Anti-Money Laundering & Counter-Terrorism Financing Policy
instantcards (Sanaga Digital) is committed to the highest standards of anti-money laundering (AML) and counter-terrorism financing (CFT) compliance. We recognise that financial technology platforms can be misused for financial crime, and we take our obligations and responsibilities in this regard with the utmost seriousness. This Policy sets out the framework we apply to prevent, detect, and report financial crime across all markets in which we operate.
Zero tolerance: instantcards has zero tolerance for money laundering, terrorist financing, sanctions evasion, or any other financial crime. Any user found to be using the platform for such purposes will have their account immediately frozen, funds held pending investigation, and the matter reported to the relevant authorities.
1. Regulatory Framework
Our AML/CFT programme is designed to comply with, and exceed where possible, the requirements of:
- COBAC Regulation R-2019/02 on electronic money institutions (Cameroon and the CEMAC zone)
- FATF (Financial Action Task Force) Recommendations on AML/CFT, including the 2012 Recommendations and subsequent updates
- FATF Guidance on Digital Payment Tokens and Virtual Assets (to the extent applicable)
- Applicable national AML/CFT legislation in each country where instantcards operates, including but not limited to Cameroon's Law No. 2005/015 on the Suppression of Money Laundering and Terrorist Financing
- OFAC (Office of Foreign Assets Control) regulations applicable to USD-denominated transactions
- UN Security Council sanctions resolutions implemented in each operating jurisdiction
- EU consolidated sanctions list (as reference for international best practice)
- The AML/CFT compliance requirements imposed by our licensed partners: Flutterwave, CinetPay, Sudo Africa, and their respective card network partners (Visa, Mastercard)
2. Regulatory Model and Licence Structure
instantcards operates as a technology aggregation layer, not as a licensed e-money institution or card issuer. The AML/CFT obligations are shared across the following licensed entities in our value chain:
| Regulated function | Licence holder | instantcards role |
|---|---|---|
| Mobile money account holding and transfer | MTN, Orange, Safaricom, and other MNOs (each independently licensed) | Technology interface only — never holds MoMo float |
| Payment aggregation and USSD routing | Flutterwave (licensed across multiple jurisdictions) and CinetPay | API client — bound by their AML/CFT terms |
| Card issuance and card programme management | Sudo Africa (Visa/Mastercard programme manager licence) | API client — bound by Sudo Africa and card network AML requirements |
| KYC identity verification | Smile Identity (licensed identity verification provider) | API client for Tier 2 KYC |
Despite this structure, instantcards accepts that it has independent AML/CFT obligations as a financial technology intermediary and takes full responsibility for the controls described in this Policy.
3. Know Your Customer (KYC) Programme
3.1 Customer Identification and Verification
All users must be identified and verified before they can transact above Tier 0 limits. Our KYC programme applies Customer Due Diligence (CDD) and, where appropriate, Enhanced Due Diligence (EDD):
| Tier | Due Diligence Level | Verification | Monthly Limit (XAF equivalent) |
|---|---|---|---|
| Tier 0 | Simplified CDD | Phone number (via MNO KYC) | XAF 150,000 |
| Tier 1 | Standard CDD | Self-declared national ID or passport number | XAF 450,000 |
| Tier 2 | Standard CDD + biometric | Document photo + Smile Identity biometric check | XAF 1,500,000 |
| EDD | Enhanced Due Diligence | Additional information required (source of funds, PEP declaration, etc.) | Case-by-case |
3.2 Enhanced Due Diligence Triggers
EDD is applied automatically or upon manual review trigger to any user who:
- Is identified as a Politically Exposed Person (PEP) or close associate of a PEP
- Transacts at unusually high volumes relative to their stated profile
- Exhibits transaction patterns consistent with structuring (deliberate transactions just below reporting thresholds)
- Is resident in a country on the FATF grey list or black list
- Has been flagged by our automated monitoring system for unusual behaviour
- Requests significant changes to their account (e.g. phone number change) shortly after high-value transactions
3.3 Ongoing Monitoring
KYC is not a one-time event. We conduct ongoing due diligence including:
- Periodic re-verification of high-tier users
- Re-verification triggers on suspicious activity or significant account changes
- Watchlist screening on an ongoing basis (not just at onboarding)
4. Transaction Monitoring and Controls
4.1 Automated Monitoring
All transactions are monitored in real-time by our automated systems for the following patterns:
- Velocity controls: Maximum number of top-up transactions per user per 24-hour period; maximum daily and monthly wallet throughput by KYC tier
- Threshold monitoring: Transactions approaching or exceeding reporting thresholds automatically trigger manual review
- Structuring detection: Multiple transactions just below round-number thresholds within a short period are flagged
- Unusual timing: Transactions at unusual hours or in unusually rapid succession are flagged
- Geographic anomalies: Cards used in unusual geographic patterns relative to the user's registered country
- Merchant category codes (MCCs): Transactions on restricted or high-risk MCCs are flagged and reviewed
4.2 Manual Review
Flagged transactions and accounts are reviewed by a compliance officer within 2 business days. The compliance officer may: clear the flag and allow the transaction; request additional information from the user; suspend the account pending further investigation; or escalate to Suspicious Activity Reporting (SAR).
