Posts

WHEN THE REGULATOR TAKES THE BOARD: THE LEGAL LIMITS OF NERC’S INTERVENTION

BY ADERONKE ALEX-ADEDIPE & EFE OKPARAVERO

Introduction

On 10 August 2026, the Nigerian Electricity Regulatory Commission (“NERC”) issued Order No. NERC/2026/086 in respect of Kaduna Electricity Distribution Plc (“KAEDC”), dissolving its existing board and appointing an interim board of “Special Directors” to oversee the company. NERC has also appointed an Administrator and commenced a 12-month process aimed at identifying a new core investor for KAEDC.

The intervention follows what NERC describes as a “grave situation”, including prolonged regulatory and market defaults, inadequate investment, operational weaknesses and significant outstanding market obligations.

The Order raises an important question for Nigeria’s electricity sector, which is how far can NERC go in taking control of a privately owned electricity distribution company without crossing the line between regulatory intervention and corporate ownership?

Taking control is not taking ownership

Section 75 of the Electricity Act, 2023 (“Electricity Act”) permits NERC, following an inquiry into the conduct or affairs of a licensee, to intervene where it determines that the licensee is in a “grave situation”.

The statutory triggers include;

  • an inability to discharge obligations under the Act or licence terms,
  • prolonged default in complying with statutory or regulatory obligations,
  • a protracted management crisis detrimental to shareholders, consumers or the operation of the undertaking, or
  • insufficient assets to meet liabilities with an imminent risk of receivership.

Where these circumstances exist, NERC is empowered to issue an interim order dissolving and removing the board and appointing Special Directors and an Administrator to manage the undertaking, notwithstanding anything contained in any written law and the memorandum and articles of association of the undertaking/licensee.

Accordingly, while the usual rights of shareholders to appoint or remove directors are displaced for as long as the intervention remains in force, the intervention does not transfer the shareholders’ ownership of KAEDC to NERC. The shareholders retain their shares and their underlying proprietary interests. What changes is the control over the affairs of the licensed undertaking.

Implications of an unsuccessful intervention

By the provisions of the Electricity Act, where the state of affairs of the licensee does not improve after NERC has taken the appropriate measures, NERC shall revoke the licence.

The Act therefore contemplates progression from regulatory intervention to licence revocation where the intervention fails, and ultimately to the sale and transfer of the undertaking. It provides  for the sale and transfer of the undertaking and addresses the treatment of liabilities and security interests.

Accordingly, if the intervention fails and a core investor has been identified, NERC may in line with the Electricity Act, proceed to revoke KAEDC’s licence and invoke the statutory process for the sale of the undertaking. This must however follow the statutory process:

  1. Regulatory intervention: This is the stage KAEDC is currently at and is critical to the preservation of its existing shareholding. At this stage, the focus is on addressing the circumstances that gave rise to the intervention and restoring the undertaking to a viable position.
  2. Licence revocation: If the regulatory intervention fails and the underlying issues are not resolved, NERC may revoke KAEDC’s licence in accordance with the Electricity Act. Revocation would trigger the statutory process for dealing with the undertaking.
  3. Compulsory sale: Following the licence revocation, NERC shall invoke the statutory sale mechanism under Section 77 of the Electricity Act and direct the sale of the undertaking.

Implications of the Intervention for KAEDC’s Creditors

The intervention has immediate implications for KAEDC’s creditors. While NERC has not revoked KAEDC’s licence or commenced the statutory process for the sale of the undertaking, the Order places KAEDC under regulatory control and introduces measures governing the company’s affairs during the intervention period.

For example, the Order directs the Corporate Affairs Commission not to register any change in KAEDC’s shareholding or directorship during the intervention period without NERC’s prior written approval. NERC has also directed the Administrator, Bureau of Public Enterprises, Nigerian Bulk Electricity Trading Plc, Nigerian Independent System Operator and other material creditors to reconcile KAEDC’s liabilities and file a liability-management plan with the Commission within 90 days from the commencement of the Order. This means that creditors should endeavour to file their interests with the Commission. The Order further provides that the liability-management plan may allow for interim warehousing of the liabilities. Under this arrangement, such warehoused liability would not be immediately enforceable but temporarily preserved for later settlement as part of the sale transaction. The warehoused liabilities would need to be disclosed in the transaction documents in relation to the sale, and prospective investors would be required to set out in their bids how they propose to settle those liabilities.

The above becomes even more significant if NERC proceeds to a statutory sale as the Electricity Act provides that the new purchaser of the undertaking gets it free of KAEDC’s existing debts and other encumbrances. Therefore, the creditors are precluded from filing any claims against the undertaking or its assets after the sale. Instead, they must recover what they are owed from the funds paid for the purchase of the undertaking, according to their order of priority.

In the interim, however, the key point is that KAEDC is in a regulatory intervention, not yet a statutory sale.  Hence, Creditors should seek to have their interests expressly captured in the liability-management plan, where they can be warehoused and settlement provided for in the event of a sale.  If they fail to do so, their principal avenue for recovery may be limited to the purchase price paid by the purchaser, distributed in accordance with the applicable order of priority, which may ultimately be insufficient to satisfy their outstanding debts.

