NAICOM’S GUIDELINES FOR FOREIGN HEALTH INSURANCE PROVIDERS: KEY COMPLIANCE CONSIDERATIONS FOR INSURERS AND POLICYHOLDERS IN NIGERIA

BY ADERONKE ALEX-ADEDIPE & OLUWAYEMI IBIRINDE

Introduction

On 31 March 2026, the National Insurance Commission (“NAICOM”) issued the Guidelines for the Operation of Foreign or International Health Insurance Providers (the “Guidelines”) pursuant to the Nigerian Insurance Industry Reform Act, 2025 (“NIIRA 2025”). The Guidelines establish, for the first time, a comprehensive regulatory framework governing foreign or international private medical insurers and reinsurers (“IPMI-R Providers”) seeking to provide health insurance services to entities registered or individuals who are resident in Nigeria.

Historically, international health insurance products were commonly procured directly from offshore insurers by multinational corporations, expatriates and high-net-worth individuals without any comprehensive regulatory framework governing such activities in Nigeria. Industry reports estimated that this resulted in approximately US$2 billion in annual premium outflows, while limiting regulatory oversight and the participation of domestic insurers. The Guidelines seek to address these gaps by requiring foreign health insurers to obtain NAICOM’s approval before operating in Nigeria, establishing approved local partnerships and complying with specified consumer protection, reporting and governance obligations.

In this newsletter, we examine the key provisions of the Guidelines and highlight some of the legal and commercial considerations for insurers and policyholders.

Who Do the Guidelines Apply To?

The Guidelines apply to all International Private Medical Insurers or Reinsurers (IPMI-R Providers) seeking to transact, market, underwrite or otherwise engage in health insurance business emanating from Nigeria.

Specifically, they apply to:

  1. foreign health insurers and reinsurers offering products to entities registered in Nigeria;
  2. foreign providers offering health insurance to persons residing in Nigeria; and
  3. intermediaries and authorised representatives acting on behalf of foreign health insurers.

Accordingly, the regulatory focus is not the location of incorporation of the insurer but whether the health insurance business or clientele originates from Nigeria.

What are the Key Compliance Requirements?

  1. Prior NAICOM Approval

The most significant change introduced by the Guidelines is that no foreign health insurer may transact, market or underwrite health insurance business originating from Nigeria without obtaining the prior written approval of NAICOM.

Similarly, no Nigerian entity or individual may transfer health insurance risks to an IPMI-R Provider unless that provider has received NAICOM’s approval.

The Guidelines further provide that where NAICOM does not communicate its approval or rejection within ten (10) working days after receiving complete documentation, the application shall be deemed approved.

  1. Mandatory Local Partnership Model

Unlike the previous regulatory position, the Guidelines prohibit foreign insurers from directly issuing health insurance policies to Nigerian entities or persons residing in Nigeria except through an authorised representative domiciled in Nigeria.

Every approved IPMI-R Provider must adopt one of the following operational models:

  • Model 1: Domestic Insurer Partnership;
  • Model 2: Domestic Administrator or Intermediary Partnership; or
  • Model 3: Health Maintenance Organisation (HMO) Partnership.

These partnership models ensure that licensed Nigerian entities participate in premium administration, claims support, regulatory reporting and other operational functions.

To obtain approval, an IPMI-R Provider must submit comprehensive documentation including:

  1. evidence of incorporation in its home jurisdiction;
  2. proof of regulatory licensing in its home jurisdiction;
  3. detailed product descriptions;
  4. a business plan;
  5. premium worksheets;
  6. proposed Nigerian intermediaries;
  7. its preferred operational model; and
  8. any additional information requested by NAICOM.
  1. Consumer Protection Requirements

The Guidelines introduce several customer protection obligations designed to improve accountability and transparency.

Approved providers are required to:

  1. provide clear information regarding policy terms and exclusions;
  2. ensure products meet customers’ needs;
  3. establish effective complaints management procedures;
  4. include claims settlement procedures within policy documentation; and
  5. ensure complaints are handled fairly through their Nigerian representatives or intermediaries.

These obligations significantly strengthen the position of Nigerian policyholders.

  1. Reporting and Ongoing Regulatory Obligations

Approved providers are required to submit quarterly production returns to NAICOM and pay the prescribed Insurance Supervisory Service (ISS) Levy.

The Guidelines therefore establish continuing regulatory oversight rather than a one-time approval process.

