Tsallake zuwa babban abun ciki
Parousia Group

Shari’a

Bin ƙa’idoji

Compliance framework

The regimes that bind the group, who answers for them inside the group, and what is not certified.

Ana bitar shari’aAn rubuta wannan takarda kuma an buga ta a fili, sai dai har yanzu ba a amince da ita ba, ko daga hukumar gudanarwa ko daga sashen shari’a na ƙungiyar. Ba ta ƙarshe ba ce.
Harsunan da ke da ƙarfin dokaWannan takarda tana da ƙarfin doka a Turanci da Faransanci. An gabatar da ita a nan cikin Turanci ne domin har yanzu babu sigar da aka duba a wannan harshe — fassarar na’ura ta rubutun da ke haifar da sakamako na doka za ta fi wannan sanarwar muni.

Scope and application

This framework binds Parousia Group, the regional companies it holds — Parousia West Africa, Parousia East Africa, Parousia Europe, Parousia America and Parousia Middle East — and Echad Technologies, the group’s technical arm in Singapore. It applies to every person who acts for the group: directors, officers, employees, temporary staff, and anyone engaged to act on the group’s behalf.

It covers the six solutions the group operates — NetVox Intelligence, Global Technology Africa, Afrika Plaza, PAGEXPRESS, PAGPay and INTIC — and every market in which they are offered. Where local law is stricter than this framework, local law applies. Where this framework is stricter than local law, this framework applies: being lawful in one country is not a defence in the others where the group is present.

Three activities decide most of the group’s regulatory exposure, and the sections below are ordered on that exposure rather than alphabetically: telecommunications infrastructure and connectivity, which is licensed and which brings export control into play; payments, which brings financial supervision, anti-money-laundering duties and operational resilience rules into play; and the hosting of data for public institutions, which brings data protection and network security law into play.

Compliance governance

Compliance is a board matter. The ethics and compliance committee oversees this framework, the code of conduct, the anti-bribery controls and the reporting channel; the risk and security committee oversees operational, cyber and infrastructure risk across the group and the regional companies; the audit committee oversees financial reporting, internal control and the relationship with the external auditors. Each committee has a written mandate.

Within the executive, a compliance function is responsible for this framework: it maintains it, screens counterparties, records decisions, and answers requests from regulators, clients and auditors. It reports to the ethics and compliance committee, and it reaches that committee without passing through the chain of command it may have to report on. A compliance function that can only speak through the people it supervises is not a control.

A decision that would breach this framework is not taken lower down and reported afterwards: it is escalated before it is taken. An instruction to disregard this framework is not a valid instruction. No person is penalised for refusing one, for asking for it in writing, or for referring it upward.

The holder is not named hereNames and roles of officers are published once the board has approved them for disclosure, and not before. Until then, correspondence on this framework is addressed to contact@parousiagroup.com marked for the attention of the ethics and compliance committee, or by post to Parousia Group, 157, avenue du Livre, Kinshasa – Gombe, Democratic Republic of the Congo.

International sanctions

The group does not do business with a person, entity, vessel or government subject to financial sanctions that bind it, and does not facilitate a transaction for a third party that would breach such a regime. Several regimes apply at once, and for different reasons: the nationality of the company involved, its place of business, the currency the transaction settles in, and the networks and servers the transaction crosses.

Sanctions regimes screened before a counterparty is accepted
ListAuthorityWhy it binds the group
United Nations Consolidated ListUN Security Council, under Chapter VII resolutionsImplemented by every state in which the group operates, including the Democratic Republic of the Congo
EU consolidated list of financial sanctionsCouncil of the European Union, by CFSP decisions and implementing regulationsApplies to dealings with EU persons, to funds within the Union, and to items and technology exported from it
UK consolidated list of financial sanctions targetsHM Treasury, Office of Financial Sanctions Implementation, under the Sanctions and Anti-Money Laundering Act 2018Parousia Europe is established in the United Kingdom, and UK sanctions bind UK companies and UK persons worldwide
US Specially Designated Nationals list and sectoral sanctions listsUS Department of the Treasury, Office of Foreign Assets Control (31 CFR Chapter V)Parousia America is a US person, and US measures also reach transactions settled in US dollars and US-origin technology

