As Nigeria’s financial technology sector grows in scale and sophistication, the systems designed to protect customers and prevent financial crime are facing an equally demanding test.
For fintech companies processing large volumes of transactions, compliance now extends far beyond meeting licensing requirements. It encompasses customer identification, transaction monitoring, anti-money laundering controls, fraud prevention, consumer protection, data privacy and an increasingly complex relationship with regulators and law enforcement agencies.
These responsibilities have become particularly important as digital financial services reach more Nigerians and fraudsters adopt increasingly sophisticated methods, including technologies capable of manipulating identities and circumventing traditional verification processes.
At OPay, much of the responsibility for navigating this environment falls within its compliance function.
In this interview with The Guardian, OPay’s Chief Compliance Officer, Chukwudinma Okafor, explains what happens behind the scenes to keep the fintech’s operations within regulatory requirements while protecting customers and the wider financial system.
Okafor discusses how OPay verifies customer identities, including the use of BVN and National Identification Number data, biometric verification and liveness checks, as well as the combination of automated monitoring and human analysis used to identify potentially suspicious transactions.
He also explains what happens when an account triggers a compliance alert, how the company responds to reports of unauthorised transactions, and why an alert should not automatically be interpreted as evidence of criminal activity.
The conversation also examines OPay’s consumer-protection tools, its engagement with the Central Bank of Nigeria and other regulatory authorities, and how compliance considerations are incorporated into new products before they reach customers.
Looking beyond the company, Okafor identifies two issues he believes will increasingly shape compliance across Nigeria’s fintech industry: greater regulatory scrutiny as fintechs become more important channels for financial transactions, and the need to modernise anti-money laundering and anti-fraud systems as artificial intelligence creates new risks.
He spoke with IFEANYI IBEH about these issues and what they could mean for the next phase of Nigeria’s rapidly evolving fintech industry.
For readers who may not fully understand the role of a Chief Compliance Officer in a fintech, what does your responsibility at OPay involve on a day-to-day basis?
I am responsible for ensuring that all the conditions for licensing are adhered to. This primarily includes complying with all regulations of the Central Bank of Nigeria, including rules related to Anti-Money Laundering/Combating the Financing of Terrorism/Combating Proliferation Financing (AML/CFT/CPF), Customer Due Diligence, Consumer Protection, and Data Privacy and Data Protection. On a daily basis, this includes ensuring that customers’ documentation is complete at onboarding and that customers are adequately monitored on an ongoing basis to ensure that their profiles are kept up to date. My role also involves liaison with regulatory authorities and cooperating with law enforcement agencies in their investigations. Also, I have to keep Management and the Board informed of all Compliance-related occurrences.
OPay operates at a scale where millions of transactions can take place across its platform. What does maintaining compliance at that scale actually require?
For the level at which OPay operates, world-class compliance standards are required. The Board provides full backing to Compliance and has ensured the deployment of technology that compares with the best globally to support the compliance function, while also ensuring that the Compliance Department has staff with adequate skills. Training is provided not just to Compliance staff but to all staff members, including Senior Management and the Board.
What does a strong compliance culture look like inside OPay, beyond simply meeting regulatory requirements?
Compliance culture is strong, backed by the Board and Management. For all employees, engagement with Compliance commences at onboarding. Also, Board-approved compliance policies are available to all staff. There are also established communication channels through which compliance matters can be escalated to the Compliance Team and Management. At OPay, Compliance is not just about meeting regulatory requirements. To ensure the sustainability of operations, compliance is designed into every procedure.
What technologies and processes does OPay use to ensure that the person opening or operating an account is genuinely who they claim to be?
OPay has integrated APIs to issuers of identity documents. The APIs have enabled the verification of identity data, such as the Bank Verification Number and National Identity numbers, directly from the issuers of the identity documents. Technology has also been deployed to confirm liveliness checks, and this ensures that still images cannot be used to open accounts.
How does OPay deal with attempts to circumvent KYC requirements, particularly through fake identities, multiple accounts or manipulated documentation?
OPay relies on a hybrid of automated verification systems and reviews by KYC analysts in verifying KYC documentation. OPay has integrations with the issuers of identity documents, and onboarding of customers involves verification of documents submitted. In addition to verification of documents, there is also biometric verification of consumers, which involves liveliness checks. KYC analysts also review and verify documents submitted by customers prior to approval. These controls ensure that attempts to circumvent KYC requirements are identified and onboarding of such parties is halted.
How does OPay monitor transactions for unusual or potentially suspicious activity?
