Posts

FOREX TRADING IN NIGERIA: THE IMPLICATIONS OF SEC PROPOSED RULES ON ONLINE FOREX TRADING FOR TECHNOLOGY AND PLATFORM PROVIDERS

BY SEUN TIMI-KOLEOLU & PROMISE ITAH

Introduction

The Securities and Exchange Commission (“SEC”) has proposed rules on Online Forex Trading and Contracts for Difference (“CFDs”) (the “Proposed Rules”), introducing a regulatory framework for businesses involved in the provision of online Forex and CFD trading services in Nigeria.

The Proposed Rules will affect not only Forex brokers and CFD providers, but also the companies that provide the technology they use. This includes companies that provide the websites and apps where users open trading accounts; check currency and asset prices; place trades; and manage their investments. It may also include companies that host these platforms or provide the technology and systems that allow them to operate.

In this newsletter, we highlight key provisions of the Proposed Rules relevant to businesses that provide technology or platforms for online Forex and CFD trading.

What are Online Forex Trading and CFDS?

Under the Proposed Rules, Forex/FX/Foreign Exchange means the exchange of one national currency for another. Online forex trading involves trading foreign currencies through an online platform.

A Contract for Difference (CFD) is a derivative that allows a person to trade based on changes in the price of an underlying asset without owning the asset.

Key Highlights of the Proposed Rules

  1. Technology and Platform Providers Within the Regulatory Framework

Under the Proposed Rules, technology and platform providers are recognised as a distinct category of regulated persons. This category appears broad enough to cover businesses that provide trading infrastructure, software, platforms, systems or other technology used in connection with online Forex and CFD trading.

The Proposed Rules also apply to offshore businesses that target or provide services to Nigerian residents. This may arise where a platform permits Nigerian residents to open accounts, advertises its services to Nigerians, uses Nigerian currency or references, engages Nigerian influencers or affiliates, or otherwise demonstrates an intention to serve the Nigerian market.

Accordingly, a technology provider may need to assess its activities carefully where its platform is used by a Forex broker or CFD operator serving Nigerian residents. The fact that the provider does not deal directly with clients or execute trades may not, by itself, take it outside the scope of the Proposed Rules.

  1. Registration and Capital Requirements

A person may not carry on, or hold itself out as carrying on, the business of a technology or platform provider within the scope of the Proposed Rules without registration with the SEC.

For technology and platform providers, the Proposed Rules contemplate a minimum paid-up capital of ₦5 billion. The provider must also be incorporated in Nigeria or be a foreign company with an appropriate local presence in Nigeria.

The proposed registration fees comprise:

  • Application fee – ₦100,000;
  • Processing fee – ₦300,000; and
  • Registration fee for a Category C technology or platform provider – ₦30 million.

In addition, a registered provider would be required to maintain professional indemnity insurance of not less than 20% of the applicable minimum capital per claim, or provide an equivalent security acceptable to the SEC.

  1. Operational and Technology Standards

The Proposed Rules place significant emphasis on the reliability, security and resilience of trading platforms. Technology providers would be expected to maintain systems that support the continuous and orderly operation of trading activities. The key requirements include:

  • Platform availability: Platforms must maintain a minimum uptime of 99.5% during trading hours.
  • Cybersecurity: Providers must have appropriate security measures in place, including end-to-end encryption of client and trade data, multi-factor authentication, regular penetration testing, and systems for monitoring and responding to security threats.
  • Business continuity and disaster recovery: Providers must maintain business continuity and disaster recovery arrangements, test these arrangements annually and submit the relevant certification to the SEC.
  • Record-keeping: Providers must retain audit trails of transactions and other relevant activities for at least seven years. Records must be readily retrievable within 24 hours and may include client information, orders, transactions, confirmations, electronic communications, financial records, AML records and risk disclosures.

These requirements may have implications for the design and operation of trading platforms and should be considered in the contractual arrangements between technology providers and the brokers or other regulated entities using their systems.

  1. Data Protection and Data Localisation

The Proposed Rules also set requirements for the storage and protection of client and trading data. Client order data must be stored in Nigeria or another jurisdiction approved by the SEC, in line with applicable data protection requirements. Technology providers may therefore need to review their data hosting arrangements, third-party access and cross-border data transfers.

  1. White-Label Platforms and Outsourced Technology

The Proposed Rules are also relevant to businesses that provide white-label platforms or outsourced technology solutions. Where a provider supplies the infrastructure used by a broker or trading operator, the parties will need to consider how responsibility for regulatory compliance is allocated. This should include responsibility for:

  • platform availability and performance;
  • cybersecurity and access controls;
  • data storage and processing;
  • incident reporting;
  • recordkeeping and audit trails;
  • business continuity and disaster recovery;
  • regulatory inspections and information requests;
  • use of subcontractors and external technology providers; and
  • suspension, termination or migration of the platform.

The Proposed Rules require prior SEC approval for certain material changes, including changes to a trading platform or technology provider. This means that brokers and other regulated entities may need to obtain SEC approval before changing their technology providers or making significant changes to their trading platform.

Technology agreements should therefore be reviewed to ensure that they contain appropriate provisions dealing with regulatory cooperation, audit rights, service levels, incident escalation, data access, business continuity and orderly transition.

  1. Incident Reporting and Regulatory Cooperation

A technology provider would be required to notify the SEC within 24 hours of a material system breach, outage or cybersecurity incident.

This requirement creates a need for clear internal escalation procedures and contractual reporting arrangements. A broker may not become aware of a system incident immediately, while a technology provider may not have sufficient information to determine whether an incident is material from a regulatory perspective.

Technology providers and their regulated clients should therefore agree in advance on:

  • What constitutes a reportable incident;
  • How quickly incidents must be escalated;
  • Who is responsible for notifying the SEC;
  • The information to be included in an incident report;
  • How affected clients will be notified; and
  • The steps required to contain, investigate and remedy the incident.

The Proposed Rules also contemplate independent systems audits and penetration testing reports for proprietary and white-labelled platforms. Providers should expect increased scrutiny of their technology architecture, security controls, access management, development processes and third-party dependencies.

  1. What Technology Providers Should Consider

Businesses providing technology or platform services to online Forex and CFD operators should begin reviewing their current operations against the proposed framework. In particular, they should:

  • assess their regulatory classification and determine whether their services fall within the proposed definition of a technology or platform provider;
  • review their Nigerian market exposure, including whether their platforms are accessible to Nigerian residents or marketed through Nigerian brokers, affiliates, influencers or other intermediaries;
  • evaluate their capital and local presence requirements, particularly where they operate through a foreign company or provide services on a white-label basis;
  • review their technology infrastructure, including uptime, encryption, authentication, monitoring, penetration testing and incident response arrangements;
  • assess their data arrangements, including data hosting locations, backups, cross-border transfers, subcontractors and compliance with applicable data protection laws;
  • update their contractual arrangements with brokers and other regulated entities to address service levels, audit rights, incident reporting, regulatory access, business continuity and liability;
  • prepare for enhanced recordkeeping and audit requirements, including the retention and retrieval of client, transaction and system records for at least seven years.

