Every CBN-licensed fintech in Nigeria (payment service providers, microfinance banks, PSSPs, and switching companies) must run a documented AML/CFT program under the CBN AML/CFT Regulations and the Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA). The program is not optional, and it is not a policy PDF you buy once. It is a set of controls you operate every day, and examiners check evidence, not intentions.

This post is the working checklist. It groups the AML requirements for fintechs in Nigeria into seven areas, maps each area to the instrument that requires it, and ends with what examiners ask for first and a 30-day implementation order for a team starting from zero. Use it to prepare for CBN supervision, a licensing application, or an internal gap review.

The checklist at a glance

AreaWhat is requiredInstrument / deadline
1. Governance Appointed compliance officer, board-approved AML/CFT policy, board oversight, annual review CBN AML/CFT Regulations; MLPPA 2022
2. Customer due diligence Tiered KYC, BVN/NIN verification, beneficial ownership for corporates, EDD for PEPs and high-risk customers CBN tiered KYC framework; MLPPA 2022
3. Monitoring and screening Risk-based monitoring rules, sanctions and PEP screening at onboarding and ongoing, local watchlists CBN AML/CFT Regulations
4. Regulatory reporting STR to NFIU via goAML; CTR above thresholds; goAML entity registration before first filing MLPPA 2022; NFIU directives. STR: 24 hours. CTR: 7 days
5. Record keeping Five-year retention floor, retrievability for examiners, NDPA-aligned storage MLPPA 2022; NDPA
6. Training and testing Staff training on a set cadence, independent audit of the AML program CBN AML/CFT Regulations
7. Technology and audit trail Monitoring with explainable verdicts, immutable audit trail, retroactive screening capability CBN AML/CFT Regulations; CBN AI/ML governance expectations

1. Governance and the compliance function

The first thing a supervisor looks for is who owns AML. The CBN AML/CFT Regulations require a designated compliance officer with enough seniority to act, and a written AML/CFT policy the board has actually approved. A policy that exists but was never minuted at board level is a finding, not a control.

  • Appoint a compliance officer and document the appointment, reporting line, and authority to escalate and to file reports without approval from business owners.
  • Draft a written AML/CFT policy covering CDD, monitoring, screening, reporting, record keeping, and training, and get it approved by the board.
  • Put AML on the board or board-committee agenda on a fixed cadence, and minute the discussion of program status and findings.
  • Review the policy at least annually, and re-approve it whenever products, channels, or the regulations change.

2. Customer due diligence (KYC/KYB)

Customer due diligence is where most fintech programs are weakest, because onboarding speed and verification depth pull in opposite directions. The CBN framework is tiered: limited accounts with limited documentation, full accounts with full verification. The obligation is to know which tier each customer sits in and to enforce the limits that come with it.

  • Map your onboarding flows to the CBN tiered KYC levels and enforce the transaction and balance limits of each tier in code, not in policy text.
  • Verify BVN and NIN against source for individual customers, and keep the verification evidence, not just the number.
  • For corporate customers, collect CAC records and identify the beneficial owners behind the entity, then verify those individuals.
  • Classify politically exposed persons and high-risk customers, and apply enhanced due diligence: senior approval, source-of-funds evidence, tighter monitoring.
  • Refresh customer records on a risk-based cycle, and treat a customer who resists routine update requests as a risk signal.

3. Transaction monitoring and screening

The regulations require monitoring that matches your risk profile. In practice that means rules that catch the patterns Nigerian regulators care about: structuring just below the CTR thresholds, rapid pass-through, and activity that does not fit the customer's declared profile. If you are new to the mechanics, our post on how AML transaction monitoring actually works covers the moving parts.

  • Write monitoring rules from your risk assessment, and document why each rule exists and what threshold it uses.
  • Screen every customer against sanctions lists and PEP databases at onboarding, before the account goes live.
  • Re-screen the full customer base when lists change, and keep evidence of when each re-screen ran.
  • Screen against local watchlists and internal blacklists, not only international lists.
  • Decide whether your monitoring runs in real time or in batch, and be honest about the gap. We break down what real-time actually means, versus batch, in a separate post.

Practical rule: if a mule account can receive funds and move them out before your monitoring runs, your monitoring is a reporting tool, not a control.

4. Regulatory reporting

Reporting is the area with hard deadlines, and it is where late programs get caught. All statutory reports go to the NFIU through goAML, and you cannot file your first report until your entity registration on the platform is validated. Our step-by-step guide to filing an STR with the NFIU covers registration, the narrative, and confidentiality.

