Posts

THE CENTRAL BANK OF NIGERIA REGULATORY UPDATE: REVISED CASH POLICIES AND AUTHORISED PUSH PAYMENT FRAUD GUIDELINES

BY SEUN TIMI-KOLEOLU AND OMODELE FATODU

Introduction

The Central Bank of Nigeria (“CBN”) has recently issued two regulatory communications: (i) the Revised Cash-Related Policies, effective 1 January 2026; and (ii) the Draft Guidelines for Handling Authorised Push Payment (“APP”) Fraud. Both documents introduce new operational requirements for financial institutions and provide guidance for customers, lenders, and payment service providers.

1. REVISED CASH-RELATED POLICIES – Key Changes

  1. Removal of Cash Deposit Limits The CBN has abolished previously applicable cash-deposit limits. Under the former regime, customers were subject to cumulative deposit limits and charges for excess cash deposits. These thresholds and associated fees have now been completely removed.
  2. Upward Adjustment of Withdrawal Limits – Individuals may now withdraw up to ₦500,000 weekly, while corporate entities may withdraw up to ₦5 million. Withdrawals exceeding these limits will attract processing fees of 3% for individuals and 5% for corporate entities.
  3. Elimination of Special Withdrawal Authorisations The requirement for customers to seek special CBN approval for unusually large cash withdrawals (previously ₦5 million for individuals and ₦10 million for corporate entities) has been discontinued.
  4. Enhanced Obligations for Financial Institutions Banks are required to ensure that ATMs remain adequately funded and stocked with various denominations. They must maintain a designated account for processing fees charged on withdrawals above the stipulated limits. Banks are also required to submit specified periodic reports, including returns on cash withdrawals above the specified limit and returns on cash deposits to the CBN to support ongoing compliance and supervision.

2. CBN DRAFT GUIDELINES ON APP FRAUD

What is APP Fraud?

APP fraud occurs when a customer is tricked into voluntarily initiating a payment to an account controlled by a fraudster. Although the customer authorises the transfer, it is done under false pretences through deception, manipulation, impersonation, or other fraudulent means.

Key Highlights

  1. Standardised Reporting Framework for Fraud Incidents Customers are required to report suspected or actual APP fraud to their financial institution within 24 hours, with allowance for reporting within 72 hours where reasonable justification is provided. The guidelines state that “reasonable justification” may include, but is not limited to, circumstances beyond the control of the customer such as illness, force majeure events, time of becoming aware of the fraud, security constraints, or demonstrable unavailability of reporting channels. Upon receiving a report, the institution must acknowledge receipt within 24 hours, open a case file, and begin processing the complaint in line with the guidelines.
  2. Mandatory Inter-Bank Notification within 30 Minutes Where an APP transaction involves more than one financial institution, the institution that first receives the complaint must notify the other insitiution within 30 minutes of receiving the customer’s complaint.
  3. Defined Timelines for Customer Refunds Where a customer is entitled to a refund, the responsible institution must complete it within 48 hours after concluding the investigation. In cases involving multiple institutions, refunds must be completed within 16 working days of the complaint.
  4. Strengthened Fraud-Prevention and Consumer-Protection Duties Financial institutions must provide 24/7 fraud-reporting channels and implement an early warning system to prevent and detect APP fraud in a timely manner. They are required to ensure that customers are aware of available reporting channels and receive clear, accessible, and ongoing education on APP fraud risks and reporting procedures. Financial institutions must also carry out quarterly APP fraud awareness campaigns across multiple media and languages, and ensure that any information shared with other institutions complies with the Nigerian Data Protection Act 2023.
  5. Customer Refund Eligibility – Refund eligibility is subject to the following conditions:
    • The customer authorised the transaction under false pretence and had no reason to suspect fraud;
    • The customer reported the fraud within 72 hours and cooperated with the investigation;
    • There is no evidence of negligence, collusion, or criminal intent by the customer; and
    • The financial institution failed to implement appropriate fraud detection, warning, or verification protocols that could have prevented the transaction.

    Financial institutions are not obligated to reimburse where:

    • The customer acted fraudulently or negligently;
    • The customer delayed reporting beyond 72 hours without reasonable justification; and
    • The transaction occurred before the effective date of the guideline, unless the institution voluntarily applies it retroactively.

Conclusion

CBN’s Revised Cash-Related Policies and Draft Guidelines on APP Fraud introduce updated operational requirements that affect both financial institutions and customers. Banks and payment service providers should review these documents to ensure compliance ahead of the effective dates, while customers should familiarise themselves with the reporting procedures and eligibility criteria to protect their interests in cases of APP fraud.

BANKING AND FINANCE IN NIGERIA: THE REGULATORY FRAMEWORK AT A GLANCE

SEUN TIMI-KOLEOLU AND EBIKENIYE BEST

 

In Nigeria, the importance of a well-regulated banking system cannot be overstated, especially in light of the sector’s influence on economic growth, investor confidence and public trust. To achieve this, a robust regulatory framework has been established, one that combines statutory legislation, institutional oversight and evolving policy guidelines to ensure stability and transparency. Both local and foreign businesses wishing to operate in the banking and fintech sector must understand the regulatory framework.

In-view of the foregoing, we have provided a snapshot of the regulatory framework.

a.     Banks and Other Financial Institution Act, (BOFIA) 2020

BOFIA 2020, which replaced the 1991 Act,[1] is the primary law governing Nigeria’s banking sector. It sets out the Central Bank of Nigeria’s regulatory powers, including the issuance and withdrawal of banking licenses, approval of new or closed bank branches, and the restructuring of banks. It also covers the operation of foreign banks in Nigeria and formally recognises digital banking, providing a clear legal basis for regulating fintech activities.[2]

b.    The Central Bank of Nigeria Act 2007 (“Act”)

The Act established the CBN which is the primary regulator of the Nigerian banking sector. It is charged with the overall control and administration of banks and other financial institutions in Nigeria. The responsibilities of the CBN include but is not limited to (i) ensuring monetary and price stability; (ii) promoting a sound financial system in Nigeria; (iii) issuing guidelines and circulars relating to its responsibility to banks, foreign exchange market, and other financial institutions.[3]

c.     The Companies and Allied Matters Act, (CAMA) 2020

CAMA establishes the Corporate Affairs Commission (CAC), which is charged with the regulatory powers over all registered companies in Nigeria, including banks and other financial institutions. The CAC is responsible for the incorporation of all corporate entities in Nigeria, including banks and other financial institutions; Under CAMA, certain corporate governance principles were introduced which require a public company to have at least three independent directors and prohibit a person from being a director in more than five public companies. These provisions apply to a bank registered as a public company.

d.    The Nigerian Deposit Insurance Corporation Act 2006 (“NDIC Act”)

The NDIC Act established the NDIC which provides regulatory oversight over Deposit Money Banks (DMBs), commonly known as commercial banks. The NDIC is responsible for insuring the deposit liabilities of licensed banks and offering financial assistance to insured institutions facing difficulties, in order to protect depositors. It also plays a key role in supporting the formulation and implementation of banking policies by the monetary authorities.

