Posts

REDEFINING AML COMPLIANCE: UNDERSTANDING CBN’S BASELINE STANDARDS FOR AUTOMATED AML SOLUTIONS FOR FINANCIAL INSTITUTIONS

BY ADERONKE ALEX-ADEDIPE AND HILLARY OKOROTIE

Introduction

With the increasing need to ensure financial security in today’s rapidly digitizing landscape and evolving compliance demands, the Central Bank of Nigeria (CBN) issued its Baseline Standards for Automated Anti-Money Laundering (AML) Solutions for Financial Institutions (“AML Solutions”) on March 10, 2026. This was followed by a Guidance Note on implementation, released on March 31, 2026.

In this newsletter, we provide an overview of the requirements of the AML Solutions for financial institutions.

What is the Purpose of the AML Solutions?

The AML Solutions is aimed at establishing a structured and automated system for the identification and reporting of suspicious transactions and strengthening adherence to AML, Combating the Financing of Terrorism (CFT), and Countering Proliferation Financing (CPF) regulatory requirements. It also applies to all financial institutions operating in Nigeria.

What are Some of the Obligations of Financial Institutions?

  1. Customer Due Diligence (CDD), Know Your Customer (KYC) and Know Your Business (KYB): Financial institutions are required to implement effective CDD, KYC and KYB frameworks supported by automated or semi-automated onboarding, instant identity verification, and integration with national identity databases such as the Bank Verification Number (BVN) and National Identification Number (NIN) systems. They must also ensure proper documentation of beneficial ownership, maintain accurate and up-to-date customer data. AML Solutions must support end-to-end CDD, KYC, KYB, and enhanced due diligence processes, including automated risk profiling and behavioral transaction analysis. They must also enable continuous data integration of KYC/KYB data with customer risk profile to provide investigators with a unified view of customer profiles and transactional history for effective monitoring and decision-making.
  1. Sanction Lists & Politically Exposed Person (PEP) Screening: Financial institutions are required to conduct sanctions and screening of PEP at onboarding and on a continuous basis. They are also required to maintain clear procedures for reviewing, escalating, and resolving alerts and being able to demonstrate the effectiveness of their screening processes with proper documentation. AML Solutions must integrate domestic/international sanctions and watchlists with instant updates, automatically flagging or blocking transactions on confirmed matches in line with regulatory requirements.
  2. Risk Assessment & Transaction Monitoring: Financial institutions are required to conduct and document periodic business risk assessments and ensure AML systems reflect these risk profiles. The AML Solutions must assess transactions based on risk and identify possible money laundering activities. It should generate explainable alerts and enable pre-emptive actions to support decision-making.
  3. Reporting & Governance: Financial institutions must ensure accurate, complete, and timely regulatory reporting, supported by internal reviews and approval processes. The AML Solutions must be implemented to ensure automated or semi-automated generation of the required reports. They are also required to establish governance frameworks covering system ownership, access controls, model validation, and periodic audits.
  4. Security & Data Protection: There is also a requirement that all data processed and stored within AML systems comply with the scope of the Nigeria Data Protection Act (NDPA) 2023 and other applicable regulations. The AML Solutions must support this by securely collecting and storing relevant data, applying security controls such as encryption in transit, at rest, and in use, enforcing role-based access and secure authentication.

What is the Compliance Timeline for the AML Solutions?

The compliance timeline for the AML Solutions is 18 months for deposit money banks and 24 months for other financial institutions. However, all financial institutions are required to prepare and submit a detailed implementation plan to the CBN within 3 months of the issuance of the AML Solutions. The implementation plan must provide a clear and detailed roadmap on the steps the financial institution intends to implement to meet all obligations set out in the AML Solutions.

What is the Risk of Non-Compliance?

Where financial institutions fail to implement the AML Solutions or does so in a manner that results in ineffective AML/CFT/CPF controls, they may be subject to penalties. This liability extends not only to the financial institutions but also to personnel responsible for the implementation of the AML Solutions. Applicable penalties will be imposed in accordance with existing regulations, including the CBN AML-CFT-CPF Administrative Sanctions Regulations 2023, the Banks and Other Financial Institutions Act, and other relevant regulatory frameworks.

