Legal
AML / KYC policy
Version 1.0 · Effective 12 Sep 2026
Anti-Money-Laundering, Counter-Terrorist-Financing and Know-Your-Customer Policy
Version: 1.0 (draft for legal review) · Last updated: 10 September 2026 · Effective: 10 September 2026
Draft. This document has not yet been reviewed by counsel and contains placeholders in — that must be completed before it takes effect.
_This policy is the public statement of our anti-money-laundering programme. The operating procedures, escalation paths, red-flag typologies, thresholds and templates that staff follow are set out in a separate, non-public procedures manual._
1\. Our obligations
1.1 Why this policy exists
Bizik (“Bizik”) holds and moves other people’s money. That makes the Platform attractive to anyone wanting to disguise the origin of funds, finance terrorism, evade sanctions, or defraud another user. We take that seriously, and this policy sets out what we do about it.
We have a zero-tolerance position on money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud and corruption. We would rather lose a customer than process a transaction we do not understand.
1.2 The framework we operate under
Our programme is designed against, among others:
- CEMAC Regulation No. 01/CEMAC/UMAC/CM of 11 April 2016 on the prevention and repression of money laundering, terrorist financing and proliferation financing in Central Africa, and the instruments that supplement or replace it;
- the requirements of the Commission Bancaire de l’Afrique Centrale (COBAC) and the Banque des États de l’Afrique Centrale (BEAC) applicable to us and to our partners;
- CEMAC Regulation No. 01/20/CEMAC/UMAC/COBAC of 3 April 2020 on payment services in CEMAC;
- CEMAC Regulation No. 02/18/CEMAC/UMAC/CM of 21 December 2018 on foreign exchange;
- Cameroonian law, including Law No. 2016/007 of 12 July 2016 (Penal Code) on fraud, breach of trust and laundering of the proceeds of crime;
- the standards of the Financial Action Task Force (FATF) and of GABAC, the Central African regional body;
- United Nations Security Council sanctions measures, and other sanctions regimes binding on us or on our banking and payment partners.
Our regulatory status is stated at —. Where a payment service is provided through —, we operate this programme in a manner consistent with that institution’s own obligations, and we cooperate with its oversight of us.
1.3 Governance
| Role | Responsibility |
|---|---|
| Board / management | Owns the programme, approves this policy and the risk assessment annually, and provides the resources to run it |
| Compliance Officer — | Day-to-day responsibility. Named point of contact for ANIF and for supervisors. Authority to freeze an account, block a transaction and file a report without needing commercial approval |
| Deputy | — acts in the Compliance Officer’s absence |
| Operations and review staff | Perform verification and first-line review under permissioned access |
| Independent review | Periodic testing of the programme by a party independent of the compliance function — |
⚠ The Compliance Officer’s decisions on freezing, blocking and reporting are not commercially overridable. Any attempt to override one is itself a reportable event.
1.4 Risk-based approach
We assess and document the money-laundering and terrorist-financing risk of our business by customer type, product, delivery channel, geography and transaction pattern, and we apply controls proportionate to it. The assessment is reviewed at least annually and whenever we launch a product, enter a market or add a payment rail.
Factors we treat as elevating risk include: a customer who cannot be verified to our standard; a politically-exposed person or their close associate; a customer or counterparty connected to a high-risk or sanctioned jurisdiction; unusual transaction size or velocity relative to the stated purpose; a Deal whose description does not correspond to any real trade; onboarding entirely through a remote channel; and a pattern that suggests structuring.
1.5 Training
Every member of staff receives anti-money-laundering training on joining and at least annually, covering their obligations, the offence of tipping off, how to raise an internal suspicion report, and the typologies relevant to their role. Training is recorded.
2\. Identity verification
2.1 Customer due diligence
We identify and verify every customer. We do not permit anonymous or pseudonymous accounts, and we do not permit an account to be operated for the benefit of an undisclosed person.
