CBN vs SEC vs NFIU: Navigating Overlapping Regulator Jurisdiction
When your product triggers multiple regulators — and how to engage without contradiction.
The question "who regulates us?" rarely has a single answer for Nigerian fintechs. A platform that lets users buy Bitcoin with naira, hold tokens in a wallet, and trade against other users may trigger three regulators simultaneously — each with different frameworks, different application processes, and different expectations.
Understanding overlap is not academic. It determines your licensing path, your AML architecture, your bank account strategy, and your investor narrative.
Why jurisdictions overlap
Nigerian financial regulation divides supervision by activity type, not by industry label:
- CBN supervises payment systems, monetary instruments, and banking relationships
- SEC Nigeria supervises securities, capital market activities, and digital asset service providers
- NFIU supervises AML/CFT compliance across all financial institutions and designated non-financial businesses — including VASPs
A single product can perform activities that fall under multiple mandates. Oturu's framework in Fintech Law and Practice in Nigeria identifies this as the central structural challenge for Nigerian fintech regulation.
Common overlap scenarios
Scenario 1: Exchange with naira on/off-ramp
- SEC — DAX registration for secondary market trading
- CBN — VASP bank account guidelines, payment system rules for naira flows
- NFIU — AML/CFT framework, goAML registration, STR filing
Scenario 2: Tokenised investment product
- SEC — DAOP or RATOP registration for primary issuance
- NFIU — AML programme for investor onboarding and transaction monitoring
- NITDA — NDPA 2023 compliance for investor personal data
Scenario 3: Custody wallet with payment features
- SEC — DAC registration for asset safekeeping
- CBN — Payment facilitation if naira balances are held
- NFIU — Full AML/CFT compliance framework
How to navigate without contradiction
- Classify first — map every product function to its regulatory category
- Identify primary regulator — usually the one governing your core revenue activity
- Build a unified compliance programme — one AML framework serving all regulators (NFIU expectations satisfy SEC and CBN AML requirements)
- Engage both regulators early — pre-screening meetings, documented correspondence
- Use consistent product descriptions — do not tell SEC one story and CBN another
Contradictory regulator engagement is a red flag in due diligence. Investors and regulators both notice when your SEC filing describes an exchange and your CBN correspondence describes a "technology platform."
The unified AML approach
NFIU's AML/CFT Compliance Framework for VASPs (December 2024) provides the baseline. A well-built AML programme — BWRA, policy manual, KYC tiers, transaction monitoring, MLRO, goAML registration — satisfies AML expectations across SEC and CBN oversight.
Build one programme. Document it thoroughly. Reference it in every regulatory engagement.
How Klarify helps
- Product Classifier — identifies dual-licence requirements and all applicable regulators
- FounderCounsel — ask about specific overlap scenarios with citations
- Compliance Roadmap — parallel tracks for SEC registration, CBN engagement, and NFIU AML setup
- Regulator CRM — log interactions with each regulator separately, export engagement summary
This is regulatory information and operational guidance — not legal advice. Multi-regulator strategies should be designed with qualified Nigerian fintech regulatory counsel.
This article adapts themes from Chapter 2 of Fintech Law and Practice in Nigeria (Oturu). Klarify provides regulatory information, not legal advice. For advice specific to your situation, consult a qualified practitioner.
Take action with Klarify
Turn regulatory guidance into a structured readiness plan — classification, roadmap, and investor-ready documentation.
Klarify provides regulatory information, not legal advice. For advice specific to your situation, consult a qualified practitioner.