DAT PAY

AML, CFT & Sanctions Policy

Last updated: 22 August 2026

Traduction non officielle

Ce document est publié en anglais. Le texte anglais constitue la version officielle et fait foi ; toute traduction est fournie à titre indicatif uniquement et n’a aucune valeur juridique. Consulter la version officielle en anglais

1. Purpose

DAT PAY is committed to maintaining a financial technology and infrastructure environment designed to prevent its services from being misused for money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud and other financial crime.

This AML, CFT & Sanctions Policy describes the principles that govern DAT PAY’s financial crime risk management framework.

The framework is designed around a risk-based approach and takes into consideration applicable laws, regulations, regulatory expectations, contractual requirements and internationally recognised financial crime prevention standards.

DAT PAY may apply controls that are more restrictive than the minimum legal requirement where necessary to protect the platform, customers, financial institutions, service providers and the integrity of the international financial system.

2. Scope

This Policy applies to activities and relationships connected with DAT PAY, including, where applicable:

  • customer onboarding;
  • individual customers;
  • business customers;
  • institutional customers;
  • authorised representatives;
  • beneficial owners;
  • transactions;
  • payment activity;
  • digital asset activity;
  • wallet activity;
  • account activity;
  • third-party service relationships;
  • financial institution relationships;
  • technology and infrastructure relationships.

The specific controls applied may vary according to the nature and regulatory structure of the relevant service.

3. Regulatory Framework

DAT PAY’s financial crime framework is designed with reference to applicable requirements and internationally recognised standards, including relevant principles issued by:

  • the Financial Action Task Force;
  • applicable CEMAC authorities;
  • applicable Cameroonian authorities;
  • relevant financial regulators;
  • applicable sanctions authorities;
  • other competent authorities having jurisdiction over a particular service or transaction.

The FATF Recommendations provide the international framework for combating money laundering, terrorist financing and proliferation financing. The current FATF Recommendations were updated in June 2026. (FATF)

Where digital asset activities are involved, DAT PAY takes into account the FATF framework applicable to virtual assets and virtual asset service providers.

4. Risk-Based Approach

DAT PAY applies a risk-based approach to financial crime prevention.

This means that controls are calibrated according to the level and nature of risk presented by:

  • the customer;
  • the beneficial owner;
  • the jurisdiction;
  • the product;
  • the transaction;
  • the counterparty;
  • the source of funds;
  • the source of wealth;
  • the delivery channel;
  • the technology involved;
  • the digital asset or blockchain network;
  • the transaction pattern;
  • other relevant risk factors.

Higher-risk relationships may be subject to enhanced controls.

Lower-risk relationships may be subject to proportionate controls where permitted by applicable law.

A risk-based approach does not mean that high-risk customers or transactions are automatically prohibited. It means that appropriate controls must be applied to identify, understand, mitigate and manage the relevant risks.

5. Financial Crime Risk Assessment

DAT PAY may periodically assess financial crime risks associated with its business and services.

Risk assessments may consider:

  • money laundering risk;
  • terrorist financing risk;
  • proliferation financing risk;
  • sanctions risk;
  • fraud risk;
  • corruption risk;
  • cybercrime risk;
  • digital asset risk;
  • jurisdictional risk;
  • customer risk;
  • product risk;
  • transaction risk;
  • delivery channel risk;
  • third-party risk.

Risk assessments may be updated when there are material changes to:

  • products;
  • customers;
  • jurisdictions;
  • technology;
  • transaction volumes;
  • financial institution relationships;
  • digital asset exposure;
  • applicable regulations;
  • threat intelligence.

6. Governance and Accountability

DAT PAY expects financial crime risk management to be supported by appropriate governance, accountability and oversight.

Depending on the scale and structure of the business, responsibilities may include:

  • senior management oversight;
  • compliance oversight;
  • customer due diligence;
  • transaction monitoring;
  • sanctions screening;
  • risk management;
  • suspicious activity escalation;
  • regulatory reporting;
  • internal controls;
  • independent review or testing.

Responsibilities may be allocated between DAT PAY and relevant regulated financial or technology service providers according to contractual arrangements and applicable law.

Where a regulated financial institution is responsible for a regulated activity, that institution retains responsibility for the obligations applicable to its regulated activity.

7. Customer Identification and Verification

DAT PAY may require customers to provide sufficient information to establish and verify their identity before providing certain services.

For individuals, information may include:

  • full legal name;
  • date of birth;
  • nationality;
  • residential address;
  • country of residence;
  • identification information;
  • tax information where applicable;
  • contact information.