Conclusion

The SEC’s Proposed Rules signal closer regulation of online Forex and CFD trading in Nigeria, including the technology infrastructure supporting such activities. While the provisions highlighted in this newsletter are not exhaustive, the proposed requirements may have significant implications for both local and foreign businesses operating in this space.

Businesses should therefore review their regulatory position and relevant operations ahead of the final rules. As the proposals remain subject to change, businesses should continue to monitor developments and assess any implications based on the nature of their services and Nigerian market exposure.

NIGERIA’S PROPOSED RULES ON DIGITAL AND VIRTUAL ASSETS: KEY PROVISIONS AND IMPLICATION FOR BUSINESSES

BY SEUN TIMI-KOLEOLU & HILLARY OKOROTIE

Introduction 

On August 20, 2026, the Securities and Exchange Commission (“SEC”) published the Proposed Rules on Digital and Virtual Assets Operations, Custody and Markets (the “Proposed Rules”). The Proposed Rules seek to establish a comprehensive regulatory framework for digital and virtual asset activities in Nigeria, including the issuance, offering, trading, custody, transfer and settlement of digital and virtual assets. 

The Proposed Rules set out: the categories of activities to which they apply; the prescribed requirements for conducting business in relation to digital and virtual assets; and regulatory requirements relating to the issuance and trading of digital assets. 

In this newsletter, we provide an overview of the key provisions of the Proposed Rules and their potential implication for businesses operating within Nigeria’s digital and virtual asset ecosystem. 

Key Provisions and Implication of the Proposed Rules 

Where the proposed rules are implemented the following are key provisions that players in the digital and  virtual assets space should take note of when operating in the Nigerian market. 

1. Application of the Proposed Rules 

The Proposed Rules will apply to persons and businesses operating in Nigeria, as well as persons providing services to Nigerian residents or the Nigerian market through digital channels in relation with the issuance, trading, custody and management of digital and virtual assets. 

The Proposed Rules will also apply to persons and entities facilitating any aspect of digital and virtual asset services, including Virtual Asset Service Providers (“VASPs”) and Digital Asset Custodians(“DAO”). 

2. Obligations of Regulated Entities 

Regulated entities are required to comply with various obligations in the conduct of their business and in the issuance, offering, and trading of digital assets in Nigeria. These obligations include, amongst others, the following: 

  1. Advertisement and Promotion: In connection with the issuance and offering of digital assets in Nigeria, entities must ensure that no publication, advertisement, or promotional material is made in respect of a digital asset unless the asset has been duly registered with SEC. Where an entity advertises or promotes a registered digital asset, such advertisement or promotional content must be accurate, fair, and not misleading.
  2. Changes to the Structure of the Entity: Where there are material changes to the structure or operations of a regulated entity, including changes to its ownership, governance structure, technology architecture, or business model, the entity must obtain SEC’s prior approval before implementing such changes. In addition, any cybersecurity incident, data loss, or loss of assets must be reported to SEC within twenty-four hours of such occurrence.
  3. Dispute and Conflict of Interest Management: Entities engaged in the trading of digital assets must maintain a comprehensive framework for receiving, handling, and resolving customer complaints. They are also required to establish and maintain appropriate procedures for identifying, managing, and mitigating conflicts of interest arising in connection with their digital asset trading activities.
  4. System Access and Transaction Monitoring: SEC may require regulated entities to provide API-based access to their financial, operational, and transaction data for regulatory monitoring and supervisory purposes. The Proposed Rules further require entities to implement systems capable of monitoring and reporting transactions involving Nigerian residents. In respect of cross-border transactions, entities must implement systems that maintain designated transaction wallets for domestic and cross-border asset flows. Such systems must also ensure that all inflows into and outflows from Nigeria are traceable to identifiable users.

3. Disclosure Requirements for the Issuance of Digital Assets 

The Proposed Rules require the disclosure of all material information relating to a digital asset prior to its issuance. An issuing entity is required to prepare a white paper containing the issuers information, characteristics, offer structure of the digital asset, and other material information to enable prospective investors make informed investment decisions. The whitepaper must be filed with SEC, and the issuing entity must obtain a no-objection or approval from SEC before offering the digital asset to the public. 

The issuing entity and its officers will be responsible for any misrepresentation or omission of material information contained in the whitepaper. Where there is a material change to the information relating to the digital asset following SEC’s no-objection or approval, the issuing entity will be required to file a supplementary or amended whitepaper with SEC and suspend further issuance of the digital asset pending compliance with the applicable requirements. 

4. Issuance of the Digital Assets 

The Proposed Rules provide that, for an asset to be eligible for issuance, the rights and obligations attached to the asset must be clear, the structure of the asset must be transparent, and the risks must be adequately disclosed. 

Digital assets shall be categorized either as Asset-Referenced Tokens, Asset-Backed Tokens, or other digital assets, including cryptocurrencies and utility tokens. Assets that are anonymous, exhibit a fraudulent token structure, or constitute an unbacked stablecoin will be prohibited from issuance. The asset must also be offered through a Digital Asset Offering Platform approved by SEC. 

5. Registration Under the Proposed Rules 

An entity intending to register under the Proposed Rules must apply to first participate in SEC’s Accelerated Regulatory Incubation Programme (“ARIP”). Following an application under the ARIP, SEC may grant the applicant an Approval-in-Principle to commence operations subject to the conditions prescribed by SEC. The Approval-in-Principle will be valid for a period of two years, after which SEC may require the entity to apply for full registration. 

SEC may, in certain circumstances, permit an applicant to bypass the ARIP process. This may apply where the applicant is a registered capital market operator, a registered (“VASP”), or a subsidiary of a licensed financial institution. 

To qualify for registration under the Proposed Rules, an entity must, amongst  other requirements, be incorporated in Nigeria in accordance with the Companies and Allied Matters Act, 2020. Its Chief Executive Officer and other principal officers must be resident in Nigeria, and the entity must maintain a registered office address in Nigeria. The applicant must also satisfy other registration and regulatory requirements prescribed by SEC. 

Conclusion 

SEC’s objective under the Proposed Rules is to establish a comprehensive regulatory framework for the digital assets market in Nigeria. Notably, the framework extends beyond the regulation of intermediaries engaged in the trading of digital assets to also encompass digital asset issuers and other relevant participants in the digital asset’s ecosystem. 

If implemented, the Proposed Rules will have significant implications for foreign entities seeking to issue digital assets in the Nigerian market. Such entities may be required to comply with requirements relating to the incorporation of a domestic entity where the parent company is incorporated outside Nigeria, as well as requirements concerning the residency of principal officers in Nigeria.

