Compliance Framework

Next scheduled review: 27th July, 2027

This Compliance Framework sets out the policies, controls, and governance structures that NetPay maintains to ensure lawful, safe, and sound operation of its cross-border payment services, in line with the requirements of the Central Bank of Nigeria (CBN), the Nigeria Data Protection Commission (NDPC), the Nigerian Financial Intelligence Unit (NFIU), and other applicable regulators.

It applies to all NetPay directors, employees, agents, and third-party service providers involved in the design, delivery, or oversight of NetPay's payment services, and reflects the Company's regulatory obligations as a payment service provider engaged in cross-border money transfer activity.

OwnerChief Compliance Officer
Approved byBoard of Directors
Review cycleAnnual

01Purpose and Scope

This Compliance Framework sets out the policies, controls, and governance structures that NetPay maintains to ensure lawful, safe, and sound operation of its cross-border payment services. It applies to all NetPay directors, employees, agents, and third-party service providers involved in the design, delivery, or oversight of NetPay's payment services.

02Applicable Regulatory Framework

NetPay's compliance programme is built around the following core instruments:

InstrumentRegulatorRelevance to NetPay
CBN Act 2007 & BOFIA 2020Central Bank of Nigeria (CBN)Overarching banking and payments supervisory authority
CBN Guidelines for Licensing and Regulation of Payment Service ProvidersCBNBasis for the Payment Solution Services (PSS) licence category and permissible activities
CBN Guidelines on International Money Transfer Services in NigeriaCBNGoverns inbound/outbound cross-border remittance operations, IMTO partnerships and settlement
Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA)EFCC / CBNPrimary AML statute; STR/CTR obligations, customer identification
Terrorism (Prevention and Prohibition) Act, 2022 (TPPA)EFCC / NFIUCounter-terrorism financing obligations
CBN AML/CFT/CPF Regulations, 2022CBNRisk-based AML/CFT/CPF programme, transaction monitoring, correspondent banking controls
CBN Customer Due Diligence Regulations, 2023CBNTiered KYC, beneficial ownership identification, PEP due diligence
Nigeria Data Protection Act, 2023 (NDPA) & GAID 2025Nigeria Data Protection Commission (NDPC)Personal data processing, cross-border data transfer, breach notification
CBN Consumer Protection RegulationsCBN Consumer Protection DepartmentFair treatment, disclosure, complaints handling
FATF RecommendationsFinancial Action Task Force (international standard)Benchmark for AML/CFT risk-based approach and correspondent relationships
Applicable sanctions regimesUnited Nations / national sanctions authoritiesSanctions screening for cross-border counterparties

03Governance and Oversight

Board and Senior Management Responsibility

The Board of Directors bears ultimate responsibility for NetPay's compliance culture and risk appetite. The Board approves this Framework, receives periodic compliance and AML/CFT/CPF reports, and ensures adequate resources are allocated to the compliance function.

Compliance Officer / Money Laundering Reporting Officer (MLRO)

NetPay designates a senior-level Compliance Officer, who also serves as the Money Laundering Reporting Officer, with direct and unimpeded access to the Board. The Compliance Officer is responsible for implementing this Framework, filing suspicious transaction reports (STRs) with the NFIU, and serving as NetPay's primary liaison with the CBN and other regulators.

Data Protection Officer (DPO)

NetPay designates a Data Protection Officer responsible for NDPA compliance, including registration with the NDPC where NetPay meets the threshold of a data controller or processor of major importance, filing of annual Compliance Audit Returns (CAR), and coordination of data protection impact assessments.

Independent Compliance Function

The compliance function operates independently of the business and commercial lines, with escalation paths that do not require prior approval from revenue-generating units.

04Licensing and Regulatory Reporting

  • Maintain our licence in good standing and comply with all conditions attached to it by the CBN.
  • Submit periodic regulatory returns to the CBN as required, including transaction volume and value reports for cross-border flows.
  • File the annual Compliance Audit Return (CAR) with the NDPC where applicable.
  • Notify the CBN promptly of material changes in ownership, control, senior management, or business model, including changes affecting beneficial ownership of shareholders.
  • Maintain an up-to-date beneficial ownership register for NetPay and material corporate shareholders, disclosing natural-person ownership at or above the applicable threshold.

05Customer Due Diligence (CDD) and Know Your Customer (KYC)

NetPay operates a risk-based, tiered KYC framework consistent with the CBN Customer Due Diligence Regulations, 2023, calibrated to the cross-border nature of its services:

TierIdentity VerificationIndicative Transaction / Balance Limits
Tier 1BVN or NIN verification; basic contact detailsLower daily transaction and cumulative balance limits, per CBN tiered KYC framework
Tier 2BVN/NIN plus government-issued ID and proof of addressModerate daily transaction and cumulative balance limits
Tier 3Full CDD including source of funds/wealth, in-person or biometric verificationHighest limits, subject to CBN thresholds applicable to PSS licensees
  • Identity verification is performed using the Bank Verification Number (BVN) and/or National Identification Number (NIN), cross-checked against NIBSS/NIMC records.
  • Enhanced Due Diligence (EDD) is applied to politically exposed persons (PEPs), customers linked to high-risk jurisdictions, complex or opaque corporate structures, and higher-value or higher-risk cross-border corridors.
  • Simplified due diligence may apply to verified low-risk, low-value transactions, consistent with CBN thresholds.
  • Ongoing monitoring is performed throughout the customer relationship, with periodic re-verification based on risk rating.

