# Bank API onboarding and compliance

> What you must have in place to use Capitec Pay, Absa Pay, Nedbank Direct EFT and PayShap Request, from eligibility through whitelisting to your ongoing obligations.

Source: https://hub.ozow.com/integration-methods/apis/payin/bank-api-compliance/

Bank APIs let a customer pay from their banking app without entering card or account details at
your checkout. They are approved per merchant by the bank, not enabled on request, so there are
requirements to meet before you can use them.

These requirements apply to:

- Capitec Pay
- Absa Pay
- Nedbank Direct EFT
- PayShap Request

## Who cannot use Bank APIs

Bank APIs are not available to businesses that are:

- Cash loans or shell banks
- Adult entertainment
- Trading without a valid licence where a government-issued licence is required, for example liquor,
  gambling, financial services, credit, authorised dealer in foreign exchange, third party payment
  provider or system operator
- International gambling, betting and lotteries
- Anonymous, where the identity of the business or its ownership is unknown
- Of unknown nature, where the industry the business operates in is unknown
- Unlawful in any way, including human trafficking, illegal narcotics, illegal weapons, counterfeit
  goods, unregistered trading in unprocessed precious metals and stones, and pyramid or Ponzi schemes
- Sanctioned, where the merchant or a related party appears on the United Nations Security Council,
  European Union, His Majesty's Treasury, Office of Foreign Assets Control or Financial Intelligence
  Centre Targeted Financial Sanctions lists
- Not South African

## High-risk industries

A business in one of these industries is classified high risk:

- Micro-lenders
- Crypto assets and platforms
- Investments, including derivatives, structured deposits and contracts for difference
- Dealers in foreign exchange
- Store of digital value, including vouchers, e-wallets, mobile money and e-money
- Gambling and betting
- Voucher providers
- Remittance providers

Ozow tells you your classification during onboarding. A high-risk classification does not exclude
you: it adds the obligations in the next two sections.

> ⚠️ **Tell Ozow when your risk category changes.** If your business activities change in a way that
> moves you into or out of a high-risk industry, the matching controls must be in place and Ozow
> must be told, in writing.

## If you hold a TPPP or SO licence

Tell Ozow if you hold a Third Party Payment Provider or System Operator licence with PASA. Ozow
engages with you separately about onboarding and activation in that case.

## Obligations if you are classified high risk

You must run the **verified ID flow**: the customer's identity is verified through a KYC process
before their first Bank API payment, and the ID or passport number cannot be edited afterwards.

1. Verify the customer's identity when they open an account or you onboard them.
2. Use the verified ID or passport number as the proxy identifier for payment initiation, and make
   it non-editable. If the bank gives you written consent to use an account number instead, verify
   that account number with the bank through an Account Verification Services transaction.
3. Allow Bank APIs only once verification has succeeded. A customer whose verification is pending or
   has failed must not be able to use them.
4. Credit only the paying customer's own account with funds received through a Bank API. **Payments
   to third-party accounts are not permitted**, so check that the account holder and the customer
   paying are the same person.
5. Credit only the paying customer's own bank account when you pay out, for example winnings or
   refunds, so check that the account holder and the person requesting the payout are the same.

[Customer Identity Verification](https://hub.ozow.com/integration-methods/apis/payin/identity-verification.md) covers how to pass the verified
ID to Ozow and what Ozow does with it at checkout.

## Compliance requirements

**Every merchant must be a South African entity and must provide CIPC documents**, which Ozow vets.
You must not be liquidated or deregistered, or in the process of either.

**A merchant in a high-risk industry must also have the verified ID flow in place.** The CIPC
documents and the verified ID flow are the baseline. The industries below need what is listed
alongside them as well.

| Industry | Additional documents |
|---|---|
| Crypto assets and platforms | FSCA registration with the associated CASP licence. A signed Risk Management and Compliance Programme. Proof of registration as an Accountable Institution with the Financial Intelligence Centre, with the programme approved by senior management |
| Gambling and betting | Registration as a bookmaker with the Gambling and Racing Board of each applicable province, and a copy of the gambling licence in the name of the entity being onboarded. A Risk Management and Compliance Programme approved by senior management |
| Remittance providers | Proof of licence as an authorised dealer in foreign exchange with the SARB. Funds must flow into the merchant's own account |
| Financial services | FSCA registration with the associated product approval. Where applicable, registration as an Accountable Institution with a Risk Management and Compliance Programme approved by senior management |
| Micro-lenders | A copy of the National Credit Regulator licence |
| Third party payment providers and system operators | A copy of the TPPP or SO licence. Further documents and verified ID flow requirements are set through a separate engagement |
| Digital wallet providers holding value | Sponsorship by a bank for taking and holding third party deposits. A bank-issued letter confirming the account the value is held in. Funds must flow into that sponsored account |
| Voucher providers | Closed-loop vouchers are low risk and do not need the verified ID flow. Open vouchers, redeemable across multiple channels and networks, are high risk and do |
| Forex | FSCA registration. Licence as an authorised dealer in foreign exchange with the SARB. Registration as an Accountable Institution with the Financial Intelligence Centre, with a Risk Management and Compliance Programme approved by senior management |
| Investments | FSCA registration |
| Everyone else | Standard onboarding documents including CIPC documents. No verified ID flow required |

## Ongoing obligations

- **Keep the verified ID flow in place** for as long as you use Bank APIs, if you are in a high-risk
  category.
- **Tell Ozow in writing** about any change to your business activities, ownership or regulatory
  classification that changes your risk profile, including new business lines, services or products
  in a high-risk industry.
- **Do not share your credentials.** Access to Bank APIs, including API keys, is limited to your
  business as the whitelisted merchant. You must not share them, and you must not redirect or
  process transactions on behalf of another entity, unless Ozow has agreed to it in writing for Bank
  APIs specifically.

### Licensing and documentation

- Keep the licences and registrations your sector requires valid and current, for example FSCA, NCR,
  a gambling board or the SARB.
- Tell Ozow immediately about any change to your licensing status, regulatory classification or
  business model that affects Bank API compliance.
- Make sure neither you nor a related party appears on a global sanctions list.
- Send Ozow a replacement licence when one expires.

### Disputes and fraud

- Cooperate with Ozow and the bank investigating a customer dispute or fraud claim.
- Respond to a dispute or fraud complaint within **two business days**.
- Make reasonable efforts to hold the underlying transaction while a suspected fraud is
  investigated, and refund where appropriate once it concludes.

## Getting whitelisted

Bank APIs appear in the bank selection screen of the Ozow payment flow once the bank approves you.
**The process takes up to 10 working days.**

1. **Onboard as a merchant.** Submit your onboarding requirements and Ozow starts a formal
   onboarding process.
2. **Meet the compliance requirements.** Ozow runs KYC and AML checks, including screening against
   global sanctions lists, and requests any further licences, agreements and documents your industry
   needs.
3. **Integrate.** Build against the compliance and security requirements for the methods you want.
4. **Verification and approval.** Ozow reviews your integration, then submits your whitelisting
   application to the bank.
5. **Go live.** The bank confirms your whitelisting and your account is enabled to transact.

> ℹ️ **Approval is the bank's decision.** A bank approves Bank API merchants at its own discretion,
> and Ozow decides at its own discretion which merchants to submit. Non-compliance with any
> obligation on this page can result in Bank API access being suspended or disabled without notice.