CBN AML/CFT/CPF

The supervisory core of Nigerian financial crime compliance: due diligence, monitoring and reporting.

Market regime · CBN AML/CFT/CPF Regulations, with the CDD Regulations 2023

Issued by

Central Bank of Nigeria

Region

Nigeria

Effective

Regulations 2022, with the CDD Regulations 2023

Oversight

Supervised and examined by the Central Bank of Nigeria

Applies when

Banks and other financial institutions under CBN supervision

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

The CBN's AML/CFT/CPF regime sets the operating rules for financial-crime compliance in Nigerian banking: risk-based customer due diligence, ongoing monitoring, sanctions and PEP screening, record-keeping, board-level accountability and the reporting lines into the NFIU.

It moves: circulars, the CDD Regulations 2023 and the 2026 automated-AML baseline keep raising the bar. The programme that satisfies it is a living system, not an annual policy refresh.

Where programmes are tested.

01

Risk-based CDD

Customer risk assessment, identification and verification, enhanced due diligence for higher-risk relationships and PEPs.

02

Ongoing monitoring

Transaction monitoring tuned to the risk assessment, with alerts dispositioned and escalations evidenced.

03

Reporting and records

Suspicious and threshold reports filed on time, and records kept to the mandated horizon.

04

Governance

Board oversight, a compliance officer with standing, and training the institution can evidence.

Curated once, evidenced continuously.

  • The CBN AML set is curated and versioned centrally: when a circular lands, the mapping updates once and every customer inherits it through their overlay.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

CBN AML/CFT/CPF, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who does the CBN AML/CFT/CPF regime apply to?

Banks and other financial institutions under CBN supervision, including payment service providers and other licensed non-bank institutions. Designated non-financial businesses fall under the same national regime through SCUML rather than the CBN.

What does risk-based customer due diligence require?

An institution-wide risk assessment, customer identification and verification proportionate to risk, beneficial-ownership checks, and enhanced due diligence for politically exposed persons and other higher-risk relationships, all evidenced, because the examiner samples the file, not the policy.

How does the regime relate to the MLPPA 2022?

The MLPPA is the federal statute that creates the offences and core duties; the CBN regulations operationalise them for its licensees, and circulars keep tightening the detail. An examiner cites both, which is why the catalog maps statute and regulation to the same controls.

How long must CDD and transaction records be kept?

At least five years after the transaction or the end of the business relationship, and they must be retrievable: a record you cannot produce during an audit is treated as a record you do not have.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.