Counterparties — clients, suppliers, agents, distributors, and the people who ultimately own them — are screened against these lists before the relationship starts, and again when a list changes in a way that could affect them. A possible match suspends the relationship until it is resolved. A confirmed match is reported to the competent authority where the law requires it, and any funds or resources are dealt with as that law directs.

The group does not restructure a transaction, a route or a payment chain so that a sanctions regime ceases to apply to it. A request to do so is itself a fact to be reported under this framework.

Export control and dual-use items

A telecommunications operator exports controlled technology whether or not it thinks of itself as an exporter. Network equipment, cryptographic software, monitoring and network-management tools, functions capable of interception, and the technical documentation and source code that go with them, appear on dual-use control lists. This is not a peripheral regime for the group: it is the one its core activity touches most directly.

Regulation (EU) 2021/821 sets the Union’s dual-use regime. Its Annex I lists the controlled items, Category 5 covering telecommunications and information security; the regulation brought cyber-surveillance items expressly into scope and obliges an exporter who is aware that an item may be intended for use in connection with internal repression or serious violations of human rights or international humanitarian law to act on that awareness. Where an item, its software or its technology leaves the Union, the licence position is established before the transfer, not after it.

Two further regimes reach the group. The US Export Administration Regulations (15 CFR Parts 730–774) apply to US-origin items and to foreign items with US content wherever they are located, and to re-exports. The UK regime, under the Export Control Act 2002 and the Export Control Order 2008, applies to transfers from the United Kingdom and to UK persons. All three implement the control lists agreed in the Wassenaar Arrangement, which is why the item descriptions largely coincide and the licences do not.

Releasing controlled technology to a national of a third country is a transfer, even when nothing crosses a border. The group therefore treats granting access to a repository, a design document or a test environment that holds controlled technology as an export decision, taken before the access is granted rather than discovered in an audit afterwards.

What the group does not supplyThe group does not supply mass-surveillance, bulk traffic-analysis or population-monitoring capability. Lawful interception assistance is provided only where it is required by the law of the country concerned, on an individualised and judicially or independently supervised basis, and within the terms of the operating licence. Where a licence would be required for a transfer, the absence of that licence ends the discussion; where a licence could be obtained but the intended use is the surveillance of a population, the group declines the business.

Money laundering, terrorist financing and knowing the counterparty

The group operates a payment solution, PAGPay, and a logistics solution, PAGEXPRESS. Both move value, and both are used by counterparties the group does not choose one by one. Controls against money laundering and terrorist financing therefore apply across the group, and not only to the payment business.

Directive (EU) 2015/849, as amended by Directive (EU) 2018/843, is the reference framework in the European Union; it is replaced for the most part by Regulation (EU) 2024/1624 and Directive (EU) 2024/1640 as from 10 July 2027, with an Anti-Money Laundering Authority established by Regulation (EU) 2024/1620. In the Democratic Republic of the Congo, Loi n° 22/068 of 27 December 2022 governs money laundering, terrorist financing and proliferation financing, and replaced Loi n° 04/016 of 19 July 2004; the financial intelligence unit is CENAREF. Behind all of these sit the FATF Recommendations, which is where the standard these texts implement is actually written.

Where a payment or money transmission service requires an authorisation or a licence, the service is not offered in that market until the authorisation is held. The group does not operate under another party’s licence without a written arrangement that names it and that the regulator concerned would recognise.

