1. Purpose and scope
Cloove AI Technologies Ltd builds software. Some of that software connects businesses and individuals to financial services that licensed institutions provide. That position, sitting between a user and a regulated financial system, carries a real risk that someone will try to use Cloove's products to move criminal proceeds, fund terrorism, or fund the proliferation of weapons of mass destruction.
This policy sets out how Cloove manages that risk. It describes what Cloove does, what Cloove expects of the people who use its products, and where Cloove's role ends and the role of a licensed financial institution begins. It is written to be accurate rather than impressive.
It applies to:
- All Cloove employees, contractors, officers and directors.
- All Cloove products, including AI business assistants, Flow, business dashboards, merchant tools, payment and collection integrations, virtual account integrations, transfers, settlement and reconciliation, bill payments where supported, voice products and APIs.
- All businesses and individuals who use those products.
- All vendors, agents, resellers and partners acting for or through Cloove.
It does not govern the internal compliance programmes of the licensed institutions Cloove integrates with. Those institutions operate their own programmes under their own licences and supervision.
On zero tolerance
2. What Cloove is, and what it is not
Cloove AI Technologies Ltd is a technology company incorporated in Nigeria. It is not a bank, a microfinance bank, a payment service bank, a deposit-taking institution, a switching company, a money transmitter, or a licensed financial institution of any kind.
Where a Cloove product gives a user access to an account, a transfer, a collection, a settlement or a bill payment, the underlying financial service is provided by a licensed bank, microfinance bank, payment service provider or other regulated institution. Cloove provides the interface, the business logic around it, and the risk controls described in this policy. Cloove does not hold customer funds in its own right, does not execute payments under its own authority, and does not carry the statutory obligations that attach to a licensed institution.
This distinction runs through the whole of this policy and is set out control by control in section 4.
3. Regulatory context
Cloove operates in Nigeria and designs its controls with reference to the Nigerian financial crime framework, including the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, and the standards of the Financial Action Task Force as they are applied in Nigeria. Where Cloove's products connect to services regulated by the Central Bank of Nigeria, the requirements the Bank places on the providing institution shape how those products work.
Cloove does not hold a financial services licence and does not claim any regulatory registration or certification it has not obtained. Where a statement in this policy describes a control, it describes a control Cloove operates.
4. Who does what
This is the operative part of the policy. It states plainly which controls Cloove operates and which controls the licensed institution operates.
Cloove operates
- Verification of businesses registering for Cloove's business and merchant products, and of the individuals who control them
- Risk classification of businesses and users
- Screening against Cloove's prohibited and restricted business categories
- Monitoring of platform behaviour, including account, device and access signals, and activity inconsistent with a declared business profile
- Fraud prevention at the point of use, including authentication and confirmation steps
- Product-level limits and eligibility gating on financial features
- Restriction, suspension and termination of access to Cloove products
- Internal investigation of escalated matters, with a case record
- Escalation to regulated partners and, where applicable, to competent authorities
- Access controls and audit trails across Cloove systems
- Retention of the records Cloove holds
- Risk assessment of new products and material changes
The licensed institution operates
- Issuance and maintenance of accounts, including virtual accounts, under its licence
- The statutory customer identification requirements that attach to a financial account
- Execution, clearing and settlement of payments and transfers
- Transaction monitoring at the level of the regulated account and the payment rail
- Sanctions screening of financial transactions and of the parties to them
- Freezing, blocking or holding funds where required by law, court order or regulatory instruction
- Statutory suspicious transaction reporting and other regulatory reporting
- The customer relationship in respect of the regulated service itself, including its terms and its complaints route
Some responsibilities are shared, and where they are, this is how they work:
Onboarding
Cloove collects and validates business information and passes what the institution requires. Access depends on the institution's own process completing. Neither process substitutes for the other.
Suspicious activity
Cloove identifies and escalates. The institution assesses the matter against its own obligations and decides on any regulatory report. Cloove supports that assessment with the information it holds.
Restricting access
Cloove can restrict access to Cloove products. The institution can restrict or freeze the regulated account. Either may act independently, and either may act on information from the other.
Records
Each party retains the records it generates. Cloove does not rely on an institution to hold Cloove's records, and does not assume access to the institution's.
5. Definitions
- Money laundering
- Handling, converting, concealing or transferring property that represents the proceeds of crime, or helping someone else to do so.
- Terrorist financing
- Providing or collecting funds or other assets with the intention or knowledge that they will be used to carry out terrorist acts or to support a terrorist or terrorist organisation.
- Proliferation financing
- Providing funds or financial services used, in whole or in part, for the manufacture, acquisition, development, export, stockpiling or use of nuclear, chemical or biological weapons and their delivery systems, in breach of national law or international obligations.
- Customer due diligence
- Identifying a customer, verifying that identity from reliable information, understanding the purpose of the relationship, and keeping that understanding current.
- Beneficial owner
- The natural person or persons who ultimately own or control a business, or on whose behalf a transaction is conducted.
- Politically exposed person
- An individual who holds or has held a prominent public function, together with their close family members and known close associates.
- Regulated partner
- A licensed bank, microfinance bank, payment service provider or other regulated financial institution that provides financial services accessed through a Cloove product.
