QorePay

    QorePay Risk & Compliance Policy

    Version 1.0 · Effective Date: 1 January 2026 · Last Updated: 1 January 2026

    1. Introduction

    This Risk & Compliance Policy ("Policy") sets out the principles, controls, and enforcement framework used by QorePay Technology Solutions Limited ("QorePay", "we", "our", or "us") to manage financial, regulatory, operational, fraud, and reputational risk across its platform and merchant ecosystem.

    This Policy applies to all merchants, users, integrations, APIs, and transactions processed through QorePay services.

    It forms part of the QorePay contractual framework and must be read alongside the Terms of Use, Acceptable Use Policy, Merchant Services Agreement (MSA), and all applicable regulatory requirements.

    2. Purpose of This Policy

    The purpose of this Policy is to:

    • Prevent financial crime, fraud, and illicit activity
    • Ensure compliance with Applicable Laws and regulatory obligations
    • Protect customers, financial partners, and payment ecosystems
    • Define QorePay's risk classification and enforcement powers
    • Establish ongoing merchant monitoring and due diligence standards

    QorePay operates a risk-based compliance framework, meaning controls are applied dynamically based on assessed risk exposure.

    3. Regulatory Framework

    QorePay operates in compliance with, where applicable:

    • Central Bank of Nigeria (CBN) regulations
    • Nigerian Financial Intelligence Unit (NFIU) guidelines
    • Anti-Money Laundering (AML) regulations
    • Counter-Terrorism Financing (CTF) laws
    • Data protection laws (including NDPC requirements)
    • Card scheme rules (Visa, Mastercard, Verve, etc.)
    • Acquiring bank and payment processor requirements
    • International financial crime standards where applicable

    QorePay may implement additional controls beyond regulatory minimums.

    4. Risk-Based Approach

    QorePay applies a risk-based model to all merchants and transactions. Risk is assessed continuously using factors including:

    • Transaction volume and velocity
    • Average transaction value
    • Chargeback ratios and dispute patterns
    • Refund frequency and behaviour
    • Industry classification
    • Business model complexity
    • Geographic exposure
    • Customer complaints and behaviour patterns
    • External intelligence and adverse media
    • Regulatory alerts or enforcement actions
    • Internal fraud detection systems
    • API and platform usage behaviour

    Risk scoring is proprietary and confidential.

    5. Merchant Due Diligence (KYC/KYB)

    All merchants must undergo onboarding verification before access to services is granted.

    QorePay may request, at onboarding or any time thereafter:

    • Corporate registration documents (CAC or equivalent)
    • Director and shareholder information
    • Beneficial ownership details
    • Government-issued identification
    • BVN/NIN and tax identification
    • Bank account verification
    • Business model and product descriptions
    • Website, domain, and application details
    • Transaction flow documentation
    • Source of funds and source of wealth information
    • Financial statements or bank records
    • Regulatory licences (where applicable)

    Failure to provide requested documentation may result in suspension or termination.

    6. Ongoing Monitoring

    QorePay continuously monitors merchant activity on a real-time and retrospective basis. Monitoring includes:

    • Transaction patterns and anomalies
    • Fraud detection signals
    • Chargeback ratios and dispute behaviour
    • Refund and reversal patterns
    • API usage and integration behaviour
    • Website and platform activity
    • Customer complaints and external reports
    • Regulatory and law enforcement intelligence
    • Sanctions screening and watchlists
    • Third-party risk intelligence

    Monitoring may occur without notice.

    7. High-Risk Classification

    QorePay may classify any merchant or user as High Risk at its sole discretion.

    Classification may be based on:

    • Industry type or business model
    • Transaction behaviour and anomalies
    • Fraud or chargeback exposure
    • Regulatory sensitivity
    • Adverse media or intelligence reports
    • Suspicious onboarding information
    • Use of undisclosed platforms or funnels
    • API misuse or integration irregularities

    QorePay is not required to disclose its internal risk scoring methodology or classification rationale.

    High-Risk classification may result in enhanced controls, including reserves, delays, or restrictions.

