AML Compliance Software in Nigeria: A Buyer's Guide for Banks, Fintechs and DNFBPs (2026)

How to choose AML compliance software in Nigeria: NFIU goAML and RapidAML reporting, the 24-hour STR and ₦5m/₦10m CTR rules, provider types, evaluation criteria, cost drivers and red flags.

CS
Creodata Solutions Team
AML Compliance Software in Nigeria: A Buyer's Guide for Banks, Fintechs and DNFBPs (2026)

Short answer: Good anti-money laundering (AML) compliance software for a Nigerian reporting entity does five jobs well: it screens customers against sanctions and PEP data, including the Nigeria Sanctions List, rates customer risk, monitors transactions across every channel you run, turns alerts into documented cases fast enough to meet the 24-hour suspicious transaction report (STR) rule, and gets STRs and currency transaction reports to the Nigerian Financial Intelligence Unit (NFIU) through goAML. Choose on evidence from scripted demos on your own data, and compare three-year costs on the same basis.

This guide is for compliance officers, heads of risk and procurement teams at Nigerian banks, microfinance banks, payment service providers, mobile money operators, bureaux de change, insurers, capital-market operators, virtual asset service providers and designated non-financial businesses and professions (DNFBPs) that are replacing spreadsheets or an older system. The Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA) sets the duties, and the Central Bank of Nigeria (CBN) has also issued baseline standards for automated AML solutions, which makes the choice of system a supervisory matter for the institutions it regulates.

Creodata offers AML compliance software in Nigeria, so we say plainly where we fit near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal advice: confirm requirements against current law and guidance from the NFIU and your regulator.

What AML compliance software does

AML software turns your customer and transaction data into the decisions an AML programme has to make, and keeps the evidence of each one.

FunctionWhat it doesWhat matters in Nigeria
Customer due diligence and risk ratingScores each customer's money-laundering risk from factors such as geography, product, channel and PEP statusA model your compliance team can change, with every override approved and recorded
Sanctions and PEP screeningChecks names against sanctions lists, PEP data and adverse media, at onboarding and whenever lists changeThe Nigeria Sanctions List as well as UN lists, matching that copes with Nigerian names and spellings, and proof of which list version was used
Transaction monitoringRuns rules and models over transactions to raise alerts on suspicious patternsCoverage of cash, transfers, cards, mobile money and agents, and detection of transactions split to stay under the ₦5 million and ₦10 million lines
Case managementTurns alerts into owned cases with deadlines, evidence and approvalsA 24-hour clock on every suspicion, and the reason and action taken recorded for the STR
Regulatory reportingPrepares STRs and currency transaction reportsFiles the NFIU's goAML portal accepts, whether you use the web form or XML upload
Audit trailRecords every action and decisionAn append-only log that stands up when the CBN, SEC, NAICOM or SCUML examines it

The complete AML platform guide explains each function in depth.

Who needs AML software in Nigeria

The MLPPA 2022 places its duties on financial institutions and DNFBPs. The NFIU reads the Act's definition of financial institutions as including virtual asset service providers. The Act's list of DNFBPs is long: automotive dealers, hotels and other hospitality businesses, casinos, pools betting, clearing and settlement companies, consultants, dealers in jewellery and in precious metals and stones, real estate dealers, developers, agents and brokers, high-value dealers, legal practitioners and notaries, licensed accountants, mortgage brokers, supermarkets, tax consultants and trust and company service providers, among others.

Each reporting entity's regulator enforces the Act alongside its own AML/CFT regulations:

SectorRegulator and rules
Banks, microfinance banks and other financial institutionsCentral Bank of Nigeria, under its AML/CFT/CPF Regulations, 2022
Payment service providers, mobile money operators and bureaux de changeCentral Bank of Nigeria
Capital-market operatorsSecurities and Exchange Commission, under its AML/CFT/CPF Regulations, 2022
InsurersNational Insurance Commission (NAICOM), under its AML/CFT Regulations, 2022
DNFBPs, including casinos and pools bettingSpecial Control Unit Against Money Laundering (SCUML), a department of the EFCC, under the EFCC (SCUML) Regulations, 2023

Not every institution needs the same system. A large bank needs real-time monitoring across many channels, while a microfinance bank or a DNFBP usually needs dependable screening, risk rating and reporting first, at a cost that fits its size. Spreadsheets carry a very small reporting entity only until volumes grow or an examiner asks why a customer was rated low risk and the answer is in someone's memory.

The Nigerian requirements that shape the choice

Most vendor demos look alike until you test them against the rules you actually work under. Section numbers below are those of the MLPPA 2022.

