Posts

NIGERIA’S FOREIGN EXCHANGE MARKET: RECENT REGULATORY REQUIREMENTS FOR BDC OPERATORS AND BANKS

BY ADERONKE ALEX-ADEDIPE & HILLARY OKOROTIE

Introduction

On February 10, 2026, the Central Bank of Nigeria (CBN) issued a circular on the Participation of Licensed Bureau De Change Operators in the Nigerian Foreign Exchange Market, permitting licensed Bureau De Change (BDC) operators to participate in the Nigerian Foreign Exchange Market (NFEM).

Following the commencement of BDC operators’ participation in the NFEM, the CBN, on July 15, 2026, issued the Guidance on the Purchase of Foreign Exchange by Bureau De Change Operators Through Authorized Dealer Banks in the Nigerian Foreign Exchange Market (the “Guidance Notice”). The Guidance Notice establishes the procedures governing the purchase of foreign exchange by BDC operators through authorized dealer banks and outlines the obligations of dealer banks in facilitating such transactions.

In this newsletter, we provide insights on the obligations of BDC operators and authorized dealer banks.

What Are the Obligations of Dealer Banks and BDC Operators Under the Guidance Notice?

Under the Guidance Notice, dealer banks and BDC operators are required to undertake the following:

  1. Due Diligence Processes
    Under the Guidance Notice, dealer banks are required to conduct Know Your Customer (KYC) and Customer Due Diligence (CDD) checks  before engaging in any foreign exchange transaction with a BDC operator. As part of this process, dealer banks must obtain and verify the BDC operator’s incorporation documents, valid operating license, as well as beneficial ownership information. Where a BDC operator is identified as presenting a higher risk following the due diligence assessment, the dealer bank is required to apply Enhanced Due Diligence (EDD) measures before proceeding with the transaction. 
  2. Fulfilment of Foreign Exchange Purchase Requests
    Requests by BDC operators to purchase foreign exchange must be submitted through the CBN’s Foreign Exchange Purchase Tracker Portal (the “Portal”) to the preferred authorized dealer BDC operators are required to register on the Portal and provide real-time updates of all foreign exchange purchase transactions. . Upon receipt of the BDC’s purchase request, the dealer bank may either approve or reject the request through the Portal. Where a request is rejected, the dealer bank must state the reason for the rejection on the Portal.The Guidance Notice also permits BDC operators to submit multiple foreign exchange purchase requests within a week, provided that the value of the purchases does not exceed the prescribed weekly purchase limit of US$150,000.

     

  3. Disbursement of Funds to BDC Operators
    In processing and fulfilling a foreign exchange purchase request, dealer banks are required to disburse foreign exchange only into foreign exchange settlement accounts maintained by the BDC operators with licensed financial institutions. Dealer banks must ensure that all disbursements are made solely to the BDC operator’s designated settlement account and not to the account of any third party. Any disbursement of foreign exchange to a third-party account constitutes a breach of the Guidance Notice and may attract sanctions against the dealer bank by the CBN. 
  4. Retention of Purchased Foreign Exchange
    BDC operators are required to sell all foreign exchange purchased through the NFEM within 24 hours. Any outstanding balance must be sold within 24 hours. Failure to comply may result in regulatory sanctions, including the forfeiture of the outstanding balance to the CBN or the suspension of the BDC operator’s license. In addition, BDC operators are required to disclose any outstanding balance in their foreign exchange purchase request for the following week. 

What Are the Penalties for Non-Compliance?

The CBN has prescribed sanctions for breach of its circular on the Participation of Licensed Bureau De Change Operators in the Nigerian Foreign Exchange Market and the Guidance Notice. BDC operators that fail to comply with these directives may be subject to monetary penalties, suspension or revocation of their operating license, or suspension of their access to the NFEM.

Similarly, dealer banks that fail to comply with the CBN’s directives when transacting with BDC operators may have their status as authorized dealer banks revoked. Where a breach involves suspected criminal conduct, the CBN may also refer the matter for criminal investigation and prosecution to the appropriate authorities

Conclusion

The CBN’s objective in permitting BDC operators to purchase foreign exchange through authorized dealer banks in the Nigerian Foreign Exchange Market (NFEM) is to improve liquidity within the formal foreign exchange market. The framework is also intended to curb abuses and arbitrage in the foreign exchange market. If properly implemented therefore, it is expected that these policies will sustain the current stability in the market.

For more information on the participation of BDC operators in NFEM, please see our previous newsletter.

 

BEYOND LICENSING – CBN’S DRAFT GUIDELINES FOR FINANCIAL HOLDING COMPANIES IN NIGERIA

BY ADERONKE ALEX-ADEDIPE AND ENIOLA SOGBESAN

BEYOND LICENSING – CBN’S DRAFT GUIDELINES FOR FINANCIAL HOLDING COMPANIES IN NIGERIA.

Introduction

On 10 June 2026, the Central Bank of Nigeria (CBN) issued an Exposure Draft of the Revised Guidelines for Licensing and Regulating Financial Holding Companies (FHCs) in Nigeria (the “Draft Guidelines”). The Draft Guidelines is the first review of Nigeria’s financial holding company framework since the introduction of the Guidelines for the Licensing and Regulation of Financial Holding Companies in Nigeria 2014 (the “2014 Guidelines”).

The Draft Guidelines seek to:

  1. strengthen the financial resilience of holding companies;
  2. improve group-wide governance and oversight;
  3. clarify ownership and control requirements;
  4. enhance regulatory supervision of financial groups; and
  5. address concerns arising from shared service arrangements and complex group structures.

For existing FHCs, banking groups, investors, and prospective promoters, the Draft Guidelines signal a shift from a regime focused primarily on licensing to one that places greater emphasis on governance, capital adequacy, ownership accountability, and consolidated supervision.

