CBN AML Baseline Standards for Fintechs, PSPs and MMOs
ByTemitope Lawal
•5mins Read
Key Takeaways
1. The Baseline Standards, issued 10 March 2026, cover fintechs, PSPs, mobile money operators, international money transfer operators, payment service banks, microfinance banks and virtual asset service providers.
2. Full compliance is due 10 March 2028. Implementation began on the date of issuance, not on the deadline.
3. Implementation roadmaps were due to the CBN Compliance Department by 10 June 2026, so supervisors already hold each institution's own plan.
4. The standards require one automated system covering identification, risk assessment, screening, monitoring, case management, reporting, audit and data protection.
5. Proportionality applies: the system is calibrated to size, risk profile, business model, transaction volume and complexity, but the calibration must be documented and defensible.
6. Fintechs that rely on banking partners are increasingly asked to show compliance capability comparable to those partners, regardless of their own deadline.
The CBN AML requirements for fintechs, payment service providers (PSPs) and mobile money operators (MMOs) are the same as those for banks, with one difference: the deadline. Fintechs and other financial institutions have until 10 March 2028 to fully comply with the Baseline Standards for Automated AML Solutions, while deposit money banks must comply by 10 September 2027.
That extra six months has been widely read as breathing room. For most fintechs it is not. A payment provider processing thousands of wallet-to-wallet transfers an hour, across several channels, with a compliance team of four, is facing a harder build than a bank with an established financial crime function and an existing monitoring platform.
Do the CBN AML Baseline Standards Apply to Fintechs, PSPs and Mobile Money Operators?
Yes. The CBN AML Baseline Standards apply to every institution under CBN supervision, and the circular names mobile money operators, international money transfer operators, payment service providers and other financial institutions alongside banks. Issued under section 2(d) of the CBN Act 2007 and section 66(2) of the Banks and Other Financial Institutions Act 2020, they carry the full weight of CBN supervisory powers.
Institution type
Category
Full compliance deadline
Deposit money banks
DMB
10 September 2027
Payment service providers and switches
Other financial institution
10 March 2028
Mobile money operators
Other financial institution
10 March 2028
International money transfer operators
Other financial institution
10 March 2028
Payment service banks and microfinance banks
Other financial institution
10 March 2028
Virtual asset service providers
Financial institution under the MLPPA 2022
Treated within the CBN framework where CBN-regulated
Virtual asset businesses should note the overlap. Section 30 of the Money Laundering (Prevention and Prohibition) Act 2022already defines virtual asset service providers as financial institutions, so the statutory AML duties apply whatever the licensing position.
When Is the Compliance Deadline for Fintechs and Other Financial Institutions?
The compliance deadline for fintechs and other financial institutions is 10 March 2028, twenty-four months from the circular's issuance on 10 March 2026. Two earlier dates have already passed, and both matter more than the final one.
Roadmaps must show current state, target state, actions, timelines, ownership and governance
10 June 2026
Implementation roadmaps due to the CBN Compliance Department
Supervisors hold your plan and can test progress against it
8 September 2026
CBN names terrorism financing a supervisory priority
Monitoring, sanctions implementation and reporting quality face closer scrutiny
10 March 2028
Full compliance for fintechs, PSPs, MMOs, IMTOs and other financial institutions
Systems live, tuned and evidenced
The roadmap deadline changed the nature of the risk. Before June 2026, a capability gap was an internal planning matter. Now the CBN holds the institution's own stated plan, and a missed milestone is measured against a commitment the institution made itself.
What Must a Fintech's AML System Actually Do?
Under the Baseline Standards, an AML solution must provide eight capabilities: customer identification and verification, risk assessment and profiling, sanctions screening, transaction and fraud monitoring, case management, regulatory reporting, audit and governance, and data protection. The standards also require interoperability, meaning the AML system must integrate with core banking, onboarding and payment platforms rather than sitting beside them.
Capability
What it means for a fintech or PSP
Identification and verification
BVN, NIN and corporate registry checks with liveness, feeding the customer record rather than stopping at onboarding
Risk assessment and profiling
Risk scores that update as wallet behaviour changes, not a tier fixed at signup
Sanctions screening
Domestic and international lists with fuzzy and alias matching, refreshed in real time or near real time
Transaction and fraud monitoring
Coverage of every channel: wallets, cards, transfers, agents and API-initiated payments, in real time or near real time
Case management
Alerts becoming assigned, tracked investigations, with automated closure allowed only in narrow low-risk conditions
Regulatory reporting
STRs, SARs and CTRs generated from case data and filed with the NFIU, consistent with the evidence behind them
Audit and governance
Tamper-proof logs of configuration changes and alert decisions, with annual independent validation of any AI or machine learning models
Data protection
Encryption, role-based access, multi-factor authentication and tested disaster recovery, aligned to the Nigeria Data Protection Act 2023
How Does Proportionality Work for a Smaller Fintech?
Proportionality means the extent, configuration and sophistication of the system is calibrated to the institution's size, risk profile, business model, transaction volumes and complexity. A microfinance bank with 20,000 customers is not expected to run what a tier-one bank runs. What it is expected to do is show the reasoning behind its calibration.
Read proportionality as a documentation duty rather than a discount. Write down the volumes, the products, the corridors and the risks you assessed, the level of automation you chose as a result, and who approved it. An institution that cannot explain why its configuration fits its risk has not applied proportionality; it has simply bought less.
Why Is the 24-Month Window Harder Than It Looks?