6. Governance and responsibilities
Overall responsibility for this policy sits with the Board of Cloove AI Technologies Ltd. The Board approves the policy, receives reporting on financial crime risk, and is accountable for ensuring the compliance function has the authority and resources to do its work.
Day-to-day responsibility sits with a named member of executive management, referred to in this policy as the compliance lead, who is responsible for:
- Maintaining this policy and the procedures beneath it.
- Maintaining Cloove's business-wide financial crime risk assessment.
- Operating the escalation and investigation process.
- Deciding on restrictions, suspensions and terminations arising from financial crime risk.
- Maintaining the records described in section 12 and delivering staff training.
- Managing Cloove's compliance-related communication with regulated partners.
Product, engineering and operations leadership are responsible for ensuring the controls this policy relies on are built and running, and for raising it when they are not. Every member of staff is responsible for reporting anything that looks like financial crime, promptly, and without discussing it with the user concerned.
7. Risk-based approach
Cloove applies its controls in proportion to risk. Higher-risk users, activities and products attract more scrutiny, tighter limits and more frequent review. Lower-risk ones attract less. This is not a way of doing less work. It is a way of putting the work where it changes an outcome.
Cloove maintains a written assessment of the money laundering, terrorist financing and proliferation financing risk arising from its business, covering its products, the ways they can be misused, the profile of the users they attract, the delivery channels involved, the geographies involved, and the controls in place against each risk. It is reviewed at least annually and whenever a material new product, channel, partner or user segment is introduced.
Business users are classified as low, medium, high or prohibited:
Low
Established activity in a category presenting no particular concern, ordinary transaction patterns, straightforward ownership. Standard onboarding and periodic review.
Medium
An elevated factor, such as a cash-intensive category, an unusual pattern, or incomplete information. Standard onboarding plus targeted questions and closer monitoring.
High
A restricted category, PEP exposure, opaque ownership, adverse information, activity inconsistent with the declared profile, or a prior compliance concern. Enhanced due diligence, tighter limits, senior sign-off.
Prohibited
A prohibited category, a sanctions match, or conduct that makes a relationship unacceptable. No access, or termination of an existing relationship.
Risk level is a property of the relationship, not a permanent label. It is reassessed when something changes: a shift in activity, a change in ownership, new adverse information, a fraud signal, a change in the products a user has access to, or the passage of time.
8. Due diligence
Before a business can access Cloove's payment, collection or settlement features, Cloove collects and records:
- The legal name of the business and any trading names.
- The nature of the business and what it actually sells or does.
- Registration details, where the business is registered.
- The business address and contact details.
- The identity of the individuals who own or control the business.
- The identity of the individual opening and operating the account.
- The intended use of the Cloove products requested.
Where Cloove's own verification cannot be completed to a satisfactory standard, the relevant features are not enabled.
Where the regulated partner comes in
Beneficial ownership. Cloove asks business users to identify the natural persons who ultimately own or control the business. Where ownership is layered or otherwise not transparent, Cloove asks for more, and treats an unwillingness or inability to explain ownership as a risk factor in its own right.
Enhanced due diligence applies to high-risk relationships, before financial features are enabled and again on review. It may involve additional information about the business, its customers and its expected activity; information about the source of funds and, where relevant, source of wealth; documentary corroboration; direct contact with the individuals concerned; senior sign-off; and tighter limits with a shorter review cycle.
Simplified due diligence. Where a product presents demonstrably low risk, for example a Cloove product with no money movement capability, Cloove may apply a proportionately lighter onboarding process. It is never applied where there is any indication of financial crime risk, and never to a user with transfer or payout functionality.
Politically exposed persons. PEP status is not a reason to refuse a relationship. It is a reason to look more carefully. Cloove asks business users to disclose whether any owner or controller is a politically exposed person, or a close family member or associate of one, and treats a positive answer as a factor that raises the risk classification and triggers enhanced due diligence and senior sign-off.
Individual users. For users of Flow and similar conversational products, Cloove collects the identifying information necessary to operate the product and to enable the regulated services requested. The identity requirements applicable to a financial account are set by the institution providing that account and by applicable regulation. Where they are not met, the corresponding features are unavailable.
9. Sanctions and proliferation financing
Cloove does not knowingly provide its products to any person or entity subject to applicable sanctions, and does not knowingly facilitate any activity that would breach them. Where Cloove becomes aware, from any source, that a user or a matter is connected to a sanctioned person or entity, Cloove will restrict access, investigate, and escalate to the relevant regulated partner and, where applicable, to the competent authority.
Sanctions screening of financial transactions and of the parties to them is performed by the licensed institutions that execute those transactions, under their own regulatory obligations.
Proliferation financing risk is assessed as part of Cloove's business-wide risk assessment and is considered in the classification of business activity. Categories connected to arms, munitions, dual-use goods and controlled technologies are prohibited or restricted, and any indication that a user is involved in the movement of such goods is escalated. Cloove's exposure arises primarily through the business categories it serves rather than through direct trade finance activity, and its controls are calibrated accordingly.
