cypra.
Terms Privacy AML Open bot
Legal

AML Policy

Vela Labs Ltd · Cypra · Last updated 7 April 2026

On this page
1. Purpose 2. Scope 3. Regulatory Positioning 4. Legal Framework 5. Definitions 5.1 Money Laundering 5.2 Terrorist Financing 5.3 AML/CFT 5.4 Financial Action Task Force (FATF) 5.5 Suspicious Activity Report (SAR) 5.6 Politically Exposed Person (PEP) 5.7 Structuring 6. Risk-Based Approach 7. Transaction Monitoring 8. Examples of Suspicious Transactions 9. Suspicious Activity Reporting 9.1 Internal Escalation 9.2 Compliance Officer Procedures 9.3 Tipping-Off Prohibition 10. Verification Grace Period 11. Anonymous Account Prohibition 12. Prohibited Persons & Sanctions Screening 13. Record Keeping 14. Data Protection 15. Personnel Training AML Compliance Officer 16. Policy Review

Company: VELA LABS LTD Product: Cypra Effective date: 7 April 2026 Company RC: 9463024


1. Purpose

This Anti-Money Laundering (AML) Policy establishes the framework by which VELA LABS LTD prevents, detects, and reports money laundering, terrorist financing, and other financial crimes in the operation of Cypra — a Telegram-based crypto-to-fiat and fiat-to-crypto payment service.

2. Scope

This policy applies to all employees, contractors, and systems involved in financial transactions, customer onboarding, and payment processing across all platforms operated by VELA LABS LTD.

3. Regulatory Positioning

VELA LABS LTD operates as a sender entity on a third-party payment protocol. In this capacity:

  • VELA LABS LTD does not directly hold or custody fiat currency on behalf of users. Fiat disbursements are executed by licensed liquidity providers within the payment network directly to users' bank accounts.
  • VELA LABS LTD does not operate a wallet or escrow for local fiat (including NGN and other supported currencies). Its role is to initiate and route payment orders on behalf of users.
  • VELA LABS LTD does not retain control over user funds beyond initiating transactions via third-party infrastructure.

This positioning does not exempt VELA LABS LTD from AML obligations. As the sender entity, VELA LABS LTD is responsible for the compliance posture of the users it onboards and the transactions it initiates.

4. Legal Framework

The AML procedures implemented by VELA LABS LTD are based on:

  • CBN AML/CFT Regulations 2022 (Risk-Based Supervision Framework)
  • NFIU compliance directives for fintech operators
  • Financial Action Task Force (FATF) Recommendations
  • Nigeria Data Protection Act 2023 (NDPA) — governing the collection, storage, and processing of customer personal data
  • Third-party sender compliance obligations under the payment protocol used by Cypra

5. Definitions

5.1 Money Laundering

Money laundering is the process of making funds obtained through criminal activity appear to originate from a legitimate source. It involves three stages:

5.1.1 Placement

The introduction of illegally obtained funds into the financial system.

5.1.2 Layering

Concealing the origin of those funds through a series of complex transactions designed to obscure the audit trail.

5.1.3 Integration

Reintroducing the laundered funds into the economy as apparently legitimate money.

5.2 Terrorist Financing

The process of providing funds or financial support to individuals or groups for the purpose of carrying out terrorist activities, regardless of whether the funds originate from legitimate or criminal sources.

5.3 AML/CFT

Anti-Money Laundering (AML) and Counter-Terrorism Financing (CFT) refer collectively to the set of laws, regulations, and procedures designed to prevent the use of financial systems for money laundering or the financing of terrorism.

5.4 Financial Action Task Force (FATF)

An intergovernmental organisation established in 1989 that sets international standards for combating money laundering and terrorist financing. Countries that inadequately implement FATF Recommendations are placed on the FATF grey or black list and subject to enhanced scrutiny.

5.5 Suspicious Activity Report (SAR)

A formal report submitted to the Nigerian Financial Intelligence Unit (NFIU) where a transaction or pattern of behaviour is suspected to involve money laundering or terrorist financing.

5.6 Politically Exposed Person (PEP)

An individual who holds or has held a prominent public position — such as a head of state, senior government official, judicial officer, or senior executive of a state-owned entity — and their immediate family members and close associates.

5.7 Structuring

The deliberate breaking up of transactions into smaller amounts to avoid detection thresholds or reporting obligations. Structuring is itself a criminal offence regardless of whether the underlying funds are legitimate.

6. Risk-Based Approach

VELA LABS LTD adopts a risk-based approach to AML compliance. The intensity of controls applied to any customer or transaction is proportionate to the assessed level of risk. Customers are categorised into risk tiers as defined in the separate KYC Policy.

7. Transaction Monitoring

All transactions are monitored in real time for unusual patterns. The following are treated as flags requiring internal review:

  • Structuring: multiple transactions just below tier limits within a short window
  • Velocity anomalies: transaction frequency inconsistent with the user's historical profile
  • Large or rapid transfers inconsistent with the user's stated purpose or profile
  • Transactions involving FATF-blacklisted or high-risk jurisdictions
  • Beneficiary accounts linked to flagged or sanctioned identities
  • Repeated transaction initiation and cancellation
  • Transactions with no discernible legitimate purpose
  • Use of accounts in the name of a third party not connected to the user
  • Sudden spikes in transaction volume inconsistent with the account's history
  • Transactions inconsistent with the user's occupation or economic profile

Accounts flagged by automated monitoring are reviewed before further transactions are permitted. Users are not informed of the specific flag that triggered review (tipping-off prohibition).

