Version 1.2
Next Review Date: 31 July 2027
Approved by the Board of SWAP LTD
SWAP LTD is a Nigerian digital fintech platform that facilitates peer-to-peer (P2P) cryptocurrency trading, gift card transactions, airtime and data bundle purchases, and utility bill payments through our mobile and web applications with plans for regional expansion within and outside Africa.
We are fully committed to preventing our platform from being used for money laundering, terrorist financing, or any other illicit activities. SWAP LTD adopts a risk-based approach to comply with the Money Laundering (Prevention and Prohibition) Act 2022, Terrorism (Prevention and Prohibition) Act 2022, Investments and Securities Act 2025, SEC Rules on Digital Assets, SEC Capital Market Operators AML/CFT/CPF Regulations 2022, Nigeria Tax Administration Act 2025, Central Bank of Nigeria (CBN) regulations, Nigerian Financial Intelligence Unit (NFIU) guidelines, and other applicable laws in Nigeria.
This policy applies to all directors, staff, contractors, and users of the SWAP LTD platform.
a. Prevent SWAP LTD from being used as a conduit for money laundering or terrorist financing.
b. Establish robust Customer Due Diligence (CDD) and Know Your Customer (KYC) procedures tailored to our P2P crypto and fintech services.
c. Detect, monitor, and report suspicious transactions in a timely manner.
d. Maintain proper record-keeping, staff awareness, and continuous improvement of our compliance framework.
a. CEO: Overall responsibility for AML/CFT compliance and report to the Board.
b. AML Compliance Officer: oversee day-to-day AML/CFT operations and report to the CEO.
c. All Staff/Team Members: Must understand and adhere to this policy, complete customer verification where required, and report any suspicious activity immediately to the CEO or designated Compliance Officer.
d. Users: Must provide accurate information and valid identification during onboarding and comply with all verification requests.
We apply a risk-based KYC process proportionate to the nature of services (P2P crypto trading, gift cards, and bill payments):
Standard KYC (for all users):
a. Full name, date of birth, phone number, email address, and residential address.
b. Valid government-issued ID (NIN, BVN-linked data, National ID, Driver's License, International Passport, or Voter's Card).
c. Selfie or live photo for facial verification (where technically feasible via our app).
d. Bank account details or other verified payment information.
Enhanced Due Diligence (EDD) for higher-risk cases:
a. Large or frequent cryptocurrency transactions (above defined thresholds).
b. Politically Exposed Persons (PEPs) or users with PEP connections.
c. Users from high-risk or sanctioned jurisdictions.
d. Unusual transaction patterns (e.g., rapid large inflows/outflows, structuring to avoid thresholds, or inconsistent with user profile).
e. Source of funds/wealth declaration for significant crypto-related activities.
We verify identities using reliable, independent sources (including NIN, BVN where applicable) and may request additional documents such as proof of address (utility bill) or source of funds declarations. Ongoing monitoring of customer activity is performed to detect changes in risk profile.
Crypto trading and P2P transactions inherently carry higher ML/TF risk. Therefore, we apply stricter monitoring on crypto buy/sell and P2P transfer activities compared to airtime, data, or bill payment services.
We monitor user activity for red flags, including but not limited to:
a. Sudden large-volume crypto trades or P2P transfers inconsistent with the user's profile and transaction history.
b. Multiple accounts operated by the same user or rapid fund movements across accounts.
c. Transactions linked to sanctioned individuals, entities, or high-risk countries.
d. Unusual patterns such as frequent small transactions just below reporting thresholds (structuring).
e. Reluctance to provide required KYC information or source of funds documentation.
Prior to onboarding and on a risk-based ongoing/periodic basis, SWAP LTD screens customers, beneficial owners, directors, and other key related parties against relevant sanctions lists. These include the Nigerian Sanctions List, United Nations Security Council Consolidated List, OFAC Specially Designated Nationals (SDN) List, and other applicable international and local sanctions regimes. PEP screening is performed using reliable databases combined with customer self-declarations.