    8. Enhanced Due Diligence (EDD)

    Where risk is elevated, QorePay may require Enhanced Due Diligence, including:

    • Additional identity verification
    • Proof of business activity and customers
    • Transaction-level explanations
    • Contracts, invoices, or service evidence
    • Source of funds verification
    • Independent audits or compliance checks
    • Ongoing periodic reporting

    Failure to comply may result in immediate enforcement action.

    9. Transaction Monitoring & Controls

    QorePay may apply automated and manual controls including:

    • Real-time transaction screening
    • Velocity and volume limits
    • Geo-blocking or restrictions
    • Transaction holds or delays
    • Fraud scoring and risk tagging
    • Manual review queues

    QorePay may decline or reverse transactions where risk is identified.

    10. Risk Mitigation Tools

    To manage exposure, QorePay may apply:

    • Rolling reserves (as defined in MSA)
    • Settlement delays or holds
    • Security deposits or guarantees
    • Transaction limits
    • Partial or full service restrictions
    • Account segmentation or isolation

    These measures may be applied before, during, or after onboarding.

    11. Fraud Prevention Framework

    QorePay actively detects and prevents:

    • Unauthorized transactions
    • Account takeover attempts
    • Card testing or enumeration attacks
    • Synthetic identity fraud
    • Phishing or social engineering activity
    • Payment laundering or layering schemes
    • Fraudulent merchant onboarding

    Where fraud is suspected, QorePay may act immediately without notice.

    12. Compliance Investigations

    QorePay may conduct investigations at any time into:

    • Merchant activity
    • Transactions or settlements
    • Customer disputes
    • Platform usage patterns
    • External reports or intelligence

    During investigations, QorePay may:

    • Suspend processing
    • Withhold funds (per MSA)
    • Request documentation
    • Contact financial institutions or regulators
    • Restrict account access

    13. Regulatory Cooperation

    QorePay may disclose merchant or transaction data to:

    • Central Bank of Nigeria (CBN)
    • Nigerian Financial Intelligence Unit (NFIU)
    • EFCC and law enforcement agencies
    • Payment schemes and card networks
    • Acquiring banks and financial partners

    Such disclosure may occur without prior notice where legally required or necessary to prevent financial crime.

    14. Sanctions and Watchlist Compliance

    QorePay may screen merchants, transactions, and beneficiaries against:

    • International sanctions lists
    • Government watchlists
    • Law enforcement databases
    • Internal risk databases

    QorePay may block or freeze activity where a match or potential match is identified.

    15. Data Retention and Recordkeeping

    QorePay retains merchant and transaction records for compliance purposes in accordance with Applicable Laws.

    Records may include:

    • Transaction history
    • KYC/KYB documents
    • Communication logs
    • Risk scoring outputs
    • Investigation records

    These may be shared with regulators where required.

    16. Enforcement Actions

    Where risk, breach, or suspicious activity is identified, QorePay may:

    • Suspend or terminate accounts
    • Block or reverse transactions
    • Freeze or withhold settlements
    • Impose or adjust rolling reserves
    • Restrict platform access
    • Revoke API credentials
    • Escalate to regulators or law enforcement

    Actions may be immediate and without prior notice.

    17. Survival of Risk Controls

    Risk controls may continue after termination, including:

    • Fund withholding
    • Reserve retention
    • Investigation processes
    • Regulatory reporting obligations
    • Chargeback and liability recovery

    18. No Obligation to Onboard or Continue Service

    QorePay is under no obligation to:

    • Onboard any merchant
    • Maintain ongoing service access
    • Disclose internal risk decisions
    • Continue processing where risk is deemed unacceptable

    19. Limitation of Liability

    To the maximum extent permitted by law, QorePay shall not be liable for:

    • Losses arising from risk enforcement actions
    • Transaction declines or delays
    • Fraud-related losses
    • Regulatory actions or reporting
    • Third-party system failures

    20. Updates to This Policy

    QorePay may update this Policy at any time.

    Continued use of services constitutes acceptance of updates.

    21. Governing Law

    This Policy is governed by the laws of the Federal Republic of Nigeria.