Security and controls

Every action that moves money has a second pair of eyes.

Verified identity, dual control on the actions that matter, and a permission system enforced on the server. Built for the institution that answers to a board and a regulator, and for the collector who just wants their own money to tie out.

Illustrative example, not customer data

Controls

Six controls, built in from day one.

  • Ghana Card verification

    A member's identity is verified against the national ID through the National Identification Authority (NIA) when they are added.

  • Maker-checker dual control

    A second person must approve a payout, a reversal, a forfeit or an overpayment resolution before it executes. No single member of staff can do all four alone.

  • Audit log, actor typed

    Every sensitive action records who did it and whether they were staff, a member or the system.

  • Thirteen staff permissions

    Every request is checked against thirteen permissions on the server. The check runs where the record lives, so it holds however the request arrives.

  • Organisation verification

    An organisation moves through a verification lifecycle before it can collect from members.

  • Collect-only agent role

    A field agent can be scoped to collection alone. That role has no access to payouts, reversals or the ledger. The person on the round carries only the risk their job requires.

Dual control

Four actions no one person can take alone.

Each is requested by one person and approved by another. The request, the approval and the reason are on the audit log.

  • Payouts

    Releasing a member's money needs a second approval before the instruction goes to the provider.

  • Reversals

    Undoing a posted transaction needs a second approval. A reversal needs the same approval as the action it undoes.

  • Forfeits

    Forfeiting a balance needs a second approval, with the reason recorded against it.

Illustrative example, not customer data

Overpayment resolutions

Deciding what happens to an overpayment needs a second approval.

Custody

We hold the record. SusuPaa never holds your members' money.

SusuPaa is not a custodian. Your members' savings never sit with us, and there is no SusuPaa account they pass through.

The money moves on licensed rails

Collections and payouts run through the mobile money networks and the licensed payment providers named on our homepage. That means MTN, Telecel and AirtelTigo, over Moolre, Hubtel, Paystack and LibertePay.

Funds rest in your name

What a provider holds between collection and settlement is held in your organisation's own account. SusuPaa reads it and reconciles it against the ledger. It never takes possession of it.

What we actually hold is the ledger

Every cedi has a journal entry behind it. That entry is what we are responsible for. Its accuracy, its audit trail, and your ability to prove it to a board or a regulator.

SusuPaa ledger
MTN MoMo
Telecel Cash
AirtelTigo Money
Banks
Moolre
Hubtel
Paystack
LibertePay
WhatsApp & SMS
KYC verification
GCSCA / BoG returns
Your settlement account

Bring your board or your regulator questions. See the controls running against your own book. Thirty minutes, screen shared.