Any potential matches, alerts, or PEP hits are promptly escalated to the CEO/AML Compliance Officer for review, investigation, and (where necessary) Enhanced Due Diligence and senior management approval before establishing or continuing a business relationship. Screening is currently conducted manually. Automated screening tools will be implemented post-launch to improve efficiency and coverage.
Ongoing transaction monitoring is conducted manually in the pre-launch and early launch phase and will be progressively automated as the platform scales and transaction volume increases. Automated alerts will be configured for high-risk indicators.
Any suspicious activity will be investigated internally by the CEO/Compliance Officer. Where there are reasonable grounds to suspect money laundering or terrorist financing, a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) will be filed promptly with the Nigerian Financial Intelligence Unit (NFIU) in accordance with legal requirements.
SWAP LTD will cooperate fully with law enforcement agencies, the NFIU, CBN, and other regulatory authorities in any investigation or request for information, while maintaining appropriate confidentiality.
All KYC documents, transaction records, identification data, STRs/SARs, and related compliance records will be securely stored (both digitally and with appropriate backups) for a minimum of five (5) years after the end of the business relationship or as required by applicable law sometimes up to seven (7) years, whichever is longer. Records will be readily retrievable for regulatory inspection.
SWAP LTD maintains a system of internal controls designed to ensure compliance with this policy and applicable AML/CFT laws. Key controls include:
a. Segregation of duties: Where team size permits, different individuals handle customer onboarding/verification, transaction approval, and fund movement to reduce risk of error or fraud.
b. Dual approval / escalation: High-value, high-risk, or unusual transactions require review and approval by the CEO/AML Compliance Officer before processing.
c. Access controls: Role-based access to customer data, transaction systems, and compliance records is restricted and logged.
d. Escalation matrix: Clear procedures exist for staff to escalate potential issues, red flags, or policy breaches directly to the CEO without delay.
e. Periodic compliance review: The CEO conducts regular reviews of KYC files, transaction samples, and screening records to assess effectiveness of controls, with findings documented.
These controls are proportionate to the current size and risk profile of the company and will be strengthened as the platform scales and transaction volumes increase.
SWAP LTD shall process all personal data collected or generated in connection with its KYC, AML/CFT/CPF and transaction-monitoring activities—including NIN- and BVN-derived information, government-issued identification documents, facial images or selfies, bank account details, contact information and customer transactional profiles—in accordance with the Nigeria Data Protection Act 2023, the Nigeria Data Protection Commission’s General Application and Implementation Directive (GAID) 2025, and the Company’s Privacy and Data Protection Policy.
Personal data shall be collected only for specified and lawful purposes, limited to what is necessary, protected by appropriate technical and organisational safeguards, retained only for the period required by law or legitimate regulatory purposes, and disclosed to third parties only where legally permitted or required.
SWAP LTD shall also ensure that customers are appropriately informed of the nature and purpose of such processing and that any data sharing with verification providers, financial institutions, regulators or other service providers is subject to applicable data-protection requirements.
All team members will receive basic AML/CFT training covering onboarding procedures, customer due diligence, red flags and suspicious activity indicators, record keeping, and reporting obligations. Training will be refreshed periodically (at least annually) and documented.
As the platform launches and the team expands, more role-specific and advanced training will be provided, particularly for staff involved in customer support, transaction monitoring, and compliance functions. The CEO/Compliance Officer is responsible for ensuring training adequacy.
This policy will be reviewed at least annually or whenever there are significant changes in regulations, business operations, risk profile, product offerings, or regulatory guidance. The current version (1.2) was reviewed and updated on 01 August 2026 to add explicit subsections on Sanctions & PEP Screening and Internal Controls, in response to feedback received during partner onboarding.
This policy has been signed and approved.
Adesokan Quwamdeen Adebayo
CEO / Director, SWAP LTD
Date: 01 August 2026
Trade crypto, redeem gift cards, top up your wallet, and withdraw funds — all from one seamless, secure mobile app. Available free on iOS and Android.