Skip to content
Built for Bank of Zambia–designated payment service providers

Compliance that runs itself. Built for Zambia’s PSPs.

Automate BoZ, FIC and NATC compliance end to end

Ontech PSP Compliance watches wallet and agent activity against BoZ limits and FIC rules, keeps sanctions lists current, drafts goAML reports from closed cases and chases every filing before it falls due. Your compliance team reviews and decides; the platform does the rest.

BoZ PSP rulebook mapped goAML schema-validated UN, FIC & OpenSanctions lists Four-eyes case review
11
Authorities covered
62
PSP obligations mapped
68
Filings on the calendar
6
PSP detection rules
248
Official source documents
Who it’s for

One platform for every kind of PSP

The obligations differ by licence; the platform switches on the ones that apply to yours.

E-money issuers & mobile money

Wallet limits checked per transaction by hand; agent activity reviewed after the fact

With PSP Compliance: KYC-tier limits across every wallet a customer holds, agent structuring and rapid cash-out rules, trust-account and unclaimed-funds duties on the calendar

Tier 1 & 2 limits

Money-transfer service providers

Cross-border transfers with missing originator details caught at audit, not at the time

With PSP Compliance: Wire-information checks from USD 1,000, sanctions screening of every counterparty, high-risk-country rules kept to the latest FATF plenary

FIC SI 53/2022

Payment system businesses

Returns to the DFS portal tracked in spreadsheets; a late one costs K500 a day

With PSP Compliance: Every daily, monthly and quarterly return on one calendar with reminders and escalation, figures assembled for the BoZ return

DFS portal returns

Payment system participants

Incident and outage notifications to BoZ and ZECHL depend on someone remembering

With PSP Compliance: Event-driven filings with their own clocks, operational-risk register and business-continuity obligations mapped

NFS & ZECHL rules
Automation

What runs without anyone pressing a button

Six jobs the platform does on its own, every day. People step in only where a decision is needed.

A filing calendar that chases itself

Every BoZ, FIC and NATC filing is projected onto one calendar — daily, monthly, quarterly and annual — with the due dates worked out for you.

  • Reminders 30, 14, 7, 3 and 1 day before, on the day and when overdue — plus 5 days out on FIC AML filings
  • Mark a filing done with its reference and its reminders stop
  • One morning digest email to the compliance team, not one email per item
  • Escalates to the manager at 7 days overdue and to the CRO at 14
Nothing missed

Transaction monitoring tuned for PSPs

6 PSP rules run over wallet, agent and cross-border activity and raise alerts with the evidence attached.

  • Limits checked across all of a customer’s wallets, not one wallet at a time
  • Agent structuring, fan-in, fan-out and rapid cash-out patterns
  • Thresholds you can tune for your institution
  • Plus seven general rules, machine-learning scoring and the FATF high-risk country lists
6 PSP rules

Sanctions screening that fails safe

UN lists refresh every 6 hours and OpenSanctions — OFAC, EU, UK and more — every 12.

  • Screen at onboarding, on transactions or the whole book — and again when the UN or FIC lists change
  • If the lists can’t be searched, screening stops — nobody is cleared by default
  • A confirmed match opens a freeze record with its 16-hour clock and drafts the NATC report
  • A screening report for the file: the lists matched, biography and close associates
1.5M list entries

Cases with four-eyes built in

Alerts become cases. An analyst recommends a disposition; a different reviewer closes it.

  • Four-eyes enforced by the system, not by policy alone
  • An STR disposition drafts the goAML report, validated against the FIC schema
  • The 3-working-day STR clock runs on the case, with Zambian public holidays counted
  • Currency transaction reports drafted daily for cash of USD 10,000 or more, single or linked
goAML-ready

Risk controls that react to breaches

When a key risk indicator breaches, Ontech PSP Compliance opens a risk and control self-assessment, recommends controls and notifies the owner.

  • 39 risk indicators, 44 control indicators and a 50-risk PSP register ready to use
  • Open breaches re-alerted once a day until resolved
  • Overdue assessments escalate automatically
  • Operational losses recorded against the Basel II event types
Board-ready

The rulebook, on file

248 Acts, statutory instruments, directives, circulars, rulebooks, guidelines and forms from 11 authorities, each with a SHA-256 checksum.

