FREESanctions, PEP & AML/CFT screening database. Search any name.
← All research
ComplianceBanks, fintechs & regulators5 min read

Compliance Became Infrastructure

Nigeria came off the FATF grey list, then the CBN spent 2026 turning effectiveness into mandatory, real-time rules.

In October 2025, Nigeria came off the FATF grey list. For two years we had been the country other institutions filed extra paperwork just to deal with. We cleared a 19-point action plan and came out rated compliant, or largely compliant, on 37 of the 40 FATF recommendations. In January 2026 the European Union followed and removed us from its high-risk list too.

Most people read that as the end of a hard chapter. I read it as the start of a much harder one.

Here is why. A grey-list exit is not a certificate you frame. FATF earns you out on effectiveness, and effectiveness has to keep being true every single day after the plenary. The countries that slide back are the ones that celebrated and slowed down. So the real question was never how we got off the list. It was what we would do to stay off it.

The Central Bank answered that question in 2026, and it answered it with a stack of rules that, read together, change what compliance even means in this market.

Look at the timeline.

On 10 March, the CBN issued its Baseline Standards for Automated AML Solutions. Every regulated institution, banks, fintechs, payment service providers, mobile money operators, was required to file an automated AML implementation roadmap by 10 June. Read the standard itself and it is not describing a policy. It is describing a system: automated KYC, KYB and AML/CFT, with enterprise case management, full audit trails, role-based workflows and maker-checker controls, and records retained for five years.

Two days later, on 12 March, came the Additional Functionalities for Instant Payment circular, effective 1 July, mandating fraud-prevention and identity-assurance controls on instant transfers. Around the same window, a new cybersecurity framework with a 10 June deadline, and a Cybersecurity Self-Assessment Tool for the regulator to grade your posture directly.

Then the quiet one that changes the most. The CBN now expects banks to bring fraud response times to under 30 minutes, with real-time detection, analysis and reporting of suspicious activity. Thirty minutes is not a service-level target. In a country that settles payments in seconds, a 30-minute response mandate is a real-time mandate wearing a polite face. You cannot meet it with a control that runs overnight or an analyst who clears a queue in the morning.

And to close the loop, fraud reporting by the CBN and NIBSS now goes to the National Assembly, quarterly, broken down by channel, by which institutions complied with their reporting duties, and by what enforcement followed. Fraud stopped being a private embarrassment a bank manages quietly. It became a matter of public, legislative record.

Put those next to the numbers and the picture sharpens. Over ₦1.07 quadrillion moved across Nigeria's instant-payment rails in 2024. Electronic-payment fraud fell 51% in 2025 to ₦25.85 billion, real progress driven mostly by BVN and NIN integration, and yet bank fraud and forgery losses in the first quarter of 2025 jumped 603% year on year. Volume is falling. Severity is rising. And the NDPC has started fining banks for data breaches, with one bank fined ₦555.8 million.

This is the shift I want people in our market to see clearly. Compliance in Nigeria used to be something you filed. A report, a return, a policy document, an attestation. You could be compliant on paper and blind in practice, and for a long time the two were allowed to drift apart.

That gap is now closing by regulation. When the rule is automated monitoring, real-time response, auditable case management and quarterly public reporting, you cannot file your way to it. You have to build it. Compliance became infrastructure. It moved from the legal department's filing cabinet into the payment path itself, and it now has to run on every transaction, in real time, or it is not compliance at all.

I find this genuinely good news, even though it is hard. It means the institutions that invested early in real, automated, behaviour-aware controls are about to look very different from the ones that treated compliance as a box to tick. And it means a Nigeria that wants to set the standard for African fintech is finally building the enforcement layer that a standard actually needs.

This is the problem we work on at Autogon. Omniguard is automated AML and screening with real-time transaction scoring, case management, maker-checker and audit trails, the shape the CBN's own standards now describe, so that meeting the rule and stopping the fraud are the same action instead of two. That is the whole idea. Allow what is normal for each customer, hold what is not, and produce clean evidence on demand.

Off the grey list is not the finish line. It is the standard we now have to keep, and keeping it is an engineering job. If that is your world, we are at autogon.ai.


Sources

Keep reading