In cases of bank failure, the NDIC is empowered to take over the management and control of the affected institution, ensuring an orderly resolution or closure without disrupting the stability of the banking system.

e.    Foreign Exchange (Monitoring and Miscellaneous Provisions) Act, 1995 (FEMM Act)

The FEMM Act establishes the regulatory framework for conducting and controlling foreign exchange transactions in Nigeria. It mandates that transactions in the foreign exchange market be carried out in convertible foreign currencies and specifies the permissible monetary instruments that may be used within the market.

f.     The Financial Reporting Council of Nigeria (FRCN) Act 2011

Under the FRCN Act, the FRCN is responsible for developing and enforcing standards on accounting, auditing, corporate governance, and financial reporting. These responsibilities extend to private companies and public interest entities, including banks and other financial institutions, ensuring transparency, accountability, and sound financial practices across the sector.

g.    The Investment and Securities Act (ISA) 2025

The ISA establishes the Securities and Exchange Commission (SEC) which regulates capital market activities and public companies in Nigeria. While a licensed bank will not in the ordinary course of its banking activities fall within the regulatory purview of the SEC, where such a bank is a public company or its affiliate undertakes capital market activities, the bank or the relevant affiliate will fall within the SEC’s purview.

h.     Nigerian Financial Intelligence Unit (NFIU) Act, 2018

As Nigeria’s central national agency for financial intelligence, the NFIU enforces compliance with anti-money laundering and combating the financing of terrorism. This means that the NFIU ensures that banks and other financial institutions comply with the Money Laundering (Prevention and Prohibition) Act, 2022, Terrorism (Prevention and Prohibition) Act, 2022 and the NFIU operational guidelines.[4]

Conclusion

As Nigeria positions itself in the global financial space, the effectiveness of its regulatory institutions will continue to play a significant role. Companies in the banking and fintech sector are advised to liaise with professional advisers to ensure compliance and facilitate ease of doing business.

Further information, do not hesitate to reach out to us.

[1] https://pavestoneslegal.com/revised-banking-law-in-nigeria-bofia-2020/

[2] https://pavestoneslegal.com/5074-2/

[3] https://pavestoneslegal.com/licensing-requirements-for-banks-and-other-financial-institutions-in-nigeria/

[4] https://pavestoneslegal.com/anti-money-laundering-regulation-in-nigeria-recent-updates/

FOREIGN CURRENCY DISCLOSURE, DEPOSIT, REPATRIATION, AND INVESTMENT SCHEME: CENTRAL BANK OF NIGERIA IMPLEMENTATION GUIDELINES

By Aderonke Alex-Adedipe and Olawale Atanda

Download Publication

 

Introduction

On November 5, 2024, the Central Bank of Nigeria (CBN) released its Implementation Guidelines on the Foreign Currency Disclosure, Repatriation, and Investment Scheme (the “Guidelines”). These Guidelines complement the Foreign Currency Disclosure, Deposit, Repatriation, and Investment Scheme Guidelines, 2024 (the “Scheme”), issued by the Minister of Finance and Coordinating Minister of the Economy on April 8, 2024. The Scheme was introduced to operationalize Presidential Executive Order No. 15 (Modification Notice), aimed at facilitating the voluntary disclosure, deposit, and repatriation of foreign currencies held by Nigerians, whether within or outside the country.

The Guidelines outline the role of Commercial, Merchant, and Non-Interest Banks (“Banks”) in the Scheme. It details how foreign currencies are to be disclosed, deposited, repatriated, or invested.

In this article, we examine the key provisions of the Guidelines and their role in implementing the Scheme effectively.

 

1.Objectives of the Scheme    

The Scheme aims to enhance financial transparency by formalizing legitimate foreign currency assets held by Nigerians and legal residents. It provides a framework for the voluntary disclosure of internationally tradable foreign currency, whether held in cash or electronic form, onshore or offshore. Also, it establishes mechanisms for depositing disclosed foreign currency into participating financial institutions in Nigeria and repatriating offshore-held currency through approved channels. The Scheme seeks to promote investment in designated sectors and instruments, leveraging these disclosed assets to boost economic resilience, drive infrastructure development, and foster job creation.

 

2.Operation of the Scheme

2.1 Procedure for Application

To participate in the Scheme, applicants must provide Banks with required details, including their full name, Bank Verification Number (BVN), National Identification Number (for natural persons), or Tax Identification Number (for legal entities). Applicants must also disclose the amount of foreign currency they intend to deposit, details of their designated domiciliary account, and any additional information requested by the Bank.

2.2. Deposit and Repatriation of Foreign Currency

Upon verifying compliance with the application requirements, the Bank will receive the foreign currency into the participant’s designated domiciliary account. The Bank must then submit a report to the CBN detailing the receipt of the funds.

2.3. Withdrawals and Termination of Investment

Banks are prohibited from imposing restrictions on withdrawals from a participant’s designated domiciliary account (except as otherwise provided in the Scheme)* or on the termination of investments made in Permissible Investment Sectors or Instruments** under the Scheme.

2.4 Conversion of Deposited Foreign Currency

Participants may convert part or all of the foreign currency in their designated domiciliary accounts into Naira at the prevailing exchange rate. Banks are to ensure that such conversions are properly disclosed and reported in their foreign exchange returns.

 

3.Responsibilities of Stakeholders

3.1 Responsibilities of Banks

Banks participating in the Scheme are required to open designated domiciliary accounts for customers, process applications in line with the Guidelines, and accept deposits of disclosed foreign currencies directly or through nominated entities. They must issue receipts acknowledging the country of origin for deposited funds within 24 hours and track participants’ investments in permissible instruments or sectors. Also, Banks must ensure compliance with relevant laws and maintain strict confidentiality of participants’ information in line with data protection laws.

