Nigeria’s banks are winning ground against identity fraud, and a sweeping change to anti-money laundering rules in Europe suggests where the next battle will be fought.
Losses to electronic payment fraud fell to 25.85 billion naira in 2025, down 51 percent from 52.26 billion naira in 2024, according to data from the Nigeria Inter-Bank Settlement System (NIBSS). The number of reported fraud cases also fell, to about 67,500.
NIBSS attributed much of the decline to tighter verification and coordinated industry controls, which it said prevented about 20 billion naira in potential losses.
The threat has not gone away. Social engineering remains the most common fraud technique, NIBSS said, and Lagos accounted for 63 percent of losses.
Regulators are responding. From May 1, 2026, the Central Bank of Nigeria (CBN) introduced amendments to the Bank Verification Number (BVN) framework, including a temporary fraud watchlist, stricter enrolment rules and limits on how often customers can change their personal data.
The reforms follow Nigeria’s exit from the Financial Action Task Force (FATF) grey list in October 2025, after more than two years of work to strengthen its anti-money laundering and counter-terrorist financing framework.
In Europe, a larger overhaul is under way. From July 10, 2027, the European Union’s
Anti-Money Laundering Regulation (AMLR) will apply directly in all 27 member states, replacing a patchwork of national laws with a single rulebook.
A new supervisor, the Anti-Money Laundering Authority (AMLA), has operated from Frankfurt since 2025 and will begin directly supervising some of the largest cross-border financial institutions in 2028.
The most significant change may not be in the rules themselves but in how firms must prove they follow them.
Under the new regime, banks are expected to show evidence that every alert was reviewed, who reviewed it, how long it took and why a case was closed or escalated. Written policies alone will carry little weight.
‘Nigeria has shown that tighter identity checks work. Fraud losses halved in a single year,’ said Teodor Rogojina, chief executive of Qoobiss, a Romanian RegTech company that works with banks and fintechs in Europe. ‘The next step, and the one Europe is now writing into law, is being able to prove to a regulator, on demand, exactly what happened with every customer and every alert.’
That approach relies on connecting systems that often sit apart. In many institutions, identity checks, sanctions screening and transaction monitoring run in separate tools, while investigations are tracked in spreadsheets and email.
European lenders are increasingly moving to platforms that bring those signals into a single case, with a full audit trail. Qoobiss offers one such tool, governance, risk and compliance software that pulls screening results, transaction alerts and identity events into one investigation workflow.
Identity verification is also changing. As fraudsters use generative AI to create fake documents and deepfake selfies, banks are layering document authentication, biometric face matching and liveness detection in a single automated check.
Qoobiss’s own identity verification product (qoobiss.com/products/ontrace) combines these checks and supports identity documents from a wide range of countries, including African passports.
The shift is visible closer to home too. Across the continent, African banks are already turning to digital identity verification to cut onboarding fraud as more customers open accounts remotely.
For Nigerian lenders, the European model carries a practical lesson. BVN and NIN integration has helped close the door on many fake identities at onboarding. The harder task now is monitoring what happens after an account is open, and documenting every decision along the way.
Analysts say that matters beyond domestic supervision. Nigerian banks and fintechs with operations in Europe, or with European correspondent banking partners, will increasingly be asked to show controls that meet the new EU standard.
‘Leaving the grey list was a major achievement,’ Rogojina said. ‘Staying off it, and building trust with international partners, will depend on being able to show that the controls work every single day, not just during an assessment.’