High-Risk Customers Under Nigerian AML/CFT/CPF Rules: What Compliance Teams Must Know

A practical guide to high-risk customers under Nigerian AML rules, covering EDD, PEPs, non-residents, private banking, beneficial ownership and geographic risk.

High-Risk Customers Under Nigerian AML/CFT/CPF Rules: What Compliance Teams Must Know

Nigeria’s Anti-Money Laundering, Counter-Terrorist Financing and Counter-Proliferation Financing framework is built around a risk-based approach. Financial institutions are expected to assess the level of financial-crime risk presented by each customer and apply controls proportionate to that risk.

This means Customer Due Diligence should not look the same for every customer.

A low-risk retail customer may require standard due diligence, while a higher-risk customer, relationship or transaction may require Enhanced Customer Due Diligence (EDD), additional management oversight and more intensive ongoing monitoring.

The CBN Customer Due Diligence Regulations 2023 expressly require financial institutions to conduct an initial risk assessment for prospective customers and determine whether standard, simplified or enhanced CDD is appropriate. The Regulations identify categories including non-resident customers, money or value transfer service providers, private banking customers, non-face-to-face customers and Politically Exposed Persons among customers presenting higher-risk profiles.

For capital-market operators, the SEC AML/CFT/CPF Regulations also identify specific higher-risk customers, relationships and transactions requiring enhanced attention. These include non-resident clients, clients linked to high-crime locations, FATF high-risk jurisdictions, PEPs, complex legal arrangements, nominee-shareholder companies, cross-border relationships, wire transfers and non-face-to-face transactions.

Understanding these distinctions is important because “high risk” is not simply a label attached to a person. Risk may arise from:

  • Who the customer is
  • Where the customer or transaction is connected to
  • What product or service is being used
  • How the relationship is conducted
  • The ownership structure involved
  • The nature or pattern of the transaction

Compliance teams therefore need systems capable of evaluating the complete customer and transaction context.


What Does “High Risk” Mean Under Nigerian AML Rules?

A high-risk customer is one whose characteristics, activities, ownership, geography, products, delivery channels or transaction behaviour create an elevated exposure to money laundering, terrorist financing or proliferation financing.

Being classified as high risk does not mean the customer has committed a crime. It means the institution has identified factors that warrant greater scrutiny and stronger controls. Depending on the circumstances, Enhanced Due Diligence may involve:

  • obtaining additional customer information;

  • conducting additional identity verification;

  • obtaining more information about beneficial ownership;

  • establishing source of funds;

  • establishing source of wealth;

  • understanding the purpose of the relationship in greater detail;

  • obtaining additional information on expected activity;

  • conducting additional sanctions, PEP or adverse-media screening;

  • obtaining appropriate management approval;

  • applying more frequent customer reviews; and

  • applying enhanced ongoing transaction monitoring.

The exact measures should be proportionate to the particular risk presented.


1. Non-Resident Customers

The CBN Customer Due Diligence Regulations expressly identify non-resident customers among customers with higher-risk profiles. The SEC AML/CFT/CPF Regulations similarly identify non-resident clients as requiring greater caution and enhanced due diligence. 

Non-resident relationships can present additional challenges because the institution may need to verify:

  • foreign identity documents;

  • overseas addresses;

  • foreign businesses or employers;

  • foreign sources of funds;

  • tax residency;

  • beneficial ownership across jurisdictions; and

  • the legitimacy of cross-border transaction activity.

The customer’s country of residence also matters.

A customer resident in a well-regulated jurisdiction with transparent sources of funds may present a very different level of risk from a customer operating through jurisdictions with weak AML controls, elevated corruption risk or limited access to reliable identity information.

EDD should therefore go beyond simply tagging the customer as “non-resident”.

The institution should understand why the relationship exists, how funds are being generated and what cross-border activity should reasonably be expected.

2. Politically Exposed Persons

PEPs are among the most important higher-risk customer categories under Nigeria’s AML framework.

However, PEP treatment requires nuance.

The CBN’s PEP Guidance requires financial institutions to determine whether customers or beneficial owners are domestic PEPs, foreign PEPs or International Organisation PEPs and assess the level of risk associated with the relationship.

The Guidance states that most Nigerian domestic PEPs should be regarded as high risk by default because of the country’s corruption-risk environment, while still allowing a risk-based assessment for domestic and International Organisation PEPs. Foreign PEPs and higher-risk PEP relationships require Enhanced Due Diligence. 