3.2. Responsibilities of Participants

Participants must open designated domiciliary accounts for Scheme-related transactions and invest only in permissible sectors or instruments. They are required to confirm the legality of deposited funds, provide accurate and complete information, and consent to the sharing of relevant account data with the CBN and other legally authorized parties.

3.3.Responsibilities of the CBN

The CBN regulates Banks’ participation in the Scheme, collects monthly reports from them, and provides templates for transaction reporting. It also shares data with the Ministry of Finance on the operation of the Scheme at both industry and individual bank levels.

 

4.Treatment of Uninvested Funds

Banks may utilize uninvested foreign currencies deposited under the Scheme for trading purposes, provided the funds remain accessible to the participant whenever required. Interest on balances in designated domiciliary accounts will be paid in accordance with the provisions of the Guide to Charges by Banks and Other Financial Institutions in Nigeria.

 

5. Compliance with Anti-Money Laundering and Counter-Terrorism Regulations

Transactions under the Scheme are subject to the Money Laundering (Prevention & Prohibition) Act, 2022; Terrorism (Prevention and Prohibition) Act, 2022, and various CBN regulations, including AML/CFT/CPF regulations and Customer Due Diligence guidelines. These laws prohibit the introduction of funds derived from illegal or criminal activities into Nigeria’s financial system.

Banks participating in the Scheme must ensure compliance with all relevant AML/CFT/CPF regulations by:

i.Conducting comprehensive Customer Due Diligence (CDD) on applicants, including identifying the beneficial owners of the funds.

ii.Verifying the ownership of accounts receiving funds under the Scheme.

iii.Ensuring deposits via wire transfers comply with applicable regulatory requirements.

iv.Applying enhanced due diligence for funds repatriated from jurisdictions that do not meet Financial Action Task Force (FATF) Recommendations.

 

Conclusion

The Guidelines provide a structured framework to facilitate the inflow of foreign currency currently outside the Nigerian financial system. The goal is to promote local investment in key economic sectors and approved investment instruments. By aligning with relevant regulatory provisions, the Scheme aims to bolster economic resilience while preserving the integrity of the financial system in Nigeria.

 

Footnotes

*The Scheme requires participants to commit to retaining the disclosed and deposited foreign currency for a minimum period of five (5) years from the deposit date. Withdrawal is only permitted for investment in Permissible Investment Sectors or Instruments.

**Permissible Investment Sectors are those designated by the President to drive economic growth, infrastructure development, and job creation. Permissible Investment Instruments are foreign currency-denominated financial instruments issued under relevant executive orders or as determined by the President.

 

 

 

REGULATORY UPDATE: THE NIGERIA FOREIGN EXCHANGE (FX) CODE

By Seun Timi-Koleolu and Qasim Ogunjimi

DOWNLOAD PUBLICATION

Introduction

In light of ongoing challenges in the Nigerian foreign exchange market, including recent distortions driven by speculators and illicit traders, the need for a robust regulatory framework has become increasingly urgent. In view of this, the Central Bank of Nigeria (CBN) has introduced the Nigeria Foreign Exchange Code (the “FX Code”), effective October 14, 2024, to enhance the integrity and operational efficiency of the Nigerian Foreign Exchange Market (NFEM). This comprehensive framework establishes robust guidelines for licensed banks and financial institutions, including Bureau de Change (BDC) operators, International Money Transfer Operators (IMTOs), FinTechs and others organisations engaged in wholesale foreign exchange transactions (“Market Participants”).

The FX Code aligns with the principles set forth in the FX Global Code maintained by the Global Foreign Exchange Committee (GFXC) and aims to promote ethical conduct and best practices within Nigeria’s foreign exchange landscape.

At the core of the FX Code are six key principles: Ethics; Governance; Execution; Information Sharing; Risk Management and Compliance; and Confirmation and Settlement Processes. These principles not only ensure high standards of ethical conduct and operational excellence but also allow for a transparent, competitive, and fair market environment. The focus of this newsletter is to examine the compliance requirements outlined in the FX Code, emphasizing its six key principles.

COMPLIANCE REQUIREMENTS UNDER THE FX CODE

To ensure that Market Participants align with the FX Code, several compliance requirements have been established. These requirements are designed to promote accountability, transparency, and adherence to high ethical standards in the foreign exchange market. The key compliance obligations include:

  1. Self-Assessment and Reporting: Market Participants are required to conduct a thorough self-assessment of their adherence to the FX Code and submit a detailed compliance report to CBN by December 31, 2024. This assessment must evaluate their current practices against the standards set forth in the FX Code. This report should highlight their level of compliance, strengths and identify any areas requiring improvement.
  2. Implementation Plan: Alongside the self-assessment, each Market Participant is required to submit to CBN by December 31, 2024, a compliance implementation plan that has been approved by its Board of Directors. This plan should detail the strategies and steps the institution will take to achieve full compliance with the FX Code.
  3. Quarterly Reporting Mechanisms: Following the initial compliance assessments and plans, Market Participants must also provide ongoing updates to the CBN. They are obligated to submit quarterly reports on their level of compliance to the Financial Markets Department of CBN within 14 days after the end of each calendar quarter. This process ensures continuous monitoring and reinforces the commitment to uphold the principles of the FX Code.
  4. Other Compliance Requirements: In addition to the primary obligations outlined above, Market Participants are expected to adhere to several other compliance requirements, including but not limited to:
  • Training and Awareness: Conduct regular training sessions for employees to ensure their understanding of the FX Code and its principles.
  • Internal Controls: Establish robust internal control mechanisms to continuously monitor adherence to the FX Code and detect potential violations.
  • Record Keeping: Maintain accurate and comprehensive records of all transactions, communications, and compliance activities to demonstrate adherence during audits.
  • Risk Management Framework: Implement a framework to identify, assess, and mitigate risks associated with FX activities, including monitoring market conditions and counterparty exposure.
  • Governance Structures: Establish clear governance structures outlining roles and responsibilities related to compliance, including appointing compliance officers and ensuring Board oversight.
  1. Enforcement of the FX Code: Please note that the FX Code provides that CBN may take appropriate enforcement and other administrative action including monetary penalties as provided for under the CBN Act 2007 and Banks and Other Financial Institution Act 2020 against any Market Participant for failure to comply with the FX Code.