  • Linked to the obligations they create
  • Reporting catalogues for every authority a PSP answers to
  • Each obligation with its responsible officer, its filings and its source documents
  • Conditional duties switched on only when they apply
11 authorities
PSP sector response

The rulebook, mapped to what PSP Compliance does

What a BoZ-designated payment service provider owes each authority, the deadline or threshold that comes with it, and the automation behind it. All payment-system returns go to the Bank of Zambia through the DFS portal, mandatory since May 2021 — late or incorrect returns cost K500 per return per day.

Authority Obligation Deadline or threshold What Ontech PSP Compliance does
BoZ E-money transaction and balance limits (PSB Circular 01/2020) Tier 1: K20,000 a day, K100,000 balance · Tier 2: K100,000 a day, K500,000 balance Wallet-limit rule checks each customer against their KYC tier, across all their wallets
BoZ Daily, monthly and quarterly payment-system returns (DFS portal) Daily returns by close of the next business day; monthly and quarterly on the BoZ calendar On the filing calendar with reminders and escalation
BoZ Major operational or security incident report (e-money issuers and money-transfer providers) Within 48 hours Listed as an event-driven filing with its clock and source directive
ZECHL National Financial Switch participation: disruptive-event and fraud reports, chargebacks and recalls, annual participation fee Disruptive events within 24 hours; confirmed fraud immediately; chargebacks within 2 working days; K5,000 each January Mapped to obligations, controls and filings from the ZECHL rulebooks; the filings switch on when you join the NFS
FIC Suspicious transaction report, including attempted transactions Within 3 working days of forming the suspicion An STR disposition on the case drafts the goAML XML for review; the 3-working-day clock runs on the case
FIC Currency transaction report USD 10,000 or more, single or linked; within 3 working days CTR drafts built daily for each customer's cash at or above the threshold, single or linked; the agent-structuring rule flags splitting
FIC Wire transfer information Full originator and beneficiary details from USD 1,000 Incomplete-wire rule flags cross-border transfers missing either side
NATC Targeted financial sanctions: freeze assets and report the freeze Freeze without delay (NATC standard: 16 hours); report to NATC and the FIC UN lists refreshed every 6 hours and national listings loaded from NATC's circulars; a confirmed match opens a freeze record with its 16-hour clock and drafts the NATC report
ODPC Data controller registration and personal-data breach notification Register before processing; notify breaches within 24 hours On the obligations register with renewal and deadline reminders
CSA · ZICTA Cyber Security Act 2025 duties if designated critical information infrastructure; ECT online-supplier registration, USSD short codes, SIM recycling As prescribed by each instrument Mapped as obligations; the conditional cyber duties switch on when you are designated
CCPC Fee and price display; refund or re-perform failed services Refund or re-perform within 14 days Consumer-protection obligations mapped to controls and evidence
LCC · PAYZ · ZPPA Lusaka City Council levies, rates, fire certificate and signage; PAYZ DFS Code (voluntary); e-GP supplier registration for government tenders Annual or as applicable Renewals on the calendar; voluntary and tender duties off until you opt in
BoZ Daily payment-system returns
DFS portal return
By close of the next business day Scheduled every business day
BoZ Monthly payment-system returns
DFS portal return
About the 6th business day after month end (2026: 9 Feb, 10 Mar … 8 Dec; 11 Jan 2027) BoZ dates loaded; reminders from 5 days out
BoZ Quarterly payment-system returns
DFS portal return
10 Apr, 10 Jul, 8 Oct 2026; 11 Jan 2027 Reminders from 10 days out
BoZ Mobile money rewards return
DFS portal return
22 Apr, 22 Jul, 20 Oct 2026; 21 Jan 2027 On the calendar with the rewards and remittance rules
BoZ Quarterly agent report and BCP/DR test report
DFS portal return
With the quarterly returns Scheduled alongside the quarterly returns
BoZ Agent consumer-complaints report
DFS portal return
Monthly, with the monthly returns Scheduled monthly
BoZ Annual attestation of vital statistics
DFS portal return
31 January (template issued through the DFS portal) Reminders from 30 days out
BoZ Audited financial statements
DFS portal return
Within 3 months of financial year end Reminders from 60 days out
BoZ Annual cyber maturity self-assessment
DFS portal return
Annually On the calendar with its source guideline
Detection rules

Six rules written for how PSP money moves

Built on BoZ limits and FIC thresholds, around the channels that carry the most money-laundering risk in the sector: agents, cross-border transfers and cash.

Wallet limit breach

Daily value or balance above the customer’s KYC-tier limit, summed across every wallet they hold.

Tier 1: K20,000 a day · Tier 2: K100,000 a day

Agent structuring

Cash-in or cash-out split across several agents to stay under the limits.

