Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

Customer Due Diligence and Enhanced Due Diligence in Nigeria
Anti-Money Laundering (AML)

Customer Due Diligence and Enhanced Due Diligence in Nigeria

ByTemitope Lawal
October 1, 2026•5mins Read

Key Takeaways

 

  • 1. Customer due diligence has four requirements: identify the customer, verify the identity, identify the beneficial owner, and monitor the relationship on an ongoing basis.
  • Due diligence can be simplified, standard or enhanced, decided by your own risk assessment.
  • 2. Enhanced due diligence is mandatory for politically exposed persons, non-resident customers, money or value transfer service providers, private banking customers, non-face-to-face customers and anyone linked to a country flagged by the Financial Action Task Force (FATF).
  • 3. Most domestic politically exposed persons are treated as high risk by default under CBN guidance.
  • 4. Customer files must be reviewed every 12 months for high risk, 18 months for medium risk and three years for low risk.
  • 5. Records must be kept for at least five years after a relationship ends.
  • 6. The CBN Baseline Standards require this to run automatically by 10 September 2027 for banks and 10 March 2028 for other financial institutions.

Customer due diligence (CDD) is the process of identifying a customer, verifying that identity against an independent source, establishing who ultimately owns or controls the account, and monitoring the relationship over time. Enhanced due diligence (EDD) is the deeper version applied to higher-risk customers, and in Nigeria it is mandatory, not discretionary.

 

The rules come from three places: section 4 of the Money Laundering (Prevention and Prohibition) Act 2022, the Central Bank of Nigeria (CBN) AML/CFT/CPF Regulations 2022, and the CBN Customer Due Diligence Regulations 2023. The last of these is the most detailed, and it is the one most compliance teams have not read closely.

 

What Is Customer Due Diligence?

 

Customer due diligence is the set of checks a financial institution carries out to establish who its customer is, who stands behind them, and what financial crime risk the relationship carries. It applies when the relationship starts and continues for as long as it lasts.

 

In Nigeria the duty sits in section 4 of the Money Laundering (Prevention and Prohibition) Act 2022, which applies to financial institutions and to designated non-financial businesses and professions. The CBN Customer Due Diligence Regulations 2023, made on 31 May 2023, add detail for every institution the CBN supervises.

One rule comes before all the others. Institutions cannot open, operate or maintain anonymous or fictitious-name accounts. A relationship cannot begin until the customer is actually known.

 

What Are the Four Customer Due Diligence Requirements?

 

Customer due diligence has four core requirements: customer identification, identity verification, beneficial ownership identification, and ongoing monitoring of the relationship. Nigerian law adds a fifth duty, which is verifying anyone acting on the customer's behalf.

 

RequirementWhat it means in practice
Identify the customerCollect full name, date of birth and a residential address where the customer can actually be located
Verify the identityCheck that information against reliable, independent sources such as the Bank Verification Number (BVN) and National Identification Number (NIN) databases
Identify the beneficial ownerEstablish the ultimate beneficial owner, the natural person who ultimately owns or controls a corporate customer
Verify representativesApply the same identification and verification steps to directors, signatories and anyone acting for the customer
Monitor on an ongoing basisCheck that activity matches the customer's known profile and keep the information current
4 customer due diligence requirements

 

Collecting a document is not verification. The Act asks institutions to verify identity against reliable independent sources, which in practice means checking authoritative databases rather than accepting an uploaded identity card at face value.

 

What Is the Difference Between KYC and Customer Due Diligence?

 

Know your customer (KYC) is the identification and verification work carried out at onboarding. Customer due diligence is broader: it includes KYC, then adds beneficial ownership, risk assessment and ongoing monitoring for the life of the relationship.

Put simply, KYC answers "who is this person?" Due diligence answers "who is this person, who is behind them, what risk do they bring, and is their behaviour still consistent with what they told us?"