We apply customer due diligence:
- before establishing the business relationship, to the extent our tiered model requires;
- before permitting a customer to create a Deal, send money or withdraw;
- when a transaction reaches a threshold or a risk trigger;
- when we doubt the accuracy or adequacy of information previously obtained;
- when we suspect money laundering or terrorist financing, regardless of any threshold or exemption;
- periodically, on a risk-sensitive basis, for the life of the relationship.
2.2 What we collect
Natural persons
- Full legal name as it appears on the identity document.
- Date of birth.
- Nationality and country of residence.
- Phone number, and email where provided.
- An identity document from the accepted list: national identity card, passport, driving licence, or voter’s card, with the document number and images of the front and, where the document has one, the back.
- A selfie holding the document, for the liveness and face-match check.
- The purpose and intended nature of the relationship, and, on a risk basis, the source of funds and source of wealth.
Legal persons — —
Where we onboard a company, partnership or association we additionally obtain its constitutional documents, RCCM registration, registered address, the identity of the natural persons authorised to act, and the identity of the beneficial owners holding or controlling the entity, verified to the same standard as a natural person. We do not accept an entity whose beneficial ownership we cannot establish.
2.3 Access tiers
Access to functions depends on verification. As at the date of this policy:
| Function | Verification required |
|---|---|
| Receive money, check balance, view Deals, share handle | None |
| Pay / fund a Deal | None |
| Create a Deal | Verified (standard tier) |
| Send money to another user | Verified (standard tier) |
| Withdraw | Verified (standard tier) |
Receiving is deliberately not gated: a person being paid should not be forced through verification to accept money that is already theirs. Every route by which value leaves the platform, or by which a customer takes on an obligation, is gated.
2.4 How a submission is assessed
- The documents are sanitised and stored in restricted, access-logged storage; the document number is encrypted at rest.
- An automated analysis measures document quality and legibility, detects faces, compares the selfie against the document photograph, and flags indicators such as a photograph of a screen rather than a document. It produces itemised findings with reasons.
- Reference thresholds are: overall document confidence 0.85, selfie/liveness check 0.90, and face match 0.85.
- ⚠ A person decides. Automatic approval on passing scores is disabled. A trained reviewer examines the documents and the findings and records an approval, a rejection with a reason, or a request for further information. The reviewer’s identity and the time of the decision are recorded.
- A submission that falls below threshold, or that the analysis could not assess, is routed to manual review rather than being rejected automatically.
- The outcome is communicated to the customer, with a reason where we are permitted to give one.
The analysis is advisory. It does not approve, reject or verify anyone.
2.5 Enhanced due diligence
We apply enhanced measures — additional documents, source-of-funds evidence, senior approval to onboard or continue, and closer ongoing monitoring — where:
- the customer or a beneficial owner is a politically exposed person, a family member or a known close associate;
- the customer, counterparty or transaction is connected to a jurisdiction identified as high-risk, or subject to countermeasures;
- the relationship or transaction is unusually complex, unusually large, or has no apparent economic or lawful purpose;
- a sanctions or adverse-media match requires resolution;
- our risk assessment otherwise requires it.
2.6 Simplified due diligence
Where the law permits, and only where the assessed risk is demonstrably low, we may apply simplified measures. Simplified measures are never applied where there is a suspicion, and they never mean no verification at all.
2.7 When we refuse
⚠ We will refuse to open, will restrict, or will close an account, and will not carry out the transaction, where:
- we cannot complete customer due diligence to our satisfaction;
- the customer refuses or fails to provide information we are required to obtain;
- the identity documents appear altered, forged, or do not belong to the person presenting them;
- the customer is a sanctions target, or acting for one;
- the customer is under 18 or lacks capacity;
- we suspect the relationship or transaction is connected to money laundering, terrorist financing or another crime.
Where we form a suspicion, we consider whether to file a report before we terminate, and we follow the tipping-off rules in §4.4.
2.8 Re-verification
We may require re-verification at any time, including where our information has become out of date, where the risk profile changes, where documents have expired, or where a transaction requires a higher assurance.
2.9 Reliance on third parties
Where we rely on a third party to perform an element of due diligence, we remain responsible for it, we satisfy ourselves that the third party is appropriately regulated and supervised, and we ensure that the underlying records can be obtained by us without delay.
