Currency Transaction Reports are a core part of Nigeria's anti-money laundering, counter-terrorist financing and counter-proliferation financing framework.
Under Section 11 of the Money Laundering (Prevention and Prohibition) Act 2022 (MLPPA), financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs) are required to report qualifying transactions above prescribed thresholds.
The applicable thresholds are:
More than ₦5 million or its equivalent for an individual; and
More than ₦10 million or its equivalent for a body corporate.
Qualifying transactions must be reported within seven days. For financial institutions, the report is made to the Nigerian Financial Intelligence Unit (NFIU); for DNFBPs, it is made to the Special Control Unit Against Money Laundering (SCUML).
For compliance teams processing significant transaction volumes, meeting this obligation consistently involves more than simply knowing the reporting threshold. Institutions need reliable processes to identify reportable transactions, obtain the required information, prepare the report in the correct format, submit it within the statutory timeframe and retain evidence of the process.
This guide explains the CTR requirement, how financial institutions file CTRs in Nigeria and how the reporting process can be automated.
What Is a Currency Transaction Report?
A Currency Transaction Report, or CTR, is a threshold-based regulatory report made in respect of qualifying transactions above prescribed monetary limits.
The NFIU receives threshold-based reports from financial institutions as part of its broader responsibility for receiving, analysing and disseminating financial intelligence.
Importantly, a CTR does not mean that the customer or transaction is necessarily suspicious. A CTR is generally triggered because the relevant transaction exceeds the applicable reporting threshold.
A Suspicious Transaction Report (STR), by contrast, is triggered by suspicion and does not depend on the transaction exceeding a particular value.
Where a transaction meets the threshold for a CTR and is also suspicious, the NFIU confirms that the appropriate reports should be filed for both obligations.
What Are the CTR Thresholds in Nigeria?
Section 11 of the MLPPA requires a financial institution or DNFBP to report any qualifying single transaction, lodgement or transfer of funds above ₦5 million or its equivalent for an individual; or ₦10 million or its equivalent for a body corporate.
The report must be made within seven days of the transaction.
This is why institutions need controls capable of detecting transactions crossing the relevant thresholds without relying solely on compliance officers manually reviewing transaction records.
CTRs and transaction structuring
Compliance teams should also be alert to customers deliberately breaking transactions into smaller amounts in an attempt to avoid reporting requirements.
Structuring or other activity intended to evade AML reporting requirements can itself raise suspicion and may create a separate STR obligation.
For DNFBPs, SCUML expressly warns that attempts to structure transactions to evade CTR or Cash-Based Transaction Report requirements should be treated as suspicious and reported accordingly.
CTRs Are Different From Foreign Transaction Reports
CTR requirements should also be distinguished from Nigeria's separate reporting requirements for certain cross-border transactions.
Under Section 3 of the MLPPA, financial institutions have a separate obligation in respect of qualifying transfers of funds or securities to or from a foreign country exceeding US$10,000 or its equivalent.
The NFIU refers to these separately as Foreign Transaction Reports (FTRs), and its current goAML reporting schema includes FTR as a distinct report type.
Compliance teams should therefore ensure their systems distinguish between different regulatory-reporting triggers, report types and deadlines rather than treating all threshold-based reports as CTRs.
Who Is Required to File CTRs?
Financial Institutions
Financial institutions covered by Nigeria's AML/CFT framework include banks and other regulated entities such as microfinance banks, Bureau de Change operators, insurance companies, capital market operators and other covered financial-services businesses.
For financial institutions, Section 11 CTR reports are made to the Nigerian Financial Intelligence Unit.
Designated Non-Financial Businesses and Professions
The obligation also applies to Designated Non-Financial Businesses and Professions (DNFBPs).
These include a range of businesses and professions exposed to money-laundering and terrorist-financing risks.
For DNFBPs, CTRs are submitted through SCUML rather than through the normal financial-institution goAML process. SCUML collects CTRs and Cash-Based Transaction Reports from DNFBPs for onward transmission to the NFIU.
Since 1 January 2026, SCUML has required DNFBPs to submit CTRs and CBTRs through its online portal rather than by email.