CONCLUSION

The introduction of the Nigeria Foreign Exchange Code marks a significant milestone in the ongoing effort to stabilize and enhance the Nigerian Foreign Exchange Market. It is important for all Market Participants to familiarize themselves with the provisions of the FX Code and actively work towards meeting its compliance requirements.

 

For further readings on the Nigerian foreign exchange market, you can refer to our previous articles

  1. KEEPING UP WITH FOREIGN EXCHANGE REGULATIONS: NEW CBN MEASURES FOR INTERNATIONAL MONEY TRANSFER OPERATORS (IMTOs)
  2. RECENT CBN REFORMS IN THE NIGERIA FOREIGN EXCHANGE MARKET

CENTRAL BANK OF NIGERIA: MONETARY, CREDIT, FOREIGN TRADE AND EXCHANGE POLICY GUIDELINES (2024/2025)

Download Publication

By Aderonke Alex-Adedipe and Olawale Atanda 

 

Introduction

The Central Bank of Nigeria (the “CBN”) recently issued its Monetary, Credit, Foreign Trade, and Exchange Policy Guidelines for the fiscal years 2024 and 2025 (the “Policy Guidelines”) which outline the CBN’s objectives for the financial system and the regulations applicable to Banks and other Financial Institutions during this period. The Guidelines contain provisions on policy measures; foreign trade and exchange policy measures; consumer protection, among others.

In  this newsletter, we discuss the provisions relating to the payments system within the monetary and credit policy measures, as well as policy developments under foreign trade and exchange measures.

1. The Payments System
In line with its vision of creating a widely used and internationally recognized payments system, the CBN aims to enhance the credibility and security of the Payments System. To achieve this, the CBN will continue implementing the Payments System Vision (PSV) 2025 throughout the 2024/2025 fiscal years. The PSV focuses on promoting the safety and efficiency of the payments system, deepening financial inclusion, and increasing  competition among service providers. To achieve this, the following key areas will be addressed:

i. Security of the Payments System

The CBN will continue to ensure that all regulated entities conduct their operations in line with global payment industry standards. These include: Payment Application Data Security Standard (PA DSS); Payment Card Industry PIN Entry Device (PCI PED); Payment Card Industry Data Security Standard (PCI DSS); Triple Data Encryption Standard (Triple DES); Europay, MasterCard and Visa (EMV) Standards; and others as may be stipulated from time to time. Card schemes and financial institutions are to ensure that all cards produced and issued in Nigeria are chip-based to enhance safety. To this end, the CBN will continue to enforce its payment system guidelines.1

ii. Payment System Initiatives

The CBN will promote the regulatory sandbox program where Fintechs can test and innovate with new financial products and services. The CBN will also advance contactless payments that allow customers to make payments by tapping their card or mobile device on a contactless terminal. This includes the implementation of the Quick Response (QR) code system, which facilitates payments through the scanning of a barcode (QR Code) with a mobile device.

iii. eNaira

According to the CBN, the eNaira, which is the digital version of Nigeria’s fiat currency, offers several benefits, including faster and cheaper payments, increased financial inclusion, and reduced fraud.2

Key initiatives  to drive its adoption include the rollout of eNaira version 2.0, focusing on wholesale Central Bank Digital Currency (CBDC) to encourage the participation of deposit money banks and empower them to champion its adoption. Additional efforts involve implementing offline functionality and fostering greater collaboration with Federal and State Governments to expand its usage.

iv. Operation of the Bank Verification Number

The CBN will continue to ensure compliance with the requirements for customers to obtain Bank Verification Number (BVN) and National Identification Number (NIN) which provide unique identifiers to customers and improve Know-Your-Customer (KYC) documentation. All Tier 1 bank accounts and wallets for individuals are mandated to have BVN or NIN while Tier 2 and 3 accounts must be linked to the BVN and NIN of their users. 3

 

2. Policy Developments in Foreign Exchange Market

The following developments will apply in the foreign exchange market during the 2024-2025 fiscal period.

i. Pan-African Payments and Settlement System

The Pan-African Payments and Settlement System (PAPSS) facilitates payments within Africa by enabling settlement of cross-border payments in local currency at lower costs, thereby boosting intra-African trade. 4

In a July 2023 circular, the CBN provided further clarifications regarding PAPSS transactions settled using CBN foreign exchange. The key points are as follows:

a.PAPSS transactions must be trade-backed.

b.Payments will be made using the “Bills for Collection” method. 5

c.The transaction limit per customer is set at USD 20,000 per quarter.

d.Authorized Dealer Banks (ADB) have a limit of USD 200,000 per quarter.

e.Multiple applications by customers through different ADBs are not permitted.

f.ADBs must obtain CBN approval for USD cover before initiating payments on PAPSS.

g.ADBs may maintain a USD settlement account with the PAPSS settlement bank for transactions where CBN cannot provide foreign exchange. 6

ii. Mechanisms for Bureau De Change Operations in Nigeria

To improve efficiency in the operations of the Bureau De Change (BDC) segment of the Foreign Exchange Market, the CBN recently introduced, the following:

a. Maintenance of a permissible limit of -2.5 per cent to +2.5 per cent of the Nigerian Foreign Exchange Market window weighted average rate of the previous day, being the spread on buying and selling by BDC operators; and

b. Mandatory rendition of daily and monthly returns by BDC operators on the Financial Institution Forex (FIFX) rendition system. 7

iii. Electronic Certificate of Capital Importation

To enhance transparency and efficient processing of investment flows into Nigeria, the CBN integrated the electronic Certificate of Capital Importation (eCCI) application with the Society for Worldwide Interbank Financial Telecommunication (SWIFT) database. The aim  is to verify all inflows before an eCCI is issued. 8

iv. Payout option in Naira for Receipt of Proceeds of Diaspora Remittances

In a move to further liberalize the payouts of diaspora remittances, the CBN introduced Naira payments in July 2023, in addition to USD and eNaira. This allows recipients of diaspora remittances to choose between receiving their funds in USD, Naira, or eNaira from licensed International Money Transfer Operators. Naira payments will be based on the Investors and Exporters (I&E) Window exchange rate applicable on the day of the transaction.