Key Highlights of the Draft Guidelines

  1. Definition and StructureThe Draft Guidelines introduce a clear definition of what constitutes a FHC. Under the Draft Guidelines, a FHC is defined as a non-operating holding company that has two or more direct subsidiaries, one of which must be a bank. The Draft Guidelines further stipulate that a FHC may adopt either a Parent HoldCo or Intermediate HoldCo structure.Under the Parent HoldCo structure, a parent holding company holds direct equity investment in each Nigerian subsidiary, however under the Intermediate HoldCo structure, an intermediate holding company is incorporated for the purpose of holding equity investment in foreign subsidiaries. Accordingly, all existing FHCs are required to notify the CBN of their preferred structure within six (6) months of the effective date of the Guidelines. Also, once the preferred structure is approved by the CBN, such FHC must operate that structure for a minimum of 5 years before it may elect to reverse or alter the approved structure.

    The Draft Guidelines list individuals, non-bank corporate investors and banks [commercial, merchant and non-interest] as eligible promoters of FHCs. This clarification provides greater regulatory certainty for investors considering the use of a holding company structure to expand their presence within Nigeria’s financial services sector.

  1. Permissible and Non-Permissible Activities
    Under the Draft Guidelines, the following activities are permissible for FHCs. These activities include-
    1. holding equity investment in subsidiaries engaged in financial services;
    2. investment in government securities or placement with banks;
    3. with the prior approval of the CBN, raising bonds and debentures;
    4. subject to the prior approval of the CBN, borrowing internationally to capitalize any of its subsidiaries and;
    5. providing either by itself or through any subsidiary, shared services to the group members in respect of facilities, legal and ICT services and other services that may be prescribed by the CBN from time to time.

However, FHCs are prohibited from engaging in the following activities –

    1. investing in entities not involved in financial services;
    2. pledging its shares in any subsidiary as collateral for any purpose;
    3. establishing, divesting or closing any subsidiary without the prior approval of CBN;
    4. interfacing with any customers of its subsidiaries and;
    5. bearing the expense of any of its subsidiaries.
  1. Corporate Governance Requirements
    In addition to the provisions of the Corporate Governance Guidelines for Financial Holding Companies in Nigeria, the Draft Guidelines introduce additional corporate governance rules for FHC’s.Some of these additional corporate governance are –
    1. subsidiaries of FHCs are prohibited from acquiring shares in the FHC and/or other subsidiaries of the FHC;
    2. Nominee companies that are subsidiaries of the FHC are prevented from investing client funds in the FHC or any other subsidiary;
    3. where a FHC loses control in the only or all Nigerian banking subsidiaries for a period that exceeds six (6) consecutive months, its license shall be revoked;
    4. where a FHC that has only two (2) subsidiaries loses control in either subsidiary for a period that exceeds six (6) consecutive months, its license shall be revoked;
    5. No employee of a FHC shall be appointed as a non-executive director in the FHC or any other subsidiary; and
    6. interlocking directorship within a FHC is limited to a maximum of one other company.More importantly, the Corporate Governance rules of the Draft Guidelines are required to be read in conjunction with the Nigerian Code of Corporate Governance 2018, Corporate Governance Guidelines for Financial Holding Companies in Nigeria and where applicable the SEC’s Code of Corporate Governance for Public Companies and Listed Entities in Nigeria.
  1. Intra-Group Transactions, Prudential Requirements & AML/CFT Compliance
    The Draft Guidelines make extensive provisions for intra-group transactions. More specifically, FHCs are prohibited from interfering in the daily operations of their subsidiaries and all transactions with their subsidiaries must be strictly on an arm’s length basis. In particular, the Draft Guidelines expressly prohibit the practice where board members of a subsidiary attend board meetings of the FHC and vice versa.All FHCs are required to maintain a minimum regulatory capital which shall exceed the sum of the minimum regulatory capital of its subsidiaries by at least 20%. In determining what constitutes minimum regulatory capital, the Draft Guidelines provide that only the paid up capital shall be recognized. Additionally, excess capital in one subsidiary shall not be computed to make up for a shortfall in the share capital of another subsidiary.Furthermore, the Draft Guidelines require all FHC’s to comply with all AML/CFT/CPF regulations and to appoint a compliance officer who shall not be below the grade of a senior management staff responsible for filing the required returns with the CBN.

What Should Financial Holding Companies Be Doing Now?

Although the Draft Guidelines remain in draft form, affected institutions should begin evaluating the potential implications of the proposed framework.

Key considerations include:

    1. assessing compliance with the proposed ownership thresholds;
    2. reviewing group structures and foreign subsidiary arrangements;
    3. evaluating shared service models and related documentation;
    4. assessing capital adequacy and funding arrangements;
    5. reviewing governance frameworks and board oversight mechanisms; and
    6. identifying areas that may require regulatory engagement or restructuring.

Conclusion

The Draft Guidelines appears to be more than a routine update of the 2014 Guidelines. It reflects a broader regulatory shift towards stronger governance, clearer ownership structures, enhanced prudential safeguards, and more effective consolidated supervision of financial groups. For financial holding companies and banking groups, the message is clear: regulatory expectations are evolving beyond licensing and corporate structure requirements only.

The practical implication of the Draft Guidelines is that financial holding companies must begin to reassess their governance frameworks, group structures, risk management systems, and compliance functions to ensure alignment with the heightened regulatory standards. As the Central Bank of Nigeria continues to strengthen its supervisory oversight of financial conglomerates, early preparation and strategic compliance will be critical to achieving long-term sustainability and regulatory success.

KEY REGULATORY UPDATE IN NIGERIA: THE CBN FOREIGN EXCHANGE MANUAL 2026

BY SEUN TIMI-KOLEOLU & OLUWAYEMI IBIRINDE

Introduction

On June 1, 2026, the Central Bank of Nigeria (CBN) implemented the Fourth Edition of the Foreign Exchange Manual (the “2026 Manual”), replacing the Foreign Exchange Manual 2018 (the “2018 Manual”). The 2026 Manual introduces significant changes to currency and trade rules and consolidates various foreign exchange policies and directives into a single framework governing foreign exchange transactions in Nigeria. While the 2026 Manual introduces measures intended to improve access to foreign exchange and facilitate cross-border transactions, it also strengthens regulatory oversight and significantly increases the consequences of non-compliance.