The legal limits of NERC’s power

NERC’s intervention powers are broad, but they are not unfettered. Their exercise remains subject to the statutory framework established by the Electricity Act. In particular:

  1. Statutory threshold: There must be a proper basis for concluding that the licensee is in a “grave situation” within the meaning of section 75 of the Electricity Act with at least one of the four statutory triggers identified above being present.
  2. Statutory purpose: The intervention must be directed towards the statutory objectives underlying section 75 of the Electricity Act, including maintaining the continuity of electricity supply and resolving the particular statutory trigger that warranted the regulatory intervention.
  3. Legal constraints: NERC’s exercise of its powers remains subject to applicable legal principles. Accordingly, issues of compliance with statutory preconditions, procedural requirements, and the rationality of the decision may arise in any litigation challenging the intervention.

These limitations do not, however, mean that NERC requires shareholder approval before exercising its power to remove or replace a licensee’s board.

Recommendations

  1. For KAEDC and its shareholders: KAEDC and its shareholders should closely monitor the intervention and ensure strict compliance with the requirements of the Order. In particular, they should obtain legal advice on the extent to which the intervention affects existing shareholder rights, board powers, contractual arrangements and proposed changes to the company’s shareholding or directorship.
  2. For creditors: Creditors should undertake an immediate review of their existing exposures to KAEDC, including the nature and enforceability of any security interests. They should also assess the effect of the Order on enforcement rights and engage with the liability-management process within 90 days as directed by NERC, to ensure that their claims are properly recognised and protected.
  3. For NERC: NERC should ensure that the intervention remains closely tied to the statutory conditions and objectives under section 75 of the Electricity Act. Any further measures taken during the intervention should have a clear statutory basis and be implemented in a manner that provides sufficient certainty to KAEDC, its shareholders, creditors and prospective investors.
  4. For prospective investors: Potential investors should conduct enhanced legal and regulatory due diligence before committing to KAEDC. This should extend beyond KAEDC’s financial position to include its regulatory obligations, outstanding liabilities, existing security interests, shareholder structure and the statutory implications of any subsequent licence revocation or sale.
  5. For other DisCos and their stakeholders: Other electricity distribution companies should treat the KAEDC intervention as a regulatory warning. DisCos should strengthen compliance, investment, governance and financial-management frameworks to address regulatory and market defaults before they develop into circumstances capable of triggering intervention under section 75 of the Electricity Act.
  6. For policymakers and regulators: The KAEDC intervention also highlights the need for greater clarity around the relationship between regulatory intervention, shareholder ownership, creditor rights and the proposed replacement of a core investor. Clearer guidance on how a replacement investor is to acquire an interest during an intervention would provide greater certainty for existing shareholders, creditors and prospective investors.

Conclusion

The KAEDC intervention is more than a decision to remove a board. It is a test of the boundary between regulatory control and corporate ownership. The Electricity Act gives NERC significant powers to intervene in the management of a distressed electricity licensee. However, removing the board does not, by itself, make NERC the owner of KAEDC or extinguish the proprietary interests of its shareholders and creditors.

If the intervention succeeds and KAEDC is returned to a viable position, NERC’s role may remain one of temporary regulatory control. If it does not succeed, section 75(4) of the Electricity Act creates a potential route towards licence revocation and the statutory sale of the undertaking. This is where the balance between regulatory intervention, shareholder ownership and creditor rights becomes most significant.

NAICOM’S GUIDELINES FOR FOREIGN HEALTH INSURANCE PROVIDERS: KEY COMPLIANCE CONSIDERATIONS FOR INSURERS AND POLICYHOLDERS IN NIGERIA

BY ADERONKE ALEX-ADEDIPE & OLUWAYEMI IBIRINDE

Introduction

On 31 March 2026, the National Insurance Commission (“NAICOM”) issued the Guidelines for the Operation of Foreign or International Health Insurance Providers (the “Guidelines”) pursuant to the Nigerian Insurance Industry Reform Act, 2025 (“NIIRA 2025”). The Guidelines establish, for the first time, a comprehensive regulatory framework governing foreign or international private medical insurers and reinsurers (“IPMI-R Providers”) seeking to provide health insurance services to entities registered or individuals who are resident in Nigeria.

Historically, international health insurance products were commonly procured directly from offshore insurers by multinational corporations, expatriates and high-net-worth individuals without any comprehensive regulatory framework governing such activities in Nigeria. Industry reports estimated that this resulted in approximately US$2 billion in annual premium outflows, while limiting regulatory oversight and the participation of domestic insurers. The Guidelines seek to address these gaps by requiring foreign health insurers to obtain NAICOM’s approval before operating in Nigeria, establishing approved local partnerships and complying with specified consumer protection, reporting and governance obligations.

In this newsletter, we examine the key provisions of the Guidelines and highlight some of the legal and commercial considerations for insurers and policyholders.

Who Do the Guidelines Apply To?

The Guidelines apply to all International Private Medical Insurers or Reinsurers (IPMI-R Providers) seeking to transact, market, underwrite or otherwise engage in health insurance business emanating from Nigeria.

Specifically, they apply to:

  1. foreign health insurers and reinsurers offering products to entities registered in Nigeria;
  2. foreign providers offering health insurance to persons residing in Nigeria; and
  3. intermediaries and authorised representatives acting on behalf of foreign health insurers.

Accordingly, the regulatory focus is not the location of incorporation of the insurer but whether the health insurance business or clientele originates from Nigeria.

What are the Key Compliance Requirements?

  1. Prior NAICOM Approval

The most significant change introduced by the Guidelines is that no foreign health insurer may transact, market or underwrite health insurance business originating from Nigeria without obtaining the prior written approval of NAICOM.

