CBN BVN Regulations Update: What Changes for Banks and Fintechs
ByTemitope Lawal
•5mins Read
Key Takeaways
1. The CBN amended the Revised Regulatory Framework for BVN Operations and Watch-List in a circular dated 12 March 2026, effective 1 May 2026.
2. Institutions must run a temporary watchlist holding a flagged BVN for a maximum of 24 hours while the customer is contacted.
3. Customers may change the phone number linked to their BVN once in a lifetime, which targets SIM-swap fraud.
4. BVN enrolment is limited to individuals aged 18 and above.
5. Access to BVN data is restricted to CBN-licensed financial institutions, cutting off unapproved aggregators and third-party verification services.
6. From 1 July 2026, banking apps run on one device at a time, with fresh authentication and a ₦20,000 cap for the first 24 hours on a new device.
7. BVN enrolment stood at 68.59 million as of March 2026, so these controls apply across almost the entire banked population.
The CBN BVN regulations update introduces five changes for financial institutions: a temporary fraud watchlist that holds a flagged Bank Verification Number (BVN) for up to 24 hours, a lifetime limit of one change to the phone number linked to a BVN, enrolment restricted to adults aged 18 and above, tighter access to BVN data, and device binding with a ₦20,000 cap on the first 24 hours of a new device.
The first four took effect on 1 May 2026, from a circular dated 12 March 2026. Device binding and the first-day cap followed on 1 July 2026 in a separate directive. Both are now in force, so the question for compliance and engineering teams is no longer what to build but what evidence exists that it works.
What Changed in the CBN BVN Regulations Update?
The CBN BVN regulations update changed five things: watchlisting, phone number changes, enrolment age, data access and device control. The amendments sit on top of the Revised Regulatory Framework for BVN Operations and Watch-List rather than replacing it.
Change
What institutions must do
In force
Temporary fraud watchlist
Maintain a watchlist for BVNs flagged in suspicious transactions, hold for a maximum of 24 hours, contact the customer and resolve
1 May 2026
One lifetime phone number change
Enforce a single change per BVN and rebuild recovery journeys that assumed repeat changes
1 May 2026
Age restriction on enrolment
Limit BVN enrolment to customers aged 18 and above
1 May 2026
Restricted data access
Confirm that BVN data is accessed only through CBN-licensed institutions or routes the CBN has approved
1 May 2026
Device binding and first-day cap
Allow one active device per customer, require fresh authentication on a new device, cap inflows and outflows at ₦20,000 for the first 24 hours
1 July 2026
Table 1 : BVN Rules changed by the CBN
Most published coverage of these new BVN rules was written for account holders. For institutions, each change is a workflow the CBN can examine, and each one has to produce a record.
When Did the New BVN Rules Take Effect?
The new BVN rules arrived in two waves: the circular of 12 March 2026 took effect on 1 May 2026, and the device binding directive followed on 1 July 2026. Treating them as one set of changes with one date is the most common error in internal policy documents written this year.
Date
Event
12 March 2026
CBN issues amendments to the Revised Regulatory Framework for BVN Operations and Watch-List
1 May 2026
Watchlist, phone number limit, age restriction and data access rules take effect
1 July 2026
Device binding and the ₦20,000 first-day cap take effect
Table 2: When did the CBN BVN's Rules Changed?
Each BVN update in this cycle amends the same instrument. The original framework dates to 12 October 2021, so any internal policy still referencing only that version is two cycles behind.
Who Must Comply With the CBN BVN Regulations Update?
The three organizations or groups that must comply with the CBN BVN new rules are deposit money banks, other financial institutions such as microfinance banks and payment service banks, and payment service providers including mobile money operators and fintech platforms. Any institution that opens accounts or wallets against a BVN is covered, and the BVN requirements are the same whichever licence the institution holds.
The weight is not evenly distributed. A bank with an established fraud desk is extending processes it already runs. A digital-first fintech now needs a 24-hour watchlist queue, a device registry and a customer contact workflow, often built from scratch, in the same year it is preparing for the automated AML deadline.
What Is the BVN Temporary Watchlist, and How Should Banks Run It?
The BVN watchlist is a list institutions must maintain for BVNs flagged in suspicious or potentially fraudulent transactions, holding each flagged BVN for a maximum of 24 hours while restrictions apply and the customer is contacted. It is a time-boxed review, not a permanent block, and the time box is what makes it demanding.
1. Detection: Deciding What Puts a BVN on the Watchlist
Your fraud rules now carry a second job. Beyond raising alerts, they must identify which alerts justify restricting a customer within minutes. Write the criteria down, approve them at the right level and keep the version history, because an examiner will ask why one customer was restricted and another was not.
