In March 2026 the Central Bank of Nigeria issued its Baseline Standards for Automated AML/CFT/CPF Solutions. For the first time, the supervisor has written down what a credible automated anti-money-laundering system must look like, and the bar is a “glass box,” not a black one. Here's what it means in practice, and how to know if you're ready.
What the Baseline actually demands
Strip away the detail and the guidance rests on three expectations. Your automated AML system must be defensible, governed, and demonstrably effective, and you remain fully responsible for it regardless of which vendor built it.
- Defensibility. Decisions must be explainable and traceable. When an examiner asks why a transaction was flagged, or why one wasn't, you need an audit trail, not a shrug.
- Governance. Every model needs an owner, independent validation, and change control. A threshold that quietly changed last quarter is a finding waiting to happen.
- Demonstrable effectiveness. It is no longer enough to say the system works. You have to show it, with evidence the supervisor can examine.
Why “glass box” is the right metaphor
A black-box vendor tool that scores transactions and produces alerts is no longer sufficient, even if it works, because you can't prove how or why it works. A glass box is one where the model inventory, the validations, the changes, and the decisions are all visible and recorded. The institution can answer for the system end to end.
Crucially, the responsibility does not transfer to your vendor. If your screening engine, your transaction-monitoring rules, or your KYC scoring sits with a third party, the governance, validation and effectiveness obligations are still yours.
A readiness checklist
Before your next audit, you should be able to produce, on request:
- A complete model inventory, every AML, sanctions and KYC model, with purpose, owner, version, criticality and lifecycle status.
- Evidence of independent validation for each model, where the validator is demonstrably not the model's owner or developer.
- A change log for every material change, retrains, threshold or parameter changes, data changes, version bumps, decommissions, with who and when.
- An audit trail of consequential decisions and the people who made them, that you can hand to an examiner without re-assembling it by hand.
- A clear account of effectiveness, not just that the system ran, but that the human disposition (adjudication, escalation, reporting) closed the loop.
The common gaps
Most institutions fail not on the technology but on the paper trail around it. The model exists; the independent validation doesn't. The system runs; the change history lives in someone's inbox. The alerts fire; nobody can show what happened after. The Baseline closes exactly these gaps, which is why a static model-risk PDF refreshed once a year no longer survives contact with an audit.
How a GRC system helps
A platform built for this turns the checklist into a living register rather than an annual scramble. Model governance becomes an inventory with validation that is independent by construction and a change log that is the trail an examiner asks for. The immutable audit trail underneath every action supplies the defensibility. And because the framework is curated centrally, the Baseline's requirements arrive already mapped to controls. You adopt them; you don't reverse-engineer them from the circular.
The CBN has, in effect, written the specification. The work now is to build to it, deliberately, with the evidence in place, before the examiner asks.