Anti-Money Laundering (AML) & Know Your Customer (KYC) Policy
Last Updated: 2 September 2026
I. Background
This Anti-Money Laundering and Know Your Customer Policy (“AML Policy”) sets out the framework adopted by OSO Money (Pty) Ltd (“OSO Money”, “Company”, “we”, “us” or “our”) to prevent and mitigate the risks of money laundering (“ML”), terrorist financing (“TF”), proliferation financing (“PF”), fraud, sanctions breaches, corruption, bribery, financial crime and other illicit activity.
OSO Money (Pty) Ltd is the trading name used by the regulated business through which the relevant foreign exchange and international payment services are provided. The applicable regulated entity, regulatory permissions and licensing details are as disclosed in the Company’s Terms of Service and customer onboarding documentation.
This AML Policy is intended to support OSO Money’s compliance with applicable South African laws and regulations, including applicable requirements relating to customer due diligence, anti-money laundering, counter-terrorist financing, sanctions screening, suspicious transaction reporting, record keeping and risk management.
OSO Money applies a risk-based approach to customer and transaction management and may adopt controls that are proportionate to the risks identified in its business, customer relationships, products, services, jurisdictions and transactions.
Scope and Objectives
This AML Policy covers the following principal areas:
- Customer identification and verification procedures;
- Customer due diligence and enhanced due diligence;
- Sanctions and Politically Exposed Persons (PEP) screening;
- Compliance oversight and reporting;
- Transaction monitoring;
- Risk assessment and risk-based controls;
- Record keeping and information management; and
- Staff awareness and training.
The AML Policy is designed to:
- prevent OSO Money from being used, intentionally or unintentionally, for money laundering, terrorist financing, proliferation financing or other financial crime;
- enable OSO Money to understand its customers, beneficial owners, authorised representatives, counterparties, business activities and sources of funds;
- identify and mitigate risks arising from customers, jurisdictions, products, services and transactions;
- detect and report suspicious or otherwise reportable activity in accordance with applicable law;
- maintain appropriate records and controls; and
- ensure that employees and contractors understand their AML/KYC responsibilities and reporting obligations.
This Policy is reviewed periodically and may be amended to reflect changes in applicable law, regulatory expectations, business activities, identified risks and relevant industry standards. It forms part of OSO Money’s broader compliance framework and should be read together with its applicable policies, procedures and risk management and compliance programme.
II. Customer Identification and Verification Procedures
Customer Due Diligence (“CDD”) is a fundamental component of OSO Money’s AML framework. Before establishing a business relationship or providing certain Services, OSO Money will obtain and verify information appropriate to the nature and risk of the customer and relationship.
OSO Money may require reliable and independent source documents, data or information, which may include an identity document, passport, proof of residential address, company registration documents, bank statements, information concerning directors and beneficial owners, and other documentation reasonably required to establish and verify identity.
OSO Money will take reasonable steps to assess the authenticity and reliability of information and documents supplied by customers. Verification may be performed directly or through appropriate third-party service providers.
Customer identification and verification may be repeated or refreshed on an ongoing basis, particularly where customer information changes, a transaction or pattern of activity appears unusual, the customer’s risk profile changes, or applicable law requires updated information.
OSO Money may request additional information concerning the customer, beneficial owners, authorised representatives, business activities, expected transaction activity, source of funds, source of wealth, purpose of the relationship or purpose of a transaction.
Failure to provide satisfactory information may result in an application being declined or a transaction or business relationship being delayed, restricted, suspended or terminated, subject to applicable law.
III. Sanctions and PEP Screening
OSO Money screens customers and, where appropriate, beneficial owners, directors, authorised representatives, counterparties and other relevant associated parties against applicable sanctions lists and recognised Politically Exposed Persons (“PEP”) and related screening databases.
Screening may take place:
- before establishing a business relationship;
- during ongoing customer due diligence;
- before or during the processing of relevant transactions;
- when customer or transaction information changes; and
- as part of ongoing screening of the customer database.
OSO Money may use appropriately selected third-party screening and compliance service providers. Where a potential match or elevated risk is identified, the matter may be referred for further review and appropriate action in accordance with applicable law and internal procedures.
IV. Compliance Officer
OSO Money will appoint an appropriately authorised compliance officer or responsible compliance function to oversee the effective implementation and enforcement of its AML/KYC framework.
The Compliance Officer’s responsibilities may include:
- overseeing the collection and review of customer identification information;
- maintaining and updating AML/KYC policies and procedures;
- ensuring appropriate records are created, maintained and retrievable;
- overseeing transaction monitoring and investigation of unusual activity;
- reviewing and updating the Company’s financial-crime risk assessment;
- ensuring appropriate regulatory and suspicious transaction reporting;
- coordinating responses to lawful requests from regulators and law-enforcement authorities;
- providing or arranging AML/KYC training and awareness for relevant personnel; and
- escalating material compliance risks to senior management and other relevant governance bodies.
V. Transaction Monitoring
OSO Money monitors customer activity and transactions to identify and manage financial-crime risks associated with customer relationships.
Transaction monitoring may involve automated or manual review of transactions and related customer behaviour to identify activity that appears unusual, inconsistent with the information obtained during onboarding, or potentially suspicious.
