AML Compliance Software in Nigeria: A Buyer's Guide for Banks, Fintechs and DNFBPs (2026)
How to choose AML compliance software in Nigeria: NFIU goAML and RapidAML reporting, the 24-hour STR and ₦5m/₦10m CTR rules, provider types, evaluation criteria, cost drivers and red flags.

Short answer: Good anti-money laundering (AML) compliance software for a Nigerian reporting entity does five jobs well: it screens customers against sanctions and PEP data, including the Nigeria Sanctions List, rates customer risk, monitors transactions across every channel you run, turns alerts into documented cases fast enough to meet the 24-hour suspicious transaction report (STR) rule, and gets STRs and currency transaction reports to the Nigerian Financial Intelligence Unit (NFIU) through goAML. Choose on evidence from scripted demos on your own data, and compare three-year costs on the same basis.
This guide is for compliance officers, heads of risk and procurement teams at Nigerian banks, microfinance banks, payment service providers, mobile money operators, bureaux de change, insurers, capital-market operators, virtual asset service providers and designated non-financial businesses and professions (DNFBPs) that are replacing spreadsheets or an older system. The Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA) sets the duties, and the Central Bank of Nigeria (CBN) has also issued baseline standards for automated AML solutions, which makes the choice of system a supervisory matter for the institutions it regulates.
Creodata offers AML compliance software in Nigeria, so we say plainly where we fit near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal advice: confirm requirements against current law and guidance from the NFIU and your regulator.
What AML compliance software does
AML software turns your customer and transaction data into the decisions an AML programme has to make, and keeps the evidence of each one.
| Function | What it does | What matters in Nigeria |
|---|---|---|
| Customer due diligence and risk rating | Scores each customer's money-laundering risk from factors such as geography, product, channel and PEP status | A model your compliance team can change, with every override approved and recorded |
| Sanctions and PEP screening | Checks names against sanctions lists, PEP data and adverse media, at onboarding and whenever lists change | The Nigeria Sanctions List as well as UN lists, matching that copes with Nigerian names and spellings, and proof of which list version was used |
| Transaction monitoring | Runs rules and models over transactions to raise alerts on suspicious patterns | Coverage of cash, transfers, cards, mobile money and agents, and detection of transactions split to stay under the ₦5 million and ₦10 million lines |
| Case management | Turns alerts into owned cases with deadlines, evidence and approvals | A 24-hour clock on every suspicion, and the reason and action taken recorded for the STR |
| Regulatory reporting | Prepares STRs and currency transaction reports | Files the NFIU's goAML portal accepts, whether you use the web form or XML upload |
| Audit trail | Records every action and decision | An append-only log that stands up when the CBN, SEC, NAICOM or SCUML examines it |
The complete AML platform guide explains each function in depth.
Who needs AML software in Nigeria
The MLPPA 2022 places its duties on financial institutions and DNFBPs. The NFIU reads the Act's definition of financial institutions as including virtual asset service providers. The Act's list of DNFBPs is long: automotive dealers, hotels and other hospitality businesses, casinos, pools betting, clearing and settlement companies, consultants, dealers in jewellery and in precious metals and stones, real estate dealers, developers, agents and brokers, high-value dealers, legal practitioners and notaries, licensed accountants, mortgage brokers, supermarkets, tax consultants and trust and company service providers, among others.
Each reporting entity's regulator enforces the Act alongside its own AML/CFT regulations:
| Sector | Regulator and rules |
|---|---|
| Banks, microfinance banks and other financial institutions | Central Bank of Nigeria, under its AML/CFT/CPF Regulations, 2022 |
| Payment service providers, mobile money operators and bureaux de change | Central Bank of Nigeria |
| Capital-market operators | Securities and Exchange Commission, under its AML/CFT/CPF Regulations, 2022 |
| Insurers | National Insurance Commission (NAICOM), under its AML/CFT Regulations, 2022 |
| DNFBPs, including casinos and pools betting | Special Control Unit Against Money Laundering (SCUML), a department of the EFCC, under the EFCC (SCUML) Regulations, 2023 |
Not every institution needs the same system. A large bank needs real-time monitoring across many channels, while a microfinance bank or a DNFBP usually needs dependable screening, risk rating and reporting first, at a cost that fits its size. Spreadsheets carry a very small reporting entity only until volumes grow or an examiner asks why a customer was rated low risk and the answer is in someone's memory.
The Nigerian requirements that shape the choice
Most vendor demos look alike until you test them against the rules you actually work under. Section numbers below are those of the MLPPA 2022.
- Reporting through goAML and RapidAML. The NFIU receives STRs "primarily" through goAML at goaml.nfiu.gov.ng, as an online web report or by uploading XML built to its schema; it publishes the schema guide, the lookup tables and an XML validator. Its second portal, RapidAML, complements goAML: bureaux de change file STRs, currency transaction reports, nil reports and PEP reports there, SCUML-supervised DNFBPs file STRs, and other CBN-regulated entities file nil and PEP reports. Ask which portal each of your report types goes to, and test both.
