REDEFINING AML COMPLIANCE: UNDERSTANDING CBN’S BASELINE STANDARDS FOR AUTOMATED AML SOLUTIONS FOR FINANCIAL INSTITUTIONS

BY ADERONKE ALEX-ADEDIPE AND HILLARY OKOROTIE

Introduction

With the increasing need to ensure financial security in today’s rapidly digitizing landscape and evolving compliance demands, the Central Bank of Nigeria (CBN) issued its Baseline Standards for Automated Anti-Money Laundering (AML) Solutions for Financial Institutions (“AML Solutions”) on March 10, 2026. This was followed by a Guidance Note on implementation, released on March 31, 2026.

In this newsletter, we provide an overview of the requirements of the AML Solutions for financial institutions.

What is the Purpose of the AML Solutions?

The AML Solutions is aimed at establishing a structured and automated system for the identification and reporting of suspicious transactions and strengthening adherence to AML, Combating the Financing of Terrorism (CFT), and Countering Proliferation Financing (CPF) regulatory requirements. It also applies to all financial institutions operating in Nigeria.

What are Some of the Obligations of Financial Institutions?

  1. Customer Due Diligence (CDD), Know Your Customer (KYC) and Know Your Business (KYB): Financial institutions are required to implement effective CDD, KYC and KYB frameworks supported by automated or semi-automated onboarding, instant identity verification, and integration with national identity databases such as the Bank Verification Number (BVN) and National Identification Number (NIN) systems. They must also ensure proper documentation of beneficial ownership, maintain accurate and up-to-date customer data. AML Solutions must support end-to-end CDD, KYC, KYB, and enhanced due diligence processes, including automated risk profiling and behavioral transaction analysis. They must also enable continuous data integration of KYC/KYB data with customer risk profile to provide investigators with a unified view of customer profiles and transactional history for effective monitoring and decision-making.
  1. Sanction Lists & Politically Exposed Person (PEP) Screening: Financial institutions are required to conduct sanctions and screening of PEP at onboarding and on a continuous basis. They are also required to maintain clear procedures for reviewing, escalating, and resolving alerts and being able to demonstrate the effectiveness of their screening processes with proper documentation. AML Solutions must integrate domestic/international sanctions and watchlists with instant updates, automatically flagging or blocking transactions on confirmed matches in line with regulatory requirements.
  2. Risk Assessment & Transaction Monitoring: Financial institutions are required to conduct and document periodic business risk assessments and ensure AML systems reflect these risk profiles. The AML Solutions must assess transactions based on risk and identify possible money laundering activities. It should generate explainable alerts and enable pre-emptive actions to support decision-making.
  3. Reporting & Governance: Financial institutions must ensure accurate, complete, and timely regulatory reporting, supported by internal reviews and approval processes. The AML Solutions must be implemented to ensure automated or semi-automated generation of the required reports. They are also required to establish governance frameworks covering system ownership, access controls, model validation, and periodic audits.
  4. Security & Data Protection: There is also a requirement that all data processed and stored within AML systems comply with the scope of the Nigeria Data Protection Act (NDPA) 2023 and other applicable regulations. The AML Solutions must support this by securely collecting and storing relevant data, applying security controls such as encryption in transit, at rest, and in use, enforcing role-based access and secure authentication.

What is the Compliance Timeline for the AML Solutions?

The compliance timeline for the AML Solutions is 18 months for deposit money banks and 24 months for other financial institutions. However, all financial institutions are required to prepare and submit a detailed implementation plan to the CBN within 3 months of the issuance of the AML Solutions. The implementation plan must provide a clear and detailed roadmap on the steps the financial institution intends to implement to meet all obligations set out in the AML Solutions.

What is the Risk of Non-Compliance?

Where financial institutions fail to implement the AML Solutions or does so in a manner that results in ineffective AML/CFT/CPF controls, they may be subject to penalties. This liability extends not only to the financial institutions but also to personnel responsible for the implementation of the AML Solutions. Applicable penalties will be imposed in accordance with existing regulations, including the CBN AML-CFT-CPF Administrative Sanctions Regulations 2023, the Banks and Other Financial Institutions Act, and other relevant regulatory frameworks.

Conclusion

The AML Solutions imposes clear and enforceable obligations on financial institutions to implement effective, technology-driven frameworks for detecting and monitoring money laundering and other related activities. It is therefore imperative for financial institutions to promptly implement these requirements in line with the prescribed timelines.

