The regulatory architecture of Nigerian fintech: CBN licensing, NDPA data protection, AML/CFT and open banking The Regulatory Architecture
Graywhite Attorneys/Insights/Fintech Regulation

What Every Fintech Startup in Nigeria Must Know to Operate Legally and Safely

Daniel Udoka Esq.·8 July 2026·11 min read

Most fintech failures in Nigeria are not, at bottom, product failures. They are regulatory failures. A company builds a working payment flow, onboards users, moves real money, and only then discovers that it holds the wrong licence, or no licence at all, that it should have registered with the data protection regulator months earlier, and that the account balances it has been holding for customers were never lawful for a company of its category to hold.

Nigeria's fintech regime has moved decisively out of its permissive early phase. For most of the last decade the working assumption among founders was that you built fast, scaled aggressively, and treated compliance as something to fix once the business had traction. That assumption is now dangerous. The Central Bank of Nigeria issued more than a dozen policy changes affecting fintech across 2025, and 2026 is the year enforcement of those changes has arrived together: real-time transaction monitoring, authorised push payment fraud liability, open banking, and data-protection audit deadlines are all live or imminent at the same time. What follows is a working map of what a founder must satisfy to operate both legally and safely, organised in the order the questions actually arise.

01 — Licence CategoryIdentify the Licence Your Product Actually Needs

The single most consequential decision a Nigerian fintech makes is which CBN licence it applies for, and the most common early mistake is applying for the wrong one. The licensing framework is functional: it is tied to what your product does with money, not to what you call the product. Under the CBN's licence categorisation for the payments system, the categories a founder is most likely to be choosing between are these:

The distinction that catches founders most often is the line between a PSSP and an MMO. A PSSP moves money but cannot store it; an MMO can hold customer balances. If your product design involves customers loading value that sits with you until they spend it, you are operating a wallet, and holding those balances on a PSSP licence is a regulatory violation regardless of how the feature is labelled internally. The correct question is never "what do we want to call this," but "does our design cause us to hold customer funds, even briefly," because the answer dictates the category, and the category dictates everything downstream.

The licence is tied to what your product does with money, not to what you call it. If your design causes you to hold customer balances, you are operating a wallet, whatever the pitch deck says.

02 — Capital and Fit-and-ProperUnderstand the Cost of Entry Before You Commit

Licensing in Nigeria is not a matter of filing forms and waiting. Each category carries a capital threshold that must be demonstrably in place, and for the higher categories the sums are substantial: Switching and Processing and Mobile Money Operations each require capital in the region of two billion naira, while the payment solution categories sit lower. On top of the capital requirement sits a non-refundable application fee and, in most cases, an escrow deposit lodged with the CBN during the pendency of the application and returned, with any accrued income, once the process concludes.

Capital is only half of it. The CBN assesses the promoters and management against a fit-and-proper standard that examines education, experience, integrity, and the absence of relevant criminal history. Directors, significant shareholders, and key management are all in scope. A founder should treat the board and senior appointments as a regulatory matter from the outset, because a technically strong application can still fail on the character and competence assessment of the people behind it. The application itself is a substantial exercise: incorporation in Nigeria is mandatory, and the CBN expects a multi-year business plan, an articulated AML/CFT framework, IT security certifications including PCI-DSS where relevant, disaster recovery arrangements, data-protection policies, and a pre-submission engagement with the CBN's payments supervision function before formal filing.

03 — The SandboxUse the Regulatory Sandbox If Your Product Does Not Fit

Not every innovative product maps cleanly onto an existing category, and a founder confronting that gap has a legitimate route: the CBN Regulatory Sandbox. The sandbox allows a novel product to be tested in a live but controlled environment, under CBN supervision, without full licensing and without the associated minimum-capital burden during the test window. It is designed precisely for startups whose products do not fit the settled categories, and a successful sandbox cohort can use the results to support a subsequent full-licence application. The candour point for founders is that conversion from sandbox to full licence is not automatic and historically has not been high, so the sandbox should be treated as a structured path toward licensing, not as an indefinite operating status.

04 — Data ProtectionRegister and Comply Under the NDPA, Not Just the CBN

A founder who fixates entirely on the CBN misses the second regulator that governs every fintech in Nigeria: the Nigeria Data Protection Commission. The Nigeria Data Protection Act 2023, operationalised through the General Application and Implementation Directive 2025, imposes obligations that apply to any organisation processing the personal data of individuals in Nigeria, and its reach is extraterritorial, so a foreign-incorporated fintech serving Nigerian users is squarely within scope.