06Cross-Border Transaction Controls

Cross-border payments carry heightened money-laundering, terrorism-financing, and sanctions risk. NetPay applies the following controls to its cross-border corridors:

  • Sanctions screening of all parties to a transaction — sender, recipient, and any intermediary institution — against the UN Consolidated List and other designated lists applicable to the corridors served, prior to execution.
  • Due diligence on correspondent banks and partner payment institutions, including assessment of their AML/CFT controls, ownership, and regulatory standing, before onboarding them as settlement partners.
  • Prohibition on establishing or maintaining relationships with shell banks or unlicensed money transfer operators.
  • Transaction limits and enhanced scrutiny for transfers above CBN-prescribed thresholds for individual and corporate customers.
  • Currency and foreign exchange controls in line with CBN foreign exchange regulations applicable to internationally recognised payment corridors.
  • Retention of full transaction records, including originator and beneficiary information, for the minimum statutory period.

07AML/CFT/CPF Programme

NetPay's Anti-Money Laundering, Countering the Financing of Terrorism, and Countering Proliferation Financing programme is approved by the Board and reviewed at least annually. It includes:

  • An enterprise-wide risk assessment covering customer, product, channel, and geographic risk, updated at least annually or upon material change in the business.
  • Risk-based transaction monitoring, using automated tools to detect patterns consistent with money laundering, terrorism financing, or sanctions evasion.
  • Timely filing of Suspicious Transaction Reports (STRs) and, where applicable, Currency Transaction Reports (CTRs) with the NFIU.
  • Independent testing of the AML/CFT/CPF programme through periodic internal or external audit.
  • Mandatory, documented AML/CFT/CPF training for all customer-facing and compliance staff, refreshed at least annually.
  • Record keeping of customer identification, transaction, and due diligence records for a minimum of five (5) years.

08Data Protection Compliance

NetPay's handling of personal data is governed by its Privacy Policy and by the Nigeria Data Protection Act, 2023 and the General Application and Implementation Directive, 2025. Key compliance obligations include:

  • Registration with the NDPC as a data controller/processor of major importance, where applicable thresholds are met.
  • Lawful basis assessment and documentation for all personal data processing activities.
  • Data Protection Impact Assessments (DPIAs) for high-risk processing, including large-scale cross-border data transfers and automated fraud/risk-scoring decisions.
  • Cross-border data transfer safeguards, including adequacy assessment, standard contractual clauses, or consent, as set out in the Privacy Policy.
  • Breach notification to the NDPC and affected data subjects within the statutory timeframe.
  • Maintenance of a data breach register recording causes and remedial actions.

09Consumer Protection

  • Clear and transparent disclosure of fees, exchange rates, and processing times for cross-border transfers prior to execution.
  • A documented, accessible complaints-handling process with defined resolution timelines, consistent with CBN Consumer Protection Regulations.
  • Fair treatment of customers, including equitable access regardless of transaction size.
  • Safeguarding of customer funds held pending settlement, in line with CBN requirements for PSS licensees.

10Internal Controls, Audit, and Training

  • Segregation of duties between transaction processing, compliance, and risk management functions.
  • Periodic internal audit of compliance controls, with findings reported to the Board.
  • Independent external audit of the AML/CFT/CPF and data protection programmes, at a frequency determined by risk and regulatory expectation.
  • Ongoing staff training and competency assessment on AML/CFT/CPF, data protection, and consumer protection obligations.

11Incident and Breach Management

NetPay maintains an incident response plan covering both financial-crime incidents (e.g., suspected fraud, sanctions breaches) and data security incidents. The plan defines:

  • Escalation paths to the Compliance Officer, DPO, and Board.
  • Notification obligations to the CBN, NFIU, and NDPC as applicable.
  • Remediation and post-incident review procedures.

12Record-Keeping and Retention

NetPay retains customer identification records, transaction records, due diligence records, and compliance monitoring records for a minimum of five (5) years from the date of the transaction or the termination of the business relationship, whichever is later, or such longer period as may be directed by the CBN, NFIU, or a court of competent jurisdiction.

13Policy Review and Amendment

This Framework is reviewed at least annually, and additionally upon material regulatory change, business model change, or following a material compliance incident. Amendments are approved by the Board and communicated to all relevant staff.

14Compliance Contacts

For compliance queries, suspicious activity concerns, or to exercise rights under this Framework, please contact the relevant team below.

Data Protection Officer

dpo@netpayinstant.com

Registered Address

Plot 439 Abogo Largema Street,
Central Business District,
Abuja, Nigeria