Similarly, no Nigerian entity or individual may transfer health insurance risks to an IPMI-R Provider unless that provider has received NAICOM’s approval.

The Guidelines further provide that where NAICOM does not communicate its approval or rejection within ten (10) working days after receiving complete documentation, the application shall be deemed approved.

  1. Mandatory Local Partnership Model

Unlike the previous regulatory position, the Guidelines prohibit foreign insurers from directly issuing health insurance policies to Nigerian entities or persons residing in Nigeria except through an authorised representative domiciled in Nigeria.

Every approved IPMI-R Provider must adopt one of the following operational models:

  • Model 1: Domestic Insurer Partnership;
  • Model 2: Domestic Administrator or Intermediary Partnership; or
  • Model 3: Health Maintenance Organisation (HMO) Partnership.

These partnership models ensure that licensed Nigerian entities participate in premium administration, claims support, regulatory reporting and other operational functions.

To obtain approval, an IPMI-R Provider must submit comprehensive documentation including:

  1. evidence of incorporation in its home jurisdiction;
  2. proof of regulatory licensing in its home jurisdiction;
  3. detailed product descriptions;
  4. a business plan;
  5. premium worksheets;
  6. proposed Nigerian intermediaries;
  7. its preferred operational model; and
  8. any additional information requested by NAICOM.
  1. Consumer Protection Requirements

The Guidelines introduce several customer protection obligations designed to improve accountability and transparency.

Approved providers are required to:

  1. provide clear information regarding policy terms and exclusions;
  2. ensure products meet customers’ needs;
  3. establish effective complaints management procedures;
  4. include claims settlement procedures within policy documentation; and
  5. ensure complaints are handled fairly through their Nigerian representatives or intermediaries.

These obligations significantly strengthen the position of Nigerian policyholders.

  1. Reporting and Ongoing Regulatory Obligations

Approved providers are required to submit quarterly production returns to NAICOM and pay the prescribed Insurance Supervisory Service (ISS) Levy.

The Guidelines therefore establish continuing regulatory oversight rather than a one-time approval process.

Compliance Considerations

Pending further regulatory guidance, organisations that utilise international health insurance arrangements should consider the following.

a. Review Existing Insurance Arrangements

Multinational companies should determine whether their current international health insurance programmes involve IPMI-R Providers that have obtained, or intend to obtain, NAICOM approval.

b. Assess Existing Partnership Structures

Foreign insurers should evaluate whether their existing operating model aligns with one of the three partnership structures prescribed under the Guidelines and identify any restructuring that may be required.

c. Review Distribution and Intermediary Arrangements

Insurers, brokers, HMOs and third-party administrators should assess whether their contractual arrangements adequately reflect the roles and reporting obligations contemplated under the Guidelines.

d. Strengthen Compliance Frameworks

Organisations should establish internal governance procedures to monitor ongoing compliance with NAICOM’s approval requirements, reporting obligations and customer protection standards.

e. Review Existing Policies

The Guidelines permit policies issued before the effective date to continue until expiry. However, organisations should review renewal arrangements to ensure that future policies comply with the new regulatory framework.

Penalties for Non-Compliance

The Guidelines introduce significant sanctions for non-compliance.

  1. Any entity registered in Nigeria or person residing in Nigeria that transacts health insurance business with an unapproved IPMI-R Provider may be liable to a penalty of not less than the total premium involved.
  2. The Guidelines also required providers to regularise their operations within the prescribed ninety-day transitional period. Failure to satisfy the approval requirements may result in rejection of the application and suspension of the issuance of new policies and renewals.

Conclusion

With the Guidelines having taken effect on 31 March 2026, multinational employers, foreign insurers, HMOs, brokers and other intermediaries, should immediately prioritize assessing existing operational structures and contractual arrangements to ensure continued compliance with the new regulatory framework. Organisations that undertake this assessment proactively will be better positioned to navigate future regulatory developments while minimising compliance risks.

CBN’S DATA LOCALISATION DIRECTIVE – COMPLIANCE CONSIDERATIONS FOR PAYMENT SYSTEM PARTICIPANTS

BY ADERONKE ALEX-ADEDIPE & PROMISE ITAH

Introduction

On June 15, 2026, the Central Bank of Nigeria (“CBN“) issued a Circular on Introduction of Market Structure Requirements, Data Localisation, Ultimate Beneficial Ownership Disclosure, and Systemic Oversight Measures in the Nigeria Payments System (the “Circular“). Among other regulatory reforms, the Circular introduces a significant data localisation requirement directing all financial institutions and participants facilitating payments within Nigeria—including banks, payment service providers, mobile money operators and other payment participants— (collectively “Payment System Participants”) to ensure that data generated in relation to payment transactions in Nigeria is stored and managed in Nigeria by January 1, 2027.

In this newsletter, we examine the scope of the CBN’s data localisation requirements, their interaction with existing data protection obligations, and some of the key legal, contractual and operational considerations which Payment System Participants should consider in preparation for compliance.

  1. Who does the Circular Apply to?
    The Circular applies to payment transaction data generated through Nigeria’s payments system. Although the Circular does not define the term “payment transaction data”, it intuitively includes information generated in connection with a payment transaction, including the payer’s and beneficiary’s payment details, transaction amounts, payment references, authentication records, settlement and routing information, transaction logs and other related technical data required to process, verify or record a payment.

