Microfinance Banks play an important role in Nigeria's financial system by extending formal financial services to individuals and businesses that may otherwise have limited access to traditional banking.
The Central Bank of Nigeria defines a Microfinance Bank as a company licensed by the CBN to provide services including savings and deposits, loans, domestic funds transfers and other financial and non-financial services to microfinance clients. Their target market includes low-income households, underserved and unbanked customers, informal-sector operators, micro-entrepreneurs and subsistence farmers.
This role also exposes Microfinance Banks to significant regulatory, operational and financial-crime risks.
MFBs process customer funds and personal information, extend credit, operate payment channels and can increasingly provide digitally enabled financial services. As a result, they are subject to requirements covering everything from corporate governance and prudential returns to AML/CFT/CPF, fraud controls, data protection and technology governance.
The regulatory consequences of getting these obligations wrong can be significant. In July 2026, the CBN revoked the licences of 46 Microfinance Banks, citing issues including insufficient assets to meet liabilities, prolonged inactivity, unauthorised cessation of operations and failure to maintain minimum capital requirements.
The CBN's recent sectoral ML/TF/PF risk assessment also assessed the Microfinance Bank subsector's overall money-laundering, terrorist-financing and proliferation-financing risk as Moderate.
Compliance for an MFB therefore cannot be treated as a collection of occasional regulatory filings. It requires a coordinated framework covering the institution's governance, finances, customers, transactions, technology and data.
This guide examines six major areas Microfinance Banks should keep under review.
1. Corporate Governance and Licensing Obligations
Strong governance is fundamental to the operation of a Microfinance Bank.
The CBN's corporate-governance framework for MFBs places responsibility on the Board for the affairs and performance of the institution and requires appropriate oversight of strategy, risk management, internal controls and management.
In practice, governance obligations extend to matters such as:
Board composition and responsibilities;
appointment and approval of key officers;
management oversight;
insider and related-party transactions;
conflicts of interest;
internal audit and control;
risk management;
regulatory approvals; and
compliance with the scope and conditions of the MFB's licence.
Governance should not be treated as simply a Board-secretariat responsibility.
For an MFB, many regulatory failures — from inappropriate lending and weak AML controls to poor data management and inaccurate regulatory returns — ultimately become governance issues because the institution must demonstrate that appropriate oversight and accountability existed.
2. Prudential, Accounting and Regulatory-Return Obligations
MFBs also have extensive financial and prudential obligations.
The CBN's MFB framework requires institutions to maintain appropriate financial records and submit regulatory returns covering areas such as:
assets and liabilities;
profit and loss;
loans and investments;
deposit liabilities;
interest-rate structures;
balances with other financial institutions;
related-party and insider credits;
non-performing loans and assets; and
other information prescribed by the CBN.
These requirements allow the regulator to monitor the safety and soundness of the institution, including its capital, liquidity, asset quality and risk profile.
Compliance teams should therefore work closely with Finance, Risk and Operations rather than viewing regulatory reporting as a separate compliance function.
Poor data quality is particularly dangerous. An institution may have an appropriate policy on paper but still face regulatory exposure where the information being submitted to the regulator is incomplete, inconsistent or inaccurate.
3. Internal Controls, Fraud and General Compliance
Microfinance Banks also need effective internal-control systems.
The CBN's MFB guidelines require an internal audit function and require MFBs to maintain an internal-control framework covering areas such as risk assessment, control activities, information and communication, and monitoring. The framework also contains requirements around reporting fraud and attempted fraud.
A modern compliance programme should therefore include controls around:
fraud identification and escalation;
whistleblowing;
employee conduct;
segregation of duties;
Maker-Checker controls;
conflicts of interest;
customer complaints;
regulatory-report tracking;
policy reviews;
staff training; and
evidence that identified compliance weaknesses have actually been remediated.
A recurring problem for regulated institutions is treating the existence of a policy as evidence of compliance.