2. Restriction: Applying Controls Without Freezing the Wrong Customer
Restrictions reach across accounts linked to the BVN, so the blast radius is wider than one account. Decide in advance what is blocked, what stays available and what a support agent can see when the customer calls. A legitimate customer restricted with no explanation is a churn event.
3. Resolution: Clearing or Escalating Inside 24 Hours
Twenty-four hours includes nights and weekends, so contact, clarification and a decision have to run on a rota rather than office hours. Define the escalation path for cases that cannot be cleared in time, including when the matter becomes a suspicious transaction report to the Nigerian Financial Intelligence Unit (NFIU).
4. Evidence: Logging Every Flag, Contact and Release
Record who flagged the BVN and why, when the customer was contacted, what they said, who released or escalated, and when. That log is the difference between a defensible control and a claim, and it feeds the audit trail the CBN Baseline Standards require.
How Does the One-Time BVN Phone Number Change Rule Affect Banks?
The BVN phone number change rule limits customers to a single change per lifetime, which removes the phone number as a flexible recovery channel and pushes recovery onto device and biometric checks. The rule targets SIM-swap fraud, where criminals take control of a number and use it to reset account access.
Three consequences follow for institutions. Recovery journeys built on sending a code to the registered number need a stronger second path. Support teams will meet customers who have already used their one change and cannot self-serve, so a documented exception process is needed. And proactive customer communication is cheaper than handling the complaint after someone is locked out.
What Does the BVN Age Limit Mean for Customer Onboarding?
The BVN age limit restricts enrolment to individuals aged 18 and above, so any onboarding flow that assumed a BVN for younger customers needs redesigning. Teen accounts, student products and guardian-linked wallets are the ones to review first.
Check three things: how onboarding validates date of birth before enrolment, which identity route remains available for under-18 products, and how existing records for customers enrolled below 18 are to be treated. Confirm that third point with your supervisor rather than assuming, since remediation on live accounts carries its own customer impact.
Who Can Access BVN Data Under the CBN BVN Regulations Update?
Access to BVN data is now restricted to CBN-licensed financial institutions. Third parties, including aggregators and informal verification services, are cut off unless expressly approved by the CBN. This is the change most likely to sit outside a compliance team's view, because it affects procurement and engineering rather than policy.
Two actions follow. Map every system, vendor and integration that touches BVN verification data today, and confirm the access route each one uses is licensed or approved. Then apply role-based access internally, so the number of staff who can read BVN records matches the number who genuinely need to.
This also supports obligations under the Nigeria Data Protection Act 2023, which governs how customer identity data is processed and secured.
How Does Device Binding Work Under the New BVN Rules?
Device binding allows a mobile banking app to be active on one device at a time, requires fresh multi-factor authentication when a customer moves to a new device, and caps inflows and outflows at ₦20,000 for the first 24 hours after activation. It took effect on 1 July 2026, separately from the May changes.
That turns the device into part of the identity record. Institutions need a registry linking customer, BVN and active device, with a controlled migration path, supported by real-time BVN verification and National Identification Number (NIN) checks with liveness.
It also creates a dependency worth naming in the risk register. When NIBSS or NIMC services slow or go offline, legitimate customers cannot migrate devices or complete onboarding, and no separate route exists to authorise them. Monitor those integrations like production infrastructure, because the failure appears as blocked customers rather than as an outage notice.
How Do the New BVN Rules Connect to the CBN Baseline Standards?
The CBN BVN regulations update and the CBN Baseline Standards for Automated AML Solutions ask for the same underlying capability: verified identity feeding live monitoring, alerts becoming managed cases with deadlines, and an audit trail behind every decision. Institutions treating them as separate projects will build the same thing twice.
A temporary watchlist is a case management workflow with a 24-hour service level. Device binding is a risk signal that belongs in the customer profile your monitoring reads. Real-time BVN and NIN checks are the identity layer the Baseline Standards already require, with deadlines of 10 September 2027 for banks and 10 March 2028 for other institutions. The wider framework is mapped in our guide to AML regulations in Nigeria, and the verification detail sits in the CBN KYC and AML requirements for 2026.
How Should Banks and Fintechs Implement the CBN BVN Regulations Update?
Banks and fintechs acan implement the CBN BVN regulations update by doing the following: building the watchlist queue, creating a device registry, planning for identity database downtime, rewriting recovery and support journeys, auditing who can reach BVN data, and loging every decision for examination.
