Shujaa Pay — Africa's Reputation-powered EscrowBack to home

Shujaa Pay — Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) Policy

Document TitleAnti-Money Laundering & Counter-Terrorist Financing Policy
PlatformShujaa Pay (www.shujaapay.com)
Operating CompanyShujaa Tech Company Limited
Version2.0
Effective Date25 June 2026
Last Updated25 June 2026
Policy OwnerMoney Laundering Reporting Officer (MLRO)
Contactcompliance@shujaapay.com · +255 746 259 442

[LEGAL REVIEW REQUIRED: This Policy must be reviewed, completed, and certified by a qualified Tanzanian AML/CFT legal specialist before reliance. All statutory citations, regulator names, reporting thresholds, and timelines below are marked where they require verification against current Tanzanian law and Bank of Tanzania / FIU guidance.]


1. Purpose

Shujaa Pay, operated by Shujaa Tech Company Limited ("Shujaa Pay", "we", "us", "our"), is committed to preventing its escrow payment platform from being used to launder the proceeds of crime, finance terrorism, evade sanctions, or commit fraud or other financial crime.

This Anti-Money Laundering and Counter-Terrorist Financing Policy ("Policy") sets out the controls, procedures, and governance structure we apply to detect, prevent, and report money laundering ("ML") and terrorist financing ("TF"). It is designed to give effect to our obligations under Tanzanian law and to internationally recognised standards, including the recommendations of the Financial Action Task Force ("FATF").

This Policy forms part of our binding agreement with users. It must be read together with our Terms and Conditions, Privacy Policy, and Security Policy.


2. Legal and Regulatory Framework

This Policy is intended to align with the following legal and regulatory instruments:

InstrumentRelevance
Anti-Money Laundering Act, Cap 423 (Tanzania)Primary AML statute; CDD, record-keeping, and reporting obligations
Anti-Money Laundering Regulations (and amendments)Operational requirements for reporting persons
Proceeds of Crime Act, Cap 256 (Tanzania)Criminalises dealing in proceeds of crime
Prevention of Terrorism Act, Cap 19 (Tanzania)Counter-terrorist financing obligations
Bank of Tanzania (BoT) AML/CFT GuidelinesSupervisory expectations for payment ecosystem participants
National Payment Systems Act and RegulationsGoverns payment activity (conducted via our licensed PSP)
United Nations Security Council ResolutionsSanctions and asset-freezing obligations
FATF RecommendationsInternational AML/CFT standards

[LEGAL REVIEW REQUIRED: Confirm the exact short titles, chapter/cap numbers, current amendments, and applicability of each instrument to Shujaa Pay's specific activity as an escrow facilitator operating through a licensed PSP. Confirm whether Shujaa Pay is itself a "reporting person" under the AML Act or whether obligations are discharged via the PSP, and document the conclusion here.]


3. Scope

This Policy applies to:

  • All seller accounts, applications, and transactions on Shujaa Pay
  • All buyer payment flows processed through our licensed payment partner (Selcom)
  • All escrow holds, releases, refunds, and payouts
  • All directors, officers, employees, contractors, and administrators with access to financial operations, customer data, or compliance functions
  • Our relationships with third-party partners, including the PSP and approved logistics partners

Every person within scope is required to understand and comply with this Policy. Failure to comply may result in disciplinary action up to and including dismissal, termination of contract, account closure, and referral to authorities.


4. Governance and Responsibilities

4.1 Money Laundering Reporting Officer (MLRO)

Shujaa Pay designates a senior individual as the Money Laundering Reporting Officer (MLRO) / AML Compliance Officer. The MLRO holds primary responsibility for the AML/CFT programme and acts as the central point of contact with the Financial Intelligence Unit ("FIU") and other competent authorities.

[LEGAL REVIEW REQUIRED: Appoint and name a specific, suitably senior and sufficiently independent MLRO (and a deputy MLRO for continuity). The MLRO should not have conflicting operational responsibilities that compromise independence. Record the appointee's name, title, and FIU registration/notification status here.]

The MLRO is responsible for:

  • Owning, maintaining, and annually reviewing this Policy and the underlying procedures
  • Maintaining the enterprise ML/TF risk assessment (Section 5)
  • Receiving internal suspicious activity escalations and deciding whether to file a Suspicious Transaction Report (STR) with the FIU
  • Acting as liaison with the FIU, Bank of Tanzania, and law enforcement
  • Overseeing sanctions and PEP screening controls
  • Approving (or declining) high-risk and PEP relationships
  • Ensuring staff training is delivered and recorded
  • Maintaining AML records and management information / reporting to senior management

4.2 Board and Senior Management

Senior management is accountable for fostering a culture of compliance, providing adequate resources to the AML/CFT function, and reviewing periodic reports from the MLRO. Senior management approval is required for onboarding higher-risk and PEP customers.

