Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

AML Compliance in Nigeria: What CBN and NFIU Require
Anti-Money Laundering (AML)

AML Compliance in Nigeria: What CBN and NFIU Require

ByTemitope Lawal
August 24, 2026•5mins Read

Key Takeaways

  1. ML compliance in Nigeria is defined by two instruments: the Central Bank of Nigeria's AML/CFT/CPF Regulations and the Money Laundering (Prevention and Prohibition) Act, 2022, and non-compliance carries specific, named financial and criminal penalties under that Act.
     

  2. A compliant programme rests on five pillars: customer due diligence, ongoing transaction monitoring, suspicious transaction reporting to the NFIU, a named compliance officer, and independent audit. Missing any one of them is a compliance gap, not a rounding error.
     

  3. Installing a screening or monitoring tool, including Youverify's, supports only one of those five pillars; it does not by itself make an institution AML-compliant.

AML compliance in Nigeria is not a single checklist item  it is a live legal obligation enforced by two separate authorities, and getting it wrong is expensive in a specific, quantifiable way. Under Section 7 of the Money Laundering (Prevention and Prohibition) Act, 2022, failing to report a suspicious transaction alone triggers a fine of ₦1,000,000 for every day the failure continues.


 

This article sets out, in plain terms, who has to comply, what a compliant programme actually contains, what non-compliance costs, and where Nigerian fintechs and banks most often get it wrong. Every regulatory claim below links directly to the CBN, NFIU, or SEC Nigeria source it comes from, so you can verify it yourself rather than take our word for it.


 

What AML Compliance Means in Nigeria

Anti-money laundering (AML) compliance is the programme a regulated institution runs to detect, prevent, and report the movement of illicit funds through its systems. In Nigeria, two instruments govern that programme: the Money Laundering (Prevention and Prohibition) Act, 2022  the primary statute, published in Official Gazette No. 90 of 13 May 2022  and the Central Bank of Nigeria's AML/CFT/CPF Regulations, which apply the statute's requirements specifically to CBN-licensed institutions.


 

AML Vs KYC: Why The Terms Are Not Interchangeable

KYC (identity verification of the customer) is one input into the broader AML programme. AML also covers ongoing transaction monitoring, suspicious transaction reporting, and governance that KYC data on its own does not satisfy. Youverify's guide to KYC and AML compliance breaks down where the two disciplines separate in practice, and it is worth reading before assuming that a strong KYC process alone covers your AML obligations.


 

Who CBN, SEC, and NFIU Expect to Comply

CBN's AML/CFT/CPF obligations apply to the institutions it licenses and supervises, including commercial banks, microfinance banks, payment service banks, payment service providers, mobile money operators, and bureaux de change. Nigeria's Securities and Exchange Commission runs a parallel AML/CFT/CPF regime for capital market operators, issued the same month as the Act itself, which sits outside CBN's direct licensing remit.


 

The Nigerian Financial Intelligence Unit is not a licensing regulator. It is the agency that receives, analyses, and acts on suspicious transaction reports (STRs) filed by CBN- and SEC-regulated institutions alike. Confusing NFIU's reporting role with CBN's supervisory role is a common and avoidable error in how compliance teams describe their own obligations internally.


 

The Five Pillars of an AML Compliance Programme

A programme that satisfies CBN and the Act rests on five components. The table below sets out what each one requires and what Youverify recommends beyond the regulatory floor.


 

Pillar

What CBN and the Act require

What Youverify recommends

Customer due diligence (CDD) and enhanced due diligence (EDD)

Identity verification at onboarding, with deeper scrutiny for higher-risk customers under Section 6 of the Act

Automate document and biometric capture; escalate EDD triggers to a human reviewer

Ongoing transaction monitoring

Continuous review of account activity for suspicious patterns

Rule-based and behavioural monitoring tuned over time to reduce false positives

Suspicious transaction reporting (STR)

Filing STRs with NFIU within 24 hours of the suspicion arising, per NFIU's 2023 STR guidelines

Maintain a documented, auditable internal decision trail beyond what NFIU requires for the filing itself

Designated compliance officer

A named individual accountable to the board for the AML programme

Give that officer direct visibility into monitoring and screening alerts, not just periodic reports

Independent audit and staff training

Periodic review of the programme's effectiveness

Treat audit findings as inputs to the next risk assessment, not a one-off exercise


 

Customer Due Diligence and Enhanced Due Diligence Explained

CDD and EDD are distinct depths of the same process, not interchangeable terms. EDD applies to higher-risk customers, including politically exposed persons, customers with complex ownership structures, and customers in higher-risk sectors. Youverify's breakdown of enhanced due diligence in banking sets out exactly which triggers should move a customer from standard CDD into EDD, and what additional checks that shift requires.