    The Circular also appears to frame the localisation requirement by reference to payment transaction data generated within Nigeria, rather than the location in which the business is principally domiciled. On this basis, therefore any Payment System Participant processing payment transaction data generated within Nigeria may be expected to comply with this requirement, regardless of their country of domicile.

  1. What are the Key Compliance Requirements?

    a. Local Processing and Storage
    Payment System Participants must ensure that payment transaction data is both stored and managed within Nigeria. This extends beyond maintaining a local copy of data and requires that the primary processing environment, databases, backups and operational control remain on infrastructure located within Nigeria.

    The requirement for payment transaction data to be “managed” in Nigeria may also have implications for administrative activities such as access management, database administration, encryption key management and audit logging, particularly where these functions are performed through offshore infrastructure or personnel.

    b. Technology and Infrastructure
    The Circular is likely to require many Payment System Participants to review their technology infrastructure, particularly where payment services rely on foreign cloud service providers or systems hosted outside Nigeria. Given the requirement for payment transaction data generated within Nigeria to be stored and managed locally, organisations should assess whether their existing technology architecture involves the storage, processing or replication of payment transaction data outside Nigeria. Areas that may require review include:

    • cloud hosting arrangements and the location of servers;
    • disaster recovery and backup systems;
    • analytics and monitoring platforms that process payment data;
    • testing and development environments that use live or production payment data; and
    • third-party APIs and other technology integrations that may transfer payment data outside Nigeria.

Payment System Participants operating hybrid or multiple cloud environments should assess whether payment data is stored, replicated or processed outside Nigeria and, where necessary, implement appropriate technical or operational changes before the compliance deadline.

c. Vendor and Outsourcing Arrangements

Whilst it is commonplace for Payments System Participants to assign data processing and storage activities to third parties, the Circular does not appear to transfer the obligations from Payment System Participants to service providers in such instance. Accordingly, organisations should review their contractual arrangements with cloud service providers, payment processors, application programming interface (API) providers and other technology vendors to assess whether those arrangements support compliance with the localisation requirement. In particular, organisations should consider whether their contracts adequately address:

    • the requirements for payment data to be stored and managed within Nigeria;
    • restrictions on processing payment data outside Nigeria;
    • rights to conduct audits and facilitate regulatory inspections;
    • controls over the use of subcontractors that may have access to payment data;
    • obligations to promptly notify the Payment System Participant of any data breaches or incidents; and
    • termination rights where a vendor is unable to comply with the localisation requirements.
  1. How does the Circular Interact with the Nigeria Data Protection Act (NDPA)?

The Circular complements rather than replaces the NDPA. While the NDPA regulates the processing and international transfer of personal data through recognised transfer mechanisms and safeguards, the CBN Circular imposes an additional regulatory obligation applicable specifically to payment transaction data. Accordingly, compliance with the NDPA alone will not satisfy the CBN’s localisation requirements.

  1. Practical Compliance Steps

Pending any further guidance from the CBN, Payment System Participants should consider taking the following steps to prepare for implementation:

    1. conducting a comprehensive data mapping exercise to identify where payment data is stored, processed and transmitted;
    2. assessing existing cloud and infrastructure arrangements for localisation risks;
    3. reviewing third-party vendor relationships and contractual provisions;
    4. updating internal data governance, outsourcing and information security policies;
    5. establishing board and management oversight of the implementation programme; and
    6. maintaining adequate documentation to demonstrate compliance during regulatory inspections.

Conclusion

The CBN’s payment data localisation requirements represent a significant development in the regulation of Nigeria’s payments ecosystem. By requiring payment transaction data generated within Nigeria to be stored and managed in Nigeria, the Circular appears intended to strengthen regulatory oversight, enhance operational resilience and support the security of Nigeria’s payments infrastructure. For Payment System Participants, the immediate priority will be to assess whether existing technology infrastructure, data governance frameworks and third-party vendor arrangements are consistent with the new localisation requirement. Given the breadth of the obligation and the absence of detailed implementation guidance, organisations that begin assessing their compliance position ahead of the January 2027 implementation date will be better positioned to address any legal, operational or contractual gaps as further guidance emerges.

NIGERIA CAPITAL MARKET REGULATORY UPDATE: SEC MANDATES REGISTRATION OF COLLATERAL MANAGEMENT COMPANIES, WAREHOUSE OPERATORS AND WAREHOUSES

BY ADERONKE ALEX-ADEDIPE & OMODELE FATODU

On 11 May 2026, the Securities and Exchange Commission (the “Commission”) issued a circular clarifying the registration requirements applicable to certain capital market operators.

The Circular applies to entities involved in the storage, management and facilitation of commodities used in structured trade financing or warehouse receipt arrangements. In particular:

  • Collateral Management Companies (“CMCs”);
  • Warehouse Operators; and
  • Warehouses linked to commodity exchanges or electronic warehouse receipt systems.

Although these categories of operators were already recognised and regulated under the SEC Rules on Commodity Exchanges and Trading Platforms; Warehouse Receipt Systems; and Collateral Management and Warehousing Operations, the Circular appears intended to reinforce compliance with the existing registration regime and clarify that entities operating under informal, transitional or unregistered arrangements are not exempt from regulatory requirements.

The Commission notes that entities currently carrying on any of the relevant activities under such informal or transitional arrangements are also required to apply for registration. Accordingly, the Commission has directed all existing and prospective entities within the scope of the Circular to submit complete registration applications within 90 days from the date of the Circular (the “Registration Deadline”).

