Zanda Comply is the KYC, KYB, AML and sanctions-screening platform built for Zambian financial institutions — where every decision is explainable, every action is on a tamper-evident audit chain, and protected data physically cannot leave the country without an approved, expiring authorisation.
Most institutions run onboarding in one tool, screening in another, monitoring in a spreadsheet and filings by hand. Zanda Comply runs the entire lifecycle in one place — so evidence never falls between the cracks.
A guided applicant journey from link to decision — no app install required.
Verify the business and the people behind it — including the ones hiding three shell companies deep.
Real UN Consolidated and OFAC SDN data with fuzzy + phonetic matching that catches transliterations and near-misses.
An idempotent, batch-friendly ingestion API feeding rule families tuned for real laundering patterns.
Eight specialised queues with assignment, notes, evidence timelines and deadlines that enforce themselves.
Onboarding isn't a moment — it's a subscription. Customers are rescreened continuously against every watchlist update.
STRs and CTRs generated from case evidence, built as validated goAML XML — the format the FIC actually ingests.
Zambia's Data Protection Act, operationalised — not filed away.
Eight quiz-based modules that onboard your team on the full workflow — and double as your auditable training register.
Send a link. Get a defensible decision. Stay covered for the whole relationship — with a webhook into your core system at every milestone.
Send a secure verification link — works on any phone, in English, Bemba or Nyanja, on 2G-era bandwidth.
Documents with live quality checks, selfie with active-challenge liveness, consent recorded to the ledger.
Registry checks and face match run in an async pipeline while the applicant carries on with their day.
Sanctions, PEP and adverse-media screening with fuzzy + phonetic matching across real watchlist data.
An explainable risk decision — facts, rule trace and versions stored — approved automatically or routed to a case.
Perpetual KYC and transaction monitoring keep watching. Alerts become cases; cases become filings.
These aren't features bolted on for a sales deck. They're architectural decisions most vendors can't retrofit — because they have to be true from the first line of code.
Everyone promises your data stays in-country. Zanda Comply enforces it at runtime: personal, biometric and financial-crime data is blocked from leaving Zambia unless a scoped, expiring, maker-checker-approved transfer authorisation exists. Every attempt — allowed or blocked — is recorded. There's even a live attestation endpoint so you can prove residency to a regulator on demand, not once a year in a PDF.
Every action links cryptographically to the one before it — including timestamps, actor IP and sequence — so history cannot be quietly rewritten by anyone, including us. An integrity-verification endpoint re-checks the whole chain on demand. When an examiner asks "how do I know this log is complete?", you have a mathematical answer.
Every decision stores the facts it saw, the rules it fired, the ruleset version and the provider versions that produced the inputs. Six months later you can reconstruct exactly why a customer was approved — which is precisely the question a regulator, an auditor, or a court will ask.
Case dispositions, regulatory filings, data-transfer authorisations — none of them happen on one person's say-so. Segregation of duties isn't a policy document here; it's a constraint the software physically enforces.
All outbound traffic passes one hardened gate: destinations are resolved and SSRF-checked, region-classified against policy, and logged to the residency ledger. Sensitive fields are encrypted at rest, and searchable identifiers are keyed-hashed so they can't be brute-forced out of the database.
Because KYC, KYB, screening, transactions, cases and goAML filings live in one system, an alert carries its full history: who the customer is, how they were verified, what they've done since. No swivel-chair investigations across four tools — and no evidence gaps between them.
| Typical compliance stack | Zanda Comply | |
|---|---|---|
| Data residency | A paragraph in the contract; data actually lives in a US or EU cloud | Runtime enforcement that fails closed, with every attempt logged and a live attestation endpoint |
| Audit trail | A log table an administrator can edit | Append-only hash chain — tamper-evident, verifiable via API |
| Risk decisions | An opaque score from a model you can't inspect | Facts, rule trace, ruleset & provider versions stored with every decision |
| Screening at scale | Full watchlist scan per check — slows as lists grow | Trigram + phonetic candidate blocking — fast at any list size |
| Regulatory filing | Export a CSV, re-type it into goAML | Native, schema-validated goAML XML with a maker-checker filing lifecycle |
| Four-eyes control | An optional workflow add-on, often switched off | Built into dispositions, filings and transfer authorisations |
| Applicant experience | English-only, heavyweight, assumes fast data | English, Bemba & Nyanja; compressed low-bandwidth capture; any phone browser |
| Ongoing diligence | Annual re-KYC projects, done manually | Perpetual KYC — continuous rescreening on every watchlist delta |
| Paying for it | USD invoice, card required, priced for US banks | Kwacha pricing — pay by MTN, Airtel or Zamtel mobile money |
Global compliance vendors treat Zambia as a locale code. Zanda Comply was designed here, for the realities of verifying and monitoring customers here.
Compliance platforms earn trust by being boring in exactly the right ways: versioned APIs, verifiable behaviour, and controls that were designed in — not audited in later.
A committed, contract-tested OpenAPI spec with Python and TypeScript SDKs, signed webhooks, and idempotent batch ingestion.
Organisation-scoped isolation on every row, role-based access control, and single sign-on through Zanda Accounts.
Live notification streams to the analyst console, SLA timers, and Prometheus metrics for your ops team.
Field-level encryption for sensitive data at rest; searchable identifiers stored as keyed hashes, not plaintext.
SOC 2 and ISO 27001 control mappings from a machine-readable control register; STRIDE and presentation-attack threat models; DR/BCP and incident-response plans on the shelf.
178 automated tests spanning tenant isolation, RBAC, maker-checker, audit-chain integrity, residency egress and screening scale — run on every change.
Zanda Comply plugs into the same identity, organisation and billing spine as every Zanda module. Your team signs in once; your subscription is one line; new modules switch on without another procurement cycle.
We'll walk your team through a live KYC journey, a sanctions escalation, a blocked cross-border transfer and a goAML filing. Bring your hardest questions.