Last updated: July 24, 2026
This Anti-Money Laundering (AML) Policy sets out the framework, procedures, and controls AchiPay (operated by JAFA Tech Limited) has implemented to prevent, detect, and report money laundering, terrorist financing, and other financial crimes. We are committed to complying with all applicable AML/CFT laws in every jurisdiction we operate in, maintaining robust and proportionate controls, fostering a culture of compliance, cooperating fully with regulators and law enforcement, and protecting our platform from being used for financial crime. This Policy applies to all directors, officers, employees, contractors, agents, and users of AchiPay, and any violation may result in account suspension or termination and reporting to the relevant authorities.
In the UK, we comply with the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (effective 30 June 2026), the Sanctions and Anti-Money Laundering Act 2018, the Proceeds of Crime Act 2002, the Terrorism Act 2000, and FCA guidance for payments and e-money firms. In Nigeria, we comply with the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, the NFIU Act 2018, the CBN AML Baseline Standards for Automated AML Solutions, and CBN KYC requirements for fintechs.
The JAFA Tech Limited Board of Directors holds ultimate responsibility for AML compliance, ensuring adequate resources, regular framework review, and a strong compliance culture. We have appointed a Money Laundering Reporting Officer (MLRO) with senior management responsibility, who oversees this Policy, reviews internal suspicious activity reports, decides on SAR filings, liaises with regulators and law enforcement, reports to the Board, and ensures staff training. A dedicated Compliance Team supports the MLRO with day-to-day monitoring, customer due diligence, investigations, record-keeping, and periodic risk assessments, and senior management is accountable for ensuring AML controls operate effectively in practice.
We conduct a Business-Wide Risk Assessment (BWRA) considering customer risk, product risk (WhatsApp payments, cross-border transfers, and future products), geographic risk across the 70+ countries we operate in, delivery-channel risk, and transactional risk. The BWRA is a living document, reviewed at least annually and updated whenever our business model, customer base, products, or risk environment change materially, with customer risk profiles updated automatically as behaviour or data changes. We also assess jurisdictional risk based on each country's AML framework, FATF mutual evaluation results, sanctions exposure, corruption indices, and our own transaction data.
We conduct CDD when onboarding a new customer, when a customer's risk profile changes materially, where money laundering or terrorist financing is suspected, or where required by law. For individuals we collect and verify full legal name, date of birth, residential address, phone number (via WhatsApp), email, and government-issued ID with a selfie; for businesses we collect business name and registration details, registered address, nature of business, Ultimate Beneficial Owners, directors, and bank account details. We use automated or semi-automated KYC systems, including real-time checks against government databases such as BVN and NIN, third-party document verification, biometric selfie matching, and liveness detection. Sanctions and PEP screening is conducted in real time before onboarding and before transaction approval against domestic and global watchlists, internal risk registers, and adverse media, and any match automatically blocks onboarding or holds the transaction. KYC records are retained for at least 5 years after a customer relationship ends.
Mandatory EDD applies to customers from FATF "Call for Action" (black list) countries, Politically Exposed Persons (PEPs), and customers from high-risk jurisdictions. Risk-based EDD applies to unusually complex or large transactions, higher-risk customer profiles, unusual transaction patterns, and cross-border transfers to high-risk jurisdictions. EDD measures include obtaining additional source-of-funds and source-of-wealth information, enhanced ongoing monitoring, senior management approval for the relationship, and more frequent risk-profile reviews. Where risk is low, we may apply Simplified Due Diligence (SDD), a decision that is documented and reviewed regularly.
We use automated transaction monitoring, as required by the CBN for regulated financial institutions, incorporating customer segmentation, peer-group analysis, behavioural profiling over time, AI/ML models for emerging risks, and linkage to KYC data and customer risk assessments. We monitor for unusually large or frequent transactions, transfers to or from high-risk jurisdictions, transactions involving sanctioned parties, structuring to avoid reporting thresholds, rapid movement of funds, and activity inconsistent with a customer's profile. Alerts present a consolidated view — identity, risk profile, transaction history, and prior alerts — so compliance teams can act efficiently. Our AI/ML monitoring models are validated at least annually for accuracy and bias, and fraud signals feed directly into each customer's risk profile.