 

In Nigeria the two connect through tiered KYC. The CDD Regulations require institutions to apply tiered KYC measures for individual customers, where verification depth determines the transaction and balance limits on the account. The tier structure is set out in our guide to the CBN KYC and AML requirements for 2026.

 

Which Laws Govern Customer Due Diligence in Nigeria?

 

Four instruments govern due diligence in Nigeria: the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, the CBN AML/CFT/CPF Regulations 2022 and the CBN Customer Due Diligence Regulations 2023.

 

InstrumentWhat it contributes
Money Laundering (Prevention and Prohibition) Act 2022Section 4 sets the statutory due diligence duties and the penalties for failing them
Terrorism (Prevention and Prohibition) Act 2022Adds sanctions screening and freezing duties on confirmed matches
CBN AML/CFT/CPF Regulations 2022Turns the statutory duties into supervisory rules for CBN-licensed institutions
CBN Customer Due Diligence Regulations 2023Adds detailed measures: higher-risk categories, review cycles, correspondent banking, trusts, electronic KYC
Laws Governing Customer Due Diligence in Nigeria

 

The 2023 Regulations are the operational layer. They were issued under the other three instruments and are read alongside the AML/CFT/CPF Regulations rather than in place of them. The wider framework, including reporting duties to the Nigerian Financial Intelligence Unit (NFIU), is mapped in our guide to AML regulations in Nigeria.

 

When Must a Nigerian Institution Carry Out Due Diligence?

 

Due diligence is required at five points: when a business relationship is established, when an occasional transaction crosses the prescribed threshold, when carrying out a wire transfer, whenever money laundering or terrorist financing is suspected, and whenever there is doubt about information collected previously.

 

Two of those override everything else. Suspicion removes the threshold entirely, so the amount becomes irrelevant. Doubt about existing records triggers fresh verification, which means a long-standing customer whose file no longer adds up cannot be left alone because they were onboarded years ago.

 

For casual customers the Money Laundering Act sets the threshold at the equivalent of US$1,000. Linked transactions that together cross that line are treated as one, which is why structuring detection and due diligence belong in the same system.

 

What Are the Three Levels of Customer Due Diligence?

 

Nigerian rules recognise three levels: simplified due diligence, standard due diligence and enhanced due diligence. The level applied depends on the risk presented by the customer, product, channel or transaction, based on the institution's own documented risk assessment.

 

LevelWhen it appliesWhat it adds
SimplifiedLower-risk customers, where the risk assessment supports it. Never where there is suspicionReduced verification depth and lighter ongoing checks, still identity-based
StandardMost customersThe four requirements above, plus understanding the purpose of the relationship
EnhancedHigher-risk customers and situations named in the CDD RegulationsSource of funds and wealth, senior management approval, deeper ownership work, closer monitoring
Levels of Due Diligence

Simplified does not mean skipped. It means proportionate, and the institution must be able to produce the risk assessment that justified the lighter approach.

 

What Information Does Customer Due Diligence Require You to Collect in Nigeria?

 

The CDD Regulations expanded the information institutions must obtain. For individuals it is the identity set plus BVN or NIN. For corporate customers it reaches into ownership documents and senior management, which many older onboarding checklists do not cover.

Individual customersCorporate customers and legal arrangements
Full name, date of birth and a traceable residential addressCertificate of incorporation and constitutional documents
BVN and NIN, verified against the relevant databaseLegal documents identifying persons with significant control
Valid government-issued identificationIdentification documents of those persons with significant control
Contact details, including social media handlesIdentification of people in senior management positions
Source of funds or wealth where requiredNature and purpose of the business relationship

 

A corporate file is really several individual files attached to a company record, because directors, signatories and beneficial owners each go through the same identification and verification steps as an individual customer.

 

The social media handle requirement, introduced by the 2023 Regulations, has drawn pushback from the National Assembly and the Nigeria Data Protection Commission on data protection grounds. Institutions should take their own legal advice on how far to apply it.

