AML Regulations in Nigeria: What Banks and Fintechs Must Do
ByTemitope Lawal
•5mins Read
Key Takeaways
Nigeria's AML framework rests on the MLPPA 2022, the Terrorism (Prevention and Prohibition) Act 2022, the NFIU Act 2018 and the CBN AML/CFT/CPF Regulations 2022.
CBN Baseline Standards (10 March 2026) require automated, risk-based AML systems.
Deadlines: banks 10 September 2027; other CBN-regulated institutions 10 March 2028. Roadmaps were due 10 June 2026.
Report cash transactions above ₦5m (individuals) and ₦10m (companies); STRs within 24 hours via goAML.
CBN does not certify vendors; ask for a clause-by-clause map, gaps included.
AML regulations in Nigeria come from three laws and one set of central bank rules: the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, the NFIU Act 2018 and the CBN AML/CFT/CPF Regulations 2022. Since 10 March 2026, the CBN Baseline Standards for Automated AML Solutions add a hard deadline: full compliance by 10 September 2027 for banks and 10 March 2028 for other financial institutions.
For a compliance team, that deadline turns anti-money laundering (AML) from a policy question into a systems question. The regulator is no longer asking whether you have a programme. It is asking whether your monitoring, screening and reporting are automated, explainable and provably effective.
What Are the AML Regulations in Nigeria?
The AML regulations in Nigeria are made up of six instruments: the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, the NFIU Act 2018, the CBN AML/CFT/CPF Regulations 2022, the CBN Baseline Standards for Automated AML Solutions 2026, and the Nigeria Data Protection Act (NDPA) 2023. The first three are acts of the National Assembly. The last three set how regulated institutions must operate day to day.
Each instrument answers a different question. The laws define the offences and the reporting duties. The CBN regulations turn those duties into supervisory rules for licensed institutions. The Baseline Standards set the minimum technology needed to meet them. The NDPA governs how the customer data behind all of it is stored and protected.
Instrument
Issued by
What it does
Who it binds
Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA)
National Assembly
Defines money laundering offences, customer due diligence duties, cash thresholds, reporting and penalties
All financial institutions and designated non-financial businesses
Terrorism (Prevention and Prohibition) Act 2022
National Assembly
Sets counter-terrorist financing (CFT) duties, including targeted financial sanctions
All reporting entities
NFIU Act 2018
National Assembly
Establishes the NFIU as the national centre for receiving and analysing financial intelligence
All reporting entities
CBN AML/CFT/CPF Regulations 2022
Central Bank of Nigeria
Turns the laws into supervisory rules covering AML, CFT and countering proliferation financing (CPF)
CBN-licensed institutions
CBN Baseline Standards for Automated AML Solutions 2026
Central Bank of Nigeria
Sets minimum functional, governance and reporting standards for AML systems
Banks, payment service providers, mobile money operators and other CBN-regulated institutions
Nigeria Data Protection Act 2023
National Assembly
Governs how personal data, including KYC and transaction data, is processed and secured
Any organisation processing personal data in Nigeria
Table 1: The 6 AML Regulations in Nigeria
The MLPPA 2022 replaced the Money Laundering (Prohibition) Act 2011. Any policy, onboarding script or vendor document that still cites the 2011 Act is out of date and should be revised. For a section-by-section reading of the Act, see our guide to the Money Laundering (Prevention and Prohibition) Act 2022.
Who Enforces AML Regulations in Nigeria?
AML regulations in Nigeria are enforced by four groups of authorities: the Central Bank of Nigeria (CBN), the Nigerian Financial Intelligence Unit (NFIU), the Economic and Financial Crimes Commission (EFCC) through SCUML, and sector regulators for capital markets, insurance, and pensions. Each owns a different stage of the chain, from supervision to intelligence to prosecution.
Authority
Role in the AML regime
Who it covers
Central Bank of Nigeria (CBN)
Licenses, examines and sanctions financial institutions for AML/CFT/CPF failures
Deposit money banks, microfinance banks, payment service banks, payment service providers, mobile money operators and other financial institutions
Nigerian Financial Intelligence Unit (NFIU)
Receives and analyses suspicious transaction reports (STRs) and currency transaction reports (CTRs) through goAML
All financial institutions
EFCC and SCUML
SCUML supervises designated non-financial businesses and professions; the EFCC investigates and prosecutes
Lawyers, accountants, real estate firms, car dealers, dealers in precious metals and similar businesses
Sector regulators
Apply AML rules within their own sectors
Capital market operators (SEC Nigeria), insurers (NAICOM) and pension fund administrators (PenCom)
Table 2: Bodies that Enforce AML Regulations in Nigeria.