In this newsletter, we highlight some of the key changes introduced by the 2026 Manual and their implications for financial institutions and other stakeholders.

Key Operational Adjustment

Increased Flexibility for Trade and Foreign Exchange Transactions

  1. Import and Export
    Under the 2018 Manual, importers were generally permitted to make advance payments of up to 15% of the Free on Board (FOB) value of physical imports. However, under the New Manual the permissible advance payment threshold for physical imports has been increased to 30% of the Free on Board (FOB) value of the goods. This adjustment provides importers with greater flexibility in negotiating payment terms with foreign suppliers and may reduce procurement challenges associated with international trade transactions.Also, to incentivize international trade and reduce processing hassles, the New Manual mandates that the processing of Form NXP for exporters shall now be entirely free of charge.  These measures are expected to simplify access to foreign currency held in domiciliary accounts and reduce administrative blockages associated with remittance transactions.
  2. Tuition Remittances
    Under the 2018 Manual, International tuition fee remittances were restricted to USD 15,000 per semester, capped at two semesters per year. However, the 2026 Manual raises this threshold to USD25,000 per semester. This provision provides greater clarity regarding the amount that may be accessed through official channels for educational expenses.

  3. Domiciliary Account Holders
    Also, the 2026 Manual removes the Form A requirement for outward remittances for holders of self funded domiciliary accounts.

    Similarly, Domiciliary account holders may now initiate direct telegraphic transfers of up to USD10,000 per day without triggering exhaustive trade documentation.

Export Proceeds and Inbound Remittances

The 2026 Manual provides that all exporters shall ensure that export proceeds are repatriated and credited to their export domiciliary account in the bank where the NXP was established, within 180 days from the Bill of Lading date for oil and gas exports and 90 days for non-oil exports. Failure to adhere to this timeline imposes a penalty of 1% of the amount involved.

Furthermore, the Manual provides that inbound foreign currency transfers shall be paid to beneficiaries in Naira or such other currency as may be determined by the CBN from time to time.

It further provides that cash withdrawals relating to inbound transfers shall not exceed the Naira equivalent of USD200, while amounts above this threshold must be paid through a bank account.

Revised Travel Allowance Framework

CBN previously prohibited cash payments of Personal Travel Allowance (PTA) and Business Travel Allowance (BTA) under its 2024 cashless directive. However, Under the 2026 Manual, 25% of the PTA and BTA may now be disbursed in physical foreign currency cash while the remaining 75% must be disbursed through electronic channels such as debit or credit cards. This policy shift aims to balance the digital payment objectives of the apex bank with the practical cash liquidity demands faced by international travelers.

Domestic Transactions and Naira Denomination Requirements

The 2026 Manual reaffirms the requirement that transactions involving goods and services exchanged between Nigerian entities must generally be denominated and settled in Naira.

However, exemptions continue to apply to certain sectors and transactions, including specified activities within the oil and gas, maritime, aviation and free trade zone sectors.

Regulatory Compliance and Enforcement

The New Manual introduces a high-stakes environment for Authorized Dealer Banks (ADBs) and corporate entities:

  1. Financial Sanctions: Banks processing transactions without adequate documentation face a 100 million flat fine, plus 10 million per affected transaction.
  2. Export Penalties: A 1% penalty applies to exporters failing to repatriate proceeds within the mandatory 90 days (non-oil) or 180 days (oil/gas) windows.
  3. Strict Documentation: The CBN has codified the use of the Electronic Certificate of Capital Importation (eCCI). Capital must be registered within 24–48 hours of inflow; failure to do so may permanently compromise the legal standing of the investment.
  4. Domestic Denominations: All domestic transactions must be priced and settled in Naira. Exemptions are strictly limited to specific sectors, including Oil & Gas, Maritime, Aviation, and businesses within Free Trade Zones.

Conclusion

The 2026 Foreign Exchange Manual represents an important development in Nigeria’s foreign exchange regulatory framework.

On one hand, the Manual provides businesses and individuals with greater flexibility through higher import payment thresholds, increased tuition remittance limits, simplified domiciliary account operations, and reduced export transaction costs. On the other hand, it introduces a more stringent compliance environment characterised by enhanced documentation requirements, stronger reporting obligations, and substantial penalties for non-compliance.

Accordingly, all stakeholders involved should undertake a comprehensive review of their foreign exchange policies, documentation procedures, transaction monitoring systems, and internal controls to ensure alignment with the new framework. Given the scale of the sanctions introduced by the Manual, compliance failures may no longer be viewed as routine administrative lapses but as material regulatory risks with potentially significant financial and operational consequences.

As implementation of the Manual progresses, we expect that further regulatory guidance will be put in place to provide additional clarity on the application of the 2026 Manual provisions.

Key Changes at a Glance

Area 2018 Manual 2026 Manual
Advance Import Payments 15% of FOB Value 30% of FOB Value
PTA/BTA Disbursement More restrictive cash framework 75% Electronic / 25% Cash
Tuition Fee Remittances Lower limits Up to USD 25,000 per Semester
Domiciliary Account Remittances Form A Required Form A Removed
Form NXP Processing Processing Fees Applicable Free of Charge
Documentation Violations Lower sanctions ₦100m + ₦10m per affected transaction
Export Proceeds Repatriation Existing obligations 1% penalty for non-compliance
Inbound Money Transfers Less detailed framework Enhanced payment and withdrawal restrictions

 

DECODING THE NCC’S DRAFT BUSINESS RULES FOR MOBILE VIRTUAL NETWORK OPERATORS IN NIGERIA

BY SEUN TIMI-KOLEOLU AND HILLARY OKOROTIE

Introduction

The Nigerian Communications Commission (“NCC”) recently published the Draft Business Rules for Mobile Virtual Network Operators in Nigeria (the “Draft Rules”), aimed at establishing a comprehensive regulatory framework for the operation of Mobile Virtual Network Operators (“MVNOs”) in Nigeria. The Draft Rules aim to promote transparency in the relationships between MVNOs, Host Network Operators (“HNOs”), and service delivery. The Draft Rules outline key operational obligations, compliance requirements and standards intended to guide the conduct of MVNOs within the Nigerian telecommunications sector.

