Ozow Hub
On this page9 sections

Bank APIs let a customer pay from their banking app without entering card or account details at your checkout. They are approved per merchant by the bank, not enabled on request, so there are requirements to meet before you can use them.

These requirements apply to:

  • Capitec PayCapitec Pay Capitec's own payment method. The payer gives a cellphone, account or ID number rather than card details, and approves the payment in the Capitec app, so no card number and no banking login is ever entered at checkout. It gets its own button rather than sitting inside the bank list, and it requires Customer Identity Verification.Capitec
  • Absa PayAbsa Pay Absa's own payment method, which the customer authorises in their Absa banking app. It gets its own button at checkout rather than sitting inside the bank list, and it requires Customer Identity Verification.Absa
  • Nedbank Direct EFTNedbank Direct EFT Nedbank's own payment method. Like the other bank APIs it gets its own button at checkout rather than sitting inside the bank list, and it requires Customer Identity Verification.Nedbank
  • PayShap RequestPayShap Request The request side of PayShap. Rather than the payer pushing money, the payee asks for it: the payer receives a request and approves it in their own banking app, and the funds move once they do. Enabled by Ozow on request rather than by default.payshap.co.za

Who cannot use Bank APIs

Bank APIs are not available to businesses that are:

  • Cash loans or shell banks
  • Adult entertainment
  • Trading without a valid licence where a government-issued licence is required, for example liquor, gambling, financial services, credit, authorised dealer in foreign exchange, third party payment provider or system operator
  • International gambling, betting and lotteries
  • Anonymous, where the identity of the business or its ownership is unknown
  • Of unknown nature, where the industry the business operates in is unknown
  • Unlawful in any way, including human trafficking, illegal narcotics, illegal weapons, counterfeit goods, unregistered trading in unprocessed precious metals and stones, and pyramid or Ponzi schemes
  • Sanctioned, where the merchant or a related party appears on the United Nations Security Council, European Union, His Majesty's Treasury, Office of Foreign Assets Control or Financial Intelligence Centre Targeted Financial Sanctions lists
  • Not South African

High-risk industries

A business in one of these industries is classified high risk:

  • Micro-lenders
  • Crypto assets and platforms
  • Investments, including derivatives, structured deposits and contracts for difference
  • Dealers in foreign exchange
  • Store of digital value, including vouchers, e-wallets, mobile money and e-money
  • Gambling and betting
  • Voucher providers
  • Remittance providers

Ozow tells you your classification during onboarding. A high-risk classification does not exclude you: it adds the obligations in the next two sections.

Tell Ozow when your risk category changes.

If your business activities change in a way that moves you into or out of a high-risk industry, the matching controls must be in place and Ozow must be told, in writing.

If you hold a TPPP or SO licence

Tell Ozow if you hold a Third Party Payment Provider or System Operator licence with PASA. Ozow engages with you separately about onboarding and activation in that case.

Obligations if you are classified high risk

You must run the verified ID flow: the customer's identity is verified through a KYC process before their first Bank API payment, and the ID or passport number cannot be edited afterwards.

  1. Verify the customer's identity when they open an account or you onboard them.
  2. Use the verified ID or passport number as the proxy identifier for payment initiation, and make it non-editable. If the bank gives you written consent to use an account number instead, verify that account number with the bank through an Account Verification Services transaction.
  3. Allow Bank APIs only once verification has succeeded. A customer whose verification is pending or has failed must not be able to use them.
  4. Credit only the paying customer's own account with funds received through a Bank API. Payments to third-party accounts are not permitted, so check that the account holder and the customer paying are the same person.
  5. Credit only the paying customer's own bank account when you pay out, for example winnings or refunds, so check that the account holder and the person requesting the payoutPayout Money sent from a merchant to a bank account. Unlike a refund, a payout is not tied to a payment anyone made you, so you can pay anyone with a bank account. Payouts draw on your float rather than on your incoming payments, and they are not self-service: they need approval from Ozow and testing in staging first. are the same.

Customer Identity Verification covers how to pass the verified ID to Ozow and what Ozow does with it at checkout.