Compliance Considerations

Pending further regulatory guidance, organisations that utilise international health insurance arrangements should consider the following.

a. Review Existing Insurance Arrangements

Multinational companies should determine whether their current international health insurance programmes involve IPMI-R Providers that have obtained, or intend to obtain, NAICOM approval.

b. Assess Existing Partnership Structures

Foreign insurers should evaluate whether their existing operating model aligns with one of the three partnership structures prescribed under the Guidelines and identify any restructuring that may be required.

c. Review Distribution and Intermediary Arrangements

Insurers, brokers, HMOs and third-party administrators should assess whether their contractual arrangements adequately reflect the roles and reporting obligations contemplated under the Guidelines.

d. Strengthen Compliance Frameworks

Organisations should establish internal governance procedures to monitor ongoing compliance with NAICOM’s approval requirements, reporting obligations and customer protection standards.

e. Review Existing Policies

The Guidelines permit policies issued before the effective date to continue until expiry. However, organisations should review renewal arrangements to ensure that future policies comply with the new regulatory framework.

Penalties for Non-Compliance

The Guidelines introduce significant sanctions for non-compliance.

  1. Any entity registered in Nigeria or person residing in Nigeria that transacts health insurance business with an unapproved IPMI-R Provider may be liable to a penalty of not less than the total premium involved.
  2. The Guidelines also required providers to regularise their operations within the prescribed ninety-day transitional period. Failure to satisfy the approval requirements may result in rejection of the application and suspension of the issuance of new policies and renewals.

Conclusion

With the Guidelines having taken effect on 31 March 2026, multinational employers, foreign insurers, HMOs, brokers and other intermediaries, should immediately prioritize assessing existing operational structures and contractual arrangements to ensure continued compliance with the new regulatory framework. Organisations that undertake this assessment proactively will be better positioned to navigate future regulatory developments while minimising compliance risks.

ONE AFRICA, ONE CLICK: WHAT THE AFCFTA DIGITAL TRADE PROTOCOL MEANS FOR AFRICA

BY SEUN TIMI-KOLEOLU & EFE OKPARAVERO

Introduction

Last week, Lagos hosted the AfCFTA Digital Trade Forum 2026, bringing together policymakers, regulators, financial institutions, technology companies, legal practitioners, and other stakeholders from across Africa and beyond under the theme, “Digital Trade for a Connected African Market.”

The Forum underscored the growing momentum behind the AfCFTA Protocol on Digital Trade. This Protocol seeks to govern the cross-border exchange of goods, services and other tradeable items that are facilitated by digital platforms and technologies. For more information on this, see our article here.

In light of the discussions and developments emerging from the Lagos Forum, this is an opportune moment to revisit the Protocol, assess the progress made to date, and consider the practical steps African countries and businesses should take to prepare for its implementation.

Changes Since the Adoption of the Protocol by the African Union on 18 February 2024

The most significant development has been the adoption of eight supplementary Annexes on 16 February 2025, transforming the Protocol from a mere framework into a more operational instrument setting out detailed rules for implementation.

Three notable annexes include:

  1. Annex on Rules of Origin: The Rules of Origin (ROO) Annex was introduced to provide clarity on the ‘African origin requirements’ for digital products (mentioned in Article 5 of the Protocol) by introducing a two-tier test. Under these new rules, both the supplying enterprise or platform must be African-owned and operated, and the digital content itself must qualify as African content to enjoy preferential treatment under AfCFTA.
  2. Annex on Cross-Border Digital Payments: This Annex sets out practical measures (improving on Article 15 of the Protocol) to promote secure and efficient digital payment systems across the African market. Such measures include requirements and guidance on interoperable payment infrastructure; electronic know-your-customer (e-KYC) processes; open application programming interfaces (APIs); fraud prevention mechanisms; and regulatory cooperation on anti-money laundering and counter-terrorist financing (AML/CFT).
  3. Annex on Cross-Border Data Transfer: This Annex (mentioned in Article 20 of the Protocol) now creates an adequacy-based system for the free flow of data between countries engaging in digital trade. To fulfill the adequacy requirement, countries are required to maintain a domestic data protection framework which at a minimum meets the standards set out in Articles 5 to 14 of this Annex, such as Personal Data Protection by Design and Default; Data Minimisation; and Competent Data Protection Authorities etc.

