Escropal

Secure Nigerian deals from agreement to payout.

Escropal is a mobile-first transaction assurance and escrow-orchestration platform for Nigerian buyers and sellers who meet on social channels, referrals, classifieds, freelance communities, or direct outreach. It helps them formalise terms, verify funding, preserve evidence, manage disputes, and release or refund funds through licensed safeguarding and payout partners without Escropal itself becoming the deposit-taking party.

Business Goals

  • Reach 5,000 registered users and 500 completed transactions within 6 months of limited production launch.
  • Achieve at least 35 percent repeat-transaction rate among active users within 90 days of first completed transaction.
  • Keep provider-confirmed transaction failure rate below 2 percent and duplicate-payout incidents at zero from day one of production use.
  • Resolve at least 80 percent of disputes within 7 calendar days after case opening during the first 2 quarters.
  • Maintain a net promoter score of 45 or higher among transacting users after the first 1,000 completed transactions.

User Goals

  • Enable two strangers to agree transaction terms in a structured, auditable way before money changes hands.
  • Let buyers verify that funds are actually secured with an approved Nigerian partner before the seller ships or delivers.
  • Provide both parties a fair inspection and dispute path without relying on screenshots, informal chat promises, or verbal assurances.
  • Reduce fraud exposure by preserving identity, payment, delivery, and evidence records in one traceable case file.
  • Give sellers a clearer release process and buyers a predictable refund path if agreed terms are not met.

Non-Goals

  • Operating as a marketplace, product listing site, or discovery engine.
  • Holding customer funds in Escropal-owned operating accounts or creating reusable stored-value balances.
  • Supporting cross-border, FX, crypto, cash, or credit products in the MVP.
  • Acting as a logistics company, inspector, insurer, or unconditional guarantor of sale outcomes.

Ada, 31, Instagram-based reseller - Ada sells fashion items through Instagram DMs and frequently deals with first-time customers who are nervous about paying upfront. She needs a simple way to secure trust, show proof of delivery, and get paid without endless follow-up messages.

Ada, 31, Instagram-based reseller

  • As a seller, I want to create a transaction link from a chat conversation so that I can formalise agreed terms quickly.
  • As a seller, I want to upload shipping and delivery evidence so that I can prove I fulfilled my side before release.
  • As a seller, I want to see when funds are provider-confirmed as secured so that I know when to ship.

Tunde, 38, small business buyer - Tunde buys electronics from vendors he finds on WhatsApp and classified sites. He wants a safer way to pay without risking loss to a scammer or poor-quality delivery.

Tunde, 38, small business buyer

  • As a buyer, I want to accept transaction terms before funding so that I know exactly what I am paying for.
  • As a buyer, I want to inspect a delivered item within a defined window so that I can dispute defects in time.
  • As a buyer, I want a clear refund path if the seller fails to deliver or the item is materially not as described.

Mariam, 44, operations case officer - Mariam works in the internal review team that manages disputes, sanctions holds, and payout exceptions. She needs a controlled case-management workflow with evidence, audit history, and segregation of duties.

Mariam, 44, operations case officer

  • As a case officer, I want a complete event timeline and evidence pack so that I can make a reasoned decision.
  • As a case officer, I want conflict and independence controls on assignment so that the review process stays fair.
  • As a case officer, I want one controlled appeal path so that decisions are reviewable without endless re-opening.

Identity, onboarding and access control · High priority

  • The platform shall onboard verified adults and approved businesses with authentication, KYC/KYB, and role-based access before any transaction action is permitted.
  • The platform shall support phone-number-based account creation with OTP and device binding.
  • The platform shall require individual KYC or business KYB before a user can create, accept, fund, or receive a transaction.
  • The platform shall support step-up verification for account recovery, payout changes, and suspicious login events.
  • The platform shall block minors, anonymous users, and unverified accounts from transaction initiation.
  • The platform shall record verification status, review outcome, and evidence references in the user profile.

Transaction orchestration · High priority

  • The platform shall allow either buyer or seller to create a versioned transaction, invite a counterparty, and progress through acceptance, funding, fulfilment, inspection, dispute, and payout states.
  • The platform shall allow terms to be versioned and re-accepted when any material field changes.
  • The platform shall require mutual acceptance of product or service description, amount, delivery method, fees, deadline, and inspection rules before funding.
  • The platform shall support physical goods, digital goods delivered externally, and single-completion services.
  • The platform shall prevent release or refund actions unless the transaction is in a permitted state and the action is independently verified.
  • The platform shall generate a unique transaction reference and immutable event history for every state transition.