 

Conclusion

The Policy Guidelines reflect a commitment to enhancing the payments system, fostering financial inclusion, and improving the efficiency of foreign trade transactions. The outlined initiatives, from advancing the eNaira to streamlining cross-border payments through PAPSS, demonstrate the CBN’s intention to promote a more secure, inclusive, and globally competitive financial landscape.

For more on the Policy Guidelines, please visit https://pavestoneslegal.com/newsletters/ to read our analysis of CBN circulars and regulations issued over the past several years.

 

 

Footnotes

  1. Some of the many guidelines the CBN will continue to enforce include the New License Categorization for the Nigerian Payments System; Framework for Regulatory Sandbox Operations; Framework for Quick Response (QR) Payments in Nigeria; Circular on Issuance of Regulatory Framework for Open Banking; Regulatory Framework for Mobile Money Services in Nigeria, amongst others.
  2. Please see our article on eNaira here – https://pavestoneslegal.com/enaira-the-future-of-digital-currency-in-nigeria/
  3. Please see our article on the BVN Framework here – https://pavestoneslegal.com/regulatory-update-the-revised-regulatory-framework-for-bank-verification-number-bvn-operations-in-nigeria/
  4. Please see our article on the PAPSS here – https://pavestoneslegal.com/5815-2/
  5. This means that the payment is processed through banks, where the seller’s bank sends the shipping documents to the buyer’s bank, and the buyer pays when the goods are delivered.
  6. If the CBN cannot provide foreign currency for a particular transaction, banks (ADBs) can use their own USD accounts with PAPSS to settle these transactions directly, instead of waiting for the CBN to provide the funds.
  7. Please see our article on this here – https://pavestoneslegal.com/regulatory-update-central-bank-of-nigerias-operational-mechanism-for-bureau-de-change-operations-in-nigeria-a-note-to-bdcs/
  8. Please see our article on eCCI here – https://pavestoneslegal.com/doing-business-in-nigeria-the-relevance-of-the-certificate-of-capital-importation-to-foreign-investors-in-nigeria/

 

 

KEY REGULATORY CONSIDERATIONS FOR OPERATING A MONEY LENDING BUSINESS IN NIGERIA

By Aderonke Alex-Adedipe and Sharon Okpo

DOWNLOAD PUBLICATION

Introduction

Money Lending in Nigeria has evolved from traditional banking to a more flexible and technology-driven system which accommodates FinTechs and other digital companies, and has allowed for more convenience, speed, and efficiency. Following the evolution of money lending in Nigeria, there grew the need to regulate the activities of entities and their relations with borrowers. In this publication, we highlight some regulatory and compliance considerations which are relevant to establishing and operating money lending businesses in Nigeria.

  1. Who can Offer Money Lending Services in Nigeria?

In addition to the traditional banks such as the Deposit Money Banks (DMBs) and Microfinance Banks (MFBs), money lending services can also be offered by finance companies, corporative societies, and financial technology companies operating through a money lenders’ licence to carry out such activity.

  1. What are the Regulatory Concerns to Note in the Money Lending Business in Nigeria?

There are various regulatory and compliance issues to navigate in the operation of a money lending business. Some of these regulatory and compliance concerns are highlighted below:

    1. Licensing

Any entity wishing to carry on the business of money lending in Nigeria is required to obtain a Money Lending License. This license permits the holder to carry on money lending activities only in the state where it was issued. The Money Lender’s License is typically issued by the Ministry of Home Affairs in each state in Nigeria and is regulated by the money lending law applicable in each state. It is important to note that the license once issued expires on the 31st of December every year, regardless of the date of issuance.

Institutions such as deposit money banks, microfinance banks, merchant banks and finance companies are exempt from applying for a money lender’s license, as the relevant operating licenses issued by the Central Bank of Nigeria (CBN) and other regulating authorities also permit them to provide lending services to their customers.[1]

b. Registration with the Federal Competition and Consumer Protection Commission (FCCPC)

Further to the “Limited Interim Regulatory/Registration and Guidelines for Digital Lending 2022” (“Framework”) issued by the FCCPC, entities intending to carry on the business of digital lending in Nigeria are required to register with the FCCPC. Our previous newsletter highlights the requirements for the registration of a digital lender with the FCCPC. An approval must be obtained from the FCCPC before such entity may continue or commence the business of digital lending in Nigeria. Such registration is a one-time registration and requires compliance with the Framework to sustain the permit.

Where an entity proceeds to commence the business of digital money lending without this registration, such entity runs the risk of being banned from operating a money lender and having its lending mobile application delisted from the relevant digital distribution service hosting the mobile lending application (e.g. Google Play Store, or Apple Store).

It is important to note that entities which are exempt from applying for a money lender’s license are also exempt from applying for registration with the FCCPC. Such entities are however required to apply to obtain an exemption from the FCCPC on the basis that they are CBN regulated entities.

c. Consumer Protection

The FCCPC, in keeping with its mandate to safeguard the rights of consumers in Nigeria has set measures in place to deter digital lenders from exploiting consumers, or engaging in abusive conducts, in respect of balance calculations, loan default enforcement and recovery processes.

Digital money lenders are also required to develop and implement policies and systems aimed at protecting the rights of consumers of their services. In the engagement of money recovery agents, money lenders should ensure that the agents are not harassed and abused in an attempt to recover debts owed by consumers. Where necessary, the money lender should also enter into agreements with recovery agents which should contain provisions safeguarding the rights of the consumer/borrower.

Money lenders are also required to ensure transparency and accountability with the consumers, especially with respect to interest rates, penalties, mode of calculation, and disclosure of all charges.

Under the FFCPC Act, 2018 (FCCPA), the money lender is required to avoid unfair, unreasonable and unjust terms in its loan contract, such as waiver of any rights or assumption of obligation by the consumer and terms that limit or exempt the money lender from any loss directly or indirectly caused by its gross negligence.

The CBN Consumer Protection Framework also provides for minimum standards to be observed by financial institutions to adequately address customer complaints. Financial institutions are required to be transparent in their relations with customers, and to establish effective complaint channels.

d. Data Protection

As is the case with all entities collecting and processing personal data of Nigerian citizens, it is important that digital money lenders acknowledge and observe the requirements of relevant data protection laws in Nigeria, especially the Nigeria Data Protection Act, 2023 (NDPA). This is especially as digital money lenders utilize data provided by the borrowers for various processing activities including verification of identity, credit rating and assessment, marketing, etc.