4.3 All Personnel

Every staff member must remain alert to ML/TF risk indicators, complete required training, escalate suspicions to the MLRO promptly, and never "tip off" a customer (see Section 11).


5. Risk-Based Approach and Risk Assessment

In line with FATF Recommendation 1, Shujaa Pay applies a risk-based approach: controls are calibrated to the level of ML/TF risk presented by a customer, transaction, product, geography, or delivery channel.

We maintain a documented enterprise-wide ML/TF risk assessment, reviewed at least annually and upon material change to our business, covering at minimum:

Risk CategoryExamples of Factors Considered
Customer riskSeller type, beneficial ownership opacity, PEP status, adverse media, transaction behaviour, prior disputes/fraud flags
Product/service riskEscrow holding, payout to mobile money, link-based payments, reusable links, high single-transaction values
Geographic riskCross-border elements, higher-risk jurisdictions, FATF-listed jurisdictions, sanctioned territories
Delivery/channel riskNon-face-to-face onboarding, social-commerce origination (WhatsApp, Instagram, Facebook, TikTok), delivery corridor integrity

Each seller is assigned a risk rating (e.g., Low / Medium / High) that determines the level of due diligence and monitoring applied. Ratings are reviewed on a periodic and event-driven basis.

[LEGAL REVIEW REQUIRED: Confirm the risk-assessment methodology, rating tiers, and review frequency meet BoT/FIU expectations and document the standalone enterprise risk-assessment document referenced here.]


6. Customer Due Diligence (CDD) / Know Your Customer (KYC)

6.1 Standard CDD (Sellers)

Before a seller may withdraw funds, and as part of onboarding, Shujaa Pay performs identity verification including:

  • Full legal name matching the National Identification (NIDA) record
  • NIDA number and card images (front and back)
  • Selfie / liveness verification matched to the ID
  • Mobile money number whose registered name matches the verified NIDA identity

Withdrawals are blocked until KYC status is VERIFIED. We verify the identity of the customer using reliable, independent source documents, data, or information.

6.2 Buyers

Buyers transact without a standing account. For each transaction we collect name, phone number, and (where provided) email, together with payment and device metadata. Buyer payments are processed through the licensed PSP, which performs payment-level controls. Buyer activity is subject to transaction monitoring and sanctions screening as described below.

6.3 Beneficial Ownership

Where a seller account is operated for or on behalf of a business or another person, Shujaa Pay takes reasonable measures to identify and verify the beneficial owner(s) — the natural person(s) who ultimately own or control the account or on whose behalf transactions are conducted.

[LEGAL REVIEW REQUIRED: Confirm the beneficial-ownership threshold (e.g., ownership/control percentage) and the verification evidence required under Tanzanian law.]

6.4 Ongoing Due Diligence

We conduct ongoing monitoring of the business relationship, including scrutiny of transactions to ensure they are consistent with our knowledge of the customer, their risk profile, and source of funds. Customer information is kept current and is refreshed on a risk-sensitive basis.

6.5 Simplified and Enhanced Due Diligence

  • Simplified Due Diligence (SDD) may be applied to demonstrably low-risk situations, where permitted by law.
  • Enhanced Due Diligence (EDD) is mandatory for higher-risk situations (see Section 7).

6.6 Inability to Complete CDD

Where we cannot complete required CDD, we will not establish or continue the relationship, will not process payouts, and will consider whether the circumstances give rise to a reportable suspicion (see Sections 10 and 12).


7. Enhanced Due Diligence (EDD)

EDD applies to higher-risk customers and situations, including but not limited to:

  • Politically Exposed Persons (PEPs) and their family members and close associates (see Section 8)
  • Sellers with high transaction volumes or values, or rapid growth inconsistent with their profile
  • Sellers operating in higher-risk or flagged product categories
  • Transactions with a cross-border element or links to higher-risk jurisdictions
  • Customers presenting adverse media or prior fraud / dispute abuse indicators
  • Any case where standard CDD raises unresolved questions

EDD measures may include:

  • Obtaining additional identity and beneficial-ownership information
  • Establishing the source of funds and source of wealth
  • Obtaining senior management / MLRO approval to establish or continue the relationship
  • Applying enhanced ongoing monitoring with lower alert thresholds and more frequent review

8. Politically Exposed Persons (PEPs)

A PEP is an individual who is or has been entrusted with a prominent public function, and includes their immediate family members and known close associates.

Shujaa Pay:

  • Screens customers to identify PEP status at onboarding and on an ongoing basis
  • Treats PEP relationships as high risk and applies EDD
  • Requires MLRO / senior management approval before onboarding or continuing a PEP relationship
  • Establishes the source of funds and wealth for PEP customers
  • Applies enhanced, ongoing monitoring of PEP transactions

[LEGAL REVIEW REQUIRED: Confirm the Tanzanian definition of domestic and foreign PEPs, the scope of "family members and close associates", and the approval level required.]


