Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

CBN POS Guidelines and Fraud Monitoring for PSPs
Anti-Money Laundering (AML)

CBN POS Guidelines and Fraud Monitoring for PSPs

ByTemitope Lawal
September 29, 2026•5mins Read

Key Takeaways

 

  • 1. Terminals must connect to both NIBSS and UPSL, and switch automatically if one goes down. This has applied since 11 January 2026.
  • 2. Every terminal must be tagged with its location, and new devices must be tagged before they are switched on.
  • 3. Terminals must operate within 70 metres of their registered address. Enforcement started 1 August 2026.
  • 4. Agent location and exclusivity rules started on 1 April 2026.
  • 5. A terminal working outside its registered area breaks a rule and, more often than not, signals fraud.
  • 6. POS is also a channel under the CBN Baseline Standards, so terminal activity must feed your AML monitoring by 10 March 2028.

The CBN POS guidelines now ask payment service providers to do four things: connect every terminal to both routing networks, tag each terminal with its location, keep it working within 70 metres of that location, and follow the agent location and exclusivity rules. Every deadline has passed, so the question is no longer whether you have done it. It is whether you can prove it.

 

Most articles about these rules treat them as a fix for POS downtime. They are also fraud controls. Once a terminal reports where it is and which route it used, several common POS scams become visible for the first time.

 

What Are the CBN POS Guidelines?

The CBN POS guidelines are a set of circulars from the CBN's Payments System Supervision Department about how POS terminals are routed, located and supervised.

 

Four rules matter most, and all four are already in force.

 

RuleWhat it means in practiceIn force since
Location taggingEvery terminal is registered to an address. New devices are tagged before activationOctober 2025
Dual connectivityEach terminal connects to both routing networks, NIBSS and UPSL, and switches over automatically if one fails11 January 2026
Agent location and exclusivityAn agent works for one provider only, from a registered location1 April 2026
Geo-fencingA terminal must stay within 70 metres of its registered address, up from 10 metres1 August 2026

 

The thinking behind them is simple. Each rule ties a terminal to a place, a route and a company that answers for it. Together they remove the anonymity that made POS terminals useful to fraudsters.

 

Who Must Follow the POS Rules by the CBN?

 

The rules apply to six groups: banks and other financial institutions, acquirers, processors, payment terminal service providers, the two aggregators that route transactions, and the super agents and agent networks that hand out terminals.

 

Responsibility travels upward. The company that owns the merchant or agent relationship answers for what happens at the terminal, even though someone else is standing behind the counter. So terminal data needs to reach a monitoring system, not sit in a deployment spreadsheet.

 

What Does Dual Connectivity Actually Require?

Dual connectivity means every POS transaction can travel through either of Nigeria's two routing networks, NIBSS and Unified Payment Services Limited, and switches automatically when one has problems. It came in a circular dated 11 December 2025, took effect on 11 January 2026, and requires regular testing of that switchover.

Fraud teams should care about this for two reasons.

 

First, a terminal's transactions can now arrive through either network. If your monitoring only reads one feed, you are seeing half the picture, and any rule about how much a terminal is doing will be wrong.

 

Second, switching networks mid-transaction can create duplicates and reconciliation gaps. That confusion is exactly what refund and reversal fraud relies on.

 

What Is POS Geo-Fencing, and What Changed in 2026?

 

Geo-fencing means a terminal can only be used within a set distance of the address it was registered to. A circular dated 29 May 2026 widened that distance from 10 metres to 70 metres and moved enforcement to 1 August 2026. Proof of compliance was due to the CBN by 31 July 2026.

 

The wider radius was not the CBN going soft. At 10 metres, terminals inside big shops, upstairs offices or crowded markets were flagged even though nothing was wrong, because location readings drift. Seventy metres removes most of those false alarms.

That matters for how you treat alerts. With fewer false alarms built in, a terminal reporting outside its fence today is a real exception. It deserves a look, not a tolerance setting.

 

Why Is Terminal Location a Fraud Signal?

 

Location data shows four things your transaction rules cannot: terminals that have been moved, several unrelated terminals operating from one address, activity at hours that do not match the business, and shops whose registered type does not match where the device actually is.

 

Moved terminals are the clearest case. A device registered to a shop in Lagos but transacting in another state is the classic pattern in cash-out schemes and in terminals passed on to informal operators. Before location tagging, all you could see was transaction volume, which looks normal until the chargebacks arrive.

 

Clusters are the second. Several terminals, registered to different merchants, all working from the same spot usually means either an operator working outside its permissions or someone running a bank of devices. You only see it once location is treated as real data about the customer.

 

Which POS Fraud Patterns Should PSPs Watch For?

 

Five patterns are worth building rules around: moved terminals, customers splitting cash across agents, merchants abusing refunds, stolen card data being tested, and money landing in accounts that do not match the business.

 

1. Moved Terminals: Devices Working Far From Home

 

Alert whenever a terminal transacts outside its registered area, and watch for devices that keep doing it. How long a terminal stays outside its fence matters too. A brief drift is not the same as a device that has clearly been relocated and kept in use.