Due diligence carried out before a counterparty is accepted, and when it is repeated
CounterpartyWhat is verifiedWhen it is repeated
Corporate or institutional clientLegal existence, ownership and beneficial ownership, directors and signatories, sanctions screening, and the source of funds where the relationship or a transaction departs from what the business explainsOn onboarding, on a material change of ownership or control, and on a periodic review whose interval is set by the risk rating
Individual customer of a payment serviceIdentity from a probative document, address, and the additional checks imposed by the licence conditions of that marketOn onboarding, and whenever activity departs from the expected pattern
Supplier and subcontractorLegal existence, beneficial ownership, sanctions screening, and the anti-bribery diligence set out in the anti-bribery policyOn engagement and on renewal or material amendment of the contract
Agent, intermediary, distributor or resellerEverything required of a supplier, plus the written business rationale for the appointment and the basis on which remuneration is calculatedOn appointment, and annually for as long as the appointment lasts
Politically exposed person, their family and close associatesEnhanced due diligence including source of wealth, and approval at a level above the person who owns the relationshipThroughout the relationship, and for as long after the person leaves office as the risk requires
Any counterparty connected with a jurisdiction the FATF identifies as high-risk or under increased monitoringEnhanced due diligence, closer transaction monitoring, and any counter-measure the applicable law imposesContinuously, and on each change to the FATF public statements

Suspicious activity is reported to the financial intelligence unit competent for the entity concerned, within the time the applicable law sets. Where that law forbids telling the customer that a report has been made, the customer is not told, and nothing in this framework overrides that prohibition.

Competition

The group competes on what it builds and what it charges for it. It does not agree with a competitor on prices, on the division of markets, territories or customers, or on who will win a tender; it does not exchange current or forward-looking commercially sensitive information with a competitor, including inside a trade association, a consortium or a standards body; and where it holds a strong position in a market, it does not use that position to shut a rival out.

Which law applies follows where the conduct has effect, not where the meeting was held: Articles 101 and 102 of the Treaty on the Functioning of the European Union, Chapters I and II of the UK Competition Act 1998, sections 1 and 2 of the Sherman Act (15 U.S.C. §§ 1–2), Loi organique n° 18/020 of 9 July 2018 in the Democratic Republic of the Congo, the Competition Act 2010 in Kenya, the Federal Competition and Consumer Protection Act 2018 in Nigeria, and the COMESA Competition Regulations in the common market. A concentration that requires clearance is not completed before the clearances are held.

Two situations recur in this industry and are treated as high risk. The first is the consortium bid, where the group and a competitor bid together and necessarily see each other’s cost base: what may be shared is limited in writing before the first meeting. The second is access to infrastructure the group operates, where refusing access, delaying it, or pricing it so that a downstream competitor cannot survive can itself be an abuse. In both, the compliance function is involved before the conduct rather than after the complaint.

Data protection

How the group collects, uses, shares and retains personal data — the record of processing activities required by Article 30 of Regulation (EU) 2016/679, the categories of recipient, the retention periods, and the rights of a data subject and how to exercise them — is set out in the group’s privacy policy and is not repeated here. This section states only where the obligation comes from and how it meets the rest of this framework.

The applicable texts include Regulation (EU) 2016/679 in the European Union and, in the United Kingdom, the UK GDPR with the Data Protection Act 2018; in the Democratic Republic of the Congo, Ordonnance-loi n° 23/010 of 13 March 2023 bearing the Code du numérique, whose Book III, Title III governs personal data; the Data Protection Act 2019 in Kenya and the Nigeria Data Protection Act 2023; and the African Union Convention on Cyber Security and Personal Data Protection, in force since 8 June 2023.

The group’s governance principle is that data is hosted in the jurisdiction whose law governs it, and that where the client is a public institution, the institution holds the encryption keys. That is a compliance control and not only an architectural preference: it settles which authority can compel disclosure, and it limits what the group is able to produce when it is compelled.

A transfer of personal data out of a jurisdiction that restricts it rests on a legal basis named in the contract — an adequacy decision, standard contractual clauses, or the mechanism the local law provides — and never on the assumption that one group company may send data to another because they are related.