Compliance requirements

Every merchant must be a South African entity and must provide CIPC documents, which Ozow vets. You must not be liquidated or deregistered, or in the process of either.

A merchant in a high-risk industry must also have the verified ID flow in place. The CIPC documents and the verified ID flow are the baseline. The industries below need what is listed alongside them as well.

Industry Additional documents
Crypto assets and platforms FSCA registration with the associated CASP licence. A signed Risk Management and Compliance Programme. Proof of registration as an Accountable Institution with the Financial Intelligence Centre, with the programme approved by senior management
Gambling and betting Registration as a bookmaker with the Gambling and Racing Board of each applicable province, and a copy of the gambling licence in the name of the entity being onboarded. A Risk Management and Compliance Programme approved by senior management
Remittance providers Proof of licence as an authorised dealer in foreign exchange with the SARB. Funds must flow into the merchant's own account
Financial services FSCA registration with the associated product approval. Where applicable, registration as an Accountable Institution with a Risk Management and Compliance Programme approved by senior management
Micro-lenders A copy of the National Credit Regulator licence
Third party payment providers and system operators A copy of the TPPP or SO licence. Further documents and verified ID flow requirements are set through a separate engagement
Digital wallet providers holding value Sponsorship by a bank for taking and holding third party deposits. A bank-issued letter confirming the account the value is held in. Funds must flow into that sponsored account
Voucher providers Closed-loop vouchers are low risk and do not need the verified ID flow. Open vouchers, redeemable across multiple channels and networks, are high risk and do
Forex FSCA registration. Licence as an authorised dealer in foreign exchange with the SARB. Registration as an Accountable Institution with the Financial Intelligence Centre, with a Risk Management and Compliance Programme approved by senior management
Investments FSCA registration
Everyone else Standard onboarding documents including CIPC documents. No verified ID flow required

Ongoing obligations

  • Keep the verified ID flow in place for as long as you use Bank APIs, if you are in a high-risk category.
  • Tell Ozow in writing about any change to your business activities, ownership or regulatory classification that changes your risk profile, including new business lines, services or products in a high-risk industry.
  • Do not share your credentials. Access to Bank APIs, including API keys, is limited to your business as the whitelisted merchant. You must not share them, and you must not redirectRedirect Sending the payer to the Ozow payment page to complete the payment, and returning them to your site afterwards. The alternative is embedding the checkout in your own page, where the payer never leaves it. or process transactions on behalf of another entity, unless Ozow has agreed to it in writing for Bank APIs specifically.

Licensing and documentation

  • Keep the licences and registrations your sector requires valid and current, for example FSCA, NCR, a gambling board or the SARB.
  • Tell Ozow immediately about any change to your licensing status, regulatory classification or business model that affects Bank API compliance.
  • Make sure neither you nor a related party appears on a global sanctions list.
  • Send Ozow a replacement licence when one expires.

Disputes and fraud

  • Cooperate with Ozow and the bank investigating a customer disputeDispute A customer challenging a completed card payment through their own bank. A successful dispute becomes a chargeback and reverses the funds. Distinct from a refund, which you initiate and control. or fraud claim.
  • Respond to a dispute or fraud complaint within two business days.
  • Make reasonable efforts to hold the underlying transaction while a suspected fraud is investigated, and refund where appropriate once it concludes.

Getting whitelisted

Bank APIs appear in the bank selection screen of the Ozow payment flow once the bank approves you. The process takes up to 10 working days.

  1. Onboard as a merchant. Submit your onboarding requirements and Ozow starts a formal onboarding process.
  2. Meet the compliance requirements. Ozow runs KYC and AML checks, including screening against global sanctions lists, and requests any further licences, agreements and documents your industry needs.
  3. Integrate. Build against the compliance and security requirements for the methods you want.
  4. Verification and approval. Ozow reviews your integration, then submits your whitelisting application to the bank.
  5. Go live. The bank confirms your whitelisting and your account is enabled to transact.

Approval is the bank's decision.

A bank approves Bank API merchants at its own discretion, and Ozow decides at its own discretion which merchants to submit. Non-compliance with any obligation on this page can result in Bank API access being suspended or disabled without notice.

Last updated