
Shari’a
Bin ƙa’idoji
Compliance framework
The regimes that bind the group, who answers for them inside the group, and what is not certified.
Scope and application
This framework binds Parousia Group, the regional companies it holds — Parousia West Africa, Parousia East Africa, Parousia Europe, Parousia America and Parousia Middle East — and Echad Technologies, the group’s technical arm in Singapore. It applies to every person who acts for the group: directors, officers, employees, temporary staff, and anyone engaged to act on the group’s behalf.
It covers the six solutions the group operates — NetVox Intelligence, Global Technology Africa, Afrika Plaza, PAGEXPRESS, PAGPay and INTIC — and every market in which they are offered. Where local law is stricter than this framework, local law applies. Where this framework is stricter than local law, this framework applies: being lawful in one country is not a defence in the others where the group is present.
Three activities decide most of the group’s regulatory exposure, and the sections below are ordered on that exposure rather than alphabetically: telecommunications infrastructure and connectivity, which is licensed and which brings export control into play; payments, which brings financial supervision, anti-money-laundering duties and operational resilience rules into play; and the hosting of data for public institutions, which brings data protection and network security law into play.
Compliance governance
Compliance is a board matter. The ethics and compliance committee oversees this framework, the code of conduct, the anti-bribery controls and the reporting channel; the risk and security committee oversees operational, cyber and infrastructure risk across the group and the regional companies; the audit committee oversees financial reporting, internal control and the relationship with the external auditors. Each committee has a written mandate.
Within the executive, a compliance function is responsible for this framework: it maintains it, screens counterparties, records decisions, and answers requests from regulators, clients and auditors. It reports to the ethics and compliance committee, and it reaches that committee without passing through the chain of command it may have to report on. A compliance function that can only speak through the people it supervises is not a control.
A decision that would breach this framework is not taken lower down and reported afterwards: it is escalated before it is taken. An instruction to disregard this framework is not a valid instruction. No person is penalised for refusing one, for asking for it in writing, or for referring it upward.
International sanctions
The group does not do business with a person, entity, vessel or government subject to financial sanctions that bind it, and does not facilitate a transaction for a third party that would breach such a regime. Several regimes apply at once, and for different reasons: the nationality of the company involved, its place of business, the currency the transaction settles in, and the networks and servers the transaction crosses.
| List | Authority | Why it binds the group |
|---|---|---|
| United Nations Consolidated List | UN Security Council, under Chapter VII resolutions | Implemented by every state in which the group operates, including the Democratic Republic of the Congo |
| EU consolidated list of financial sanctions | Council of the European Union, by CFSP decisions and implementing regulations | Applies to dealings with EU persons, to funds within the Union, and to items and technology exported from it |
| UK consolidated list of financial sanctions targets | HM Treasury, Office of Financial Sanctions Implementation, under the Sanctions and Anti-Money Laundering Act 2018 | Parousia Europe is established in the United Kingdom, and UK sanctions bind UK companies and UK persons worldwide |
| US Specially Designated Nationals list and sectoral sanctions lists | US Department of the Treasury, Office of Foreign Assets Control (31 CFR Chapter V) | Parousia America is a US person, and US measures also reach transactions settled in US dollars and US-origin technology |
Counterparties — clients, suppliers, agents, distributors, and the people who ultimately own them — are screened against these lists before the relationship starts, and again when a list changes in a way that could affect them. A possible match suspends the relationship until it is resolved. A confirmed match is reported to the competent authority where the law requires it, and any funds or resources are dealt with as that law directs.
The group does not restructure a transaction, a route or a payment chain so that a sanctions regime ceases to apply to it. A request to do so is itself a fact to be reported under this framework.
Export control and dual-use items
A telecommunications operator exports controlled technology whether or not it thinks of itself as an exporter. Network equipment, cryptographic software, monitoring and network-management tools, functions capable of interception, and the technical documentation and source code that go with them, appear on dual-use control lists. This is not a peripheral regime for the group: it is the one its core activity touches most directly.
Regulation (EU) 2021/821 sets the Union’s dual-use regime. Its Annex I lists the controlled items, Category 5 covering telecommunications and information security; the regulation brought cyber-surveillance items expressly into scope and obliges an exporter who is aware that an item may be intended for use in connection with internal repression or serious violations of human rights or international humanitarian law to act on that awareness. Where an item, its software or its technology leaves the Union, the licence position is established before the transfer, not after it.
Two further regimes reach the group. The US Export Administration Regulations (15 CFR Parts 730–774) apply to US-origin items and to foreign items with US content wherever they are located, and to re-exports. The UK regime, under the Export Control Act 2002 and the Export Control Order 2008, applies to transfers from the United Kingdom and to UK persons. All three implement the control lists agreed in the Wassenaar Arrangement, which is why the item descriptions largely coincide and the licences do not.