In this newsletter, we share insights into the impact of the Draft Rules on the operations of MVNOs.

Onboarding and Integration of MVNOs

The Draft Rules establish a structured onboarding and integration framework aimed at minimizing delays in the negotiation, onboarding, and integration processes between MVNOs and HNOs. Under the Draft Rules, every HNO is required to maintain an approved Reference Onboarding Information Pack containing key information and requirements relevant to prospective MVNO partnerships. Upon receiving a request from a licensed MVNO, the HNO is required to acknowledge receipt within ten days and, within twenty days of receiving the required documentation from the MVNO, confirm its readiness to proceed together with an indicative implementation timeline. Where an HNO declines a hosting request, it is required to provide the MVNO and the NCC with a rationale for the refusal within the same twenty days period.

Furthermore, upon confirmation of readiness to proceed, the parties are required to commence negotiations and establish a joint onboarding working group within ten days to oversee implementation. The Draft Rules also prohibit HNOs from unjustifiably and indefinitely delaying the onboarding process. The Rules further provide that commercial and technical agreements relating to onboarding and integration must be concluded within one hundred and twenty days from the date of the formal hosting request.

Commercial Agreements between MVNOs and HNOs

Under the Draft Rules, parties are required to submit any executed commercial agreement relating to MVNO services to the NCC within fourteen days of execution, or within such timeline as may be prescribed by the NCC. In addition, the Draft Rules also impose ongoing obligation to notify the NCC in respect of amendments to existing agreements. Specifically, where parties make changes relating to pricing, onboarding models, numbering arrangements, interconnection architecture, SIM ownership, eSIM enablement, customer migration or termination rights, the NCC must be notified within thirty days of executing such amendments and prior to the implementation of the changes.

The Draft Rules further require that commercial agreements clearly identify the party responsible for key operational obligations, including Know Your Customer (“KYC”) verification, activation approvals, subscriber complaint management, and other compliance responsibilities relating to eSIM services.

Furthermore, existing commercial agreements between MVNOs and HNOs are required to be reviewed in line with the provisions of the Draft Rules within thirty days from the commencement date of the Draft Rules. This transitional period is intended to ensure that existing MVNO operations and contractual arrangements are aligned with the regulatory requirements introduced by the NCC.

The Dispute Resolution Framework Under the Draft Rules

The Draft Rules also introduce a structured dispute resolution mechanism aimed at preventing prolonged commercial and technical disagreements between MVNOs and HNOs. Under the Draft Rules, every commercial agreement must contain a clearly defined escalation ladder, for example technical disputes affecting onboarding of users or service continuity must first be escalated between designated technical leads within five days, while unresolved commercial disputes are to be escalated to executive representatives within ten days.

Where parties are unable to resolve the dispute, either party may refer the matter to the NCC. Importantly, the Rules prohibit retaliatory measures pending the duration of any dispute such as disruption of the service.

Consumer Protection and Quality of Service Obligations

The Draft Rules prohibit HNOs from unfairly limiting or restricting MVNO network traffic, this is aimed at ensuring fair treatment and quality service delivery for MVNO subscribers operating on host networks.

In addition, MVNOs are required to maintain transparent tariff structures, accessible customer complaint channels and effective dispute resolution mechanisms. The Draft Rules also place primary responsibility for subscriber relationships and customer care obligations on MVNOs, notwithstanding their reliance on HNO infrastructure. In delivering their services, MVNOs are further required to comply with the consumer protection standards and regulatory requirements prescribed by the NCC.

Conclusion

The Draft Rules seek to address some of the challenges that affect MVNO operations, particularly onboarding delays, infrastructure access, commercial uncertainty, disputes over operational responsibilities and other operational aspects of MVNOs. When finalized, these Rules will represent a significant step towards establishing a more structured and transparent framework for MVNO operations in Nigeria.

An aspect of the Draft Rules that can be improved upon is with respect to the regulation of quality of service and traffic management. We recommend that the NCC includes detailed guidelines to monitor the quality of service provided by HNOs and traffic management practices with a view to promoting fair treatment of all MVNOs.

For further details on MVNO licensing framework and the various tiers of MVNO licences, please refer to our previous newsletter.

REGULATORY UPDATE: NDPC EXTENDS DATA AUDIT FILING DEADLINE

By Seun Timi-Koleolu and Omodele Fatodu

The Nigeria Data Protection Commission (“NDPC”) has announced an extension of the deadline for the filing of the 2025 Data Protection Compliance Audit Returns (“CAR”) from March 31 to May 30, 2026. Data Processors and Controllers of Major Importance (“DPCMIs”) are therefore encouraged to utilise this period to ensure that their data protection frameworks are aligned with regulatory expectations and to file their Compliance Audit Returns within the extended timeline.

DPCMIs should note that failure to file within the prescribed timeline will attract regulatory sanctions. In particular, late filing of the CAR is subject to a penalty of 50% of the applicable filing fee, in addition to the risk of further regulatory scrutiny or enforcement action by the NDPC.