  • Reporting through goAML and RapidAML. The NFIU receives STRs "primarily" through goAML at goaml.nfiu.gov.ng, as an online web report or by uploading XML built to its schema; it publishes the schema guide, the lookup tables and an XML validator. Its second portal, RapidAML, complements goAML: bureaux de change file STRs, currency transaction reports, nil reports and PEP reports there, SCUML-supervised DNFBPs file STRs, and other CBN-regulated entities file nil and PEP reports. Ask which portal each of your report types goes to, and test both.
  • STRs within 24 hours. A suspicious transaction must be reported to the NFIU immediately, and within 24 hours after the transaction the institution must draw up the report, act to prevent the laundering and report what it did (section 7). There is no minimum amount, and the duty applies whether or not the transaction was completed. With a clock that short, alert triage, investigation and MLRO approval have to fit inside a working day.
  • Currency transaction reports within seven days. Any single transaction, lodgment or transfer of funds above ₦5 million for an individual or ₦10 million for a body corporate must be reported in writing within seven days: by financial institutions to the NFIU, and by DNFBPs to SCUML (section 11). The threshold depends on the customer type, so the customer record has to say reliably whether a customer is a natural person or a company.
  • Cash limits and structuring. Cash payments above the same ₦5 million and ₦10 million amounts may only be made or accepted through a financial institution, and splitting transactions to avoid a reporting duty is prohibited (section 2). Monitoring should flag deposits split to stay under the lines.
  • Five-year records. Transaction records must be kept for at least five years after completion, and due-diligence records for at least five years after the business relationship ends (section 8).
  • PEPs. Foreign PEPs need senior-management approval, source-of-wealth and source-of-funds checks and enhanced ongoing monitoring; the same measures apply to domestic PEPs where the relationship is higher risk (section 4). RapidAML also collects PEP reports, so your PEP flags should be accurate enough to report from.
  • The Nigeria Sanctions List. The Nigeria Sanctions Committee (NIGSAC), set up under the Terrorism (Prevention and Prohibition) Act, 2022, implements UN targeted financial sanctions and publishes the Nigeria Sanctions List. Your screening has to cover it, with evidence of when each list update was loaded.
  • The CBN's baseline standards. If you are CBN-regulated, ask each vendor to map its product to the CBN's baseline standards for automated AML solutions, requirement by requirement, and check the mapping against the circular yourself.

Our Nigeria NFIU goAML reporting guide covers filing in more detail. If your group also operates in East Africa, see our buyer's guide to AML compliance software in Kenya; the rules there differ.

The types of AML software provider in Nigeria

A search for AML software or an automated AML solution in Nigeria returns very different kinds of supplier. Knowing which kind you are talking to tells you what to test.

Provider typeTypical strengthsWatch for
Global AML suitesDepth, large-bank references, mature analyticsCost, long implementations, and whether NFIU goAML reporting and Nigerian payment channels work out of the box or through partners
AML modules from core banking vendorsTight integration with the vendor's own core systemScreening and monitoring depth compared with specialist tools, and lock-in to one core platform
Local software houses and consultanciesLocal presence, regulatory knowledge, help with policies and returnsWhose software it is, who supports it, and whether it is a full system or a tracker for obligations and returns
Identity verification and KYC API providersFast digital onboarding and document checksOnboarding checks are not transaction monitoring, case management or NFIU reporting
Specialist AML vendors from other African marketsgoAML reporting built in, and experience of mobile money and agent channelsSupport arrangements in Nigeria, references of similar size, security assurance, and the roadmap behind each module
Spreadsheets and in-house buildsLow starting cost, full controlKey-person risk, no audit trail, and the cost of keeping pace with NFIU and CBN changes

The types can be combined, for example an identity verification API at onboarding and an AML system for everything after it, provided they share one record of the customer.

Evaluation criteria

Score every vendor against the same requirements, weighted before the first demo.

AreaWhat to test
Regulatory fitgoAML files the NFIU's portal accepts, by XML upload or web form; RapidAML reports where they apply; a 24-hour STR clock; ₦5 million and ₦10 million lines that follow the customer type; a mapping to the CBN baseline standards if you are CBN-regulated
Risk ratingCompliance can change the model without code; overrides need four eyes; ratings explain themselves
ScreeningMatching quality on your own sample of Nigerian names; the Nigeria Sanctions List and UN lists; list freshness you can prove; false-positive control
Transaction monitoringCash, transfer, card, mobile money and agent coverage; structuring below ₦5 million and ₦10 million; back-testing before rules go live
Case managementThe time suspicion arose on every case; MLRO approval inside 24 hours; tipping-off controls; an append-only audit trail
Data and integrationProven integration with your core banking, switching or wallet platform; visible handling of failed feeds
Deployment and dataWhere data is stored and processed; the same features in cloud and on-premises editions; security assurance
AI governanceExplanations for every score; a human makes the decision; model approval and rollback
CommercialsThree-year cost; currency of the quote; implementation plan; references; exit terms; regulatory updates included

How to run the evaluation

  1. Set priorities with compliance, risk, IT and procurement before meeting vendors.
  2. Long-list suppliers and drop those that fail your Must-have requirements.
  3. Issue an RFP with your questions and the evidence you expect. Our free AML vendor RFP checklist and scoring template was written for Kenya, but most requirements carry over once you swap in the NFIU, the MLPPA 2022 and your regulator.
  4. Run scripted demos on your own data: a domestic PEP at onboarding, a near-match against the Nigeria Sanctions List, cash lodgments by one company that each stay just under ₦10 million, and an alert taken to a filed STR with the 24-hour clock visible throughout.
  5. Call references of similar size and sector, and ask what went wrong.
  6. Score independently, then calibrate as a panel, and file the scoring sheet with the decision papers.

