Skip to content
From the team · Page 2

Risk & Compliance

Page 2

  • Risk & Compliance

    PEP screening: what a match means and what to do next

    A PEP match means you must confirm the person and classify them, not refuse them. Foreign PEPs always need senior management approval, source of wealth and funds, and enhanced monitoring; domestic PEPs need it only when your risk assessment says the relationship is higher risk.

  • Risk & Compliance

    The Travel Rule explained for teams launching crypto transfers

    The Travel Rule requires the sending VASP to collect originator and beneficiary information, pass it to the receiving VASP immediately and securely, and make it available to authorities. The hard parts are finding the counterparty, handling self-hosted wallets and jurisdictions that disagree.

  • Risk & Compliance

    Handling biometric data under African data protection laws

    All three laws treat biometric data as a special category. Nigeria names facial images and limits sensitive data to listed grounds, Kenya treats biometric processing as high risk, and POPIA prohibits it unless an authorisation applies. Plan a lawful ground, a DPIA and minimisation.

  • Risk & Compliance

    What device and IP signals can and cannot tell you

    Device and IP signals describe the handset and connection, not the person. Emulators and datacentre IPs are strong warnings; shared devices, IP velocity and IP location are weak. Use them as corroboration, and trust IP location at country level only.

  • Risk & Compliance

    Finding the same person behind many accounts

    Rank shared artefacts by what they prove. A repeated verified ID number means the same person. A repeated face is strong evidence for review. A shared device, phone or address is common in families, so treat it as corroboration and count distinct people before acting.

  • Risk & Compliance

    Preparing customer due diligence for the EU AML Regulation

    The EU AML Regulation applies directly from 10 July 2027 and replaces national CDD rules with one text. Build to the Regulation now: its data list, verification routes, 25% ownership test and refresh ceilings are fixed, while AMLA's detailed CDD standards were still in draft as of September 2026.