 

When Is Enhanced Due Diligence Mandatory in Nigeria?

 

Enhanced due diligence is mandatory for six categories named in the CBN Customer Due Diligence Regulations: politically exposed persons, non-resident customers, money or value transfer service providers, private banking customers, customers onboarded without a face-to-face meeting, and customers connected to countries flagged by the FATF.

 

Three further situations trigger it. Opaque trust or foundation arrangements, where the structure obscures who benefits. Correspondent banking relationships, which carry their own regime. And any relationship your own risk assessment rates high, whatever category it falls into.

 

Correspondent banking is worth separating out. Institutions must establish whether the correspondent or counterparty is itself regulated for anti-money laundering purposes. Where it is not, additional checks on that institution's policies and KYC procedures are required. Relationships with shell banks are prohibited, and staff handling these accounts must be trained specifically for them.

 

What Does Enhanced Due Diligence Involve?

 

Enhanced due diligence adds four things to standard checks: establishing where the money comes from, obtaining senior approval before proceeding, tracing ownership to the real people behind the customer, and monitoring the relationship more closely afterwards.

 

1. Source of Funds and Source of Wealth: Two Separate Questions

 

Source of funds is where the money in this transaction came from. Source of wealth is how the customer built their assets overall. A customer can answer one convincingly and not the other, and that gap is usually where the problem shows. Record the explanation and the supporting evidence, not just the conclusion.

 

2. Senior Management Approval: A Decision With a Name Against It

For foreign politically exposed persons, senior management must approve the relationship before it begins or continues. Record who approved it and when. An enhanced due diligence file with no identifiable approver is a gap an examiner finds quickly.

 

3. Ownership and Control: Follow the Chain to a Person

Layered ownership is the standard way this duty is defeated. Trace control to the natural person who ultimately owns the customer and document how you got there. Where the structure is opaque, the Regulations expect additional work rather than a note saying the owner could not be determined.

 

4. Enhanced Monitoring: Tighter Rules After Onboarding

Higher-risk relationships need closer ongoing monitoring, not just a heavier onboarding file. In practice that means tighter alert thresholds, more frequent review, and a defined escalation route when activity stops matching what the customer described.

 

How Are Politically Exposed Persons Treated Under Nigerian Due Diligence Rule?

 

CBN guidance applies a risk-based approach to politically exposed persons, with one significant default: most domestic politically exposed persons are considered high risk. Foreign and high-risk politically exposed persons require enhanced due diligence as standard, whether they are the customer or the beneficial owner behind one.

 

The guidance also covers change. If a customer becomes politically exposed, or their exposure changes, the institution must reassess the risk, apply enhanced measures where the customer is now high risk or foreign, and adjust transaction monitoring to reflect it. That makes this a screening and monitoring duty, not only an onboarding one.

Records should capture why the classification was made: the position held, the country, and how long it was held. A classification with no reasoning behind it is difficult to defend during an examination.

 

How Often Must Customer Due Diligence Files Be Reviewed?

 

The CDD Regulations set review cycles by risk rating: every 12 months for high-risk customers, every 18 months for medium-risk customers and every three years for low-risk customers. Institutions must also apply due diligence requirements to existing customers on the basis of materiality and risk.

That second duty creates most of the work. Customers onboarded under older rules, with files that have never been refreshed, remain the institution's responsibility today. Most remediation programmes running in Nigerian banks exist because this requirement was treated as tomorrow's problem.

Records from the whole process must be kept for at least five years after the relationship ends or the occasional transaction completes, and must be retrievable quickly when a regulator asks. Archived records that take weeks to produce fail that test even though they exist.

 

What Makes Customer Due Diligence Difficult in Practice?

 

Four problems come up repeatedly: customer data that does not match across sources, a backlog of existing customers whose files predate current rules, source of funds checks that depend on documents nobody verifies, and alert volumes larger than the team reviewing them.