Adverse information. Where a business is classified as high risk, or where something in the relationship warrants it, Cloove carries out an adverse information check using publicly available sources, and records what it finds and what it concluded. This is a targeted check, not a continuous one.
10. Monitoring
Cloove monitors activity on its platform for behaviour that is inconsistent with what it knows about a user, or that indicates fraud, account compromise or misuse. The signals Cloove looks at include:
- Activity that does not fit the declared business category or expected volume.
- Sudden changes in the pattern, value or frequency of activity.
- Indicators of account takeover, including unusual device, location or access patterns.
- Patterns suggesting collusion between accounts, or one party operating several accounts.
- Repeated failed verification or authentication attempts.
- Structuring of activity to stay below a threshold.
- Reactivation of a long-dormant account followed by immediate money movement.
- Behaviour in the conversational channel suggesting coercion, impersonation or scripted third-party control of an account.
Monitoring is a mix of automated checks and human review, calibrated to risk. It is not a substitute for the transaction monitoring a regulated institution performs on the accounts and payment rails it operates, and it does not attempt to duplicate it.
11. Suspicious activity and escalation
Activity is treated as suspicious where there is no reasonable explanation for it consistent with what Cloove knows about the user, or where it fits a known pattern of financial crime. Suspicion does not require proof. It requires a reasonable basis for concern, and staff are trained to escalate on that basis rather than to wait for certainty.
Any member of staff who suspects financial crime escalates to the compliance lead immediately and does not discuss the matter with the user. The compliance lead records the matter, investigates, decides what action to take on the user's access to Cloove products, and records the reasoning and the outcome.
Escalation beyond Cloove
Cloove responds to lawful requests for information from competent authorities and courts, and cooperates with investigations, subject to applicable law.
No tipping off
12. Records and retention
Cloove retains:
- Business and individual identification information collected at onboarding, and the record of what was verified and how.
- Risk classification decisions and the basis for them.
- Enhanced due diligence records and sign-offs.
- Records of activity on Cloove's platform, including the metadata of transactions initiated through Cloove products.
- Escalation and investigation case records, including decisions and reasons.
- Restriction, suspension and termination decisions.
- Screening records, training records, and records of compliance communication with regulated partners.
These records are kept for at least five years from the end of the relationship or the date of the record, whichever is later, unless a longer period is required by law. Retention periods across Cloove are governed by a single internal retention schedule, which both this policy and the Privacy Notice refer to, so that the two cannot drift apart.
Records of the regulated financial service itself, including the account record and the underlying transaction record, are retained by the institution providing it, under that institution's own obligations.
13. Training, new products and partners
Training. Staff whose work touches onboarding, payments, support, product or platform risk receive financial crime awareness training appropriate to their role, on joining and periodically thereafter. Training covers how financial crime presents in Cloove's products, what to look for, how to escalate, and the prohibition on tipping off. Attendance is recorded.
New products. Before a new product, feature, channel or partner integration goes live, and before any material change to an existing one, the compliance lead assesses the financial crime risk it introduces, the controls needed to manage it, and whether those controls will exist at launch. The assessment is recorded and the outcome is a condition of launch. This applies with particular force to anything that adds or widens money movement, adds a new user segment or channel, or changes how a user is verified.
Partners and vendors. Before Cloove integrates with a financial institution or payment provider whose services will be accessed through a Cloove product, Cloove satisfies itself as to the partner's regulatory standing, the licence under which it provides the relevant service, and the division of compliance responsibility between the parties. That division is recorded in writing.
14. Prohibited and restricted activity
Cloove maintains a framework of business categories that are prohibited outright, and categories that may be accepted subject to enhanced review. In outline, Cloove prohibits any use of its products connected to fraud, money laundering, terrorist financing, proliferation financing, sanctioned persons and entities, narcotics, arms and munitions, human trafficking and exploitation, stolen goods, counterfeit products, pyramid and Ponzi schemes, unlicensed financial activity, illegal gambling, and other unlawful activity.
Cloove does not prohibit lawful industries simply because they are unfamiliar or because a category sounds risky. Categories that warrant care are treated as restricted, meaning available subject to additional review and conditions, rather than closed. The full list is at Prohibited and restricted businesses.
15. Review and governance of this policy
This policy is reviewed at least annually. It is reviewed earlier where there is a material change in applicable regulation, a material change in Cloove's products or partners, a material incident, or a material change in the risk profile of the business. Reviews are recorded with the date, the reviewer, what changed and who approved it.
The controls described here are reviewed at least annually by management. Cloove intends to commission independent review of its financial crime controls as the business and its transaction volumes grow.
Beneath this policy sit the operating procedures that implement it. Those are internal and are not published, because publishing them would tell the people this policy exists to stop exactly how the controls work.
16. Contact
Questions about this policy, or reports of suspected misuse of Cloove's products, should go to compliance@clooveai.com.
Reports may be made anonymously. Cloove does not retaliate against anyone who raises a concern in good faith, whether or not the concern turns out to be well founded.
Compliance query?
If you have a question about this policy, or need to report suspected misuse of Cloove's products, contact our compliance team. Reports can be made anonymously.
Contact compliancecompliance@clooveai.com