Information security and the standards the group works to

Security obligations arrive from three directions at once: the client contract, sector regulation, and the law that applies to the product itself. They are not interchangeable, and satisfying one does not answer another.

Directive (EU) 2022/2555, known as NIS 2, sets risk-management measures and incident reporting for entities in sectors that include electronic communications, cloud computing services, data centres and managed service providers. Where a group company is established in a member state, or offers such services in the Union and is caught by the directive’s jurisdiction rules, the consequences follow: accountability at management level, supply-chain security, an early warning within 24 hours of becoming aware of a significant incident, and a notification within 72 hours.

Regulation (EU) 2022/2554, known as DORA, applies to financial entities in the Union and reaches their ICT third-party service providers through the contractual content required by Article 30 — including audit and access rights, exit strategies, service levels and cooperation on incidents — while a provider designated as critical under Article 31 comes under direct oversight. The group sells payment and connectivity services to financial institutions, and treats those contractual requirements as the baseline for such contracts rather than as clauses to be negotiated away.

Standards the group engineers to, and their certification status
StandardWhat it coversStatus
ISO/IEC 27001Information security management systemApplied in engineering — no certificate issued
ISO/IEC 27701Privacy information management, extending 27001Applied in engineering — no certificate issued
ISO 22301Business continuity managementApplied in engineering — no certificate issued
ISO 9001Quality managementApplied in engineering — no certificate issued
PCI DSS v4Payment card data security, for the payment solutionTargeted — no attestation of compliance held
SOC 2Service organisation controls reported on by an independent auditorTargeted — no report issued
WCAG 2.2 level AADigital accessibilityApplied and self-assessed; the accessibility statement gives the method and the known limitations
No certification is claimedNo certification body has issued a certificate to any group entity against any of the standards above, and no auditor has issued a SOC report on any group service. Where this document says the group engineers to a standard, it means the controls are designed against the text of that standard and the design can be shown — not that a certificate exists. On the day one is issued, its number, its scope and the issuing body will be published, and not before.

Incidents are handled under a single process across the group, and notification is driven by law and contract rather than by preference: the 72-hour notification of a personal data breach under Article 33 of Regulation (EU) 2016/679, the NIS 2 timings above, the terms of the client contract, and the rules of the sector regulator where one applies. Where an incident must be notified, it is notified, including when notifying is commercially unwelcome.

Third parties and subcontractors

A control that stops at the group’s own perimeter does not work, because most of what a client experiences is delivered with someone else’s help: carriers, data centres, installers, resellers, payment partners, and the labour those parties subcontract in turn.

Third parties are assessed before engagement, at a depth set by what they will do and where they will do it: sanctions and ownership screening for all of them; anti-bribery diligence where they will face a public body, a customs authority or a regulator on the group’s behalf; security and data protection assessment where they will hold group or client data; and labour and human rights diligence where they supply site works, security services or logistics.

Contracts carry the obligations down rather than describing them. The clauses the group does not trade away are: compliance with sanctions and export control; the anti-bribery undertakings and the right to terminate for a breach of them; data protection terms meeting Article 28 of Regulation (EU) 2016/679 where the third party processes personal data on the group’s behalf; security requirements and incident notification with fixed timings; the right to audit or to accept an equivalent independent report; and prior written consent before a subcontractor is appointed.

A supplier who will not accept the sanctions, anti-bribery and data protection clauses is not engaged. The group would rather lose a supplier than hold a contract it cannot show to a regulator. The supplier code of conduct states the same obligations in the form a supplier signs up to; it is listed with its status on the group’s governance page.

Training and attestation

Everyone who acts for the group is trained on this framework on joining and at least once a year afterwards, in a language they work in. Roles with more exposure receive more: procurement, public sector sales and tendering, licensing and regulatory affairs, customs and logistics, payments and customer onboarding, and anyone who instructs or supervises an agent.