Funds safeguarding and payout orchestration · High priority

  • The platform shall route funding, release, and refund instructions through licensed safeguarding and payout partners, while Escropal maintains only a mirror sub-ledger and control logic.
  • The platform shall mark funds as secured only after authoritative provider confirmation and reconciliation checks succeed.
  • The platform shall not treat screenshots, SMS alerts, or user statements as funding confirmation.
  • The platform shall support idempotent payment initiation and payout execution with duplicate-prevention keys.
  • The platform shall support late payment confirmation, timeout handling, reversal detection, and beneficiary mismatch controls.
  • The platform shall pause financial actions when provider status is inconsistent or when sanctions, fraud, or dispute holds apply.

Dispute management and evidence · High priority

  • The platform shall provide a fair evidence-based dispute workflow with deadlines, notice, evidence preservation, review, decision, and appeal.
  • The platform shall open disputes only within defined eligibility windows and capture reason codes at opening.
  • The platform shall allow equal evidence submission windows for both parties and preserve metadata, hashes, and timestamps.
  • The platform shall assign cases to conflict-cleared officers using a controlled rule set.
  • The platform shall support release, refund, partial allocation, cure or replacement, settlement, and escalation to external legal or regulatory orders.
  • The platform shall permit one internal appeal on defined grounds with reviewer independence controls.

Compliance, privacy and operations · High priority

  • The platform shall implement sanctions, PEP, AML, fraud, privacy, audit, support, and record-retention controls suitable for a regulated Nigerian transaction-assurance product.
  • The platform shall screen users and transactions against sanctions, PEP, and prohibited-use lists before and during transaction processing.
  • The platform shall support suspicious activity escalation and hold execution while reviews are active.
  • The platform shall support data subject rights requests, controlled redaction, retention schedules, and access logging.
  • The platform shall provide an internal web-based operations portal with case management, audit trails, and report exports.
  • The platform shall emit operational, compliance, and product analytics for monitoring, reporting, and reconciliation.

Fast Transaction Setup

  • User signs up with phone number, OTP, and device verification.
  • User completes individual KYC or business KYB with ID, selfie, business registration, and beneficial ownership details as applicable.
  • User creates or opens a transaction link from a chat message, referral, or direct invite.
  • User reviews versioned terms, fees, deadlines, and dispute rules, then accepts.
  • User funds through an approved Nigerian channel and sees a pending status until provider confirmation.
  • Target time to first transaction setup: under 6 minutes for a returning verified user and under 10 minutes for a new verified user.

1. Create transaction

  • Either party can draft a transaction from a secure link after login. The draft captures who is buying, who is selling, what is being exchanged, and how fulfilment will happen.
  • If required fields are missing, the draft cannot proceed to invite.
  • Changes to amount, beneficiary, delivery method, or inspection window create a new version and require re-acceptance.
  • Drafts expire after a configurable inactivity period to reduce stale commitments.

2. Invite and accept terms

  • The counterparty is invited through a secure link or app notification and must authenticate before viewing and accepting terms.
  • The invite link is single-use or time-limited and cannot be forwarded for acceptance.
  • Both parties must agree to the same version before funding is enabled.
  • If one party rejects or edits terms, the transaction returns to draft with a version history retained.

3. Fund and verify

  • The buyer funds through an approved Nigerian funding rail and Escropal waits for provider-confirmed safeguarding before progressing.
  • Funding remains pending until authoritative provider confirmation matches the transaction reference and amount.
  • A screenshot does not advance state and is treated only as supporting evidence.
  • If reconciliation fails or timing is inconsistent, the transaction enters review hold rather than release or refund automatically.

4. Fulfil and inspect

  • The seller provides fulfilment evidence and the buyer receives an inspection window appropriate to the transaction type.
  • Physical goods require shipping or delivery evidence and buyer acknowledgement of receipt or delivery proof.
  • Digital goods require externally delivered evidence such as access logs, transfer proof, or delivery confirmation.
  • Services require completion evidence and the buyer cannot start inspection before the service-completion event is logged.

