AML & KYC Policy

Effective date: March 11, 2026. Last updated: March 11, 2026. This policy is drafted for South African operations and is intended to be aligned with applicable AML/CFT obligations, including the Financial Intelligence Centre Act, 38 of 2001 (“FICA”), and related regulatory requirements, where applicable.

1. Purpose and Scope

Bwiser operates an operational finance and voucher platform that may be used by Drivers, Stations/Merchants, and internal operational staff. This Policy sets out how we apply a risk-based approach to anti-money laundering and counter-terrorist financing (“AML/CFT”), including customer due diligence (“KYC”), ongoing monitoring, escalation, reporting, and recordkeeping.

This Policy applies to all Bwiser employees, contractors, and authorised users who onboard customers, review applications, approve vouchers or limits, redeem vouchers, process repayments, and manage settlements. Where third-party partners are used (for example, payment gateways), Bwiser applies vendor due diligence and contractual controls to ensure appropriate safeguards.

2. Key Principles

  • Risk-based approach: controls are proportionate to the risk presented by a user, transaction, or station.
  • Know your customer: we aim to understand who is using the Platform and the legitimacy of their activity.
  • Ongoing monitoring: onboarding checks are not “once-off”; we monitor behaviour and events.
  • Auditability: decisions and key events are logged for accountability and regulatory readiness.
  • Escalation: suspicious activity is escalated quickly for investigation and action.

3. Roles and Responsibilities

Bwiser maintains an internal compliance function appropriate to its size and risk profile. Responsibilities may include:

  • Information/Compliance Officer: oversight of AML/KYC implementation, escalations, and reporting.
  • Operations staff: collecting documents, verifying information, applying controls, and escalating concerns.
  • Engineering and security: implementing technical safeguards, logging, and monitoring.
  • Station/Merchant admins: ensuring staff follow voucher redemption rules and report suspicious activity.

4. Customer Due Diligence (KYC)

We collect and verify information necessary to establish and maintain accounts, and to mitigate fraud and financial crime. KYC may be performed at onboarding and updated periodically or when risk triggers occur.

4.1 Driver KYC (Examples)

Depending on the product and risk level, Driver onboarding may include:

  • Full name, identity number (where applicable), date of birth, and contact details (email and phone).
  • Proof of address or confirmation of address and geolocation capture for operational purposes.
  • Driver licence or other role-relevant authorisations.
  • Selfie or liveness checks (where implemented) to reduce impersonation risk.
  • Device and session metadata for fraud prevention (for example, device ID or login fingerprint).

4.2 Merchant/Station KYC (Examples)

Merchant and Station onboarding may include:

  • Registered business name, registration number (where applicable), and trading address.
  • Authorised representative details and proof of authority to act for the business.
  • Business documentation (for example, CK documents, licences, and proof of banking details where needed).
  • Optional B-BBEE documentation (where applicable) and any franchise/brand selection data used for operations.
  • Station location coordinates (latitude/longitude) for operational matching and controls.

4.3 Enhanced Due Diligence (EDD)

We may apply enhanced checks for higher-risk cases. Examples of triggers include:

  • Unusual behaviour or patterns inconsistent with the stated purpose of the account.
  • Repeated failed repayments, multiple failed card authorisations, or payment method mismatch indicators.
  • Frequent high-value voucher requests or rapid velocity changes.
  • Geolocation anomalies (for example, repeated redemptions far from expected locations).
  • Adverse media, fraud flags, or sanctions/PEP risk indicators (where screening is performed).

EDD may include requesting additional documents, performing additional verification steps, applying tighter limits, or requiring manual review before approvals.

5. Monitoring and Transaction Controls

We monitor onboarding, voucher issuance, redemption, repayments, and settlement events for anomalies and potential misuse. Monitoring may include:

  • Velocity checks (sudden increase in voucher applications, redemptions, or repayment attempts).
  • Repeated redemption failures and retry patterns.
  • Station redemption behaviours (for example, unusually high redemption rates vs peers).
  • Geographic patterns (distance between driver location and station, and repeated out-of-area usage).
  • Device and session patterns (multiple accounts on the same device, unusual login locations).

Controls may include step-up verification, temporary holds, manual review, and in serious cases, suspension of voucher issuance or redemption privileges.

5.1 Station/Merchant Operational Controls (Examples)

Because vouchers are redeemed at stations, merchant controls are a key part of AML and fraud prevention. Depending on risk and operational design, controls may include:

  • Restricting which staff can redeem vouchers, and logging staff identifiers per redemption.
  • Requiring voucher redemption only through the Platform workflow (scan/verify/confirm).
  • Limiting redemption volume per station or per staff member based on operational thresholds.
  • Flagging stations with unusual redemption-to-settlement ratios or repeated disputes.
  • Requiring additional verification for high-value redemptions or unusual time-of-day patterns.

Stations are expected to report suspected fraud promptly. Failure to comply with redemption rules or repeated suspicious activity may result in suspension from the Platform, delayed settlements pending review, or termination of the relationship.

6. Suspicious Activity Escalation and Reporting

Bwiser encourages immediate escalation of suspicious activity. Examples include:

  • Attempts to redeem a voucher without providing goods/services.
  • Evidence of identity misuse, forged documents, or impersonation.
  • Unexplained payment behaviour or use of unauthorised payment methods.
  • Collusion between drivers and stations or repeated irregular redemptions.

