Grymey

Compliance

Anti-Money Laundering, Counter-Terrorism and Proliferation Financing, and Anti-Bribery and Corruption Policy

Grymey Technologies Limited · RC No. 8749776 · Last updated: July 2026 · Version 1.0

Part 1

Anti-Money Laundering (AML) Policy

1.1 Introduction and Regulatory Framework

1.1.1 Objective

Grymey Technologies Ltd ("the Company") maintains an absolute zero-tolerance mandate regarding Anti-Money Laundering (AML), Countering the Financing of Terrorism (CFT), and Countering Proliferation Financing (CPF). This document defines the institutional rules and automated control mechanisms built natively into our product architecture to prevent our platform from being used for illicit finance.

1.1.2 Regulatory Alignment

This program is designed and calibrated to comply strictly with:

Nigeria

  • Money Laundering (Prevention and Prohibition) Act 2022
  • Terrorism (Prevention and Prohibition) Act 2022
  • Central Bank of Nigeria (CBN) AML/CFT/CPF Regulations and CBN Baseline Standards for Automated AML Solutions
  • Banks and Other Financial Institutions Act (BOFIA)
  • Nigeria Data Protection Commission (NDPC) Act

International

  • Financial Action Task Force (FATF) Recommendations
  • Applicable United Nations Security Council Resolutions (UNSCRs)
  • OFAC Specially Designated Nationals (SDN) and Consolidated Sanctions Lists
  • Applicable EU and UK sanctions regimes

Regional and International Expansion

Where Grymey operates or intends to operate within the West African Economic and Monetary Union (WAEMU) region, the Company will comply with applicable BCEAO payment service and AML/CFT directives and obtain the required regulatory authorizations prior to commencement of operations in each jurisdiction. This policy applies globally to all Grymey entities and subsidiaries. Local implementation may include additional jurisdictional-specific watchlists, reporting contacts, and regulatory filings, consistent with this global framework.

1.1.3 Governance and Oversight

Ultimate responsibility rests with the Board of Directors. Daily operations, compliance engineering audits, automated rules calibration, and regulatory escalations are managed exclusively by our designated Compliance Officer. This individual possesses the executive authority to execute real-time administrative freezes on any wallet balance or API pathway deemed anomalous. This policy shall be reviewed and formally re-approved by the Board of Directors on an annual basis, or more frequently as regulatory changes or business developments necessitate.

1.2 Customer Due Diligence (CDD) and KYB Tiering

1.2.1 Individual Onboarding (KYC)

The Company enforces an immutable identity verification process prior to ledger activation. For individual retail wallets, the platform programmatically collects full legal name, residential address, verified email address, phone number, and date of birth. This data is validated instantly against national databases through secure API infrastructure integrations checking Bank Verification Numbers (BVN) or National Identification Numbers (NIN), coupled with required biometric liveness detection.

1.2.2 Corporate Merchants and Global B2B Issuers (KYB)

For commercial entities utilizing our cross-border global checkout and invoicing rails, Grymey implements a mandatory business authentication gate. Merchants must submit:

  • Validated Corporate Affairs Commission (CAC) registration profiles (RC/BN numbers)
  • Official Corporate Tax Identification Numbers (TIN) cross-verified against relevant local authorities
  • Full identity screening, documentation, and biometric validation of all directors and Ultimate Beneficial Owners (UBOs) holding a stake greater than or equal to 5% equity

1.2.3 Risk Tiering Framework

Following the completion of onboarding verification, all customers and merchants are assigned a risk classification:

Risk LevelExamplesApplicable Measures
LowRegulated local businesses, established SMEs with clean track recordsStandard CDD/KYB as described in Sections 1.2.1 and 1.2.2
MediumNewly incorporated entities, international merchants from low-risk jurisdictionsStandard CDD/KYB + enhanced document verification and review of financial history
HighPEPs, entities operating in or originating from High-Risk Jurisdictions, cash-intensive businesses, non-profit organizationsEnhanced Due Diligence (EDD): Mandatory collection of source of wealth, source of funds, independent verification of submitted documents, and senior management approval for onboarding

High-risk relationships are subject to more frequent transaction monitoring reviews and mandatory six-monthly periodic recertification of KYC/KYB documentation.