 

The last one is worth naming plainly. Enhanced monitoring produces more alerts, and alerts need investigators. A monitoring configuration set without regard to team capacity creates a backlog, and a backlog of unreviewed alerts is itself a supervisory finding.

The first problem is the most solvable. Verification against BVN, NIN and corporate registry data at the point of onboarding removes most downstream mismatches, because the record starts out matching an authoritative source instead of a typed form.

 

What Do the CBN Baseline Standards Change About Customer Due Diligence?

 

The CBN Baseline Standards for Automated AML Solutions, issued on 10 March 2026, expect due diligence to be automated and connected to monitoring. Banks must comply fully by 10 September 2027, and fintechs, payment service providers and other non-bank institutions by 10 March 2028.

 

Three things change for due diligence teams. Verification must run against authoritative databases rather than submitted documents. Customer risk profiles must update as behaviour changes, instead of holding a score set at onboarding. And every decision, including the risk rating and the reasoning behind it, must leave an audit trail that can be produced on demand.

 

Implementation roadmaps were due to the CBN Compliance Department by 10 June 2026, so supervisors already hold each institution's own plan and can measure delivery against it.

 

What Are the Penalties for Failing Customer Due Diligence in Nigeria?

 

Failures are penalised on two tracks. The CBN applies administrative sanctions under the Banks and Other Financial Institutions Act 2020, including fines and licence action. Separately, the Money Laundering Act penalises breaches of its due diligence provisions with ₦10 million or at least three years' imprisonment for individuals, and ₦25 million for a company.

 

Failing to maintain the internal AML programme that supports due diligence, including compliance officers and an internal audit unit, attracts ₦5 million for a bank under section 10 of the Act, alongside possible suspension of licence.

 

Supervisory penalties are already running at scale. A review of annual reports by Prime Business Africa found the CBN fined nine listed banks about ₦17.35 billion in 2024, with anti-money laundering findings among the reported infractions. Smaller cases make the same point at control level: one tier-one bank was penalised ₦13 million for failing to verify a customer's identity and delaying a related transaction report.

 

Running Customer Due Diligence and Enhanced Due Diligence With Youverify

 

Customer due diligence and enhanced due diligence in Nigeria come down to three things working together: verification you can evidence, risk scoring that keeps pace with the customer, and a file that still makes sense five years later. Youverify builds all three for Nigerian banks, fintechs and payment providers.

 

Customer Onboarding runs document, anti-deepfake liveness and government-source checks in one journey, scored to a risk tier. That covers identification, verification against BVN, NIN and company registry data, and the risk rating that decides whether standard or enhanced measures apply. Politically exposed person and sanctions screening runs in the same flow, so a customer who belongs on the enhanced path is identified before the account opens.

 

Transaction Monitoring applies rules and models on live flows, with typologies tuned to multi-currency, mobile money and cross-border corridors, which is what the ongoing half of due diligence actually requires. When behaviour stops matching the profile, Case Management holds the queues, SLAs, the entity graph, evidence and a decision trail you can hand to an examiner.

 

Risk appetite and approval decisions stay with your compliance team, as the rules intend. Youverify supplies checks that run in seconds and a record that survives the audit. Book a demo with our compliance experts to see your due diligence process run end to end.

FAQs

Frequently Asked Questions

Related Articles

Why is Negative News Screening (NNS) Important?
Anti-Money Laundering (AML)
Lola, Edited by Emmanuel Agwu•April 25, 2023

Why is Negative News Screening (NNS) Important?

Read More
What is a Sanctions List?
Anti-Money Laundering (AML)
Priscilla, Edited by Emmanuel Agwu•April 28, 2023

What is a Sanctions List?

Read More
RegTech's Influence On Regulatory Policy and Reform
Anti-Money Laundering (AML)
Emmanuel Agwu•February 14, 2024

RegTech's Influence On Regulatory Policy and Reform

Read More