5. Accept, dispute, or auto-release

  • At the end of the inspection window the buyer can accept, open a dispute, or allow controlled auto-release if no dispute is filed in time.
  • If a dispute is opened before release, auto-release is blocked until the dispute is resolved or withdrawn.
  • Auto-release only occurs if the transaction is in a release-eligible state and no risk hold is active.
  • All payout and refund actions require idempotent execution and provider confirmation.

Advanced Controls and Exception Handling

  • One-click transaction cloning for repeat counterparties with edited terms and fresh acceptance.
  • Conditional holds for sanctions review, account takeover suspicion, or reconciliation mismatch.
  • Internal appeal workflow with restricted reviewer access and evidence freeze.
  • Structured partial allocation and settlement outcomes for mixed-delivery disputes.
  • Mobile low-bandwidth fallback mode with compressed views, resumable uploads, and offline draft save.

Trust-First Mobile UI

  • Use a clear state banner on every transaction showing draft, awaiting acceptance, funded, secured, in fulfilment, inspection, dispute, release pending, paid out, refunded, or closed.
  • Show plain-language explanations for why a button is disabled, especially for compliance and security holds.
  • Use large tap targets, high-contrast text, and accessible colour-independent status indicators.
  • Design for intermittent connectivity with autosave, retry queues, and visible sync states.
  • Expose receipts, timestamps, and evidence hashes in a dedicated audit timeline for each transaction.

Ada sells a pair of sneakers through Instagram DM. Instead of asking the buyer to send money to a personal account and trust chat screenshots, she creates a secure transaction link in Escropal, sets the item description, delivery method, inspection window, and fee split, then sends the invite to the buyer.

The buyer logs in, verifies the terms, and funds through an approved Nigerian channel. Escropal waits for provider confirmation before marking the funds as secured, so Ada knows the money is truly controlled in the safeguarding structure and not just promised by a payment alert.

When the courier delivers, Ada uploads evidence and the buyer inspects within the agreed window. The buyer accepts, Escropal sends a release instruction to the licensed partner, and both parties receive a full audit trail and receipt, turning a risky chat-based sale into a controlled transaction with clear accountability.

User-Centric Metrics

  • At least 90 percent of verified users complete transaction setup without customer support intervention.
  • At least 85 percent of fulfilled transactions reach buyer acceptance or expiry without dispute.
  • At least 80 percent of disputes are opened with complete required evidence on first submission.
  • At least 95 percent of users receive transaction status notifications within 30 seconds of the triggering event.
  • At least 70 percent of users rate the transaction process as easier than their informal direct-chat method.

Business Metrics

  • Monthly completed transaction volume grows to 1,000 by month 6 of limited production.
  • At least 30 percent of completed transactions lead to a repeat transaction within 60 days.
  • Transaction conversion from accepted terms to funded status reaches at least 65 percent.
  • Gross revenue from successful release fees becomes predictable within a 10 percent monthly variance band after the first 500 completed transactions.

Technical Metrics

  • Production availability of 99.5 percent or better for user-facing transaction flows.
  • P95 API response time under 500 milliseconds for read operations and under 1.5 seconds for non-payment writes, excluding third-party dependency delays.
  • Zero duplicate payout executions and zero unreviewed release actions caused by webhook replay or timeout.
  • Critical security and compliance alerts acknowledged within 15 minutes during business hours and 30 minutes otherwise.

Tracking Plan

  • Track transaction_created with actor role, channel, and transaction type.
  • Track transaction_terms_accepted with version number and acceptance timestamp.
  • Track funding_initiated and funding_confirmed with provider reference and reconciliation result.
  • Track fulfilment_evidence_submitted with evidence type, hash, and metadata completeness.
  • Track dispute_opened with reason code and deadline status.
  • Track decision_made with outcome, reason code, reviewer role, and appeal eligibility.
  • Track payout_completed or refund_completed with idempotency key and provider confirmation.

Technical Needs

  • Mobile app built with React Native or Flutter for Android-first Nigerian usage, with iOS parity where commercially justified.
  • Backend services in a typed stack such as TypeScript on NestJS or Java/Kotlin on Spring Boot with strict idempotency and event logging.
  • Transactional database such as PostgreSQL with append-only event tables and optimistic concurrency control.
  • Object storage for evidence files with signed URLs, encryption at rest, and access logging.
  • Queue and workflow layer such as Redis queues, RabbitMQ, or managed cloud queues for async provider callbacks and reconciliation jobs.
  • Observability stack with structured logs, metrics, tracing, and alerting, using tools such as OpenTelemetry, Grafana, and Sentry.
  • Internal web portal for operations and compliance with role-based access controls and audit history.