A combination of automated tools. Monitoring rules are configured based on several red flag scenarios. Alerts generated by the automated tools are reviewed by analysts who have also been trained on the identification of suspicious transactions. Transactions deemed to be suspicious are reported and customer risk profiles are also updated based on their transaction activity.
What role does technology, including artificial intelligence or automated transaction monitoring, play in OPay’s anti-money laundering framework?
Technology plays a key role in transaction monitoring. Today, it is impossible for any financial institution to manually monitor transactions. Technology has been deployed to monitor transactions in real time. AML/CFT/CPF and anti-fraud rules have been deployed to ensure automated real-time monitoring. These rules are key in ensuring that transactions suspected to be linked to fraud and other financial crimes are prevented in real time.
What happens internally when a transaction or account triggers a compliance alert?
First, I must state that when transactions trigger a compliance alert, it does not immediately imply that the transaction is linked to criminal activity. Flagged transactions are confirmed if there are suspicions of criminal activity. Where no suspicions are found, then the alert is closed. However, where transactions are suspected to be linked to criminal activities, then actions taken include a reassessment of the customer profile and also reporting such transactions to all relevant parties as required by regulations and laws.
Fraudsters are constantly changing their methods. How does OPay ensure its compliance systems evolve quickly enough to stay ahead of emerging threats?
OPay proactively updates compliance systems to evolve in a manner that ensures the continued effectiveness of the controls. Also, transaction patterns are analysed periodically to identify and mitigate any new risks from new trends. Compliance systems and monitoring rules are also reviewed periodically to ensure new emerging threats are mitigated.
Compliance is not only about preventing financial crime. How does consumer protection feature in OPay’s compliance framework?
Consumer Protection is key in OPay’s prevention of financial crimes. OPay has deployed in-app security features that reduce the likelihood of customers losing funds to financial crimes. These security features such as large transaction shield and night guard require biometric verification before transfers are made. This ensures only the customers can authenticate withdrawals from their accounts. Other features, such as Emergency Lock, stop all withdrawals from customer accounts. Additionally, the USSD codes *955*131 and *955*132 allow OPay customers to block their accounts and cards, respectively. The USSD codes can be initiated with any phone line issued by the Nigerian Telcos. The USSD codes are particularly useful when there is a loss or theft of the customer’s phone or debit card. These USSD codes allow customers to independently stop all transactions without the need to contact OPay.
When a customer reports an unauthorised transaction, what happens behind the scenes?
When customers report unauthorised transactions, investigations are conducted in collaboration with the financial institution where funds were received. Efforts are made to recover funds lost due to unauthorised transactions. Punitive actions are also taken against parties that are the recipients of unauthorised transactions.
How does OPay engage with regulators to ensure that its operations remain aligned with Nigeria’s evolving financial regulations?
OPay has established communication channels with the Central Bank of Nigeria and other regulatory agencies. A cordial and professional relationship exists with the regulators, and the regulators are always open to engagement by operators like OPay. Clarification is always sought from regulators, and regulatory approvals are always obtained before launching new products.
What happens when a commercial objective conflicts with a compliance requirement?
At OPay, Compliance is a key consideration in all aspects of business and operations. Compliance is part of every new product and service from the ideation stage. This ensures that all commercial objectives are aligned with compliance requirements.
Conflicts in commercial objectives and compliance requirements are identified early and addressed. This ensures that products, services and operations are designed in a compliant manner with all necessary amendments made by the business teams in line with compliance rules.
Ultimately, all commercial objectives align with compliance requirements, and this alignment is key to sustained commercial growth.
How much does OPay invest in compliance, whether in technology, people, training or systems?
OPay has deployed world-class technology to support the Compliance function. Also, staff are trained on an ongoing basis to ensure that knowledge and skills remain up to date.
What do you see as the biggest compliance challenge for Nigeria’s fintech sector over the next three to five years?
Firstly, with the adoption of Fintechs, we are already experiencing increased regulatory compliance oversight from multiple government establishments. Fintechs must therefore improve regulatory compliance oversight to ensure coverage of regulations of all relevant government agencies. This is because, as fintechs become the primary channel for financial transactions, oversight by government agencies will increase. Fintechs must therefore be prepared to manage increased examination and supervision from regulatory authorities and other government agencies.
Also, there is the need for the modernisation of AML/CFT/CPF and anti-fraud measures due to the rapid advancements of AI models. Fintechs must therefore proactively implement measures to mitigate emerging risks from new and emerging technologies.
Follow Us on Google News
Follow Us on Google Discover