AML Compliance for Insurers in Nigeria: NAICOM, the MLPPA 2022 and the 2025 Insurance Reform Act (2026)

What Nigerian insurance institutions must do on AML: MLPPA 2022 duties, section 202 of the Nigerian Insurance Industry Reform Act 2025, NAICOM supervision, customer and beneficiary checks, STRs within 24 hours, currency transaction reports, NFIU filing and records.

CS
Creodata Solutions Team
AML Compliance for Insurers in Nigeria: NAICOM, the MLPPA 2022 and the 2025 Insurance Reform Act (2026)

Short answer: Insurance institutions are financial institutions under the Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA), so they carry its full set of duties: customer due diligence with enhanced checks for politically exposed persons, suspicious transaction reports to the Nigerian Financial Intelligence Unit (NFIU) within 24 hours, currency transaction reports above ₦5 million or ₦10 million within seven days, five-year records and a compliance programme. The National Insurance Commission (NAICOM) supervises them. Section 202 of the Nigerian Insurance Industry Reform Act, 2025 requires every insurance institution to adopt a written AML, CFT and CPF commitment and gives NAICOM power to make rules and impose sanctions. NAICOM's prudential guidelines also bar insurers from outsourcing AML/CFT compliance.

This guide is for chief compliance officers, money laundering reporting officers and claims and underwriting leaders at Nigerian insurers, reinsurers and other insurance institutions. It is a practical guide, not legal advice: the Act, the NAICOM (AML/CFT) Regulations, 2022 and NAICOM's directives are the authoritative texts.


The rules that apply

InstrumentWhat it does for insurers
Money Laundering (Prevention and Prohibition) Act, 2022Defines "financial institution" to include an insurance institution, and sets the core duties below
Nigerian Insurance Industry Reform Act, 2025, section 202Written commitment to KYC, AML, CFT and CPF compliance; internal controls against proliferation financing; NAICOM rule-making and administrative sanctions
NAICOM (AML/CFT) Regulations, 2022NAICOM's sector regulations under the MLPPA
NAICOM Prudential Guidelines for Insurance Institutions (October 2022)List "Compliance with AML/CFT Requirements" among the core activities an insurer may not outsource
NFIU guidance (2023 and 2024)How to prepare, document and file STRs

The Reform Act (Act No. 14 of 2025) came into force on 31 July 2025. Section 202(1) requires all insurance institutions to adopt policies stating their commitment to comply with KYC, AML, CFT and CPF obligations under existing laws, regulations and directives, and to implement internal controls to prevent any transaction relating to proliferation financing. NAICOM makes the regulations, guidelines and policies for the sector (section 202(2)), cooperates with foreign counterparts (section 202(3)) and may impose administrative sanctions for non-compliance (section 202(4)).


The core duties, applied to insurance

  • Customer due diligence. Identify and verify policyholders and beneficial owners at the start of the relationship, for occasional transactions above the regulations' threshold, on suspicion and when earlier data is doubtful, and keep due diligence current (section 4 of the MLPPA). Apply enhanced measures where risk is higher.
  • Politically exposed persons. For foreign PEPs, obtain senior-management approval, establish the source of wealth and funds, and monitor more closely; do the same for domestic PEPs where the relationship is higher risk (section 4(8)–(9)).
  • Suspicious transactions. Report to the NFIU immediately and, within 24 hours after the transaction, draw up a written report, act to prevent the laundering and report the action taken (section 7). The NFIU's 2023 guidance lists early policy termination among the types of suspicious activity an STR narrative might open with, and termination of an insurance policy among the follow-up actions it might record. See our NFIU STR guide.
  • Currency transaction reports. Report any single transaction, lodgment or transfer of funds above ₦5,000,000 for an individual or ₦10,000,000 for a body corporate to the NFIU in writing within seven days (section 11). See our currency transaction report guide.
  • Records. Keep transaction records for at least five years after the transaction, and due-diligence records, including policy files, for at least five years after the relationship ends (section 8).
  • Programme. Designate compliance officers at management level, train staff regularly, centralise information and run an internal audit unit (section 10). NAICOM may penalise a failure and suspend a licence.

Filing with the NFIU

Insurers file suspicious and currency transaction reports on the NFIU's goAML portal, as web forms or XML uploads, after registering (see our NFIU goAML registration guide). NAICOM-regulated entities file nil reports on the NFIU's RapidAML portal. If goAML fails, the NFIU accepts STRs from capital market and insurance companies at cmi@nfiu.gov.ng, but only with its prior permission, and the report must be re-sent on goAML once the system is restored. The NFIU's guidance asks for the policy opening package among the documents attached to an STR.


Where insurance risk shows up

The duties are the same as for banks, but the signals differ. Insurers commonly watch for:

  • policies surrendered or cancelled early, especially soon after a large single premium;
  • premiums paid by third parties, or refunds requested to a different account;
  • beneficiaries changed shortly before a claim or a payout;
  • overpayments followed by refund requests;
  • policyholders or beneficiaries who are PEPs or appear on sanctions lists.

Each of these calls for a documented review, and a suspicious transaction report within 24 hours once the review finds the transaction suspicious.


Compliance checklist for insurers

  1. Adopt the section 202 AML, CFT and CPF policy commitment, approved by the board.
  2. Keep AML/CFT compliance in-house, as NAICOM's prudential guidelines require.
  3. Identify policyholders, beneficial owners and beneficiaries, and flag PEPs.
  4. Monitor surrenders, third-party premiums, refunds and beneficiary changes.
  5. Report suspicious transactions within 24 hours, and currency transactions above ₦5 million or ₦10 million within seven days.
  6. File on goAML, and nil reports on RapidAML.
  7. Keep policy and transaction records for at least five years.

Frequently asked questions

Do the MLPPA 2022 duties apply to insurers?

Yes. The Act defines "financial institution" to include an insurance institution, so insurers carry its customer due diligence, reporting, record-keeping and compliance programme duties.

What does section 202 of the Nigerian Insurance Industry Reform Act, 2025 require?

Every insurance institution must adopt policies committing it to comply with KYC, AML, CFT and CPF obligations and implement internal controls against proliferation financing. NAICOM makes the sector's AML rules and may impose administrative sanctions for non-compliance.

Can an insurer outsource AML compliance in Nigeria?

No. NAICOM's Prudential Guidelines list compliance with AML/CFT requirements among the core activities an insurer may not outsource. Software can support the function, but the function stays with the insurer.

How do Nigerian insurers file STRs?

On the NFIU's goAML portal, by web form or XML upload, within 24 hours after the transaction. In a system failure, and only with the NFIU's permission, insurers can e-mail cmi@nfiu.gov.ng and must re-send the report on goAML afterwards.


See how Creodata's AML compliance software in Nigeria supports an insurer's AML programme: book a demo.

See AML Compliance Software in action.