The SEC further clarified that compliance will only be recognised upon submission of a complete application within the Registration Deadline. Consequently, incomplete applications, or failure to respond to requests for additional information within the stipulated timelines, will not satisfy the registration requirement.

In view of this Circular, we have set out below a brief overview of the registration and minimum capital requirements applicable to CMCs and Warehouse Operators:

S/N Capital Market Operator Registration Documents Minimum Capital
1. Collateral Management Companies
  • Duly completed SEC Forms 2, 2D and 3
  • Minimum of three sponsored individuals, including a Managing Director and Compliance Officer;
  • Certificate of Incorporation, Memorandum and Articles of Association, and CAC Status Report;
  • Company profile, organisational structure and details of principal officers;
  • Evidence of payment for shares allotted to shareholders;
  • Evidence of financial and technical capacity to carry out collateral management functions;
  • Latest audited accounts or statement of affairs; and
  • Valid fidelity insurance bond covering at least 20% of the minimum paid-up capital.
Tier 1 (Local/Regional Operators) – ₦200,000,000

Tier 2 (National/International Reach) – ₦500,000,000

 

2. Warehouse Operators
  • Duly completed SEC Forms 2, 2D and 3;
  • Minimum of three sponsored individuals, including a Managing Director and Compliance Officer;
  • Certificate of Incorporation, Memorandum and Articles of Association, and CAC Status Report;
  • Evidence of adequate storage facilities and appropriate security arrangements;
  • Evidence of requisite weighing and quality control equipment;
  • Evidence of comprehensive insurance coverage for facilities, equipment and commodities;
  • Evidence of suitable operational infrastructure, including loading and unloading systems;
  • Standard Operating Procedures (SOPs) for warehousing operations;
  • Latest audited accounts or statement of affairs; and
  • Valid fidelity insurance bond covering at least 20% of the applicable minimum capital requirement.
₦500,000,000

 

Conclusion

The Circular reflects the Commission’s intention to strengthen regulatory oversight, transparency and accountability within the commodities trading and warehouse receipt ecosystem. By requiring all relevant operators to formally register, the Commission is likely seeking to ensure that only entities with adequate operational capacity, governance structures and financial standing participate in the market and remain subject to direct regulatory supervision.

Accordingly, entities operating within this sector should assess whether their activities fall within the scope of the Circular and take immediate steps to commence or regularise their registration with the Commission where applicable.

REDEFINING AML COMPLIANCE: UNDERSTANDING CBN’S BASELINE STANDARDS FOR AUTOMATED AML SOLUTIONS FOR FINANCIAL INSTITUTIONS

BY ADERONKE ALEX-ADEDIPE AND HILLARY OKOROTIE

Introduction

With the increasing need to ensure financial security in today’s rapidly digitizing landscape and evolving compliance demands, the Central Bank of Nigeria (CBN) issued its Baseline Standards for Automated Anti-Money Laundering (AML) Solutions for Financial Institutions (“AML Solutions”) on March 10, 2026. This was followed by a Guidance Note on implementation, released on March 31, 2026.

In this newsletter, we provide an overview of the requirements of the AML Solutions for financial institutions.

What is the Purpose of the AML Solutions?

The AML Solutions is aimed at establishing a structured and automated system for the identification and reporting of suspicious transactions and strengthening adherence to AML, Combating the Financing of Terrorism (CFT), and Countering Proliferation Financing (CPF) regulatory requirements. It also applies to all financial institutions operating in Nigeria.

What are Some of the Obligations of Financial Institutions?

  1. Customer Due Diligence (CDD), Know Your Customer (KYC) and Know Your Business (KYB): Financial institutions are required to implement effective CDD, KYC and KYB frameworks supported by automated or semi-automated onboarding, instant identity verification, and integration with national identity databases such as the Bank Verification Number (BVN) and National Identification Number (NIN) systems. They must also ensure proper documentation of beneficial ownership, maintain accurate and up-to-date customer data. AML Solutions must support end-to-end CDD, KYC, KYB, and enhanced due diligence processes, including automated risk profiling and behavioral transaction analysis. They must also enable continuous data integration of KYC/KYB data with customer risk profile to provide investigators with a unified view of customer profiles and transactional history for effective monitoring and decision-making.
  1. Sanction Lists & Politically Exposed Person (PEP) Screening: Financial institutions are required to conduct sanctions and screening of PEP at onboarding and on a continuous basis. They are also required to maintain clear procedures for reviewing, escalating, and resolving alerts and being able to demonstrate the effectiveness of their screening processes with proper documentation. AML Solutions must integrate domestic/international sanctions and watchlists with instant updates, automatically flagging or blocking transactions on confirmed matches in line with regulatory requirements.
  2. Risk Assessment & Transaction Monitoring: Financial institutions are required to conduct and document periodic business risk assessments and ensure AML systems reflect these risk profiles. The AML Solutions must assess transactions based on risk and identify possible money laundering activities. It should generate explainable alerts and enable pre-emptive actions to support decision-making.
  3. Reporting & Governance: Financial institutions must ensure accurate, complete, and timely regulatory reporting, supported by internal reviews and approval processes. The AML Solutions must be implemented to ensure automated or semi-automated generation of the required reports. They are also required to establish governance frameworks covering system ownership, access controls, model validation, and periodic audits.
  4. Security & Data Protection: There is also a requirement that all data processed and stored within AML systems comply with the scope of the Nigeria Data Protection Act (NDPA) 2023 and other applicable regulations. The AML Solutions must support this by securely collecting and storing relevant data, applying security controls such as encryption in transit, at rest, and in use, enforcing role-based access and secure authentication.

