody understands is a control that is not operating. Every new joiner completes AML, CFT and sanctions training before being given access to customer data. Everyone, including directors, completes a refresher each year. Onboarding reviewers, payout operators and the engineers building the controls receive training specific to what their role can get wrong. Training is assessed rather than merely attended, and access is suspended where it is overdue by more than thirty days.
The framework is tested at least annually by internal audit or an independent external reviewer who had no part in designing or operating the controls. Testing covers whether onboarding files contain what this policy requires, whether screening catches known designated names when they are seeded, whether alerts are worked in time and adequately reasoned, whether reports met their deadlines, and whether access to customer data is properly limited. Findings go to the Board rather than to management, with an owner and a due date each, and open findings are reported quarterly until closed.
15. Breaches, exceptions and review
A breach of this policy is reported to the Chief Compliance Officer immediately on discovery, by whoever discovers it, including the person responsible for it. Breaches are logged, root-caused, remediated and reported to the Board.
An exception may be granted only by the Chief Compliance Officer, only in writing, only for a defined period, and only where it does not conflict with a legal obligation. There is no exception to a sanctions prohibition, to the reporting duties in section 12, or to the prohibition on tipping off.
This policy is reviewed at least annually, and out of cycle on a change in law, a change in the business model or risk profile, a material incident, or a finding from independent testing. Material amendments require Board approval, and every version is retained.
16. Contact
Compliance questions, and requests from partner institutions and regulators, go to [email protected]. Data protection requests go to [email protected].