Compliance Framework
Next scheduled review: 27th July, 2027
This Compliance Framework sets out the policies, controls, and governance structures that NetPay maintains to ensure lawful, safe, and sound operation of its cross-border payment services, in line with the requirements of the Central Bank of Nigeria (CBN), the Nigeria Data Protection Commission (NDPC), the Nigerian Financial Intelligence Unit (NFIU), and other applicable regulators.
It applies to all NetPay directors, employees, agents, and third-party service providers involved in the design, delivery, or oversight of NetPay's payment services, and reflects the Company's regulatory obligations as a payment service provider engaged in cross-border money transfer activity.
01Purpose and Scope
This Compliance Framework sets out the policies, controls, and governance structures that NetPay maintains to ensure lawful, safe, and sound operation of its cross-border payment services. It applies to all NetPay directors, employees, agents, and third-party service providers involved in the design, delivery, or oversight of NetPay's payment services.
02Applicable Regulatory Framework
NetPay's compliance programme is built around the following core instruments:
| Instrument | Regulator | Relevance to NetPay |
|---|---|---|
| CBN Act 2007 & BOFIA 2020 | Central Bank of Nigeria (CBN) | Overarching banking and payments supervisory authority |
| CBN Guidelines for Licensing and Regulation of Payment Service Providers | CBN | Basis for the Payment Solution Services (PSS) licence category and permissible activities |
| CBN Guidelines on International Money Transfer Services in Nigeria | CBN | Governs inbound/outbound cross-border remittance operations, IMTO partnerships and settlement |
| Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA) | EFCC / CBN | Primary AML statute; STR/CTR obligations, customer identification |
| Terrorism (Prevention and Prohibition) Act, 2022 (TPPA) | EFCC / NFIU | Counter-terrorism financing obligations |
| CBN AML/CFT/CPF Regulations, 2022 | CBN | Risk-based AML/CFT/CPF programme, transaction monitoring, correspondent banking controls |
| CBN Customer Due Diligence Regulations, 2023 | CBN | Tiered KYC, beneficial ownership identification, PEP due diligence |
| Nigeria Data Protection Act, 2023 (NDPA) & GAID 2025 | Nigeria Data Protection Commission (NDPC) | Personal data processing, cross-border data transfer, breach notification |
| CBN Consumer Protection Regulations | CBN Consumer Protection Department | Fair treatment, disclosure, complaints handling |
| FATF Recommendations | Financial Action Task Force (international standard) | Benchmark for AML/CFT risk-based approach and correspondent relationships |
| Applicable sanctions regimes | United Nations / national sanctions authorities | Sanctions screening for cross-border counterparties |
03Governance and Oversight
Board and Senior Management Responsibility
The Board of Directors bears ultimate responsibility for NetPay's compliance culture and risk appetite. The Board approves this Framework, receives periodic compliance and AML/CFT/CPF reports, and ensures adequate resources are allocated to the compliance function.
Compliance Officer / Money Laundering Reporting Officer (MLRO)
NetPay designates a senior-level Compliance Officer, who also serves as the Money Laundering Reporting Officer, with direct and unimpeded access to the Board. The Compliance Officer is responsible for implementing this Framework, filing suspicious transaction reports (STRs) with the NFIU, and serving as NetPay's primary liaison with the CBN and other regulators.
Data Protection Officer (DPO)
NetPay designates a Data Protection Officer responsible for NDPA compliance, including registration with the NDPC where NetPay meets the threshold of a data controller or processor of major importance, filing of annual Compliance Audit Returns (CAR), and coordination of data protection impact assessments.
Independent Compliance Function
The compliance function operates independently of the business and commercial lines, with escalation paths that do not require prior approval from revenue-generating units.
04Licensing and Regulatory Reporting
- Maintain our licence in good standing and comply with all conditions attached to it by the CBN.
- Submit periodic regulatory returns to the CBN as required, including transaction volume and value reports for cross-border flows.
- File the annual Compliance Audit Return (CAR) with the NDPC where applicable.
- Notify the CBN promptly of material changes in ownership, control, senior management, or business model, including changes affecting beneficial ownership of shareholders.
- Maintain an up-to-date beneficial ownership register for NetPay and material corporate shareholders, disclosing natural-person ownership at or above the applicable threshold.
05Customer Due Diligence (CDD) and Know Your Customer (KYC)
NetPay operates a risk-based, tiered KYC framework consistent with the CBN Customer Due Diligence Regulations, 2023, calibrated to the cross-border nature of its services:
| Tier | Identity Verification | Indicative Transaction / Balance Limits |
|---|---|---|
| Tier 1 | BVN or NIN verification; basic contact details | Lower daily transaction and cumulative balance limits, per CBN tiered KYC framework |
| Tier 2 | BVN/NIN plus government-issued ID and proof of address | Moderate daily transaction and cumulative balance limits |
| Tier 3 | Full CDD including source of funds/wealth, in-person or biometric verification | Highest limits, subject to CBN thresholds applicable to PSS licensees |
- Identity verification is performed using the Bank Verification Number (BVN) and/or National Identification Number (NIN), cross-checked against NIBSS/NIMC records.