  • Register your entity on goAML and designate the compliance officer as correspondent, well before you need to file.
  • File an STR within 24 hours of forming the suspicion. Timestamp when each alert reaches compliance so the clock is provable.
  • File a CTR for cash transactions above ₦5 million (individual) or ₦10 million (corporate) within 7 days.
  • File both reports when a transaction is both above the CTR threshold and suspicious. One does not substitute for the other.
  • Restrict knowledge of STRs to the compliance unit. Tipping off the customer is a criminal offence for the individual involved.

5. Record keeping

The MLPPA sets a five-year retention floor for customer identification records, transaction records, and report files. Retention alone is not enough: the records must be retrievable. An examiner who asks for the full file on one named customer expects it in minutes, not after a week of digging through the core banking export.

  • Keep CDD records, transaction histories, STR and CTR files, and internal investigation notes for at least five years after the relationship or transaction ends.
  • Index records so any customer, account, or date range can be pulled on demand, and test that retrieval before an examiner does.
  • Align storage with the NDPA: lawful basis for processing, access controls on customer data, and a documented retention schedule.

6. Training and independent testing

Staff who touch customers or transactions need to know what suspicion looks like and what to do with it. The program also needs independent testing: someone who did not build the controls checking that the controls work. Both are explicit expectations under the CBN AML/CFT Regulations.

  • Train all customer-facing, operations, and engineering staff at onboarding, and refresh at least annually.
  • Keep training logs with dates, attendees, and content covered. Examiners ask for the log, not the slide deck.
  • Commission an independent audit or review of the AML program on a fixed cycle, separate from the compliance function.
  • Track every audit finding to closure with an owner and a date, and report remediation status to the board.

7. Technology and audit trail

Every item above eventually reduces to evidence, and evidence lives in your systems. A monitoring stack that cannot explain why it flagged a transaction, or that lets someone edit the record after the fact, will not survive an examination. CBN expectations on AI and ML governance push in the same direction: decisions about customers must be explainable.

  • Use monitoring that produces explainable verdicts, decomposed rule by rule, so an examiner can read the reason for every alert and every pass.
  • Keep an immutable audit trail of every alert, investigation decision, and filing, with no path to silent edits.
  • Make sure you can screen your full transaction history retroactively. New rules are only useful if they can look backwards; we covered the mechanics in bulk import and retroactive screening.
  • Test failure modes: if a screening engine degrades or goes down, affected transactions must be queued and re-screened, and compliance must be alerted.

What examiners ask for first

Supervisory visits follow a pattern. Prepare these five items so they can be produced the same day:

  • The board-approved AML/CFT policy document, with the approval minutes.
  • The complete STR file for a named customer: alert, review notes, KYC snapshot, goAML acknowledgement.
  • Training logs for the last cycle, with attendees and dates.
  • Screening evidence for a chosen date range: which lists were in force, what was screened, what matched, what was done about it.
  • An audit trail extract showing that alerts and decisions cannot be altered after the fact.

The 30-day implementation order

For a fintech starting from zero, sequence matters. Do the unblockable registrations first and the technology build last:

  1. Days 1-7: Appoint the compliance officer, register the entity on goAML, and start the AML/CFT policy draft. Registration takes validation time, so it goes first.
  2. Days 8-14: Take the policy to the board for approval. Map your onboarding to the KYC tiers and define the corporate KYB and beneficial-ownership process.
  3. Days 15-21: Stand up sanctions and PEP screening at onboarding, write the first monitoring rules from your risk assessment, and run a retroactive screen of your transaction history.
  4. Days 22-30: Train staff, run one mock STR end to end (alert, review, narrative, goAML submission), fix what broke, and schedule the first independent review.

Where Finhaq fits

Areas 3, 4, and 7 of this checklist are the parts that fail under volume, and they are what Finhaq automates. Six screening engines score every transaction in real time, with verdicts in 142ms that decompose rule by rule for examiners. Every alert and decision sits in an immutable audit trail, reports come out in goAML-ready formats, and bulk CSV import screens your full history on day one, no code required. At Buildbank MFB, this blocked over ₦97 million in suspicious value with zero false negatives.

If you want to know which checklist items your current setup would fail in an examination, the free AML readiness assessment scores it in three minutes.


This article is general guidance for compliance professionals, not legal advice. Obligations are set by the Money Laundering (Prevention and Prohibition) Act 2022, CBN AML/CFT regulations, and NFIU directives. Always check the current instruments and your regulator's circulars.

Turn this checklist into a working program

A 30-minute demo on your scenarios: real-time screening, explainable verdicts, retroactive screening, and goAML-ready reporting.