What is the Compliance Timeline for the AML Solutions?

The compliance timeline for the AML Solutions is 18 months for deposit money banks and 24 months for other financial institutions. However, all financial institutions are required to prepare and submit a detailed implementation plan to the CBN within 3 months of the issuance of the AML Solutions. The implementation plan must provide a clear and detailed roadmap on the steps the financial institution intends to implement to meet all obligations set out in the AML Solutions.

What is the Risk of Non-Compliance?

Where financial institutions fail to implement the AML Solutions or does so in a manner that results in ineffective AML/CFT/CPF controls, they may be subject to penalties. This liability extends not only to the financial institutions but also to personnel responsible for the implementation of the AML Solutions. Applicable penalties will be imposed in accordance with existing regulations, including the CBN AML-CFT-CPF Administrative Sanctions Regulations 2023, the Banks and Other Financial Institutions Act, and other relevant regulatory frameworks.

Conclusion

The AML Solutions imposes clear and enforceable obligations on financial institutions to implement effective, technology-driven frameworks for detecting and monitoring money laundering and other related activities. It is therefore imperative for financial institutions to promptly implement these requirements in line with the prescribed timelines.

VIRTUAL ASSET SERVICE PROVIDER (VASP) LICENCES IN KENYA & NIGERIA – WHAT YOU NEED TO KNOW

By Seun Timi-Koleolu, Ombo Malumbe,  Eniola Sogbesan and Faith Ngarama 

 

Introduction

The future of Africa’s digital asset market is no longer speculative. It is real, growing, and increasingly regulated. For founders, Fintechs, and even traditional financial institutions looking to operate in the digital currency space, obtaining a Virtual Asset Service Provider (VASP) license is the price of market entry. In jurisdictions like Nigeria and Kenya—two of the continent’s most active crypto markets—regulators are moving to formalize the ecosystem, protect consumers, and bring operators within a defined legal framework.

However, while both countries are moving in the same direction, their regulatory approaches, licensing processes, and compliance expectations differ in important ways. Understanding these nuances is critical for any business looking to establish or expand operations across either market.

In this newsletter, we examine the licensing requirements, regulated activities, applicable regulatory authorities and other practical considerations for navigating the process successfully.

S/N SUBJECT NIGERIA KENYA
1 Principal Regulator Securities and Exchange Commission Central Bank of Kenya, and Capital Markets Authority
2 License Categories ·       Ancillary Assets Service Providers (AVASPs)

·       Digital Assets Offering Platform (DAOP)

·       Digital Assets Intermediary (DAI)

·       Digital Assets Platform Operator

·       Real-world Assets Tokenization and Offering Platform

·       Digital Assets Exchange (DAX)

·       Digital Assets Custodian

·       Virtual Asset Wallet Provider

·       Virtual Asset Exchange

·       Virtual Asset Payment Processor

·       Virtual Asset Broker

·       Virtual Assets Investment Advisor

·       Virtual Asset Manager

·       Virtual Asset Offering Provider (Initial Coin Offering)

·       Virtual Asset Offering Provider (Virtual Asset Tokenization)

·       Virtual Asset Offering Provider (Token Issuance)

·       Virtual Asset Offering Provider (Stablecoin Issuance)

 

3 Permissible Activities Digital Assets Offering Platform This license is used to facilitate fund raising through a digital asset offering via the use of a distributed ledger technology. Virtual Asset Wallet Provider: Services provided by a third party, in which the private keys to the subject’s virtual assets are held and managed by the third party for proof of ownership and facilitation of transactions.

Virtual Asset Exchange: Providing a digital online platform facilitating virtual asset transfers and exchanges. Exchanges may occur between one or more forms of virtual assets, or between virtual assets and fiat currency; or A platform providing for the facilitation of the sale, trading, or exchange of virtual assets for fiat currencies or for other virtual assets.

Virtual Asset Payment Processor: Arranging transactions involving virtual assets and fiat currency, or between virtual assets.

Virtual Asset Broker: Facilitate the exchange between one or more forms of virtual assets through a virtual asset exchange and virtual asset wallet providers for and on behalf of clients, which may include retail, institutional investors, or funds.

Virtual Assets Investment Advisor: Provision of investment advice on virtual assets, initial virtual asset offering and non-fungible tokens for and on behalf of clients, which may include individuals or institutional investors.

Virtual Asset Manager: Managing portfolios in accordance with mandates given by clients on a discretionary basis where such portfolios include one; or more virtual assets.

Virtual Asset Offering Provider (Initial Coin Offering): Issuing and selling virtual assets to the public. May involve participating in and providing financial services relating to the initial coin offering.

Virtual Asset Offering Provider (Virtual Asset Tokenization): The process of converting real-world assets (like real estate, art, or, commodities) into digital token on a blockchain.

Virtual Asset Offering Provider (Token Issuance): Provision of tokenization platform for issuance and secondary trading of tokens of real-world assets.

Virtual Asset Offering Provider (Stablecoin Issuance): The process of creating and managing approved stablecoins.

