When people think about anti-money laundering compliance, banks and other financial institutions usually come to mind first.
But significant money-laundering, terrorist-financing and proliferation-financing risks also exist outside the traditional financial sector.
Real estate transactions can be used to store or transfer illicit wealth. High-value goods can be purchased with criminal proceeds and resold. Corporate and professional services can be used to create or manage complex ownership structures. Hotels, casinos, automotive dealers and other businesses may also process significant payments or interact with customers whose source of funds requires greater scrutiny.
This is why Nigeria's AML/CFT/CPF framework places specific obligations on Designated Non-Financial Businesses and Professions (DNFBPs).
DNFBPs are supervised for AML/CFT/CPF purposes principally by the Special Control Unit Against Money Laundering (SCUML), which is responsible for their registration, monitoring, supervision and enforcement.
The current framework includes the Money Laundering (Prevention and Prohibition) Act 2022, the Terrorism (Prevention and Prohibition) Act 2022, and, importantly, the Economic and Financial Crimes Commission AML/CFT/CPF Regulations for DNFBPs 2024.
For DNFBPs, compliance therefore goes considerably further than simply obtaining a SCUML certificate.
What Businesses and Professions Are DNFBPs in Nigeria?
The 2024 Regulations identify a broad range of businesses and professions as DNFBPs, including:
jewellery businesses;
car and automobile dealers;
dealers in luxury goods;
chartered accountants and accounting firms;
audit firms;
tax consultants;
clearing and forwarding companies;
legal practitioners, law firms and notaries;
hotels and travel agencies;
casinos;
supermarkets;
dealers in precious stones and metals;
trust and company service providers;
real-estate dealers, developers, agents and brokers;
estate surveyors and valuers;
mortgage brokers;
consultants and consulting companies;
construction companies;
practitioners of mechanised farming;
pool betting and lottery businesses; and
dealers in high-value goods.
The Regulations define high-value goods dealers by reference to goods or items worth more than ₦5 million, and allow additional sectors to be designated by the relevant authorities.
The precise obligations that matter most will differ by sector and business model. A real-estate developer does not face exactly the same risk profile as an accounting practice or luxury-goods dealer.
That is why the Nigerian framework increasingly emphasises a risk-based approach rather than a one-size-fits-all compliance programme.
1. Register With SCUML
The first obligation is registration.
Under the 2024 Regulations, new DNFBPs are required to register with SCUML before commencing business. SCUML is responsible for registering, monitoring and supervising DNFBPs for AML/CFT/CPF purposes.
SCUML currently operates an online registration process and states that registration and certification are free of charge.
Registration should not, however, be treated as the end of the compliance process.
A SCUML certificate demonstrates registration. It does not replace the DNFBP's ongoing obligations around customer due diligence, risk assessment, reporting, training, record keeping and internal controls.
2. Establish an AML/CFT/CPF Compliance Programme
The 2024 Regulations require DNFBPs to establish and implement an AML/CFT/CPF programme based on the risks associated with their business and proportionate to their size.
The programme is expected to include areas such as:
AML/CFT/CPF policies, procedures and internal controls;
customer due diligence;
risk-based customer treatment;
compliance-management arrangements;
appointment of a compliance officer;
independent testing or audit;
regulatory reporting;
employee training;
record keeping;
centralisation of relevant information; and
measures proportionate to identified financial-crime risks.
This is an important development.
For a DNFBP, AML compliance should not simply mean “we collect customers' ID and have a SCUML certificate.”
There should be a documented system showing how financial-crime risks are identified, assessed, escalated, reported and reviewed.
3. Appoint a Compliance Officer and Establish Accountability
The Regulations require DNFBPs to designate a Compliance Officer at management level with appropriate competence, authority and independence to implement the AML/CFT/CPF programme.
Where the business operates more than one location or branch, the Regulations require a Chief Compliance Officer at Head Office at management level.
The compliance function's responsibilities include areas such as:
developing AML/CFT/CPF policies and processes;
monitoring day-to-day compliance;
reporting compliance risks to management;
coordinating regulatory reporting;
training employees;
assessing new products and business practices for financial-crime risk; and
acting as liaison with regulators.
The Regulations also place responsibility on Boards, where applicable, to provide leadership and oversight for ML/TF/PF compliance risks and to approve and oversee relevant policies.
4. Assess Your Money-Laundering, Terrorist-Financing and Proliferation-Financing Risks
DNFBPs are required to periodically assess the ML, TF and PF risks inherent in their operations.
The 2024 Regulations specifically require consideration of risk relating to:
customers;
products and services;
geographical locations; and
delivery channels.
