Nigeria's AML/CFT/CPF environment is changing quickly.
For the State of AML Compliance in Nigeria 2026, Regfyl surveyed 227 compliance professionals across Nigeria's financial sector to understand how institutions are managing today's financial-crime risks, where their compliance processes continue to struggle and where they intend to invest. The survey data was collected between September and November 2025.
The timing was significant.
In October 2025, Nigeria was formally removed from the Financial Action Task Force's list of jurisdictions under increased monitoring after completing its agreed action plan. FATF nevertheless emphasised that Nigeria should continue working with GIABA to sustain improvements to its AML/CFT framework.
Since the survey was completed, the regulatory environment has moved even further. In March 2026, the Central Bank of Nigeria issued its Baseline Standards for Automated AML/CFT/CPF Solutions, establishing mandatory minimum expectations for automated financial-crime controls across CBN-regulated financial institutions.
Against that backdrop, our research reveals an industry that wants to modernise, but is still constrained by fragmented systems, manual processes, data-quality challenges and the cost and complexity of technology adoption.
Here are some of the most important findings.
1. AML Compliance Is Still Too Fragmented
One of the clearest findings from the report is that automation exists across the industry, but it has not been implemented consistently across the entire AML lifecycle.
Institutions may have screening technology, transaction monitoring or identity-verification tools, but human intervention is often still needed to connect one stage of the compliance process to another. Regulatory reporting, address verification and periodic compliance reviews remain particularly dependent on manual or hybrid processes.
This fragmentation creates practical problems:
duplicated effort;
slower investigations;
repeated manual data entry;
inconsistent customer information;
higher operating costs; and
compliance teams spending time moving information between systems instead of analysing risk.
The industry's priorities reflect this.
77% of respondents identified process improvement as a priority for 2026, slightly ahead of technology upgrades at 75%.
The message is important: institutions do not simply want more technology. They want better-connected compliance processes.
2. Identity Verification Is Common — But Confidence in the Data Is Not
Nigeria has made considerable progress in building identity infrastructure around systems such as BVN and NIN.
But performing an identity check and having confidence in the identity are not necessarily the same thing.
Among respondents:
65% identified the reliability and authenticity of identity documents as a challenge;
35% reported inconsistent access to authoritative identity databases; and
70% identified establishing true beneficial ownership as their leading KYB challenge.
This is an important distinction for compliance teams.
The question is moving from:
“Did we perform KYC?”
to:
“How confident are we that we actually know who this person or business is?”
Address verification presents a similar challenge. 55% cited the cost of physical verification, while 45% identified document reliability as a major issue.
The broader lesson is that KYC effectiveness cannot be measured simply by whether a verification step occurred. Institutions increasingly need to assess the quality, reliability and context of the underlying data.
3. Screening Teams Are Still Fighting Too Much Noise
Sanctions, PEP and adverse-media screening are now standard parts of most mature AML programmes.
But effectiveness remains difficult where systems generate large numbers of alerts without sufficiently distinguishing genuine risk from noise.
Our survey found recurring concerns around:
outdated or unreliable screening information;
weak localisation of PEP data;
false positives;
inconsistent domestic PEP coverage; and
subjectivity in adverse-media analysis.
The challenge is particularly pronounced with domestic PEP screening. Global data sources may capture prominent political figures but can struggle with the depth and timeliness required to identify state-level appointments, associated persons and changing local political structures.
The implication is that effective screening is not simply about having access to more names.
It requires better data, localisation, intelligent matching and risk-based alert management.
4. Transaction Monitoring Has a Signal-to-Noise Problem
Transaction monitoring remains one of the most operationally demanding parts of AML compliance.
63% of respondents identified false positives as their primary transaction-monitoring challenge, while 37% cited staff capacity.
But the underlying problem is often deeper than the monitoring rules themselves.
Where transaction-monitoring systems are poorly integrated with core banking systems, payment platforms, KYC data and customer risk assessments, it becomes much harder to distinguish genuinely unusual behaviour from ordinary activity.
The industry therefore appears to be moving away from the idea that better monitoring simply means more rules and more alerts.
The more important questions are:
Is monitoring informed by the customer's actual risk profile?
Can rules be segmented appropriately?
Is relevant KYC/KYB context available to investigators?
Are thresholds regularly reviewed and tuned?
Can the institution explain why an alert was generated?
Are false positives and false negatives being measured?
These questions are now even more important because the CBN Baseline Standards require institutions to demonstrate appropriate configuration, integration, governance, tuning and effectiveness of their automated AML controls.
5. Regulatory Reporting Remains Too Manual
Regulatory reporting is another area where fragmentation creates a significant operational burden.
66% of respondents identified gathering data across multiple systems as their primary reporting challenge, while 34% cited issues associated with the NFIU reporting portal.
This is significant because reports such as CTRs and STRs should ideally be outputs of the financial-crime compliance lifecycle rather than separate manual exercises.
Where reporting requires compliance officers to extract information from one system, reconcile it in a spreadsheet, obtain additional customer information elsewhere and then recreate the report in another portal, the institution introduces additional opportunities for:
errors;
delays;
incomplete information;
missed deadlines; and
weak audit trails.