PEP-related EDD may include:

  • senior management approval;

  • source-of-funds enquiries;

  • source-of-wealth enquiries;

  • enhanced monitoring;

  • more frequent reviews;

  • beneficial-owner screening; and

  • closer scrutiny of transactions involving family members and close associates.

PEP status itself does not mean the customer is involved in wrongdoing. The purpose of the controls is to manage the higher corruption and abuse-of-office risk associated with prominent public functions.


3. Private Banking Customers

Private banking relationships can involve large asset balances, cross-border transactions, investment structures and customers with complex financial affairs. The CBN Customer Due Diligence Regulations identify private banking customers among higher-risk customer profiles. 

An effective private-banking due-diligence process should therefore look beyond basic identification. Institutions should understand:

  • the identity of the customer;

  • beneficial owners;

  • source of funds;

  • source of wealth;

  • purpose and expected use of the relationship;

  • expected transaction volumes;

  • jurisdictions involved; and

  • whether the customer or beneficial owner is politically exposed.

Higher asset values alone do not establish criminality.

They do, however, increase the importance of understanding whether the customer’s financial activity is consistent with their legitimate wealth and economic profile.

4. Money or Value Transfer Service Providers

The CBN Customer Due Diligence Regulations also identify Money or Value Transfer Service providers among customers that may present higher-risk profiles.  These relationships can expose financial institutions to significant volumes of transactions involving multiple originators, beneficiaries and jurisdictions.

Where a financial institution provides services to a remittance, payment or money-transfer business, it should understand matters such as:

  • the customer’s licensing status;

  • nature of its business;

  • geographic exposure;

  • customer base;

  • transaction volumes;

  • AML/CFT/CPF framework;

  • sanctions controls;

  • transaction-monitoring capabilities; and

  • regulatory history.

The institution should also understand whether the provider's expected transaction activity is consistent with its business model.


5. Non-Face-to-Face Customers

The CBN’s 2023 CDD Regulations also identify non-face-to-face customers among higher-risk customer profiles, while separately recognising electronic KYC and digital onboarding requirements. 

Digital onboarding does not inherently mean that a customer is illegitimate. However, remote relationships may introduce risks around:

  • impersonation;

  • stolen identities;

  • synthetic identities;

  • falsified documentation;

  • account opening through intermediaries;

  • device manipulation; and

  • difficulty establishing the true person behind the application.

Financial institutions should therefore ensure that remote onboarding includes appropriate identity assurance and fraud controls. Depending on the business model, this may include biometric verification; authoritative identity checks; liveness detection; device intelligence; address verification; additional authentication; and enhanced checks where inconsistencies arise.

The relevant question is not simply: “Was the customer onboarded digitally?”

It is: “How confident are we that the person using the account is genuinely who they claim to be?”


6. Complex Legal Persons and Legal Arrangements

Complex corporate and legal structures can create elevated financial-crime risk where they make it difficult to determine who ultimately owns or controls assets.

Examples may include:

  • multi-layered corporate structures;

  • trusts;

  • personal asset-holding companies;

  • special purpose vehicles;

  • offshore companies;

  • structures involving multiple jurisdictions; and

  • arrangements where ownership and control are separated.

The presence of complexity does not automatically mean the structure is illegitimate. There are many valid commercial reasons for using holding companies, trusts and other legal arrangements. The risk arises where the complexity has no clear commercial rationale or obscures the natural persons exercising ultimate ownership or control.


7. Companies With Nominee Shareholders

Nominee arrangements can create additional beneficial-ownership risk because the registered shareholder may hold shares on behalf of another person.

The SEC Regulations expressly identify companies with nominee shareholders among higher-risk client categories for capital-market operators. 

Where nominee arrangements exist, the institution should not stop at the nominee’s name. It should identify and verify the natural person who ultimately owns or controls the interest.

The institution should also understand why the nominee arrangement exists and whether it is consistent with the customer’s commercial circumstances.

This is particularly important where nominee structures are combined with multiple corporate layers; offshore companies; trusts; PEP exposure; higher-risk jurisdictions; or unexplained movement of significant assets.

What About Bearer Shares?

Older Nigerian AML materials frequently refer to companies with bearer shares as higher-risk customers. However, the Companies and Allied Matters Act 2020 prohibits Nigerian companies from issuing bearer shares.