Controls should then be proportionate to the risks identified.
This means a compliance programme should be designed around the actual business.
For example, a real-estate business receiving large payments from overseas customers may face different risks from a consultancy providing mainly domestic business-to-business services.
The purpose of the risk assessment is to ensure that compliance resources are concentrated where exposure is greatest.
5. Conduct Customer Due Diligence
Customer Due Diligence is one of the central AML obligations for DNFBPs.
DNFBPs should identify customers and verify their identities using reliable and independent information.
CDD should also extend beyond simply collecting a name or identification document.
Depending on the customer and transaction, the institution should understand:
who the customer is;
whether the person is acting for somebody else;
the purpose and intended nature of the relationship;
the customer's risk profile;
where appropriate, the source of funds or source of wealth; and
whether enhanced scrutiny is required.
The 2024 Regulations expressly require standard CDD when establishing new business relationships and for certain occasional cash transactions, while enhanced CDD is required in higher-risk circumstances.
Enhanced Due Diligence
Enhanced measures may be required where, for example:
there is suspicion of ML/TF/PF;
existing identification information appears unreliable;
the transaction may involve proceeds of crime;
the customer or beneficial owner is a PEP; or
other higher-risk factors exist.
Enhanced measures can include obtaining additional customer information, establishing source of funds or wealth, obtaining more information about the transaction and applying enhanced management oversight.
6. Identify and Verify Beneficial Owners
For corporate customers, it is not enough to know the name of the company.
DNFBPs are required to identify the natural persons who ultimately own or control legal persons or arrangements and take reasonable measures to verify those individuals using reliable information.
Where ownership is not straightforward, the business may need to look through corporate layers to determine:
Who ultimately owns this company?
Who exercises actual control?
Is somebody acting on behalf of another person?
Beneficial ownership is particularly relevant to businesses such as lawyers, accountants, company-service providers, real-estate businesses and consultants, where customers may transact through corporate structures.
7. Screen Customers for Sanctions and PEP Exposure
DNFBPs also have obligations relating to sanctions and politically exposed persons.
The 2024 Regulations require customer transactions to be screened against the United Nations Consolidated List and Nigeria Sanctions List, with targeted financial sanctions implemented where applicable.
DNFBPs should therefore have processes capable of identifying whether customers, beneficial owners or relevant related parties are subject to applicable sanctions.
PEPs also require additional attention.
Where the customer or beneficial owner is a PEP, enhanced due diligence is required. The Regulations additionally require reporting of transactions conducted for or on behalf of PEPs to SCUML monthly, with Nil Reports where applicable.
8. Monitor for Suspicious Activity and File STRs
DNFBPs must be able to identify transactions or activities that may indicate money laundering, terrorist financing or proliferation financing.
The Regulations identify potentially suspicious activity as including transactions that:
are unusual because of their size, volume, type or pattern;
resemble known money-laundering methods;
are inconsistent with the customer's legitimate or normal activity; or
lack an obvious economic justification.
Suspicious transactions — including attempted transactions — must be reported regardless of amount.
The NFIU currently states that reporting entities should file an STR immediately and no later than 24 hours after establishing reasons for suspicion.
For DNFBPs, STRs are currently filed through the NFIU's RapidAML platform.
Employees should also understand the prohibition against tipping off a customer that an STR has been or will be filed.
9. File Currency Transaction Reports
DNFBPs also have threshold-based reporting obligations.
Under the 2024 Regulations, transactions exceeding:
- ₦5 million for an individual; or
- ₦10 million for a body corporate
must be reported to SCUML within seven days of the transaction.
This reporting obligation is independent of whether the transaction itself is suspicious.
A transaction can therefore generate a CTR because of its value and, separately, an STR if there are reasonable grounds for suspicion.
10. Understand Cash-Based Transaction Reporting
A particularly important obligation for DNFBPs is the Cash-Based Transaction Report (CBTR).
Under the 2024 Regulations, DNFBPs must complete the prescribed reporting process for cash transactions exceeding US$1,000 or its equivalent and submit the required information to SCUML within seven days.
This is especially relevant to businesses that regularly accept cash, including certain dealers, hospitality businesses and other high-value or retail businesses.
An important 2026 reporting change
Since 1 January 2026, SCUML no longer accepts CTRs and CBTRs by email.
DNFBPs are required to submit these reports through the SCUML portal.
This means businesses should ensure that the appropriate compliance personnel have working portal credentials and that reporting processes reflect the new channel.
11. Maintain Required Records
AML compliance needs to be auditable.