Training ends in an attestation: the person confirms that they have read the framework, that they are not aware of a breach they have not reported, and that they have declared any conflict of interest. An attestation that cannot honestly be given is itself a report, and is handled as one rather than treated as a failure to complete a form.

The group does not publish completion rates. Where a client, a regulator or an auditor asks for evidence that named personnel have been trained and have attested, the compliance function produces the records for those personnel.

Reporting a concern

Anyone — an employee, a supplier, a client, a candidate or a member of the public — may report a suspected breach of this framework. The route, the protections and the timings are set out in the group’s whistleblowing policy, which is a separate document and is not summarised here: a summary of a protection is exactly what a person relies on when the protection turns out to say something narrower.

Two points from that procedure govern this framework and are repeated here on purpose: a report may be made without passing through line management, and retaliation against a person who reports in good faith is itself a breach of this framework. Directive (EU) 2019/1937 sets the minimum protection in the European Union; the group applies the same protection in every country it operates in, including where local law does not require it.

Where to writeReports and questions on this framework: contact@parousiagroup.com, marked for the attention of the ethics and compliance committee, or by post to Parousia Group, 157, avenue du Livre, Kinshasa – Gombe, Democratic Republic of the Congo; telephone +243 892 844 000. A report may be made in any of the languages this site is published in, and will not be set aside for having been written in the wrong one.

Consequences of a breach

A breach of this framework is a disciplinary matter, up to and including dismissal, and it is handled the same way at every level of the group. For a third party, it is a ground for suspension of the relationship and for termination of the contract. Where the conduct is also an offence, the group reports it where the law requires and cooperates with the authority that investigates it.

Two arguments are not defences, and are written here so that no one has to have that conversation: that the breach was profitable for the group, and that it was instructed by someone more senior. A person who declines an instruction that would breach this framework is protected by it. A person who carries one out is not.

The group can lose a contract, a licence or a whole market for a compliance failure, and an individual can be prosecuted for the same conduct. Neither consequence substitutes for the other, and neither is settled by the fact that the other did not occur.

Tushen ƙa’ida

  • Regulation (EU) 2021/821 — control of exports of dual-use items
  • US Export Administration Regulations (15 CFR Parts 730–774)
  • UK Export Control Act 2002 and Export Control Order 2008
  • United Nations Security Council Consolidated List
  • EU consolidated list of persons, groups and entities subject to financial sanctions
  • UK Sanctions and Anti-Money Laundering Act 2018 (HM Treasury consolidated list)
  • US sanctions administered by OFAC (31 CFR Chapter V)
  • Directive (EU) 2015/849 as amended by Directive (EU) 2018/843
  • Regulation (EU) 2024/1624, Directive (EU) 2024/1640 and Regulation (EU) 2024/1620
  • FATF Recommendations (2012, as updated)
  • Loi n° 22/068 du 27 décembre 2022 (DRC) — anti-money laundering, counter-terrorist financing and counter-proliferation financing
  • Articles 101 and 102 of the Treaty on the Functioning of the European Union
  • UK Competition Act 1998, Chapters I and II
  • Sherman Antitrust Act (15 U.S.C. §§ 1–2)
  • Loi organique n° 18/020 du 9 juillet 2018 (DRC) — price freedom and competition
  • COMESA Competition Regulations
  • Regulation (EU) 2016/679 (GDPR) and UK GDPR with the Data Protection Act 2018
  • Ordonnance-loi n° 23/010 du 13 mars 2023 (DRC) — Code du numérique, Book III, Title III
  • African Union Convention on Cyber Security and Personal Data Protection (Malabo, 2014)
  • Directive (EU) 2022/2555 (NIS 2)
  • Regulation (EU) 2022/2554 (DORA)
  • Loi n° 20/017 du 25 novembre 2020 (DRC) — telecommunications and ICT
  • Directive (EU) 2019/1937 — protection of persons who report breaches of Union law