  1.  Practical Steps During the Extension Period

To make effective use of the extended timeline, DPCMIs should consider the following:

  1. Data Mapping: Ensure that all personal data processing activities are clearly identified and documented, including the nature of data collected, purposes of processing, storage locations, and third-party disclosures.
  2. Policy Review: Review privacy policies and internal data protection procedures to confirm that they are up to date and aligned with regulatory requirements and actual data processing practices.
  3. Remediation of Prior Findings: Ensure that any identified gaps or recommendations from prior audits have been appropriately addressed and implemented.
  4. Engage a licensed Data Protection Compliance Organisation (DPCO): A licensed DPCO can conduct the data protection compliance audit and file the CAR on behalf of the organisation, helping to ensure that the audit meets NDPC expectations.
  1. Update on Filing Fees

DPCMIs are also reminded that the filing fees applicable to the CARs were revised under the General Application and        Implementation Directive, 2025 (“GAID”). The fees depend on the DPCMI category, as well as the number of data subjects processed by the organisation, as outlined below:

  1. Ultra-High Level DPCMI
    Tier A – 50,000 data subjects and above: N1,000,000
    Tier B – 25,000 – 49,999 data subjects: N750,000
    Tier C – below 25,000 data subjects: N500,000
  2. Extra-High Level DPCMI
    Tier A – 10,000 data subjects and above: N250,000
    Tier B – 2,500 – 9,999 data subjects: N200,000
    Tier C – below 2,500 data subjects: N100,000
  1. Further Guidance

For a more detailed overview of compliance obligations under Nigerian data protection laws, and the role of DPCOs, please refer to our previous publications:

Conclusion

The extension of the 2025 data audit filing deadline provides organisations with an extended opportunity to review their data protection practices and file their Compliance Audit Returns on time.

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a DPCO. We provide support to organisations across diverse industries in conducting data protection compliance audits, preparing and filing Compliance Audit Returns, and ensuring alignment with the GAID and Nigeria Data Protection Act, 2023.

New CBN Measures on Diaspora Remittances: What They Mean for Market Participants

BY ADERONKE ALEX-ADEDIPE AND PROMISE ITAH

Introduction

On March 24, 2026, the Central Bank of Nigeria (CBN) issued a circular on Measures to Further Deepen Diaspora Remittances and Compliance (the “Circular”). The Circular, which is effective from May 1, 2026, builds on the CBN’s revised guidelines for international money transfer services in Nigeria, and is aimed at enhancing  diaspora remittances, strengthening transparency, traceability, and effective monitoring of all remittance related transactions.

In this newsletter, we highlight the measures introduced by the CBN and assess their practical implications for participants.

What Are the New Measures?

The following measures have been prescribed by the CBN.

  1. Designated Naira Settlement Accounts: All transactions related to International Money Transfer Operators’ (IMTO) operations, including payments to beneficiaries and any settlements, must be processed through designated settlement accounts held with authorised dealer banks (ADBs or Banks). IMTOs may either open new accounts or use existing ones for this purpose and can maintain multiple naira settlement accounts based on their business needs. However, they are required to regularly provide the CBN with an updated list of these designated accounts through the Director of the Trade and Exchange Department.
  2. Account Funding Restrictions: The circular makes it clear that these settlement accounts can only receive money from remittances or foreign exchange transactions carried out by the IMTOs or their agents through authorized participants in the Nigerian Foreign Exchange Market (NFEM). This means that no other funds are allowed to be deposited into these accounts.
  3. Authorised Transfers to Other Market Participants and BDCs: To improve the flow of foreign exchange and support fair pricing, ADBs are permitted to process foreign currency transfers from IMTO settlement accounts to other ADBs and approved market participants, including licensed Bureau de Change (BDC) operators.
  4. Real-Time FX Pricing: IMTOs must set their remittance rates to reflect current market prices from Bloomberg’s BMatch platform rather than being set independently. By doing this, the CBN aims to ensure more accurate pricing, reduce information gaps between banks and IMTOs, and encourage greater use of the official FX market.
  5. Compliance and Record Keeping: In addition to complying with the above measures, all IMTOs (and ADBs) must strictly comply with anti‐money laundering and counter-terrorism financing rules. Detailed records of all remittance transactions (origins, amounts, beneficiaries, conversions, etc.) must also be kept for regulatory review and audit purposes.

 

What Are the Practical Implications?

The new measures may require certain operational changes. We have set out below, some key implications and action points for IMTOs, banks, BDCs and other stakeholders:

  1. IMTOs (Money Transfer Operators):

    In view of the above regulatory measures, IMTOs may require system upgrades and staff training and must also strengthen record-keeping and AML/KYC processes, maintaining detailed transaction logs for regulatory review.

  2. ADBs (Commercial Banks):

    ADBs should prepare for increased demand from IMTOs to open and manage multiple naira settlement accounts and streamline onboarding processes accordingly. Banks will also need to closely monitor these accounts to ensure they are used solely for remittance flows and comply with FX funding requirements, while supporting IMTOs in meeting AML/CFT obligations.

  3. BDCs:

    Since ADBs are permitted to process foreign currency transfers from IMTO settlement accounts, BDCs may engage ADBs and their IMTO partners to access this FX liquidity.

  4. General Market Effects:

    In general, the measures are expected to improve transparency by channeling remittance flows through the formal banking system, giving the CBN greater visibility into FX inflows. In the medium term, it is expected that this will reduce reliance on informal markets, support better rate alignment, and contribute to improved liquidity and stability in the FX market.

Conclusion

The CBN’s new measures on diaspora remittances are part of a series of significant steps toward formalising diaspora remittance flows and improving transparency in Nigeria’s foreign exchange market. By mandating designated settlement accounts, real-time pricing, and stricter compliance standards, the framework is expected to enhance liquidity, strengthen regulatory oversight, and reduce reliance on informal channels. While stakeholders will need to adjust their operations to meet the new requirements, the CBN expects that the reforms should, over time, support better price discovery and contribute to greater stability of the naira.