Verification may involve:

  • government-issued identification;
  • identity verification technology;
  • address verification;
  • document verification;
  • biometric verification where legally permitted;
  • additional verification procedures.

8. Business and Institutional Due Diligence

Business and institutional customers may be subject to KYB procedures.

These procedures may include verification of:

  • legal name;
  • incorporation;
  • registration;
  • registered address;
  • operating activities;
  • directors;
  • authorised representatives;
  • ownership structure;
  • beneficial owners;
  • regulatory status;
  • licensing;
  • tax information;
  • source of funds;
  • source of wealth;
  • expected activity.

Additional information may be requested where the structure, ownership or activity presents elevated risk.

9. Beneficial Ownership

DAT PAY seeks to identify the natural persons who ultimately own or control relevant legal entities or arrangements.

Beneficial ownership information may be required for:

  • companies;
  • partnerships;
  • trusts;
  • foundations;
  • other legal arrangements;
  • institutional customers;
  • counterparties where required.

Customers must provide accurate and up-to-date beneficial ownership information.

Complex ownership structures may require additional documentation.

Where beneficial ownership cannot be reasonably established or verified, DAT PAY may decline or restrict the relationship.

FATF’s current beneficial ownership framework emphasises the availability of adequate, accurate and up-to-date information concerning the true owners and controllers of legal persons and arrangements. (FATF)

10. Customer Risk Classification

Customers may be assigned a risk classification based on relevant risk factors.

Factors may include:

  • customer type;
  • ownership structure;
  • country of residence;
  • country of incorporation;
  • business activity;
  • expected transaction activity;
  • transaction size;
  • source of funds;
  • source of wealth;
  • PEP status;
  • sanctions exposure;
  • adverse media;
  • digital asset exposure;
  • use of unhosted wallets;
  • unusual activity;
  • other relevant indicators.

Risk classifications may change during the relationship.

11. Enhanced Due Diligence

Enhanced due diligence may be applied where a relationship or transaction presents elevated risk.

Additional measures may include:

  • additional identification documents;
  • additional corporate documents;
  • detailed ownership information;
  • source of wealth verification;
  • source of funds verification;
  • transaction purpose verification;
  • additional management approval;
  • enhanced transaction monitoring;
  • additional screening;
  • periodic review;
  • restrictions on certain services.

High-risk relationships may be subject to additional contractual or operational restrictions.

12. Politically Exposed Persons

DAT PAY may identify and assess politically exposed persons, their family members and known close associates in accordance with applicable legal and regulatory requirements.

Where enhanced controls are required, DAT PAY may request:

  • additional information;
  • source of wealth information;
  • source of funds information;
  • additional management approval;
  • enhanced ongoing monitoring.

PEP status does not automatically mean that a customer is prohibited from using DAT PAY.

13. Sanctions Screening

DAT PAY maintains or may use screening controls designed to identify exposure to applicable sanctions and restrictive measures.

Screening may cover:

  • customers;
  • beneficial owners;
  • directors;
  • authorised representatives;
  • counterparties;
  • beneficiaries;
  • payment information;
  • jurisdictions;
  • digital asset wallet addresses;
  • other relevant parties.

Relevant sanctions sources may include applicable governmental and international sanctions lists.

A potential match may require additional investigation.

A confirmed sanctions concern may result in:

  • rejection;
  • restriction;
  • suspension;
  • freezing or blocking where legally required;
  • termination;
  • regulatory reporting;
  • other action required by applicable law.

14. Sanctions Evasion

DAT PAY prohibits the use of its services to evade sanctions or restrictive measures.

Customers must not:

  • conceal the identity of a sanctioned party;
  • disguise the origin or destination of funds;
  • structure transactions to avoid sanctions controls;
  • use intermediaries to circumvent restrictions;
  • use digital assets to circumvent applicable sanctions;
  • provide false information to bypass screening.

Attempts to circumvent sanctions may result in immediate restriction or termination of services and may be reported to competent authorities where required.

15. Adverse Media and Negative Information

DAT PAY may consider reliable adverse information when assessing financial crime risk.

Information may concern:

  • fraud;
  • corruption;
  • money laundering;
  • terrorist financing;
  • sanctions violations;
  • organised crime;
  • cybercrime;
  • serious financial misconduct;
  • other relevant criminal or regulatory conduct.

Adverse media is a risk indicator and does not by itself establish that a person has committed an offence.

Where appropriate, DAT PAY may request additional information before reaching a decision.

16. Source of Funds

DAT PAY may request information concerning the origin of funds used in connection with a customer relationship or transaction.

