On 10 March 2026, the Central Bank of Nigeria issued its Baseline Standards for Automated AML/CFT/CPF Solutions, establishing minimum functional, governance and control requirements for automated AML solutions used by regulated financial institutions.
The Standards apply to banks, mobile money operators, international money transfer operators, other financial institutions and payment service providers, and are intended to strengthen the effectiveness, integration and governance of technology used to prevent and detect money laundering, terrorist financing and proliferation financing.
The initial implementation-plan deadline of 10 June 2026 has now passed, meaning financial institutions should be actively progressing their implementation programmes ahead of the applicable full-compliance deadlines.
In this article, we look at what the CBN requires, how Regfyl can support institutions implementing the Standards, and the governance responsibilities institutions must retain themselves.
Understanding the CBN Baseline Standards
The Standards go considerably further than requiring financial institutions simply to acquire AML software.
They establish detailed requirements around customer due diligence, screening, risk assessment, transaction monitoring, fraud monitoring, case management, reporting, auditability, integration, security and system configuration.
Importantly, on 31 March 2026 the CBN issued a further Guidance Note on Implementation clarifying that compliance is assessed at the level of the financial institution.
Technology is an enabler, but compliance depends on how the institution configures, governs, integrates and demonstrates the effectiveness of its control environment. The CBN expressly states that it does not approve, certify or endorse individual AML solutions or technology providers.
For institutions, the question is therefore not simply “Does our system have these features?” but:
Can we demonstrate that our AML technology is appropriately configured to our risk profile, properly governed, effectively integrated and producing defensible outcomes?
That distinction is central to implementation of the Standards.
How Regfyl Supports the Functional Requirements
Regfyl provides an integrated financial crime compliance platform covering the core functions addressed throughout Sections 5.1–5.12 of the Baseline Standards.
Customer Due Diligence, KYC and KYB – Section 5.2
The CBN requires AML solutions to link customer identity and due diligence information with customer risk profiles and transactional activity.
Investigators should be able to assess alerts in the context of the customer's identity, expected activity, risk classification and previous case history rather than reviewing transaction data in isolation.
Regfyl supports end-to-end customer risk assessment, ongoing customer profiling and consolidated customer views designed to bring relevant KYC/KYB, risk and transactional information into the investigation process.
Sanctions and PEP Screening – Section 5.3
The Standards require integration with appropriate domestic and international sanctions and watchlists, effective matching techniques, timely list updates, auditability, internal watchlists, PEP identification and adverse-media capabilities.
Regfyl supports sanctions, PEP, watchlist and adverse-media screening, together with configurable matching, internal lists and ongoing screening workflows.
Risk Assessment – Section 5.4
The CBN expects AML systems to reflect an institution's documented risk appetite and support both customer-level and enterprise-level ML/TF/PF risk assessment.
Where AI or machine learning is used, governance, human oversight and explainability become particularly important.
Regfyl enables institutions to configure risk methodologies, rules and thresholds in line with their own policies and risk appetite, while supporting dynamic reassessment as relevant customer and behavioural information changes.
Transaction Monitoring and Risk-Based Analysis – Section 5.5
The Standards require risk-based transaction monitoring that goes beyond simple static thresholds.
Monitoring should use appropriate customer and contextual data, support configurable scenarios and segmentation, and, where appropriate, incorporate anomaly detection, behavioural analysis, related-party mapping, network analysis and peer grouping.
Regfyl supports configurable transaction-monitoring scenarios, customer segmentation, behavioural analysis and contextual investigation workflows designed to help institutions identify and investigate unusual activity.
The CBN also imposes important institution-level responsibilities, including governance of false positives and false negatives, model validation where AI/ML is used, threshold review and change control. These responsibilities remain with the financial institution even when a third-party solution is deployed.
Fraud Monitoring and Detection – Section 5.6
The Standards recognise the relationship between fraud and financial crime while preserving the distinct objectives of AML and fraud controls.
Where AML technology is also used for fraud monitoring, institutions must ensure appropriate segregation, governance and integration between the two control environments.