1.2.4 Prohibited Entity Types and Pre-Screening

Prior to the commencement of any onboarding data collection, all prospective customers and merchants shall be screened against the sanction lists referenced in Section 1.3.1. Any confirmed match shall result in immediate rejection without further processing. Grymey explicitly prohibits establishing business relationships, issuing ledgers, or processing transactions for shell banks, unverified corporate vehicles, anonymous accounts, or individuals operating under fictitious names. Politically Exposed Persons (PEPs) and merchants operating inside High-Risk Jurisdictions are restricted from regular access and are routed into manual Enhanced Due Diligence (EDD) pipelines.

1.3 Automated Real-Time Sanctions Screening

1.3.1 Multi-List Cross-Referencing

Before the initialization of any local virtual account rail, incoming digital dollar balance, or cross-border settlement, the automated processing engine screens all platform originators and beneficiaries against mandatory domestic and international sanction datasets, including:

  • CBN Domestic Watchlist and the Nigerian Financial Intelligence Unit (NFIU) Internally Designated Persons List
  • Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) Index
  • United Nations Security Council Consolidated List

1.3.2 Fuzzy Matching Protocols

To ensure compliance with modern baseline standards, screening is conducted utilizing advanced phonetic matching, alias handling, and transliteration algorithms. This eliminates the vulnerability of exact-match evasions by flagging spelling modifications or structural script alterations. Confirmed matches instantly lock the account and place a hard programmatic hold on all linked settlement webhooks.

1.3.3 Ongoing Continuous Screening

Sanctions and watchlist screening is conducted not only at onboarding but continuously on an ongoing basis for all customers, merchants, and beneficiaries. The Company maintains a daily synchronization schedule with all referenced watchlists. Any new designation or updated list entry is immediately cross-referenced against our entire customer database, and any confirmed match triggers the account lock and hard hold procedures defined in Section 1.3.2.

1.4 Transaction Monitoring and Automated Guardrails

1.4.1 Velocity and Anti-Structuring (Smurfing) Controls

The internal ledger monitors transaction patterns continuously. Programmatic limits are hardcoded to detect structuring attempts -- the intentional splitting of high-value invoices into smaller, rapid batches designed to circumvent standard processing flags or our maximum credit card limit caps.

1.4.2 Behavioral Profile Deviation

Every verified corporate merchant is assigned an operational threshold baseline during onboarding based on their declared industry vertical and expected monthly volumes. The system automatically triggers an automated alert and suspends outward settlements when:

  • Transaction volume exceeds 150% of the calibrated merchant baseline within any 30-day rolling period
  • A merchant executes three or more transactions that individually exceed 90% of the applicable daily or per-transaction limit within a 2-hour window
  • Cumulative daily transaction volume increases by more than 200% compared to the previous 7-day average without a pre-approved justification

Any such alert is immediately escalated to the Compliance Officer for review.

1.4.3 Alert-to-Report Investigation Workflow

Upon the triggering of any automated alert under Sections 1.4.1 or 1.4.2, the following process is immediately initiated:

  1. System Alert: Automated rule triggers and a programmatic hold is placed on the affected wallet or settlement webhook.
  2. Compliance Review: The Compliance Officer accesses all relevant transactional, customer, and beneficiary data within 2 hours of the alert.
  3. Disposition: The Compliance Officer determines the alert is either dismissed (classified as a false positive with documented rationale) or escalated (classified as a true positive requiring further investigation).
  4. STR Filing: If escalated and confirmed as suspicious, the Compliance Officer proceeds to the STR filing process defined in Section 1.5.1.
  5. Documentation: All steps, decisions, and rationale are recorded within the compliance management system and preserved under Section 1.4.4.

1.4.4 Immutable Record Retention

In strict compliance with regulatory rules, all customer onboarding records, verified identity tokens, physical documentation logs, and chronological transaction ledger histories are securely preserved in an encrypted state for a minimum period of five (5) years from the date of profile termination or account closure.

1.5 Regulatory Escalation and Reporting

1.5.1 NFIU 24-Hour Reporting Window

When transaction alerts are evaluated by the compliance desk and deemed a true positive for financial crime or illicit structuring, the Company automatically converts the log data into a formal Suspicious Transaction Report (STR) schema. This is prepared for transmission to the Nigerian Financial Intelligence Unit (NFIU) within 24 hours of formal determination. The Compliance Officer is responsible for ensuring that each STR contains all relevant transactional, customer, and contextual information necessary for the NFIU to conduct its analysis, including customer identification data, transaction amounts and dates, beneficiary details, and a narrative description of the suspicious activity observed.