 

2. Split Cash: One Customer, Several Agents

 

Agent banking caps deposits and withdrawals at ₦100,000 a day and ₦500,000 a week per customer. Anyone moving more simply spreads it across different agents, and each transaction looks fine on its own. You only catch it by following the customer across the whole network, not the terminal.

 

3. Refund Abuse: Money Going Back Without Sales Going Out

 

Watch for refunds that do not match sales, reversals piling up on a few terminals, and transactions reversed soon after approval. Because dual routing makes reconciliation harder, these patterns need their own rules rather than being left to month-end checks.

 

4. Stolen Cards: Small Test Payments Before Big Ones

 

Fraudsters test stolen card details with tiny amounts before spending properly. Look for small payments followed by large ones, the same cards appearing on terminals that have no connection, and unusual numbers of declines.

 

5. Suspicious Settlement: Where the Money Ends Up

 

Terminal fraud always ends in a settlement account. Watch for one account receiving settlements for merchants who are supposedly unrelated, money moved out immediately after it lands, and account activity that does not match the business it was opened for.

 

How Do the POS Rules Connect to Agent Banking and AML Rules?

 

These rules overlap with two others: the agent banking guidelines, which make you responsible for checking, training and monitoring your agents, and the CBN Baseline Standards, which require automated AML monitoring across every channel by 10 March 2028.

 

The overlap is deliberate. Location and exclusivity enforcement began on the same day under the CBN agent banking guidelines, and the monthly report those guidelines require includes fraud cases, which is the same information your POS monitoring produces. The CBN AML requirements for fintechs and PSPs then expect monitoring to cover every channel, POS included, as transactions happen.

 

Handle these as three projects and you get three systems and three reports that disagree with each other. Handle them once and terminal, agent, customer and settlement data sit in one place. The full picture is in our guide to AML regulations in Nigeria.

 

How Should PSPs Set Up POS Fraud Monitoring?

 

There are six practical steps for payment sev: give every terminal a record, alert on location breaches, learn what normal looks like for each terminal, connect terminals to the people behind them, give alerts somewhere to go, and pull your reports from the same place.

 

1. Terminal Records: Know Every Device and Who Owns It

Keep the terminal ID, registered address, deployment date, the agent or merchant behind it, and the account it settles into, all in one record. A terminal nobody owns in your system cannot be investigated when it misbehaves.

 

2. Location Alerts: Treat a Breach as Something to Act On

When a terminal works outside its 70 metre area, send it to someone for review rather than writing it to a report nobody opens. Keep the history, because a device that breaches repeatedly tells a different story from one that drifted once.

 

3. Normal Behaviour: Compare Each Terminal to Itself

Work out what a terminal should be doing based on its business type, location and how long it has been deployed, then alert when it drifts. A new rural terminal doing city-centre volume in its second week is the kind of thing a single company-wide limit will always miss.

 

4. Connections: Link the Terminal, Agent, Customer and Account

Fraud shows up in the links. Connect the device to the agent, the agent to your business, the customer to everything they do across terminals, and the terminal to where the money settles. Split cash and suspicious settlement patterns only appear once those links exist.

 

5. Investigation: Decide Who Acts and What Happens Next

Agree who reviews a location breach, who can switch off a terminal, and when the case becomes a suspicious transaction report to the NFIU. Write down each decision and the reason behind it.

 

6. Reporting: One Source for Every Return

Your geo-fencing evidence, agent banking monthly report and AML filings should all come from the same records. Pulling three spreadsheets together under deadline is how contradictions reach the regulator.

 

Meeting the CBN POS Guidelines With Youverify

 

Meeting the CBN POS guidelines means showing that every terminal is where it should be, doing what it should be doing, and settling into an account you can explain. Youverify gives Nigerian payment providers, acquirers and agent networks the monitoring and the paper trail behind those answers.

 

Fraud Insights scores device and browser fingerprint, IP spoofing, incognito and Tor, emulators and remote tools, velocity and behaviour inside the same session, so a device acting out of character shows up while the transaction is still live. Transaction Monitoring applies rules and models on live flows, with typologies tuned to multi-currency, mobile money and cross-border corridors, which is how split cash across agents and unusual terminal activity get caught.

When something needs investigating, Case Management holds the queues, SLAs, the entity graph, evidence and a decision trail you can hand to an examiner. That entity graph is what ties a terminal to its agent, its customers and its settlement account, turning scattered alerts into one story. Customer Onboarding covers the front end, running document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier, for the merchants and agents behind those terminals.

 

Decisions about suspending a terminal or dropping a merchant stay with your risk team. Youverify makes sure you see the signal early and still have the record months later. Book a session with our fraud team to look at how your terminals are monitored to

FAQs

Frequently Asked Questions

Related Articles

Why is Negative News Screening (NNS) Important?
Anti-Money Laundering (AML)
Lola, Edited by Emmanuel Agwu•April 25, 2023

Why is Negative News Screening (NNS) Important?

Read More
What is a Sanctions List?
Anti-Money Laundering (AML)
Priscilla, Edited by Emmanuel Agwu•April 28, 2023

What is a Sanctions List?

Read More
RegTech's Influence On Regulatory Policy and Reform
Anti-Money Laundering (AML)
Emmanuel Agwu•February 14, 2024

RegTech's Influence On Regulatory Policy and Reform

Read More