- STRs within 24 hours. A suspicious transaction must be reported to the NFIU immediately, and within 24 hours after the transaction the institution must draw up the report, act to prevent the laundering and report what it did (section 7). There is no minimum amount, and the duty applies whether or not the transaction was completed. With a clock that short, alert triage, investigation and MLRO approval have to fit inside a working day.
- Currency transaction reports within seven days. Any single transaction, lodgment or transfer of funds above ₦5 million for an individual or ₦10 million for a body corporate must be reported in writing within seven days: by financial institutions to the NFIU, and by DNFBPs to SCUML (section 11). The threshold depends on the customer type, so the customer record has to say reliably whether a customer is a natural person or a company.
- Cash limits and structuring. Cash payments above the same ₦5 million and ₦10 million amounts may only be made or accepted through a financial institution, and splitting transactions to avoid a reporting duty is prohibited (section 2). Monitoring should flag deposits split to stay under the lines.
- Five-year records. Transaction records must be kept for at least five years after completion, and due-diligence records for at least five years after the business relationship ends (section 8).
- PEPs. Foreign PEPs need senior-management approval, source-of-wealth and source-of-funds checks and enhanced ongoing monitoring; the same measures apply to domestic PEPs where the relationship is higher risk (section 4). RapidAML also collects PEP reports, so your PEP flags should be accurate enough to report from.
- The Nigeria Sanctions List. The Nigeria Sanctions Committee (NIGSAC), set up under the Terrorism (Prevention and Prohibition) Act, 2022, implements UN targeted financial sanctions and publishes the Nigeria Sanctions List. Your screening has to cover it, with evidence of when each list update was loaded.
- The CBN's baseline standards. If you are CBN-regulated, ask each vendor to map its product to the CBN's baseline standards for automated AML solutions, requirement by requirement, and check the mapping against the circular yourself.
Our Nigeria NFIU goAML reporting guide covers filing in more detail. If your group also operates in East Africa, see our buyer's guide to AML compliance software in Kenya; the rules there differ.
The types of AML software provider in Nigeria
A search for AML software or an automated AML solution in Nigeria returns very different kinds of supplier. Knowing which kind you are talking to tells you what to test.
| Provider type | Typical strengths | Watch for |
|---|---|---|
| Global AML suites | Depth, large-bank references, mature analytics | Cost, long implementations, and whether NFIU goAML reporting and Nigerian payment channels work out of the box or through partners |
| AML modules from core banking vendors | Tight integration with the vendor's own core system | Screening and monitoring depth compared with specialist tools, and lock-in to one core platform |
| Local software houses and consultancies | Local presence, regulatory knowledge, help with policies and returns | Whose software it is, who supports it, and whether it is a full system or a tracker for obligations and returns |
| Identity verification and KYC API providers | Fast digital onboarding and document checks | Onboarding checks are not transaction monitoring, case management or NFIU reporting |
| Specialist AML vendors from other African markets | goAML reporting built in, and experience of mobile money and agent channels | Support arrangements in Nigeria, references of similar size, security assurance, and the roadmap behind each module |
| Spreadsheets and in-house builds | Low starting cost, full control | Key-person risk, no audit trail, and the cost of keeping pace with NFIU and CBN changes |
The types can be combined, for example an identity verification API at onboarding and an AML system for everything after it, provided they share one record of the customer.
Evaluation criteria
Score every vendor against the same requirements, weighted before the first demo.
| Area | What to test |
|---|---|
| Regulatory fit | goAML files the NFIU's portal accepts, by XML upload or web form; RapidAML reports where they apply; a 24-hour STR clock; ₦5 million and ₦10 million lines that follow the customer type; a mapping to the CBN baseline standards if you are CBN-regulated |
| Risk rating | Compliance can change the model without code; overrides need four eyes; ratings explain themselves |
| Screening | Matching quality on your own sample of Nigerian names; the Nigeria Sanctions List and UN lists; list freshness you can prove; false-positive control |
| Transaction monitoring | Cash, transfer, card, mobile money and agent coverage; structuring below ₦5 million and ₦10 million; back-testing before rules go live |
| Case management | The time suspicion arose on every case; MLRO approval inside 24 hours; tipping-off controls; an append-only audit trail |
| Data and integration | Proven integration with your core banking, switching or wallet platform; visible handling of failed feeds |
| Deployment and data | Where data is stored and processed; the same features in cloud and on-premises editions; security assurance |
| AI governance | Explanations for every score; a human makes the decision; model approval and rollback |
| Commercials | Three-year cost; currency of the quote; implementation plan; references; exit terms; regulatory updates included |
How to run the evaluation
- Set priorities with compliance, risk, IT and procurement before meeting vendors.
- Long-list suppliers and drop those that fail your Must-have requirements.
- Issue an RFP with your questions and the evidence you expect. Our free AML vendor RFP checklist and scoring template was written for Kenya, but most requirements carry over once you swap in the NFIU, the MLPPA 2022 and your regulator.
- Run scripted demos on your own data: a domestic PEP at onboarding, a near-match against the Nigeria Sanctions List, cash lodgments by one company that each stay just under ₦10 million, and an alert taken to a filed STR with the 24-hour clock visible throughout.