This split matters when you plan compliance. A fintech with a CBN payment licence answers to the CBN for its systems and to the NFIU for its reports. A pension fund administrator answers to PenCom, so the CBN Baseline Standards may not apply to it directly, even though the MLPPA does.
The stakes rose after Nigeria's grey-listing. The Financial Action Task Force (FATF) placed Nigeria under increased monitoring in February 2023 and removed it on 24 October 2025, after Nigeria completed a 19-point action plan. Regulators now have to show the reforms hold, and our note on Nigeria's removal from the FATF grey list explains why that raises supervisory pressure rather than lowering it.
Which Institutions Must Follow Nigeria's AML Regulations, and by When?
Every financial institution and designated non-financial business in Nigeria must follow the MLPPA 2022, but the CBN Baseline Standards deadlines apply only to CBN-regulated institutions: deposit money banks by 10 September 2027, and other financial institutions by 10 March 2028. Other sectors follow their own regulator's timelines.
Microfinance banks, payment service banks, mortgage banks, finance companies
CBN
10 March 2028 (24 months)
Payment service providers, switches and mobile money operators
CBN
10 March 2028 (24 months)
Capital market operators
SEC Nigeria
Not directly covered; follow SEC rules
Insurers
NAICOM
Not directly covered; follow NAICOM rules
Pension fund administrators
PenCom
Not directly covered; follow PenCom rules
Designated non-financial businesses and professions
SCUML
Not directly covered; register and report to SCUML
Table 3: Institutions that must abide by the AML Regulations in Nigeria and their deadline.
The 24-month window is easy to misread as breathing room. Fintechs and payment providers often run higher transaction velocity than banks, across more channels, with leaner compliance teams. Their build is often harder, not easier, so the extra six months tends to disappear into integration work.
What Do the CBN Baseline Standards for Automated AML Solutions Require?
The CBN Baseline Standards for Automated AML Solutions require seven core capabilities: customer identification and verification, risk assessment and profiling, sanctions and watchlist screening, transaction monitoring, case management, regulatory reporting, and audit logging. Issued in a circular dated 10 March 2026, they also set rules for governance, data protection and system resilience.
The CBN applies a proportionality principle. A small microfinance bank is not expected to run the same stack as a tier-one bank. But every institution must calibrate its system to its size, transaction volume and risk exposure, and be able to show that calibration to an examiner.
1. Risk Profiling: Customer Risk That Updates in Real Time
Customer risk can no longer be a static score set at onboarding. The standards expect risk profiles to adjust as behaviour changes, new data arrives or external risk indicators shift. KYC, KYB and customer due diligence (CDD) data must feed directly into monitoring, so every alert is judged against the customer's full profile.
2. Transaction Monitoring: Every Channel, in Real Time or Near Real Time
Monitoring must cover all relevant channels, including cards, e-channels, deposits and lending, in real time or near real time. It must combine behavioural pattern recognition, anomaly detection and predictive analytics. Institutions must define thresholds for false positives and false negatives, document every tuning decision, and govern changes to monitoring logic.
3. Screening: Sanctions, PEP and Adverse Media With Fuzzy Matching
Screening must connect to domestic and international watchlists with real-time or near real-time updates. Fuzzy and AI-based name matching is expected, to catch spelling variations and aliases. Systems must also support adverse media monitoring and automatic blocking when a match is confirmed. Politically exposed persons (PEPs) and enhanced due diligence (EDD) triggers are covered in our guide to enhanced due diligence in banking.
4. Case Management and Audit Trails: Every Decision Traceable
Alerts must flow into enterprise case management that generates, assigns and tracks investigations. Automated alert closure is allowed only under narrowly defined low-risk conditions. Every configuration change and alert decision must sit in a tamper-proof audit trail that examiners can retrieve on demand.
5. Reporting and Model Governance: Automated Filing, Validated Models
Systems must generate STRs, suspicious activity reports (SARs) and CTRs automatically, consistent with the underlying case data. Where artificial intelligence or machine learning models are used, they must be explainable, governed and independently validated at least once a year. The standards also require NDPA-aligned encryption, role-based access, multi-factor authentication and tested disaster recovery.