Bearer-share risk may still be relevant when dealing with foreign legal entities or structures originating from jurisdictions where such instruments remain possible, but it should no longer be presented as an ordinary Nigerian corporate structure.


8. Cross-Border Business Relationships

Cross-border relationships create additional AML/CFT/CPF complexity because they may involve:

  • multiple legal systems;

  • different standards of customer identification;

  • foreign intermediaries;

  • correspondent institutions;

  • cross-border ownership structures;

  • currency conversion;

  • different sanctions regimes; and

  • jurisdictions with varying levels of financial-crime risk.

The SEC Regulations expressly identify cross-border business relationships among higher-risk categories requiring enhanced attention. 

CBN AML guidance similarly recognises cross-border banking and business relationships as circumstances requiring enhanced consideration. 

Institutions should therefore understand both the customer and the jurisdictions through which funds or financial services are being provided.


9. Correspondent Banking Relationships

Correspondent banking is essential to the international financial system but can expose one financial institution to customers and transactions originating through another institution.

Financial institutions should conduct appropriate due diligence on correspondent relationships, understand the respondent institution’s business and reputation, assess its AML/CFT/CPF controls and apply enhanced measures where the risk warrants them.

Correspondent banking risk is therefore better understood as a higher-risk business relationship than simply another type of customer.


10. Customers or Transactions Connected to High-Risk Jurisdictions

Geographic risk is a core component of customer risk assessment. The FATF regularly identifies jurisdictions with significant weaknesses in their AML/CFT/CPF frameworks. However, compliance teams should distinguish between two different FATF categories.

High-Risk Jurisdictions Subject to a Call for Action

These are jurisdictions presenting particularly significant deficiencies. As of the FATF’s June 2026 statements, DPRK, Iran and Myanmar remain subject to a Call for Action. FATF calls for countermeasures in relation to DPRK and Iran and enhanced due diligence proportionate to the risks associated with Myanmar. 

These lists can change and should not be hard-coded permanently into institutional procedures. Compliance systems should use current FATF and regulatory information.

Jurisdictions Under Increased Monitoring

The FATF also maintains a separate list of jurisdictions under increased monitoring, commonly called the grey list. These countries have committed to work with the FATF to address identified strategic deficiencies. 

A grey-list designation should not simply be treated as identical to the FATF Call for Action list.

Institutions must consider the requirements imposed by their own Nigerian regulator and their risk-based framework.

For example, the SEC periodically issues circulars directing capital-market regulated entities on the specific measures to be applied to FATF-listed jurisdictions. In June 2026, the SEC prescribed specific restrictions for DPRK and Iran and enhanced due diligence and monitoring for relationships connected to Myanmar. 

Compliance teams should therefore monitor both: FATF updates and CBN, SEC or other regulator-specific directives

rather than relying on an old static country list.


11. Customers Connected to High-Crime Locations

For SEC-regulated capital-market operators, clients associated with locations known for elevated criminal activity, including drug production, trafficking or smuggling, are expressly identified among higher-risk categories.

Geographic risk assessment should nevertheless be evidence-based. Institutions should avoid simply labelling customers high risk because they come from a particular neighbourhood, State or region without a defensible risk basis.

Relevant considerations may include:

  • recognised financial-crime typologies;

  • law-enforcement intelligence;

  • national or sector risk assessments;

  • trafficking or smuggling corridors;

  • terrorism-financing exposure;

  • fraud concentrations;

  • sanctions exposure; and

  • reliable regulator or government advisories.

Geography should form part of the overall risk assessment rather than becoming a substitute for individual customer analysis.

12. Wire Transfers and Certain Transaction Types

The SEC AML/CFT/CPF Regulations identify wire transfers and non-face-to-face transactions among categories requiring greater caution. 

The reason is that transactions can themselves introduce risk even where the underlying customer would not otherwise have been considered particularly high risk.

This reinforces an important principle: Customer risk and transaction risk are related, but they are not the same thing.

A standard-risk customer can conduct a high-risk transaction. Likewise, a high-risk customer can conduct perfectly legitimate routine transactions.

The institution’s monitoring framework needs to account for both.


High Risk Is Not Static

A customer’s risk classification at onboarding should not remain unchanged indefinitely. Risk can increase or decrease as circumstances change.

The CBN requires financial institutions to apply CDD to existing customers based on materiality and risk and identifies significant transactions, unusual transactions, material changes in account operation and significant changes in customer profile as circumstances requiring renewed attention.