3 or more agents, K20,000 or more within 24 hours

Fan-in

Many different senders paying one customer — the shape of a collection or mule account.

10 or more senders, K50,000 or more within 24 hours

Fan-out

One customer paying many different recipients — the shape of a distribution network.

10 or more recipients, K50,000 or more within 24 hours

Rapid cash-out

An electronic receipt taken out as cash at an agent soon after it lands. Higher severity when international or within 30 minutes.

Receipts of K5,000 or more, cashed out within 2 hours

Incomplete wire information

Cross-border transfers at or above the FIC threshold with originator or beneficiary details missing.

USD 1,000 or more

Thresholds shown are the defaults; each institution tunes its own. Alongside them run seven general rules — structuring, velocity, round-tripping, dormant-account reactivation and more — machine-learning scoring, and the FATF high-risk country lists, kept to the latest plenary.

How it works

From your transaction feed to the regulator

Five steps, the same every day, with a record of each one for the inspector.

1

Connect

Customers and their KYC tiers, wallets, agents and transactions from your e-money platform, through PSP Compliance’s ingest API or a file import.

2

Monitor

PSP rules and sanctions screening run continuously; every alert carries its evidence.

3

Investigate

Alerts become cases. An analyst recommends, a second reviewer decides.

4

Report

STR and CTR drafts for goAML, NATC freeze reports, and returns and notices on the calendar with reminders.

5

Prove

Risk and compliance changes, case decisions, screenings and filings recorded with who, when and the reference.

Self-assessment

How ready is your PSP?

Six quick questions on the duties inspectors look at first. Your answers stay in your browser — nothing is sent anywhere.

Security

Secure by default

What protects your data and your decisions, switched on from the first day.

Two-step sign-in

A password plus a one-time code sent by e-mail; accounts lock after 5 failed attempts.

Least privilege

Every API call checks who is signed in and what their role may do.

Four-eyes and a full trail

Every risk and compliance change, case action, screening and filing recorded with who and when.

Hardened pages

Cross-site request forgery protection on every form and a strict content security policy on every page.

Fails closed

If the sanctions lists cannot be searched, screening stops rather than clearing anyone.

A registered controller

Operated by Ontech Solutions, a registered data controller (ODPC, DP000394).

FAQ

Frequently asked questions

Everything you need to know about PSP Compliance.

General What is Ontech PSP Compliance?
Ontech PSP Compliance is a compliance platform for Bank of Zambia–designated payment service providers. It combines AML/CFT transaction monitoring, sanctions screening, case management and goAML reporting with a register of every BoZ, FIC, NATC and other obligation a PSP carries, and a filing calendar that reminds and escalates until each one is done.
Regulators Is it approved by the Bank of Zambia or the FIC?
No. Ontech Solutions is not affiliated with the Bank of Zambia, the FIC or any other authority. The platform maps their requirements and prepares the reports they expect; filing them, and the decisions in them, stay with your compliance officer.
Reporting Does it file with goAML for us?
It drafts STRs and CTRs from your cases and transactions and validates them against the FIC’s published goAML schema. You review each draft and upload it to the goAML portal, or submit it through the web service once the FIC has issued your reporting-entity credentials.
Integration How does our data get in?
Through the ingest API from your e-money or core platform, or by file import of customers and transactions. Monitoring and screening run on everything that arrives, from the first day.
Security How is our data protected?
Two-step sign-in, role-based access checked on every call, four-eyes on case decisions, a full audit trail, and screening that fails closed. Ontech Solutions is a registered data controller with the ODPC (DP000394).
Trial Can we try it first?
Yes. Request a demo and you get your own instance, under your company’s name, with a fictional PSP’s month of data — alerts, cases, reports and an assessed compliance register — to explore for a week.
Get in touch

Contact us

Questions about your obligations, a walkthrough for your team, or your own demo instance.

Let’s start a conversation

We’ll walk your compliance team through your BoZ filing calendar, your FIC reporting and the PSP detection rules — on your own numbers.

Phone+260 211 448 275 / *388#
LocationLusaka, Zambia
Business hoursMon – Fri: 08:00 – 17:00 CAT

Get your own demo instance

A fictional PSP’s month of data, under your company’s name, ready to explore for a week.

For anything else, e-mail info@ontech.co.zm.

Ready to put your compliance on autopilot?

Monitoring, screening, goAML reporting and every BoZ, FIC and NATC filing — in one platform.

Get started instantly: Call 388 SMS 388 USSD *388#