VIRTUAL ASSET SERVICE PROVIDER (VASP) LICENCES IN KENYA & NIGERIA – WHAT YOU NEED TO KNOW

By Seun Timi-Koleolu, Ombo Malumbe,  Eniola Sogbesan and Faith Ngarama 

 

Introduction

The future of Africa’s digital asset market is no longer speculative. It is real, growing, and increasingly regulated. For founders, Fintechs, and even traditional financial institutions looking to operate in the digital currency space, obtaining a Virtual Asset Service Provider (VASP) license is the price of market entry. In jurisdictions like Nigeria and Kenya—two of the continent’s most active crypto markets—regulators are moving to formalize the ecosystem, protect consumers, and bring operators within a defined legal framework.

However, while both countries are moving in the same direction, their regulatory approaches, licensing processes, and compliance expectations differ in important ways. Understanding these nuances is critical for any business looking to establish or expand operations across either market.

In this newsletter, we examine the licensing requirements, regulated activities, applicable regulatory authorities and other practical considerations for navigating the process successfully.

S/N SUBJECT NIGERIA KENYA
1 Principal Regulator Securities and Exchange Commission Central Bank of Kenya, and Capital Markets Authority
2 License Categories ·       Ancillary Assets Service Providers (AVASPs)

·       Digital Assets Offering Platform (DAOP)

·       Digital Assets Intermediary (DAI)

·       Digital Assets Platform Operator

·       Real-world Assets Tokenization and Offering Platform

·       Digital Assets Exchange (DAX)

·       Digital Assets Custodian

·       Virtual Asset Wallet Provider

·       Virtual Asset Exchange

·       Virtual Asset Payment Processor

·       Virtual Asset Broker

·       Virtual Assets Investment Advisor

·       Virtual Asset Manager

·       Virtual Asset Offering Provider (Initial Coin Offering)

·       Virtual Asset Offering Provider (Virtual Asset Tokenization)

·       Virtual Asset Offering Provider (Token Issuance)

·       Virtual Asset Offering Provider (Stablecoin Issuance)

 

3 Permissible Activities Digital Assets Offering Platform This license is used to facilitate fund raising through a digital asset offering via the use of a distributed ledger technology. Virtual Asset Wallet Provider: Services provided by a third party, in which the private keys to the subject’s virtual assets are held and managed by the third party for proof of ownership and facilitation of transactions.

Virtual Asset Exchange: Providing a digital online platform facilitating virtual asset transfers and exchanges. Exchanges may occur between one or more forms of virtual assets, or between virtual assets and fiat currency; or A platform providing for the facilitation of the sale, trading, or exchange of virtual assets for fiat currencies or for other virtual assets.

Virtual Asset Payment Processor: Arranging transactions involving virtual assets and fiat currency, or between virtual assets.

Virtual Asset Broker: Facilitate the exchange between one or more forms of virtual assets through a virtual asset exchange and virtual asset wallet providers for and on behalf of clients, which may include retail, institutional investors, or funds.

Virtual Assets Investment Advisor: Provision of investment advice on virtual assets, initial virtual asset offering and non-fungible tokens for and on behalf of clients, which may include individuals or institutional investors.

Virtual Asset Manager: Managing portfolios in accordance with mandates given by clients on a discretionary basis where such portfolios include one; or more virtual assets.

Virtual Asset Offering Provider (Initial Coin Offering): Issuing and selling virtual assets to the public. May involve participating in and providing financial services relating to the initial coin offering.

Virtual Asset Offering Provider (Virtual Asset Tokenization): The process of converting real-world assets (like real estate, art, or, commodities) into digital token on a blockchain.

Virtual Asset Offering Provider (Token Issuance): Provision of tokenization platform for issuance and secondary trading of tokens of real-world assets.

Virtual Asset Offering Provider (Stablecoin Issuance): The process of creating and managing approved stablecoins.

Digital Assets Intermediary

This license is used to facilitate transactions involving virtual assets such as:

a. execution of orders for virtual assets on behalf of clients;

b. acceptance and transmission of orders for virtual assets on behalf of clients;

c. placing of virtual assets;

d. providing advice on virtual assets investment;

e. providing financial portfolio.

Digital Assets Custodian

This license is suitable for facilitating the safekeeping/holding in custody and/or administration of virtual assets or instruments that enable control over virtual assets.

Digital Assets Exchange

This license is used to facilitate the trading of virtual or digital assets.

The creation of new license categories such as

·       Ancillary Virtual Asset Service Providers (AVASPs)

·       Digital Assets Platform Operators (DAPOs); and

·       Real‑World Assets Tokenization and Offering Platforms (RATOPs).

highlights an area where further regulatory clarity will be required. As there is no existing regulatory framework that expressly identifies the permissible activities that fall within these newly introduced license categories.

