Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

CBN AML Baseline Standards for Fintechs, PSPs and MMOs
Anti-Money Laundering (AML)

CBN AML Baseline Standards for Fintechs, PSPs and MMOs

ByTemitope Lawal
September 27, 2026•5mins Read

Key Takeaways

 

  • 1. The Baseline Standards, issued 10 March 2026, cover fintechs, PSPs, mobile money operators, international money transfer operators, payment service banks, microfinance banks and virtual asset service providers.
  • 2. Full compliance is due 10 March 2028. Implementation began on the date of issuance, not on the deadline.
  • 3. Implementation roadmaps were due to the CBN Compliance Department by 10 June 2026, so supervisors already hold each institution's own plan.
  • 4. The standards require one automated system covering identification, risk assessment, screening, monitoring, case management, reporting, audit and data protection.
  • 5. Proportionality applies: the system is calibrated to size, risk profile, business model, transaction volume and complexity, but the calibration must be documented and defensible.
  • 6. Fintechs that rely on banking partners are increasingly asked to show compliance capability comparable to those partners, regardless of their own deadline.

The CBN AML requirements for fintechs, payment service providers (PSPs) and mobile money operators (MMOs) are the same as those for banks, with one difference: the deadline. Fintechs and other financial institutions have until 10 March 2028 to fully comply with the Baseline Standards for Automated AML Solutions, while deposit money banks must comply by 10 September 2027.

 

That extra six months has been widely read as breathing room. For most fintechs it is not. A payment provider processing thousands of wallet-to-wallet transfers an hour, across several channels, with a compliance team of four, is facing a harder build than a bank with an established financial crime function and an existing monitoring platform.

 

Do the CBN AML Baseline Standards Apply to Fintechs, PSPs and Mobile Money Operators?

 

Yes. The CBN AML Baseline Standards apply to every institution under CBN supervision, and the circular names mobile money operators, international money transfer operators, payment service providers and other financial institutions alongside banks. Issued under section 2(d) of the CBN Act 2007 and section 66(2) of the Banks and Other Financial Institutions Act 2020, they carry the full weight of CBN supervisory powers.

 

Institution typeCategoryFull compliance deadline
Deposit money banksDMB10 September 2027
Payment service providers and switchesOther financial institution10 March 2028
Mobile money operatorsOther financial institution10 March 2028
International money transfer operatorsOther financial institution10 March 2028
Payment service banks and microfinance banksOther financial institution10 March 2028
Virtual asset service providersFinancial institution under the MLPPA 2022Treated within the CBN framework where CBN-regulated

Virtual asset businesses should note the overlap. Section 30 of the Money Laundering (Prevention and Prohibition) Act 2022 already defines virtual asset service providers as financial institutions, so the statutory AML duties apply whatever the licensing position.

 

When Is the Compliance Deadline for Fintechs and Other Financial Institutions?

 

The compliance deadline for fintechs and other financial institutions is 10 March 2028, twenty-four months from the circular's issuance on 10 March 2026. Two earlier dates have already passed, and both matter more than the final one.

 

DateWhat happened or is dueWhy it matters now
10 March 2026Baseline Standards issued; implementation starts immediatelyThe clock has been running for over a year
31 March 2026CBN clarification letter on roadmap contentRoadmaps must show current state, target state, actions, timelines, ownership and governance
10 June 2026Implementation roadmaps due to the CBN Compliance DepartmentSupervisors hold your plan and can test progress against it
8 September 2026CBN names terrorism financing a supervisory priorityMonitoring, sanctions implementation and reporting quality face closer scrutiny
10 March 2028Full compliance for fintechs, PSPs, MMOs, IMTOs and other financial institutionsSystems live, tuned and evidenced

The roadmap deadline changed the nature of the risk. Before June 2026, a capability gap was an internal planning matter. Now the CBN holds the institution's own stated plan, and a missed milestone is measured against a commitment the institution made itself.

 

What Must a Fintech's AML System Actually Do?

 

Under the Baseline Standards, an AML solution must provide eight capabilities: customer identification and verification, risk assessment and profiling, sanctions screening, transaction and fraud monitoring, case management, regulatory reporting, audit and governance, and data protection. The standards also require interoperability, meaning the AML system must integrate with core banking, onboarding and payment platforms rather than sitting beside them.