Customer risk assessment should therefore be a living process, not a one-time onboarding exercise.


What Should an Effective High-Risk Customer Framework Look Like?

A strong framework should enable the institution to answer questions such as:

  • Do we have clearly defined customer-risk factors?

  • Can we identify high-risk customers during onboarding?

  • Do we assess geographic, product, customer and delivery-channel risk?

  • Can we identify PEP and beneficial-ownership exposure?

  • Can we distinguish customer risk from transaction risk?

  • Are EDD requirements triggered automatically where appropriate?

  • Can we establish source of funds and source of wealth when required?

  • Is management approval captured where applicable?

  • Are high-risk relationships reviewed more frequently?

  • Can changes in risk trigger a reassessment?

  • Are higher-risk customers subject to appropriate ongoing monitoring?

  • Can compliance teams explain how each risk rating was determined?

  • Can the institution demonstrate the complete decision trail to its regulator?

A risk rating should lead to a different compliance response. If every customer receives essentially the same onboarding, review and monitoring process regardless of their risk rating, the institution does not have a meaningful risk-based approach.


How Regfyl Supports High-Risk Customer Management

Regfyl helps financial institutions connect customer risk assessment with KYC, KYB, screening, Enhanced Due Diligence, monitoring and investigations.

Automated Customer Risk Rating

Regfyl supports configurable customer risk-rating methodologies that allow institutions to assess customers using factors relevant to their own business and regulatory requirements.

These may include customer type; geography; product exposure; occupation or industry; delivery channel; PEP status; sanctions exposure; beneficial ownership; transaction characteristics; and other institution-specific risk factors.

PEP, Sanctions and Adverse-Media Screening

Customers and relevant related parties can be screened against PEP, sanctions and adverse-media information. Screening results can form part of the wider customer risk assessment rather than existing as an isolated compliance check.

KYB and Beneficial Ownership

For corporate customers, Regfyl supports business verification and beneficial-ownership identification, helping institutions understand the natural persons behind legal entities and identify risk hidden within corporate structures.

Enhanced Due Diligence Workflows

Higher-risk customers can be routed into additional review and approval processes. This can help institutions maintain evidence of additional information obtained; documentation reviewed; source-of-funds or source-of-wealth enquiries; escalation; review; approvals; and final decisions.

Ongoing Risk Monitoring

Customer risk should evolve as customer information and behaviour change. Regfyl can support ongoing screening and monitoring so that new information can trigger further review rather than waiting until the next scheduled manual assessment.

Transaction Monitoring

Customer risk information can provide important context for transaction monitoring. A transaction involving a higher-risk customer may warrant different thresholds, scenarios or investigative priorities from the same transaction conducted by a lower-risk customer.

Investigation and Case Management

Where customer behaviour or new information requires investigation, Regfyl provides structured case workflows for review, evidence, escalation, approvals and decision-making.

Supporting CBN Baseline Standards Implementation

Regfyl’s connected approach to customer risk profiling, PEP and high-risk profiling, screening, transaction monitoring, investigations and regulatory reporting can support financial institutions implementing the CBN Baseline Standards.

The objective is to move from a fragmented model where: KYC sits in one system, risk ratings in a spreadsheet, screening elsewhere and transaction monitoring in another application to a more connected compliance environment where customer risk informs the full AML lifecycle.


Is Your High-Risk Customer Framework Actually Risk-Based?

The objective of customer risk assessment is not simply to divide customers into Low, Medium and High categories. The important question is what happens after the customer receives that classification.

  • Does a high-risk customer receive more extensive due diligence?
  • Is beneficial ownership examined more closely?
  • Is source of wealth understood where required?
  • Does management approve relevant relationships?
  • Is the customer reviewed more frequently?
  • Does transaction monitoring reflect the additional risk?
  • Can the institution explain its decision to a regulator?

If the answer to those questions is unclear, the risk-rating framework may be functioning more as documentation than as an effective financial-crime control.

See how Regfyl can help your institution connect customer risk assessment, Enhanced Due Diligence, screening and ongoing monitoring within one compliance workflow.

See Regfyl Customer Risk Management in Action


Tags: #High-Risk Customers #Enhanced Due Diligence #EDD #Customer Risk Assessment #AML/CFT/CPF #CBN #SEC #Politically Exposed Persons #Beneficial Ownership #Financial Crime Compliance
← Back to Insights