4.3 Record Keeping
All transaction records are retained for a minimum of 7 years from the date of the transaction, in a format that can be retrieved and submitted to regulators on request within a reasonable timeframe. Records include: transaction amount, currency, timestamp, provider reference, settlement status, user ID, and the full Flutterwave/CinetPay verification response.
5. Sanctions Screening
instantcards screens all users at registration and on an ongoing basis against the following sanctions lists:
- US Treasury OFAC Specially Designated Nationals (SDN) list
- UN Security Council consolidated sanctions list
- EU consolidated financial sanctions list
- UK HM Treasury financial sanctions list
- African Union sanctions designations (where applicable)
- COBAC and BEAC watchlists (Cameroon/CEMAC)
A positive match or potential match triggers immediate account suspension and escalation to the compliance officer. Confirmed matches result in permanent account termination, freezing of all wallet funds pending regulatory direction, and mandatory reporting to the relevant Financial Intelligence Unit (FIU) or equivalent authority.
We also screen all transactions, not just accounts, to prevent routing of funds through sanctioned payment corridors.
6. Suspicious Activity Reporting (SAR)
Where instantcards, in the course of its compliance activities, knows or reasonably suspects that a user is involved in money laundering, terrorist financing, or sanctions evasion, it is legally required to file a Suspicious Activity Report (SAR) or equivalent report with the relevant Financial Intelligence Unit or authority in the applicable jurisdiction.
In Cameroon, this is the Agence Nationale d'Investigation Financière (ANIF), established under Law No. 2005/015.
Tipping-off prohibition: Once a SAR has been filed or is contemplated, we are legally prohibited from informing the subject user that a report has been or will be filed, or that an investigation is underway. This is a mandatory legal requirement and is not a matter of our discretion. Users whose accounts are frozen while a SAR is under consideration will be informed of the suspension but not of the reason beyond "regulatory compliance requirements."
7. Prohibited Users and Activities
instantcards will not knowingly onboard or provide services to:
- Any person or entity appearing on a sanctions list referenced in Section 5
- Any person convicted of a financial crime (money laundering, fraud, terrorist financing, corruption)
- Shell companies or structures with no identifiable beneficial owner
- Users who provide demonstrably false KYC information
- Users resident in FATF-blacklisted jurisdictions (currently: Iran, North Korea, Myanmar)
- Users who have previously had an instantcards account terminated for compliance reasons
- Virtual asset service providers (VASPs) seeking to use instantcards as a fiat on/off ramp without prior written agreement and KYB verification
8. Governance and Training
The following governance structures support our AML/CFT programme:
- Compliance Officer: A designated compliance officer is responsible for the day-to-day implementation of this Policy, SAR filings, and liaison with regulators and law enforcement
- Policy review: This Policy is reviewed at least annually or upon material changes to the regulatory environment, business model, or risk landscape
- Staff training: All staff with access to user data or transaction records receive AML/CFT training at induction and annually thereafter
- Third-party due diligence: All partner relationships (Flutterwave, CinetPay, Sudo Africa, Smile Identity) are subject to ongoing due diligence to ensure their AML/CFT controls remain adequate
9. Reporting Concerns
If you have concerns about financial crime, suspicious activity, or a compliance matter related to instantcards, please contact:
AML/CFT Compliance: compliance@instantcards.app
All reports are treated in strict confidence. Reports from users in good faith are protected from any form of retaliation.