Conclusion

The AML Solutions imposes clear and enforceable obligations on financial institutions to implement effective, technology-driven frameworks for detecting and monitoring money laundering and other related activities. It is therefore imperative for financial institutions to promptly implement these requirements in line with the prescribed timelines.

KEY REGULATORY UPDATE: CBN GUIDELINES ON INSTANT PAYMENT FUNCTIONALITIES AND MOBILE BANKING SECURITY

By: Aderonke Alex-Adedipe and Mark Imonitie

Introduction

On 12 March 2026, the Central Bank of Nigeria (CBN) issued a circular (the “Circular”) to all financial institutions (FIs) offering Instant Payment (IP) services in Nigeria.

The Circular provides the CBN’s Guidelines on instant payments and introduces sweeping measures to strengthen IP operations, enhance security protocols, improve consumer protection, and align with global best practices. This newsletter highlights the key provisions introduced by the Guidelines.

  1. VOLUNTARY OPT-IN AND OPT-OUT FUNCTION

Under the existing framework, FIs are not mandated to provide a feature on their mobile banking application, enabling customers to voluntarily opt in or out of IP services.

The new Guidelines however require FIs to allow customers to opt in or out at any time, subject to Multi-Factor Authentication (MFA).

New customers will be onboarded in opt-in mode by default. While opted out, customers cannot perform instant online fund transfers from their account; however, such transfers remain available via a physical branch visit.

  1. FLEXIBILITY IN SETTING TRANSACTION LIMITS

Prior to establishing the Guidelines, the maximum transaction limits of N25,000,000.00 for individuals and ₦250,000,000.00 for corporate entities, were fixed, with no option for customers to set personalized limits within those thresholds.

The Guidelines will subsequently allow both individuals and corporate entities to adjust these limits as needed, subject to enhanced due diligence and appropriate risk management by the FI.

To ensure security, the new transaction limit takes effect only after the customer completes the Multi-Factor Authentication (MFA) process.

  1. LIVELINESS CHECKS AND ENHANCED SECURITY FOR ONLINE TRANSACTIONS
    The Guidelines provide that where a customer seeks to open an account online or reactivate an online account, the following enhanced security measures shall apply:

    • liveliness check of the online account;
    • real-time validation of BVN/NIN database for online account openings/reactivations;
    • enhanced authentication mechanisms such as biometric authentication, soft token, hard token, for online account reactivations.

    A liveliness check is a biometric security measure which confirms that a user is a live, physically present human rather than a photo, video, or deepfake—by analyzing facial traits like skin texture, eye movement, and depth during remote onboarding or transactions, thereby preventing spoofing attacks.

  2. FRAUD MONITORING FUNCTIONALITY

The Guidelines mandate that all FIs implement and activate enterprise-wide fraud monitoring functionality covering both in-flows and out-flows. This measure restricts suspicious transactions in real-time while enabling prompt fraud detection and response.

  1. MANDATORY DEVICE BINDING

Under the existing framework, customers can operate their mobile banking application concurrently on multiple devices. The new Guidelines restrict mobile banking applications to one active device at a time, prohibiting concurrent use across devices. Switching to a new device triggers automatic deactivation of the previous one, followed by re-activation and authentication.

  1. ADDITIONAL REQUIREMENTS

The Guidelines introduce the following measures for mobile financial services applications and internet banking:

  • New account owners: Upon activation of a mobile banking application, inflow and outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira).
  • Existing account owners: Upon activation of a mobile banking application, outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira)
  • First-time login on a new device for internet banking requires enhanced Multi-Factor Authentication (MFA).

Conclusion

The Central Bank of Nigeria’s (CBN) new Guidelines on Instant Payment Functionalities for Financial Institutions mark a significant advancement in safeguarding digital transactions nationwide.

Effective 1 July 2026, financial institutions (FIs) must implement these measures. Among other requirements, the Guidelines necessitates comprehensive security and Data Protection Impact Assessments (DPIAs) to ensure compliance with the Nigeria Data Protection Act 2023 particularly resulting from mandatory features like multi-factor authentication (MFA), facial recognition, and continuous transaction monitoring.

About us:

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organization. We provide quality and innovative legal and data protection  support across diverse industries, helping clients operate in compliance with applicable laws and regulations to drive sustainable business growth.