Regfyl supports fraud monitoring alongside AML capabilities, helping institutions share relevant financial-crime intelligence while maintaining configurable workflows and controls.
Case Management – Section 5.7
Generating an alert is only the beginning of the compliance process. The CBN expects structured case-management capabilities covering assignment, prioritisation, investigation, escalation, review and audit trails.
Regfyl provides enterprise case-management workflows designed to help institutions manage alerts through investigation and resolution, including role-based access, review workflows, escalation and detailed activity records.
Reporting – Section 5.8
Financial institutions must be able to produce accurate and timely regulatory and management reporting, supported by appropriate review and approval processes.
The Standards specifically contemplate STRs, SARs, CTRs, FTRs and other relevant AML/CFT/CPF returns, together with management reporting for Compliance, senior management and the Board.
Regfyl supports structured regulatory-reporting workflows and management visibility designed to reduce manual processing while preserving review, accountability and auditability.
Audit and Governance – Section 5.9
Auditability is one of the strongest themes running through the Standards.
AML solutions must maintain comprehensive, tamper-resistant activity records covering configuration changes, access, alert decisions, reporting and other relevant system activities. Institutions must also establish documented governance around ownership, configuration, access, model validation and change management.
Regfyl maintains detailed system and user audit trails and provides governance functionality designed to support oversight, investigation and regulatory review.
System Integration and Scalability – Section 5.10
The CBN requires secure integration between AML solutions and relevant customer, KYC, core-banking and transactional systems.
The Guidance Note reinforces this requirement by warning that fragmented or partially integrated environments without robust automated integration will not meet regulatory expectations.
Regfyl is designed around API-enabled integration with institutional systems and supports both real-time and appropriate batch processing depending on the use case and regulatory requirement.
Security and Data Protection – Section 5.11
AML technology processes some of an institution's most sensitive customer and transactional information. The Standards therefore require controls around encryption, access management, authentication, data protection, resilience, recovery and information-security risk.
Regfyl incorporates security and access controls designed to support these requirements, including encryption, role-based access and multi-factor authentication.
User Interface and Customisation – Section 5.12
The CBN also recognises that AML technology must remain usable and configurable. Systems should provide appropriate dashboards, investigation interfaces and configurable workflows while allowing institutions to tailor rules and settings to their own business model, customers, products and risk profile.
Regfyl enables compliance teams to configure rules, thresholds, workflows and monitoring approaches to reflect institution-specific requirements.
AI Governance, ISO 42001 and Third-Party Risk
Section 6 of the Baseline Standards extends beyond functionality into vendor and technology governance.
Financial institutions must maintain appropriate third-party management arrangements, carry out heightened due diligence on AML technology providers and, where applicable, adhere to ISO 42001 and/or other relevant standards in the usage and governance of artificial intelligence.
Regfyl has achieved ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System, covering the management system supporting the design, development, maintenance and operation of its AI-enabled compliance platform and associated products.
For financial institutions, this provides an additional assurance point when assessing the governance of an AI-enabled technology provider. It does not remove the institution's own responsibility for AI governance, configuration, model validation or compliance with the CBN Standards.
Where Institutions Should Be Now
The implementation-roadmap deadline of 10 June 2026 has passed.
Institutions should therefore now be focused on execution: closing identified gaps, completing integrations, implementing governance structures, testing controls and assembling the evidence needed to demonstrate effectiveness to the CBN.
The CBN has made clear that supervisory assessment will focus not only on whether capabilities have been implemented, but whether institutions can demonstrate integration, governance, effectiveness and defensibility.
For Deposit Money Banks, full compliance is required within 18 months of the March 2026 issuance; for other financial institutions, the timeline is 24 months.
Assess Your CBN Baseline Standards Readiness
If your institution is implementing the Standards, the starting point should be a clear understanding of what has already been implemented, what remains outstanding and what evidence will be required.
Use our free CBN Baseline Standards Gap Assessment to assess your current environment and receive a tailored implementation guide.
If you would like to discuss your implementation programme and how Regfyl can support it:
Book a Baseline Standards Review