AML / CFT / CPF Policy
Anti-Money Laundering, Counter-Terrorist Financing and Counter-Proliferation Financing
1.0 Policy Statement
KudiLink Financial Services Limited (“KudiLink”) is committed to preventing its products, services, channels, and infrastructure from being used for money laundering (“ML”), terrorist financing (“TF”), or proliferation financing (“PF”).
This policy establishes the minimum standards for compliance with applicable Nigerian laws and international regulatory frameworks, including:
- Money Laundering (Prevention and Prohibition) Act 2022
- Terrorism (Prevention and Prohibition) Act 2022
- Central Bank of Nigeria (CBN) AML/CFT/CPF Regulations (latest edition)
- Nigerian Financial Intelligence Unit (NFIU) Guidelines
- Financial Action Task Force (FATF) Recommendations
KudiLink adopts a strict risk-based approach (RBA) to customer onboarding, ongoing monitoring, sanctions screening, and suspicious transaction reporting.
2.0 Objectives
- Prevent the use of KudiLink's financial services for illicit activities.
- Identify, assess, and mitigate ML/TF/PF risks across products, customer profiles, and delivery channels.
- Ensure mandatory and timely filing of Suspicious Transaction Reports (STRs) and prescribed regulatory declarations to the NFIU.
- Maintain robust internal compliance controls, clear governance, and mandatory employee training.
- Ensure full alignment with FATF standards and Nigerian statutory requirements.
3.0 Governance Structure
- Board of Directors: Approves the overall AML/CFT/CPF compliance framework, sets risk appetite, and reviews quarterly compliance reports.
- Senior Management: Implements board-approved policies, allocates requisite resources, and ensures daily operational compliance.
- Chief Compliance Officer (CCO): Oversees the execution of the AML/CFT/CPF program, serves as regulatory liaison to NFIU/CBN, and monitors compliance metrics.
- All Employees: Required to strictly comply with policy mandates and immediately escalate any suspicious transaction or customer activity.
4.0 Risk-Based Approach (RBA)
KudiLink conducts periodic Company-Wide Risk Assessments (CWRA) evaluating:
- Customer Risk: Individual vs. corporate profiles, background, occupation, and PEP status.
- Product / Service Risk: Loan tenure, transaction volume, and disbursement mechanisms.
- Delivery Channel Risk: Non-face-to-face digital onboarding and app-based interactions.
- Geographic Risk: High-risk regional locations or cross-border touchpoints.
- Transaction Risk: High velocity, irregular repayment sources, or unusual patterns.
Risk Ratings: Customers are categorized as Low, Medium, High, or Prohibited. Enhanced Due Diligence (“EDD”) is mandatory for all High-Risk categories.
5.0 Customer Due Diligence (CDD)
CDD must be executed:
- At the point of customer onboarding prior to establishing a business relationship.
- When doubts arise regarding the authenticity or adequacy of previously obtained identification data.
- When transactions appear inconsistent with the customer's known financial profile.
- Whenever there is a suspicion of money laundering, terrorist financing, or proliferation financing.
CDD measures include identity verification via official government databases (NIN, BVN), establishing beneficial ownership for corporate accounts, verifying the nature of the business relationship, and conducting ongoing monitoring.
6.0 Enhanced Due Diligence (EDD)
EDD is mandatory for high-risk categories, including:
- Politically Exposed Persons (PEPs) and their family members or close associates.
- High-value or unusually complex transactions.
- Businesses operating in high-risk sectors (crypto-assets, gaming/gambling, firearms, foreign exchange trading).
- Non-resident applicants or entities located in FATF high-risk jurisdictions.
EDD Measures Include: Obtaining Senior Management/Compliance approval prior to account activation, mandatory verification of source of funds and source of wealth, and increased transaction monitoring frequency.
7.0 Ongoing Monitoring & Sanctions Screening
KudiLink maintains automated, continuous transaction monitoring to detect:
- Abnormal transaction patterns, volume spikes, and high velocity.
- Structuring or smurfing designed to evade regulatory reporting thresholds.
- Unusual geographic transfer flows.
- Real-time screening against global UN, OFAC, NFIU, and CBN sanctions watchlists.
8.0 Reporting Obligations
Suspicious Transaction Reports (STRs) will be filed with the NFIU in strict accordance with statutory deadlines.
Prohibition of Tipping-Off: Directors, officers, and employees of KudiLink are strictly prohibited by law from disclosing to a customer or third party that an STR or related investigation has been submitted or is being conducted.
9.0 Record Keeping
All Customer Due Diligence documents, transaction records, monitoring logs, risk scoring sheets, and STR filings must be retained securely for a minimum period of five (5) years following the termination of the business relationship or completion of the transaction, in line with CBN AML/CFT regulations.
10.0 Staff Training
Mandatory annual AML/CFT/CPF training is conducted for all staff members, with specialized advanced training provided to high-risk units (Compliance, Credit Risk, Customer Onboarding, and Support).
11.0 Independent Audit
KudiLink's AML/CFT/CPF compliance framework and internal controls undergo annual independent audit testing by qualified external auditors to evaluate program effectiveness.
12.0 Policy Inquiries
All questions, escalations, or inquiries regarding this AML/CFT/CPF Policy should be directed to the Legal & Compliance Department:
KudiLink Financial Services Limited — Legal & Compliance
E-mail: compliance@kudiloans.com | legal@kudiloans.com
Address: Propertygate Centre (3rd Floor), 2 The Rock Drive, Lekki Phase 1, Lagos State, Nigeria.