One point stands out for fraud and compliance leaders. The standards do not force a single AML and fraud platform, but they encourage a unified financial crime architecture where transaction volume or risk justifies it. For high-volume digital lenders and payment providers, separate fraud and AML stacks are now a visible gap.
What Are the Key Dates in Nigeria's 2026 AML Compliance Timeline?
Nigeria's 2026 AML compliance timeline has six key dates: the Baseline Standards circular on 10 March 2026, a CBN clarification letter on 31 March 2026, the implementation roadmap deadline on 10 June 2026, the terrorism financing supervisory priority on 8 September 2026, full bank compliance on 10 September 2027, and full compliance for other institutions on 10 March 2028.
Date
Event
What it means for compliance teams
10 March 2026
CBN issues the Baseline Standards for Automated AML Solutions
Implementation starts on the date of issue
31 March 2026
CBN clarification letter
Roadmaps must show current state, target state, actions, timelines, ownership and governance
10 June 2026
Implementation roadmaps due to the CBN Compliance Department
Supervisors now hold each institution's own plan and can test progress against it
8 September 2026
CBN makes terrorism financing a current supervisory priority
Expect focused scrutiny of transaction monitoring, sanctions implementation and STR quality
10 September 2027
Full compliance deadline for deposit money banks
Systems must be live, tuned and evidenced
10 March 2028
Full compliance deadline for other financial institutions
Same bar for PSPs, mobile money operators, microfinance banks and others
Table 4: Dates for AML Regulations in Nigeria and what it means.
The roadmap date has passed, which changes the risk. Before June, a gap was a planning problem. Now the CBN holds your own stated plan, and missed milestones become evidence in an examination. The CBN has said it will monitor adherence through off-site surveillance, on-site examinations and thematic reviews.
What Must Financial Institutions Report to the NFIU?
Nigerian financial institutions must report three things to the NFIU: suspicious transactions, cash transactions above the statutory thresholds, and any other disclosures the NFIU requires, all filed through the goAML platform. The MLPPA 2022 sets the thresholds and timelines, and the CBN Baseline Standards now expect these reports to be generated automatically from case data.
Report
Trigger
Filed with
Suspicious transaction report (STR)
Any transaction the institution suspects involves proceeds of crime or terrorist financing, regardless of amount; within 24 hours under section 7 of the MLPPA 2022
NFIU via goAML
Currency transaction report (CTR)
Cash transactions above ₦5 million for individuals or ₦10 million for companies
NFIU for financial institutions; SCUML for designated non-financial businesses
The MLPPA 2022 also criminalises breaking one payment into smaller amounts to stay under the ₦5 million or ₦10 million threshold. That makes structuring detection a monitoring requirement, not an optional rule. Tipping off a customer about a pending STR is a separate offence.
What Are the Penalties for Breaching AML Regulations in Nigeria?
Penalties for breaching AML regulations in Nigeria come in two forms: statutory penalties under the MLPPA 2022, such as daily fines and prison terms, and administrative sanctions the CBN imposes on licensed institutions, including fines, remedial directives and licence action. The two can apply to the same failure.
Breach
Penalty under the MLPPA 2022
Failure to carry out customer due diligence (section 6)
₦250,000 for each day the offence continues, plus possible licence suspension or revocation
Failure to report a suspicious transaction (section 7)
₦1,000,000 for each day the offence continues
Money laundering (section 18)
Individuals: 4 to 14 years' imprisonment or a fine of at least five times the proceeds. Companies: a fine of at least five times the funds involved
Tipping off, destroying records, false identities and related offences (section 19)
Individuals: at least ₦10 million or at least three years' imprisonment. Companies: at least ₦25 million
CBN administrative sanctions are already significant. A review of annual reports by Prime Business Africa found the CBN fined nine NGX-listed banks about ₦17.35 billion in 2024. Among the reported infractions were anti-money laundering findings and breaches of targeted financial sanctions and screening rules.
Smaller fines tell the same story at the control level. In one reported case, a tier-one bank was fined ₦13 million for failing to verify a customer's identity and delaying a related transaction report. Examiners are testing specific controls, not just policies.
How Do Banks and Fintechs Prepare for the CBN AML Deadline?
Banks and fintechs prepare for the CBN AML deadline in six ways: running a gap analysis against each Baseline Standard, connecting customer data to monitoring, documenting alert thresholds, testing screening coverage, automating NFIU reporting, and putting model governance on a fixed calendar. Each one produces evidence an examiner can inspect.
