CBN Unveils Sweeping New Digital Banking Security Framework
The Central Bank of Nigeria has launched a comprehensive set of new regulations designed to significantly enhance security within the nation's rapidly evolving digital banking ecosystem. These directives, formally issued on March 12, 2026, introduce fresh controls over transaction limits, mobile application usage, and instant payment services, marking a pivotal shift towards greater consumer protection and fraud prevention.
Flexible Transaction Limits Within Regulatory Boundaries
A cornerstone of the new policy is the introduction of adjustable transaction limits for both individual and corporate banking customers. While the existing maximum thresholds of N25 million for individuals and N250 million for corporate entities remain firmly in place, customers now have the voluntary option to set lower limits based on their personal financial needs and risk tolerance.
Financial institutions are mandated to conduct thorough risk assessments and due diligence before approving any adjustments to a customer's transaction ceiling. This process is intended to ensure strict compliance with anti-fraud protocols and overall financial security standards, giving account holders more direct control while mitigating the risk of large-scale unauthorized transfers.
Enhanced Controls for Instant Payment Services
The regulatory framework also brings substantial changes to the operation of instant payment platforms, which have become integral to daily financial activities for millions of Nigerians. Banks are now required to provide customers with a clear and accessible mechanism to opt in or opt out of instant payment services at their discretion.
This feature must be safeguarded by robust multi-factor authentication (MFA) protocols to prevent unauthorized access and fraudulent transactions. By default, the opt-in setting will be automatically enabled for customers, with banks responsible for offering straightforward procedures for deactivation, thereby balancing convenience with enhanced security measures.
Stricter Digital Account Verification Procedures
In a decisive move to combat identity theft and fraudulent account creation, the CBN has mandated significantly stricter verification processes for online account openings and reactivations. Banks must now implement real-time liveness checks during these digital procedures to confirm the physical presence of the individual initiating the action.
Furthermore, all new accounts established through digital channels must undergo immediate validation against the official Bank Verification Number (BVN) and National Identification Number (NIN) databases. Regulators anticipate that these enhanced verification steps will dramatically reduce incidents of identity-related fraud within the banking system.
One-Device Restriction for Mobile Banking Applications
One of the most notable changes is the imposition of a strict one-device rule for mobile banking applications. Under the new directive, banks are prohibited from allowing a single banking profile to operate across multiple devices simultaneously. Each mobile banking app is now restricted to use on one device at any given time.
Should a customer switch to a new phone, the system will automatically trigger a fresh and comprehensive authentication process before granting access to banking services. This restriction is specifically designed to minimize account compromise and bolster the overall security framework of mobile financial services.
Temporary Transaction Caps on Newly Activated Devices
The circular also introduces a protective temporary transaction limit for newly activated mobile banking applications. For both new and existing accounts, a banking app activated on a new device will be subject to a maximum transaction cap of N20,000 within the first 24 hours of activation.
Financial institutions retain the authority to set even lower limits based on their internal risk management assessments. This temporary measure is strategically implemented to prevent fraudsters from executing large-sum transfers immediately after illicitly gaining access to a banking application.
These sweeping new rules represent the CBN's latest effort to tighten regulatory oversight of Nigeria's digital banking landscape. By introducing these measures, the apex bank aims to strike a careful balance between maintaining user convenience for millions of customers and implementing robust security protocols to safeguard the integrity of the financial system.