Fintechs are not treated as ordinary data handlers under this regime. In the NDPC's classification, financial-services firms and fintechs are expressly placed among the entities of major importance, with the most data-intensive of them sitting in the highest tier of obligation. That classification triggers a defined set of duties: registration with the NDPC as a data controller or processor of major importance, appointment of a Data Protection Officer whose details are filed with the Commission, engagement of a licensed Data Protection Compliance Organisation to conduct the annual audit, and filing of a Compliance Audit Return covering the prior year's processing activities. The NDPC has already moved from guidance to enforcement, issuing compliance notices to well over a thousand organisations and imposing penalties measured in hundreds of millions of naira, so registration and audit are not paper formalities.

Core NDPA Obligations for a Fintech

Registration — register with the NDPC as a data controller or processor of major importance, generally within six months of becoming one.

Data Protection Officer — appoint a qualified DPO and file their details with the NDPC.

Lawful basis and transparency — process personal data on a clear legal ground, for specified purposes, disclosed through a compliant privacy policy and record of processing activities.

Breach notification — notify the NDPC within seventy-two hours of becoming aware of a breach likely to affect data subjects, and notify affected users where the risk is high.

Compliance Audit Return — file the annual CAR through a licensed DPCO within the NDPC's filing window.

Cross-border transfer — where Nigerian user data is hosted or processed abroad, rely on an adequacy determination, binding contractual safeguards, or another lawful transfer mechanism, and document it.

Cross-border data flows deserve particular attention, because most fintechs run on cloud infrastructure that stores or processes data outside Nigeria. Moving Nigerian personal data offshore is only lawful where the destination affords adequate protection or an approved safeguard is in place, and those mechanisms must be mapped and documented before the data leaves, not reconstructed after a regulator asks.

05 — AML, KYC, and Fraud LiabilityBuild the Financial-Crime Controls Into the Product

A licensed fintech is a reporting entity in Nigeria's anti-money-laundering architecture, and the controls this requires cannot be bolted on after launch because they sit inside the onboarding and transaction flow itself. Risk-based customer due diligence anchored in BVN and NIN verification is mandatory, and suspicious transaction reports and cash transaction reports must be filed consistently with the Nigerian Financial Intelligence Unit. The CBN's move to mandatory real-time transaction monitoring, with baseline standards for automated AML solutions, means the monitoring obligation is now continuous rather than periodic, and the implementation timelines carry audit requirements with genuine consequences.

The most significant recent shift is on fraud liability. Under the authorised push payment fraud reforms, a fintech can now share or fully absorb the loss where a customer is manipulated into sending money to a fraudulent recipient, in some cases even where the customer personally initiated and approved the transfer. Liability can be apportioned between sending and receiving institutions according to where the control failure occurred, and an institution that failed to flag a suspicious account in the fraud chain can be held fully liable for the loss. For a founder, this converts fraud from a customer-service problem into a balance-sheet exposure, and it makes the quality of transaction monitoring and account-screening a direct financial matter, not merely a compliance checkbox.

06 — Open Banking and PartnershipsAccount for the New Rules on Data Sharing and Bank Relationships

Two structural features of the current environment shape how a fintech is built. The first is that only certain licence categories may hold customer funds, which means most fintechs necessarily operate through partnerships with licensed banks or intermediaries, and those partnership arrangements themselves require prior CBN approval rather than being purely commercial deals struck between the parties. The second is open banking: Nigeria's open banking framework, now moving into active enforcement, standardises how customer-permitted financial data is shared between institutions through defined interfaces, with implementation roadmaps and deadlines that founders integrating with bank data need to build toward rather than discover late.

07 — The Underlying PatternCompliance Is Architecture, Not Paperwork

The thread running through every one of these obligations is the same. The licence category is fixed by how the product handles money; the data duties are fixed by the fact that a fintech is, by classification, a major processor of personal data; the AML and fraud controls live inside the transaction flow; and the partnership and open-banking rules shape the technical architecture itself. None of this can be treated as a compliance layer added after the product is built, because each requirement reaches back into decisions made at the design stage. A fintech that maps its regulatory obligations before it writes its core flows spends far less, and carries far less existential risk, than one that builds first and reconciles with the CBN and the NDPC afterward.

Graywhite Attorneys advises fintech founders, payment companies, and their bank partners on licence selection and application, data-protection registration and audit readiness, AML/CFT frameworks, and regulatory engagement with the CBN and the NDPC.

Daniel Udoka Esq.

Managing Partner & Principal Counsel

Daniel Udoka Esq.

Daniel Udoka is the Managing Partner of Graywhite Attorneys, Nigeria's first law firm dedicated exclusively to banking and finance, with a litigation record spanning mortgage perfection and enforcement, banking fraud claims, and regulatory defence across all courts. He founded Terra Titles Limited, a title perfection and security documentation company, and is completing an LL.M at the University of Lagos in secured credit transactions.

Fintech & Regulatory Advisory

Launching or Scaling a Fintech in Nigeria?

Graywhite Attorneys advises fintech founders and their bank partners on CBN licensing, NDPA data-protection compliance, AML/CFT frameworks, and regulatory engagement.

Instruct the Firm