Integration Points

  • Licensed Nigerian safeguarding bank or mobile money partner for custody and account confirmation.
  • Payout or transfer processor for approved release and refund instructions.
  • Identity verification provider for NIN, BVN, selfie, and document checks, subject to lawful access and partner availability.
  • Sanctions and PEP screening source or workflow integrated through compliance tooling.
  • Notification providers for SMS, email, and push messaging, with retry and delivery tracking.

Data Storage & Privacy

  • Store only the minimum necessary personal data for KYC, KYB, transaction execution, compliance, and audit purposes.
  • Encrypt sensitive data at rest and in transit, and segregate evidence files from transactional records.
  • Implement role-based access, field-level masking, and audit logs for all access to personal and dispute data.
  • Support retention, deletion, and redaction controls aligned to legal, regulatory, and contractual obligations.
  • Treat privacy and data-location requirements as Legal/Regulatory Verification Required until Nigerian counsel confirms applicable obligations and partner terms.

Scalability & Performance

  • Use asynchronous processing for provider callbacks, evidence processing, and reconciliation jobs.
  • Design the core ledger-mirror model for append-only writes and read-optimised views to support growth.
  • Support intermittent low-bandwidth access with compressed assets and resumable uploads.
  • Plan for burst traffic around social-media-driven transaction spikes and payment confirmation delays.

Potential Challenges

  • Provider webhook duplication or reordering could cause incorrect state transitions; mitigate with idempotency keys, event sequencing, and state-machine guards.
  • A timeout could tempt the system to retry a payment blindly; mitigate by making all financial actions status-verified before any second attempt.
  • Evidence files may be large or missing metadata; mitigate with upload validation, resumable storage, and mandatory metadata capture.
  • Sanctions or fraud flags may arrive mid-transaction; mitigate with hard holds, visible reasons, and manual review queues.
  • Low connectivity may interrupt user sessions; mitigate with autosave drafts, retry queues, and session-resume tokens.

Team & resourcing - Small cross-functional team: 1 product manager, 2 backend engineers, 2 mobile engineers, 1 full-time designer, 1 QA analyst, 1 part-time compliance lead, and shared DevOps/security support.

Phase 1: Decision closure and design control · Weeks 1 to 4

  • Regulatory classification memo marked Legal/Regulatory Verification Required where needed
  • Partner due-diligence checklist for safeguarding, collections, and payouts
  • PRD baseline, data model, and state machine spec
  • Clickable mobile and ops portal wireframes
  • Risk register and launch gate criteria

Phase 2: Private beta build · Weeks 5 to 10

  • User registration, KYC/KYB intake, and invite-based transaction creation
  • Versioned terms, funding initiation, and provider-confirmed secured-funds state
  • Evidence upload, fulfilment tracking, and controlled release/refund orchestration
  • Internal case-management portal with dispute opening and evidence review
  • Analytics instrumentation, audit logs, and reconciliation jobs

Phase 3: Limited production · Weeks 11 to 16

  • Approved Nigerian funding and payout partner integration
  • Dispute decision and one-appeal workflow
  • Sanctions, PEP, fraud, and prohibited-use screening controls
  • Notifications, receipts, and support workflows
  • Operational dashboards and incident response runbooks

Phase 4: Controlled scale · Weeks 17 to 24

  • Performance hardening and low-bandwidth improvements
  • Advanced exception handling such as partial allocation and settlements
  • Improved reconciliation automation and exception queues
  • Policy tuning, training materials, and QA audit process
  • Readiness evidence pack for broader rollout decision

Paste this into Cursor, Bolt, Lovable, or v0 to start building.

Build a mobile-first transaction assurance platform for Nigeria called Escropal.

Product summary:
Escropal is not a marketplace or wallet. It is an escrow-orchestration and transaction-assurance app for buyers and sellers who meet outside the platform, especially through Instagram, WhatsApp, X, referrals, and classifieds. Users create a secure transaction from an invite link, accept versioned terms, fund through an approved Nigerian payment flow, upload fulfilment evidence, inspect delivery, open disputes, and trigger release or refund outcomes. The app also needs an internal web ops portal for case management, compliance review, reconciliation, and support.