The extra six months is offset by four things fintechs face that banks generally do not: higher transaction velocity, pressure from banking partners, leaner compliance teams, and fraud and AML systems that were built separately.
1. Velocity: Real-Time Rails Leave No Review Window
Instant transfers and wallet-to-wallet movement settle in seconds, so monitoring that runs on a batch cycle detects laundering after the money has gone. Real-time or near real-time detection is a rebuild for anyone whose current controls run overnight.
2. Partner Pressure: Your Sponsor Bank's Deadline Is 2027, Not 2028
Fintechs, PSBs and PSPs that depend on banking infrastructure are increasingly asked to demonstrate compliance capability comparable to their banking partners. Your partner bank must be fully compliant by September 2027, and partner due diligence questionnaires will reach you well before that. In practice, the commercial deadline arrives ahead of the regulatory one.
3. Team Size: Four People Cannot Clear an Untuned Alert Queue
Automation generates alerts, and alerts need investigators. A system tuned without regard to team capacity produces a backlog that is itself a supervisory finding. Threshold design and staffing have to be planned together.
4. Split Systems: Fraud and AML Built as Separate Stacks
Most fintechs bought fraud tooling first, to stop losses, and treated AML as a reporting obligation. The standards encourage a unified financial crime architecture where transaction volume or risk justifies it, which means two disconnected systems are now a visible gap rather than an accepted trade-off.
What Do Banking Partners Now Expect From Fintechs?
Banking partners increasingly expect three things: evidence that your AML controls are automated, a copy or summary of your implementation roadmap, and the ability to answer questions about screening coverage, monitoring scope and reporting timelines. Their own examiners now ask about the risk introduced through partner channels.
This turns compliance capability into a commercial asset. A fintech that can show a clause-by-clause map of its controls moves faster through partner onboarding than one that promises to be ready by 2028. It is worth preparing that pack before it is requested.
How Do the CBN's Baseline Standards Fit With Other CBN Rules for PSPs?
The CBN Baseline Standards sit alongside three other sets of rules that apply to payment providers: the amended BVN framework effective 1 May 2026, the agent banking guidelines with provisions from 1 April 2026, and the statutory duties in the MLPPA 2022. They repeatedly ask for the same underlying capability.
Rule
What it adds for a fintech or PSP
CBN BVN regulations update
A 24-hour temporary watchlist, device binding, a ₦20,000 first-day cap and one lifetime phone change
Due diligence, 24-hour suspicious reporting, seven-day threshold reporting, five-year records
Built separately, these become four projects. Built once, they become one platform that verifies identity, scores risk, monitors live flows, manages cases and files reports. The wider map is set out in our guide to AML regulations in Nigeria.
How Should a Fintech Prepare for CBN AML Baseline Standards Before March 2028?
Fintechs can prepare for CBN AML Baseline Standards for Fintechs, PSPs and MMOs prepare in six ways: tracking delivery against the roadmap already filed, connecting identity data to monitoring, unifying fraud and AML signals, tuning thresholds to team capacity, automating NFIU reporting, and setting up model governance.
1. Roadmap Tracking: Measure Delivery Against What You Filed
Pull out the roadmap submitted in June 2026 and mark each milestone delivered, in progress or slipped, with reasons. Supervisors will assess progress against that document, so the gap analysis should start there rather than from scratch.
2. Identity Integration: Feed Verification Results Into Monitoring
Connect BVN, NIN and corporate verification results to the monitoring engine so alerts are judged against who the customer is. Verification stored only in the onboarding system cannot support risk profiling that updates over time.
3. Unified Signals: Put Fraud and AML on the Same Customer View
Device, IP and behavioural signals from fraud tooling are the same signals that explain an AML alert. Bringing them into one profile reduces duplicate investigation and matches the architecture the CBN encourages.
4. Threshold Tuning: Set Alert Volumes Your Team Can Clear
Define acceptable false-positive and false-negative levels per scenario, test them against historical data, and record who approved them. Keep the before and after whenever a rule changes.
5. Reporting Automation: Generate NFIU Filings From the Case File
Configure suspicious and threshold reports to draw from case data in goAML format. Manual filing is where the 24-hour and seven-day deadlines slip, and both carry daily penalties.
6. Model Governance: Schedule Validation Before You Need It
If you use machine learning for scoring or detection, document how the models decide and book independent validation annually. Explainability is a requirement, not a preference.
Meeting CBN AML Requirements for Fintechs With Youverify
Meeting the CBN AML requirements for fintechs, PSPs and mobile money operators before March 2028 means one system that verifies customers, watches live flows, manages cases and files reports. Youverify runs all four for Nigerian payment providers, wallets, lenders and virtual asset businesses, on rails built for this market.
Customer Onboardingruns document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier, which covers identification, verification and the risk profile the standards expect. Transaction Monitoringapplies rules and models on live flows, with typologies tuned to multi-currency, mobile money and cross-border corridors, which is exactly the traffic a PSP or MMO has to explain to an examiner.
Fraud Insightsscores device and browser fingerprint, IP spoofing, incognito and Tor, emulators and remote tools, velocity and behaviour inside the same session, so fraud and AML signals sit on one customer view instead of two systems. When a flag becomes a case, Case Management holds the queues, SLAs, the entity graph, evidence and a decision trail you can hand to an examiner, and Regulatory Reportingdrafts STRs, CTRs and periodic returns from that case file, formatted per regulator, filed with the evidence attached.
Regulator-ready before the regulator asks, and ready for your banking partner's questionnaire before it lands. Talk to our team about your 2028 roadmap and see where your current stack meets the standards and where it does not.