1.5.2 Whistleblower and No-Tipping-Off Policy

All employees, directors, and contractors are strictly prohibited from disclosing to any person, including the subject of an investigation, that a Suspicious Transaction Report (STR) has been or will be filed, or that an investigation is ongoing. This prohibition applies both during and after employment with the Company. Any breach of this confidentiality obligation shall constitute gross misconduct and shall result in severe disciplinary action, up to and including termination of employment and referral for legal prosecution. The Company encourages all personnel to report any actual or suspected breaches of this policy through confidential internal whistleblowing channels.

Part 2

Counter-Terrorism and Proliferation Financing (CTF/CPF) Policy

2.1 Policy Statement and Scope

Grymey Technologies Ltd maintains an absolute zero-tolerance policy for the platform's utilization in financing terrorism, terrorist acts, or the proliferation of weapons of mass destruction. The Company operates in strict adherence to the Terrorism (Prevention and Prohibition) Act 2022, Central Bank of Nigeria (CBN) AML/CFT/CPF Regulations, Financial Action Task Force (FATF) Recommendations (specifically 5, 6, and 7), and applicable United Nations Security Council Resolutions (UNSCRs).

This policy applies globally to all Grymey entities and subsidiaries. Local implementation may include additional jurisdictional-specific watchlists, reporting contacts, and regulatory filings, consistent with this global framework.

2.2 Sanctions and Watchlist Screening

All natural and legal entities, including Ultimate Beneficial Owners, undergo automated, real-time screening at onboarding and prior to every transaction against:

  • The UN Consolidated Sanctions List
  • The Nigeria Sanctions List (NFIU / Nigeria Sanctions Committee)
  • The OFAC Specially Designated Nationals (SDN) and Consolidated Sanctions Lists
  • Applicable regional and international PEP and sanctions databases
  • EU and UK terrorism and sanctions lists

Screening is conducted utilizing advanced fuzzy matching protocols, including phonetic matching, alias handling, and transliteration algorithms to eliminate the vulnerability of exact-match evasions.

2.3 Retrospective Screening and Lookbacks

Whenever a sanctions list or watchlist update is published by relevant authorities, the Grymey system automatically triggers a retrospective lookback scan across all active, dormant, and historical account records to identify prior exposure or linked assets. This lookback includes:

  • All active customer and merchant accounts
  • Dormant accounts with any historical transaction activity
  • Historical transaction records dating back the full retention period
  • Linked wallets, cards, and settlement channels

Any confirmed match identified through a lookback triggers the asset freezing and reporting procedures defined in Sections 2.4 and 2.5.

2.4 Instant Asset Freezing and Hard Holds

Upon a confirmed match or designation by a competent authority, the Company shall immediately, without prior notice to the target entity, execute a programmatic hard hold, freezing all linked:

  • Digital cards (virtual and physical)
  • Multi-currency wallets
  • Settlement channels
  • API webhooks
  • Any other linked assets or economic resources

The freeze shall be executed without delay and maintained until the Company receives explicit instructions from the relevant competent authority.

2.5 Regulatory Escalation and Mandatory Reporting

Any match, attempted transaction, or asset freeze resulting from CTF/CPF designations must be formally escalated and reported to:

  • The Nigerian Financial Intelligence Unit (NFIU)
  • The Central Bank of Nigeria (CBN)
  • Other relevant competent authorities as required by applicable law

Reporting Timeline: All reports shall be filed within 24 hours of identification.

Reporting Content: Each report shall include, at minimum, customer and beneficiary identification data, transaction amounts, dates and counterparties, details of frozen assets, a narrative description of the suspicious activity or match, and any other information required by the competent authority.

2.6 High-Risk Typologies and Ongoing Monitoring

In addition to automated list matching, transaction monitoring engines continuously evaluate behavior for terrorism financing red flags, including:

  • Structuring transactions below reporting thresholds destined for high-risk jurisdictions or conflict zones
  • Rapid velocity of funds routed through non-profit entities or newly incorporated trade businesses without verifiable commercial substance
  • Rapid card issuance and immediate exhaustion across merchants in high-risk geographic areas
  • Transactions involving jurisdictions identified as having strategic AML/CFT deficiencies by the FATF
  • Unexplained spikes in cross-border inbound or outbound volume to high-risk border regions
  • Transactions involving non-profit or NPO accounts with unverified Ultimate Beneficial Owners
  • Rapid movement of funds across multiple international channels without obvious business purpose
  • Any transaction involving a jurisdiction subject to UN, OFAC, or EU sanctions

All flagged activity is immediately escalated to the Compliance Officer for investigation.

