Skip to content

CBN's baseline standards for automated AML: preparing your stack

The CBN's baseline standards, issued on 10 March 2026, set mandatory minimum requirements for automated systems that detect, analyse and report suspicious activity in real time. The CBN has said compliance is assessed at the level of the institution, so buying a tool is a start, not an answer.

Charles Archibong

, Co-founder

· 6 min read

Headline "CBN automated AML standards" beside an illustration of stacked verification cards, on a warm cream gradient.

Key takeaways

  • The CBN issued baseline standards for automated AML/CFT/CPF solutions in a circular dated 10 March 2026.
  • They set mandatory minimum requirements for real-time detection, analysis and reporting of suspicious activity.
  • A 31 March 2026 guidance note said compliance would be assessed at the level of the financial institution.
  • Map each requirement to a control, an owner and evidence; a vendor contract alone is not evidence.

The Central Bank of Nigeria (CBN) issued baseline standards for automated anti-money laundering, counter-terrorist financing and counter-proliferation financing (AML/CFT/CPF) solutions in a circular dated 10 March 2026. According to the CBN's own summary, they set "mandatory minimum requirements for automated monitoring systems capable of delivering real-time detection, analysis, and reporting of suspicious financial activities", and they apply to banks, mobile money operators, international money transfer operators, other financial institutions and payment service providers.

The most useful line for planning came three weeks later. A CBN guidance note dated 31 March 2026 said compliance "would be assessed at the level of the financial institution". Read plainly, a firm cannot point to a vendor's product and call the job done. It needs to show that its own detection, analysis, reporting and governance meet the standard, with evidence.

This article draws on the CBN's published summaries. It is general information, not legal advice, and it is not a substitute for the circular. Read the circular and the guidance note yourself for the full requirements and the implementation dates that apply to your type of institution.

What exactly has the CBN issued?

Three documents in the CBN's circulars index (opens in a new tab) belong together:

Date

Document

Reference

21 May 2025

Exposure of Draft Baseline Standards for Automated AML Solutions

BSD/DIR/CON/AML/018/033

10 March 2026

Issuance of Baseline Standards for Automated AML Solution for Financial Institutions in Nigeria

BSD/DIR/PUB/LAB/019/002

31 March 2026

Implementation of the Baseline Standards for Automated AML/CFT/CPF Solutions

CMD/DIR/PUB/CIR/001006

The CBN's Reforms and Initiatives page (opens in a new tab) describes the 10 March circular as jointly signed by the Director of Banking Supervision and a Deputy Director of the Compliance Department. It describes the 31 March document as a guidance note issued "to avoid the growing risk of misinterpretation of regulatory expectations", which clarifies the CBN's expectations and addresses "key areas of potential misinterpretation".

If your team has only read press summaries of the March circular, read the guidance note before planning. The CBN says it issued the note following the industry's response to the standards, to avoid misinterpretation of what it expects.

What do the standards cover, in the CBN's words?

From the CBN's summary, three capabilities sit at the centre: detection, analysis and reporting of suspicious activity, delivered by automated systems in real time. The summary also frames the standards as a way to strengthen "the integrity of the nation's financial system".

Two other CBN developments from March 2026 point the same way, and are worth reading together:

  • A circular dated 12 March 2026 on instant payments requires financial institutions to "deploy real-time enterprise fraud monitoring systems and strengthen identity verification for online account opening and reactivation", effective 1 July 2026, according to the same CBN page.

  • A circular dated 12 March 2026 amends the BVN framework, including a temporary watchlist for BVNs linked to suspicious transactions.

The existing reporting duty has not moved. Section 7 of the Money Laundering (Prevention and Prohibition) Act 2022 (opens in a new tab) requires a written report with reasons, and a report to the NFIU, within 24 hours after a suspicious transaction. Real-time detection matters partly because that clock does not wait for a batch job.

How should you run a gap assessment?

Because compliance is assessed at the institution level, structure the work around controls you own, not around products. The areas below are a planning aid drawn from the CBN's summary and from how monitoring programmes usually fail. They are not a restatement of the standard's own sections, so align them to the circular's structure once you have it in front of you.

Area

Question to answer

Evidence a supervisor could ask for

Data coverage

Does every channel that moves money feed the monitoring system, with the fields the rules need?

A channel inventory mapped to event feeds

Real-time detection

Which transactions are scored before or as they complete, and which only after the fact?

Latency by channel; rules in force

Rule design

Does each rule trace to a risk in your ML/TF/PF risk assessment?

Rule register linked to the risk assessment

Analysis

Are alerts triaged, grouped and investigated with recorded outcomes?

