AML Compliance for Microfinance Banks and Payment Service Providers in Nigeria (2026)

What Nigerian microfinance banks, payment service providers and mobile money operators must do on AML under the MLPPA 2022: customer due diligence and PEPs, 24-hour STRs, ₦5m/₦10m currency transaction reports, US$10,000 foreign transfers, NFIU and RapidAML filing, records and agent-channel risk.

CS
Creodata Solutions Team
AML Compliance for Microfinance Banks and Payment Service Providers in Nigeria (2026)

Short answer: Microfinance banks, payment service providers and mobile money operators in Nigeria are regulated by the Central Bank of Nigeria (CBN) and carry the duties of the Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA): customer due diligence with enhanced checks for politically exposed persons, suspicious transaction reports to the Nigerian Financial Intelligence Unit (NFIU) within 24 hours, currency transaction reports above ₦5 million or ₦10 million within seven days, reports of foreign transfers above US$10,000 within one day, five-year records and a compliance programme with compliance officers at every branch. They file on the NFIU's goAML portal, and nil and PEP reports on RapidAML. High volumes of small, fast transactions through agents and wallets make automated monitoring the practical way to meet those clocks.

This guide is for compliance officers, money laundering reporting officers and operations teams at Nigerian microfinance banks, payment service providers, mobile money operators and other CBN-regulated financial institutions. It is a practical guide, not legal advice: the MLPPA, the CBN (AML/CFT/CPF) Regulations, 2022 and the NFIU's guidance are the authoritative texts.


The rules that apply

InstrumentWhat it covers
Money Laundering (Prevention and Prohibition) Act, 2022The core duties for financial institutions: due diligence, reporting, records, compliance programme
CBN (AML/CFT/CPF) Regulations, 2022The CBN's sector regulations for the institutions it supervises
NFIU guidance on STRs (2023) and STR guidelines for financial institutions (2024)How to write, document and file suspicious transaction reports
The Nigeria Sanctions ListTargeted financial sanctions, published by the Nigeria Sanctions Committee

The CBN has also issued baseline standards for automated AML solutions. If you are CBN-regulated, map any system you use or buy to those standards, requirement by requirement.


The duties

  • Customer due diligence. Identify and verify customers and beneficial owners from reliable, independent sources; apply due diligence when a relationship starts, for occasional transactions above the regulations' threshold (including linked ones), for occasional wire transfers, on suspicion whatever the amount, and when earlier data is doubtful; keep it current; and apply enhanced measures where risk is higher (section 4). A casual customer's transactions above US$1,000 trigger due diligence.
  • Politically exposed persons. Senior-management approval, source of wealth and funds, and closer monitoring for foreign PEPs, and for domestic PEPs where the relationship is higher risk (section 4(8)–(9)).
  • Suspicious transactions within 24 hours. Report to the NFIU immediately and, within 24 hours after the transaction, draw up a written report, act to prevent the laundering and report the action taken, whether or not the transaction was completed (section 7). The NFIU's 2024 guidelines say the 24 hours run once the transaction has been examined and found suspicious, which should take no more than 72 hours. See our NFIU STR guide.
  • Currency transaction reports. Any single transaction, lodgment or transfer of funds above ₦5,000,000 for an individual or ₦10,000,000 for a company goes to the NFIU in writing within seven days (section 11). See our currency transaction report guide.
  • Foreign transfers. Transfers to or from a foreign country above US$10,000 or its equivalent, including by money service businesses, go to the NFIU, the CBN and the Securities and Exchange Commission in writing within one day (section 3).
  • Records. Keep transaction records for at least five years, and due-diligence records for at least five years after the relationship ends (section 8).
  • Compliance programme. Designate compliance officers at management level at head office and every branch and local office, train staff regularly, centralise information and run an internal audit unit (section 10). The CBN may impose penalties for failure (at least ₦1,000,000 for financial institutions other than banks, ₦5,000,000 for a bank) and suspend a licence.
  • No anonymous accounts. Anonymous and numbered accounts are prohibited (section 12), and new products, channels and technologies must be risk-assessed before launch (section 13).

Filing with the NFIU

ReportWhere
Suspicious and currency transaction reportsThe NFIU's goAML portal, by web form or XML upload
Nil reports and PEP reportsThe NFIU's RapidAML portal, for CBN-regulated entities other than bureaux de change
STRs when goAML is downofi@nfiu.gov.ng for other financial institutions, only with the NFIU's prior permission, then re-sent on goAML

Register first: see our NFIU goAML registration guide.


Where the risk sits in microfinance and payments

The duties are the same as for commercial banks, but the patterns differ. Microfinance banks and payment providers typically handle many small transactions, often through agents and wallets, for customers onboarded quickly. That shifts the monitoring questions:

  • Structuring. Deposits and transfers kept just under ₦5 million or ₦10 million, or spread across agents and accounts, which the MLPPA prohibits (section 2(2)).
  • Velocity and fan-out. One account receiving from many and paying out to many, the one-to-many pattern the NFIU's STR guidance illustrates.
  • Agent activity. Unusual volumes at particular agents or locations, and cash-in followed quickly by cash-out.
  • Identity. Accounts that share identifiers, devices or contact details, and customers whose activity outgrows the level of due diligence done at onboarding.
  • Cross-border flows. Transfers approaching US$10,000, and inflows from high-risk jurisdictions.

The NFIU's 2024 guidelines ask institutions to keep a written reason for every alert they close as not suspicious, and to review their monitoring rules, parameters and thresholds periodically and after events such as product launches or core-system upgrades.


Compliance checklist

  1. Apply risk-based due diligence at onboarding and step it up as activity grows.
  2. Screen customers against the Nigeria Sanctions List and UN lists, and flag PEPs.
  3. Monitor for structuring, velocity, fan-out and agent anomalies.
  4. Examine alerts within 72 hours and file STRs within 24 hours of finding a transaction suspicious.
  5. File currency transaction reports within seven days and foreign-transfer reports within one day.
  6. Keep compliance officers at head office and every branch, and train staff.
  7. Map your AML system to the CBN's baseline standards for automated AML solutions.

Frequently asked questions

Do microfinance banks in Nigeria have to report suspicious transactions?

Yes. As financial institutions under the MLPPA 2022, microfinance banks report suspicious transactions to the NFIU immediately and within 24 hours after the transaction, whatever the amount (section 7).

Which portal do payment service providers use to report to the NFIU?

Suspicious and currency transaction reports go to the NFIU's goAML portal. CBN-regulated entities other than bureaux de change file nil and PEP reports on the NFIU's RapidAML portal.

Are there currency transaction reporting thresholds for microfinance banks?

Yes, the same as for other financial institutions: any single transaction, lodgment or transfer above ₦5,000,000 for an individual or ₦10,000,000 for a company, reported within seven days (section 11 of the MLPPA 2022).

Who supervises microfinance banks and payment providers for AML?

The Central Bank of Nigeria, under the MLPPA 2022 and its AML/CFT/CPF Regulations, 2022. The CBN may impose penalties and suspend licences for failures of the compliance programme (section 10).


See how Creodata's AML compliance software in Nigeria handles monitoring and reporting for microfinance banks and payment providers: book a demo.

See AML Compliance Software in action.