Skip to content

Financial Compliance, AML & KYC Standards ​


1. Regulatory Context & Marketplace Posture ​

Debelu operates as a closed-loop e-commerce marketplace and escrow intermediary in Nigeria. The platform operates in compliance with:

  1. Central Bank of Nigeria (CBN) Guidelines on Electronic Payment Channels in Nigeria.
  2. Money Laundering (Prevention and Prohibition) Act (MLPPA) 2022.
  3. CBN Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing (AML/CFT/CPF) Regulations.

Core Regulatory Defense: Closed-Loop Escrow ​

To prevent Debelu from being exploited as a conduit for illicit money transfers or stolen card liquidation: $$\text{Fund Closed-Loop Rule}: \text{Buyer Funds (Inflow)} \implies \text{Order Escrow Lock} \implies \begin{cases} \text{Verified Delivery PIN} \to \text{Vendor NUBAN (Outflow)} \ \text{Cancelled/Disputed} \to \text{Restitution to Source Instrument} \end{cases}$$ Direct cash-out of deposited funds without a corresponding physical delivery or verified order dispute is technologically prohibited.

mermaid
graph TD
    subgraph Buyer Inflows
        BUYER[Buyer Account] -->|Card / Bank Transfer| ESCROW[Escrow Holding Pool]
    end

    subgraph AML Velocity & Monitoring Engine
        VELOCITY[payout_velocity_rules & Platform Controls]
        COOLDOWN[24h Bank Change Cooldown]
        LIMITS[Daily Cap 5M / Single Cap 2M]
    end

    subgraph KYC Verification Tiers
        T1[Tier 1: Basic Buyer]
        T2[Tier 2: Individual Merchant - NUBAN + BVN]
        T3[Tier 3: Corporate Merchant - CAC + TIN]
    end

    subgraph Payout Outflows
        ESCROW -->|Release Triggered| V_WALLET[Vendor Wallet Balance]
        V_WALLET --> VELOCITY --> COOLDOWN --> LIMITS --> PAYOUT[Paystack Transfer to Verified Bank]
    end

2. Tiered Know Your Customer (KYC) Framework ​

Debelu implements a risk-based Tiered KYC structure aligned with CBN customer due diligence standards:

KYC TierPermitted Platform RoleVerification RequirementsTransaction & Payout Limits
Tier 1: Basic BuyerBrowse catalog, place orders, message vendorsVerified Phone Number (OTP via SMS) + Verified Email AddressMaximum checkout ₦100,000 / transaction.
Cannot receive merchant payouts.
Tier 2: Individual VendorList products, fulfill campus orders, receive payoutsTier 1 + National Identity Number (NIN) / Voter's Card + NUBAN matching legal name via Paystack Resolve Account APIMax Single Payout: ₦2,000,000.
Max Daily Payout: ₦5,000,000.
Bank modification triggers 24h cooling-off lock.
Tier 3: Registered MerchantEnterprise catalog, campus hub operator, bulk salesTier 2 + Corporate Affairs Commission (CAC) Certificate + Tax Identification Number (TIN) + Verified Business AddressPayout ceilings negotiated by contract; subject to continuous automated velocity monitoring.

3. Automated Bank Account Validation Pipeline ​

Vendor bank account details are validated programmatically through Paystack's interbank resolution API prior to receiving approval:

mermaid
sequenceDiagram
    autonumber
    actor Vendor
    participant API as VendorService
    participant Paystack as Paystack Resolve Account API
    participant DB as Postgres vendor_bank_details

    Vendor->>API: 1. Submit Bank Details (account_number, bank_code)
    API->>Paystack: 2. GET /bank/resolve?account_number=X&bank_code=Y
    Paystack-->>API: 3. Return verified account_name
    API->>API: 4. Perform Fuzzy String Matching vs Vendor Profile Legal Name
    alt Name Matches
        API->>Paystack: 5. POST /transferrecipient (create recipient_code)
        Paystack-->>API: 6. Return RCP_xxx
        API->>DB: 7. Save vendor_bank_details(verified=true, recipient_code=RCP_xxx)
        DB->>DB: 8. Reset updated_at to now() -> Starts 24h Cooldown Clock
        API-->>Vendor: 9. Bank Account Linked & Verified
    else Name Mismatch
        API-->>Vendor: 10. Reject with 422: "Bank account name does not match registered identity"
    end

4. AML Velocity Rules & Platform Controls ​

Debelu enforces dynamic velocity controls governed by payout_velocity_rules and platform_settings:

4.1 Velocity Matrix ​

  1. The 24-Hour Bank Modification Cooldown (bank_change_cooldown): When a vendor modifies their payout NUBAN account in public.vendor_bank_details, all withdrawals are programmatically locked for 24 hours:
    sql
    -- Check constraint evaluated prior to payout dispatch
    IF v_bank_details.updated_at > (now() - interval '24 hours') THEN
        RAISE EXCEPTION 'Payout blocked: 24-hour security cooldown active following bank detail modification'
        USING ERRCODE = '40001';
    END IF;
    Mitigation: Prevents session hijackers or compromised vendor accounts from executing an immediate "change account $\to$ drain funds" exit scam.
  2. Single Transaction Ceiling (single_max): ₦2,000,000 per transfer.
  3. Daily Aggregation Cap (daily_cap): ₦5,000,000 per vendor in any rolling 24-hour window.
  4. Platform Global Payout Freeze (platform_settings.payout_freeze): Emergency master kill-switch that instantly blocks all outbound transfers across the platform during a suspected breach.

5. Suspicious Activity Triggers & Red Flags ​

The backend transaction observation engine monitors financial streams for anomalous behaviors:

Red Flag PatternThreat VectorAutomated Defensive Action
Circular PurchasingBuyer and Vendor share the same IP address, fingerprint, or bank account.Order flagged for escrow freeze; self-dealing investigation triggered.
Micro-Deposit ProbingMultiple small card transactions ($< ₦500$) testing stolen card batches.IP-level rate limiting triggered; card fingerprint blacklisted after 3 failures.
Rapid Payout CyclingVendor requesting immediate withdrawal within seconds of PIN entry on newly opened account.Payout routed to manual review queue; 24-hour holding buffer applied.
Abnormal Price SpikeVendor store with median price ₦2,000 suddenly processes a single ₦800,000 transaction.Order quarantined by PriceGuard; proof-of-delivery documents required before escrow release.

6. Suspicious Activity Reporting (SAR) Protocol ​

In compliance with the Money Laundering (Prevention and Prohibition) Act (MLPPA) 2022:

  1. Internal Escalation: Transactions flagged by automated monitors route to the Compliance Officer within 4 hours.
  2. Account Quarantine: If financial fraud or money laundering intent is substantiated, the Compliance Officer initiates an emergency freeze on the account and retains the locked escrow funds.
  3. Statutory Filing: Formally reported to the Nigerian Financial Intelligence Unit (NFIU) within 7 days of transaction classification, accompanied by complete audit logs, Paystack transaction references, and user identification documents.
  4. Statutory 7-Year Retention: All financial records, customer KYC dossiers, transaction ledgers, and dispute transcripts are preserved in encrypted cold storage for 7 years following account deactivation.

Released under Proprietary Enterprise License.