What AML software costs in Nigeria

Vendors price AML software in very different ways, so ask every shortlisted vendor to itemise the same lines over three years:

  • Licence: per module or tier, per customer or account, per transaction, or a flat enterprise fee.
  • List data: sanctions, PEP and adverse-media data is often a separate subscription.
  • Implementation: data mapping, core-system integration, rule configuration and training, plus travel if the vendor's team is based outside Nigeria.
  • Hosting: cloud subscription and consumption, or servers and operations on-premises.
  • Support, including whether changes to the NFIU's goAML schema and lookup tables are covered.
  • Currency: US dollars or naira, and who carries the exchange-rate risk.
  • Internal effort: your analysts' and IT team's time during and after implementation.

A lower licence fee can hide higher data, integration or change-request costs, so compare three-year totals, not first-year quotes.

Red flags

  • The vendor cannot show a goAML file the NFIU's portal accepts, or treats NFIU reporting as a future feature.
  • The STR workflow has no clock, or starts it at the end of the investigation rather than when suspicion arose.
  • The currency transaction rule uses one threshold for everyone instead of ₦5 million for individuals and ₦10 million for companies.
  • Screening leaves out the Nigeria Sanctions List, or is demonstrated only on the vendor's sample names.
  • An administrator can edit or delete audit entries.
  • Answers about where your data is stored are vague or change between meetings.
  • Must-have requirements are answered with roadmap dates.

Where Creodata fits

Creodata is a Nairobi software company, and our AML compliance software is a specialist vendor's answer to the criteria above. It covers sanctions, PEP and adverse-media screening with multi-script matching and a false-positive workflow; customer risk rating across country, industry, product, channel, behaviour and PEP or sanctions exposure, with four-eyes overrides; batch and streaming transaction monitoring with back-testing; case management with enhanced due diligence; and an append-only audit log. Reports move through a draft, review, approve and submit lifecycle, and our separate goAML reporting software for Nigeria generates and validates the file for the NFIU's portal, with a manual download if the portal is down.

The cloud edition runs on Microsoft Azure as an Azure Managed Application. Azure has no region in Nigeria, so if data must stay in the country or in your own data centre, choose the on-premises edition, which has the same features. Modules are licensed separately in Starter, Growth and Enterprise tiers, so a microfinance bank or DNFBP can start with screening, risk rating and case basics and a bank can run the full suite. Country differences are configuration, not code: see AML compliance software in Nigeria for how each Nigerian duty maps to a module and the AML product overview for every module, or book a demo and bring your own scenarios.

Frequently asked questions

What is the best AML software in Nigeria?

There is no single best system, only the best fit for your institution's size, channels and risks. Shortlist two or three vendors that meet your Must-have requirements, run the same scripted demos on your own data, and score them against one weighted checklist. If you are CBN-regulated, include the CBN's baseline standards for automated AML solutions in that checklist.

How much does AML software cost in Nigeria?

It varies because vendors price differently: by module or tier, by customer or account, by transaction volume, or as an enterprise licence, with list data, implementation and hosting often extra. Ask each shortlisted vendor to itemise licence, data, implementation, hosting and support costs over three years in the same currency, and compare the totals.

Does AML software file reports with the NFIU?

Reports reach the NFIU through its goAML portal, as a web form or by XML upload, and some report types go through its RapidAML portal. What matters is whether the software produces files the portal accepts and tracks each report to acknowledgement. Ask for a validated sample file, and ask how the vendor handles changes to the NFIU's schema and lookup tables. In Creodata's case, the AML software manages the report lifecycle and the separate Creodata goAML Reporting Platform generates and validates the file.

What are the STR and CTR deadlines in Nigeria?

Suspicious transactions are reported to the NFIU immediately, and within 24 hours after the transaction, whatever the amount (section 7 of the MLPPA 2022). Single transactions, lodgments or transfers above ₦5 million for an individual or ₦10 million for a company are reported within seven days, to the NFIU by financial institutions and to SCUML by DNFBPs (section 11).

Do microfinance banks, fintechs and DNFBPs in Nigeria need AML software?

Usually, once volumes grow. The core duties do not shrink with size: the 24-hour STR rule, the currency transaction lines and five-year record keeping apply to every reporting entity. Microfinance banks and payment firms answer to the CBN, and DNFBPs register with and are supervised by SCUML. A small DNFBP can work manually for a while, but proving it met the 24-hour clock is hard without a system that timestamps each step.

Should AML software be hosted in the cloud or on-premises in Nigeria?

Either can work: cloud is faster to start and easier to scale, while on-premises keeps data in your own data centre. Microsoft has no Azure region in Nigeria, so an Azure-hosted system stores data outside the country. Decide with your legal and risk teams whether that is acceptable, check what your regulator expects of outsourcing, and ask each vendor where data is stored and processed and whether both options have the same features.


See how Creodata's AML compliance software in Nigeria meets these criteria: book a demo and bring your own scenarios.

See AML Compliance Software in action.