4 Share Capital Requirements Ancillary Assets Service Providers (N300 million)

Digital Assets Offering Platform

(N 1billion)

 

Digital Assets Intermediary

(N500 million)

 

Digital Assets Platform Operator

(N500 million)

 

Real-world Assets Tokenization and Offering Platform

(N 1 billion)

 

Digital Assets Exchange

(N 2 billion)

 

Digital Assets Custodian

(N2 billion)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Virtual Asset Wallet Provider

(KSH 150 million)

 

Virtual Asset Exchange

(KSH 150 million)

 

Virtual Asset Payment Processor

(KSH 50 million)

 

Virtual Asset Broker

(KSH 30 million)

 

Virtual Assets Investment Advisor

(KSH 2.5 million)

 

Virtual Asset Manager

(KSH 30 million)

 

Virtual Asset Offering Provider (Initial Coin Offering)

(KSH 200 million)

 

Virtual Asset Offering Provider (Virtual Asset Tokenization)

(KSH 200 million)

 

Virtual Asset Offering Provider (Token Issuance)

(KSH 200 million)

 

Virtual Asset Offering Provider (Stablecoin Issuance)

(KSH 500 million)

5 Corporate

Governance

Requirements

All VASPs must have a minimum of five (5) directors, three (3) of whom must be Nigerian.

Also, the board of each VASP must comprise of the following committees

·       Nomination and Governance

·       Remuneration

·       Audit and Risk Management

The Board of Directors will constitute at least three (3) members.

 

Structure:

·       1/3 must be independent directors.

·       Not more than 1/3 shall be related to any director.

·       The Board’s chairperson shall not be appointed as the Chief Executive Officer (CEO).

6 Investment Thresholds High Networth Individuals

(No restriction)

 

Angel Investors

(maximum of N50 million per issuer within a 12-month period)

 

Retail Investors

(maximum of N1million per issuer not exceeding N10 million within a 12-month period)

There are yet to be any restrictions on Investment Thresholds. However, this does not limit such limits being applied as per the applicable laws more so from the Capital Markets Authority’s side.

 Conclusion

Securing a Virtual Asset Service Provider (VASP) license in Nigeria or Kenya is no longer simply a regulatory requirement but a strategic step toward building a credible and sustainable digital asset business. While both jurisdictions are actively developing their frameworks, they each present distinct requirements and regulatory expectations that must be carefully navigated. Businesses looking to operate in either market must take a proactive approach to compliance, ensuring that their structures, governance, and operational models align with the applicable rules from the outset.

Ultimately, success in this space will depend not only on obtaining a VASP license, but on maintaining ongoing compliance in an evolving regulatory environment. As regulators continue to refine their approach to Virtual assets, businesses that prioritize transparency, strong internal controls, and regulatory engagement will be best positioned to scale confidently. For prospective entrants, understanding the regulatory landscape early and preparing accordingly will make the difference between a smooth market entry or costly delays.

KEY REGULATORY UPDATE: CBN GUIDELINES ON INSTANT PAYMENT FUNCTIONALITIES AND MOBILE BANKING SECURITY

By: Aderonke Alex-Adedipe and Mark Imonitie

Introduction

On 12 March 2026, the Central Bank of Nigeria (CBN) issued a circular (the “Circular”) to all financial institutions (FIs) offering Instant Payment (IP) services in Nigeria.

The Circular provides the CBN’s Guidelines on instant payments and introduces sweeping measures to strengthen IP operations, enhance security protocols, improve consumer protection, and align with global best practices. This newsletter highlights the key provisions introduced by the Guidelines.

  1. VOLUNTARY OPT-IN AND OPT-OUT FUNCTION

Under the existing framework, FIs are not mandated to provide a feature on their mobile banking application, enabling customers to voluntarily opt in or out of IP services.

The new Guidelines however require FIs to allow customers to opt in or out at any time, subject to Multi-Factor Authentication (MFA).

New customers will be onboarded in opt-in mode by default. While opted out, customers cannot perform instant online fund transfers from their account; however, such transfers remain available via a physical branch visit.

  1. FLEXIBILITY IN SETTING TRANSACTION LIMITS

Prior to establishing the Guidelines, the maximum transaction limits of N25,000,000.00 for individuals and ₦250,000,000.00 for corporate entities, were fixed, with no option for customers to set personalized limits within those thresholds.

The Guidelines will subsequently allow both individuals and corporate entities to adjust these limits as needed, subject to enhanced due diligence and appropriate risk management by the FI.

To ensure security, the new transaction limit takes effect only after the customer completes the Multi-Factor Authentication (MFA) process.

  1. LIVELINESS CHECKS AND ENHANCED SECURITY FOR ONLINE TRANSACTIONS
    The Guidelines provide that where a customer seeks to open an account online or reactivate an online account, the following enhanced security measures shall apply:

    • liveliness check of the online account;
    • real-time validation of BVN/NIN database for online account openings/reactivations;
    • enhanced authentication mechanisms such as biometric authentication, soft token, hard token, for online account reactivations.