9. Sanctions Screening

Shujaa Pay screens customers and, where relevant, counterparties and transactions against applicable sanctions and designated-persons lists, including:

  • United Nations Security Council consolidated sanctions list
  • Tanzanian national designated-persons / asset-freeze lists
  • OFAC (US), EU, and UK (OFSI) lists, to the extent applicable to our operations and partners

Screening is performed at onboarding and on an ongoing basis (including when lists are updated). In the event of a confirmed or potential match, Shujaa Pay will:

  1. Freeze / block the relevant account, funds, or transaction without delay
  2. Decline to process the payment or payout
  3. Escalate immediately to the MLRO
  4. Report to the FIU and any other competent authority as required by law
  5. Refrain from tipping off the customer (see Section 11)

[LEGAL REVIEW REQUIRED: Confirm which sanctions regimes Shujaa Pay is legally bound by, the legal basis and process for freezing assets, the asset-freeze reporting authority and timelines, and how sanctions responsibilities are allocated between Shujaa Pay and the PSP.]


10. Transaction Monitoring

Shujaa Pay monitors activity to identify unusual or suspicious behaviour that may indicate ML/TF. Monitoring combines automated rules with human review and considers indicators such as:

  • Unusual transaction volumes, values, frequency, or velocity inconsistent with the customer profile
  • Structuring — breaking large amounts into smaller transactions to evade thresholds
  • Repeated failed payments, reversals, or disputes
  • Mismatched identity, payout, or device/location signals
  • Rapid movement of funds in and out of escrow with no apparent commercial rationale
  • Use of multiple accounts, links, or mobile money numbers in a coordinated manner
  • Transactions connected to sanctioned or higher-risk parties or jurisdictions

10.1 Transaction Thresholds and Triggers

Defined thresholds trigger additional review, EDD, source-of-funds enquiry, escalation to the MLRO, and/or regulatory reporting.

[LEGAL REVIEW REQUIRED: Set and document specific monetary thresholds for (a) enhanced review, (b) source-of-funds enquiry, (c) Cash Transaction Report (CTR) / large-transaction reporting where applicable, and (d) mandatory escalation — calibrated to Tanzanian regulatory thresholds and Shujaa Pay's risk appetite.]

Alerts are investigated by trained staff and, where suspicion is formed, escalated to the MLRO for an STR decision.


11. Suspicious Transaction Reporting (STR) and Tipping-Off

11.1 Internal Escalation

Any staff member who knows, suspects, or has reasonable grounds to suspect ML/TF or other financial crime must escalate to the MLRO without delay using the internal reporting channel. Staff must not investigate independently in a manner that could alert the subject.

11.2 STR Filing

The MLRO assesses each internal report and, where the suspicion is substantiated, files a Suspicious Transaction Report (STR) with the Financial Intelligence Unit (FIU) of Tanzania, in the prescribed form and within the time limits required by law. The MLRO documents the rationale for filing or not filing each report.

[LEGAL REVIEW REQUIRED: Confirm the FIU reporting channel, the prescribed STR form, the statutory filing deadline (e.g., within a set number of hours/days of forming suspicion), and any Cash Transaction Report (CTR) obligations and thresholds.]

11.3 Tipping-Off Prohibition

It is strictly prohibited — and may be a criminal offence under Tanzanian law — to disclose to a customer or any third party that an STR has been or may be filed, or that an ML/TF investigation is being or may be carried out. All staff must observe this prohibition absolutely. Necessary account actions (e.g., holds) must be handled so as not to reveal the existence of a report.

11.4 Protection of Reporting Staff

Staff who report suspicions in good faith are protected from liability and from retaliation.


12. De-Risking and Account Exit

Where a customer cannot be adequately identified or verified, refuses to provide required information, or presents unacceptable ML/TF risk, Shujaa Pay may:

  • Decline to onboard the customer
  • Suspend or restrict the account and block payouts
  • Exit the relationship and return funds only through verified, lawful channels (subject to any freeze, hold, or legal restriction)
  • File an STR where suspicion exists

Account exit and fund handling are always conducted consistently with the tipping-off prohibition and any instructions from competent authorities.


13. Prohibited Activities

Users must not use Shujaa Pay for:

  • Money laundering or terrorist financing
  • Fraudulent, deceptive, or misrepresented transactions
  • Processing payments for illegal goods or services
  • Structuring transactions to evade reporting thresholds or controls
  • Transacting with sanctioned persons, entities, or jurisdictions
  • Use of stolen, third-party, or synthetic identities or payment credentials
  • Evading KYC, escrow, fee, or delivery controls

Breach may result in immediate account suspension or termination, fund holds, regulatory reporting, and referral to law enforcement.