Releasing controlled technology to a national of a third country is a transfer, even when nothing crosses a border. The group therefore treats granting access to a repository, a design document or a test environment that holds controlled technology as an export decision, taken before the access is granted rather than discovered in an audit afterwards.
Money laundering, terrorist financing and knowing the counterparty
The group operates a payment solution, PAGPay, and a logistics solution, PAGEXPRESS. Both move value, and both are used by counterparties the group does not choose one by one. Controls against money laundering and terrorist financing therefore apply across the group, and not only to the payment business.
Directive (EU) 2015/849, as amended by Directive (EU) 2018/843, is the reference framework in the European Union; it is replaced for the most part by Regulation (EU) 2024/1624 and Directive (EU) 2024/1640 as from 10 July 2027, with an Anti-Money Laundering Authority established by Regulation (EU) 2024/1620. In the Democratic Republic of the Congo, Loi n° 22/068 of 27 December 2022 governs money laundering, terrorist financing and proliferation financing, and replaced Loi n° 04/016 of 19 July 2004; the financial intelligence unit is CENAREF. Behind all of these sit the FATF Recommendations, which is where the standard these texts implement is actually written.
Where a payment or money transmission service requires an authorisation or a licence, the service is not offered in that market until the authorisation is held. The group does not operate under another party’s licence without a written arrangement that names it and that the regulator concerned would recognise.
| Counterparty | What is verified | When it is repeated |
|---|---|---|
| Corporate or institutional client | Legal existence, ownership and beneficial ownership, directors and signatories, sanctions screening, and the source of funds where the relationship or a transaction departs from what the business explains | On onboarding, on a material change of ownership or control, and on a periodic review whose interval is set by the risk rating |
| Individual customer of a payment service | Identity from a probative document, address, and the additional checks imposed by the licence conditions of that market | On onboarding, and whenever activity departs from the expected pattern |
| Supplier and subcontractor | Legal existence, beneficial ownership, sanctions screening, and the anti-bribery diligence set out in the anti-bribery policy | On engagement and on renewal or material amendment of the contract |
| Agent, intermediary, distributor or reseller | Everything required of a supplier, plus the written business rationale for the appointment and the basis on which remuneration is calculated | On appointment, and annually for as long as the appointment lasts |
| Politically exposed person, their family and close associates | Enhanced due diligence including source of wealth, and approval at a level above the person who owns the relationship | Throughout the relationship, and for as long after the person leaves office as the risk requires |
| Any counterparty connected with a jurisdiction the FATF identifies as high-risk or under increased monitoring | Enhanced due diligence, closer transaction monitoring, and any counter-measure the applicable law imposes | Continuously, and on each change to the FATF public statements |
Suspicious activity is reported to the financial intelligence unit competent for the entity concerned, within the time the applicable law sets. Where that law forbids telling the customer that a report has been made, the customer is not told, and nothing in this framework overrides that prohibition.
Competition
The group competes on what it builds and what it charges for it. It does not agree with a competitor on prices, on the division of markets, territories or customers, or on who will win a tender; it does not exchange current or forward-looking commercially sensitive information with a competitor, including inside a trade association, a consortium or a standards body; and where it holds a strong position in a market, it does not use that position to shut a rival out.
Which law applies follows where the conduct has effect, not where the meeting was held: Articles 101 and 102 of the Treaty on the Functioning of the European Union, Chapters I and II of the UK Competition Act 1998, sections 1 and 2 of the Sherman Act (15 U.S.C. §§ 1–2), Loi organique n° 18/020 of 9 July 2018 in the Democratic Republic of the Congo, the Competition Act 2010 in Kenya, the Federal Competition and Consumer Protection Act 2018 in Nigeria, and the COMESA Competition Regulations in the common market. A concentration that requires clearance is not completed before the clearances are held.
Two situations recur in this industry and are treated as high risk. The first is the consortium bid, where the group and a competitor bid together and necessarily see each other’s cost base: what may be shared is limited in writing before the first meeting. The second is access to infrastructure the group operates, where refusing access, delaying it, or pricing it so that a downstream competitor cannot survive can itself be an abuse. In both, the compliance function is involved before the conduct rather than after the complaint.
Data protection
How the group collects, uses, shares and retains personal data — the record of processing activities required by Article 30 of Regulation (EU) 2016/679, the categories of recipient, the retention periods, and the rights of a data subject and how to exercise them — is set out in the group’s privacy policy and is not repeated here. This section states only where the obligation comes from and how it meets the rest of this framework.
