Building Your AML/CFT Framework From Scratch (Before Your First STR)
BWRA, AML policy, MLRO appointment, and goAML registration — the minimum viable AML programme for Nigerian fintechs.
Anti-money laundering compliance is not a checkbox you complete before your Series A. Under the Money Laundering (Prevention and Prohibition) Act 2022 and NFIU's AML/CFT Compliance Framework for VASPs, it is a legal obligation from the moment you begin handling customer transactions.
The Founder's Guide is direct: the founders who survive regulatory scrutiny are those who build AML infrastructure before their first suspicious transaction report — not after a regulator asks why they never filed one.
The five foundations
1. Business-Wide Risk Assessment (BWRA)
Your BWRA is the analytical foundation of your entire AML programme. It identifies:
- Products and services offered
- Customer types and geographies
- Delivery channels (mobile, web, agent networks)
- Risk factors specific to your business model
The NFIU VASP Framework (December 2024) requires a documented, board-approved BWRA before operations commence. Review it annually.
2. AML/CFT Policy Manual
A board-approved policy covering:
- Customer due diligence (CDD) and enhanced due diligence (EDD) procedures
- Transaction monitoring thresholds and alert protocols
- STR and CTR filing procedures
- Record retention requirements
- Staff training programme
- MLRO responsibilities and escalation paths
3. MLRO Appointment
Under MLPPA 2022, Section 12, you must appoint a Money Laundering Reporting Officer. The MLRO is the single point of accountability for AML compliance — receiving internal reports, filing STRs with NFIU, and liaising with regulators.
4. NFIU goAML Registration
goAML is NFIU's reporting portal. Registration is required before you can file suspicious transaction reports. Test your STR and CTR filing workflow before you have a real alert to report.
5. KYC Tiering Framework
Tiered customer due diligence aligned to transaction limits:
- Tier 1 — NIN/BVN verification, basic identity
- Tier 2 — enhanced documentation, address verification
- Tier 3 — full due diligence for high-value or high-risk customers
Integrate NIN and BVN verification into your onboarding flow from day one.
The minimum viable AML programme
For a pre-launch fintech, "minimum viable AML" means:
- BWRA documented and board-approved
- AML policy manual in place (even if v1.0)
- MLRO appointed with written terms
- goAML registration initiated
- KYC tiers defined and integrated into product
- Transaction monitoring thresholds configured
- STR filing workflow tested (tabletop exercise)
This is not optional infrastructure. It is what NFIU, SEC, and CBN expect before scale.
Common early-stage mistakes
- Downloading a generic AML template without customising to your product risks
- Appointing an MLRO in name only — the role requires actual authority and access
- No transaction monitoring — manual review does not scale and is not defensible
- Delaying goAML registration — you cannot file STRs without it
How Klarify helps
- Document Generator — BWRA, AML_POLICY, KYC_TIERS, PEP_REGISTER, and STR_TEMPLATE
- Compliance Roadmap — Phase 2 AML tasks with dependency locking
- Readiness Score — AML/CFT programme dimension tracks all five foundations
- Compliance Calendar — STR filing deadlines, quarterly training, annual BWRA review
This is regulatory information and operational guidance — not legal advice. AML programme design should be reviewed with qualified AML compliance specialists.
This article adapts themes from Chapter 15 of The Founder's Guide to Building in Regulated Markets (Chuta, 2026). Klarify provides regulatory information, not legal advice. For advice specific to your situation, consult a qualified practitioner.
Take action with Klarify
Turn regulatory guidance into a structured readiness plan — classification, roadmap, and investor-ready documentation.
Klarify provides regulatory information, not legal advice. For advice specific to your situation, consult a qualified practitioner.