- Call references of similar size and sector, and ask what went wrong.
- Score independently, then calibrate as a panel, and file the scoring sheet with the decision papers.
What AML software costs in Nigeria
Vendors price AML software in very different ways, so ask every shortlisted vendor to itemise the same lines over three years:
- Licence: per module or tier, per customer or account, per transaction, or a flat enterprise fee.
- List data: sanctions, PEP and adverse-media data is often a separate subscription.
- Implementation: data mapping, core-system integration, rule configuration and training, plus travel if the vendor's team is based outside Nigeria.
- Hosting: cloud subscription and consumption, or servers and operations on-premises.
- Support, including whether changes to the NFIU's goAML schema and lookup tables are covered.
- Currency: US dollars or naira, and who carries the exchange-rate risk.
- Internal effort: your analysts' and IT team's time during and after implementation.
A lower licence fee can hide higher data, integration or change-request costs, so compare three-year totals, not first-year quotes.
Red flags
- The vendor cannot show a goAML file the NFIU's portal accepts, or treats NFIU reporting as a future feature.
- The STR workflow has no clock, or starts it at the end of the investigation rather than when suspicion arose.
- The currency transaction rule uses one threshold for everyone instead of ₦5 million for individuals and ₦10 million for companies.
- Screening leaves out the Nigeria Sanctions List, or is demonstrated only on the vendor's sample names.
- An administrator can edit or delete audit entries.
- Answers about where your data is stored are vague or change between meetings.
- Must-have requirements are answered with roadmap dates.
Where Creodata fits
Creodata is a Nairobi software company, and our AML compliance software is a specialist vendor's answer to the criteria above. It covers sanctions, PEP and adverse-media screening with multi-script matching and a false-positive workflow; customer risk rating across country, industry, product, channel, behaviour and PEP or sanctions exposure, with four-eyes overrides; batch and streaming transaction monitoring with back-testing; case management with enhanced due diligence; and an append-only audit log. Reports move through a draft, review, approve and submit lifecycle, and our separate goAML reporting software for Nigeria generates and validates the file for the NFIU's portal, with a manual download if the portal is down.
The cloud edition runs on Microsoft Azure as an Azure Managed Application. Azure has no region in Nigeria, so if data must stay in the country or in your own data centre, choose the on-premises edition, which has the same features. Modules are licensed separately in Starter, Growth and Enterprise tiers, so a microfinance bank or DNFBP can start with screening, risk rating and case basics and a bank can run the full suite. Country differences are configuration, not code: see AML compliance software in Nigeria for how each Nigerian duty maps to a module and the AML product overview for every module, or book a demo and bring your own scenarios.
Frequently asked questions
What is the best AML software in Nigeria?
There is no single best system, only the best fit for your institution's size, channels and risks. Shortlist two or three vendors that meet your Must-have requirements, run the same scripted demos on your own data, and score them against one weighted checklist. If you are CBN-regulated, include the CBN's baseline standards for automated AML solutions in that checklist.
How much does AML software cost in Nigeria?
It varies because vendors price differently: by module or tier, by customer or account, by transaction volume, or as an enterprise licence, with list data, implementation and hosting often extra. Ask each shortlisted vendor to itemise licence, data, implementation, hosting and support costs over three years in the same currency, and compare the totals.
Does AML software file reports with the NFIU?
Reports reach the NFIU through its goAML portal, as a web form or by XML upload, and some report types go through its RapidAML portal. What matters is whether the software produces files the portal accepts and tracks each report to acknowledgement. Ask for a validated sample file, and ask how the vendor handles changes to the NFIU's schema and lookup tables. In Creodata's case, the AML software manages the report lifecycle and the separate Creodata goAML Reporting Platform generates and validates the file.
What are the STR and CTR deadlines in Nigeria?
Suspicious transactions are reported to the NFIU immediately, and within 24 hours after the transaction, whatever the amount (section 7 of the MLPPA 2022). Single transactions, lodgments or transfers above ₦5 million for an individual or ₦10 million for a company are reported within seven days, to the NFIU by financial institutions and to SCUML by DNFBPs (section 11).
Do microfinance banks, fintechs and DNFBPs in Nigeria need AML software?
Usually, once volumes grow. The core duties do not shrink with size: the 24-hour STR rule, the currency transaction lines and five-year record keeping apply to every reporting entity. Microfinance banks and payment firms answer to the CBN, and DNFBPs register with and are supervised by SCUML. A small DNFBP can work manually for a while, but proving it met the 24-hour clock is hard without a system that timestamps each step.
Should AML software be hosted in the cloud or on-premises in Nigeria?
Either can work: cloud is faster to start and easier to scale, while on-premises keeps data in your own data centre. Microsoft has no Azure region in Nigeria, so an Azure-hosted system stores data outside the country. Decide with your legal and risk teams whether that is acceptable, check what your regulator expects of outsourcing, and ask each vendor where data is stored and processed and whether both options have the same features.
See how Creodata's AML compliance software in Nigeria meets these criteria: book a demo and bring your own scenarios.