1. Gap Analysis: Map Your System Against Every Requirement
List each Baseline Standard requirement and mark it met, partly met or not met, with the evidence for each. Be honest about the gaps. A self-assessment with no gaps is rarely true, and it weakens your credibility when the examiner finds one.
2. Data Integration: Connect KYC and KYB Records to Monitoring
Monitoring that cannot see who the customer is will keep producing noisy alerts. Link onboarding, KYB and CDD records to the monitoring engine, so risk scores and alerts use the full customer profile. Our breakdown of the CBN KYC and AML requirements for 2026 covers the verification side in detail.
3. Alert Tuning: Set and Document False-Positive Thresholds
Decide acceptable false-positive and false-negative levels for each scenario, then record who approved them and why. When rules change, keep the before and after. That record is what shows the CBN your monitoring is governed, not guessed.
4. Screening Coverage: Test Against Nigerian and International Lists
Run known test names, including aliases and misspellings, through your sanctions and PEP screening. Confirm coverage of the Nigerian sanctions list alongside UN, OFAC, UK and EU lists. Check how quickly list updates reach your system.
5. Regulatory Reporting: Generate NFIU Reports From the Case File
Reports typed up manually from spreadsheets drift from the underlying evidence. Configure STRs and CTRs to draw directly from case data in the goAML format, so the report and the investigation always match.
6. Model Governance: Put Annual Validation on the Calendar
If you use machine learning for scoring or detection, schedule independent validation now. Document how each model makes decisions in language an examiner can follow. An unexplainable model is a finding waiting to happen.
What Should Compliance Teams Ask Before Buying an AML Solution?
Compliance teams should ask AML vendors seven questions before buying: whether they can prove performance at your volume, how their models are explained and validated, which Nigerian data sources they connect to, whether they produce goAML-ready reports, how audit trails work, where data is stored, and which Baseline Standards requirements they do not yet meet.
Question to ask
Why it matters
What a strong answer looks like
Can you show performance at our transaction volume?
The standards require systems that scale and monitor in near real time
Throughput, latency and alert metrics from live deployments, not a demo environment
How are your models explained and validated?
AI and ML models need explainability and annual independent validation
Documented model logic, validation reports and a governance process you can adopt
Which Nigerian data sources do you connect to?
Risk profiling depends on BVN, NIN and CAC data
Named, direct connections, with coverage and response times stated
Do you generate STRs and CTRs for goAML?
Reports must be automated and match case data
Reports produced from the case file, with the evidence attached
How does your audit trail work?
Examiners need tamper-proof logs of every change and decision
Immutable logs covering configuration, alerts and user actions, exportable on request
Where is our customer data stored?
The NDPA and CBN data rules govern processing and storage
A clear answer on location, encryption and access controls
Which requirements do you not meet yet?
Every system has gaps, and the roadmap is yours to defend
A clause-by-clause map, including items on the roadmap or out of scope
Factors to consider before buying an AML Solution
Treat any vendor that calls itself "CBN compliant" with care. The CBN does not certify or endorse AML vendors, and compliance belongs to the institution, not the software. What a vendor can honestly show is how its system maps to each requirement, and the evidence behind that map.
Meeting AML Regulations in Nigeria With Youverify
Meeting AML regulations in Nigeria before the CBN deadline takes a system that connects identity, monitoring, investigation and reporting in one flow. That is the gap the Baseline Standards are designed to close, and it is what Youverify is built to do for Nigerian banks, fintechs and payment providers.
Customer Onboarding runs document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier, so risk profiling starts with verified BVN, NIN, and CAC data.
Transaction Monitoring applies rules and models on live flows, with typologies tuned to multi-currency, mobile money, and cross-border corridors.
Fraud Insights scores device, IP, velocity and behaviour inside the same session, which supports the unified fraud and AML architecture the CBN encourages.
When a flag becomes a case, Case Management holds the queues, SLAs, entity graph, evidence, and decision trail you can hand to an examiner.
Regulatory Reporting drafts STRs, CTRs, and periodic returns from the case file, formatted per regulator and filed with the evidence attached. Your compliance officer, board oversight, and independent audit remain yours; Youverify gives them the evidence to work with.
Be regulator-ready before the regulator asks. Book a free demo with our compliance experts to see how Youverify maps to each Baseline Standards requirement for your institution.