8. Examples of Suspicious Transactions

The following are examples of activity that may constitute a suspicious transaction. This list is illustrative, not exhaustive:

  • Transactions with no obvious legitimate business or personal purpose
  • Multiple small deposits made in quick succession that together equal a large sum (structuring)
  • A user whose transaction volume is dramatically inconsistent with their profile or stated occupation
  • Funds received from or sent to accounts in FATF-blacklisted countries
  • A user who is reluctant to provide information or provides information that is inconsistent or difficult to verify
  • Frequent transactions to multiple different beneficiary accounts without clear justification
  • A single transaction that is unusually large compared to all prior activity on the account
  • A user who initiates a transaction and cancels it immediately after a compliance prompt
  • Transactions where the beneficiary bank account details change frequently or do not match the stated recipient
  • A user sending funds to themselves across multiple accounts or platforms in a pattern suggesting layering
  • Activity that closely mirrors known typologies for crypto-to-fiat money laundering

9. Suspicious Activity Reporting

9.1 Internal Escalation

Any employee or automated system that identifies suspicious activity must escalate immediately to the AML Compliance Officer, including a description of the activity, the relevant transaction IDs, and the basis for suspicion.

9.2 Compliance Officer Procedures

On receipt of a suspicious activity report, the AML Compliance Officer will:

  • Evaluate the report and gather all relevant transaction data
  • Immediately restrict the relevant account pending investigation if suspicion is substantiated
  • Escalate to senior management with a recommendation for action
  • Determine whether a SAR must be filed with the NFIU
  • Monitor the account and any connected accounts under close review
  • Record all findings in the compliance log
  • Take any further action required by NFIU or relevant authorities

The Compliance Officer reviews internal reports on a daily basis and conducts a formal monthly review of all flagged accounts, monitoring patterns, and outcomes.

9.3 Tipping-Off Prohibition

Once a SAR has been filed or is under consideration, all staff are prohibited from disclosing to the subject of the report — or any unauthorised third party — that a report has been or may be filed.

10. Verification Grace Period

Where a transaction triggers a tier upgrade and additional verification is required:

  • Transactions are capped at the current tier limit until verification is complete
  • The user is clearly informed of what is required and why
  • If verification is not completed within a reasonable window, further transactions above the current tier limit are suspended
  • No funds already disbursed to a beneficiary will be clawed back solely due to pending verification, unless active suspicion of money laundering exists

11. Anonymous Account Prohibition

VELA LABS LTD does not permit anonymous or pseudonymous accounts. All users must be identifiable to at least Tier 1 standard before any transaction is processed. The platform does not and will not offer any feature designed to obscure user identity or circumvent identification requirements.

12. Prohibited Persons & Sanctions Screening

VELA LABS LTD will not onboard or continue serving any person or entity that:

  • Appears on OFAC, UN, EU, or CBN sanctions lists
  • Is identified as connected to terrorist financing or designated criminal enterprises
  • Is located in or transacting with FATF-blacklisted jurisdictions
  • Has provided materially false information at any stage of onboarding

Sanctions screening is performed at onboarding and on an ongoing basis. Where a prohibited person is identified post-onboarding, their account is immediately suspended and reported to the relevant authority.

13. Record Keeping

The following records are retained for a minimum of 5 years from the date of the last transaction or account closure, whichever is later:

  • All customer identification data collected at each tier
  • Full transaction history including amounts, counterparties, timestamps, and transaction IDs
  • Internal compliance flags, review outcomes, and escalation records
  • SAR filings and all supporting documentation

Records are stored in encrypted form on secured infrastructure. Access is restricted to authorised personnel on a strict need-to-know basis.

14. Data Protection

The collection, storage, and processing of all customer personal data is governed by the Nigeria Data Protection Act 2023 (NDPA). VELA LABS LTD:

  • Collects only the personal data strictly necessary for compliance and service delivery purposes
  • Stores all personal data securely with appropriate technical and organisational controls
  • Does not sell or share customer personal data with third parties except as required by law or regulation, or as necessary to deliver the Services through subprocessors
  • Retains personal data for a minimum of 5 years in accordance with AML record-keeping obligations, after which data is deleted or anonymised where permitted
  • Will notify affected users and the Nigeria Data Protection Commission (NDPC) in the event of a data breach, in accordance with NDPA requirements

For full detail on personal data processing, see the Privacy Policy.

15. Personnel Training

VELA LABS LTD ensures that all staff with any role in customer onboarding, transaction processing, or compliance are aware of their AML obligations. The training programme includes:

  • AML/CFT awareness training for all new staff upon onboarding
  • Annual refresher training for all existing staff
  • Role-specific training for staff in compliance, customer operations, and product functions
  • Updates communicated to all relevant staff whenever this policy is materially amended

Staff are informed that they may be personally liable for failure to report suspicion of money laundering or terrorist financing.

AML Compliance Officer

VELA LABS LTD designates its Director as the AML Compliance Officer. The AML Compliance Officer is responsible for:

  • Implementation and enforcement of AML and KYC policies
  • Monitoring transactions and reviewing flagged activity
  • Filing Suspicious Activity Reports (SARs) with the Nigerian Financial Intelligence Unit (NFIU) where required
  • Ensuring ongoing compliance with applicable regulations

At the current stage of the company, this role is performed solely by the Director. As the company scales, this function may be delegated or expanded.

16. Policy Review

This policy is reviewed annually and updated as required upon any material change in applicable law, regulatory guidance, product features, or transaction volume.


VELA LABS LTD RC – 9463024 Effective Date: 7 April 2026

cypra. © 2026 Cypra · by Vela Labs LTD
Terms of use Privacy policy AML policy