This article focuses primarily on the filing process for financial institutions.
Which Platform Do Financial Institutions Use to File CTRs?
goAML
For financial institutions, the NFIU's goAML platform is the principal platform for regulatory reporting.
The NFIU identifies CTR as one of the report types available within goAML alongside reports such as STRs, SARs and Additional Information Files. Its current technical resources also provide a dedicated report code for CTR submissions.
An institution must be registered as a reporting organisation before it can access goAML.
What about RapidAML?
RapidAML is a separate simplified NFIU reporting portal that complements goAML.
Its use depends on the reporting entity and report type. As of September 2026, the NFIU states that Bureau de Change operators can file CTRs through RapidAML, while other CBN-regulated financial institutions generally use RapidAML for specified Nil and PEP reports.
Institutions should therefore use the reporting channel applicable to their regulatory category rather than assuming all financial institutions submit CTRs through RapidAML.
How to File a CTR Through goAML
For financial institutions filing directly through goAML, the reporting process can broadly be broken into the following stages.
Step 1: Identify the Reportable Transaction
The institution must first identify transactions that exceed the applicable reporting thresholds.
For institutions processing significant transaction volumes, relying on compliance personnel to identify these transactions manually creates unnecessary operational risk.
An effective system should continuously evaluate transaction data and flag transactions that meet applicable reporting criteria for review.
It should also allow compliance teams to investigate transactions that may have been structured or otherwise divided in a manner that warrants further scrutiny.
Step 2: Review the Customer and Transaction Information
Before submitting a CTR, the compliance team should ensure that the underlying information is accurate and complete.
Depending on the transaction and applicable reporting schema, relevant information may include:
transaction amount;
currency;
transaction date and type;
customer name and identification details;
relevant account information;
addresses and other customer information;
parties to the transaction;
information concerning the sending or receiving institution; and
other information required by the applicable NFIU reporting schema.
Incomplete customer or transaction data can result in validation errors or rejected reports.
Step 3: Prepare the CTR
Financial institutions generally have two routes for preparing reports for goAML.
Manual Web Reporting
A compliance officer can prepare the CTR through the goAML web interface by completing the relevant reporting fields.
This may be manageable for institutions with relatively small reporting volumes, but it becomes operationally burdensome where large numbers of threshold reports must be filed.
Structured or Automated Reporting
Institutions with appropriate AML or regulatory-reporting technology can generate CTR data in the format required by goAML.
The NFIU currently publishes a goAML Schema Guide, Lookup Master, Web Guide and XML Validator for reporting entities preparing structured submissions.
Automation can significantly reduce repetitive data entry and the risk of manual transcription errors.
Some AML platforms can go further than merely generating a file for subsequent upload.
Regfyl, for example, has direct integration with the NFIU goAML platform, allowing supported regulatory reports to be submitted to goAML through the Regfyl regulatory-reporting workflow.
This means compliance teams can manage detection, preparation, review and submission without having to generate a report in Regfyl and then manually re-enter or separately upload the same report through another system.
Step 4: Validate the Report
Before submission, the report should be checked for completeness and consistency with the applicable NFIU reporting requirements.
For structured submissions, the NFIU provides an XML Validator and current schema resources that institutions can use when developing or maintaining their reporting processes.
Validation is particularly important where reporting is automated.
Automation increases reporting capacity, but errors in mapping, underlying customer data or configuration can also be reproduced at scale if appropriate controls are not in place.
Step 5: Review and Approve the CTR
Institutions should maintain appropriate internal controls around regulatory reporting.
Rather than reports being automatically sent merely because a threshold has been triggered, an institution may require designated compliance personnel to review the transaction and associated information before submission.
The precise workflow should reflect the institution's policies, governance arrangements and regulatory obligations.
Step 6: Submit the CTR to the NFIU
Once reviewed and approved, the CTR should be submitted through goAML within the statutory timeframe.
Where an institution uses Regfyl's direct goAML integration, the approved regulatory report can be submitted to goAML from within Regfyl's regulatory-reporting workflow.