3\. Screening and monitoring
3.1 Sanctions screening
We screen customers, and where relevant counterparties and beneficial owners, against applicable sanctions and designated-person lists at onboarding, on any change of name or identity data, on an ongoing basis as lists are updated, and, on a risk basis, at the point of transaction.
A potential match is treated as a hold, not a conviction: the account is restricted while a trained reviewer resolves it. A confirmed match results in a block, a freeze, and reporting to the competent authority. We do not process a transaction for a designated person, and we do not release frozen funds without authority.
⚠ Screening data quality is a control, not a formality. We use a list source of adequate coverage and refresh frequency, and we test the screening against known cases.
3.2 Politically exposed persons
We screen for domestic and foreign politically exposed persons, their family members and close associates. A PEP is not prohibited; a PEP relationship requires senior approval, source-of-funds enquiry and enhanced monitoring.
3.3 Ongoing transaction monitoring
We monitor activity for consistency with what we know about the customer, their stated purpose and their risk profile. Indicators we act on include:
- structuring — transactions repeatedly just below a verification, approval or reporting threshold;
- rapid movement in and straight out again with no economic purpose (pass-through behaviour);
- a sudden change in volume, value or velocity that the profile does not explain;
- a network of accounts transacting circularly, or funding each other in a ring;
- Deals whose description does not correspond to any identifiable trade, or which are repeated verbatim between the same parties;
- multiple accounts sharing a device, an IP address, a payout number or an identity document;
- a customer unwilling to explain the purpose of a transaction, or giving an explanation inconsistent with the record;
- use of a third party’s payment instrument;
- transactions connected to a high-risk jurisdiction;
- adverse media concerning the customer.
3.4 Controls that fire automatically
| Control | Effect |
|---|---|
| Sanctions match | Account restricted pending human resolution; automatic freeze where our configuration requires it |
| Withdrawal at or above 500,000 XAF or equivalent | Held for manual approval before payout |
| Verification below threshold, or unanalysable | Routed to manual review, never auto-approved |
| Money action on WhatsApp | Requires explicit confirmation and a transaction PIN |
| Repeated failed PIN entries | Money actions on the channel locked |
| Mobile Money payout number | Must be verified by one-time code before use |
| Payment from a number the customer did not supply in the session | Refused |
An automatic control is a precaution that triggers human review. It is not a finding against the customer.
3.5 Account states
An account may be active, suspended (restricted, usually pending information or resolution) or frozen (a compliance hold, which only the compliance function may lift). A freeze may be imposed where required by law, by an authority or by a court, or where a compliance concern has arisen.
3.6 Escrow is not a laundering shelter
Money held in escrow is not beyond our reach. Where a suspicion attaches to a funded Deal we may suspend release, freeze the escrowed amount, and decline to act on either party’s instruction until the matter is resolved or an authority directs us.
3.7 Wallet transfers
Wallet-to-wallet transfers are monitored with particular care, because they move value without an underlying trade. Sending requires a verified account. We record the originator and the beneficiary for every transfer and can provide that information to an authority on request.
4\. Reporting
4.1 Internal reporting
Any member of staff who knows or suspects, or has reasonable grounds to know or suspect, that funds are the proceeds of crime or are connected to terrorist financing, must report it internally to the Compliance Officer without delay. There is no threshold, no discretion, and no requirement to be certain. Failing to report is a disciplinary matter and may be a criminal offence.
Staff who report in good faith are protected. Retaliation against them is prohibited.
4.2 External reporting to ANIF
The Compliance Officer assesses each internal report and, where the suspicion stands, files a declaration of suspicion (_déclaration de soupçon_) with the Agence Nationale d’Investigation Financière (ANIF), Cameroon’s financial intelligence unit, in the form and within the time the law prescribes.
We also make any other report the law requires, including reports of transactions above prescribed thresholds, reports concerning designated persons, and responses to requests for information from ANIF, a supervisor, a court or the police.
