FINTECH REGULATION IN NIGERIA; FREQUENTLY ASKED QUESTIONS

FINTECH REGULATION IN NIGERIA; FREQUENTLY ASKED QUESTIONS

By Aderonke Alex-Adedipe and Sharon Okpo

DOWNLOAD PUBLICATION

Introduction

In recent years, the Nigerian financial technology (FinTech) ecosystem has witnessed an unprecedented surge in groundbreaking technologies, disrupting traditional financial services and revolutionizing the way we transact, invest, and manage our finances. From peer-to-peer lending platforms to mobile payment solutions and blockchain-based innovations, the realm of FinTech has captured the imagination of investors and consumers alike.

With these revolutionary advancements, however, comes a myriad of legal considerations and regulatory complexities which FinTech companies must navigate to ensure their success and longevity in this ever-evolving industry.  This newsletter seeks to provide answers to inquiries often made about the legal considerations for operating in the Nigerian Fintech environment.

  1. What is the most suitable Corporate for fintech businesses?

The Companies and Allied Matters Act (CAMA), 2020 provides for various structures that may be adopted by businesses such as limited liability and unlimited liability companies, limited liability partnerships, limited partnerships, business names, and incorporated trustees. The most appropriate structure for a fintech to adopt is that of a limited liability company.

Incorporating your FinTech business as a limited liability will not only provide a distinction of the shareholders’ personal assets from that of the company but also helps in protecting shareholders against personal liability which may arise in the operation of the business. It will also boost investor confidence in the business, as equity ownership in a limited liability company can easily be transferred.

In addition, incorporating as a limited company, in general, will also aid in compliance with certain regulatory requirements and obtaining relevant licences required for the operation of a FinTech business in Nigeria. For instance, the Central Bank of Nigeria’s (CBN) minimum capital requirements for payment services providers and payment service banks, and the requirement to establish a holding company structure for businesses wishing to operate under more than one licence category provided by the CBN.

  1. Is there a single regulatory framework for FinTechs in Nigeria?

Unlike other sectors within Nigeria which may operate under a single or centralized body of laws governing their businesses (e.g the traditional banks having the CBN Act, and the Banks and Other Financial Institutions Act (BOFIA), 2020 as their primary legislations), there is no single/primary legislation governing or regulating Fintech in Nigeria. There are however various laws and regulations which may be applicable to various aspects of the Fintech business. The CBN being the primary body responsible for regulating the financial sector in Nigeria has a plethora of regulations that are applicable to various aspects of the Fintech business some of which include:

  1. CBN Guidelines on Open Banking, 2023
  2. The CBN Guidelines on Mobile Money Services in Nigeria, 2015
  3. The CBN Guidelines on International Mobile Money Remittance Service in Nigeria, 2015.
  4. The CBN Guidelines on International Money Transfer Services in Nigeria, 2014
  5. The CBN Guidelines on Finance Companies in Nigeria
  6. The CBN Guidelines for Licensing and Regulation of Payments Service Banks in Nigeria, 2018, etc.

In addition to these regulations listed above, there are other regulations which may apply to certain Fintech companies depending on their operations, some of which are listed below;

  1. CAMA 2020, which is applicable to all companies and business registered in Nigeria.
  2. Federal Competition and Consumer Protection Act, 2018
  3. Money Laundering (Prohibition) Act, 2018
  4. Economic and Financial Crimes Commission (Establishment) Act, 2004
  5. Nigerian Data Protection Act (NDPA), 2023
  6. Banks and Other Financial Institutions Act, 2020
  7. Foreign Exchange (Monitoring and Miscellaneous) Provision Act, 1995
  8. Advance Fee Fraud and other Fraud Related Offences Act, 2006
  9. Securities and Exchange Commission (SEC) Rules for the Registration of Virtual Assets Service Providers, 2022
  10. SEC Rules on Issuance, Offering Platform(s), and Custody of Digital Assets,
  11. SEC Rules on Digital Assets Exchange, 2022, etc.
  1. Who are the Key Regulators in the Nigerian Fintech Sector?

There are various regulatory bodies exercising oversight of various aspects of the Fintech business in Nigeria some of which include;

  1. The CBN– exercising oversight for payment service providers, bureau de change companies, digital banks, payment service banks, etc.
  2. The FCCPC– exercising oversight in relation to mergers and/or acquisitions, competition and consumer protection regulatory functions.
  3. The Nigerian Data Protection Commission (NDPC)- regulating how companies collect, store, and process personal data in order to safeguard the rights of data subject.
  4. SEC- where the business of the FinTech involves trading in digital assets and other capital market activities.
  5. The National Office for Technology Acquisition and Promotion (NOTAP)- where the company imports foreign technology in the course of its business such as the use of patented inventions, supply of technical expertise, etc. the company will be required to register such technology transfer agreement.
  1. What Licence is required to operate a fintech business in Nigeria?

