Skip to content

AML/CFT Policy

Last updated: · Imaripay Limited

Imaripay Limited is committed to preventing the use of its platform for money laundering, terrorism financing, proliferation financing and other financial crime. This page summarises our Anti-Money Laundering and Countering the Financing of Terrorism (“AML/CFT”) Policy, which is approved by our board of directors and reviewed at least annually.

1. Legal and regulatory framework

Our programme is designed to comply with, among others:

  • the Proceeds of Crime and Anti-Money Laundering Act, 2009 (“POCAMLA”) and the regulations made under it;
  • the Prevention of Terrorism Act, 2012 (“PoTA”) and the Prevention of Terrorism (Implementation of the UN Security Council Resolutions) Regulations;
  • guidance and directions of the Financial Reporting Centre (“FRC”) and the Central Bank of Kenya, including prudential guidelines applicable to payment service providers;
  • the Recommendations of the Financial Action Task Force (FATF); and
  • the AML/CFT requirements of our Partner Institutions and payment networks.

2. Governance

The board has ultimate responsibility for AML/CFT compliance. We have appointed a Money Laundering Reporting Officer (“MLRO”) with sufficient seniority, independence and resources, who is responsible for the day-to-day operation of the programme, reporting to the FRC, and periodic reporting to the board. The programme is subject to independent review.

3. Risk-based approach

We conduct and document an enterprise-wide risk assessment covering customers, products, delivery channels, geographies and transaction types. Every merchant is assigned a risk rating at onboarding which determines the level of due diligence and monitoring applied, and which is reviewed periodically and on trigger events.

4. Know your customer and customer due diligence

  • Identification and verification of every merchant, including legal entity details, registered address, directors, authorised signatories and beneficial owners holding 10% or more, using reliable independent sources.
  • Nature of business: understanding the merchant’s products, customers, expected volumes and source of funds.
  • Enhanced due diligence for higher-risk relationships, including politically exposed persons (PEPs), high-risk jurisdictions, restricted business types and complex ownership structures — including senior management approval and source-of-wealth checks.
  • Ongoing due diligence: periodic refresh of KYC information proportionate to risk, and re-verification on material change.
  • We do not open or maintain anonymous accounts or accounts in fictitious names, and do not establish relationships with shell banks.

5. Sanctions screening

Merchants, their directors and beneficial owners, and payout beneficiaries where applicable are screened against the United Nations Security Council Consolidated List, domestic designations under PoTA, and other lists we consider relevant (including those of the US OFAC, the UK and the EU), at onboarding and on an ongoing basis. Positive matches result in freezing of funds and reporting to the relevant authorities without delay, as required by law.

6. Transaction monitoring

We monitor Transactions using automated rules and manual review to detect unusual patterns, including structuring, rapid movement of funds, activity inconsistent with the merchant’s profile, and use of the platform by prohibited businesses. Alerts are investigated and documented.

7. Reporting

  • Suspicious transaction reports (STRs) are filed with the FRC promptly and in any event within the period prescribed by POCAMLA after suspicion arises.
  • Cash and threshold reports are filed where applicable in accordance with POCAMLA and FRC requirements.
  • Tipping off: staff must not disclose to any person that a report has been or may be made. We may therefore be unable to explain why a Transaction was delayed or an account restricted.

8. Record keeping

We retain customer due diligence records, Transaction records, account files, business correspondence and reports for at least seven (7) years after the end of the business relationship or the date of the occasional Transaction, in a form that allows Transactions to be reconstructed and records to be provided promptly to competent authorities.

9. Training

All staff receive AML/CFT training at onboarding and at least annually, tailored to their role. Staff in compliance, risk and operations receive enhanced training.

10. Merchant obligations

Merchants must provide accurate KYC information, keep it up to date, cooperate with information requests, and not use the Services for any prohibited purpose. We may suspend Services, hold funds or terminate relationships where a merchant fails to meet these obligations or where we suspect financial crime, and will comply with any lawful preservation or freezing order.

11. Contact

Questions about this policy, or requests from regulators and law enforcement, should be directed to our compliance team at compliance@imaripay.com.