TAXATION OF VIRTUAL ASSETS IN NIGERIA

SEUN TIMI-KOLEOLU & PROMISE ITAH

Introduction

On July 31, 2026, the Nigeria Revenue Service (NRS) issued the Guidelines on the Taxation of Virtual Assets (the “Guidelines”), providing the first comprehensive administrative framework for the taxation of virtual asset transactions in Nigeria.

While the Guidelines do not introduce new taxes, they clarify how existing tax laws apply to virtual assets and establish new compliance obligations for taxpayers, Virtual Asset Service Providers (VASPs) and certain peer-to-peer (P2P) marketplace operators.

This newsletter highlights the key provisions of the Guidelines and their implications for businesses operating within Nigeria’s digital asset ecosystem.

  1. Who and What Are Covered by the Guidelines?

The Guidelines apply to persons and entities who acquire, dispose of, exchange or otherwise deal in virtual assets; receive income or payments in virtual assets; operate as VASPs or P2P marketplace operators; derive taxable income, profits or gains from virtual assets; or provide virtual asset-related services. They cover a broad range of activities, including cryptocurrencies, stablecoins, non-fungible tokens (NFTs), tokenised assets, DeFi transactions, staking, mining, airdrops and token swaps.

  1. What transactions are taxable?

A tax liability generally arises where a virtual asset is disposed of or income is earned from a virtual asset activity. Common taxable transactions include:

  • selling a virtual asset;
  • exchanging one virtual asset for another;
  • receiving staking or mining rewards;
  • earning rewards from DeFi activities;
  • selling NFTs;
  • receiving virtual assets as payment for goods or services; and
  • other transactions that result in taxable income or gains.

Depending on the nature of the transaction, the applicable taxes may include income tax, withholding tax, value added tax (VAT) and stamp duty.

  1. What transactions are not taxable?

The Guidelines clarify that not every transaction involving a virtual asset gives rise to a tax liability. Generally, the following are not treated as taxable events:

  • holding a virtual asset without disposing of it;
  • transferring virtual assets between wallets owned by the same person;
  • locking up virtual assets for staking;
  • creating or minting NFTs;
  • tokenising real-world asset without a change in beneficial ownership; and
  • using virtual assets as collateral for a loan.

The Guidelines also clarify that the transfer of a virtual asset is generally not subject to VAT. Instead, VAT applies to taxable services provided by VASPs, such as exchange, brokerage and transaction facilitation services. In addition, the Guidelines do not apply to the eNaira or other Central Bank Digital Currencies (CBDCs).

  1. How Are Taxable Gains Computed?

The Guidelines introduce a new method for calculating gains from the disposal of virtual assets. Under this method, the purchase price and sale price are first converted into United States Dollars (USD) using the applicable exchange rates on the dates the asset was acquired and sold. The gain is then calculated in USD before being converted back into naira for tax purposes.

This approach is designed to ensure that taxpayers are taxed on their actual investment gains rather than gains arising solely from changes in the exchange rate.

  1. How Will Virtual Asset Taxes Be Collected?

The Guidelines establish a structured framework for collecting taxes on virtual asset transactions, with responsibility shared between taxpayers and intermediaries such as VASPs and P2P marketplace operators. While taxpayers remain responsible for filing their annual tax returns and paying any outstanding tax, these intermediaries are required to deduct and remit certain taxes on behalf of users where applicable. The Guidelines also clarify that income earned from virtual asset activities, such as staking rewards, mining rewards, DeFi yields and virtual assets received as payment for goods or services, is generally taxable when received.

  1. What Does Token-Native Tax Remittance Mean?

The Guidelines introduce a token-native tax remittance framework. Under this framework, withholding tax on qualifying virtual asset disposals and stamp duty are deducted and remitted in the same virtual asset used in the transaction, rather than first being converted into naira.

To support this framework, the NRS intends to establish a Token Treasury, which will initially accept only supported virtual assets from participating registered VASPs. Where a transaction involves an unsupported virtual asset, the Guidelines provide that it will be converted into a supported token without affecting the taxpayer’s withholding tax credit.

  1. How Should Virtual Assets Be Valued?

The Guidelines establish valuation rules to ensure that virtual assets are valued consistently for tax purposes. Where a virtual asset is not directly priced in USD, taxpayers must use approved valuation sources to determine its fair market value and retain records to support their tax calculations. The Guidelines also prescribe how the cost of a virtual asset should be determined depending on how it was acquired, whether through a purchase, token swap, staking or mining rewards, a hard fork (where a blockchain splits and creates new tokens), or an airdrop (where free tokens are distributed by a project).

Where a taxpayer holds multiple units of the same virtual asset acquired at different times or prices, the Guidelines require a consistent method for determining the cost of the units disposed of. The default method is First-In, First-Out (FIFO), which assumes that the earliest acquired units are sold first, or the Weighted Average Cost method, which uses the average cost of all units held to calculate gains or losses. Once a method is adopted, it must be applied consistently.

Taxpayers may offset virtual asset gains and losses within the same tax year, but losses can only be applied against virtual asset gains and cannot be used to reduce other income.

  1. What Are the Key Compliance Requirements and Penalties?

The Guidelines impose extensive compliance obligations on taxpayers, VASPs and certain P2P marketplace operators. Among other things, taxpayers engaging in virtual asset activities must register for tax purposes and obtain a Tax Identification Number (TIN), while VASPs are required to verify users’ TINs, maintain prescribed records, file statutory returns and comply with the reporting requirements under the Nigeria Tax Administration Act (NTAA).

Failure to comply with these obligations may result in significant penalties including administrative penalties imposed by the NRS.

Key Takeaways for Businesses

The Guidelines provide greater certainty on the taxation of virtual assets but also introduce significant compliance obligations. Businesses should therefore:

  • review how their virtual asset transactions are treated under the Guidelines;
  • ensure their accounting and tax systems can support the new valuation and reporting requirements;
  • maintain comprehensive transaction, valuation and exchange-rate records;
  • review arrangements with VASPs and other intermediaries to understand how tax compliance obligations will be managed; and
  • monitor further guidance from the NRS as the new framework is implemented.

Conclusion

The Guidelines mark a significant step in the development of Nigeria’s virtual asset tax framework by providing much-needed clarity on the taxation of digital asset transactions and the compliance obligations of taxpayers and intermediaries. While this newsletter highlights some of the key provisions of the Guidelines, it is not intended to be an exhaustive analysis of the framework.

Businesses involved in virtual asset activities should review their systems, governance and compliance processes to ensure they are prepared to meet the new reporting, withholding and record-keeping requirements and seek appropriate advice where necessary.

NIGERIA’S FOREIGN EXCHANGE MARKET: RECENT REGULATORY REQUIREMENTS FOR BDC OPERATORS AND BANKS

BY ADERONKE ALEX-ADEDIPE & HILLARY OKOROTIE

Introduction

On February 10, 2026, the Central Bank of Nigeria (CBN) issued a circular on the Participation of Licensed Bureau De Change Operators in the Nigerian Foreign Exchange Market, permitting licensed Bureau De Change (BDC) operators to participate in the Nigerian Foreign Exchange Market (NFEM).