2.7 No-Tipping-Off Obligation

Pursuant to statutory requirements, all Grymey directors, officers, employees, and third-party contractors are strictly prohibited from disclosing to any user, counterparty, or unauthorized third party that a terrorism financing query, investigation, or NFIU report has been initiated or filed.

This prohibition applies both during and after employment or engagement with the Company. Any breach of this confidentiality obligation shall constitute gross misconduct and shall result in severe disciplinary action, up to and including termination of employment or engagement and referral for legal prosecution.

2.8 Record Keeping

All CTF/CPF-related records, including sanctions screening logs, lookback scan results, asset freeze records, regulatory reports, and investigation documentation, shall be securely preserved in an encrypted state for a minimum period of five (5) years from the date of the relevant activity or account closure.

Part 3

Anti-Bribery and Corruption (ABC) Policy

2.1 Zero-Tolerance Statement

Grymey Technologies Ltd operates under an absolute zero-tolerance policy regarding bribery and corruption in all its forms. We are committed to conducting our business with integrity, transparency, and fairness in all our dealings, whether with customers, partners, vendors, or regulatory authorities.

2.2 Prohibited Activities

The following activities are strictly prohibited:

Offering, giving, or accepting bribes

No employee, contractor, or agent of Grymey shall offer, promise, give, or accept any bribe, whether directly or indirectly, to influence a business decision or gain an improper advantage.

Facilitation payments

Small or "facilitation" payments made to speed up routine government actions (e.g., processing permits, clearing customs) are prohibited, even if they are customary in certain jurisdictions.

Gifts and hospitality

Offering or accepting gifts, hospitality, or entertainment that could be perceived as influencing a business decision is prohibited. Reasonable and proportionate gifts of modest value are permitted but must be transparent and properly recorded. Any gift valued above N50,000 (or its equivalent in other currencies) must be pre-approved and logged in the internal Gift Register.

Kickbacks

No employee shall accept or solicit any form of kickback, commission, or other payment in connection with the Company's business.

Political contributions

Grymey does not make political contributions in any form, and employees are prohibited from using Company funds for political purposes.

2.3 Scope and Application

This policy applies to:

  • All employees and directors of Grymey Technologies Ltd
  • All contractors, consultants, and agents acting on behalf of Grymey
  • All third-party partners and vendors doing business with Grymey
  • All subsidiaries, affiliates, and joint ventures under Grymey's control

Any third party acting on Grymey's behalf must be contractually bound to comply with this policy and applicable anti-bribery laws. Key vendors and high-risk partners shall undergo pre-engagement screening and due diligence prior to onboarding.

2.4 Reporting and Whistleblowing

2.4.1 Internal Reporting

Any employee or third party who suspects, witnesses, or has reasonable grounds to believe that a bribe or act of corruption has occurred must report it immediately to:

2.4.2 Protection from Retaliation

Grymey strictly prohibits retaliation against any individual who raises a concern in good faith under this policy. Employees who report concerns will be protected from dismissal, demotion, or any other form of discrimination.

2.4.3 Investigation

All reports will be investigated promptly and thoroughly by the Compliance Officer. Investigations will be conducted with discretion and confidentiality to the extent reasonably possible.

2.5 Consequences of Violation

Any violation of this ABC policy constitutes gross misconduct. Consequences may include:

  • Disciplinary action: Up to and including termination of employment or engagement
  • Legal action: Referral for criminal prosecution under the Corrupt Practices and Other Related Offences Act 2000, the Economic and Financial Crimes Commission (EFCC) Act 2004, the Money Laundering (Prevention and Prohibition) Act 2022, and other applicable laws
  • Reputational damage: Public disclosure and reputational harm
  • Civil liability: Recovery of damages or losses suffered by the Company

Part 4

Effective Date and Review

3.1 Effective Date

This policy is effective as of July 2026. It shall be reviewed annually or upon material changes to applicable regulations or the Company's business model. The Compliance Officer is responsible for its implementation, maintenance, and periodic review.

3.2 Contact

Grymey Technologies Limited

RC No. 8749776

Compliance: compliance@grymey.com

Fraud: fraud@grymey.com

← Sign Up

© 2026 Grymey Technologies Ltd