Legal & Compliance

Anti-Money Laundering (AML) & Counter-Terrorist Financing (CTF) Policy

How Card App and its operating entity identify, assess, monitor, and mitigate financial crime risk.

Document Version
1.0
Effective Date
July 23, 2026
Operating Brand
Carda App
Legal Entity Name
CARDIFY LTD.
Company Registration No.
9268793
Compliance Contact
[email protected]
Registered Address
12 Commercial Avenue, Sabo, Yaba, Lagos, Lagos State 100001, Nigeria
1

Purpose

CARDIFY LTD. (operating as "Carda App") is fully committed to preventing money laundering, terrorist financing, fraud, sanctions evasion, corruption, tax evasion, and other financial crimes. This policy establishes the governance, procedures, and controls used to identify, assess, monitor, and mitigate financial crime risks across all operations.

2

Scope

This policy applies to all customers, merchants, business partners, employees, contractors, payment services, virtual accounts, card products, crypto-related funding, and all financial services provided through Carda App by CARDIFY LTD.

3

Regulatory Framework

CARDIFY LTD. adopts a risk-based approach aligned with the Financial Action Task Force (FATF) Recommendations and, where applicable, relevant national AML/CTF legislation, international sanctions regulations, data protection laws, and card scheme compliance requirements.

4

Governance

Senior management at CARDIFY LTD. is responsible for ensuring adequate AML/CTF resources and operational oversight. A designated Money Laundering Reporting Officer (MLRO) oversees compliance, suspicious activity investigations, and regulatory reporting.

5

Customer Due Diligence (CDD) & KYC

Customers must complete Know Your Customer (KYC) or Know Your Business (KYB) verification prior to accessing regulated services. Verification requirements include:

  • Individuals: Government-issued ID, selfie verification, and proof of address.
  • Businesses: Corporate registration documents, ownership structure, business proof, and Ultimate Beneficial Owner (UBO) details.
6

Risk-Based Approach

Customers and accounts are categorized as Low, Medium, or High Risk based on factors such as geographic location, products utilized, transaction patterns, sanctions exposure, Politically Exposed Person (PEP) status, and adverse media findings.

7

Enhanced Due Diligence (EDD)

High-risk customers or unusual transaction structures are subject to Enhanced Due Diligence (EDD). This may require proof of Source of Funds (SoF), Source of Wealth (SoW), additional identification documents, manual compliance review, and executive management approval.

8

Sanctions & PEP Screening

All users and corporate entities are screened prior to onboarding and on an ongoing basis against global watchlists and sanctions lists, including UN, OFAC, OFSI (UK), EU, and local Nigerian regulatory databases. PEPs and their close associates receive enhanced ongoing monitoring.

9

Transaction Monitoring

Automated monitoring systems analyze transactions in real time to detect:

  • Structuring and velocity anomalies.
  • Rapid movement of funds across multiple accounts.
  • Cross-border transactions involving high-risk jurisdictions.
  • Card usage anomalies and elevated chargeback patterns.
10

Cryptocurrency Controls

Where crypto-asset deposits or payouts are supported, blockchain analytics tools are utilized to scan wallet addresses for exposure to sanctioned entities, mixers, darknet markets, ransomware, and other illicit activities.

11

Suspicious Activity Reporting

Any activity flagged as potentially suspicious is escalated to the MLRO. Where required by applicable law, Suspicious Activity Reports (SAR/STR) are submitted to the relevant financial intelligence units and law enforcement authorities.

12

Prohibited Activities

CARDIFY LTD. strictly prohibits the use of Carda App for:

  • Money laundering, terrorist financing, and tax evasion.
  • Fraud, identity theft, and stolen payment credentials.
  • Sanctions evasion, ransomware payments, and darknet activities.
  • Child exploitation, human trafficking, and illegal gambling.
13

Record Keeping

KYC documentation, transaction history, communication logs, and compliance review records are retained securely for a minimum of five (5) years following account closure or transaction completion, or longer if required by law.

14

Data Protection & Privacy

Personal and corporate data is processed securely in compliance with applicable privacy and data protection legislation, including GDPR where relevant.

15

Training & Internal Audit

All employees receive regular AML/CTF and sanctions compliance training. CARDIFY LTD. conducts periodic independent compliance audits to assess the effectiveness of its AML framework.

16

Account Restrictions

CARDIFY LTD. reserves the right to decline onboarding, suspend transactions, freeze funds, or terminate service accounts where financial crime risks are detected or regulatory mandates require such action.

17

Policy Review

This policy is reviewed annually or immediately following material changes to regulatory frameworks, legal obligations, or operational structures.

18

Compliance & Legal Inquiries

For any inquiries regarding this policy, identity verification procedures, or compliance matters, please contact:

Legal Entity: CARDIFY LTD.

Brand: Carda App

Compliance Email: [email protected]

Registered Address: 12 Commercial Avenue, Sabo, Yaba, Lagos, Lagos State 100001, Nigeria

A

Appendix A — Examples of Red Flags

  • Structuring transactions to bypass reporting or verification thresholds.
  • Multiple accounts linked to a single individual or device without prior clearance.
  • Repeatedly failing or attempting to bypass identity verification controls.
  • Transacting with wallets, banks, or entities located in sanctioned jurisdictions.
  • Utilizing anonymization networks, VPNs, or proxies to obfuscate true origin.
  • High rates of payment disputes, chargebacks, or unauthorized card transactions.