Following the commencement of BDC operators’ participation in the NFEM, the CBN, on July 15, 2026, issued the Guidance on the Purchase of Foreign Exchange by Bureau De Change Operators Through Authorized Dealer Banks in the Nigerian Foreign Exchange Market (the “Guidance Notice”). The Guidance Notice establishes the procedures governing the purchase of foreign exchange by BDC operators through authorized dealer banks and outlines the obligations of dealer banks in facilitating such transactions.

In this newsletter, we provide insights on the obligations of BDC operators and authorized dealer banks.

What Are the Obligations of Dealer Banks and BDC Operators Under the Guidance Notice?

Under the Guidance Notice, dealer banks and BDC operators are required to undertake the following:

  1. Due Diligence Processes
    Under the Guidance Notice, dealer banks are required to conduct Know Your Customer (KYC) and Customer Due Diligence (CDD) checks  before engaging in any foreign exchange transaction with a BDC operator. As part of this process, dealer banks must obtain and verify the BDC operator’s incorporation documents, valid operating license, as well as beneficial ownership information. Where a BDC operator is identified as presenting a higher risk following the due diligence assessment, the dealer bank is required to apply Enhanced Due Diligence (EDD) measures before proceeding with the transaction. 
  2. Fulfilment of Foreign Exchange Purchase Requests
    Requests by BDC operators to purchase foreign exchange must be submitted through the CBN’s Foreign Exchange Purchase Tracker Portal (the “Portal”) to the preferred authorized dealer BDC operators are required to register on the Portal and provide real-time updates of all foreign exchange purchase transactions. . Upon receipt of the BDC’s purchase request, the dealer bank may either approve or reject the request through the Portal. Where a request is rejected, the dealer bank must state the reason for the rejection on the Portal.The Guidance Notice also permits BDC operators to submit multiple foreign exchange purchase requests within a week, provided that the value of the purchases does not exceed the prescribed weekly purchase limit of US$150,000.

     

  3. Disbursement of Funds to BDC Operators
    In processing and fulfilling a foreign exchange purchase request, dealer banks are required to disburse foreign exchange only into foreign exchange settlement accounts maintained by the BDC operators with licensed financial institutions. Dealer banks must ensure that all disbursements are made solely to the BDC operator’s designated settlement account and not to the account of any third party. Any disbursement of foreign exchange to a third-party account constitutes a breach of the Guidance Notice and may attract sanctions against the dealer bank by the CBN. 
  4. Retention of Purchased Foreign Exchange
    BDC operators are required to sell all foreign exchange purchased through the NFEM within 24 hours. Any outstanding balance must be sold within 24 hours. Failure to comply may result in regulatory sanctions, including the forfeiture of the outstanding balance to the CBN or the suspension of the BDC operator’s license. In addition, BDC operators are required to disclose any outstanding balance in their foreign exchange purchase request for the following week. 

What Are the Penalties for Non-Compliance?

The CBN has prescribed sanctions for breach of its circular on the Participation of Licensed Bureau De Change Operators in the Nigerian Foreign Exchange Market and the Guidance Notice. BDC operators that fail to comply with these directives may be subject to monetary penalties, suspension or revocation of their operating license, or suspension of their access to the NFEM.

Similarly, dealer banks that fail to comply with the CBN’s directives when transacting with BDC operators may have their status as authorized dealer banks revoked. Where a breach involves suspected criminal conduct, the CBN may also refer the matter for criminal investigation and prosecution to the appropriate authorities

Conclusion

The CBN’s objective in permitting BDC operators to purchase foreign exchange through authorized dealer banks in the Nigerian Foreign Exchange Market (NFEM) is to improve liquidity within the formal foreign exchange market. The framework is also intended to curb abuses and arbitrage in the foreign exchange market. If properly implemented therefore, it is expected that these policies will sustain the current stability in the market.

For more information on the participation of BDC operators in NFEM, please see our previous newsletter.

 

NIGERIA’S FINANCIAL MARKETS REFORM – THE VIRTUAL ASSETS COORDINATION EXECUTIVE ORDER 2026 AND SEC’S PROPOSED CROSS-BORDER TRADING RULES

BY SEUN TIMI-KOLEOLU & ENIOLA SOGBESAN

Introduction

Nigeria continues to take significant steps towards modernizing its financial markets by creating a more transparent, innovative and globally competitive investment ecosystem. Two recent developments reflect this direction: the Presidential Executive Order on Virtual Assets Coordination 2026 (the “Executive Order”) and the Securities and Exchange Commission’s (SEC) Proposed Rules on Cross-Border Securities Trading and Custody (the “Proposed Rules”). Although they address different segments of the financial market, both initiatives are aimed at strengthening Nigeria’s regulatory framework, inter-agency coordination, and supporting responsible innovation.

In this newsletter, we examine the key highlights of these developments and their implications for investors, capital market operators, fintech companies and other stakeholders. We also consider how these reforms fit into Nigeria’s broader efforts to align its financial/capital markets with international best practices while encouraging growth, protecting investors and enhancing regulatory coordination.

  1. The Presidential Executive Order on Virtual Assets Coordination 2026
    President Bola Ahmed Tinubu on July 17, 2026 signed the Presidential Executive Order on Virtual Assets Coordination, 2026 (the “Executive Order”). The Order which takes effect immediately, is a response to a largely fragmented regulatory landscape that has exposed Nigerians to unchecked losses from unregulated operators. The Executive Order aims to protect investors while promoting responsible innovation and preserving financial system integrity.Key Highlights of the Executive OrderIt is important to note that the Executive Order does not establish a new regulator but rather establishes a mechanism for coordination amongst existing regulators such as SEC, Central Bank of Nigeria (CBN), Nigeria Revenue Service (NRS), Nigerian Financial Intelligence Unit (NFIU) and Office of the National Security Adviser (ONSA). The key highlights of the Executive Order include-
  • the establishment of a Virtual Asset Council (the “Council”) chaired by the CBN Governor, with the Director-General of the SEC and the Chairman of the Nigeria Revenue Service serving as Vice-Chairs;
  • the establishment of a Virtual Asset Office (VAO) to serve as the operational arm and secretariat of the Council;
  • a functional allocation of regulatory responsibilities among regulators –
      1. SEC – regulation of virtual assets that constitute securities and investment products;
      2. CBN – supervision of payment, settlement, custody and other non-security virtual asset activities within its statutory mandate;
      3. NRS – issue a specialized tax policy for the taxation of virtual assets;
      4. NFIU – oversight for AML/CFT compliance
      5. ONSA – coordination of national security and intelligence.
  • the establishment of a dedicated CBN regulatory sandbox for virtual asset and blockchain-based innovation.Implications and Opportunities for Virtual Asset Service ProvidersThe Executive Order signals a more coordinated regulatory framework for virtual assets, with clearer allocation of responsibilities among regulators and stricter oversight of anti-money laundering and counter-terrorism financing (AML/CFT) standards. Virtual Asset Service Providers (VASPs) should also monitor opportunities to participate in the CBN’s proposed regulatory sandbox, as well as anticipated tax guidance from the Nigeria Revenue Service (NRS). Collectively, these developments are expected to provide greater regulatory certainty for compliant operators while potentially increasing enforcement against operators that do not meet the applicable regulatory requirements.