Digital Assets Intermediary

This license is used to facilitate transactions involving virtual assets such as:

a. execution of orders for virtual assets on behalf of clients;

b. acceptance and transmission of orders for virtual assets on behalf of clients;

c. placing of virtual assets;

d. providing advice on virtual assets investment;

e. providing financial portfolio.

Digital Assets Custodian

This license is suitable for facilitating the safekeeping/holding in custody and/or administration of virtual assets or instruments that enable control over virtual assets.

Digital Assets Exchange

This license is used to facilitate the trading of virtual or digital assets.

The creation of new license categories such as

·       Ancillary Virtual Asset Service Providers (AVASPs)

·       Digital Assets Platform Operators (DAPOs); and

·       Real‑World Assets Tokenization and Offering Platforms (RATOPs).

highlights an area where further regulatory clarity will be required. As there is no existing regulatory framework that expressly identifies the permissible activities that fall within these newly introduced license categories.

4 Share Capital Requirements Ancillary Assets Service Providers (N300 million)

Digital Assets Offering Platform

(N 1billion)

 

Digital Assets Intermediary

(N500 million)

 

Digital Assets Platform Operator

(N500 million)

 

Real-world Assets Tokenization and Offering Platform

(N 1 billion)

 

Digital Assets Exchange

(N 2 billion)

 

Digital Assets Custodian

(N2 billion)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Virtual Asset Wallet Provider

(KSH 150 million)

 

Virtual Asset Exchange

(KSH 150 million)

 

Virtual Asset Payment Processor

(KSH 50 million)

 

Virtual Asset Broker

(KSH 30 million)

 

Virtual Assets Investment Advisor

(KSH 2.5 million)

 

Virtual Asset Manager

(KSH 30 million)

 

Virtual Asset Offering Provider (Initial Coin Offering)

(KSH 200 million)

 

Virtual Asset Offering Provider (Virtual Asset Tokenization)

(KSH 200 million)

 

Virtual Asset Offering Provider (Token Issuance)

(KSH 200 million)

 

Virtual Asset Offering Provider (Stablecoin Issuance)

(KSH 500 million)

5 Corporate

Governance

Requirements

All VASPs must have a minimum of five (5) directors, three (3) of whom must be Nigerian.

Also, the board of each VASP must comprise of the following committees

·       Nomination and Governance

·       Remuneration

·       Audit and Risk Management

The Board of Directors will constitute at least three (3) members.

 

Structure:

·       1/3 must be independent directors.

·       Not more than 1/3 shall be related to any director.

·       The Board’s chairperson shall not be appointed as the Chief Executive Officer (CEO).

6 Investment Thresholds High Networth Individuals

(No restriction)

 

Angel Investors

(maximum of N50 million per issuer within a 12-month period)

 

Retail Investors

(maximum of N1million per issuer not exceeding N10 million within a 12-month period)

There are yet to be any restrictions on Investment Thresholds. However, this does not limit such limits being applied as per the applicable laws more so from the Capital Markets Authority’s side.

 Conclusion

Securing a Virtual Asset Service Provider (VASP) license in Nigeria or Kenya is no longer simply a regulatory requirement but a strategic step toward building a credible and sustainable digital asset business. While both jurisdictions are actively developing their frameworks, they each present distinct requirements and regulatory expectations that must be carefully navigated. Businesses looking to operate in either market must take a proactive approach to compliance, ensuring that their structures, governance, and operational models align with the applicable rules from the outset.

Ultimately, success in this space will depend not only on obtaining a VASP license, but on maintaining ongoing compliance in an evolving regulatory environment. As regulators continue to refine their approach to Virtual assets, businesses that prioritize transparency, strong internal controls, and regulatory engagement will be best positioned to scale confidently. For prospective entrants, understanding the regulatory landscape early and preparing accordingly will make the difference between a smooth market entry or costly delays.

KEY REGULATORY UPDATE: CBN GUIDELINES ON INSTANT PAYMENT FUNCTIONALITIES AND MOBILE BANKING SECURITY

By: Aderonke Alex-Adedipe and Mark Imonitie

Introduction

On 12 March 2026, the Central Bank of Nigeria (CBN) issued a circular (the “Circular”) to all financial institutions (FIs) offering Instant Payment (IP) services in Nigeria.

The Circular provides the CBN’s Guidelines on instant payments and introduces sweeping measures to strengthen IP operations, enhance security protocols, improve consumer protection, and align with global best practices. This newsletter highlights the key provisions introduced by the Guidelines.

  1. VOLUNTARY OPT-IN AND OPT-OUT FUNCTION

Under the existing framework, FIs are not mandated to provide a feature on their mobile banking application, enabling customers to voluntarily opt in or out of IP services.

The new Guidelines however require FIs to allow customers to opt in or out at any time, subject to Multi-Factor Authentication (MFA).

New customers will be onboarded in opt-in mode by default. While opted out, customers cannot perform instant online fund transfers from their account; however, such transfers remain available via a physical branch visit.

  1. FLEXIBILITY IN SETTING TRANSACTION LIMITS

Prior to establishing the Guidelines, the maximum transaction limits of N25,000,000.00 for individuals and ₦250,000,000.00 for corporate entities, were fixed, with no option for customers to set personalized limits within those thresholds.

The Guidelines will subsequently allow both individuals and corporate entities to adjust these limits as needed, subject to enhanced due diligence and appropriate risk management by the FI.

