AML/CFT Compliance Policy
1. Purpose
This policy sets out Kavo Tech Hub's (“the Company”, operating its digital wallet product Kavopay) commitment to preventing the use of its platform for money laundering, terrorism financing, or other financial crime. It establishes the minimum standards, controls, and responsibilities that apply across the business as it develops its compliance function in line with applicable Nigerian law, including the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, and relevant CBN and NFIU guidelines.
2. Scope
This policy applies to all directors, employees, contractors, and agents of Kavo Tech Hub involved in onboarding customers, processing transactions, or otherwise operating the Kavopay platform.
3. Company risk statement
Kavo Tech Hub is an early-stage digital wallet business. The Company acknowledges that as it scales transaction volumes and product offerings (including payments, virtual numbers, and bill payments), its money laundering and terrorism financing risk exposure will increase. The Company is committed to building AML/CFT controls proportionate to this growth and to strengthening this policy as the business matures, including through engagement with licensed partners and regulators.
The Company's primary payment processing and settlement partner is Flutterwave, a CBN-licensed payment service provider. Wallet funding, transfers, and bank settlement on the Kavopay platform are processed through Flutterwave's infrastructure, and the Company relies on Flutterwave's own AML/CFT and fraud controls as an additional layer alongside its own.
4. Governance & responsibility
- The Proprietor/Director of Kavo Tech Hub holds overall responsibility for AML/CFT compliance until a dedicated Compliance Officer is appointed.
- As the Company grows, a designated Compliance Officer will be appointed to oversee day-to-day AML/CFT obligations, suspicious activity reporting, and staff training.
- The Company will maintain records of all compliance-related decisions and escalations.
5. Customer Due Diligence (CDD)
Kavo Tech Hub performs identity verification on all users prior to enabling wallet functionality, as detailed in the Company's separate KYC/CDD Procedure. This includes collection of valid government-issued identification (e.g. NIN), verification of identity data, and screening against risk indicators.
6. Ongoing monitoring
- Transactions are monitored for patterns inconsistent with a customer's expected activity (e.g. unusually large transfers, rapid movement of funds, structuring).
- Accounts exhibiting suspicious activity will be flagged for manual review and, where appropriate, restricted pending investigation.
- The Company will implement automated transaction monitoring tools as transaction volume grows.
7. Politically Exposed Persons (PEPs)
Directors, key controllers, and Persons of Significant Control are screened for PEP status at onboarding and periodically thereafter. Enhanced due diligence will be applied to any customer or controller identified as a PEP or closely related to one.
8. Reporting suspicious activity
Any employee who suspects that a transaction or customer activity may relate to money laundering or terrorism financing must report it immediately to the Proprietor/Director. The Company will, where required, file Suspicious Transaction Reports (STRs) with the Nigerian Financial Intelligence Unit (NFIU).
9. Settlement timing, transaction reversals & refunds
Bank transfers initiated from a Kavopay wallet are settled through Flutterwave and may take up to 2 to 5 business days to reflect in the recipient bank account, depending on Flutterwave's settlement cycle and the receiving bank's own processing time. This is a normal part of the settlement process and is also disclosed in our Terms & Conditions.
Where a sender reports a transaction as sent in error, unauthorized, or fraudulent and provides supporting proof (e.g. a receipt or transaction reference), the Company will investigate the report and, where warranted, reverse the transaction amount back to the sender in line with Flutterwave's dispute-resolution process and applicable banking rules. A transaction under investigation following such a report may be placed on hold pending the outcome. This reversal mechanism forms part of the Company's fraud-control and dispute-handling process under this policy.
Separately, where a purchase made on the Kavopay platform (e.g. airtime, data, bill payment, or domain registration) is debited from a user's wallet but does not complete successfully, the amount is automatically refunded to the user's wallet. This is a consumer-protection control distinct from the sender-dispute reversal process described above, and does not itself constitute a suspicious-activity indicator.
10. Record keeping
All customer identification records, transaction records, and compliance correspondence will be retained for a minimum of 5 years from the date of the transaction or the end of the business relationship, in line with regulatory requirements.
11. Staff awareness
All personnel involved in customer onboarding or transaction processing will be made aware of this policy and their obligations under it. Formal training will be introduced as the team grows.
12. Policy review
This policy will be reviewed at least annually, or sooner if there is a material change in the Company's products, risk profile, or applicable regulation.
13. Related documents
This policy works alongside our Terms & Conditions, Privacy Policy, and internal KYC/CDD Procedure. Where there is any conflict between this summary and the Company's full internal AML/CFT Compliance Policy, the internal policy governs.
14. Contact us
If you suspect fraud, unauthorized activity, or wish to report a transaction, or have questions about this policy, you can contact us at:
- Email: [email protected]
- Subject line suggestion: “Kavopay AML/CFT Enquiry”
Please include enough information for us to identify your account or transaction where necessary, but do not send your password, OTP, or other sensitive credentials by email.