Nigeria’s digital payment landscape is the clear leader on the African continent, with Flutterwave, OPay and Moniepoint having attained unicorn status. While this gargantuan leap has increased the volume of digital transactions exponentially and propelled economic activity, it has introduced its own fair share of regulatory challenges that outpace customary financial supervision.
Against this backdrop, the recent directive of the Central Bank of Nigeria (CBN) requiring banks, fintechs and payment service providers to disclose their ultimate beneficial owners (UBOs), localise payments data and comply with enhanced systemic oversight by 31st December 2026 is a welcome development. This may be viewed as part of a larger systemic response to tackling some of the vulnerabilities that scaling within the fintech space intrinsically attracts.
Objectives of the Directive
The directive signals a policy shift from the traditional regulation of individual financial services institutions to a holistic supervision of the national payments infrastructure, which bears systemic significance. It is submitted that three objectives easily emerge from this effort.
The first is lifting the veil of control. By requiring disclosure of ultimate beneficial ownership, the CBN seeks to isolate the natural persons who ultimately exercise influence over fintech companies. This is consistent with anti-money laundering international best practices in the payment industry that frown at operators operating behind opaque ownership structures. Regulatory and investor confidence progressively rely not only on financial soundness but also on transparency of control.
Secondly, the directive prioritises technological self-reliance and digital sovereignty. Payment and financial data have become economic and strategic assets. By requiring Nigerian payment data to reside within the country, the apex regulator is mandating that data produced by Nigeria’s financial system should remain subject to Nigerian regulatory oversight. This is quite instructive. It is designed to facilitate data storage, enhance supervisory access, strengthen cyber robustness, improve investigative capability, mitigate offshore regulatory risks and enhance jurisdictional autonomy.
Thirdly, the framework acknowledges the risk of systemic concentration. Given the limited number of platforms that now process large transactions, the stability of the financial system could be disrupted if those platforms are not resilient enough. The directive therefore asserts that business continuity, sound governance and market structure are no longer matters exclusively for the attention of individual stakeholders but issues of financial system equilibrium.
Impact on governance
From a governance perspective, boards are advised to factor the directive in their financial decision-making and not relegate it to a compliance checklist. Consequently, matters involving lifting the veil of ownership, cloud architecture, outsourcing of data infrastructure, oversight of technology risks and enterprise-wide data governance must now move from an operational standpoint to the boardroom. Directors who fail to integrate these concerns into governance architectures may soon face heightened regulatory scrutiny and reputational risk.
Cost of Compliance
Regarding fintech investors, the ramifications are equally far-reaching. Regulatory robustness typically engenders investor confidence by establishing definitive criteria and upgrading operational safeguards. However, compliance with localisation requirements comes at a price: an inevitable increase in capital allocation, particularly for fintech start-ups dependent on cross-border cloud infrastructure and technology providers. This will lead investors to place more importance on regulatory readiness during legal due diligence, while treating factors such as governance and compliance capabilities as indicators of enterprise value rather than mere legal obligations.
Critique
The objectives of the directives deserve plaudits. That being said, it is not without shortcomings. There is suspicion that localisation of data may unwittingly be viewed as being synonymous with data protection. This could not be further from the truth. The resilience of a cybersecurity framework is rooted more in governance, access controls, operational robustness, encryption and incident response capabilities than in the geographic footprint of servers. Cosmetic reliance on localisation of data without enduring security standards merely relocates risk rather than mitigate it.
Regulatory coherence is critical to the effective execution of the directive. The Nigeria Data Protection Act, the beneficial ownership disclosure regime under the Companies and Allied Matters Act and existing AML/CFT obligations must remain the guiding compass for its implementation. Scenarios in which there are overlapping reporting requirements and inconsistent regulatory expectations could inadvertently increase compliance costs without comparable regulatory benefits.
Conclusion
Ultimately, the CBN’s directive signals a positive evolution of Nigeria’s regulatory approach from a strictly compliance-based mindset to a more risk-centred one. It recognises that faith in the payments system is predicated not only on the strength of prudential regulation but also on transparent ownership, viable payments infrastructure and sovereign control over critical financial data.
Institutions that view these reforms as an opportunity to strengthen internal governance, modernise data storage facilities and integrate compliance adaptability into their business models will likely emerge stronger. In a swiftly evolving digital economy, a unique value proposition will be leveraged by not only those who innovate fastest, but also those who govern the technological disruption most effectively.

Simeon Oyakhilome Okoduwa is Managing Partner at The Timeless Practice
Follow Us on Google News
Follow Us on Google Discover