The applicable texts include Regulation (EU) 2016/679 in the European Union and, in the United Kingdom, the UK GDPR with the Data Protection Act 2018; in the Democratic Republic of the Congo, Ordonnance-loi n° 23/010 of 13 March 2023 bearing the Code du numérique, whose Book III, Title III governs personal data; the Data Protection Act 2019 in Kenya and the Nigeria Data Protection Act 2023; and the African Union Convention on Cyber Security and Personal Data Protection, in force since 8 June 2023.
The group’s governance principle is that data is hosted in the jurisdiction whose law governs it, and that where the client is a public institution, the institution holds the encryption keys. That is a compliance control and not only an architectural preference: it settles which authority can compel disclosure, and it limits what the group is able to produce when it is compelled.
A transfer of personal data out of a jurisdiction that restricts it rests on a legal basis named in the contract — an adequacy decision, standard contractual clauses, or the mechanism the local law provides — and never on the assumption that one group company may send data to another because they are related.
Information security and the standards the group works to
Security obligations arrive from three directions at once: the client contract, sector regulation, and the law that applies to the product itself. They are not interchangeable, and satisfying one does not answer another.
Directive (EU) 2022/2555, known as NIS 2, sets risk-management measures and incident reporting for entities in sectors that include electronic communications, cloud computing services, data centres and managed service providers. Where a group company is established in a member state, or offers such services in the Union and is caught by the directive’s jurisdiction rules, the consequences follow: accountability at management level, supply-chain security, an early warning within 24 hours of becoming aware of a significant incident, and a notification within 72 hours.
Regulation (EU) 2022/2554, known as DORA, applies to financial entities in the Union and reaches their ICT third-party service providers through the contractual content required by Article 30 — including audit and access rights, exit strategies, service levels and cooperation on incidents — while a provider designated as critical under Article 31 comes under direct oversight. The group sells payment and connectivity services to financial institutions, and treats those contractual requirements as the baseline for such contracts rather than as clauses to be negotiated away.
| Standard | What it covers | Status |
|---|---|---|
| ISO/IEC 27001 | Information security management system | Applied in engineering — no certificate issued |
| ISO/IEC 27701 | Privacy information management, extending 27001 | Applied in engineering — no certificate issued |
| ISO 22301 | Business continuity management | Applied in engineering — no certificate issued |
| ISO 9001 | Quality management | Applied in engineering — no certificate issued |
| PCI DSS v4 | Payment card data security, for the payment solution | Targeted — no attestation of compliance held |
| SOC 2 | Service organisation controls reported on by an independent auditor | Targeted — no report issued |
| WCAG 2.2 level AA | Digital accessibility | Applied and self-assessed; the accessibility statement gives the method and the known limitations |
Incidents are handled under a single process across the group, and notification is driven by law and contract rather than by preference: the 72-hour notification of a personal data breach under Article 33 of Regulation (EU) 2016/679, the NIS 2 timings above, the terms of the client contract, and the rules of the sector regulator where one applies. Where an incident must be notified, it is notified, including when notifying is commercially unwelcome.
Third parties and subcontractors
A control that stops at the group’s own perimeter does not work, because most of what a client experiences is delivered with someone else’s help: carriers, data centres, installers, resellers, payment partners, and the labour those parties subcontract in turn.
Third parties are assessed before engagement, at a depth set by what they will do and where they will do it: sanctions and ownership screening for all of them; anti-bribery diligence where they will face a public body, a customs authority or a regulator on the group’s behalf; security and data protection assessment where they will hold group or client data; and labour and human rights diligence where they supply site works, security services or logistics.
Contracts carry the obligations down rather than describing them. The clauses the group does not trade away are: compliance with sanctions and export control; the anti-bribery undertakings and the right to terminate for a breach of them; data protection terms meeting Article 28 of Regulation (EU) 2016/679 where the third party processes personal data on the group’s behalf; security requirements and incident notification with fixed timings; the right to audit or to accept an equivalent independent report; and prior written consent before a subcontractor is appointed.
A supplier who will not accept the sanctions, anti-bribery and data protection clauses is not engaged. The group would rather lose a supplier than hold a contract it cannot show to a regulator. The supplier code of conduct states the same obligations in the form a supplier signs up to; it is listed with its status on the group’s governance page.
Training and attestation
Everyone who acts for the group is trained on this framework on joining and at least once a year afterwards, in a language they work in. Roles with more exposure receive more: procurement, public sector sales and tendering, licensing and regulatory affairs, customs and logistics, payments and customer onboarding, and anyone who instructs or supervises an agent.
Training ends in an attestation: the person confirms that they have read the framework, that they are not aware of a breach they have not reported, and that they have declared any conflict of interest. An attestation that cannot honestly be given is itself a report, and is handled as one rather than treated as a failure to complete a form.