    As of the date of this newsletter, we note that the official text of the Executive Order has not been publicly released, and we expect it to be released shortly. Once published, a detailed review of its provisions will be necessary to assess its implications for VASP’s and other participants in Nigeria’s digital asset ecosystem.

B. Proposed Rules On Cross-Border Securities Trading and Custody
The Securities and Exchange Commission (SEC) on July 2, 2026 published a draft of its “Proposed Rules on Cross-Border Securities Trading and Custody” (the “Proposed Rules”). The Proposed Rules represent a significant step by the SEC towards establishing a comprehensive regulatory framework for Nigerian investors’ wishing to invest in foreign securities. The Proposed Rules seek to regulate the provision of cross-border securities trading services by SEC-registered brokers, while strengthening investor protection, enhancing regulatory oversight, and promoting the integrity of cross-border investment activities.

  1. Scope/Applicability
    The Proposed Rules are applicable to every broker licensed by the SEC that provides Nigerian investors access to foreign securities listed or traded on a foreign securities exchange. More specifically, the Proposed Rules applies to the following services –
    1. trading in foreign securities on behalf of Nigerian investors;
    2. execution of cross-border securities transactions through foreign intermediaries;
    3. custody and safekeeping of foreign securities belonging to Nigerian investors;
    4. maintenance of records of beneficial ownership of foreign securities; and
    5. the protection of investor rights and assets within indirect holding structures.
  1. Licensing Requirements
    Under the Proposed Rules, a broker is prohibited from providing cross-border securities trading services without first obtaining a prior “No Objection” from the SEC.To obtain a No Objection from the SEC, a broker must submit an application which include but not limited to the following documents –
    1. detailed description of the proposed cross-border trading services;
    2. identification of foreign exchanges to which access shall be provided;
    3. details of foreign brokers and custodians to be engaged;
    4. description of custody and settlement arrangements; and
    5. policies governing safeguarding of client assets.

The Proposed Rules clearly prohibit a broker from facilitating foreign securities trading, unless it maintains a minimum net liquid capital of not less than ₦2 billion.

  1. Approval Requirements for Foreign Brokers?
    Prior to engaging in foreign securities transaction through a foreign broker, a Nigerian broker shall ensure that the foreign broker satisfies the following conditions –
    1. the foreign broker must be licensed and supervised by a securities regulator;
    2. it must operate within jurisdictions that are members of the International Organization of Securities Commissions (IOSCO) and whose regulator is a signatory to the IOSCO Multilateral Memorandum of Understanding or any other cooperation arrangement with the SEC;
    3. it must maintain adequate financial resources, operational capacity, custody safeguards, and client asset protection mechanisms;
    4. where applicable, it is a participant in recognized clearing and settlement systems; and
    5. the foreign broker is not subject to any material regulatory sanction, restrictions, suspension, or enforcement action that may impair its operations or expose investors to undue risk.
  1. Regulatory Assessment and Recognition of Foreign Brokers
    Under the Proposed Rules, a broker shall not enter any arrangement or any other business relationship with a foreign broker for the purpose of providing cross-border securities trading without the prior approval or a “No Objection” of the SEC.An application for approval to engage a foreign broker shall be accompanied by the following:
    1. the proposed agreement between the foreign and Nigerian broker;
    2. details of the services to be provided by the foreign broker;
    3. details of custody, clearing, settlement, and operational arrangements;
    4. evidence of the foreign broker’s licensing and regulatory authorization status;
    5. a status report, letter of good standing, or fit and proper confirmation issued by the foreign broker’s regulator and
    6. such other information as the SEC may require.
  1. Investor Protection
    The Proposed Rules require every foreign security purchased on behalf of a Nigerian investor to be held by a regulated foreign custodian or clearing participant. Also, all securities purchased by an investor must be segregated from the assets of the broker or custodian.Under the Proposed Rules, every broker is required to ensure that –
    1. proper books and records are maintained to clearly distinguish the assets of each investor from the assets of the broker;
    2. no investor asset is utilized for the benefit of the broker or any other investor without the prior written authorization of the affected investor client and the approval of the SEC, where applicable; and
    3. adequate systems and controls are established to ensure the continuous protection, reconciliation, and traceability of client assets.
  1. What are the reporting obligations of Brokers under the Proposed Rules?The Proposed Rules require a broker to submit quarterly reports to the SEC. The details of the report shall include the following –

      1. aggregate value of foreign securities held by Nigerian investors;
      2. custody locations of such securities; and
      3. reconciliation statements.
  2. Fees and Sanctions.The SEC shall be entitled to a fee 0.35% on the purchase of every foreign security by a Nigerian investor and this fee may be reviewed by the SEC from time to time. Upon collecting the fee, the Broker shall submit monthly transaction returns and fee remittance reports to the SEC in the form and manner prescribed by the SEC including reconciliations of transactions executed through foreign intermediaries.Where a broker fails to comply with the Proposed Rules, such broker shall be subject to sanctions such as suspension, monetary penalties, revocation of registration and any other sanction that the SEC may impose.

    Conclusion

    The Virtual Assets Coordination Executive Order 2026 and SEC’s Proposed Rules on Cross-Border Trading of Foreign Securities and Custody, represent important milestones in Nigeria’s efforts to strengthen the regulatory architecture of its financial markets. While the Proposed Rules is still in its draft form, it seeks to provide a structured framework for access to foreign securities, and the Executive Order enhances regulatory coordination for virtual assets. Together, these developments reflect a broader policy objective of positioning Nigeria’s financial markets to support innovation while aligning with international regulatory standards.

CBN’S DATA LOCALISATION DIRECTIVE – COMPLIANCE CONSIDERATIONS FOR PAYMENT SYSTEM PARTICIPANTS

BY ADERONKE ALEX-ADEDIPE & PROMISE ITAH

Introduction

On June 15, 2026, the Central Bank of Nigeria (“CBN“) issued a Circular on Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System (the “Circular“). Among other regulatory reforms, the Circular introduces a significant data localisation requirement directing all financial institutions and participants facilitating payments within Nigeria—including banks, payment service providers, mobile money operators and other payment participants— (collectively “Payment System Participants”) to ensure that data generated in relation to payment transactions in Nigeria is stored and managed in Nigeria by January 1, 2027.