This removes a significant manual step from the process and allows the institution to manage much of the reporting lifecycle within a single environment.
Step 7: Monitor the Submission
Submission should not be treated as the end of the reporting process.
Compliance teams should monitor the status of submitted reports and investigate validation failures, rejected reports or other feedback.
The NFIU provides guidance for web reporting, XML submissions and filing STR and CTR reports through its online reporting resources.
Where a report requires correction, the institution should address the issue promptly to ensure that its statutory reporting obligation is properly discharged.
What Records Should Compliance Teams Retain?
A defensible CTR process should create evidence of the entire reporting lifecycle.
Institutions should retain appropriate records of:
the underlying transaction;
why it triggered the reporting process;
the customer and transaction information used;
the CTR generated;
review and approval activity;
the date and time of submission;
submission status and acknowledgements;
any validation or rejection messages;
corrections or resubmissions; and
the final reporting outcome.
This is important not only for NFIU reporting but also for internal audit, compliance assurance and regulatory examinations.
What Are the Penalties for Failing to File a CTR?
Failure to meet the Section 11 reporting requirement can have serious consequences.
Under Section 11(3) of the MLPPA, a financial institution or DNFBP that contravenes the reporting requirement commits an offence and is liable on conviction to a fine of at least ₦250,000 and not more than ₦1 million for each day the contravention continues.
Institutions may also face additional regulatory or administrative consequences under the rules and enforcement framework of their relevant supervisory authority.
Rather than treating CTR reporting as a periodic administrative exercise, institutions should therefore maintain appropriate controls around:
transaction detection;
reporting thresholds;
data quality;
timeliness;
review and approval;
regulatory submission;
exception management; and
evidence retention.
How Regfyl Automates CTR Reporting
For institutions processing thousands or millions of transactions, the difficult part of CTR compliance is rarely knowing that a reporting requirement exists.
The operational challenge is ensuring that every reportable transaction is detected, the relevant information is complete, the report is correctly prepared and the submission is made within the required timeframe.
Regfyl can help automate that process from detection through submission.
Automated Detection of Reportable Transactions
Regfyl monitors transaction activity and can identify transactions that meet configured regulatory-reporting thresholds, reducing dependence on manual transaction reviews.
Automated CTR Generation
Customer and transaction information already available within the institution's integrated systems can be used to prepare CTRs, reducing repetitive manual data entry.
Direct Integration With NFIU goAML
A key advantage of Regfyl's regulatory-reporting capability is its direct integration with goAML.
Once the relevant report has been prepared and passed through the institution's applicable review and approval process, supported regulatory reports can be submitted to the NFIU goAML platform through Regfyl.
This reduces the need to move between multiple systems or manually upload separately generated reports.
Review and Approval Workflows
Institutions can maintain appropriate controls around regulatory submissions, including review and approval steps before reports are transmitted.
This allows technology to automate operational work without removing compliance oversight.
Centralised Regulatory Reporting
Compliance teams can manage regulatory-reporting activity from a central environment rather than maintaining separate spreadsheets, locally generated files and manual submission records.
Audit Trails
The reporting process can be recorded from identification through review and submission, creating an audit trail to support compliance assurance, management oversight and regulatory examination.
Automation Supports Compliance — It Does Not Replace Accountability
Automating CTR reporting can substantially reduce manual effort, improve consistency and make high-volume reporting easier to manage.
It does not, however, remove the financial institution's responsibility for its regulatory obligations.
Institutions remain responsible for the quality of their underlying data, the appropriateness of their reporting configuration, the review of reports and the accuracy and timeliness of information ultimately submitted to the NFIU.
The strongest reporting process therefore combines automation with effective compliance governance and human oversight.
Still Preparing or Uploading CTRs Manually?
If your compliance team is manually identifying reportable transactions, preparing CTRs across spreadsheets or separate systems, or uploading reports individually into goAML, there may be significant opportunities to streamline the process.
Regfyl can help your institution automate CTR detection, report generation, review and direct submission to NFIU goAML through one regulatory-reporting workflow.
See Regfyl Regulatory Reporting in Action
or