Source of funds information may include:

  • bank statements;
  • payment records;
  • business revenue information;
  • employment income;
  • sale of assets;
  • investment proceeds;
  • inheritance;
  • financing documentation;
  • other appropriate evidence.

The required evidence will depend on the risk and nature of the relationship.

17. Source of Wealth

Where required, DAT PAY may establish the origin of a customer’s overall wealth.

Source of wealth information may include:

  • business ownership;
  • employment;
  • investments;
  • inheritance;
  • property;
  • asset sales;
  • entrepreneurial activity;
  • other legitimate sources of wealth.

Enhanced source of wealth verification may be required for higher-risk customers.

18. Expected Activity

Customers may be asked to provide information about expected activity.

This may include:

  • expected transaction volumes;
  • expected transaction values;
  • countries involved;
  • currencies;
  • business counterparties;
  • payment purposes;
  • digital asset activity;
  • expected source and destination of funds.

This information may be used to establish a customer risk profile and identify unusual activity.

19. Ongoing Monitoring

Customer relationships may be monitored on an ongoing basis.

Monitoring may consider:

  • transaction activity;
  • changes in customer information;
  • changes in beneficial ownership;
  • changes in risk;
  • sanctions exposure;
  • transaction patterns;
  • unusual behaviour;
  • activity inconsistent with the customer’s profile.

Ongoing monitoring may result in requests for updated information or enhanced due diligence.

20. Transaction Monitoring

Transactions may be subject to automated and manual monitoring.

Monitoring may identify indicators such as:

  • unusual transaction volumes;
  • rapid movement of funds;
  • inconsistent transaction patterns;
  • unusual geographic activity;
  • unexplained third-party payments;
  • repeated failed transactions;
  • unusual digital asset transfers;
  • exposure to high-risk counterparties;
  • transactions involving sanctioned or restricted parties;
  • activity inconsistent with the customer’s profile.

Monitoring alerts may be reviewed by appropriate personnel or service providers.

21. Suspicious Activity

Where DAT PAY identifies activity that may indicate financial crime, the matter may be escalated for investigation.

Investigations may involve:

  • reviewing customer information;
  • reviewing transaction history;
  • reviewing counterparties;
  • requesting additional information;
  • conducting enhanced due diligence;
  • consulting relevant service providers;
  • restricting activity;
  • reporting to competent authorities where required.

A suspicious activity determination does not necessarily mean that criminal conduct has occurred.

22. Suspicious Transaction Reporting

Where required by applicable law, suspicious transactions or activities may be reported to the competent financial intelligence unit or other authorised authority.

Reports may be made without notifying the customer where disclosure is prohibited.

DAT PAY may also preserve records and restrict transactions associated with an investigation where legally permitted or required.

23. No Tipping-Off

DAT PAY will not disclose confidential information concerning a suspicious activity report, regulatory investigation or other protected compliance process where disclosure is prohibited by applicable law.

Customers should therefore understand that DAT PAY may sometimes be unable to explain the full reason for:

  • a transaction delay;
  • an account restriction;
  • a request for information;
  • a transaction rejection;
  • an account closure.

24. Terrorist Financing

DAT PAY prohibits the use of its services to facilitate terrorist financing.

Risk controls may include:

  • sanctions screening;
  • customer due diligence;
  • transaction monitoring;
  • counterparty screening;
  • geographic risk assessment;
  • wallet screening where relevant;
  • suspicious activity escalation.

Transactions presenting terrorist financing indicators may be restricted and reported where required.

25. Proliferation Financing

DAT PAY recognises the risks associated with proliferation financing and the misuse of financial channels to support the development, acquisition or transfer of weapons of mass destruction and related materials.

Where applicable, DAT PAY may apply targeted financial sanctions and other controls addressing proliferation financing.

Relevant transactions may be restricted, blocked or escalated in accordance with applicable requirements.

26. Digital Asset Risk

Digital asset activity presents specific financial crime risks.

DAT PAY may consider risks associated with:

  • pseudonymous transactions;
  • rapid cross-border transfers;
  • privacy-enhancing technologies;
  • mixers or tumblers;
  • sanctions exposure;
  • ransomware;
  • fraud;
  • stolen assets;
  • darknet activity;
  • illicit marketplaces;
  • high-risk exchanges;
  • unhosted wallets;
  • peer-to-peer transactions;
  • stablecoins;
  • decentralised finance;
  • chain hopping;
  • bridge activity;
  • other emerging typologies.