In this newsletter, we examine the scope of the CBN’s data localisation requirements, their interaction with existing data protection obligations, and some of the key legal, contractual and operational considerations which Payment System Participants should consider in preparation for compliance.

  1. Who does the Circular Apply to?
    The Circular applies to payment transaction data generated through Nigeria’s payments system. Although the Circular does not define the term “payment transaction data”, it intuitively includes information generated in connection with a payment transaction, including the payer’s and beneficiary’s payment details, transaction amounts, payment references, authentication records, settlement and routing information, transaction logs and other related technical data required to process, verify or record a payment.

    The Circular also appears to frame the localisation requirement by reference to payment transaction data generated within Nigeria, rather than the location in which the business is principally domiciled. On this basis, therefore any Payment System Participant processing payment transaction data generated within Nigeria may be expected to comply with this requirement, regardless of their country of domicile.

  1. What are the Key Compliance Requirements?

    a. Local Processing and Storage
    Payment System Participants must ensure that payment transaction data is both stored and managed within Nigeria. This extends beyond maintaining a local copy of data and requires that the primary processing environment, databases, backups and operational control remain on infrastructure located within Nigeria.

    The requirement for payment transaction data to be “managed” in Nigeria may also have implications for administrative activities such as access management, database administration, encryption key management and audit logging, particularly where these functions are performed through offshore infrastructure or personnel.

    b. Technology and Infrastructure
    The Circular is likely to require many Payment System Participants to review their technology infrastructure, particularly where payment services rely on foreign cloud service providers or systems hosted outside Nigeria. Given the requirement for payment transaction data generated within Nigeria to be stored and managed locally, organisations should assess whether their existing technology architecture involves the storage, processing or replication of payment transaction data outside Nigeria. Areas that may require review include:

    • cloud hosting arrangements and the location of servers;
    • disaster recovery and backup systems;
    • analytics and monitoring platforms that process payment data;
    • testing and development environments that use live or production payment data; and
    • third-party APIs and other technology integrations that may transfer payment data outside Nigeria.

Payment System Participants operating hybrid or multiple cloud environments should assess whether payment data is stored, replicated or processed outside Nigeria and, where necessary, implement appropriate technical or operational changes before the compliance deadline.

c. Vendor and Outsourcing Arrangements

Whilst it is commonplace for Payments System Participants to assign data processing and storage activities to third parties, the Circular does not appear to transfer the obligations from Payment System Participants to service providers in such instance. Accordingly, organisations should review their contractual arrangements with cloud service providers, payment processors, application programming interface (API) providers and other technology vendors to assess whether those arrangements support compliance with the localisation requirement. In particular, organisations should consider whether their contracts adequately address:

    • the requirements for payment data to be stored and managed within Nigeria;
    • restrictions on processing payment data outside Nigeria;
    • rights to conduct audits and facilitate regulatory inspections;
    • controls over the use of subcontractors that may have access to payment data;
    • obligations to promptly notify the Payment System Participant of any data breaches or incidents; and
    • termination rights where a vendor is unable to comply with the localisation requirements.
  1. How does the Circular Interact with the Nigeria Data Protection Act (NDPA)?

The Circular complements rather than replaces the NDPA. While the NDPA regulates the processing and international transfer of personal data through recognised transfer mechanisms and safeguards, the CBN Circular imposes an additional regulatory obligation applicable specifically to payment transaction data. Accordingly, compliance with the NDPA alone will not satisfy the CBN’s localisation requirements.

  1. Practical Compliance Steps

Pending any further guidance from the CBN, Payment System Participants should consider taking the following steps to prepare for implementation:

    1. conducting a comprehensive data mapping exercise to identify where payment data is stored, processed and transmitted;
    2. assessing existing cloud and infrastructure arrangements for localisation risks;
    3. reviewing third-party vendor relationships and contractual provisions;
    4. updating internal data governance, outsourcing and information security policies;
    5. establishing board and management oversight of the implementation programme; and
    6. maintaining adequate documentation to demonstrate compliance during regulatory inspections.

Conclusion

The CBN’s payment data localisation requirements represent a significant development in the regulation of Nigeria’s payments ecosystem. By requiring payment transaction data generated within Nigeria to be stored and managed in Nigeria, the Circular appears intended to strengthen regulatory oversight, enhance operational resilience and support the security of Nigeria’s payments infrastructure. For Payment System Participants, the immediate priority will be to assess whether existing technology infrastructure, data governance frameworks and third-party vendor arrangements are consistent with the new localisation requirement. Given the breadth of the obligation and the absence of detailed implementation guidance, organisations that begin assessing their compliance position ahead of the January 2027 implementation date will be better positioned to address any legal, operational or contractual gaps as further guidance emerges.

NIGERIA CAPITAL MARKET REGULATORY UPDATE: SEC MANDATES REGISTRATION OF COLLATERAL MANAGEMENT COMPANIES, WAREHOUSE OPERATORS AND WAREHOUSES

BY ADERONKE ALEX-ADEDIPE & OMODELE FATODU

On 11 May 2026, the Securities and Exchange Commission (the “Commission”) issued a circular clarifying the registration requirements applicable to certain capital market operators.

The Circular applies to entities involved in the storage, management and facilitation of commodities used in structured trade financing or warehouse receipt arrangements. In particular:

  • Collateral Management Companies (“CMCs”);
  • Warehouse Operators; and
  • Warehouses linked to commodity exchanges or electronic warehouse receipt systems.

Although these categories of operators were already recognised and regulated under the SEC Rules on Commodity Exchanges and Trading Platforms; Warehouse Receipt Systems; and Collateral Management and Warehousing Operations, the Circular appears intended to reinforce compliance with the existing registration regime and clarify that entities operating under informal, transitional or unregistered arrangements are not exempt from regulatory requirements.

The Commission notes that entities currently carrying on any of the relevant activities under such informal or transitional arrangements are also required to apply for registration. Accordingly, the Commission has directed all existing and prospective entities within the scope of the Circular to submit complete registration applications within 90 days from the date of the Circular (the “Registration Deadline”).

The SEC further clarified that compliance will only be recognised upon submission of a complete application within the Registration Deadline. Consequently, incomplete applications, or failure to respond to requests for additional information within the stipulated timelines, will not satisfy the registration requirement.