All employees must report suspicious activity to the MLRO immediately, including transactions inconsistent with a customer's profile, reluctance to provide ID, activity involving high-risk jurisdictions, or apparent structuring. The MLRO files SARs with the National Crime Agency in the UK (via SAR Online, without delay) and with the Nigerian Financial Intelligence Unit in Nigeria (within 24 hours). We protect employees who report in good faith, and maintain a strict "tipping off" prohibition — no one may inform a customer that a SAR has been or will be filed, as doing so is a criminal offence in the UK and Nigeria. SARs and supporting documentation are retained securely for at least 5 years.
We maintain comprehensive, tamper-proof, and retrievable records of customer identification, transaction data, CDD/EDD documentation, monitoring alerts and outcomes, SARs, training records, risk assessments, and audit trails. Customer identification records, transaction records, SARs, and training records are each retained for 5 years, and our governance framework undergoes independent internal audit at least annually.
All new employees receive AML training covering the legal framework, this Policy, identifying and reporting suspicious activity, and consequences of non-compliance, with regular refresher training updated for regulatory changes and emerging risks, and enhanced role-specific training for compliance, operations, and product teams. Our AML framework is independently audited internally at least once a year, covering control effectiveness, policy compliance, SAR quality and timeliness, staff training, and record-keeping, with external consultants engaged where appropriate and any deficiencies remediated through a tracked corrective action plan. We cooperate fully with inspections by the FCA, CBN, NFIU, and other relevant regulators.
Under the UK's 2026 AML Regulations, we maintain a thorough Business-Wide Risk Assessment, an appointed MLRO, robust CDD/EDD, comprehensive record-keeping, staff training, and SAR filing. Under the CBN AML Baseline Standards, we submitted a formal compliance roadmap to the CBN by June 10, 2026, and are working toward full compliance by March 2028, deploying automated CDD, real-time sanctions/PEP screening, advanced transaction monitoring, and dynamic risk scoring linked to KYC data. Our internal roadmap runs through four phases — foundation (Q3 2026), implementation (Q4 2026–Q1 2027), integration (Q2–Q4 2027), and full compliance (Q1 2028) — each with defined governance, milestones, and training workstreams.
AchiPay must not be used for money laundering, terrorist financing, fraud, drug trafficking, human trafficking, illegal gambling, sanctions violations, or any other illegal activity. We do not accept customers subject to UK, UN, US, or EU sanctions, those on terrorist watchlists, those convicted of money laundering or terrorist financing offences, those from FATF black-list countries, or PEPs without adequate justification and senior management approval. We do not conduct business involving FATF black-list countries, UK/UN-sanctioned jurisdictions, or any jurisdiction where adequate due diligence is not possible. Violations may result in immediate account suspension or termination, reporting to regulators and law enforcement, civil action, and criminal prosecution where applicable.
AML-related information, including SARs and investigations, is strictly confidential and accessible only to the MLRO, authorised compliance staff, senior management on a need-to-know basis, and regulators or law enforcement as required — "tipping off" a customer is a criminal offence. We screen all customers and transactions in real time — before onboarding, before every transaction, and periodically thereafter — against UK (OFSI), UN, US (OFAC), EU, and Nigerian sanctions lists. Any sanctions match results in an immediate transaction block, account freeze, MLRO notification, and a report to the relevant authorities.
Employees may report concerns directly to the MLRO, through the compliance team's confidential channel, or a designated whistleblowing hotline where available, and we prohibit retaliation, disciplinary action, or victimisation against good-faith whistleblowers. This Policy is reviewed at least annually and updated promptly to reflect changes in UK or CBN AML requirements, FATF guidance, and emerging typologies, with significant changes communicated to employees, customers where applicable, and regulators where required.
If you have questions or concerns about this AML Policy or our compliance practices, contact us at info@achipay.com (also reaching our MLRO), via achipay.com, or by post at JAFA Tech Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.