Alert and case records with rationales

Reporting

Can a report reach the NFIU within the legal timeline?

Case-to-STR timings; goAML submission records

Screening

Are customers and counterparties screened at onboarding and on an ongoing basis?

Screening logs and adjudication records

Change control

Are rule and threshold changes tested, approved and versioned?

Test results, approvals and version history

Governance

Who owns the system, reviews its performance and reports to the board?

Terms of reference, minutes, performance reports

Vendor oversight

Where a vendor supplies the system, how do you validate it?

Due diligence, validation results, contract terms

Work through each row and mark it as met, partly met or not met, with an owner and a date. Start data coverage and change control early: both depend on engineering work that a compliance team cannot do alone.

A worked example: a PSP with three channels

Take an illustrative payment service provider with a mobile app, a merchant collection API and an agent network.

  • The app and API already send every transfer to a monitoring engine, scored before settlement.

  • The agent network sends a daily file, so cash-in and cash-out are reviewed a day late.

  • Rules were set up at launch and have not been reviewed since. Nobody can say which risk the "round amount" rule covers.

  • Alerts are worked in a shared inbox, and STRs are typed into the NFIU portal by hand.

A gap assessment would flag the agent channel under real-time detection, the rule set under rule design and change control, and the inbox under analysis and reporting. The fixes are specific: move agents to event-level feeds, write a rule register, and move casework into a system that keeps outcomes and timings. None of those fixes is "buy a new tool", even if a tool is part of the answer.

Where can Myaza Trust help, and where can it not?

Myaza Trust provides components that map to several rows above. It does not make an institution compliant with the CBN standards, and whether any configuration meets them is a judgement for your compliance function and, ultimately, the CBN.

  • Real-time detection and rule design: Transaction Monitoring scores events as they happen, returns ALLOW, REVIEW or BLOCK with the rules that fired, and supports custom rules written as data. Where it is enabled, the Fraud Monitoring API accepts transactions with sender and recipient details.

  • Change control: rule changes can be tested against stored events before saving, and published rules are kept as immutable versions, so a past decision points to the rule that made it. See the monitoring rules documentation.

  • Analysis and reporting: alerts roll up by customer, investigations record owners, deadlines and outcomes, and SAR or STR drafts are generated in goAML format for export and submission, with the drafter unable to file their own report. See investigations and reporting.

  • Screening: Watchlist Screening covers sanctions, PEP and adverse media at onboarding and on a re-screening schedule.

  • Audit evidence: investigation and report actions are written to the organisation's audit log with the actor and timestamp.

Data coverage, governance, board reporting and vendor oversight stay with you. So does the question of whether your configuration of any system meets the standard.

What to do this quarter

  1. Download the 10 March circular and the 31 March guidance note, and record the implementation dates for your institution type.

  2. Name an accountable owner for the programme, reporting to the board.

  3. Run the gap assessment above against the circular's own structure.

  4. Fix data coverage first: a channel that does not feed monitoring cannot be monitored in real time.

  5. Put rule and threshold changes under test, approval and versioning.

  6. Measure case-to-report time against the 24-hour duty in the Money Laundering Act.

  7. Keep the evidence as you go. Compliance assessed at the institution level will be assessed on what you can show.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

  • Headline "The 2026 BVN rule changes" beside an illustration of tiles of identity number digits, on a warm cream gradient.

    Risk & Compliance

    CBN's 2026 BVN framework changes: what onboarding teams should note

    From 1 May 2026, under a CBN circular dated 12 March 2026, only adults can enrol for a BVN, the linked phone number can change only once, banks must hold BVNs tied to suspicious transactions on a 24-hour watchlist, and database access is limited to licensed institutions.

  • Headline "Rules that find risk, not noise" beside an illustration of a monitoring chart with spikes crossing a threshold line, on a warm cream gradient.

    Risk & Compliance

    Transaction monitoring rules that find risk instead of noise

    A monitoring rule earns its place when it maps to a risk you actually carry, fires on data you actually send, and produces alerts an analyst can close with a reason. Tune rules against labelled outcomes, never against alert counts alone.

  • Headline "From alert to decision" beside an illustration of a stack of case cards, on a warm cream gradient.

    Risk & Compliance

    From alert to decision: running an investigation queue that keeps up

    Keep two queues with two jobs. Triage alerts quickly and label every one; open an investigation only when the evidence needs an owner, group it by customer, prioritise by risk and deadline, and close it with a recorded outcome and rationale.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.

CBN automated AML baseline standards: how to prepare · Myaza Trust