High-risk cases are escalated to designated compliance personnel for investigation. Where required by law and applicable to the services provided, suspicious activity reports may be filed with competent South African authorities, including the Financial Intelligence Centre, in accordance with applicable legal obligations.

7. Sanctions and Prohibited Activity

Bwiser does not knowingly support activity that is prohibited by law or sanctions. Where screening is performed, we may check users and business entities against sanctions or other risk lists using lawful methods and reputable sources. If a match is suspected, we may suspend onboarding or activity and conduct further review.

8. Training and Awareness

Relevant staff are trained on AML/KYC concepts appropriate to their role, including identifying red flags, handling documents safely, protecting personal information, and escalating concerns. Training may be refreshed periodically and when policies or risk conditions change.

9. Recordkeeping and Retention

We keep KYC documentation, decision logs, and audit trails in accordance with our information governance program and applicable legal requirements. Where FICA applies, records may generally be retained for at least five years after the end of the business relationship or the date of a single transaction, as applicable, subject to any longer retention required for disputes, audit, or other legal obligations.

Records are retained to support traceability of decisions and events (who approved what, when, and why), which is important for preventing fraud and for responding to disputes. Access to retained KYC and audit records is restricted, and we aim to ensure that staff access is logged and reviewed where appropriate.

When retention is no longer necessary, we take reasonable steps to securely delete, de-identify, or anonymise records, subject to technical constraints (for example, backup retention windows).

10. Data Protection and POPIA

KYC involves processing personal information. We handle personal information in line with POPIA and our Privacy Policy. Access to KYC records is restricted to authorised personnel, and we apply security safeguards such as encryption in transit, access controls, and audit logging.

11. Policy Review

This Policy is reviewed and updated periodically to reflect operational changes, risk evolution, and legal developments. Material updates may be communicated to staff and reflected in onboarding or workflow requirements.

12. Customer Risk Rating (Illustrative)

Bwiser applies a risk-based approach. In practice, this means we may assign an internal risk rating to accounts and transactions and apply controls proportionate to that rating. Factors that may influence a risk rating include:

  • Customer type (Driver vs Merchant/Station), business structure, and onboarding completeness.
  • Transaction behaviour (frequency, size, timing) relative to expected usage.
  • Geographic patterns and whether redemptions match expected operational areas.
  • Repayment performance, failed payment patterns, and account anomalies.
  • Fraud indicators (duplicate identities, suspicious devices, repeated verification failures).

Higher-risk cases may require additional documentation, tighter operational limits, manual review, or refusal where risk cannot be mitigated to an acceptable level.

13. Red Flags (Examples)

Staff and Station/Merchant users should be alert to red flags that may indicate fraud or financial crime. Examples include:

  • Onboarding documents that appear altered, inconsistent, or duplicated across multiple accounts.
  • Drivers requesting repeated vouchers and immediately redeeming at the same station in unusual patterns.
  • Station redemptions that spike suddenly or do not align with typical operational volumes.
  • Drivers insisting on redemption without being present or requesting redemption outside approved conditions.
  • Multiple accounts using the same device identifiers, contact information, or banking details without a clear explanation.
  • Unusual repayment activity, including multiple failed attempts from different payment methods.
  • Attempts to circumvent controls, including repeated retries after declines or use of multiple identities.

Red flags do not automatically mean wrongdoing, but they do require attention. Where a pattern cannot be reasonably explained, we may request additional supporting information, apply temporary limits, or route the case for manual review. This helps protect legitimate users from fraud and reduces the risk of financial losses for stations and partners.

14. Action on Suspicion

When suspicion is identified, the immediate priority is to protect customers and the Platform. Actions may include:

  • Placing a temporary hold on a voucher application, redemption, or settlement.
  • Requesting additional verification or documentation.
  • Suspending accounts or restricting actions pending investigation.
  • Preserving logs and evidence for investigation and audit.

Where reporting obligations apply, reporting is handled through designated compliance channels. Users should not attempt to “tip off” any person that a report is being considered or has been made where such disclosure is prohibited by law.

15. Testing, Review, and Continuous Improvement

Financial crime risks evolve. Bwiser aims to periodically review the effectiveness of its controls and to improve them as the Platform grows. This may include:

  • Reviewing alert thresholds and monitoring rules to reduce false positives while still catching high-risk cases.
  • Sampling and review of onboarding decisions for consistency and quality.
  • Periodic review of station redemption patterns and settlement anomalies.
  • Updating training content when new fraud patterns are detected or when regulations change.

Where feasible, we may also conduct internal audits or request external reviews for high-risk workflows. Findings may result in tighter controls, updated onboarding requirements, or changes to approval thresholds.

Monitoring rules and risk ratings are not static. They are tuned based on observed behaviour, confirmed fraud cases, and operational feedback from stations and support teams. Changes are documented so that decisions remain explainable and auditable.

16. Contact

For AML/KYC queries or to report suspicious activity, contact [email protected] or use designated internal escalation channels.

Where you are reporting an issue from a station, include the station name, voucher reference, date/time, and a short description of what occurred. This helps us correlate the report with audit logs and take action quickly.

Reports are handled confidentially and escalated to compliance or security where appropriate.

Note: This policy is provided for transparency and operational readiness and does not constitute legal advice. If you require legal advice about AML/CFT obligations, consult a qualified professional.