Regulators increasingly expect institutions to demonstrate that controls operate effectively in practice.
That means an MFB should be able to answer questions such as:
Who owns this requirement? When was the control last performed? What evidence proves it happened? Were any exceptions identified? Who followed up on them?
4. AML/CFT/CPF Compliance Obligations
AML/CFT/CPF is one of the most significant compliance areas for a Microfinance Bank.
The current framework includes the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, the CBN's AML/CFT/CPF framework, the CBN Customer Due Diligence Regulations 2023, NFIU reporting requirements and related CBN/NFIU guidance.
The CBN Customer Due Diligence Regulations apply to banks and other financial institutions under the CBN's regulatory purview and require risk-based CDD arrangements for prospective, existing and occasional customers.
Some of the core obligations include:
Customer Identification and Verification
MFBs need procedures for establishing and verifying customer identity and, where relevant, identifying beneficial owners.
CDD is not simply an onboarding exercise. Existing customers should also be subject to ongoing due diligence based on materiality and risk.
Customer Risk Assessment
Institutions should identify the ML/TF/PF risks associated with customers, products, channels, geographies and transactions and apply controls proportionate to those risks.
Higher-risk relationships require enhanced scrutiny.
Politically Exposed Persons
MFBs must have appropriate systems for identifying PEPs and determining when enhanced due diligence, senior-management approval, source-of-funds/source-of-wealth checks and increased monitoring are required.
The CBN also requires financial institutions to render monthly returns on transactions involving PEPs to the CBN and NFIU.
Sanctions and Watchlist Screening
Customers and relevant parties should be screened against applicable sanctions and watchlists, with appropriate controls for ongoing screening, escalation, investigation and disposition of potential matches.
Transaction Monitoring
Institutions need controls capable of identifying activity that is inconsistent with the customer's expected behaviour or may indicate money laundering, terrorist financing, proliferation financing or associated predicate offences.
This should be risk-based rather than limited to simple transaction thresholds.
Suspicious Transaction Reporting
Section 7 of the MLPPA requires suspicious transactions to be reported to the NFIU once the relevant grounds for suspicion arise. The NFIU has subsequently issued detailed guidance covering identification, investigation and reporting of suspicious transactions by financial institutions.
Currency Transaction Reporting
Under Section 11 of the MLPPA, financial institutions must report qualifying transactions exceeding:
- ₦5 million for an individual; or
- ₦10 million for a body corporate.
The statutory reporting period is within seven days.
Compliance Programme and Training
The MLPPA also requires financial institutions to establish internal AML programmes, including management-level compliance responsibility, regular employee training, centralisation of relevant information and internal audit arrangements for testing compliance.
5. Data Protection and Privacy Obligations
Nigeria's data protection framework operates under the Nigeria Data Protection Act 2023, overseen by the Nigeria Data Protection Commission, together with the General Application and Implementation Directive 2025 (GAID).
The GAID expressly states that the NDPC ceased applying the NDPR 2019 as the legal instrument regulating data privacy following issuance of the GAID.
This is particularly significant for Microfinance Banks because the NDPC specifically classifies Microfinance Banks as Extra-High Level Data Controllers and Processors of Major Importance.
This creates obligations that may include:
registration with the NDPC;
designation of a Data Protection Officer;
maintaining appropriate privacy notices;
maintaining records of processing activities;
establishing lawful bases for processing personal data;
implementing appropriate technical and organisational security measures;
conducting DPIAs where required;
managing third-party processors;
managing cross-border transfers;
maintaining data-breach response procedures;
respecting data-subject rights;
conducting staff privacy training; and
maintaining appropriate compliance evidence.
For entities classified as Extra-High Level, the GAID requires registration and annual Compliance Audit Returns.
The GAID also requires DPOs to prepare an internal semi-annual data protection report for management covering the organisation's data-protection compliance position.
For an MFB, data protection is particularly important because customer onboarding, identity verification, credit assessment, transaction monitoring and digital banking can involve extensive processing of financial, identification and behavioural information.