Build the following:
Mobile app for buyers and sellers, optimized for Android-first Nigeria but responsive enough for iOS.
Internal admin web dashboard for operations, disputes, compliance holds, and audit trails.

Core screens and flows:
1. Sign up and login with phone OTP, device binding, and step-up recovery.
2. Individual KYC and business KYB onboarding, including identity, selfie, business details, and beneficial ownership fields.
3. Secure transaction creation from invite link, with fields for counterparty, item or service description, amount in NGN, delivery method, deadline, inspection window, fee payer, and dispute rules.
4. Versioned terms acceptance by both parties.
5. Funding page that waits for provider-confirmed funding before showing secured status.
6. Fulfilment evidence upload for physical goods, digital goods, and services.
7. Buyer inspection, accept, dispute, and expiry auto-release flow.
8. Dispute case timeline, evidence submission, reviewer decision, and one internal appeal.
9. Refund and payout status tracking with receipts.
10. Ops portal with case queue, sanctions or fraud holds, reconciliation exceptions, user profile review, and audit log search.

Data model:
User, Organization, VerificationCase, Transaction, TransactionVersion, Invitation, FundingAttempt, ProviderConfirmation, FulfilmentEvent, EvidenceItem, DisputeCase, AppealCase, Decision, PayoutInstruction, RefundInstruction, ReconciliationRecord, Notification, AuditEvent, RiskFlag.
Use PostgreSQL with strict state machines and append-only audit events. Store evidence in object storage with encrypted at rest files, signed URLs, hashes, timestamps, and metadata.

Rules:
Implement idempotency for all payment and payout actions.
Never auto-retry a failed or timed-out transfer without independent provider status verification.
Never mark funds as secured from a screenshot or manual customer claim.
Use role-based access control for buyer, seller, case officer, compliance reviewer, and super admin.
All contested dispute decisions must be human-made in the MVP.

Suggested stack:
Frontend mobile: Flutter or React Native
Frontend web: Next.js
Backend: NestJS or Spring Boot
Database: PostgreSQL
Cache/queue: Redis or managed queue
Storage: S3-compatible object storage
Auth: phone OTP plus optional email
Observability: OpenTelemetry, Sentry, Grafana
Hosting: AWS or equivalent cloud with Nigerian-region-aware data handling decisions

Deliverables:
Generate the app structure, database schema, API routes, state machine enums, admin roles, key components, and sample seed data.
Create production-quality UI with clear trust states, audit timeline, status banners, error states, offline draft save, low-bandwidth friendly uploads, and accessible design.
Implement mock payment-provider interfaces and event-driven webhook handling for funding confirmation, payout confirmation, reversal, and reconciliation.
Include strong validation, conflict handling, duplicate webhook protection, and case escalation flows.
Do not build any marketplace, wallet, cross-border transfer, crypto, lending, or insurance features.

