
When the Central Bank of Nigeria set firm deadlines for banks to move from manual, batch-based anti-money laundering controls to fully automated, real-time systems, it wasn’t just issuing another compliance circular. It was calling time on an entire way of working.
Nigerian financial institutions have mostly treated AML as something you clean up after the fact: a nightly batch job, a spreadsheet of flagged transactions, and a compliance officer working through a queue that never really gets shorter. The mandate says, plainly, that this is no longer good enough.
You don’t have to look far for proof of why. In August 2026, a Federal High Court in Lagos ordered 71 banks and fintechs to place debit restrictions on accounts allegedly holding part of the N1.34 billion that Access Bank says was moved out of customer accounts without authorisation through its SME internet banking app. Seventy-one separate institutions, tied to one incident, were ordered to check whether any of the money was still sitting in accounts on their books.
Further proceedings were adjourned to 31 August 2026, and the figures remain Access Bank’s own filing rather than a proven fact. But the shape of it is instructive regardless of how the case resolves: money moved fast enough and split across enough institutions that recovering it depended on dozens of banks checking their own systems after the fact and hoping the funds hadn’t moved again.
That is what “layering” looks like in practice, not as a textbook AML typology but as a live court filing.
That is the gap real-time detection is meant to close. Fraud rings don’t wait for a nightly batch job to run, and a compliance function that reviews yesterday’s transactions today is, in practical terms, reviewing money that has already left the building.
What the CBN is actually asking for
Beneath the regulatory language, the mandate has three concrete pillars every bank and payment institution needs to internalise. Real-time monitoring is now the baseline, not the ambition: screening has to run inside the live transaction path, at the moment of authorisation, not as an overnight batch. And identity has to be woven into the transaction decision itself, not parked in the onboarding form and forgotten. BVN and NIN data are expected to actively inform risk scoring on every transaction, not just tick a KYC box once at signup.
That second pillar is reinforced by BVN reforms that took effect on 1 May 2026: a temporary 24-hour watchlist for suspicious BVNs with mandatory customer contact before resolution, a hard limit of one phone-number change per BVN, and an 18+ age floor on enrolment. None of these are things a quarterly audit can catch after the fact; each has to be enforced programmatically, the moment a transaction or profile change happens.
The CBN’s own clock is unambiguous. Banks were required to submit an implementation roadmap by June 2026. Full automation compliance is due by September 2027, with other financial institutions given until March 2028. For an industry where a core banking upgrade routinely takes longer than eighteen months on its own, this isn’t a distant strategic goal. It is a delivery deadline, and for most institutions, the clock is already running.
Why “automated” rules alone won’t clear the bar
It would be a mistake to read the mandate as “digitise what we already do.” A rules engine firing on fixed thresholds (flag transfers above a set amount, flag more than a set number of transactions an hour) is technically automated. It isn’t intelligent, and it won’t hold up against how these typologies actually behave. Fraud rings structure transactions deliberately to sit just under static thresholds.
Meanwhile, genuine high-value customers get blocked by rules that were really built for the median account. You end up with the worst of both: real laundering slipping through the gaps between rules and false positives burying compliance teams in noise that has nothing to do with fraud.
A model that blocks a transaction without explaining why isn’t a compliance asset. It’s a liability waiting for an examiner to find it.
AI-enabled detection closes that gap because it learns the shape of suspicious behaviour instead of chasing a fixed number: the deviation from a customer’s own spending pattern, the network of shared devices and beneficiaries sitting behind a mule ring, the improbable sequence of a new device, a new beneficiary and a large transfer inside the same session, roughly the same pattern that shows up in almost every account-takeover case that ends up in front of a judge. Anomaly detection layered on top catches typologies nobody has labelled yet, which matters more than it sounds, because fraud tactics move faster than any rulebook gets revised.
None of that can be a black box, though. Regulators ask for the reason code, not just the decision. So every score needs a contributing factor an analyst can actually read, every hold needs an audit trail back to the data and the model version that produced it, and every high-risk action still needs a human who can review it and, if needed, override it. Done well, automation compresses the time from signal to decision from hours to milliseconds. It shouldn’t remove the human from a decision that affects whether a customer can touch their own money.
What readiness actually looks like
For a bank or PFI still working toward that compliance deadline, the honest checklist looks less like “buy AI” and more like a set of uncomfortable questions: Can we score a transaction in real time, inside the authorisation path, without adding latency nobody will accept? Does our BVN/NIN integration actually feed live risk scoring, or does it stop at onboarding?
Can we give a plain-English reason for every block, hold or SAR-worthy flag, with a data trail back to source? Is our model governance versioned and auditable enough to survive a CBN examination (training data, validation metrics, deployment approval, and rollback)? And is there a human in the loop for every high-risk action, so the automation speeds up investigation instead of replacing judgement altogether?
An institution that can answer yes to all five isn’t just compliant on paper. It’s already operating ahead of the fraud it’s supposed to be stopping, which, going by what played out at Access Bank in August 2026, is no small advantage to have.
Already built
This isn’t a hypothetical: Datalink Consulting Limited has already built an AI-powered fraud and AML intelligence platform around exactly this brief, real-time transaction scoring, BVN/NIN-aware risk profiling, explainable decisioning, full audit trails, and analyst case workflows, built from the ground up for the standard the CBN mandate sets.
Dr Osagie Kingsley Omoruyi is the Director of Innovation & Technology at Datalink Consulting Limited. He can be reached at [email protected].
Join BusinessDay whatsapp Channel, to stay up to date
Open In Whatsapp
Follow the story