The 2024 Regulations require DNFBPs to maintain necessary domestic and international transaction records for at least five years following completion of the transaction.
Records should include relevant CDD information, customer risk profiles, identification documents, transaction details, business correspondence and the results of relevant analysis.
The records should also be sufficient to allow transactions to be reconstructed and should be retrievable promptly when requested by competent authorities.
Where records relate to an investigation or disclosed transaction, the retention period may extend for at least five years after the relevant case has been closed.
12. Train Employees and Test the Compliance Programme
Employees are often the first people in a DNFBP to encounter unusual customer behaviour.
Training is therefore an explicit part of the compliance framework.
The 2024 Regulations require AML/CFT/CPF training and retraining and also require DNFBPs to submit their annual employee training programme to SCUML by 31 March each year.
The AML programme should also undergo independent testing.
The Regulations contemplate regular independent review, which can be undertaken internally by suitably competent audit personnel or externally by an appropriately qualified AML/CFT/CPF consultant.
The objective is to assess whether the controls actually work — not merely whether policies exist.
Compliance Is Increasingly Being Enforced
DNFBP compliance should not be treated as theoretical.
SCUML has authority to conduct off-site reviews, on-site inspections and spot checks, and to take enforcement action for non-compliance.
The 2024 Regulations also establish administrative sanctions for breaches and contemplate possible suspension, withdrawal or revocation of professional licences in cases of persistent and deliberate non-compliance, through the relevant self-regulatory or licensing body.
In 2025, the EFCC publicly warned DNFBPs that ignorance of the newer AML requirements would not excuse non-compliance and called for stronger internal controls across the sector.
The practical message is clear:
DNFBPs are expected to be able to demonstrate an operating AML/CFT/CPF compliance programme — not simply possess a SCUML certificate.
A Practical DNFBP AML Compliance Checklist
At a minimum, a DNFBP should be able to answer yes to questions such as:
Are we registered with SCUML?
Have we documented our ML/TF/PF risk assessment?
Do we have current AML/CFT/CPF policies and procedures?
Have we appointed an appropriate Compliance Officer?
Do we identify and verify our customers?
Do we identify beneficial owners where applicable?
Do we apply enhanced due diligence to higher-risk relationships?
Do we screen customers and beneficial owners against relevant sanctions and PEP lists?
Can employees recognise and escalate suspicious activity?
Can we file STRs through RapidAML?
Can we file CTRs and CBTRs through the SCUML portal?
Are required PEP and Nil Reports being filed?
Are customer and transaction records retained for the required period?
Do staff receive appropriate AML/CFT/CPF training?
Is our AML programme independently reviewed and tested?
If the answer to several of these questions is no, the business may have a meaningful compliance gap.
How Regfyl Can Support DNFBPs
For many DNFBPs, the challenge is not understanding that AML obligations exist.
It is implementing those obligations consistently without turning every customer interaction into a manual compliance exercise.
Regfyl can support businesses with key parts of the AML/CFT/CPF lifecycle, including:
Customer and Business Due Diligence
Verify individuals and businesses and maintain relevant onboarding information within a structured compliance workflow.
Beneficial Ownership
Identify the natural persons behind corporate customers and incorporate beneficial ownership information into the wider risk assessment.
Sanctions and PEP Screening
Screen customers, beneficial owners and other relevant parties against sanctions, PEP and other risk data, with ongoing monitoring where appropriate.
Risk Assessment
Apply risk-based customer classifications so that higher-risk relationships receive additional scrutiny.
Transaction and Activity Monitoring
Apply configurable monitoring rules and identify transactions or behaviours requiring compliance review.
Investigation and Case Management
Move alerts and unusual activity into structured investigation workflows, retaining decisions, supporting evidence and audit trails.
Compliance Governance
Use compliance calendars, tasks and controlled workflows to keep track of recurring requirements such as policy reviews, training and regulatory reporting deadlines.
AML Training
Provide organisation-wide AML/CFT training so employees understand the risks relevant to their roles and know how to escalate concerns.
Technology does not remove the responsibility of the DNFBP or its compliance officer.
It can, however, make the underlying process considerably more consistent, traceable and scalable.
Is Your DNFBP Ready for a SCUML Compliance Review?
A useful question is not simply: “Are we registered with SCUML?”
It is: “If SCUML reviewed us tomorrow, could we demonstrate our risk assessment, CDD, screening, reporting, training, records and compliance controls?”
If not, that is where the compliance work should begin.
See how Regfyl can help your business build a more structured AML/CFT/CPF compliance programme.
Book a DNFBP Compliance Review