In view of this Circular, we have set out below a brief overview of the registration and minimum capital requirements applicable to CMCs and Warehouse Operators:

S/N Capital Market Operator Registration Documents Minimum Capital
1. Collateral Management Companies
  • Duly completed SEC Forms 2, 2D and 3
  • Minimum of three sponsored individuals, including a Managing Director and Compliance Officer;
  • Certificate of Incorporation, Memorandum and Articles of Association, and CAC Status Report;
  • Company profile, organisational structure and details of principal officers;
  • Evidence of payment for shares allotted to shareholders;
  • Evidence of financial and technical capacity to carry out collateral management functions;
  • Latest audited accounts or statement of affairs; and
  • Valid fidelity insurance bond covering at least 20% of the minimum paid-up capital.
Tier 1 (Local/Regional Operators) – ₦200,000,000

Tier 2 (National/International Reach) – ₦500,000,000

 

2. Warehouse Operators
  • Duly completed SEC Forms 2, 2D and 3;
  • Minimum of three sponsored individuals, including a Managing Director and Compliance Officer;
  • Certificate of Incorporation, Memorandum and Articles of Association, and CAC Status Report;
  • Evidence of adequate storage facilities and appropriate security arrangements;
  • Evidence of requisite weighing and quality control equipment;
  • Evidence of comprehensive insurance coverage for facilities, equipment and commodities;
  • Evidence of suitable operational infrastructure, including loading and unloading systems;
  • Standard Operating Procedures (SOPs) for warehousing operations;
  • Latest audited accounts or statement of affairs; and
  • Valid fidelity insurance bond covering at least 20% of the applicable minimum capital requirement.
₦500,000,000

 

Conclusion

The Circular reflects the Commission’s intention to strengthen regulatory oversight, transparency and accountability within the commodities trading and warehouse receipt ecosystem. By requiring all relevant operators to formally register, the Commission is likely seeking to ensure that only entities with adequate operational capacity, governance structures and financial standing participate in the market and remain subject to direct regulatory supervision.

Accordingly, entities operating within this sector should assess whether their activities fall within the scope of the Circular and take immediate steps to commence or regularise their registration with the Commission where applicable.

BANKING AND FINANCE REGULATION IN NIGERIA – INTEREST RATE DETERMINATION, NOFR BENCHMARK

BY SEUN TIMI-KOLEOLU AND PROMISE ITAH

Introduction

On April 17, 2026, the Central Bank of Nigeria (CBN) announced the introduction of the Nigerian Overnight Financing Rate (NOFR) in collaboration with the Financial Markets Dealers Association (FMDA). The NOFR is a daily benchmark designed to reflect the actual cost of short-term borrowing between banks, based on real market transactions. According to the CBN, the introduction of the NOFR is aimed at enhancing transparency, strengthening monetary policy transmission, and deepening Nigeria’s money market.

In this newsletter, we highlight the rationale and framework of the NOFR, as well as its implications for the market.

What is the Rationale behind the NOFR?

Nigeria’s short-term interest rates have traditionally been guided by the Monetary Policy Rate (MPR) and interbank indicators such as the Open Buy Back (OBB) and Overnight (OVN) rates, which are meant to reflect the cost of overnight borrowing between banks.

However, these indicators do not always reflect actual transactions, as they may be influenced by estimates, limited trading activity, or inconsistent reporting. As a result, they may not accurately capture the true cost of short-term funding.

The Nigerian Overnight Financing Rate (NOFR) was introduced to address this gap by replacing indicative pricing with a benchmark based on actual transactions, thereby improving reliability and market confidence.

What is the Framework of the NOFR?

The NOFR is an average interest rate that reflects the actual cost of overnight lending between banks in naira, where the loans are secured by collateral, and based on real market transactions. The rate is calculated by giving more weight to larger transactions and removing unusually high or low rates (the higher 10% and the lower 10% percent volumes are excluded from the calculation), so that the final figure reflects normal market conditions and provides a more accurate picture of how banks actually price short-term funding.

The transactions used to calculate the NOFR must meet the following conditions:

  1. they must be carried out on the specific day the rate is being calculated (the fixing day);
  2. they must be reported by approved banks;
  3. Each transaction must be at least ₦5 billion, so that only significant market activity is included.

The rate is published daily at 10:00 a.m. for the preceding business day. Where there is insufficient qualifying transaction data, the previous day’s rate is retained and published to ensure continuity and stability. The CBN is responsible for the governance and regular publication of the NOFR. The rate can be accessed on the CBN website.

 

What are the Key Market Implications?

Some key market implications of the introduction of the NOFR are set out below:

  1. Corporate Borrowers: While the NOFR may not immediately reduce borrowing costs, it provides a clear and transparent base rate for floating-rate loans. This makes loan pricing more consistent and easier to compare. Borrowers may seek to review existing loan agreements, especially floating-rate clauses, as pricing will gradually shift to NOFR-based benchmarks, making interest costs more responsive to overall market conditions.
  2. Banks and Financial Institutions: In view of the improved accuracy in pricing short-term loans, banks will have a clearer view of funding costs, enabling more effective day-to-day liquidity management.
  3. Investors: The greater transparency and reliability of the NOFR may make it easier to price and value instruments such as treasury bills and bonds. This is expected to improve pricing consistency across the market and give both local and foreign investors greater confidence in expected returns.
  4. Legal/Contractual Considerations: The introduction of the NOFR means that existing financial agreements referencing older interbank rates or bank-specific pricing may need to be reviewed and updated to reflect the new benchmark. Going forward, new agreements are likely to adopt NOFR as the base rate, with an added margin. This makes it important to include clear provisions on benchmark use and replacement in new agreements.

Conclusion

The introduction of the NOFR marks a significant shift in how interest rates are determined in Nigeria and aligns the country with global benchmarks best practices such as the Secured Overnight Financing Rate (SOFR) in the United States and the Sterling Overnight Index Average (SONIA) in the United Kingdom. While the CBN expects the NOFR to enhance transparency, strengthen monetary policy transmission, and deepen Nigeria’s money market, its impact will ultimately depend on adoption and effective administration.

REDEFINING AML COMPLIANCE: UNDERSTANDING CBN’S BASELINE STANDARDS FOR AUTOMATED AML SOLUTIONS FOR FINANCIAL INSTITUTIONS

BY ADERONKE ALEX-ADEDIPE AND HILLARY OKOROTIE

Introduction

With the increasing need to ensure financial security in today’s rapidly digitizing landscape and evolving compliance demands, the Central Bank of Nigeria (CBN) issued its Baseline Standards for Automated Anti-Money Laundering (AML) Solutions for Financial Institutions (“AML Solutions”) on March 10, 2026. This was followed by a Guidance Note on implementation, released on March 31, 2026.

In this newsletter, we provide an overview of the requirements of the AML Solutions for financial institutions.

What is the Purpose of the AML Solutions?

The AML Solutions is aimed at establishing a structured and automated system for the identification and reporting of suspicious transactions and strengthening adherence to AML, Combating the Financing of Terrorism (CFT), and Countering Proliferation Financing (CPF) regulatory requirements. It also applies to all financial institutions operating in Nigeria.

What are Some of the Obligations of Financial Institutions?