 

CapabilityWhat it means for a fintech or PSP
Identification and verificationBVN, NIN and corporate registry checks with liveness, feeding the customer record rather than stopping at onboarding
Risk assessment and profilingRisk scores that update as wallet behaviour changes, not a tier fixed at signup
Sanctions screeningDomestic and international lists with fuzzy and alias matching, refreshed in real time or near real time
Transaction and fraud monitoringCoverage of every channel: wallets, cards, transfers, agents and API-initiated payments, in real time or near real time
Case managementAlerts becoming assigned, tracked investigations, with automated closure allowed only in narrow low-risk conditions
Regulatory reportingSTRs, SARs and CTRs generated from case data and filed with the NFIU, consistent with the evidence behind them
Audit and governanceTamper-proof logs of configuration changes and alert decisions, with annual independent validation of any AI or machine learning models
Data protectionEncryption, role-based access, multi-factor authentication and tested disaster recovery, aligned to the Nigeria Data Protection Act 2023

How Does Proportionality Work for a Smaller Fintech?

 

Proportionality means the extent, configuration and sophistication of the system is calibrated to the institution's size, risk profile, business model, transaction volumes and complexity. A microfinance bank with 20,000 customers is not expected to run what a tier-one bank runs. What it is expected to do is show the reasoning behind its calibration.

Read proportionality as a documentation duty rather than a discount. Write down the volumes, the products, the corridors and the risks you assessed, the level of automation you chose as a result, and who approved it. An institution that cannot explain why its configuration fits its risk has not applied proportionality; it has simply bought less.

 

Why Is the 24-Month Window Harder Than It Looks?

 

The extra six months is offset by four things fintechs face that banks generally do not: higher transaction velocity, pressure from banking partners, leaner compliance teams, and fraud and AML systems that were built separately.

 

1. Velocity: Real-Time Rails Leave No Review Window

 

Instant transfers and wallet-to-wallet movement settle in seconds, so monitoring that runs on a batch cycle detects laundering after the money has gone. Real-time or near real-time detection is a rebuild for anyone whose current controls run overnight.

 

2. Partner Pressure: Your Sponsor Bank's Deadline Is 2027, Not 2028

Fintechs, PSBs and PSPs that depend on banking infrastructure are increasingly asked to demonstrate compliance capability comparable to their banking partners. Your partner bank must be fully compliant by September 2027, and partner due diligence questionnaires will reach you well before that. In practice, the commercial deadline arrives ahead of the regulatory one.

 

3. Team Size: Four People Cannot Clear an Untuned Alert Queue

Automation generates alerts, and alerts need investigators. A system tuned without regard to team capacity produces a backlog that is itself a supervisory finding. Threshold design and staffing have to be planned together.

 

4. Split Systems: Fraud and AML Built as Separate Stacks

Most fintechs bought fraud tooling first, to stop losses, and treated AML as a reporting obligation. The standards encourage a unified financial crime architecture where transaction volume or risk justifies it, which means two disconnected systems are now a visible gap rather than an accepted trade-off.

 

What Do Banking Partners Now Expect From Fintechs?

 

Banking partners increasingly expect three things: evidence that your AML controls are automated, a copy or summary of your implementation roadmap, and the ability to answer questions about screening coverage, monitoring scope and reporting timelines. Their own examiners now ask about the risk introduced through partner channels.

This turns compliance capability into a commercial asset. A fintech that can show a clause-by-clause map of its controls moves faster through partner onboarding than one that promises to be ready by 2028. It is worth preparing that pack before it is requested.

 

How Do the CBN's Baseline Standards Fit With Other CBN Rules for PSPs?

 

The CBN Baseline Standards sit alongside three other sets of rules that apply to payment providers: the amended BVN framework effective 1 May 2026, the agent banking guidelines with provisions from 1 April 2026, and the statutory duties in the MLPPA 2022. They repeatedly ask for the same underlying capability.