The nature of the license required is dependent on the specific service to be provided by the fintech business. Some of the most sought after licenses are highlighted below:

  1. Money lender’s licence– this applies to FinTechs providing digital lending solutions to customers. This licence is to be obtained from the State within which the business intends to operate.
  2. Payment Service Providers Licence– some of the licences obtainable here include the mobile money operation licence, the switching and processing licence, payment solutions service provider licence, payment terminal service provider licence, super-agent licence and payment solution services licence.
  3. Microfinance Bank Licence– this licence is obtainable from the CBN, and allows the company carry on such activities such as;
    • Acceptance of deposit
    • Provision of microloans
    • Provision of credit to customers
    • Issuance of debentures
    • Provision of banking activities to customers (limited to domestic remittance of funds), etc.

iv.  Sub-broker Licence- this applies to Fintechs that offer a digital platform for others to invest in and purchase shares and stocks form foreign companies. This licence is obtainable from the SEC.

  1. What are the compliance requirements for Fintech in Nigeria?
  1. Anti-Money Laundering (AML)/Know-Your-Customer (KYC) Policy– Fintech companies are required to establish and maintain robust AML/KYC policies to prevent financial fraud and financing terrorist activities.
  2. Data Protection- Fintechs are also required to ensure that their data protection policies are efficient and effective in protecting the data of the users of their platform(s) and service(s). They are also required to file yearly reports of data audit conducted with the NDPC to ensure continued compliance with the requirements of the NDPA.
  3. Annual Returns and Corporate Governance- Fintechs like other companies incorporated under CAMA are also required to file their annual returns as and when due. They are also required to establish a proper corporate governance structure and generally comply with requirements established by their regulators.

REGULATORY UPDATE: CBN’S NEW CORPORATE GOVERNANCE GUIDELINES FOR BANKS (COMMERCIAL, MERCHANT, NON-INTEREST, AND PAYMENT SERVICES BANKS)

REGULATORY UPDATE: CBN’S NEW CORPORATE GOVERNANCE GUIDELINES FOR BANKS (COMMERCIAL, MERCHANT, NON-INTEREST, AND PAYMENT SERVICES BANKS)

By Seun Timi-Koleolu and Qasim Ogunjimi

DOWNLOAD PUBLICATION 

On the 13th of July, 2023, the Central Bank of Nigeria (“CBN”) made a significant stride in reinforcing the nation’s financial sector by issuing the Corporate Governance Guidelines for Commercial, Merchant, Non-interest, and Payment Services Banks (the “Guideline“). These guidelines are set to take effect on August 1, 2023, ushering in a new era of corporate governance for the banking/financial sector.

At Pavestones, we understand the significance of proactive adaptation to new regulatory standards. In this newsletter, we provide a concise overview of the Guideline’s key provisions, focusing on its impact, applicability, and some significant changes from the previous version, Code of Corporate Governance for Banks and Discount Houses (the  “Code”).

KEY PROVISIONS AND THEIR IMPLICATIONS:

This Guideline introduces crucial provisions that demand meticulous attention from the financial industry In this section, we highlight some of the key provisions that Banks must adhere to:

  1. APPLICABILITY: In addition to the Nigeria Code of Corporate Governance (“NCCG”) 2018, the Guidelines apply to all Commercial, Merchant, Non-interest, and Payment Service Banks (herein collectively referred to as “Banks”) in Nigeria. Unlike the Code, the scope of application of the Guideline is broader as it applies to not only commercial banks but also merchant, non-interest and payment service banks. This wider scope is indicative of the regulatory authorities’ concerted effort to address a more extensive range of financial institutions and foster robust governance practices across various banking sub-sectors.
  2. BOARD STRUCTURE & COMPOSITION: Diverging from the Code’s stipulation of a minimum of 5 (Five) and a maximum of 20 (Twenty) directors, the Guideline prescribes that Banks must maintain a board of at least 7 (Seven) directors and not exceed 15 (Fifteen) directors. With respect to the composition of the board, the Guideline requires that the board of commercial banks with international and national authorization, merchant banks, and Non-Interest Banks (“NIBs”) with national authorization should have at least 3 (Three) independent non-executive directors (“INEDs”), while payment service banks (PSBs), commercial banks with regional authorization, and NIBs with regional authorization should have at least 2 (Two) INEDs. These adjustments represent a departure from the Code’s requirement of 2 (Two) INEDs and are designed to enhance the governance structure and independence of boards across different categories of banks. By imposing higher INED quotas, the Guideline aims to bolster transparency, accountability, and prudent decision-making within the banking sector. Additionally, regarding the committees of the board, the Guideline requires that Banks should in addition to the typical committees have a Board Credit Committee (BCC) with oversight responsibility on credit matters.
  3. COMPLIANCE AND IMPLEMENTATION: To ensure regulatory compliance and accountability across control functions (e.g., audit, risk management, finance, AML/CFT/CPF) and operational areas like foreign exchange transactions, IT, and cyber-security, the Guideline mandates the appointment of an Executive Compliance Officer (“ECO”) in addition to the Chief Compliance Officer (CCO) as in the Code. The ECO will also be responsible for the prompt reporting of all regulatory infractions and concerns to the Board for resolution.
  4. NON-INTEREST BANKS: Acknowledging the unique nature of Non-Interest Banks (NIBs), the Guideline presents tailored provisions concerning their internal audits and compliance functions. NIBs are mandated to establish a Shariah Review/Compliance (SRC) function, responsible for regular assessments to ensure alignment with shariah requirements in their operations and activities. Additionally, NIBs must appoint an Internal Shariah Auditor (ISA) as the head of the internal shariah audit function, holding a position not lower than Assistant General Manager. These provisions aim to reinforce adherence to shariah principles and bolster transparency within Non-Interest Banks.
  5. SANCTIONS: Adherence to the Guidelines is of utmost importance, as any failure by a Bank to comply with the requirements outlined therein and the recommended practices in NCCG 2018 will be considered a regulatory breach. Such breaches shall attract penalties as prescribed by the CBN. In the event of a breach by a director, manager, or officer, they will face appropriate sanctions, including monetary penalties and administrative measures. The responsible individual may be subject to a six-month suspension from their position on the Bank’s board and possible removal in instances of continued recurrence of the breach.

CONCLUSION

In conclusion, the Central Bank of Nigeria’s new Corporate Governance Guidelines for Commercial, Merchant, Non-interest, and Payment Services Banks signify a transformative shift in the financial sector. With a broader scope of applicability and enhanced board structure requirements, these Guidelines promote transparency, accountability, and prudent decision-making. It is vital for Banks to adhere to the provisions of the Guideline not only to avoid potential sanctions by CBN but also to ensure long-term success in this dynamic banking sector. For further information on the key provisions of the Guideline, please do not hesitate to contact us!

 

NIGERIA’S PAYMENT SYSTEM: CENTRAL BANK OF NIGERIA GUIDELINES ON CONTACTLESS PAYMENTS

By Aderonke Alex-Adedipe and Nuratulahi Yishawu

DOWNLOAD PUBLICATION

Introduction

Across the world, Contactless Payments (“CPs”) have gained significant traction and widespread adoption in recent years. These payments enable financial transactions which allow a customer to purchase products or services using a debit, credit, smartcard, or another payment device, by mere contact between the payment device customer and the point of sale (“POS”) device. Although CP transactions have been in existence since the 1990s, they experienced a substantial increase in usage due to the global impact of the Covid-19 pandemic in 2020. Presently, CPs have become the preferred method of payment in numerous countries, with the projected global market value reaching USD 29.89 billion in 2022 and is projected to reach over USD 132.42 billion by 2032.

In our previous article, we examined the Exposure Draft of the Guidelines for Contactless Payments in Nigeria. On June 27, 2023, the Central Bank of Nigeria (“CBN”) released the Guidelines on Contactless Payments in Nigeria (“Guidelines”) to establish minimum standards and requirements for the operation of CPs within the country.

In this newsletter, we highlight some of the key provisions of the Guidelines.

1. Who Are the Stakeholders in A CP Transaction?

The Guidelines identify 11 (eleven) Stakeholders in CP transactions. They are: Acquirer; Issuer; Payment schemes; Card schemes; Switching Companies; Payment Terminal Service Provider; Payment Terminal Service Aggregator; Merchants; Terminal Owners; Customers; and any other stakeholder/participant as designated by the CBN.

It should be noted that only CBN-licensed institutions can serve as Acquirers and Issuers[1].

2. What Are the Standards for Participation in A CP Transaction?

All stakeholders involved in processing and/or storing customers’ information are mandated to ensure that their terminals, applications, and processing systems comply, at the minimum, with the following standards: (i) Payment Application Data Security Standard (PA DSS); Payment Card Industry Pin Entry Device PCI PED; (iii) Payment Card Industry Data Security Standard (PCI DSS);(iv)Advanced Encryption Standards (AES); (v) EMV; (vi) ISO 27001; (vi) ISO 1444; (vii) All required Scheme certifications for contactless cards and terminals and other international standards as may be specified by the CBN from time to time.

It is important to note that the Guidelines provide that CPs cannot be activated by default. Customers must provide consent and be provided with the option to opt-in and out of a CPs Agreement.