The group does not publish completion rates. Where a client, a regulator or an auditor asks for evidence that named personnel have been trained and have attested, the compliance function produces the records for those personnel.
Reporting a concern
Anyone — an employee, a supplier, a client, a candidate or a member of the public — may report a suspected breach of this framework. The route, the protections and the timings are set out in the group’s whistleblowing policy, which is a separate document and is not summarised here: a summary of a protection is exactly what a person relies on when the protection turns out to say something narrower.
Two points from that procedure govern this framework and are repeated here on purpose: a report may be made without passing through line management, and retaliation against a person who reports in good faith is itself a breach of this framework. Directive (EU) 2019/1937 sets the minimum protection in the European Union; the group applies the same protection in every country it operates in, including where local law does not require it.
Consequences of a breach
A breach of this framework is a disciplinary matter, up to and including dismissal, and it is handled the same way at every level of the group. For a third party, it is a ground for suspension of the relationship and for termination of the contract. Where the conduct is also an offence, the group reports it where the law requires and cooperates with the authority that investigates it.
Two arguments are not defences, and are written here so that no one has to have that conversation: that the breach was profitable for the group, and that it was instructed by someone more senior. A person who declines an instruction that would breach this framework is protected by it. A person who carries one out is not.
The group can lose a contract, a licence or a whole market for a compliance failure, and an individual can be prosecuted for the same conduct. Neither consequence substitutes for the other, and neither is settled by the fact that the other did not occur.
Tushen ƙa’ida
- Regulation (EU) 2021/821 — control of exports of dual-use items
- US Export Administration Regulations (15 CFR Parts 730–774)
- UK Export Control Act 2002 and Export Control Order 2008
- United Nations Security Council Consolidated List
- EU consolidated list of persons, groups and entities subject to financial sanctions
- UK Sanctions and Anti-Money Laundering Act 2018 (HM Treasury consolidated list)
- US sanctions administered by OFAC (31 CFR Chapter V)
- Directive (EU) 2015/849 as amended by Directive (EU) 2018/843
- Regulation (EU) 2024/1624, Directive (EU) 2024/1640 and Regulation (EU) 2024/1620
- FATF Recommendations (2012, as updated)
- Loi n° 22/068 du 27 décembre 2022 (DRC) — anti-money laundering, counter-terrorist financing and counter-proliferation financing
- Articles 101 and 102 of the Treaty on the Functioning of the European Union
- UK Competition Act 1998, Chapters I and II
- Sherman Antitrust Act (15 U.S.C. §§ 1–2)
- Loi organique n° 18/020 du 9 juillet 2018 (DRC) — price freedom and competition
- COMESA Competition Regulations
- Regulation (EU) 2016/679 (GDPR) and UK GDPR with the Data Protection Act 2018
- Ordonnance-loi n° 23/010 du 13 mars 2023 (DRC) — Code du numérique, Book III, Title III
- African Union Convention on Cyber Security and Personal Data Protection (Malabo, 2014)
- Directive (EU) 2022/2555 (NIS 2)
- Regulation (EU) 2022/2554 (DORA)
- Loi n° 20/017 du 25 novembre 2020 (DRC) — telecommunications and ICT
- Directive (EU) 2019/1937 — protection of persons who report breaches of Union law
Dukkan takardun shari’a
- Manufar sirriYadda Parousia Group ke tattarawa, amfani da kuma kare bayanan sirri.
- Manufar cookiesAbin da muke ajiyewa a na’urarka, da dalilin hakan.
- Sharuɗɗa da ƙa’idojiSharuɗɗan da ke tafiyar da amfaninka da wannan gidan yanar gizo.
- Sanarwar samun damaAlkawarinmu ga WCAG 2.2 mataki na AA, abin da muka yi, da yadda za a bayar da rahoton wata matsala.
- Bayyana raunin tsaroYadda ake bayar da rahoton raunin tsaro, abin da ƙungiyar ta yi alkawari, da kuma kariyar da masu bincike ke samu.
- Yaƙi da cin hanci da rashawaAbin da ƙungiyar ta haramta babu togiya, da kuma yadda ake tabbatar da wannan haramcin.
- Ɗaga muryaYadda ake bayar da rahoton abin da bai dace ba, abin da ke biyo baya, da kuma kariyar da doka ke ba ka.
- Bautar zamani da aikin tilasInda haɗarin yake a cikin sarkar samar da kayayyaki ta ƙungiyar, da kuma abin da ake yi a kansa.
- Sanarwar shari’aWanda ke buga wannan gidan yanar gizo, a ƙarƙashin wane suna na hukuma, da kuma inda za a aika sanarwa ta hukuma.
Tuntuɓi ƙungiyar contact@parousiagroup.com
