1. Introduction
Kalabash Technology Solutions Limited, trading as Kalabash54 ("we", "us", or "our"), operates a travel card platform through which prepaid Mastercard-branded cards are issued to customers. Cards made available on this platform are issued by Wema Bank Plc, a bank duly licensed and regulated by the Central Bank of Nigeria (CBN), in partnership with Mastercard Asia/Pacific Pte. Ltd., the card scheme operator.
The Company is committed to the highest standards of Anti-Money Laundering (AML) and Counter-Terrorism Financing (CFT) compliance. This Statement sets out the framework, policies, and controls that govern how the Company, in conjunction with its issuing bank partner, prevents the platform from being used for money laundering, terrorist financing, or other financial crime.
2. Regulatory & Partnership Structure
The Company operates as a programme/platform partner and does not itself hold customer funds or issue e-money. All card issuance, cardholder fund custody, and settlement are performed by Wema Bank Plc under its CBN banking licence. Mastercard Asia/Pacific Pte. Ltd. provides the card scheme rails and network rules under which transactions are authorised and processed. Accordingly, AML/CFT obligations in respect of the underlying banking relationship are discharged primarily by Wema Bank Plc, while the Company maintains its own complementary controls at the platform and customer-interface level.
3. Regulatory Framework
The Company's AML/CFT programme, and that of its issuing bank partner, is designed to comply with applicable Nigerian law and regulation, including:
- The Money Laundering (Prevention and Prohibition) Act, 2022
- The Terrorism (Prevention and Prohibition) Act, 2022
- The Central Bank of Nigeria (CBN) Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing (AML/CFT/CPF) Regulations, 2022
- Directives and guidelines issued from time to time by the Nigerian Financial Intelligence Unit (NFIU)
- Mastercard scheme rules on sanctions compliance and financial crime prevention
Where the Company offers services to customers outside Nigeria, or where cards are used cross-border, applicable international standards — including the Financial Action Task Force (FATF) Recommendations — also inform the design of these controls.
4. Customer Due Diligence (CDD) & KYC
Before a travel card is issued, every applicant is subject to identity verification and due diligence proportionate to the product's risk profile, consistent with Wema Bank Plc's KYC requirements and CBN's tiered KYC framework. This includes, as applicable:
- Collection and verification of full legal name, date of birth, nationality, and residential address
- Government-issued identification (e.g., NIN, international passport, or other CBN-recognised ID)
- Bank Verification Number (BVN) validation, where required
- Verification of the source of funds/wealth for higher-value or higher-risk customers
- Enhanced Due Diligence (EDD) for customers, transactions, or relationships identified as higher risk, including Politically Exposed Persons (PEPs)
The Company will not activate a card or process a transaction for an applicant whose identity cannot be adequately verified.
5. Risk-Based Approach
The Company applies a risk-based approach to AML/CFT, calibrating the intensity of due diligence and monitoring to factors such as customer type, geographic exposure, product usage patterns, transaction volume and value, and channel of interaction. Higher-risk customers and transactions are subject to enhanced scrutiny, while standard due diligence applies to lower-risk relationships.
6. Transaction Monitoring & Sanctions Screening
Card transactions processed through the Mastercard network are subject to ongoing monitoring designed to detect unusual, complex, or suspicious patterns of activity, including structuring, rapid movement of funds, and activity inconsistent with a customer's stated profile.
- Screening of customers and transactions against applicable sanctions lists (including UN, OFAC, and Nigerian designations) prior to onboarding and on an ongoing basis
- Automated and manual review of transaction patterns for indicators of money laundering or terrorist financing typologies
- Escalation of alerts to the issuing bank's compliance function for investigation
7. Suspicious Activity Reporting
Where the Company or Wema Bank Plc identifies activity giving rise to reasonable suspicion of money laundering, terrorist financing, or other financial crime, a Suspicious Transaction Report (STR) is filed with the Nigerian Financial Intelligence Unit (NFIU) in accordance with statutory timelines. The Company does not disclose to a customer, or any third party, that a report has been made or that an investigation is underway ("tipping-off" is prohibited by law).
8. Record Keeping
Customer identification records, due diligence documentation, and transaction records are retained for a minimum of five (5) years from the date of the transaction or the end of the business relationship, whichever is later, in line with CBN and statutory requirements, and are made available to competent authorities upon lawful request.
9. Governance & Compliance Oversight
The Company maintains a designated point of contact for AML/CFT matters who liaises with Wema Bank Plc's Money Laundering Reporting Officer (MLRO) and compliance function. While overall statutory AML/CFT responsibility for the programme rests with Wema Bank Plc as the licensed issuing institution supervised by the Central Bank of Nigeria, the Company treats compliance and sound governance as a core operational priority in its own right, not merely a delegated obligation.
10. Cooperation with Regulators and Law Enforcement
The Company, together with Wema Bank Plc, cooperates fully with the Central Bank of Nigeria, the Nigerian Financial Intelligence Unit, the Economic and Financial Crimes Commission (EFCC), and other competent authorities in connection with any lawful investigation, audit, or information request relating to AML/CFT matters.
11. Review and Updates
This Statement is reviewed periodically, and no less than annually, to reflect changes in law, regulation, Mastercard scheme rules, or the risk profile of the Company's business. The version below reflects the most recent review.
Effective date: 10th of July 2026. Version: v1.0.