FATF’s July 2026 update identifies fraud, stablecoins, peer-to-peer activity involving unhosted wallets, offshore VASPs and DeFi arrangements among emerging or increasing areas of concern. (FATF)

27. Blockchain Analytics and Screening

Where digital asset functionality is involved, transaction information may be analysed using blockchain analytics, risk intelligence or similar technology.

Analysis may consider:

  • wallet exposure;
  • transaction history;
  • counterparty exposure;
  • sanctions exposure;
  • illicit activity indicators;
  • high-risk services;
  • unusual transaction patterns.

A blockchain risk score or alert may require additional investigation.

A risk indicator does not automatically establish that a transaction is unlawful.

28. Unhosted Wallets

Transactions involving unhosted wallets may be subject to enhanced controls depending on:

  • the applicable jurisdiction;
  • the product;
  • transaction value;
  • counterparty information;
  • risk indicators;
  • regulatory requirements.

Additional information may be required to establish the origin, destination, ownership or purpose of a transaction.

A transaction may be rejected or restricted where required information cannot be obtained or where the relevant risk cannot be adequately mitigated.

29. Travel Rule

Where applicable, digital asset transfers may be subject to Travel Rule requirements.

DAT PAY or the relevant Service Provider may be required to obtain, verify, transmit or retain information relating to the originator and beneficiary of a virtual asset transfer.

Required information may include:

  • originator information;
  • beneficiary information;
  • originating institution information;
  • beneficiary institution information;
  • transaction information.

Transfers may be delayed or rejected where legally required information is unavailable, inaccurate or cannot be appropriately verified.

FATF continues to identify Travel Rule implementation as a key requirement in the global virtual asset framework. (FATF)

30. Third-Party Service Providers

DAT PAY may use specialised service providers to support financial crime controls.

These services may include:

  • identity verification;
  • KYB;
  • sanctions screening;
  • PEP screening;
  • adverse media;
  • fraud detection;
  • transaction monitoring;
  • blockchain analytics;
  • security monitoring;
  • compliance technology.

The use of a third-party provider does not remove DAT PAY’s responsibility for appropriately managing risks within the scope of its role.

Where a regulated Service Provider is independently responsible for a regulated activity, that provider remains responsible for the obligations applicable to its activity.

31. Information Sharing

Where legally permitted or required, DAT PAY may share information with:

  • financial institutions;
  • payment institutions;
  • regulated service providers;
  • financial intelligence units;
  • regulators;
  • law enforcement authorities;
  • courts;
  • tax authorities;
  • sanctions authorities;
  • professional advisers;
  • compliance service providers.

Information sharing will be limited to purposes permitted by applicable law and contractual requirements.

32. Record Keeping

DAT PAY may retain records necessary to demonstrate compliance and support financial crime controls.

Records may include:

  • customer identification;
  • KYB information;
  • beneficial ownership information;
  • transaction information;
  • screening results;
  • risk assessments;
  • compliance reviews;
  • suspicious activity investigations;
  • regulatory communications;
  • audit trails.

Records may be retained for periods required by applicable law, regulation or contractual obligations.

33. Training and Awareness

DAT PAY expects personnel involved in relevant activities to receive appropriate financial crime awareness and compliance training.

Training may address:

  • AML;
  • CFT;
  • sanctions;
  • fraud;
  • customer due diligence;
  • beneficial ownership;
  • suspicious activity;
  • data protection;
  • digital asset risks;
  • escalation procedures.

Training requirements may vary according to an individual’s responsibilities.

34. Internal Controls

DAT PAY may maintain controls designed to:

  • separate incompatible responsibilities;
  • limit access to sensitive information;
  • protect customer information;
  • prevent unauthorised transactions;
  • identify unusual activity;
  • maintain audit trails;
  • escalate compliance concerns;
  • support regulatory reporting.

The nature and extent of controls will depend on the relevant service and risk profile.

35. Independent Review

DAT PAY may periodically review its AML/CFT and sanctions controls.

Reviews may include:

  • internal testing;
  • control assessments;
  • compliance reviews;
  • external assessments;
  • audits;
  • technology reviews;
  • risk assessments.

Findings may result in corrective actions, enhanced controls or changes to procedures.

36. Cooperation With Authorities

DAT PAY may cooperate with competent authorities in relation to:

  • financial crime investigations;
  • sanctions investigations;
  • fraud investigations;
  • regulatory examinations;
  • court proceedings;
  • tax investigations;
  • law enforcement requests;
  • other lawful investigations.

Information will be provided in accordance with applicable law.

37. Customer Responsibilities

Customers are responsible for providing complete, accurate and current information.

