AML compliance software · Nigeria

AML compliance software for Nigeria's reporting institutions.

Sanctions and PEP screening, transaction monitoring, customer risk rating, case management and reporting to the Nigerian Financial Intelligence Unit through goAML, in one analyst workspace for financial institutions and DNFBPs under Nigeria's Money Laundering (Prevention and Prohibition) Act, 2022.

Nigeria regulatory fit

Built for the MLPPA 2022 and the Nigerian Financial Intelligence Unit.

Nigeria's Money Laundering (Prevention and Prohibition) Act, 2022 (MLPPA), the AML/CFT regulations of the CBN, SEC and NAICOM, and the NFIU's guidelines set out what a reporting entity has to do. Each duty maps to a module, so the evidence sits where an examiner will look for it.

Identify customers and rate their risk

Six-factor customer risk rating across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides, plus a beneficial-owner graph for legal-entity customers.

Customer risk ratingEntity resolution

Apply enhanced due diligence to PEPs and higher-risk customers

An EDD workflow inside case management, with periodic reviews scheduled automatically by risk band so a high-risk file does not go stale.

Case management & EDDCustomer risk rating

Screen customers against sanctions lists and PEP data

Multi-script, locale-aware matching against lists synced from providers such as Dow Jones and World-Check, plus manual upload for lists you maintain yourself, with versioned lists and freshness dashboards.

ScreeningWatchlist management

Monitor transactions for suspicious activity

A rule engine running in batch and streaming, with typology-aligned starter rules, back-testing and versioned promotion, fed by REST, SFTP, Kafka, CDC or ISO 20022 connectors.

Transaction monitoringData ingestion

Report suspicious and cash transactions to the NFIU

A draft, review, approve and submit lifecycle with acknowledgement handling. The goAML XML is generated and validated by the Creodata goAML Reporting Platform, with a manual download if the portal is down.

SAR / STR reportinggoAML Reporting Platform

Keep records and show supervisors the evidence

An append-only audit log behind every decision, evidence packs for inspections, a read-only regulator portal, and an obligation registry that turns new guidance and amendments into tracked tasks.

Regulator portalRegulatory intelligence

This maps software capability to obligations; it is not legal advice. For registration and filing mechanics, see the Nigeria NFIU goAML reporting guide.

Who it's for

For Nigeria's reporting institutions, whichever regulator supervises them.

Each reporting entity's regulator enforces the 2022 Act and its own AML/CFT regulations: the Central Bank of Nigeria, the Securities and Exchange Commission and NAICOM for financial institutions, and SCUML for designated non-financial businesses and professions.

Banks, microfinance banks and other financial institutions

Supervised by the Central Bank of Nigeria under its AML/CFT/CPF Regulations, 2022.

Payment service providers, mobile money operators and bureaux de change

Regulated by the Central Bank of Nigeria. Bureaux de change file suspicious and currency transaction reports through the NFIU's RapidAML portal.

Insurers and capital-market operators

NAICOM and the Securities and Exchange Commission, under their AML/CFT regulations of 2022.

Betting, real estate, dealers and other DNFBPs

Pools betting firms and casinos, real estate firms, dealers in jewellery, cars and precious metals, lawyers, accountants and the other designated businesses register with SCUML, a department of the EFCC, which supervises them.

FAQ

Frequently asked questions.

Does the software report to the NFIU?

Yes, through goAML. Suspicious and threshold transaction reports move through a draft, review, approve and submit lifecycle in the AML software, with retry, reconciliation and acknowledgement handling. The Creodata goAML Reporting Platform then generates and validates the goAML file for the NFIU's portal, and a manual download is available if the portal is down.

How quickly must a Nigerian reporting entity file a suspicious transaction report?

Immediately, and within 24 hours after the transaction, under section 7 of the Money Laundering (Prevention and Prohibition) Act, 2022, whatever the amount and whether or not the transaction was completed. The NFIU expects STRs to be filed primarily on its goAML portal, either through the online form or by uploading XML built to its schema.

What are Nigeria's currency transaction report thresholds?

Financial institutions report to the NFIU, and DNFBPs to SCUML, any single transaction, lodgment or transfer of funds above ₦5 million for an individual or ₦10 million for a body corporate, in writing within seven days (section 11 of the 2022 Act). Cash payments above those amounts may only be made through a financial institution (section 2).

Can we run the software on-premises in Nigeria?

Yes. The on-premises edition runs on your own Kubernetes cluster with Postgres 16, RabbitMQ, MinIO, OpenSearch and Keycloak, and has the same features as the Microsoft Azure edition, so an institution that must keep data in its own data centre is not running a lesser product.

How much does AML software cost in Nigeria?

There is no public price list. Each capability is licensed separately and grouped into Starter, Growth and Enterprise tiers, so a quote depends on the modules you switch on and whether you deploy on Azure or on-premises. A demo is the quickest route to a quote scoped to your institution.

Can a smaller institution start small?

Yes. The Starter tier covers screening, customer risk rating and case basics in the cloud. Growth adds transaction monitoring, STR/CTR reporting and ingestion connectors, which a deposit-taking institution will need for its monitoring and reporting duties. Modules switch on per tenant, so moving up a tier adds capability without starting again.

How long does implementation take?

It depends on how many modules you start with and how your data arrives. Screening and risk rating need customer data; transaction monitoring also needs transaction feeds, which connect over REST, SFTP, Kafka, change data capture or ISO 20022 with replay and a dead-letter queue, so a failed load is visible rather than silent. After scoping, we propose a phased path to your first production go-live.

See the AML software run on a Nigeria reporting profile.

Screening, monitoring, cases and NFIU reporting on a realistic alert queue, in a live demo.