In addition, operators are required to maintain valid certification for these standards, ensure ongoing compliance, and establish contactless payment agreements/contracts with relevant parties. It is important to note that operators must obtain CBN’s approval for CP products, as well as for innovative use cases and value-added services.
Furthermore, all contactless devices issued by an operator must be configured to work within a maximum of 2cm from the payment terminal to manage the risk of data interception.
Relevant stakeholders should note that contactless payments images, symbols, tactile, graphics and/or the words “contactless payments” (in Braille) must be displayed on contactless payment instruments, contactless payment devices and locations where contactless payments are accepted.

3. What Is the Transaction Limit for Contactless Payment?
In a circular released with the Guidelines, the CBN set the transaction limit for each contactless payment through accounts/wallets in Nigeria at N15,000 ($19.3) and a daily cumulative of N50,000 ($64.3). Stakeholders are allowed to set limits in line with the CBN Guidelines.
For higher-value contactless payments that exceed these limits, customers will be required to provide appropriate verification and authorisation such as their PIN or biometric data. Existing Know Your Customer (“KYC”) requirements and limits on the electronic payment channels would also apply. This is expected to mitigate the effect of fraud-related activities which may occur.

4. How Can Stakeholders Resolve Issues Where There Is a Dispute?
All stakeholders, parties or participants involved in contactless payment must establish robust support systems to guarantee round-the-clock assistance and collaborate harmoniously to ensure timely resolution of disputed transactions. Where a dispute remains unresolved, complaints may be escalated to the CBN.

5. Are There Any Sanctions or Penalties?
Failure to comply with the provisions of the guidelines and other relevant regulations of the CBN will attract sanctions and penalties as may be determined by the CBN.

Conclusion
The Guidelines reflect the growing importance and adoption of contactless payments method both globally and within Nigeria. Overall, it serves as a significant step forward in shaping the future of contactless payments in Nigeria, fostering financial inclusion, convenience, and trust for all stakeholders involved.

[1] The acquiring bank/FI is the bank on the merchant end of the transaction, and the issuing bank/FI is the cardholder or customer’s bank.

 

REGULATORY UPDATE- NIGERIA DATA PROTECTION ACT,2023

By Seun Timi-Koleolu and Omonefe Irabor-Benson

DOWNLOAD PUBLICATION

Introduction

To further safeguard individual privacy rights and promote secured data practices, President Bola Tinubu on June 12 2023 signed into law the Nigeria Data Protection Act (the“Act”). This legislation builds upon the foundation laid down by the existing primary regulation, the Nigerian Data Protection Regulation (“NDPR”), and its Implementation Framework, which we have advised on in our previous newsletter.

In this newsletter, we have highlighted key changes introduced by the Act.

KEY PROVISIONS IN THE NIGERIA DATA PROTECTION ACT

1. Persons who are covered by the scope of the Act

Similar to the NDPR, the Act applies to data controllers and processors domiciled, resident, or operating in Nigeria. Data controllers and processors now clearly state who are not domiciled in Nigeria but are processing the personal data of data subjects in Nigeria are stated to be subject to the provisions of the Act.

2. Establishment of Nigeria Data Protection Commission (the “Commission”):

The Commission replaces the Nigeria Data Protection Bureau as the body saddled with the responsibility of ensuring compliance with data protection laws in Nigeria. In exercising its power under the Act, the Commission recently announced that it will now sanction executives of Ministry, Agencies, and Departments (“MDAs”).

3. Lawful Basis for Processing Personal Data

In addition to the existing lawful basis for processing personal data i.e. vital interest, consent, contract, legal obligation, public task, etc., the Act now clearly includes legitimate interest as a basis.

4. Data Impact Assessment (DPIA):

Data controllers and processors are now mandated to consult the Commission when a new product or service introduced into their organization exposes the data subjects to a high risk of contravening their rights and freedom as data subjects.

5. Sensitive Personal Data and Child Rights

In addition to the existing definition of sensitive personal data, the Act includes genetic data and biometric data for the purpose of uniquely identifying a natural person. The Act further provides that the data processors and controllers are expected to apply appropriate mechanisms to verify the age and consent of the child.

6. Rights of Data Subject

In addition to the rights of a data subject under the NDPR, the Act now clearly provides for a data subject to have the right not to be subjected to a decision based solely on the automated processing of personal data.

7. Data Controllers and Data Processors of Major Importance

The Act provides that data processors and controllers who process the data of such number of data subjects as prescribed by the Commission (“the Prescribed number”) or such other class of data of particular value or significance to the economy, society, or security of Nigeria must be registered with the Commission within 6 months from the commencement of the Act. The Commission is yet to advise on the Prescribed Number of data subjects.

CONCLUSION
Please note that other changes were made in the Act and the foregoing is not exhaustive. Please discuss with your Data Protection Compliance Organization for further guidance.