 

RuleWhat it adds for a fintech or PSP
CBN BVN regulations updateA 24-hour temporary watchlist, device binding, a ₦20,000 first-day cap and one lifetime phone change
CBN agent banking guidelinesAgent due diligence, training, network monitoring, monthly returns and named fines
Money Laundering Act 2022Due diligence, 24-hour suspicious reporting, seven-day threshold reporting, five-year records

Built separately, these become four projects. Built once, they become one platform that verifies identity, scores risk, monitors live flows, manages cases and files reports. The wider map is set out in our guide to AML regulations in Nigeria.

 

How Should a Fintech Prepare for  CBN AML Baseline Standards Before March 2028?

 

Fintechs can prepare for CBN AML Baseline Standards for Fintechs, PSPs and MMOs prepare in six ways: tracking delivery against the roadmap already filed, connecting identity data to monitoring, unifying fraud and AML signals, tuning thresholds to team capacity, automating NFIU reporting, and setting up model governance.

 

1. Roadmap Tracking: Measure Delivery Against What You Filed

Pull out the roadmap submitted in June 2026 and mark each milestone delivered, in progress or slipped, with reasons. Supervisors will assess progress against that document, so the gap analysis should start there rather than from scratch.

 

2. Identity Integration: Feed Verification Results Into Monitoring

Connect BVN, NIN and corporate verification results to the monitoring engine so alerts are judged against who the customer is. Verification stored only in the onboarding system cannot support risk profiling that updates over time.

 

3. Unified Signals: Put Fraud and AML on the Same Customer View

Device, IP and behavioural signals from fraud tooling are the same signals that explain an AML alert. Bringing them into one profile reduces duplicate investigation and matches the architecture the CBN encourages.

 

4. Threshold Tuning: Set Alert Volumes Your Team Can Clear

Define acceptable false-positive and false-negative levels per scenario, test them against historical data, and record who approved them. Keep the before and after whenever a rule changes.

 

5. Reporting Automation: Generate NFIU Filings From the Case File

Configure suspicious and threshold reports to draw from case data in goAML format. Manual filing is where the 24-hour and seven-day deadlines slip, and both carry daily penalties.

 

6. Model Governance: Schedule Validation Before You Need It

If you use machine learning for scoring or detection, document how the models decide and book independent validation annually. Explainability is a requirement, not a preference.

 

Meeting CBN AML Requirements for Fintechs With Youverify

 

Meeting the CBN AML requirements for fintechs, PSPs and mobile money operators before March 2028 means one system that verifies customers, watches live flows, manages cases and files reports. Youverify runs all four for Nigerian payment providers, wallets, lenders and virtual asset businesses, on rails built for this market.

 

Customer Onboarding runs document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier, which covers identification, verification and the risk profile the standards expect. Transaction Monitoring applies rules and models on live flows, with typologies tuned to multi-currency, mobile money and cross-border corridors, which is exactly the traffic a PSP or MMO has to explain to an examiner.

Fraud Insights scores device and browser fingerprint, IP spoofing, incognito and Tor, emulators and remote tools, velocity and behaviour inside the same session, so fraud and AML signals sit on one customer view instead of two systems. When a flag becomes a case, Case Management holds the queues, SLAs, the entity graph, evidence and a decision trail you can hand to an examiner, and Regulatory Reporting drafts STRs, CTRs and periodic returns from that case file, formatted per regulator, filed with the evidence attached.

 

Regulator-ready before the regulator asks, and ready for your banking partner's questionnaire before it lands. Talk to our team about your 2028 roadmap and see where your current stack meets the standards and where it does not.

FAQs

Frequently Asked Questions

Related Articles

Why is Negative News Screening (NNS) Important?
Anti-Money Laundering (AML)
Lola, Edited by Emmanuel Agwu•April 25, 2023

Why is Negative News Screening (NNS) Important?

Read More
What is a Sanctions List?
Anti-Money Laundering (AML)
Priscilla, Edited by Emmanuel Agwu•April 28, 2023

What is a Sanctions List?

Read More
RegTech's Influence On Regulatory Policy and Reform
Anti-Money Laundering (AML)
Emmanuel Agwu•February 14, 2024

RegTech's Influence On Regulatory Policy and Reform

Read More