Skip to main content

Security & Compliance

Overview

The Access Bank Wallet-as-a-Service (WaaS) platform is built with enterprise-grade security and adheres to global financial industry standards.

This page outlines the security controls, compliance frameworks, and best practices that both Access Bank and integrating clients must follow.


Data Privacy & Protection

Personally Identifiable Information (PII)

The WaaS API handles sensitive customer data:

  • Bank Verification Numbers (BVN)
  • National Identification Numbers (NIN)
  • Phone numbers and email addresses
  • Biometric data (face verification)
  • Financial transaction data

Data Handling Requirements

  1. Minimize Data Collection - Only request data you need
  2. Encrypt in Transit - Always use HTTPS/TLS
  3. Secure Storage - Encrypt PII at rest
  4. Access Controls - Limit who can view sensitive data

Before collecting or processing customer data:

  • ✅ Obtain explicit consent
  • ✅ Explain data usage clearly
  • ✅ Provide privacy policy
  • ✅ Set dataConsent: true in validation requests

KYC & AML Compliance

Sanctions Screening

All customers are automatically screened against:

  • Global sanctions lists
  • Politically Exposed Persons (PEP) databases

Customer Due Diligence

You must collect and verify:

TierRequirements
Tier 1BVN, PEP Status
Tier 3BVN, NIN, Valid ID Document, Proof of Address

API Security Best Practices

Request Validation

Always validate:

  • ✅ Input data format and type
  • ✅ Required fields presence
  • ✅ Data length constraints
  • ✅ Allowed value ranges
Security Questions?

For security-related questions or to report vulnerabilities, contact the team at AFF@ACCESSBANKPLC.com