CBN Baseline Standards Explained: What Every Nigerian Financial Institution Must Know

BN Baseline Standards Explained

Inside this Article

On March 10, 2026, the Central Bank of Nigeria issued what may be the most consequential AML directive in the country’s regulatory history. Circular BSD/DIR/PUB/LAB/019/002 establishes mandatory Baseline Standards for Automated AML/CFT/CPF Solutions — and it applies to every bank, fintech, microfinance bank, mobile money operator, IMTO, and payment service provider in Nigeria.

This isn’t a guideline. It’s a mandate. And the enforcement language is sharper than most institutions realise.

We’ve spent the last three weeks analysing the circular in detail. This article breaks down what it actually requires, what most institutions are getting wrong, and what the enforcement section says that compliance officers need to read carefully.

The Deadline Structure

The circular establishes two separate deadlines that institutions need to track:

June 10, 2026: All institutions must submit detailed implementation roadmaps to the CBN Compliance Department. Submissions must be in both editable (.docx) and final (.pdf) formats. Incomplete or inconsistent filings may attract supervisory action.

Full compliance: 18 months for Deposit Money Banks (September 2027) and 24 months for all other financial institutions (March 2028) from the date of issuance.

The roadmap deadline is the immediate pressure point. Every institution needs to submit a plan that covers current state, target state, actions required, timelines, ownership, and governance arrangements — for all 10 capability areas.

The 10 Required Capabilities

This is where the gap between perception and reality becomes clear. Most institutions believe their existing compliance tools meet the standard. In our assessment, typical KYC and screening tools cover approximately 3 of the 10 requirements.

  1. Customer Identification & Verification Link KYC/KYB data, customer risk profiles, and transactional activity within a single, integrated view. NIN/BVN verification, document verification, and continuous data updates.
  2. Risk Assessment & Customer Profiling Dynamic risk scoring that continuously re-assesses customers throughout the relationship lifecycle. Risk-based CDD and EDD escalation. Not a one-time score at onboarding.
  3. Sanctions & Watchlist Screening Screen against domestic and international sanctions lists including OFAC, UN, and EU. Systems must automatically block account openings or transactions for confirmed sanctions matches.
  4. PEP Screening Politically exposed persons registers, adverse media sources, and internal watchlists. Ongoing monitoring for changes in PEP status — not just at onboarding.
  5. Transaction Monitoring This is the most misunderstood requirement. The CBN explicitly states that AML solutions must “assess activity in the context of the full customer profile and not monitoring solely on raw transactional data.” Context-aware monitoring across all products, channels, and customers.
  6. Case Management & Investigation Workflow-driven investigation processes with role-based access controls, evidence packaging, analyst assignment, and SLA tracking. Many institutions handle this in spreadsheets — that won’t pass.
  7. Regulatory Reporting (STR/CTR) Pre-formatted templates for filing Suspicious Transaction Reports and Currency Transaction Reports to the NFIU. Submission tracking, filing timeliness metrics, and quality assurance.
  8. Audit & Governance Tamper-proof audit trails for all compliance actions. Board-level compliance dashboards. Internal audit schedules. Regulatory exam support packages.
  9. Data Protection & Security Alignment with the Nigeria Data Protection Act (NDPA). Encryption at rest and in transit, role-based access controls, multi-factor authentication, and documented incident response procedures.
  10. Vendor & Third-Party Management Documented policies for procurement, implementation, ongoing support, incident handling, and exit strategies for all AML technology vendors. This is new for most institutions.

What Most Institutions Are Getting Wrong

Mistake 1: Confusing KYC with full AML compliance

Identity verification and screening tools typically cover capabilities 1, 3, and 4. That’s 3 out of 10. The remaining 7 — including transaction monitoring, case management, regulatory reporting, and audit governance — require fundamentally different technology.

Mistake 2: Letting the vendor write the roadmap

The CBN has been explicit on this point: compliance is assessed at the institutional level, not based on the capabilities of technology vendors. A follow-up circular specifically warned against “misinterpreting” the standards based on vendor representations. Your roadmap must reflect your institution’s own governance, not a vendor’s marketing material.

Mistake 3: Ignoring the governance requirements

The circular doesn’t just require technology. It requires documented ownership, timelines, board oversight, three-lines-of-defence arrangements, and independent annual validation of AI/ML models. Many roadmap submissions will be heavy on technical specifications and empty on governance. The CBN will notice.

Mistake 4: Underestimating the enforcement language

This brings us to the section most compliance officers need to read more carefully.

The Enforcement Language That Matters

The circular’s enforcement section contains a line that changes the compliance calculus significantly:

“Institutions that fail to meet these Baseline Standards, or that operate AML Solutions in a manner that results in ineffective AML/CFT/CPF control, may be subject to remedial directives, administrative sanctions and penalties in line with extant laws and regulations.”

And critically: “…consequences may affect both the institution and accountable individuals.”

That second line is the one that should have every CCO, Head of AML, and MLRO paying attention. The CBN is explicitly stating that non-compliance consequences extend beyond the institution to the individuals responsible for compliance oversight.

This is not theoretical. It means that if the CBN’s supervisory assessment finds that your institution’s AML framework is inadequate, the compliance officer personally — not just the institution — may face regulatory action.

What Your Roadmap Submission Must Include

Based on our analysis of the circular, the CBN expects roadmap submissions to cover:

ElementWhat the CBN ExpectsCommon Gap
Current stateHonest assessment of existing capabilities against all 10 requirementsInstitutions overstate coverage
Target stateClear description of the end-state compliance frameworkVague aspirational language
Actions requiredSpecific steps to close each gap, including technology and process changesGeneric “implement AML system”
TimelinesQuarterly milestones with specific deliverablesSingle end-date with no milestones
OwnershipNamed individuals accountable for each capability area“Compliance department” without named owners
GovernanceBoard oversight, reporting lines, three-lines-of-defence modelMissing entirely from most submissions
EffectivenessHow the institution will measure and demonstrate that AML controls workNot addressed
IntegrationHow AML systems integrate with core banking across all products/channelsStandalone system, no integration plan
DefensibilityEvidence that the framework would withstand regulatory scrutinyNo evidence-gathering strategy

The circular also requires submissions in a prescribed template format, delivered in both editable and final formats. Many institutions will miss this procedural requirement.

The AI/ML Governance Requirement

One requirement that deserves special attention: the CBN explicitly permits the use of artificial intelligence, machine learning, and predictive analytics for AML detection. However, it immediately follows this with a governance mandate that most institutions are unprepared for:

Institutions must “perform independent validation of all artificial intelligence and machine-learning models at least annually and upon significant change covering accuracy, performance drift, fairness audits, bias testing, and human review.”

If your vendor deploys AI/ML models, you need to ensure independent annual validation is contractually agreed and operationally feasible. “The vendor validates their own models” will not satisfy the CBN.

What Happens Next

The CBN has stated that compliance will be monitored through three mechanisms: off-site surveillance (ongoing), on-site examinations (periodic), and thematic regulatory reviews (targeted). Institutions should expect that roadmap submissions will be reviewed and that the quality of the submission will inform the intensity of subsequent supervisory engagement.

The institutions that treat this as a genuine opportunity to strengthen their compliance framework — rather than a box-ticking exercise — will be in the strongest position when examinations begin.

Picture of Brain Station 23

Brain Station 23

Summarize with