The survey also highlighted industry views on the underlying reporting framework. 49% of respondents supported more dynamic, institution-based CTR thresholds, while respondents also expressed interest in greater flexibility around STR timelines.
Those views represent industry sentiment rather than current regulatory requirements. Institutions must continue to comply with the applicable statutory thresholds and reporting timelines.
6. The Biggest Problems Are Structural, Not a Lack of Willingness
When respondents were asked about the biggest AML challenges facing their institutions, three issues stood out:
- System integration limitations — 70%
- Reliance on manual processes — 61%
- Data-quality issues — 44%
Their leading priorities for 2026 were similarly clear:
- Process improvement — 77%
- Technology upgrades — 75%
- Staff training — 47%
Taken together, the findings suggest that the industry's primary problem is not a lack of awareness of AML obligations.
It is the operational infrastructure required to execute them effectively.
This is reinforced by the barriers institutions identified when considering new technology.
7. The CBN Baseline Standards Have Raised the Bar
One of the most important developments since the survey was completed is the issuance of the CBN Baseline Standards for Automated AML/CFT/CPF Solutions on 10 March 2026.
The Standards require CBN-regulated institutions to operate automated AML solutions proportionate to their size, complexity and risk profile and introduce detailed requirements across customer identification, screening, transaction monitoring, investigations, reporting, governance, system integration and data protection.
The subsequent CBN Guidance Note made the regulator's position even clearer: AML technology must demonstrate defensibility, governance and effectiveness, and compliance is assessed at the level of the financial institution rather than simply by looking at the features a vendor provides.
This is highly consistent with what our survey respondents were already telling us.
Integration matters.
Data quality matters.
False-positive management matters.
Governance matters.
And simply buying another point solution will not necessarily solve the underlying problem.
The implementation phase is now underway
When the original version of this article was published, institutions were approaching the deadline for submission of their implementation roadmaps.
That deadline — 10 June 2026 — has now passed.
Institutions should now be executing those plans.
Under the CBN's implementation timetable, Deposit Money Banks have 18 months from 10 March 2026 to achieve full compliance, while Other Financial Institutions have 24 months.
The conversation should therefore have moved from:
“What does the Baseline Standards circular require?”
to:
“Can we demonstrate that our implementation is progressing, integrated, governed and effective?”
Four Themes That Will Shape the Next Phase of AML Compliance
The report identifies four broader forces likely to shape the Nigerian AML environment.
Technology Will Matter — But Governance Will Matter Just as Much
Nigeria has an opportunity to develop financial-crime technology that responds to local transaction patterns, typologies and regulatory requirements.
But increasingly sophisticated technology will require equally sophisticated governance.
The CBN's 2026 Baseline Standards reinforce this point by making clear that advanced technology — including AI — does not itself constitute compliance.
Public-Private Collaboration Must Continue
Nigeria's removal from FATF increased monitoring demonstrated the impact of coordinated action between regulators, financial institutions, law enforcement and other participants in the AML/CFT system.
FATF has specifically said that Nigeria should continue working with GIABA to sustain the improvements achieved.
Continued intelligence sharing, typology development and engagement between regulators and industry will remain important.
Financial Crime Risks Are Converging
The traditional boundaries between AML, fraud, cybersecurity and operational risk are becoming less distinct.
Fraud proceeds can become money-laundering activity. Compromised identity data can enable both fraud and laundering. Mule accounts can sit at the intersection of fraud, payments and AML.
Institutions therefore need a more connected view of financial-crime risk rather than isolated controls operating in separate teams and systems.
Compliance Teams Need Better Tools, Not Just More People
Our research suggests that institutions are prioritising process improvement and technology investment ahead of headcount expansion.
That does not diminish the importance of experienced compliance professionals.
It means those professionals need systems that allow them to spend less time performing repetitive operational work and more time exercising judgement, investigating risk and improving controls.
What the 2026 Data Tells Us
The State of AML Compliance in Nigeria in 2026 is best described as a transition from compliance activity to compliance effectiveness.
The underlying regulatory framework has strengthened. Nigeria has exited FATF increased monitoring. The CBN has introduced significantly more detailed expectations for automated AML systems. And financial institutions themselves overwhelmingly recognise the need to improve processes and technology.
But significant operational gaps remain.
Only 48% of institutions surveyed reported using AML technology vendors, while integration, manual processes and data quality remained among the industry's leading challenges.
The next phase of AML transformation in Nigeria will therefore not be defined simply by whether institutions acquire new technology.
It will be defined by whether they can create connected, risk-based and defensible compliance environments that actually improve detection, investigation and reporting outcomes.
Download the State of AML Compliance in Nigeria 2026
The findings covered here represent only part of the research.
The full State of AML Compliance in Nigeria 2026 report provides a deeper look at identity verification, beneficial ownership, sanctions and PEP screening, adverse media, transaction monitoring, regulatory reporting, technology adoption and the priorities of Nigerian compliance professionals.
Want to understand how your institution's current AML environment compares with the issues identified in the report?
Book a Compliance Technology Review
The State of AML Compliance in Nigeria 2026 is based on survey data collected from compliance professionals between September and November 2025. Survey findings reflect respondent views and practices during that period. This article is for informational purposes and does not constitute legal or regulatory advice.