To ensure security, the new transaction limit takes effect only after the customer completes the Multi-Factor Authentication (MFA) process.

  1. LIVELINESS CHECKS AND ENHANCED SECURITY FOR ONLINE TRANSACTIONS
    The Guidelines provide that where a customer seeks to open an account online or reactivate an online account, the following enhanced security measures shall apply:

    • liveliness check of the online account;
    • real-time validation of BVN/NIN database for online account openings/reactivations;
    • enhanced authentication mechanisms such as biometric authentication, soft token, hard token, for online account reactivations.

    A liveliness check is a biometric security measure which confirms that a user is a live, physically present human rather than a photo, video, or deepfake—by analyzing facial traits like skin texture, eye movement, and depth during remote onboarding or transactions, thereby preventing spoofing attacks.

  2. FRAUD MONITORING FUNCTIONALITY

The Guidelines mandate that all FIs implement and activate enterprise-wide fraud monitoring functionality covering both in-flows and out-flows. This measure restricts suspicious transactions in real-time while enabling prompt fraud detection and response.

  1. MANDATORY DEVICE BINDING

Under the existing framework, customers can operate their mobile banking application concurrently on multiple devices. The new Guidelines restrict mobile banking applications to one active device at a time, prohibiting concurrent use across devices. Switching to a new device triggers automatic deactivation of the previous one, followed by re-activation and authentication.

  1. ADDITIONAL REQUIREMENTS

The Guidelines introduce the following measures for mobile financial services applications and internet banking:

  • New account owners: Upon activation of a mobile banking application, inflow and outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira).
  • Existing account owners: Upon activation of a mobile banking application, outflow transactions are limited for the first 24 hours, and FI’s shall set the limit not to exceed ₦20,000.00 (Twenty Thousand Naira)
  • First-time login on a new device for internet banking requires enhanced Multi-Factor Authentication (MFA).

Conclusion

The Central Bank of Nigeria’s (CBN) new Guidelines on Instant Payment Functionalities for Financial Institutions mark a significant advancement in safeguarding digital transactions nationwide.

Effective 1 July 2026, financial institutions (FIs) must implement these measures. Among other requirements, the Guidelines necessitates comprehensive security and Data Protection Impact Assessments (DPIAs) to ensure compliance with the Nigeria Data Protection Act 2023 particularly resulting from mandatory features like multi-factor authentication (MFA), facial recognition, and continuous transaction monitoring.

About us:

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organization. We provide quality and innovative legal and data protection  support across diverse industries, helping clients operate in compliance with applicable laws and regulations to drive sustainable business growth.

REGULATORY UPDATE: NDPC EXTENDS DATA AUDIT FILING DEADLINE

By Seun Timi-Koleolu and Omodele Fatodu

The Nigeria Data Protection Commission (“NDPC”) has announced an extension of the deadline for the filing of the 2025 Data Protection Compliance Audit Returns (“CAR”) from March 31 to May 30, 2026. Data Processors and Controllers of Major Importance (“DPCMIs”) are therefore encouraged to utilise this period to ensure that their data protection frameworks are aligned with regulatory expectations and to file their Compliance Audit Returns within the extended timeline.

DPCMIs should note that failure to file within the prescribed timeline will attract regulatory sanctions. In particular, late filing of the CAR is subject to a penalty of 50% of the applicable filing fee, in addition to the risk of further regulatory scrutiny or enforcement action by the NDPC.

  1.  Practical Steps During the Extension Period

To make effective use of the extended timeline, DPCMIs should consider the following:

  1. Data Mapping: Ensure that all personal data processing activities are clearly identified and documented, including the nature of data collected, purposes of processing, storage locations, and third-party disclosures.
  2. Policy Review: Review privacy policies and internal data protection procedures to confirm that they are up to date and aligned with regulatory requirements and actual data processing practices.
  3. Remediation of Prior Findings: Ensure that any identified gaps or recommendations from prior audits have been appropriately addressed and implemented.
  4. Engage a licensed Data Protection Compliance Organisation (DPCO): A licensed DPCO can conduct the data protection compliance audit and file the CAR on behalf of the organisation, helping to ensure that the audit meets NDPC expectations.
  1. Update on Filing Fees

DPCMIs are also reminded that the filing fees applicable to the CARs were revised under the General Application and        Implementation Directive, 2025 (“GAID”). The fees depend on the DPCMI category, as well as the number of data subjects processed by the organisation, as outlined below:

  1. Ultra-High Level DPCMI
    Tier A – 50,000 data subjects and above: N1,000,000
    Tier B – 25,000 – 49,999 data subjects: N750,000
    Tier C – below 25,000 data subjects: N500,000
  2. Extra-High Level DPCMI
    Tier A – 10,000 data subjects and above: N250,000
    Tier B – 2,500 – 9,999 data subjects: N200,000
    Tier C – below 2,500 data subjects: N100,000
  1. Further Guidance

For a more detailed overview of compliance obligations under Nigerian data protection laws, and the role of DPCOs, please refer to our previous publications:

Conclusion

The extension of the 2025 data audit filing deadline provides organisations with an extended opportunity to review their data protection practices and file their Compliance Audit Returns on time.

Pavestones is a full-service legal practice, licensed by the Nigeria Data Protection Commission as a DPCO. We provide support to organisations across diverse industries in conducting data protection compliance audits, preparing and filing Compliance Audit Returns, and ensuring alignment with the GAID and Nigeria Data Protection Act, 2023.