Apay policies

AML & KYC Policy

Effective: 1 August 2026

Apay operates a risk-based Anti-Money-Laundering (AML) and Counter-Terrorism-Financing (CTF) programme aligned with FATF recommendations and applicable South Sudan regulations. This page summarises the controls in place. Full internal procedures are available to supervisors and auditors on request.

1. Customer Due Diligence (CDD)

  • Tier 1 (basic wallet): phone verification and self-declared identity — low transaction limits.
  • Tier 2 (verified): government-issued ID + selfie liveness check + address confirmation.
  • Tier 3 (enhanced): Tier 2 plus source-of-funds evidence, for higher-limit and business users.

2. Screening

Every new user is screened against sanctions lists (UN, OFAC, EU, UK) and Politically-Exposed-Person (PEP) databases at onboarding and then re-screened daily while the account is open.

3. Transaction monitoring

  • Automated rules flag structuring, unusual velocity, high-risk corridors, dormant-then-active accounts and device sharing.
  • All alerts are triaged by the compliance team; genuine suspicions are escalated.

4. Reporting

Where we form a suspicion of money laundering or terrorism financing, we file a Suspicious Activity Report (SAR) with the Financial Intelligence Unit in the manner and time-frame required by law. We do not tip off the customer.

5. Record keeping

KYC files, transaction records and SAR working papers are retained for at least 7 years after the account is closed.

6. Governance

  • A named Money-Laundering Reporting Officer (MLRO) owns the programme.
  • Annual independent AML audit; findings tracked to closure by the board.
  • Every staff member completes AML training on hire and annually thereafter.

7. Prohibited activity

We do not knowingly facilitate transactions relating to: sanctioned parties, weapons trafficking, human trafficking, child sexual abuse material, unlicensed gambling, wildlife trafficking, or virtual-asset service providers that are not themselves licensed. Accounts found doing so are frozen and reported.

MLRO / Compliance contact: mlro@apay.ss.

This page is maintained by Apay to describe current practices and controls. It is not legal advice and is not an independent certification of compliance. Where the text conflicts with a signed customer agreement, the signed agreement governs.