THE CENTRAL BANK OF NIGERIA REGULATORY UPDATE: REVISED CASH POLICIES AND AUTHORISED PUSH PAYMENT FRAUD GUIDELINES

BY SEUN TIMI-KOLEOLU AND OMODELE FATODU

Introduction

The Central Bank of Nigeria (“CBN”) has recently issued two regulatory communications: (i) the Revised Cash-Related Policies, effective 1 January 2026; and (ii) the Draft Guidelines for Handling Authorised Push Payment (“APP”) Fraud. Both documents introduce new operational requirements for financial institutions and provide guidance for customers, lenders, and payment service providers.

1. REVISED CASH-RELATED POLICIES – Key Changes

  1. Removal of Cash Deposit Limits The CBN has abolished previously applicable cash-deposit limits. Under the former regime, customers were subject to cumulative deposit limits and charges for excess cash deposits. These thresholds and associated fees have now been completely removed.
  2. Upward Adjustment of Withdrawal Limits – Individuals may now withdraw up to ₦500,000 weekly, while corporate entities may withdraw up to ₦5 million. Withdrawals exceeding these limits will attract processing fees of 3% for individuals and 5% for corporate entities.
  3. Elimination of Special Withdrawal Authorisations The requirement for customers to seek special CBN approval for unusually large cash withdrawals (previously ₦5 million for individuals and ₦10 million for corporate entities) has been discontinued.
  4. Enhanced Obligations for Financial Institutions Banks are required to ensure that ATMs remain adequately funded and stocked with various denominations. They must maintain a designated account for processing fees charged on withdrawals above the stipulated limits. Banks are also required to submit specified periodic reports, including returns on cash withdrawals above the specified limit and returns on cash deposits to the CBN to support ongoing compliance and supervision.

2. CBN DRAFT GUIDELINES ON APP FRAUD

What is APP Fraud?

APP fraud occurs when a customer is tricked into voluntarily initiating a payment to an account controlled by a fraudster. Although the customer authorises the transfer, it is done under false pretences through deception, manipulation, impersonation, or other fraudulent means.

Key Highlights

  1. Standardised Reporting Framework for Fraud Incidents Customers are required to report suspected or actual APP fraud to their financial institution within 24 hours, with allowance for reporting within 72 hours where reasonable justification is provided. The guidelines state that “reasonable justification” may include, but is not limited to, circumstances beyond the control of the customer such as illness, force majeure events, time of becoming aware of the fraud, security constraints, or demonstrable unavailability of reporting channels. Upon receiving a report, the institution must acknowledge receipt within 24 hours, open a case file, and begin processing the complaint in line with the guidelines.
  2. Mandatory Inter-Bank Notification within 30 Minutes Where an APP transaction involves more than one financial institution, the institution that first receives the complaint must notify the other insitiution within 30 minutes of receiving the customer’s complaint.
  3. Defined Timelines for Customer Refunds Where a customer is entitled to a refund, the responsible institution must complete it within 48 hours after concluding the investigation. In cases involving multiple institutions, refunds must be completed within 16 working days of the complaint.
  4. Strengthened Fraud-Prevention and Consumer-Protection Duties Financial institutions must provide 24/7 fraud-reporting channels and implement an early warning system to prevent and detect APP fraud in a timely manner. They are required to ensure that customers are aware of available reporting channels and receive clear, accessible, and ongoing education on APP fraud risks and reporting procedures. Financial institutions must also carry out quarterly APP fraud awareness campaigns across multiple media and languages, and ensure that any information shared with other institutions complies with the Nigerian Data Protection Act 2023.
  5. Customer Refund Eligibility – Refund eligibility is subject to the following conditions:
    • The customer authorised the transaction under false pretence and had no reason to suspect fraud;
    • The customer reported the fraud within 72 hours and cooperated with the investigation;
    • There is no evidence of negligence, collusion, or criminal intent by the customer; and
    • The financial institution failed to implement appropriate fraud detection, warning, or verification protocols that could have prevented the transaction.

    Financial institutions are not obligated to reimburse where:

    • The customer acted fraudulently or negligently;
    • The customer delayed reporting beyond 72 hours without reasonable justification; and
    • The transaction occurred before the effective date of the guideline, unless the institution voluntarily applies it retroactively.

Conclusion

CBN’s Revised Cash-Related Policies and Draft Guidelines on APP Fraud introduce updated operational requirements that affect both financial institutions and customers. Banks and payment service providers should review these documents to ensure compliance ahead of the effective dates, while customers should familiarise themselves with the reporting procedures and eligibility criteria to protect their interests in cases of APP fraud.

TAX BREAKS & MORE: WHAT THE NIGERIAN STARTUP ACT OFFERS

BY ADERONKE ALEX-ADEDIPE AND OMODELE FATODU

Introduction

The Nigerian Startup Act 2022 (NSA) is a significant piece of legislation, designed to foster innovation, attract investment, and create a favourable business climate for tech-enabled startups in Nigeria. It aims to position Nigeria as a leading hub for digital entrepreneurship in Africa by removing regulatory barriers and offering targeted incentives.

This newsletter explores key incentives available under the NSA and what they mean for startups and investors.

The Startup Label: A Gateway to Incentives

The NSA introduces the Startup Label, issued by the National Information Technology Development Agency (NITDA) which is a prerequisite for enjoying the incentives available under the NSA. To qualify, a startup must:

  • Be registered as a limited liability company with the CAC, and in operation for less than 10 years.
  • Have its objects focused on innovation, development, production, or improvement of a digital product, service or process
  • Have at least 33% of its shares held by a Nigerian founder or co-founder
  • Be certified by NITDA via the Startup Portal

Only Labelled startups may benefit from the incentives discussed below.