1. Watchlist Queue: Build the 24-Hour Workflow First
Stand up the queue with named owners, a rota covering nights and weekends, clear entry criteria and a release decision. Connect it to fraud alerts so flagging is automatic, and test it with real cases before relying on it.
2. Device Registry: Bind, Re-Verify and Cap
Link each customer and BVN to one active device, trigger authentication and liveness on migration, and enforce the ₦20,000 first-day limit. Keep the device change history, since repeated migrations are themselves a fraud signal.
3. Downtime Planning: Treat NIBSS and NIMC as Critical Dependencies
Set up monitoring and alerting on those integrations with a documented response when they degrade, and agree in advance what customers are told while checks are unavailable.
4. Customer Journeys: Rewrite Recovery Paths and Agent Scripts
Update onboarding copy, in-app prompts and support scripts to cover the one-time phone change, the first-day cap and device migration. Most of the volume reaching your support line comes from customers who did not know the rule existed.
5. Data Access Audit: Know Every Route Into BVN Records
List the systems, vendors and integrations that touch BVN data, confirm each access route is licensed or approved, and document the review. Apply role-based access so only staff who need the data can see it.
6. Examination Evidence: Record Decisions, Not Just Outcomes
For every control, keep the rule that triggered it, who or what acted, the time and the resolution. Supervisors assess whether a control works in practice, and the log is how that is shown without relying on memory.
Meeting the CBN BVN Regulations Update With Youverify
The CBN BVN regulations update asks institutions to verify identity in real time, judge risk inside the session, restrict and release customers within 24 hours, and evidence every step. Youverify is built for that sequence, for Nigerian banks, fintechs and payment providers working to the same 2027 and 2028 deadlines.
Customer Onboarding runs document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier, which is exactly what device migration and new-account journeys now depend on. Fraud Insightsscores device and browser fingerprint, IP spoofing, incognito and Tor, emulators and remote tools, velocity and behaviour inside the same session, so a suspicious device change surfaces before money moves.
When a flag becomes a case, Case Management holds the queues, SLAs, the entity graph, evidence and a decision trail you can hand to an examiner, which is the shape a 24-hour watchlist needs. Transaction Monitoring applies rules and models on live flows, with typologies tuned to multi-currency, mobile money and cross-border corridors, so watchlist decisions draw on full customer behaviour rather than a single transaction.
Your fraud thresholds and customer treatment stay with your team. Youverify supplies the signals and the record behind each decision. Talk to our fraud team about your watchlist workflow and see how it runs end to end.
FAQs
Frequently Asked Questions
The new BVN rules introduce five changes: a temporary watchlist holding a flagged BVN for up to 24 hours, a lifetime limit of one change to the phone number linked to a BVN, enrolment restricted to people aged 18 and above, BVN data access limited to CBN-licensed institutions, and device binding with a ₦20,000 cap on the first 24 hours after activating a new device.
In two stages. The circular dated 12 March 2026 amended the Revised Regulatory Framework for BVN Operations and Watch-List, and those changes took effect on 1 May 2026. Device binding and the ₦20,000 first-day transaction cap followed separately on 1 July 2026. Both sets of rules are now in force.
The BVN watchlist is a list financial institutions must maintain for BVNs flagged in suspicious or potentially fraudulent transactions. A flagged BVN stays on it for a maximum of 24 hours while restrictions may apply to linked accounts and the institution contacts the customer to verify the transaction. It is a time-boxed review rather than a permanent restriction.
Once in a lifetime. Before 1 May 2026, customers could update the number linked to their BVN more than once. The restriction targets SIM-swap fraud. For institutions, it removes the phone number as a flexible account recovery channel and pushes recovery onto device binding and liveness verification instead.
BVN enrolment is limited to individuals aged 18 and above. Institutions offering products to younger customers, such as student accounts or guardian-linked wallets, need an alternative identity route. They should also confirm with their supervisor how existing records for customers enrolled below 18 are to be treated.
Only CBN-licensed financial institutions. Third parties including aggregators and informal verification services are cut off unless expressly approved by the CBN. Institutions should map every system, vendor and integration that touches BVN data, confirm each access route is licensed or approved, and apply role-based access internally.
Device binding means a mobile banking app can be active on only one device at a time. Logging in on a new device deactivates the previous one and triggers fresh multi-factor authentication, supported by real-time BVN and NIN checks with liveness. Inflows and outflows are capped at ₦20,000 for the first 24 hours after activation. It took effect on 1 July 2026.
Yes. The rules apply to deposit money banks, other financial institutions, payment service providers, mobile money operators and fintech platforms. Any institution opening accounts or wallets against a BVN must run the temporary watchlist, enforce device binding and apply the first 24-hour transaction cap.