6. Technology, Cybersecurity and Automated AML Requirements
Technology compliance is becoming an increasingly important part of MFB regulation.
In March 2026, the CBN issued its Baseline Standards for Automated AML/CFT/CPF Solutions, introducing mandatory minimum expectations for the technology financial institutions use to manage financial-crime risk. The CBN's announcement makes clear that the Standards apply across regulated financial institutions, including the Other Financial Institutions segment.
The Standards cover areas including:
customer identification and verification;
customer risk assessment;
sanctions and watchlist screening;
transaction monitoring;
case management;
regulatory reporting;
audit and governance;
systems integration;
security and data protection; and
system usability and configurability.
For MFBs using automated AML solutions, this changes the compliance conversation.
It is no longer sufficient to simply say, “We have transaction-monitoring software.”
The institution needs to consider whether its system is appropriately configured, integrated, governed, tested and capable of demonstrating that its controls are effective.
The CBN has also continued to strengthen its broader cybersecurity expectations. In March 2026 it deployed a Cybersecurity Self-Assessment Tool covering cybersecurity governance, risk management, technology and third-party risks, incident response and operational resilience.
Technology should therefore be treated as part of the MFB's compliance framework, rather than solely as an IT issue.
Building an Effective MFB Compliance Programme
With so many requirements operating simultaneously, the biggest risk for an MFB is fragmentation.
Corporate governance may be managed by the Company Secretary. AML may sit with Compliance. Regulatory returns may sit with Finance. Data protection may sit with Legal or a DPO. Fraud may sit with Operations or Risk. Cybersecurity may sit with IT.
But regulators assess the institution.
An effective MFB compliance framework should therefore bring those obligations together through:
A central regulatory obligations register - Know every applicable obligation, deadline, owner and required evidence.
Clear ownership - Each regulatory requirement should have an accountable person or function.
A compliance calendar - Recurring returns, reviews, audits, training requirements and regulatory deadlines should not depend on someone's memory.
Policies connected to operating controls - Every policy requirement should be traceable to the procedure or system control that implements it.
Evidence of compliance - Maintain documentation showing that controls were actually performed.
Automated monitoring where appropriate - High-volume activities such as customer screening, transaction monitoring and regulatory reporting are difficult to manage effectively through spreadsheets and manual processes alone.
Periodic testing - Institutions should regularly assess whether controls work as intended and whether changing products, customers, regulations or risks require them to be updated.
Is Your MFB's Compliance Framework Keeping Up?
Nigeria's regulatory environment has continued to evolve.
The CBN's decision to revoke 46 MFB licences in 2026 is another reminder that regulatory compliance, capital adequacy, governance and operational soundness are conditions for remaining in the financial system — not administrative formalities.
At the same time, MFBs now need to manage obligations arising from newer frameworks including the Nigeria Data Protection Act and GAID, updated NFIU reporting guidance and the CBN Baseline Standards for Automated AML/CFT/CPF Solutions.
For compliance teams, the challenge is therefore not simply understanding individual regulations.
It is building a system capable of keeping track of obligations, detecting financial crime, managing investigations, maintaining evidence and reporting accurately to regulators as the institution grows.
How Regfyl Can Help Microfinance Banks
Regfyl helps financial institutions bring key parts of the financial-crime compliance lifecycle into one connected environment.
For Microfinance Banks, this can include:
customer and business risk assessment;
sanctions, PEP and adverse-media screening;
ongoing customer monitoring;
automated transaction monitoring;
configurable AML and fraud rules;
investigation and case-management workflows;
audit trails and governance controls;
automated regulatory reporting; and
direct submission of supported reports to the NFIU goAML platform.
This allows compliance teams to spend less time managing fragmented manual processes and more time investigating and managing actual risk.
Strengthen Your MFB Compliance Framework
Want to understand where your current AML technology and processes stand against today's regulatory requirements?
Book an MFB Compliance & Technology Review