There is an obligation on the money lender to observe all the provisions of the NDPA including informing the borrower of the data being collected and processed, the purpose for processing, details of any third-party with whom such data will be shared and obtaining the consent of the borrower before commencing any processing activity in respect of such personal data collected.

Furthermore, the CBN Consumer Protection Framework prohibits the disclosure of customer’s data by financial institutions that are regulated by the CBN.

e. Anti-Money Laundering /Combating Financing of Terrorism (AML/CFT) Requirement

Digital money lenders, especially those regulated by the CBN, are also required to observe and establish a governance framework that shows their commitment to adhere to AML/CFT regulations, and set up internal controls to mitigate against the risk of money laundering and terrorism financing.

Consequently, money lenders are required to have policies on AML/CFT; develop appropriate and effective know-your-customer (KYC) requirements; and implement internal controls to avoid the use of their facilities for money laundering and terrorism financing.

Money lenders are also required to identify and verify the identity of their customers prior to the disbursement of any facility. It is also important that the money lenders determine the categories of data/information required to conduct satisfactory customer due diligence, and the extend of such due diligence, especially putting into consideration the level of risk such customer may pose to the lender.

Conclusions The above list is not exhaustive, and it is advised that entities stay up to date on regulatory and compliance requirements for their operations as money lenders. It is also important that there are periodic upgrades and improvements to their governance framework, policies, and systems set in place in furtherance of any regulatory or compliance requirement as a money lender.   [1] For more information on this, please see our previous newsletter highlighting the operational limitations of these financial institutions.  

AVOIDING CORPORATE MISSTEPS: KEY QUESTIONS ANSWERED FROM THE REVOCATION OF THE HERITAGE BANKING LICENSE

By Seun Timi-Koleolu and Olawale Atanda

Download Publication

Introduction

On June 3, 2024, the Central Bank of Nigeria (CBN) revoked the banking license of Heritage Bank PLC. According to the CBN, this decision was taken in accordance with its mandate to promote a sound financial system in Nigeria and in exercise of its powers under Section 12 of the Banks and Other Financial Act 2020 (BOFIA).

The CBN stated that the bank’s inability to improve its financial position posed a threat to the stability of the financial ecosystem and the CBN was compelled to take the decision in order to strengthen public confidence in the banking system and ensure the soundness of the financial sector. Further to this, the Nigeria Deposit Insurance Corporation (NDIC) was appointed as the liquidator of the bank in accordance with Section 12 (2) of BOFIA.

In this article, we answer pertinent questions about the factors leading to the revocation of the license of Heritage Bank and discuss the essential lessons businesses, especially fintechs, can learn from this crisis to avoid similar pitfalls.

  1. What led to the revocation of Heritage Bank’s license?

In its public notice announcing the revocation, the CBN stated that Heritage Bank had breached Section 12(1) of the BOFIA, which outlines various infractions that can lead to the revocation of a bank’s license. Although the CBN did not specify the exact infraction, the NDIC highlighted that the bank’s loans exceeded its customer deposits. Additionally, public reports based on the audited annual report of the bank indicated that over 80% of the bank’s loans were non-performing. These issues and more likely  contributed to the CBN’s decision to revoke the bank’s license.

  1. What will happen to the deposits of Heritage Bank’s customers?

The NDIC is the official body that insures the deposits of customers in financial institutions in Nigeria. It also functions as the statutory liquidator for financial institutions whose licenses have been revoked by the CBN as provided in Section 55 (1) and (2) of the NDIC Act. Further to this, the NDIC has moved to ensure that the Heritage Bank’s customers recover their deposits. According to the NDIC, depositors with a bank balance of less than NGN5 million, the maximum insured limit by the NDIC, will be fully reimbursed.

For balances exceeding the insured limit, the excess amount will be treated as an unsecured credit. Depositors will receive liquidation dividends from the proceeds of the liquidated assets of the bank once the bank’s assets have been realized and loans recovered.

  1. What strategies can help keep bad loans at the minimum?

Some of the strategies that companies in the financial services space can implement to keep bad loans at the barest minimum are:

i. Use of Credit Scoring Methods: Companies should utilize credit bureaus to provide an accurate assessment of borrowers’ creditworthiness which would in turn help in determining the credit viability of a borrower.

ii. Partnerships and Collaborations: Businesses can enter into partnerships and collaborations with other financial institutions or fintechs to share risk. This can include co-lending arrangements or selling portions of the loan portfolio to other lenders.

iii. Efficient, Effective, and Ethical Loan Recovery Methods: Companies should implement efficient and effective loan recovery methods, including dedicated teams for collections and the use of technology for automated reminders and follow-ups. Companies can also explore legal avenues for recovery but must always ensure ethical loan recovery standards are upheld.

iv. Customer Education: It is advisable that companies invest in financial literacy programs to educate customers on responsible borrowing and effective financial management because improved borrower education can reduce the likelihood of defaults.

v. Good corporate governance: Effective corporate governance ensures accountability, fairness, and transparency in a company’s relationships with its stakeholders. It helps prevent mismanagement and unethical practices while also signaling to potential investors that the company has robust governance structures and sound risk management systems. This assurance enhances investor confidence and indicates that their investments will be protected and yield returns.

For more on how startups can implement strong and effective corporate  governance structures, please see our article on corporate governance best practices here https://pavestoneslegal.com/corporate-governance-and-startups-lessons-from-the-collapse-of-the-silicon-valley-bank/

  1.  How can companies ensure they remain compliant with regulations?

It is important that companies prioritize compliance with regulations to avoid regulatory sanctions. Compliance steps that companies can take include:

i. Conducting regular risk assessments to identify potential areas of non-compliance and vulnerabilities within the company.

ii. Staying updated with the latest regulatory requirements and ensuring that all business practices align with these regulations.

iii. Appointing a Chief Compliance Officer (CCO) or Chief Risk Officer (CRO) to oversee compliance and risk management as they will have the authority and resources to enforce compliance across the organization.

iv. Implementing comprehensive compliance training programs for all employees to ensure that staff are aware of regulatory changes and understand their roles in maintaining compliance.

v. Working with legal advisers who specialize in regulatory compliance to help in interpreting complex regulations and ensuring that the company’s practices are in line with legal requirements.