4.3 Suspension pending a report
Where the law requires or permits us to defer a transaction pending a report or an instruction from ANIF, we will do so.
4.4 Tipping off
⚠ This is the part customers most often misunderstand.
It is a criminal offence to disclose to a customer, or to a third party, that a suspicion report has been made or is contemplated, or that an investigation is being or may be carried out. Accordingly:
- we will not tell you that a report has been filed;
- we will not confirm or deny that one exists;
- where an account is frozen for a reason we may not disclose, our staff will say only that the account is under review and that they cannot say more;
- our staff are trained not to hint, and are not permitted to make an exception for a customer who insists, complains or threatens legal action.
This is not evasiveness or poor service. It is the law, and it binds us.
4.5 Cooperation with authorities
We cooperate fully with ANIF, COBAC, BEAC, GABAC, the police, the courts, tax authorities and their counterparts abroad where an obligation applies to us, and we respond to lawful requests for information within the time required. We do not require a customer’s consent to make a disclosure we are legally obliged to make.
4.6 Fraud reporting to users
Separately from suspicion reporting, where we identify that a user has been targeted by fraud we will warn them where it is lawful and safe to do so, and we will cooperate with a police investigation they initiate.
5\. Record keeping
5.1 What we keep
- Identification data, identity documents and verification records, including the analysis findings and the reviewer’s decision and reasons.
- The full transaction record: amount, currency, date, originator, beneficiary, payment instrument, references, escrow movements, fees and any conversion.
- Deal records, milestone history, delivery submissions, dispute evidence and rulings.
- Correspondence with the customer relevant to due diligence.
- Internal suspicion reports, the Compliance Officer’s assessment, and any external report, together with the supporting material.
- Screening results, including how a potential match was resolved.
- Risk assessments, policy versions, training records and independent-review reports.
- The audit log of significant actions taken on the Platform.
5.2 How long
⚠ Ten (10) years from the end of the business relationship or from the date of the transaction, whichever is later, unless a longer period is required, for example where an investigation or proceeding is open.
Records relating to a suspicion report are retained for at least the same period and are not deleted on a customer’s request. A customer’s right to erasure does not extend to them.
5.3 Form and retrievability
Records are kept in a form that permits reconstruction of an individual transaction and of the relationship as a whole, and are retrievable without delay on a lawful request. Records held by a service provider on our behalf remain retrievable by us.
5.4 Integrity
The audit log is append-only. Financial records are not editable after the fact; a correction is made by a further entry, so that the original and the correction are both visible.
5.5 Confidentiality
Records are treated as confidential and are disclosed only to those who need them, to authorities entitled to receive them, and as described in the Privacy Policy.
6\. What this means for you as a customer
- You will be asked to verify your identity before you can create a Deal, send money or withdraw. Submitting documents does not verify you; a person reviews them.
- You may be asked for more, including where your money comes from. Answer fully. A refusal or an unconvincing answer is itself a risk indicator.
- Use your real name. The name on your account must match your identity document.
- Do not let anyone else use your account, and do not open an account for someone else. Acting as a “money mule” is a crime, and being paid a fee for it is not a defence.
- Do not create Deals with no real trade behind them. A Deal is not a way to move money between your own accounts, and a circular Deal is a red flag, not a technique.
- Expect delays on large withdrawals. A hold above 500,000 XAF is routine.
- If your account is under review and we cannot tell you why, that may be because the law forbids us from telling you. Pressing our support staff will not change it.
- You can complain — see §7 — and you retain every legal remedy available to you.
7\. Review, complaints and contact
This policy is reviewed at least annually and whenever the law, our products or our markets change materially.
| Purpose | Contact |
|---|---|
| Compliance and AML matters | |
| To complain about a decision affecting your account | support@bizik.com, then legal@bizik.com |
| Data-protection questions | privacy@bizik.com — and see the Privacy Policy |
A complaint about a freeze or a refusal will be reviewed by someone other than the person who made the decision, so far as our size permits. We will tell you the outcome, subject always to §4.4.
_Bizik — RCCM — — —, Republic of Cameroon._