Customers must promptly inform DAT PAY of material changes to:

  • identity;
  • residence;
  • business activity;
  • ownership;
  • beneficial ownership;
  • directors;
  • authorised representatives;
  • source of funds;
  • source of wealth;
  • regulatory status.

Providing false, incomplete or misleading information may result in restrictions or termination.

38. Prohibited Financial Crime Activity

DAT PAY prohibits the use of its services for:

  • money laundering;
  • terrorist financing;
  • proliferation financing;
  • sanctions evasion;
  • fraud;
  • corruption;
  • bribery;
  • tax evasion;
  • proceeds of crime;
  • identity theft;
  • cybercrime;
  • ransomware;
  • illicit marketplaces;
  • unlawful gambling where prohibited;
  • financing of prohibited activities;
  • concealment of beneficial ownership;
  • structuring intended to evade controls;
  • other unlawful financial activity.

39. Refusal and Termination

DAT PAY may refuse to establish or continue a relationship where:

  • identity cannot be verified;
  • beneficial ownership cannot be established;
  • source of funds cannot be reasonably established;
  • source of wealth cannot be reasonably established where required;
  • sanctions concerns cannot be resolved;
  • financial crime risk cannot be adequately mitigated;
  • information provided is false or misleading;
  • the customer refuses required due diligence;
  • the relationship would create unacceptable legal or regulatory risk;
  • a relevant Service Provider declines the relationship;
  • applicable law requires refusal or termination.

40. No Guaranteed Access

Completion of KYC or KYB does not guarantee access to every DAT PAY service.

A customer may pass identity verification and still be subject to:

  • enhanced due diligence;
  • transaction restrictions;
  • sanctions screening;
  • product restrictions;
  • jurisdictional restrictions;
  • additional Service Provider requirements.

41. Risk-Based Restrictions

DAT PAY may apply different controls to different customers, products, transactions or jurisdictions based on risk.

Such measures may include:

  • transaction limits;
  • additional documentation;
  • enhanced monitoring;
  • delayed processing;
  • manual review;
  • restricted functionality;
  • geographic restrictions;
  • rejection;
  • suspension;
  • termination.

42. Data Protection

AML/CFT and sanctions controls may involve processing sensitive personal and financial information.

DAT PAY processes such information in accordance with applicable data protection requirements.

Financial crime prevention obligations may require DAT PAY to retain, analyse or disclose information even where an individual would otherwise request deletion.

Further information is available in the DAT PAY Privacy Policy.

43. Confidentiality

Information collected for AML/CFT and sanctions purposes is handled confidentially and accessed only by authorised persons or service providers with a legitimate need for access.

Confidentiality requirements do not prevent lawful disclosure to competent authorities or other persons where required or permitted by law.

44. Continuous Improvement

Financial crime risks evolve continuously.

DAT PAY may update its controls in response to:

  • new typologies;
  • regulatory developments;
  • sanctions changes;
  • emerging digital asset risks;
  • fraud trends;
  • cybersecurity threats;
  • changes in customer behaviour;
  • changes in transaction patterns;
  • regulatory guidance;
  • risk assessments.

The framework may therefore change without prior notice where necessary to protect the platform and comply with applicable requirements.

45. Regulatory Perimeter

DAT PAY is a technology and financial infrastructure platform operated by HACHTHER SARL.

HACHTHER SARL does not represent itself as a bank, payment institution, electronic money issuer, money transfer institution, custodian, investment manager, broker or virtual asset service provider unless and to the extent that it holds the applicable authorisation.

Where regulated activities are performed by an authorised institution, the relevant institution remains responsible for the regulated activity within the scope of its authorisation.

This Policy does not create or imply a regulatory licence for HACHTHER SARL.

46. No Circumvention

DAT PAY does not intend to facilitate the circumvention of AML/CFT, sanctions, payment, banking, digital asset or other financial regulation.

The platform may restrict functionality where a transaction structure, customer relationship or activity creates a risk of regulatory circumvention.

47. Policy Changes

DAT PAY may update this Policy to reflect:

  • changes in applicable law;
  • regulatory developments;
  • changes in FATF standards;
  • changes in CEMAC requirements;
  • changes in products;
  • changes in transaction structures;
  • changes in financial crime risks;
  • changes in technology.

The latest version will be published on the DAT PAY website.

48. Contact

Questions concerning this Policy may be submitted through the official contact channels published on the DAT PAY website.

HACHTHER SARL DAT PAY Republic of Cameroon

AML, CFT & Sanctions Policy | DAT PAY