Conclusion

In conclusion, the revocation of Heritage Bank’s license serves as a stark reminder of the importance of strong corporate governance, effective risk management, and strict regulatory compliance in the operations of a business. Companies must ensure that they put these standards in place to avoid regulatory sanctions and business hazards.

REGULATION OF CYBERCRIME IN NIGERIA AND THE CYBERSECURITY LEVY

BY SEUN TIMI-KOLEOLU AND HILLARY OKOROTIE

DOWNLOAD PUBLICATION

INTRODUCTION

On May 6, 2024, the Central Bank of Nigeria (“CBN”) published a circular providing “Implementation Guidance on the Collection and Remittance of theNational Cybersecurity Levy” (the “CBN Circular”) introduced by the Cybercrime (Prohibition, Prevention, etc.) Act of 2015 and amended by the Cybercrime (Prohibition, Prevention, etc.) Amendment Act 2024 (the “Act”). The Circular has raised concerns about its implications for businesses and individuals. There are also concerns about whether the CBN has properly interpreted the application of
the levy.

In this article, we have provided a general background on the regulation of Cybercrime in Nigeria and also set out our view on the implementation of the Cybercrime levy by the CBN.

A. What is the Applicable Law on Cybercrime in Nigeria?

In Nigeria, Cybercrime is primarily regulated by the Cybercrime (Prohibition, Prevention, etc.) Amendment Act 2024. The Act addresses various cyber-related offences and is aimed at instituting an effective regulatory framework that prohibits and prosecutes cybercrime in Nigeria. It prescribes different cybersecurity obligations for organizations including financial institutions in the country.

It also grants the President the right to designate certain major computer systems, programs, and networks as critical national information infrastructure and prescribe minimum standards, guidelines and rules in respect of such infrastructure.

B. What is Recognized as Cybercrime under the Act?

The Act provides a list of different activities that will be considered to be Cybercrime in Nigeria including:

(i) knowingly altering data with the intention that such data will be acted upon as if it were authentic;

(ii) misdirecting electronic mail with the intention to fraudulently obtain financial gains;

(iii) unlawfully destroying or aborting any electronic mail through which money or valuable information is being conveyed, etc. The Act also states the penalties for such activities.

C. Where did the Cybersecurity Levy Originate From?

The Cybersecurity Levy (the “Levy”) was introduced by section 44(2)(a) of the Act and amended by the Cybersecurity Amendment Act. The Act (as amended) provides that a Levy of 0.5% or 0.005 is to be remitted by the following businesses (set out in the second schedule of the Act) to a National Security Fund domiciled with the CBN:

i. Banks and other Financial Institutions
ii. GSM Service providers and all telecommunication Companies
iii. Internet Service Providers
iv. Insurance Companies
v. Nigerian Stock Exchange.

D. What is the Cybersecurity Levy to be Used For and Who is to
Administer the Fund?

What is clear from the Act is that the levy collected is to be administered by the Office of the National Security Adviser and included as part of the National Security Fund. The Act states that 40% of the Fund (which comprises of various levies collected by government) may be used for programs relating to countering violent extremism.

E. What is stated in the 2024 CBN Implementation Guidance on the
Collection and Remittance of the National Cybersecurity Levy?

Although the Cybersecurity Levy is a levy introduced by the Act, there had been no steps taken by regulators to implement it until the recent CBN Circular.

With the recently issued CBN Circular, CBN placed a responsibility on Banks, Payment Service Providers, and other Financial Institutions (the “Financial Institutions”) to commence the collection of the Cybersecurity Levy from
businesses and customers in the course of their transactions. The Circular requires Financial Institutions to collect a Cybersecurity levy of 0.5% on all electronic transactions at the point of the electronic transfer origination and
remit the sums collected to the Fund. The deducted amount is to be reflected as “Cybersecurity Levy” in the customer’s account.

F. When is the CBN Guidance to Take Effect?

According to the Circular, all deductions from electronic transactions is to commence 2 weeks from the date the circular was published. Commercial, Merchant, Non-Interest Banks, and Mobile Money Operator are to ensure they configure their systems within 4weeks to collect the levy in an automated manner whilst all other Financial Institutions have been given eight weeks to configure their systems to collect the levy in an automated manner.

G. What Transactions Are Exempted?

The Circular sets out 16 transactions excluded from the Cybersecurity levy including the following:

i. loan disbursement and repayment;
ii. salary payments;
iii. inter-branch transfers with one bank;
iv. letters of credits;
v. intra-bank transfers between customers of the same bank;
vi. bank transfers to CBN;
vii. educational institution transactions including tuition payments and other
related transactions;
viii. non-profit organization transactions, etc.

H. Is There a Penalty for Failing to Deduct the Cybersecurity Levy?

The Guidance states that institutions that fail to deduct the Levy as prescribed will be fined at least 2% of the institution’s annual turnover.

Conclusion

A review of Section 44 of the Act on its own, suggests that the intention of the draftsman when introducing the Cybersecurity Levy was for the levy to apply to businesses as stated in the Second Schedule listed above; and not to broaden its implementation to affect all individuals and businesses in the Country in the manner that the CBN Circular purports to achieve.

We note that the implementation of the Circular by the CBN is currently being challenged by the House of Representatives and the public. We expect that more clarity will be provided on the application of the Cybersecurity Levy once deliberations have been concluded.

 

FINANCIAL SERVICES REGULATION IN NIGERIA: THE PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS

By Aderonke Alex- Adedipe  and Feyijuwa Akinyanmi

DOWNLOAD PUBLICATION

Introduction

Since the introduction of electronic payments systems in Nigeria, the Central Bank of Nigeria (“CBN”) has sought to maintain a high standard of conduct within the banking sector to protect consumers. One of the measures implemented by the CBN to achieve this, is the requirement that financial institutions involved in electronic payments are required to comply with the provisions of the Payment Card Industry Data Security Standards (“PCI DSS”).

This newsletter provides a brief exposition on PCI DSS and the compliance requirements.

What is PCI DSS?

PCI DSS is a set of security standards developed by prominent card schemes: MasterCard, Visa Inc., American Express, Discover Financial Services and JCB International, to ensure the security of debit and credit card transactions and prevent data theft and fraud. It includes technical and operational requirements which are designed to protect the data of payment cards. The PCI DSS is managed by the above- mentioned card schemes, which form the Payment Card Industry Security Standards Council and are responsible for the review of the PCI DSS [1].