  1. Customer Due Diligence (CDD), Know Your Customer (KYC) and Know Your Business (KYB): Financial institutions are required to implement effective CDD, KYC and KYB frameworks supported by automated or semi-automated onboarding, instant identity verification, and integration with national identity databases such as the Bank Verification Number (BVN) and National Identification Number (NIN) systems. They must also ensure proper documentation of beneficial ownership, maintain accurate and up-to-date customer data. AML Solutions must support end-to-end CDD, KYC, KYB, and enhanced due diligence processes, including automated risk profiling and behavioral transaction analysis. They must also enable continuous data integration of KYC/KYB data with customer risk profile to provide investigators with a unified view of customer profiles and transactional history for effective monitoring and decision-making.
  1. Sanction Lists & Politically Exposed Person (PEP) Screening: Financial institutions are required to conduct sanctions and screening of PEP at onboarding and on a continuous basis. They are also required to maintain clear procedures for reviewing, escalating, and resolving alerts and being able to demonstrate the effectiveness of their screening processes with proper documentation. AML Solutions must integrate domestic/international sanctions and watchlists with instant updates, automatically flagging or blocking transactions on confirmed matches in line with regulatory requirements.
  2. Risk Assessment & Transaction Monitoring: Financial institutions are required to conduct and document periodic business risk assessments and ensure AML systems reflect these risk profiles. The AML Solutions must assess transactions based on risk and identify possible money laundering activities. It should generate explainable alerts and enable pre-emptive actions to support decision-making.
  3. Reporting & Governance: Financial institutions must ensure accurate, complete, and timely regulatory reporting, supported by internal reviews and approval processes. The AML Solutions must be implemented to ensure automated or semi-automated generation of the required reports. They are also required to establish governance frameworks covering system ownership, access controls, model validation, and periodic audits.
  4. Security & Data Protection: There is also a requirement that all data processed and stored within AML systems comply with the scope of the Nigeria Data Protection Act (NDPA) 2023 and other applicable regulations. The AML Solutions must support this by securely collecting and storing relevant data, applying security controls such as encryption in transit, at rest, and in use, enforcing role-based access and secure authentication.

What is the Compliance Timeline for the AML Solutions?

The compliance timeline for the AML Solutions is 18 months for deposit money banks and 24 months for other financial institutions. However, all financial institutions are required to prepare and submit a detailed implementation plan to the CBN within 3 months of the issuance of the AML Solutions. The implementation plan must provide a clear and detailed roadmap on the steps the financial institution intends to implement to meet all obligations set out in the AML Solutions.

What is the Risk of Non-Compliance?

Where financial institutions fail to implement the AML Solutions or does so in a manner that results in ineffective AML/CFT/CPF controls, they may be subject to penalties. This liability extends not only to the financial institutions but also to personnel responsible for the implementation of the AML Solutions. Applicable penalties will be imposed in accordance with existing regulations, including the CBN AML-CFT-CPF Administrative Sanctions Regulations 2023, the Banks and Other Financial Institutions Act, and other relevant regulatory frameworks.

Conclusion

The AML Solutions imposes clear and enforceable obligations on financial institutions to implement effective, technology-driven frameworks for detecting and monitoring money laundering and other related activities. It is therefore imperative for financial institutions to promptly implement these requirements in line with the prescribed timelines.

KEY REGULATORY UPDATE: CBN GUIDELINES ON INSTANT PAYMENT FUNCTIONALITIES AND MOBILE BANKING SECURITY

By: Aderonke Alex-Adedipe and Mark Imonitie

Introduction

On 12 March 2026, the Central Bank of Nigeria (CBN) issued a circular (the “Circular”) to all financial institutions (FIs) offering Instant Payment (IP) services in Nigeria.

The Circular provides the CBN’s Guidelines on instant payments and introduces sweeping measures to strengthen IP operations, enhance security protocols, improve consumer protection, and align with global best practices. This newsletter highlights the key provisions introduced by the Guidelines.

  1. VOLUNTARY OPT-IN AND OPT-OUT FUNCTION

Under the existing framework, FIs are not mandated to provide a feature on their mobile banking application, enabling customers to voluntarily opt in or out of IP services.

The new Guidelines however require FIs to allow customers to opt in or out at any time, subject to Multi-Factor Authentication (MFA).

New customers will be onboarded in opt-in mode by default. While opted out, customers cannot perform instant online fund transfers from their account; however, such transfers remain available via a physical branch visit.

  1. FLEXIBILITY IN SETTING TRANSACTION LIMITS

Prior to establishing the Guidelines, the maximum transaction limits of N25,000,000.00 for individuals and ₦250,000,000.00 for corporate entities, were fixed, with no option for customers to set personalized limits within those thresholds.

The Guidelines will subsequently allow both individuals and corporate entities to adjust these limits as needed, subject to enhanced due diligence and appropriate risk management by the FI.

To ensure security, the new transaction limit takes effect only after the customer completes the Multi-Factor Authentication (MFA) process.

  1. LIVELINESS CHECKS AND ENHANCED SECURITY FOR ONLINE TRANSACTIONS
    The Guidelines provide that where a customer seeks to open an account online or reactivate an online account, the following enhanced security measures shall apply:

    • liveliness check of the online account;
    • real-time validation of BVN/NIN database for online account openings/reactivations;
    • enhanced authentication mechanisms such as biometric authentication, soft token, hard token, for online account reactivations.

    A liveliness check is a biometric security measure which confirms that a user is a live, physically present human rather than a photo, video, or deepfake—by analyzing facial traits like skin texture, eye movement, and depth during remote onboarding or transactions, thereby preventing spoofing attacks.

  2. FRAUD MONITORING FUNCTIONALITY

The Guidelines mandate that all FIs implement and activate enterprise-wide fraud monitoring functionality covering both in-flows and out-flows. This measure restricts suspicious transactions in real-time while enabling prompt fraud detection and response.

  1. MANDATORY DEVICE BINDING

Under the existing framework, customers can operate their mobile banking application concurrently on multiple devices. The new Guidelines restrict mobile banking applications to one active device at a time, prohibiting concurrent use across devices. Switching to a new device triggers automatic deactivation of the previous one, followed by re-activation and authentication.

  1. ADDITIONAL REQUIREMENTS

The Guidelines introduce the following measures for mobile financial services applications and internet banking:

  • New account owners: Upon activation of a mobile banking application, inflow and outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira).
  • Existing account owners: Upon activation of a mobile banking application, outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira)
  • First-time login on a new device for internet banking requires enhanced Multi-Factor Authentication (MFA).

Conclusion

The Central Bank of Nigeria’s (CBN) new Guidelines on Instant Payment Functionalities for Financial Institutions mark a significant advancement in safeguarding digital transactions nationwide.

Effective 1 July 2026, financial institutions (FIs) must implement these measures. Among other requirements, the Guidelines necessitates comprehensive security and Data Protection Impact Assessments (DPIAs) to ensure compliance with the Nigeria Data Protection Act 2023 particularly resulting from mandatory features like multi-factor authentication (MFA), facial recognition, and continuous transaction monitoring.

About us:

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organization. We provide quality and innovative legal and data protection  support across diverse industries, helping clients operate in compliance with applicable laws and regulations to drive sustainable business growth.