Beyond the regulatory framework, there have been continent-wide initiatives such as:

  1. AfCFTA Digital Inclusion and Entrepreneurship Programme (ADIEP): Delivered in partnership with Google, ADIEP is reported to have trained more than 7,500 SMEs across 19 African countries through 25 cohorts between November 2025 and June 2026, equipping businesses with skills in artificial intelligence, cross-border e-commerce and cloud technologies.
  2. Pan-African Payment and Settlement System (PAPSS): PAPSS is expected to reduce the cost, complexity and settlement time of cross-border transactions, supporting one of the Protocol’s central objectives of seamless digital trade across Africa. For more on PAPSS, see here.
  3. Africa Digital Access and Public Infrastructure for Trade (ADAPT): An implementation initiative, launched in November 2025 by the AfCFTA Secretariat, ADAPT designated Nigeria, Kenya and Morocco as its pilot countries. This initiative focuses on strengthening digital public infrastructure through digital identity systems; payment integration; and the digitisation of trade documentation.

What This Means Commercially

Africa’s digital economy is projected to grow from approximately US$180 billion today to US$712 billion by 2050, hence the stakes are quite high. For businesses, the Protocol is expected to deliver:

  1. Greater market access: Harmonised rules will make it easier for businesses to reach customers across Africa without establishing a physical presence in every market, reducing regulatory fragmentation and expansion costs.
  2. Stronger compliance obligations: Businesses will need to enhance data governance, privacy frameworks and cross-border transfer arrangements as digital trade rules become more aligned across jurisdictions.
  3. Improved digital payments: Interoperable payment systems, supported by initiatives such as PAPSS, could reduce transaction costs and improve settlement efficiency, while requiring stronger AML/CFT/KYC compliance from financial institutions and Fintechs.

Ratification Status

Adoption is distinct from entry into force. Under Article 47 of the Protocol and Article 23 of the AfCFTA Agreement, the Protocol enters into force 30 days after the 22nd State Party deposits its instrument of ratification. That threshold has not yet been met, meaning the Protocol remains a framework for future implementation rather than an enforceable regime.

Nigeria has advanced its implementation efforts as a Co-Champion of the Protocol, with the Federal Executive Council approving Nigeria’s ratification on 6 November 2025.

The Protocol, however, does not yet have the force of law within Nigeria, as treaties require domestication by the National Assembly pursuant to Section 12 of the Constitution of the Federal Republic of Nigeria 1999 (as amended).

Recommendations

Going forward, we recommend the following:

A. State Parties should:

  1. Identify gaps or discrepancies between their domestic legal frameworks and the Protocol, take steps to align their laws with the provisions of the Protocol.
  2. Accelerate ratification of the Protocol and incorporate it into their domestic legal frameworks to ensure effective implementation.
  3. Promote regulatory cooperation with other State Parties by working towards greater harmonisation of digital trade regulations, particularly in areas such as data protection, cybersecurity, digital identity, electronic transactions and consumer protection.

B. Businesses should:

  1. Prepare ahead of the Protocol’s entry into force by monitoring ratification and regulatory developments,
  2. Review contracts and data governance practices to align them with the Protocol
  3. Strengthen cybersecurity, AML/CFT/KYC frameworks and digital payment capabilities to meet emerging cross-border digital trade requirements.

Conclusion

The AfCFTA Digital Trade Protocol represents a significant step towards building a better connected and competitive African digital economy. Whilst the Protocol is not yet operational, ongoing implementation initiatives signal a clear shift towards greater digital integration. Governments and businesses that begin preparations now will be better positioned to take advantage of the opportunities created by a single African digital market.

CBN’S DATA LOCALISATION DIRECTIVE – COMPLIANCE CONSIDERATIONS FOR PAYMENT SYSTEM PARTICIPANTS

BY ADERONKE ALEX-ADEDIPE & PROMISE ITAH

Introduction

On June 15, 2026, the Central Bank of Nigeria (“CBN“) issued a Circular on Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System (the “Circular“). Among other regulatory reforms, the Circular introduces a significant data localisation requirement directing all financial institutions and participants facilitating payments within Nigeria—including banks, payment service providers, mobile money operators and other payment participants— (collectively “Payment System Participants”) to ensure that data generated in relation to payment transactions in Nigeria is stored and managed in Nigeria by January 1, 2027.

In this newsletter, we examine the scope of the CBN’s data localisation requirements, their interaction with existing data protection obligations, and some of the key legal, contractual and operational considerations which Payment System Participants should consider in preparation for compliance.