- Enhanced Due Diligence (EDD) is applied to politically exposed persons (PEPs), customers linked to high-risk jurisdictions, complex or opaque corporate structures, and higher-value or higher-risk cross-border corridors.
- Simplified due diligence may apply to verified low-risk, low-value transactions, consistent with CBN thresholds.
- Ongoing monitoring is performed throughout the customer relationship, with periodic re-verification based on risk rating.
06Cross-Border Transaction Controls
Cross-border payments carry heightened money-laundering, terrorism-financing, and sanctions risk. NetPay applies the following controls to its cross-border corridors:
- Sanctions screening of all parties to a transaction — sender, recipient, and any intermediary institution — against the UN Consolidated List and other designated lists applicable to the corridors served, prior to execution.
- Due diligence on correspondent banks and partner payment institutions, including assessment of their AML/CFT controls, ownership, and regulatory standing, before onboarding them as settlement partners.
- Prohibition on establishing or maintaining relationships with shell banks or unlicensed money transfer operators.
- Transaction limits and enhanced scrutiny for transfers above CBN-prescribed thresholds for individual and corporate customers.
- Currency and foreign exchange controls in line with CBN foreign exchange regulations applicable to internationally recognised payment corridors.
- Retention of full transaction records, including originator and beneficiary information, for the minimum statutory period.
07AML/CFT/CPF Programme
NetPay's Anti-Money Laundering, Countering the Financing of Terrorism, and Countering Proliferation Financing programme is approved by the Board and reviewed at least annually. It includes:
- An enterprise-wide risk assessment covering customer, product, channel, and geographic risk, updated at least annually or upon material change in the business.
- Risk-based transaction monitoring, using automated tools to detect patterns consistent with money laundering, terrorism financing, or sanctions evasion.
- Timely filing of Suspicious Transaction Reports (STRs) and, where applicable, Currency Transaction Reports (CTRs) with the NFIU.
- Independent testing of the AML/CFT/CPF programme through periodic internal or external audit.
- Mandatory, documented AML/CFT/CPF training for all customer-facing and compliance staff, refreshed at least annually.
- Record keeping of customer identification, transaction, and due diligence records for a minimum of five (5) years.
08Data Protection Compliance
NetPay's handling of personal data is governed by its Privacy Policy and by the Nigeria Data Protection Act, 2023 and the General Application and Implementation Directive, 2025. Key compliance obligations include:
- Registration with the NDPC as a data controller/processor of major importance, where applicable thresholds are met.
- Lawful basis assessment and documentation for all personal data processing activities.
- Data Protection Impact Assessments (DPIAs) for high-risk processing, including large-scale cross-border data transfers and automated fraud/risk-scoring decisions.
- Cross-border data transfer safeguards, including adequacy assessment, standard contractual clauses, or consent, as set out in the Privacy Policy.
- Breach notification to the NDPC and affected data subjects within the statutory timeframe.
- Maintenance of a data breach register recording causes and remedial actions.
09Consumer Protection
- Clear and transparent disclosure of fees, exchange rates, and processing times for cross-border transfers prior to execution.
- A documented, accessible complaints-handling process with defined resolution timelines, consistent with CBN Consumer Protection Regulations.
- Fair treatment of customers, including equitable access regardless of transaction size.
- Safeguarding of customer funds held pending settlement, in line with CBN requirements for PSS licensees.
10Internal Controls, Audit, and Training
- Segregation of duties between transaction processing, compliance, and risk management functions.
- Periodic internal audit of compliance controls, with findings reported to the Board.
- Independent external audit of the AML/CFT/CPF and data protection programmes, at a frequency determined by risk and regulatory expectation.
- Ongoing staff training and competency assessment on AML/CFT/CPF, data protection, and consumer protection obligations.
11Incident and Breach Management
NetPay maintains an incident response plan covering both financial-crime incidents (e.g., suspected fraud, sanctions breaches) and data security incidents. The plan defines:
- Escalation paths to the Compliance Officer, DPO, and Board.
- Notification obligations to the CBN, NFIU, and NDPC as applicable.
- Remediation and post-incident review procedures.
12Record-Keeping and Retention
NetPay retains customer identification records, transaction records, due diligence records, and compliance monitoring records for a minimum of five (5) years from the date of the transaction or the termination of the business relationship, whichever is later, or such longer period as may be directed by the CBN, NFIU, or a court of competent jurisdiction.
13Policy Review and Amendment
This Framework is reviewed at least annually, and additionally upon material regulatory change, business model change, or following a material compliance incident. Amendments are approved by the Board and communicated to all relevant staff.
14Compliance Contacts
For compliance queries, suspicious activity concerns, or to exercise rights under this Framework, please contact the relevant team below.
Compliance & MLRO
compliance@netpayinstant.comData Protection Officer
dpo@netpayinstant.comRegistered Address
Plot 439 Abogo Largema Street,
Central Business District,
Abuja, Nigeria