CFT/AML Policy
How Giva keeps criminal money off the platform: identity verification, sanctions screening, continuous monitoring and reporting to the NFIU.
Last updated: 8 August 2026
1. Our commitment
Giva is committed to preventing money laundering, terrorist financing and proliferation financing on our platform. We operate a risk-based compliance programme aligned with the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, the guidance of the Nigerian Financial Intelligence Unit (NFIU) and the requirements of our licensed partners.
You accept this policy when you create a Giva account. It applies to every user, every transaction and every feature in the app.
2. Governance
Our compliance programme is owned by senior management and run day to day by a designated Compliance Officer who is independent of commercial targets and has authority to freeze accounts, block transactions and file reports.
The programme is documented, reviewed at least annually, updated whenever the law or our risk profile changes, and supported by mandatory AML/CFT training for all staff at onboarding and every year thereafter.
3. Customer due diligence (KYC)
No user can transact on Giva anonymously. Before your account is enabled we verify your identity, and we re-verify when your risk profile or activity changes. Depending on your tier we collect and validate:
- your full legal name, date of birth and residential address;
- your BVN or NIN, validated against the issuing source;
- a government-issued photo ID and a liveness or selfie check to confirm you are the document holder;
- your phone number and email, confirmed by one-time code; and
- for higher limits or higher-risk activity, proof of address, source of funds and source of wealth.
Business or third-party use of a personal account is prohibited. We do not permit anonymous accounts, nominee accounts or accounts opened in false names.
4. Screening
Every user is screened at onboarding and on an ongoing basis against sanctions lists, terrorism watchlists, and politically exposed person (PEP) and adverse-media databases. Confirmed sanctions matches are blocked and reported. PEPs and other higher-risk users are only onboarded with senior management approval and are subject to enhanced due diligence.
Deposit and withdrawal addresses are screened using blockchain analytics. Funds linked to mixers, darknet markets, ransomware, sanctioned entities, scams or other illicit sources may be frozen and reported.
5. Transaction monitoring
We monitor activity continuously for behaviour that does not match a customer's stated profile. Typical red flags include:
- structuring — breaking large amounts into smaller transactions to stay under a threshold;
- rapid pass-through activity where funds arrive and leave immediately with no economic purpose;
- cash-outs to bank accounts belonging to multiple unrelated third parties;
- deposits from wallets flagged for fraud, scams or sanctions exposure;
- inconsistent device, IP or location patterns suggesting account takeover or account renting; and
- volumes inconsistent with a customer's declared income or occupation.
Alerts are investigated by our compliance team. We may request additional information or documentation, and we may hold a transaction while a review is completed.
6. Reporting and record keeping
Where a transaction meets the applicable thresholds or gives reasonable grounds for suspicion, we file Currency Transaction Reports and Suspicious Transaction Reports with the NFIU within the timeframes set by law.
Filing a report is confidential. We are prohibited by law from tipping off a customer that a report has been made, so we may be unable to explain why an account is restricted.
Identity records, transaction data, screening results and investigation files are retained for a minimum of five years after the relationship ends or the transaction is completed, whichever is later.
7. Prohibited activity
The following will result in immediate restriction and, where required, a report to the authorities:
- using Giva to launder proceeds of crime or to finance terrorism or proliferation;
- fraud of any kind, including romance and investment scams, phishing and impersonation;
- operating an unlicensed exchange, bureau de change or P2P desk through your account;
- renting, selling or sharing your Giva account or bank details with another person;
- submitting forged, altered or borrowed identity documents; and
- attempting to evade sanctions or our transaction limits.
8. What we ask of you
Keep your information accurate and up to date, respond promptly when our compliance team asks for documents, transact only for yourself, and never move funds on behalf of someone you do not know. Delays in responding to a compliance request are the most common reason an account stays restricted.
If you believe you have been targeted by a scam, contact us immediately at hello@usegiva.com — speed matters.
9. Contacting compliance
To report suspicious activity, respond to a review, or make a compliance enquiry, email hello@usegiva.com with your registered email address and the relevant transaction reference. Reports are treated confidentially.
This policy is reviewed at least annually and updated whenever regulation or our risk assessment changes.
Questions about this policy?
Our team reads every message. Reach us and we'll get back to you as quickly as we can.
hello@usegiva.com