  1. Who does the Circular Apply to?
    The Circular applies to payment transaction data generated through Nigeria’s payments system. Although the Circular does not define the term “payment transaction data”, it intuitively includes information generated in connection with a payment transaction, including the payer’s and beneficiary’s payment details, transaction amounts, payment references, authentication records, settlement and routing information, transaction logs and other related technical data required to process, verify or record a payment.

    The Circular also appears to frame the localisation requirement by reference to payment transaction data generated within Nigeria, rather than the location in which the business is principally domiciled. On this basis, therefore any Payment System Participant processing payment transaction data generated within Nigeria may be expected to comply with this requirement, regardless of their country of domicile.

  1. What are the Key Compliance Requirements?

    a. Local Processing and Storage
    Payment System Participants must ensure that payment transaction data is both stored and managed within Nigeria. This extends beyond maintaining a local copy of data and requires that the primary processing environment, databases, backups and operational control remain on infrastructure located within Nigeria.

    The requirement for payment transaction data to be “managed” in Nigeria may also have implications for administrative activities such as access management, database administration, encryption key management and audit logging, particularly where these functions are performed through offshore infrastructure or personnel.

    b. Technology and Infrastructure
    The Circular is likely to require many Payment System Participants to review their technology infrastructure, particularly where payment services rely on foreign cloud service providers or systems hosted outside Nigeria. Given the requirement for payment transaction data generated within Nigeria to be stored and managed locally, organisations should assess whether their existing technology architecture involves the storage, processing or replication of payment transaction data outside Nigeria. Areas that may require review include:

    • cloud hosting arrangements and the location of servers;
    • disaster recovery and backup systems;
    • analytics and monitoring platforms that process payment data;
    • testing and development environments that use live or production payment data; and
    • third-party APIs and other technology integrations that may transfer payment data outside Nigeria.

Payment System Participants operating hybrid or multiple cloud environments should assess whether payment data is stored, replicated or processed outside Nigeria and, where necessary, implement appropriate technical or operational changes before the compliance deadline.

c. Vendor and Outsourcing Arrangements

Whilst it is commonplace for Payments System Participants to assign data processing and storage activities to third parties, the Circular does not appear to transfer the obligations from Payment System Participants to service providers in such instance. Accordingly, organisations should review their contractual arrangements with cloud service providers, payment processors, application programming interface (API) providers and other technology vendors to assess whether those arrangements support compliance with the localisation requirement. In particular, organisations should consider whether their contracts adequately address:

    • the requirements for payment data to be stored and managed within Nigeria;
    • restrictions on processing payment data outside Nigeria;
    • rights to conduct audits and facilitate regulatory inspections;
    • controls over the use of subcontractors that may have access to payment data;
    • obligations to promptly notify the Payment System Participant of any data breaches or incidents; and
    • termination rights where a vendor is unable to comply with the localisation requirements.
  1. How does the Circular Interact with the Nigeria Data Protection Act (NDPA)?

The Circular complements rather than replaces the NDPA. While the NDPA regulates the processing and international transfer of personal data through recognised transfer mechanisms and safeguards, the CBN Circular imposes an additional regulatory obligation applicable specifically to payment transaction data. Accordingly, compliance with the NDPA alone will not satisfy the CBN’s localisation requirements.

  1. Practical Compliance Steps

Pending any further guidance from the CBN, Payment System Participants should consider taking the following steps to prepare for implementation:

    1. conducting a comprehensive data mapping exercise to identify where payment data is stored, processed and transmitted;
    2. assessing existing cloud and infrastructure arrangements for localisation risks;
    3. reviewing third-party vendor relationships and contractual provisions;
    4. updating internal data governance, outsourcing and information security policies;
    5. establishing board and management oversight of the implementation programme; and
    6. maintaining adequate documentation to demonstrate compliance during regulatory inspections.

Conclusion

The CBN’s payment data localisation requirements represent a significant development in the regulation of Nigeria’s payments ecosystem. By requiring payment transaction data generated within Nigeria to be stored and managed in Nigeria, the Circular appears intended to strengthen regulatory oversight, enhance operational resilience and support the security of Nigeria’s payments infrastructure. For Payment System Participants, the immediate priority will be to assess whether existing technology infrastructure, data governance frameworks and third-party vendor arrangements are consistent with the new localisation requirement. Given the breadth of the obligation and the absence of detailed implementation guidance, organisations that begin assessing their compliance position ahead of the January 2027 implementation date will be better positioned to address any legal, operational or contractual gaps as further guidance emerges.