The objectives of transaction monitoring include:
- identifying potentially suspicious or unusual transactions;
- assessing whether transactions are consistent with the customer’s known profile and expected activity;
- confirming the continued relevance of customer and beneficial-owner information;
- identifying changes in the customer’s risk profile;
- understanding the purpose and nature of the business relationship;
- identifying unusual payment patterns, counterparties, jurisdictions or transaction behaviour; and
- supporting appropriate escalation, investigation and reporting.
OSO Money reserves the right, subject to applicable law, to:
- request additional information or documentation concerning a customer or transaction;
- delay or suspend a transaction while appropriate due diligence or investigation is conducted;
- decline or reject a transaction where required or permitted by law or internal risk controls;
- report suspicious or otherwise reportable activity to the appropriate authority; and
- suspend or terminate a customer relationship where there are reasonable grounds for concern or where continued provision of Services is not appropriate.
The above controls are not exhaustive. Monitoring may be conducted on an ongoing basis and may be adjusted according to the customer’s risk profile, transaction activity, applicable regulatory requirements and emerging financial-crime risks.
VI. Risk Assessment
OSO Money applies a risk-based approach to AML/CFT/CPF compliance. Controls are proportionate to the nature, scale and complexity of the risks identified and may be enhanced where a customer, transaction, product, service, jurisdiction or other factor presents higher risk.
OSO Money assesses and manages financial-crime risks associated with its business activities, customer relationships and transactions. Risk assessment may consider customer characteristics, ownership and control, business activity, source of funds and wealth, expected transaction activity, jurisdictions, delivery channels, counterparties, transaction patterns and other relevant factors.
In developing and maintaining its risk-based controls, OSO Money may consider:
- risks and guidance identified by the Financial Intelligence Centre and other competent South African authorities;
- applicable South African laws and regulations;
- relevant international standards and recognised financial-crime risk guidance;
- risks identified through OSO Money’s own business activities and customer base; and
- new or emerging financial-crime typologies and threats.
Prior to establishing a business relationship, OSO Money may conduct a customer risk assessment and assign an appropriate risk level. The risk level may be increased or decreased over time following periodic or event-driven reassessment.
Risk reassessment may occur:
- before establishing a business relationship;
- on an ongoing basis according to the customer’s risk level;
- when a new or materially different product or service is provided;
- when material new information or circumstances arise;
- when there is a significant deviation from expected customer behaviour;
- when transaction activity changes materially; or
- when other factors indicate that the customer’s risk profile may have changed.
OSO Money maintains internal controls intended to ensure that relevant customer and transaction information is periodically reviewed and assessed. The Company may consider regulatory guidance, law-enforcement information, financial-crime typologies, sanctions developments and other relevant information when assessing emerging risks.
VII. Enhanced Due Diligence
Where a customer or transaction presents higher financial-crime risk, OSO Money may apply Enhanced Due Diligence (“EDD”) measures.
EDD may include additional identification and verification, information concerning source of funds or source of wealth, information concerning the purpose and nature of the relationship, supporting commercial documentation, additional management approval, enhanced transaction monitoring or other measures considered appropriate to the identified risk.
The specific measures applied will depend on the circumstances and applicable legal and regulatory requirements.
VIII. Suspicious Activity and Reporting
Where OSO Money identifies activity that may require reporting under applicable law, the matter will be escalated in accordance with its internal procedures and applicable regulatory requirements.
OSO Money may submit reports or provide information to the Financial Intelligence Centre, regulators, law-enforcement authorities, courts, banks, payment providers or other competent authorities where required or permitted by law.
Nothing in this Policy requires OSO Money to disclose to a customer that a suspicious transaction or other regulatory report has been made where such disclosure is prohibited by law.
IX. Record Keeping and Confidentiality
OSO Money maintains records relating to customer identification, verification, transactions, due diligence, risk assessments, screening and other compliance activities in accordance with applicable legal and regulatory requirements.
Personal Data collected as part of AML/KYC processes will be handled in accordance with OSO Money’s Privacy Policy and applicable data-protection laws.
Access to AML/KYC information is restricted to personnel and service providers who require such information for legitimate business, compliance, legal, security or regulatory purposes.
X. Third-Party Service Providers
OSO Money may use appropriately selected third-party providers to support identity verification, sanctions and PEP screening, fraud prevention, transaction monitoring, payment processing, data storage and other compliance or operational functions.
Where appropriate, OSO Money will assess relevant third-party providers and implement contractual or other controls concerning confidentiality, security, data protection and appropriate use of customer information.
XI. Staff Training and Awareness
OSO Money will provide appropriate AML/KYC and financial-crime training and awareness to relevant employees and contractors.
Relevant personnel are expected to understand their responsibilities, identify and escalate unusual or suspicious activity, maintain confidentiality and comply with applicable AML/KYC procedures and reporting obligations.
XII. Governance and Review
Senior management is responsible for supporting an effective financial-crime compliance framework and ensuring that appropriate resources, controls and oversight are maintained.
This AML Policy is reviewed periodically and may be updated to reflect changes in legislation, regulatory expectations, OSO Money’s products and services, customer base, risk profile, technology or emerging financial-crime threats.
XIII. Regulatory and Company Information
OSO Money (Pty) Ltd is the trading name used in connection with the regulated business providing the relevant foreign exchange and international payment services.
Reference / Registration No.: 26368
Business address:
Suite D1, Nautica Building
13 Beach Road
Cape Town
Western Cape
8005
Republic of South Africa
Primary compliance and customer contact: [email protected]