14. Escrow and Payment Controls

The escrow model itself functions as an AML control. Funds are held until release conditions are met, creating an auditable record of each transaction's lifecycle.

ControlDescription
PSP RoutingAll payment collection and disbursement is processed through Selcom, a licensed Payment Service Provider, which applies its own regulated AML/payment controls
KYC GateSellers must be KYC-verified before any payout
Name MatchingPayout mobile money account name must match the verified NIDA identity
Escrow HoldsDisputes, compliance reviews, and admin holds block release
Idempotent ReleaseRelease logic prevents duplicate payouts
Audit TrailAll escrow holds, releases, refunds, payouts, approvals, and rejections are logged

14.1 Allocation of AML Responsibilities with the PSP

Shujaa Pay and Selcom each perform AML/payment controls within their respective roles. Selcom, as the licensed PSP, performs regulated payment-level screening and reporting; Shujaa Pay performs platform-level CDD, monitoring, and escalation.

[LEGAL REVIEW REQUIRED: Document the contractual division of AML/CFT responsibilities between Shujaa Pay and Selcom (and mobile money operators), including who is the reporting entity for which controls, to avoid gaps or duplication.]


15. Record Keeping

Shujaa Pay retains AML/CFT records — including CDD/KYC documentation, transaction records, screening results, internal reports, STR decisions, and supporting correspondence — for a minimum of seven (7) years from the end of the business relationship or the date of the transaction, or longer where required by law or requested by a competent authority.

Records are stored securely and are retrievable to respond to lawful requests from the FIU, Bank of Tanzania, or law enforcement. Retention and protection of these records is governed by our Privacy Policy and Security Policy.

[LEGAL REVIEW REQUIRED: Confirm the statutory minimum retention period(s) and the point from which they run under Tanzanian AML law.]


16. Staff Training Programme

Shujaa Pay maintains a structured AML/CFT training programme so that all in-scope personnel can recognise and respond to ML/TF risk. The programme includes:

ElementStandard
AudienceAll staff, contractors, and administrators with access to financial operations or customer data
Onboarding trainingCompleted before access to financial/customer systems is granted
Refresher trainingAt least annually, and upon material regulatory or policy change
CurriculumML/TF typologies, red flags, CDD/EDD, PEP and sanctions screening, escalation, STR process, tipping-off prohibition, record keeping
AssessmentKnowledge check / assessment with a minimum pass standard
RecordsAttendance, completion, and assessment results recorded and retained

The MLRO reviews training content periodically to reflect emerging risks and regulatory developments.


17. Independent Review and Assurance

The AML/CFT programme is subject to periodic independent review (internal audit or qualified external party) to test the adequacy and effectiveness of controls. Findings are reported to senior management with tracked remediation.

[LEGAL REVIEW REQUIRED: Confirm whether an independent AML audit is mandated, and at what frequency, for an entity of Shujaa Pay's type.]


18. Cooperation with Authorities

Shujaa Pay cooperates fully with the FIU, the Bank of Tanzania, law enforcement, and other competent authorities, responding to lawful requests for information, production orders, freezing orders, and investigations through proper legal channels, consistent with our Privacy Policy and applicable law.


19. Policy Governance and Review

This Policy is reviewed at least annually, and additionally after any significant regulatory change, material incident, or change to our business model. Changes are version-controlled and approved by the MLRO and senior management.

This Policy forms part of the binding agreement between users and Shujaa Pay and is incorporated by reference into the Terms and Conditions.


20. Contact

AML / Compliance (MLRO)compliance@shujaapay.com
Phone+255 746 259 442
General Supportsupport@shujaapay.com
CompanyShujaa Tech Company Limited, Zanzibar, United Republic of Tanzania

[ACTION REQUIRED: Provision and monitor a dedicated compliance@shujaapay.com mailbox owned by the MLRO function rather than an individual personal account.]


21. Document Control

VersionDateAuthorChanges
1.022 June 2026Mohamed Hafidh MohamedInitial release (approx. 500 words)
2.025 June 2026Compliance / MLROFull rewrite per legal audit: added risk-based approach, CDD/EDD, PEP & sanctions screening, transaction thresholds, STR filing & tipping-off prohibition, beneficial ownership, MLRO governance, training programme, record keeping, and Tanzanian legislative framework (pending legal certification)

© 2026 Shujaa Pay · Shujaa Tech Company Limited. All rights reserved.

This Policy supports our Terms and Conditions, Privacy Policy, and Security Policy. It does not constitute legal advice and is pending certification by qualified Tanzanian AML/CFT counsel. Statutory references and thresholds marked "[LEGAL REVIEW REQUIRED]" must be verified before this Policy is relied upon for regulatory purposes.

© 2026 Shujaa Pay · Shujaa Tech Company Limited