  1. TAX AND FISCAL INCENTIVES

One of the most attractive features of the NSA is its suite of tax incentives designed to encourage startup formation and sustainability:

  1. Pioneer Status Incentive (PSI) – The NSA allows for a Labelled startup to apply for PSI which grants an initial three-year tax holiday, extendable for an additional two years. This exemption from Companies Income Tax is a critical incentive for early-stage businesses as it allows them to reinvest significantly in their growth.
  2. Exemption from Capital Gains Tax – To encourage long-term investment, the NSA provides that angel investors, venture capitalists, private equity firms, and other institutional investors who invest in Labelled startups and hold their equity for a minimum of two years are exempted from paying Capital Gains Tax on the disposal of such investments.
  3. Tax deductions for Investments in Research & Development (R&D) – To encourage investment and innovation in R&D, Labelled startups may claim tax deductions for expenses on R&D which are wholly incurred in Nigeria and restrictions placed by the Companies Income Tax Act shall not apply.
  4. Access to the Startup Investment Seed Fund – The NSA establishes the Startup Investment Seed Fund, to be managed by the Nigeria Sovereign Investment Authority (NSIA). The fund is intended to provide early-stage finance to Labelled Startups, support for technology development, and grants for research and innovation.
  1. REGULATORY SUPPORT AND EASE OF DOING BUSINESS

The NSA introduces measures to reduce regulatory friction:

  1. Regulatory Sandboxes – The NSA empowers regulatory authorities (such as the Naional Insurance Commission (NAICOM), CBN or SEC)  to introduce sandbox programs that allow Labelled Startups to test innovative products or services in a controlled environment without the full burden of regulatory compliance.
  2. Fast-Tracked Approvals and Support – Labelled startups may request expedited approvals, waivers, or forbearances from regulators where traditional compliance requirements are unduly burdensome or incompatible with digital innovation. The NSA requires regulators to consider such requests and respond promptly through designated innovation desks.
  3. Single Window Platform – the NSA mandates the creation of a single platform to streamline startup registration, compliance, and access to government programs which help reduce bureaucratic delays.
  1. CAPACITY DEVELOPMENT AND TALENT SUPPORT

The NSA mandates collaboration between the Federal Government, academic institutions, and the private sector to promote digital training programs, tech-focused curriculum, and upskilling in areas like AI, cybersecurity, and blockchain. Labelled startups may benefit from access to trained talent pools at lower cost.

  1. INTELLECTUAL PROPERTY AND COMMERCIALISATION SUPPORT

The NSA encourages simplified processes for IP registration. Labelled Startups are eligible for reduced fees and technical support in registering trademarks, patents, and copyrights with the National Office for Technology Acquisition and Promotion and the Trademarks, Patents and Designs Registry.

Conclusion

The NSA is a forward-thinking legislative framework that provides critical incentives to drive innovation and entrepreneurship. However, these incentives are contingent on obtaining the Startup Label and remaining compliant with the NSA’s requirements. As the implementation of the NSA continues, stakeholders are encouraged to engage actively with the Startup Portal, monitor new guidelines from NITDA and NSIA, and seek legal advice to ensure eligibility and access to full benefits.

WHAT IS NEW IN NIGERIA’S MERGERS AND ACQUISITION LANDSCAPE? A REVIEW OF REGULATORY SHIFT.

BY ADERONKE ALEX-ADEDIPE AND HILLARY OKOROTIE

The regulatory framework governing mergers and acquisitions in Nigeria has experienced a notable shift with the enactment of the Investments and Securities Act 2025 (the “Act”). While the Federal Competition and Consumer Protection Commission (FCCPC) continues to be the primary regulator overseeing all mergers and acquisitions in Nigeria, the Act was recently amended to streamline the role of the Securities and Exchange Commission (the “Commission”) in overseeing mergers and acquisitions related to public companies and the conduct of stakeholders in such transactions.

This newsletter highlights some of the provisions in the Act as they relate to public companies and what they mean for stakeholders.

  • Approval of Mergers by the Commission

The Act provides specifically that all public companies intending to undertake a scheme, transaction, arrangement, or activity or issue securities or offer for subscription or purchase of securities must first seek the approval of the Commission before undergoing such arrangement. Where a public company proposes a compromise, arrangement, or scheme involving the issuance of securities for the amalgamation of two or more listed companies, the public company is required to make an application to the Commission for its approval and obtain an approval in principle. Upon obtaining the approval in principle, the public company is required  to make an application to the Federal High Court(“Court”) for a meeting of the shareholders for their agreement on the merger.

In considering an application for approval of a merger, the Commission will assess whether shareholders are treated equitably and fairly. Once the merger is approved, the parties must apply to the Court for the merger to be sanctioned. Upon the Court’s sanction, the merger becomes binding on all parties involved.

  • Acquiring Voting Rights

The Act provides that no single person shall acquire more than 30% or more of the voting rights of a public company. It further stipulates that no person acting alone or in concert with other individuals may acquire more than 30% or more of the voting rights or such other threshold as may be prescribed by the Commission.

Where a person intends to acquire more than 30% of a company’s voting rights, the Act stipulates that such person must first make an offer to acquire all or part of the voting rights of the company to the shareholders.  This is referred to as a take-over bid and is subject to the approval of the Commission. During such take-over bid, the Commission shall ensure that (i) the identity of the acquirer is disclosed to the shareholders;(ii) the shareholders have reasonable time to consider the offer;(iii) the shareholders are supplied with necessary information to assess the take-over offer made.

In the acquisition of the rights in the company, both the company and the offeror must ensure that the shareholders, particularly minority shareholders are treated fairly in such a transaction.

Where the take-over bid fails, the offeror cannot proceed with the acquisition of the voting rights. In the event that the Commission approves the take-over bid, the offeror may proceed with the take-over bid and acquire the additional voting rights.

  • Payment for Director’s Loss of Office During a Merger or Takeover

The Act provides that payment to a director for loss of office due to the transfer of shares in a company or its subsidiary in the course of a merger or takeover cannot be made unless such payment is made with the approval of the shareholders of the company- specifically shareholders whose shares are being targeted or purchased during the merger or takeover.

In addition, the Act provides that a resolution approving the payment must be disclosed in a memorandum and made available for inspection by the shareholders at least 15 days before the meeting of the members of the company.

