CBN's baseline standards for automated AML: preparing your stack
The CBN's baseline standards, issued on 10 March 2026, set mandatory minimum requirements for automated systems that detect, analyse and report suspicious activity in real time. The CBN has said compliance is assessed at the level of the institution, so buying a tool is a start, not an answer.

Charles Archibong, Co-founder
· 6 min read

Key takeaways
- The CBN issued baseline standards for automated AML/CFT/CPF solutions in a circular dated 10 March 2026.
- They set mandatory minimum requirements for real-time detection, analysis and reporting of suspicious activity.
- A 31 March 2026 guidance note said compliance would be assessed at the level of the financial institution.
- Map each requirement to a control, an owner and evidence; a vendor contract alone is not evidence.
The Central Bank of Nigeria (CBN) issued baseline standards for automated anti-money laundering, counter-terrorist financing and counter-proliferation financing (AML/CFT/CPF) solutions in a circular dated 10 March 2026. According to the CBN's own summary, they set "mandatory minimum requirements for automated monitoring systems capable of delivering real-time detection, analysis, and reporting of suspicious financial activities", and they apply to banks, mobile money operators, international money transfer operators, other financial institutions and payment service providers.
The most useful line for planning came three weeks later. A CBN guidance note dated 31 March 2026 said compliance "would be assessed at the level of the financial institution". Read plainly, a firm cannot point to a vendor's product and call the job done. It needs to show that its own detection, analysis, reporting and governance meet the standard, with evidence.
This article draws on the CBN's published summaries. It is general information, not legal advice, and it is not a substitute for the circular. Read the circular and the guidance note yourself for the full requirements and the implementation dates that apply to your type of institution.
What exactly has the CBN issued?
Three documents in the CBN's circulars index (opens in a new tab) belong together:
Date | Document | Reference |
|---|---|---|
21 May 2025 | Exposure of Draft Baseline Standards for Automated AML Solutions | BSD/DIR/CON/AML/018/033 |
10 March 2026 | Issuance of Baseline Standards for Automated AML Solution for Financial Institutions in Nigeria | BSD/DIR/PUB/LAB/019/002 |
31 March 2026 | Implementation of the Baseline Standards for Automated AML/CFT/CPF Solutions | CMD/DIR/PUB/CIR/001006 |
The CBN's Reforms and Initiatives page (opens in a new tab) describes the 10 March circular as jointly signed by the Director of Banking Supervision and a Deputy Director of the Compliance Department. It describes the 31 March document as a guidance note issued "to avoid the growing risk of misinterpretation of regulatory expectations", which clarifies the CBN's expectations and addresses "key areas of potential misinterpretation".
If your team has only read press summaries of the March circular, read the guidance note before planning. The CBN says it issued the note following the industry's response to the standards, to avoid misinterpretation of what it expects.
What do the standards cover, in the CBN's words?
From the CBN's summary, three capabilities sit at the centre: detection, analysis and reporting of suspicious activity, delivered by automated systems in real time. The summary also frames the standards as a way to strengthen "the integrity of the nation's financial system".
Two other CBN developments from March 2026 point the same way, and are worth reading together:
A circular dated 12 March 2026 on instant payments requires financial institutions to "deploy real-time enterprise fraud monitoring systems and strengthen identity verification for online account opening and reactivation", effective 1 July 2026, according to the same CBN page.
A circular dated 12 March 2026 amends the BVN framework, including a temporary watchlist for BVNs linked to suspicious transactions.
The existing reporting duty has not moved. Section 7 of the Money Laundering (Prevention and Prohibition) Act 2022 (opens in a new tab) requires a written report with reasons, and a report to the NFIU, within 24 hours after a suspicious transaction. Real-time detection matters partly because that clock does not wait for a batch job.
How should you run a gap assessment?
Because compliance is assessed at the institution level, structure the work around controls you own, not around products. The areas below are a planning aid drawn from the CBN's summary and from how monitoring programmes usually fail. They are not a restatement of the standard's own sections, so align them to the circular's structure once you have it in front of you.
Area | Question to answer | Evidence a supervisor could ask for |
|---|---|---|
Data coverage | Does every channel that moves money feed the monitoring system, with the fields the rules need? | A channel inventory mapped to event feeds |
Real-time detection | Which transactions are scored before or as they complete, and which only after the fact? | Latency by channel; rules in force |
Rule design | Does each rule trace to a risk in your ML/TF/PF risk assessment? | Rule register linked to the risk assessment |
Analysis | Are alerts triaged, grouped and investigated with recorded outcomes? | Alert and case records with rationales |
Reporting | Can a report reach the NFIU within the legal timeline? | Case-to-STR timings; goAML submission records |
Screening | Are customers and counterparties screened at onboarding and on an ongoing basis? | Screening logs and adjudication records |
Change control | Are rule and threshold changes tested, approved and versioned? | Test results, approvals and version history |
Governance | Who owns the system, reviews its performance and reports to the board? | Terms of reference, minutes, performance reports |
Vendor oversight | Where a vendor supplies the system, how do you validate it? | Due diligence, validation results, contract terms |
Work through each row and mark it as met, partly met or not met, with an owner and a date. Start data coverage and change control early: both depend on engineering work that a compliance team cannot do alone.
A worked example: a PSP with three channels
Take an illustrative payment service provider with a mobile app, a merchant collection API and an agent network.
The app and API already send every transfer to a monitoring engine, scored before settlement.
The agent network sends a daily file, so cash-in and cash-out are reviewed a day late.
Rules were set up at launch and have not been reviewed since. Nobody can say which risk the "round amount" rule covers.
Alerts are worked in a shared inbox, and STRs are typed into the NFIU portal by hand.
A gap assessment would flag the agent channel under real-time detection, the rule set under rule design and change control, and the inbox under analysis and reporting. The fixes are specific: move agents to event-level feeds, write a rule register, and move casework into a system that keeps outcomes and timings. None of those fixes is "buy a new tool", even if a tool is part of the answer.
Where can Myaza Trust help, and where can it not?
Myaza Trust provides components that map to several rows above. It does not make an institution compliant with the CBN standards, and whether any configuration meets them is a judgement for your compliance function and, ultimately, the CBN.
Real-time detection and rule design: Transaction Monitoring scores events as they happen, returns ALLOW, REVIEW or BLOCK with the rules that fired, and supports custom rules written as data. Where it is enabled, the Fraud Monitoring API accepts transactions with sender and recipient details.
Change control: rule changes can be tested against stored events before saving, and published rules are kept as immutable versions, so a past decision points to the rule that made it. See the monitoring rules documentation.
Analysis and reporting: alerts roll up by customer, investigations record owners, deadlines and outcomes, and SAR or STR drafts are generated in goAML format for export and submission, with the drafter unable to file their own report. See investigations and reporting.
Screening: Watchlist Screening covers sanctions, PEP and adverse media at onboarding and on a re-screening schedule.
Audit evidence: investigation and report actions are written to the organisation's audit log with the actor and timestamp.
Data coverage, governance, board reporting and vendor oversight stay with you. So does the question of whether your configuration of any system meets the standard.
What to do this quarter
Download the 10 March circular and the 31 March guidance note, and record the implementation dates for your institution type.
Name an accountable owner for the programme, reporting to the board.
Run the gap assessment above against the circular's own structure.
Fix data coverage first: a channel that does not feed monitoring cannot be monitored in real time.
Put rule and threshold changes under test, approval and versioning.
Measure case-to-report time against the 24-hour duty in the Money Laundering Act.
Keep the evidence as you go. Compliance assessed at the institution level will be assessed on what you can show.
Sources

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


