Top

KYC Policy

1. Purpose

This policy establishes a clear framework for the onboarding and offboarding of customers using

KPIE GLOBAL LIMITED’s digital platforms and services. It ensures compliance with regulatory

requirements, enhances user experience, and promotes secure integration and disconnection

from our systems, especially in Open Banking contexts.

2. Scope

This policy applies to:

All individual and corporate customers of KPIE GLOBAL LIMITED.

All digital services, platforms, and APIs provided by the company.

Employees and third-party service providers involved in onboarding and offboarding

processes.

3. Onboarding Policy

3.1. Customer Identification & Verification (KYC)

Mandatory collection of customer identification details.

Verification via government-issued ID, BVN, TIN, CAC (for businesses), etc.

Use of biometric or two-factor authentication (2FA) where applicable.

3.2. Consent Management

Customers must explicitly grant consent for data sharing, especially for Open Banking

use.

Consent is logged and timestamped for audit purposes.

Revalidation of consent occurs every 180 days or upon significant service changes.

3.3. Account Creation & Credential Issuance

Unique customer ID and secure login credentials are issued.●

Customers are informed about security practices and responsibility for credentials.

3.4. Service Activation

Activation of APIs or features is staged and based on verified permissions.

Customers receive sandbox access for testing (if applicable) before going live.

3.5. Communication

Customers are provided with welcome documentation, terms of service, and API guides.

Support channels are made available for integration and configuration.

4. Offboarding Policy

4.1. Initiation

Offboarding can be initiated by the customer (via support ticket or written request) or by

KPIE GLOBAL LIMITED (due to inactivity, breach of terms, etc.).

4.2. Data Retention & Deletion

Customer data is retained in accordance with regulatory timelines (e.g., 5 years

post-termination).

After the retention period, data is securely deleted or anonymized.

4.3. Consent Withdrawal

Upon offboarding, any active data-sharing consent (e.g., Open Banking APIs) is

revoked.

Partner institutions are notified to halt data flows or service access.

4.4. API Deactivation & Access Removal

API keys are revoked or disabled immediately upon offboarding confirmation.●

Login credentials and system tokens are invalidated.

4.5. Final Communication

Customers are notified of successful offboarding and data retention policy.

A survey or feedback form may be provided to improve future experiences.

5. Roles and Responsibilities

Role Responsibility

Customer Success

Handles onboarding and first-level support.

Team

Compliance Officer IT & Security Team API Support Team Ensures regulatory and KYC compliance.

Manages access provisioning and

revocation.

Provides technical onboarding/offboarding.

6. Compliance & Review

This policy is reviewed annually or as required by regulatory changes.

Non-compliance may result in suspension or penalties as stated in the service

agreement.