  • Penalties for Non-Compliance

Where an acquirer fails to comply with the provisions of the Act on Mergers and Acquisitions, or the directives of the Commission, the acquirer shall be liable to a penalty of ₦10,000 and an additional ₦25,000 for each day the violation continues. Any other party involved in the transaction who fails to comply with the provisions of the Act shall also be liable to a penalty of not less than ₦10,000 and a further sum of ₦25,000 for every day the violation persists. Furthermore, any person who provides the Commission with false or misleading information in relation to a merger or takeover transaction shall, upon conviction, be liable to a fine of ₦5,000,000 or imprisonment for a term of not less than five years, or both.

Conclusion

As public companies proceed with mergers and acquisitions, they must generally ensure that their transactions strictly comply with the Act. The Act ensures that mergers involving public companies are transparent, equitable, and are investor friendly. For companies, it means stricter obligations around disclosure and fairness. For investors, it offers greater protection and recourse in takeover transactions.

Compliance in Nigeria: Data Protection Directives for Businesses

BY SEUN TIMI-KOLEOLU AND EBIKENIYE BEST

Introduction

As businesses in Nigeria increasingly leverage technology including social media platforms such as LinkedIn, Instagram, and Medium; and Emerging Technologies including Artificial Intelligence to expand their customer reach both locally and internationally, such businesses must adhere to Data Protection provisions in Nigeria.

In view of the foregoing, it is important to note recent updates to the protection of Personal Data in Nigeria. The most recent update is the Nigeria Data Protection Act – General Application and Implementation Directive (the “GAID”) issued on March 20, 2025, by the Nigeria Data Protection Commission (the “Commission”).

In this newsletter, we have set out useful information on the GAID to guide businesses.

1.     What is the effect of the GAID on the Nigeria Data Protection Regulation (NDPR), 2019?

With the adoption of the GAID, the NDPR shall no longer regulate data in Nigeria. Data Protection in Nigeria is now regulated by the existing Nigeria Data Protection Act and the GAID.

Please note, however, n that any act done under the NDPR prior to the issuance of the GAID remains valid.

2.    What are the obligations under the GAID for data controllers and processors?

Under the GAID, data controllers and processors of major importance are required to adhere to certain obligations including:

a.    engaging a licensed Data Protection Compliance Organisation (DPCO) to carry out an audit of their business within 15 (fifteen) months of commencing business and subsequently annually before March 31 of each year;

b.    filing a compliance audit report not later than March 31 of each year through a DPCO;

c.     appointing associate/assistant Data Protection Officers (DPOs) and privacy champions to support the DPO where the data controller or processor interfaces with data subjects on multiple platforms;

d.    storing personal data for not more than 6 (six) months after the purpose of processing the data has been achieved. Please note that this would only apply where no existing law has specified a retention period.

3.   In what circumstances is explicit consent required under the GAID?

The GAID acknowledges that consent as a lawful basis for processing personal data could be constructive or implied. It, however, states that explicit consent is required for certain activities like – direct marketing, processing children’s data and sensitive personal data, automated decision making and cross-border data transfer.

4.    Are there provisions for Emerging Technologies?

Yes, the GAID now provides explicit provisions on Emerging Technologies such as Artificial Intelligence, Blockchain, and the Internet of Things. It requires that any data controller or processor deploying or planning to deploy Emerging Technologies for personal data processing must adhere to the provisions of the NDPA, public policies, the GAID, and any other regulations issued by the Commission.

In addition, a data controller or processor must do the following:

a.    develop and implement technical and organizational frameworks for the design of Emerging Technologies tools, ensuring that these frameworks are properly documented and submitted to the Commission; and

b.    conduct a Data Privacy Impact Assessment, considering factors such as how data processing might unfairly affect different groups and the level of risk faced by vulnerable individuals, to access and reduce privacy risks effectively.

5.    Are there provisions on Data Ethics under the GAID?

Yes. In auditing data controllers and processors, DPCOs are required to confirm if data controllers and processors apply global best practices on Data Ethics when handling personal data. The DPCO must ensure that data controllers and processors possess: (i) organizational policy on ownership of data; (ii) demonstrable transparency and accountability; (iii) fairness of intention; and (iv) respect for data subjects’ rights to control the use of their personal data.

6.    What are the requirements for Cross-Border Data Transfer?

Under the GAID, a data controller or processor must obtain approval from the Commission before transferring personal data outside Nigeria. The Commission will grant approval based on an adequacy decision, which considers whether the receiving country has enforceable data subject rights; a robust data protection law; and a competent supervisory authority with sufficient enforcement powers.

In the absence of an adequacy decision, the data controller or processor will be required to prepare and submit a Cross-Border Data Transfer Instrument (the “Instrument”) for approval by the Commission. This Instrument may be in the form of (i) code of conduct; (ii) certification, (iii) binding corporate rules; or (iv) standard contractual clauses.

7.    Are data subject’s rights provided for under the GAID?

The GAID reinforces data subjects’ rights, including the right to access, right to rectification, right to data portability, right to be forgotten, right to lodge a complaint, and right to objection. Businesses are required to create transparent and easy to use processes to respond to these rights promptly.

8.    What is the procedure for lodging complaints under the GAID?

The GAID now allows data subjects who believe that their right to privacy has been violated to seek redress directly from data controllers by sending a document titled “Standard Notice to Address Grievance” to the relevant data controller or processor. A format of this document has been provided in the GAID. This action is to be taken without prior notification to the Commission.

9.    When will the GAID come into effect?

The Commission noted that for ease of doing business, the GAID shall take effect 6 (six) months from the date of publication, that is, September 2025.

Conclusion

To ensure compliance with Nigeria’s evolving data protection landscape, organizations should carefully review the key updates introduced by the GAID. To align with applicable data protection laws, organisations should engage the services of licensed DPCOs.

 

For more information on data protection compliance, please see our previous newsletter.