AML Compliance in Nigeria: A 2026 Guide for Fintechs and Regulated Businesses

Nigeria's AML rulebook runs through NFIU and CBN — here's what regulated fintechs actually have to report, screen, and retain in 2026.

Share
AML Compliance in nigeria

AML compliance is a core operating requirement for any fintech, neobank, or payment provider moving money in Nigeria. VOVE ID works with regulated businesses across the region to build this into onboarding and monitoring rather than treating it as a separate check.

This guide covers Nigeria's AML reporting and screening obligations specifically. For the underlying framework and definitions, see our AML requirements explained.

Nigeria's AML/CFT regime rests on a small number of laws that regulated businesses need to track directly:

  • Money Laundering (Prevention and Prohibition) Act (MLPPA), 2022 — criminalizes money laundering, sets CDD and reporting obligations, and requires immediate escalation of suspicion with written reporting and action within 24 hours (s.7).
  • Terrorism (Prevention and Prohibition) Act (TPPA), 2022 — governs terrorist and proliferation financing, targeted financial sanctions, and asset freezes; TF/PF reports are also due within 24 hours (s.84).
  • CBN Customer Due Diligence Regulations, 2023 — the detailed CDD, beneficial-ownership, and ongoing-monitoring rulebook for CBN-supervised institutions.
  • CBN AML/CFT/CPF Regulations, 2022, plus the Baseline Standards for Automated AML/CFT/CPF Solutions, mandatory for CBN-supervised institutions from 10 March 2026.

Who Supervises What

Supervision depends on activity, not just sector label: the CBN oversees banks, other financial institutions, and payment institutions; the SEC covers capital-market operators and virtual asset service providers; NAICOM covers insurance; PenCom covers pensions; and SCUML covers designated non-financial businesses and professions (DNFBPs). Suspicious transaction reports go to the NFIU through the applicable channel — generally goAML, with RapidAML used for nil, CTR, and PEP returns depending on entity type.

A technology provider is not automatically a reporting entity. Which obligations apply depends on the regulated service, license, or contractual arrangement actually in place — this is worth mapping explicitly rather than assuming from the "fintech" label.

Who Must Comply

  • Fintechs (mobile money, digital wallets, BNPL platforms)
  • Neobanks and digital lenders
  • Virtual asset service providers and OTC desks
  • Remittance and forex operators
  • DNFBPs (real estate agents, lawyers, accountants, dealers in precious metals)

Core AML Obligations

Customer due diligence. Verify identity through reliable independent sources, and for legal persons, identify and verify beneficial owners against the CAC's persons-with-significant-control register (a ≥5% disclosure trigger, not a substitute for full beneficial-ownership analysis). For KYC and KYB workflow detail, see our Nigeria KYC and Nigeria KYB guides.

Sanctions screening and targeted financial sanctions. Screen customers, beneficial owners, directors, and transaction parties against current UN and Nigeria sanctions lists before onboarding, on list updates, and on an ongoing basis. On a confirmed match, freeze the relevant assets without delay or prior notice and report immediately to NIGSAC, NFIU, and the sector regulator.

Suspicious transaction reporting. File to the NFIU immediately once suspicion is established, with written reporting and follow-up action within 24 hours under MLPPA s.7 (TF/PF reports within 24 hours under TPPA s.84). NFIU guidance describing a longer internal examination window does not extend this statutory deadline.

Domestic and cross-border thresholds. Report single transactions above ₦5 million (individuals) or ₦10 million (corporates) within seven days, and cross-border transfers above US$10,000 to NFIU, CBN, and SEC within one day.

Record retention. Keep CDD records, account files, and analysis for at least five years after the relationship ends or the transaction completes — longer where another rule requires it.

Automated AML infrastructure. Institutions under CBN supervision must implement the Baseline Standards for Automated AML Solutions (effective 10 March 2026): risk-based customer profiling, real-time sanctions screening, transaction monitoring across all channels, case management, automated regulatory reporting, and governed AI/ML models where used. Deposit money banks have 18 months to reach full compliance; other supervised institutions have 24 months. For the full breakdown of this circular, see our CBN Baseline Standards guide.

International Context: FATF and GIABA

Nigeria was removed from the FATF grey list in October 2025. That's a milestone, not a finish line — GIABA membership and mutual-evaluation follow-up still shape what regulators expect from beneficial-ownership transparency and DNFBP oversight going forward.

Practical Steps

  1. Map which regulator(s) actually apply to your licensed activity before assuming a generic AML checklist covers you.
  2. Build sanctions and PEP screening into onboarding and keep it running post-onboarding, not just at signup.
  3. Set a documented, conservative interpretation of reporting thresholds and test it against real transaction patterns.
  4. Keep an auditable STR decision trail — including cases where you decided not to file.
  5. Track the CBN Baseline Standards roadmap deadline for your institution type and don't wait until the compliance deadline to start.

Final Thoughts

Nigeria's AML/CFT regime is detailed and actively enforced, and the 2026 Baseline Standards raise the technical bar further.

Platforms like VOVE ID help fintechs build sanctions screening, monitoring, and reporting into a single connected workflow rather than a set of disconnected checks.

See how VOVE ID can help

This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. AML requirements may vary depending on jurisdiction, activity, and licensing status. For binding compliance obligations, consult the relevant regulator or a qualified professional.