Who should comply with the PCI DSS?

The PCI DSS requires all financial institutions that store, process, and/or transmit cardholder data to be compliant. Furthermore, merchants/vendors that accept or process payments cards are also to comply with the standards.

In addition to the above, the CBN through its Guidelines for Card Issuance; and Usage in Nigeria and the Guidelines on Operation of Electronic Payment Channels in Nigeria, requires all financial institutions that process, transmit and/or store cardholder information to ensure compliance with the PCI DSS and to conduct continuous reviews of their policies and practices in line with the standards.

Examples of these financial institutions include Deposit Money Banks, Microfinance Banks, Payment Service Operators e.t.c.

What are the Requirements of the PCI DSS?

To be compliant with the PCI DSS, the financial institution is required to meet 6 goals as highlighted in the table below.

S/N Goals Requirements
1. Build and maintain a secure network and systems •Install and maintain network security controls.

•Apply secure configurations to all system components.

2. Maintain an Information Security Policy •Support information security with organizational policies and programs.
3. Regularly Monitor and Test Networks •Support information security with organizational policies and programs.

•Log and monitor all access to system components and cardholder data.

•Test security of systems and networks regularly.

4. Protect Account Data •Protect stored card account data.

•Protect cardholder data with strong cryptography during transmission over public network.

5. Maintain a Vulnerability Management Program •Protect all systems and networks from malicious software.

•Develop and maintain secure systems and software.

6. Implement Strong Access Control Measures •Restrict access to system components and cardholder data by business need to know.

•Identify users and authenticate access to system components.

•Restrict physical access to cardholder data.

How are PCI DSS assessments conducted?

Entities required to comply with the PCI DSS are to undergo a form of assessment to determine their compliance with the PCI DSS. Each card scheme is permitted to develop their compliance programs which would dictate the form of assessment the entity needs to conduct.
The assessment could be through Self- Assessment Questionnaires which is filled by the entity or Report on Compliance- a report by Qualified Security Assessors appointed by the Payments Card Industry Security Standards Council which is constituted by the card schemes.

Conclusion

Although the PCI DSS does not provide for sanctions and penalties for failure to comply with its requirements, card schemes are at liberty to set out penalties against financial institutions and vendors found to be non-compliant. In addition, the CBN is also empowered to sanction non-compliant organisations. It is therefore advisable that all financial institutions take the relevant steps to understand the requirements of the PCI DSS and adhere to them.

Additional information about the PCI DSS is contained here.

 

REGULATORY UPDATE: REGISTRATION OF DIGITAL LENDING COMPANIES WITH THE FEDERAL COMPETITION AND CONSUMER PROTECTION COMMISSION

By Aderonke Alex-Adedipe and Eustace Aroh

 

Introduction

In 2021, the National Information Development Technology Agency (“NITDA”) issued a fine of 10 Million Naira against Soko Lending Company (a digital lending company) after receiving over 40 petitions on the abuse of personal data by the lending company.[i] Due to the rising complaints about the abuse of customers’ rights, the NITDA consequently collaborated with the Federal Competition and Consumer Protection Commission (“FCCPC”) for the protection of the rights of Consumers. The FCCPC had since then (together with the Inter-agency Joint Regulatory and Enforcement Task Force[ii]) imposed and enforced several sanctions on digital lending companies for breach of consumer rights.

On August 18, 2022, the FCCPC issued the “Limited Interim Regulatory/Registration Framework and Guidelines for Digital Lending 2022” (the “Framework”) further to its enabling Act[iii], which would allow the FCCPC regulate the digital lending space.

Who does the Framework apply to?

The Framework was issued and aimed at any company intending to carry on the business of digital lending in Nigeria.

Potential Conflict with the BOFIA 2020

Upon review of the Framework, it would appear that the Framework seeks to apply to all digital lending companies irrespective of their enabling license. In view of provisions of the Bank and Other Financial Institution Act 2020 (“BOFIA”), however, the intention of the FCCPC to regulate institutions licensed by the Central Bank of Nigeria (“CBN”) conflicts with the provision of section 65 of the BOFIA. Specifically, section 65 restricts the Federal Competition and Consumer Protection Act 2019 (FCCPA)[iv] from applying to the services of banks and other financial institutions.

Provisions of the Framework

  1. The Framework requires digital lending companies to apply to the FCCPC for registration by completing the FCCPC Interim Digital Lending Guidelines Form 001. The FCCPC will further request for specific information on the lending business of the company such as:
  1. the name and contact address of the business in Nigeria;
  2. The identity and nationality of the promoters, directors, nominee directors, secretaries, and key officials;
  3. the source of funding including the nature of the instrument, identity, nationality and nature of business of the source;
  4. any affiliations the lending company has with any company whether in Nigeria or abroad including parent companies, subsidiaries, associate companies etc;
  5. the license authorizing the business;
  6. a list of its digital application used in its operation;
  7. the interest rate and applicable fees including the method of calculation.

 

  1. The Framework also requires lending companies to prepare and submit the following documents together with their application for registration.
  1. Incorporation documents.
  2. An organogram showing its key officers.
  3. Contact information of the staff authorised to accept correspondence.
  4. Service level agreement with its service providers relating to operations.
  5. Evidence of feedback and complaint mechanism.

 

  1. The lending company is expected to appoint a representative who will relate with the FCCPC and act on behalf of the company.

 

Conclusion

Whilst the Framework is an interim instrument, the intention is to ensure that all digital lending companies are governed by a single regulatory regime in view of consumers’ rights.

The Framework, however, does not provide clear rules for digital lending companies to comply with. It is expected that upon release of the final regulation, the rules of the FCCPC will be adequately spelt out and CBN licensed institutions will be exempted from the Framework.

[i] See the NITDA press release <https://nitda.gov.ng/nitda-collaborates-with-the-federal-competition-and-consumer-commission-fccpc-to-tackle-data-abuse-by-money-lending-operations/>

[ii] An inter-agency Joint Regulatory and Enforcement Task Force was formed constituting the FCCPC, NITDA, Independent Corrupt Practices Commission (ICPC) etc.

[iii] The Federal Competition and Consumer Protection Act 2019 (“FCCPA”)

[iv] The enabling law of FCCPC