Business Idea

Act as a senior product manager, fintech business analyst, requirements engineer and Nigerian financial-services product specialist. Generate a complete, production-grade Product Requirements Document (PRD) v1.0 for a company called Escropal. Do not produce a generic template, short outline, pitch deck or marketing plan. Produce a detailed, internally reviewable PRD that product, design, engineering, security, legal/compliance, finance, risk, customer operations and regulated partners could use to evaluate and build the product. PRODUCT OVERVIEW Escropal is a mobile-first transaction-assurance and escrow-orchestration platform initially serving Nigeria. It helps buyers and sellers who meet through Instagram, WhatsApp, X, referrals, classified platforms, freelance communities and other direct channels formalise transaction terms, verify payment, document fulfilment, preserve evidence, inspect delivery, resolve disputes and reach an authorised release or refund outcome. Escropal is not: - A marketplace, storefront, classifieds platform or product-discovery service. - A bank, deposit-taking institution or general payment gateway. - A reusable stored-value wallet. - A lender, insurer or unconditional commercial guarantee. - A courier, warehouse, inspection centre or logistics operator. - A cryptocurrency, foreign-exchange or cross-border remittance product. - A general-purpose file-hosting service. - A party to the underlying buyer-seller sale. Escropal should be described as a “transaction assurance platform” or “escrow-orchestration platform.” MVP MARKET AND SCOPE The MVP is for: - Domestic Nigerian transactions only. - Nigerian Naira only. - Verified adults and approved Nigerian businesses. - Mobile-first buyer and seller experiences. - An internal web-based operations and case-management portal. - Physical goods, externally delivered digital goods and single-completion services. - Transactions initiated outside Escropal and formalised through an invitation or secure transaction link. Exclude cross-border transactions, FX, cryptocurrency, cash funding, lending, insurance, product listings, reusable balances, anonymous users, minors, general content hosting and multi-milestone releases from the initial MVP. Multi-milestone transactions and a proprietary secure digital-transfer feature may be treated as deferred capabilities. CORE OPERATING MODEL Escropal must not receive or commingle customer principal in its ordinary operating accounts. For the MVP, customer funds must be received, controlled and safeguarded through a properly licensed Nigerian bank, mobile money operator or other structure approved by Nigerian counsel and any required regulator. Escropal maintains transaction state and a reconciled mirror sub-ledger and sends authenticated release or refund instructions only after permitted product events. Do not assume that integrating Paystack, Flutterwave or another payment provider automatically gives Escropal legal authority to hold customer money. Clearly distinguish: - Licensed custody/safeguarding partner. - Collection processor. - Payout or transfer processor. - Escropal’s orchestration, evidence, ledger-mirror and case-management responsibilities. “Funds Secured” must appear only after authoritative provider confirmation and reconciliation controls—not after a screenshot, SMS alert or unverified customer statement. CORE TRANSACTION JOURNEY Design detailed requirements and workflows covering: 1. Account registration and authentication. 2. Individual KYC and business KYB. 3. Sanctions, PEP, fraud and prohibited-use screening. 4. Transaction creation by either buyer or seller. 5. Counterparty invitation and authentication. 6. Versioned transaction terms. 7. Mutual acceptance of description, value, category, fulfilment evidence, delivery method, fees, deadlines and inspection rules. 8. Funding through approved NGN channels. 9. Provider-confirmed funding and safeguarded-funds state. 10. Seller fulfilment and evidence submission. 11. Physical, digital and service-specific fulfilment rules. 12. Buyer inspection period. 13. Buyer acceptance. 14. Expiry and controlled auto-release. 15. Dispute opening before release. 16. Financial hold while a dispute or appeal is active. 17. Evidence submission and preservation. 18. Human dispute review and reasoned decision. 19. Full release, full refund, partial allocation or approved settlement. 20. One controlled internal appeal on defined grounds. 21. Partner-executed payout or refund. 22. Reconciliation, settlement and closure. 23. Receipts, notifications, audit history and support access. Handle concurrency and failure scenarios including duplicate API requests, replayed or out-of-order webhooks, provider timeouts, late payment confirmation, reversal after apparent success, beneficiary mismatch, duplicate payout risk, dispute opened during auto-release, evidence-provider outage, sanctions hold, reconciliation mismatch, account takeover and interrupted low-bandwidth mobile sessions. A provider timeout must never automatically trigger a blind second transfer. Financial actions must be idempotent and independently status-verified. DISPUTE MODEL Define a fair, evidence-based dispute-resolution framework covering: - Eligibility and opening deadlines. - Notice to both parties. - Equal evidence opportunity. - Evidence categories, metadata, hashes and preservation. - Privacy, redaction and access rules. - Late evidence. - Conflict-free case-officer assignment. - Decision standards and reason codes. - Full release, full refund, partial allocation, cure/replacement, party settlement and external legal or regulatory orders. - Appeal grounds, deadlines and reviewer independence. - Complaint and external escalation routes. - Service levels, quality assurance and auditability. Automated tools may support triage, fraud detection and