    A liveliness check is a biometric security measure which confirms that a user is a live, physically present human rather than a photo, video, or deepfake—by analyzing facial traits like skin texture, eye movement, and depth during remote onboarding or transactions, thereby preventing spoofing attacks.

  2. FRAUD MONITORING FUNCTIONALITY

The Guidelines mandate that all FIs implement and activate enterprise-wide fraud monitoring functionality covering both in-flows and out-flows. This measure restricts suspicious transactions in real-time while enabling prompt fraud detection and response.

  1. MANDATORY DEVICE BINDING

Under the existing framework, customers can operate their mobile banking application concurrently on multiple devices. The new Guidelines restrict mobile banking applications to one active device at a time, prohibiting concurrent use across devices. Switching to a new device triggers automatic deactivation of the previous one, followed by re-activation and authentication.

  1. ADDITIONAL REQUIREMENTS

The Guidelines introduce the following measures for mobile financial services applications and internet banking:

  • New account owners: Upon activation of a mobile banking application, inflow and outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira).
  • Existing account owners: Upon activation of a mobile banking application, outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira)
  • First-time login on a new device for internet banking requires enhanced Multi-Factor Authentication (MFA).

Conclusion

The Central Bank of Nigeria’s (CBN) new Guidelines on Instant Payment Functionalities for Financial Institutions mark a significant advancement in safeguarding digital transactions nationwide.

Effective 1 July 2026, financial institutions (FIs) must implement these measures. Among other requirements, the Guidelines necessitates comprehensive security and Data Protection Impact Assessments (DPIAs) to ensure compliance with the Nigeria Data Protection Act 2023 particularly resulting from mandatory features like multi-factor authentication (MFA), facial recognition, and continuous transaction monitoring.

About us:

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organization. We provide quality and innovative legal and data protection  support across diverse industries, helping clients operate in compliance with applicable laws and regulations to drive sustainable business growth.

REGULATORY UPDATE: NDPC EXTENDS DATA AUDIT FILING DEADLINE

By Seun Timi-Koleolu and Omodele Fatodu

The Nigeria Data Protection Commission (“NDPC”) has announced an extension of the deadline for the filing of the 2025 Data Protection Compliance Audit Returns (“CAR”) from March 31 to May 30, 2026. Data Processors and Controllers of Major Importance (“DPCMIs”) are therefore encouraged to utilise this period to ensure that their data protection frameworks are aligned with regulatory expectations and to file their Compliance Audit Returns within the extended timeline.

DPCMIs should note that failure to file within the prescribed timeline will attract regulatory sanctions. In particular, late filing of the CAR is subject to a penalty of 50% of the applicable filing fee, in addition to the risk of further regulatory scrutiny or enforcement action by the NDPC.

  1.  Practical Steps During the Extension Period

To make effective use of the extended timeline, DPCMIs should consider the following:

  1. Data Mapping: Ensure that all personal data processing activities are clearly identified and documented, including the nature of data collected, purposes of processing, storage locations, and third-party disclosures.
  2. Policy Review: Review privacy policies and internal data protection procedures to confirm that they are up to date and aligned with regulatory requirements and actual data processing practices.
  3. Remediation of Prior Findings: Ensure that any identified gaps or recommendations from prior audits have been appropriately addressed and implemented.
  4. Engage a licensed Data Protection Compliance Organisation (DPCO): A licensed DPCO can conduct the data protection compliance audit and file the CAR on behalf of the organisation, helping to ensure that the audit meets NDPC expectations.
  1. Update on Filing Fees

DPCMIs are also reminded that the filing fees applicable to the CARs were revised under the General Application and        Implementation Directive, 2025 (“GAID”). The fees depend on the DPCMI category, as well as the number of data subjects processed by the organisation, as outlined below:

  1. Ultra-High Level DPCMI
    Tier A – 50,000 data subjects and above: N1,000,000
    Tier B – 25,000 – 49,999 data subjects: N750,000
    Tier C – below 25,000 data subjects: N500,000
  2. Extra-High Level DPCMI
    Tier A – 10,000 data subjects and above: N250,000
    Tier B – 2,500 – 9,999 data subjects: N200,000
    Tier C – below 2,500 data subjects: N100,000
  1. Further Guidance

For a more detailed overview of compliance obligations under Nigerian data protection laws, and the role of DPCOs, please refer to our previous publications:

Conclusion

The extension of the 2025 data audit filing deadline provides organisations with an extended opportunity to review their data protection practices and file their Compliance Audit Returns on time.

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a DPCO. We provide support to organisations across diverse industries in conducting data protection compliance audits, preparing and filing Compliance Audit Returns, and ensuring alignment with the GAID and Nigeria Data Protection Act, 2023.