 

A Common Compliance Scenario: The Agent Banking Blind Spot

Consider an illustrative, common pattern rather than a specific case: a Nigerian fintech onboards several hundred agents to serve underbanked customers in rural areas. Each agent passes CDD at onboarding and is individually low-risk. Over several months, a small number of agents begin processing daily cash-in and cash-out volumes well above what their registered business profile would predict, but because monitoring rules are calibrated at the individual-transaction level rather than the aggregate-agent level, no single transaction crosses a threshold that triggers review. The pattern only becomes visible once monitoring is run at the agent-network level rather than the transaction level, which is precisely the gap between "we ran CDD" and "we are AML-compliant" that Section 7's continuing daily fine for undetected suspicious activity is designed to make expensive to ignore.


 

Penalties for AML Non-Compliance in Nigeria

The Money Laundering (Prevention and Prohibition) Act, 2022 sets out specific, named penalties rather than leaving sanctions to regulator discretion. Failure to comply with customer due diligence obligations under Section 6 carries a fine of ₦250,000 for each day the offence continues, alongside possible licence suspension or revocation.

Failure to report a suspicious transaction under Section 7 carries a fine of ₦1,000,000 for each day the offence continues. The principal money laundering offence under Section 18 carries, for individuals, imprisonment of not less than four and not more than fourteen years, or a fine of not less than five times the value of the proceeds involved; a body corporate faces a fine of not less than five times the value of the funds or property involved.

Other offences under Section 19, including tipping off a customer about a pending STR, destroying records, or facilitating transactions under a false identity  carry a fine of at least ₦10,000,000 or imprisonment of at least three years for individuals, and a fine of at least ₦25,000,000 for a body corporate, with an additional professional ban of up to five years possible for individuals.

 

These are statutory penalties under the Act itself, distinct from any separate administrative sanctions CBN may impose on a licensed institution under its own AML/CFT/CPF Regulations for supervisory breaches.


 

Recommendations

Running sanctions and politically-exposed-person screening on a recurring cadence, not only at onboarding, catches risks that emerge after a customer relationship is already open. Documenting the risk-based approach an institution actually follows, rather than a generic template, is what examiners look for when they ask how due diligence decisions get made. CBN's 2026 KYC and AML requirements already push institutions toward real-time, automated verification rather than periodic batch checks, and monitoring should be held to the same real-time standard.

 

Youverify's Fraud Insights and transaction monitoring solutions support the monitoring and screening pillar of financial institutions specifically. The designated compliance officer, governance structure, and audit function remain the institution's own responsibility and cannot be outsourced to software.

 

To get started book a free demo today. 

 

A Practical AML Compliance Checklist for 2026
 

  1. Confirm your institution's CBN licensing category, or SEC Nigeria registration if you are a capital market operator, and which specific AML/CFT/CPF obligations apply to it.

  2. Appoint and document a named compliance officer with direct, board-level accountability.

  3. Automate CDD and EDD workflows with a documented escalation path for high-risk customers.

  4. Run transaction monitoring continuously, and at the account-network level as well as the individual-transaction level.

  5. Document your STR filing process against NFIU's current guidelines, including the 24-hour filing window.

  6. Schedule an independent audit and recurring staff training rather than a one-time compliance rollout.

 

 

About the Author

Victoria Okere is a Compliance Content Writer at Youverify, specializing in AML compliance, financial crime risk, regulatory technology, and emerging trends in financial services.


 

FAQs

Frequently Asked Questions

Related Articles

Why is Negative News Screening (NNS) Important?
Anti-Money Laundering (AML)
Lola, Edited by Emmanuel Agwu•April 25, 2023

Why is Negative News Screening (NNS) Important?

Read More
What is a Sanctions List?
Anti-Money Laundering (AML)
Priscilla, Edited by Emmanuel Agwu•April 28, 2023

What is a Sanctions List?

Read More
RegTech's Influence On Regulatory Policy and Reform
Anti-Money Laundering (AML)
Emmanuel Agwu•February 14, 2024

RegTech's Influence On Regulatory Policy and Reform

Read More