recommendations, but they must not make the final decision for a contested MVP dispute that releases or refunds principal. BUSINESS MODEL Assume a transparent transaction-assurance fee may be charged when funds are successfully released. The fee payer may be the buyer, seller or split between them, but this must be agreed before funding. Treat the final percentage, cap, VAT treatment, provider-cost allocation, discounts and refund treatment as open commercial decisions. Do not invent final pricing. REGULATORY AND COMPLIANCE CONTEXT Research and consider current Nigerian primary sources as of August 2026, where browsing is available, including relevant materials from: - Central Bank of Nigeria. - Nigeria Data Protection Commission. - Nigerian Financial Intelligence Unit. - Nigeria Inter-Bank Settlement System. - Federal Competition and Consumer Protection Commission. - Corporate Affairs Commission. - Nigeria Sanctions Committee. - Nigerian Communications Commission or ngCERT. - Official Paystack and Flutterwave documentation. Cover regulatory classification, licensed custody, safeguarding, CDD/KYC/KYB, beneficial ownership, AML/CFT/CPF, transaction monitoring, suspicious-activity escalation, sanctions, PEPs, consumer protection, complaints, privacy, data-subject rights, cybersecurity, fraud, incident response, outsourcing, record retention and regulatory change management. Distinguish clearly between: - Binding legal or regulatory obligations. - Partner or licence-holder responsibilities. - Provider capabilities. - Industry good practice. - Escropal product-policy decisions. - Proposed internal targets. Do not fabricate laws, regulatory approvals, licence conclusions or source citations. If browsing or verification is unavailable, label the matter “Legal/Regulatory Verification Required.” State that the PRD is not a substitute for Nigerian legal advice. REQUIREMENT QUALITY Write atomic, testable requirements using “shall.” Assign every requirement: - A unique ID using logical families such as PR, BR, FR, COMP, SEC, PRIV, OPS, DATA, NFR, UX, MET and TECH. - A short title. - Must, Should or Could priority. - Accountable functional owner. - Verification method or acceptance evidence. - Relevant source, assumption or product-decision basis. Avoid vague terms such as “fast,” “secure,” “scalable” or “user-friendly” unless accompanied by measurable criteria. Include detailed Given/When/Then acceptance criteria for the most critical user stories and financial-control scenarios. REQUIRED PRD CONTENT The final document must include: 1. Document control, version, status and approval accountabilities. 2. Executive summary. 3. Product vision, mission and product thesis. 4. Nigerian problem statement and market context. 5. Product classification and positioning. 6. Personas and jobs to be done. 7. Product principles and value proposition. 8. Business objectives and measurable product goals. 9. MVP scope and explicit out-of-scope list. 10. Assumptions, constraints and dependencies, with failure responses. 11. Business requirements. 12. Functional requirements. 13. Roles, permissions and transaction authority. 14. Canonical transaction data model. 15. Transaction, payment, dispute and payout state models. 16. State-transition rules and invariants. 17. End-to-end customer and operational workflows. 18. Priority user stories and Given/When/Then acceptance criteria. 19. Functional edge cases and required outcomes. 20. Payment, custody, collection and payout integrations. 21. Flow of funds and reconciliation controls. 22. Fee, tax and disclosure requirements. 23. KYC/KYB, AML, sanctions and fraud controls. 24. Privacy and data-governance requirements. 25. Security architecture and privileged-access controls. 26. Dispute and appeal framework. 27. Internal operations, support and case-management requirements. 28. Notifications and communication requirements. 29. Non-functional requirements covering availability, reliability, latency, capacity, scalability, low bandwidth, accessibility, backup, disaster recovery, observability, maintainability and compatibility. 30. Data model, event taxonomy, analytics and reporting requirements. 31. Product KPIs, control metrics and proposed launch targets. 32. Operational, product, financial, regulatory and security risk register. 33. Launch gates with required evidence, accountable owner and blocking conditions. 34. Phased roadmap from decision closure through private beta, limited production and controlled scale. 35. Open decisions, assumptions requiring validation and unresolved questions. 36. Requirement register. 37. Requirement-to-source traceability matrix. 38. Data and evidence retention schedule. 39. Roles, access-control and segregation-of-duties matrix. 40. Controlled glossary. 41. Official source register with direct URLs, issuer, title, publication/access date and relevance. 42. Regulatory change-control procedure. OUTPUT EXPECTATIONS - Produce the complete PRD, not merely headings or instructions for filling it out. - Use professional tables where repeated fields need comparison. - Include happy paths and non-happy paths. - Separate confirmed requirements from proposed assumptions. - Challenge weak assumptions and identify contradictions. - Do not claim Escropal is launch-ready merely because the PRD is complete. - Treat legal classification, custody structure, partner contracts, commercial pricing and regulatory approvals as launch-blocking decisions until verified. - Make the result suitable for independent comparison against another professionally prepared Escropal PRD. - End with a concise assessment of the PRD’s remaining gaps and the evidence required before its status can change from “Ready for Review” to “Approved Baseline.”

Make My PRD

Design by The Resonance | Powered by GPC – The AI Transformation Company

    PRD: Act as a senior product manager