An Overview of the Regulatory Framework of FinTech in Nigeria – Olayanju Phillips

INTRODUCTION

Since the global financial crisis of 2007, several banking regulatory reforms have been instituted in a bid to increase trust in the Nigerian banking sector and maintain stability in the financial industry. These regulatory reforms, however, did not anticipate the intrusion of technology in the delivery of financial services.

‘FinTech’ is a contraction of the words ‘financial’ and ‘technology’, which is broadly used to describe any technological innovation in the delivery of financial services. It covers a wide range of areas including financial literacy, wealth/asset management, lending and borrowing, retail banking, fundraising, money transfers, payments, investment management, digital insurance, and cryptocurrency.

The absence of a direct and unified regulation on FinTech in Nigeria has engendered the erroneous notion that the Nigerian FinTech industry is uncharted territory. However, notwithstanding the inexistence of a cohesive FinTech regulation, the Central Bank of Nigeria (CBN) has issued several guidelines, which impacts various aspects of the FinTech industry, especially the digital payments sub-sector which has witnessed the highest amount of activity in recent times. These regulations seek to improve financial inclusion while allowing for continuous innovation.

The purpose of this paper is to identify and examine the existing regulations in Nigeria’s FinTech industry and to canvass for a cohesive and comprehensive legislation for Fintech in Nigeria.

 

FinTech Regulatory Framework in Nigeria:

The Central Bank of Nigeria has issued the following guidelines which impact FinTech companies in Nigeria:

  1. Guidelines on Mobile Money Services in Nigeria
  2. Guidelines on Operations of Electronic Payment Channels in Nigeria
  3. Regulatory Framework for the Use of Unstructured Supplementary Service Data (USSD) for Financial Services in Nigeria.
  4. Guidelines on International Money Transfer Services
  5. Guidelines on International Mobile Money Remittance Service
  6. Exposure Draft of New CBN Licensing Regime for Payment Service Providers
  7. Regulation for Direct Debit Scheme in Nigeria

In addition to the above, the National Information Technology Development Agency (NITDA) recently issued the Nigerian Data Protection Regulation[2] which impacts the use, transfer, and processing of data of Nigerian citizens. The Central Bank of Nigeria has also issued the Risk-Based Cyber-Security Framework and Guidelines for Deposit Money Banks and Payment Service Providers,[3] which will be of importance to FinTech companies operating in Nigeria.

  1. Guidelines on Mobile Money Services

In 2009, the CBN issued the guidelines on mobile money services in Nigeria with the aim of ensuring a structured and orderly development of mobile money services in Nigeria. Basically, mobile money services are financial services offered over mobile devices, such as mobile payment, credit card payment, and QR code payment.

The guidelines identify two models for the implementation of mobile money services: Bank Led and Non-Bank Led.[4] Under the Bank Led model, either a bank or a consortium of banks may act as a Lead Initiator in providing mobile money services as part of its banking services.[5]

A corporate organization (other than a deposit money bank or telecommunication company) specifically licensed by CBN to provide mobile money services in Nigeria may also act as a Lead Initiator of mobile money services under the Non-Bank Led model.[6]

The guideline also identifies the various participants in the mobile money industry – Banks, licensed corporate organizations, infrastructure providers, Mobile Network Operators (MNOs), and consumers – their roles and responsibilities[7] and, the minimum technology standards[8] and business rules.[9]

Mobile Money Operators (MMOs) are required to:

  • Be licensed by the CBN.
  • Be issued a unique Scheme Code by the Nigerian Inter-Bank Settlement System.
  • Be issued unique short codes by the Nigerian Communications Commission (NCC).
  • Ensure that all telecommunications equipment are of a type approved by the NCC.
  • Register users of its scheme based on the technology standards and requirements of the guidelines.
  • Ensure that the registration process fulfills the Know Your Customer (KYC) requirements specified in the guidelines.[10]
  1. Guidelines on Operations of Electronic Payment Channels

The electronic payment guidelines provide specific regulations on the use and operations of the following e-payment channels: Automated Teller Machine (ATM),[11] Point of Sale (POS) machines,[12] Mobile Point of Sale (MPOS) devices[13] and the Internet.[14]

The guidelines are made to supersede the previous standards and guidelines on ATM operations and POS card acceptance services issued by the Central Bank of Nigeria (CBN).

The e-payment guidelines identify stakeholders in electronic payment, such as Acquirers, Issuers, Merchants, and Cardholders, and define their roles and responsibilities.[15]

It specifies the standards and specifications for ATM technology,[16] guidelines for ATM deployment,[17] minimum standards[18] and specifications[19] for POS terminals, minimum standards[20] and technical specifications[21] for MPOS devices, and minimum standards for gateway provider of web payment services.[22]

The guidelines also establish a settlement mechanism for POS and MPOS transactions[23] with the Nigeria Interbank Settlement Systems (NIBSS) acting as the Payment Terminal Service Aggregator for the financial industry.[24]

  1. Regulatory Framework for the Use of USSD for Financial Services in Nigeria

Taking effect from October 2018, the guidelines seek to reduce the risks associated with the implementation and use of USSD technology for offering financial services in Nigeria.[25]

Therefore, only Mobile Network Operators (MNOs) and CBN licensed entities with a letter of no objection or letter of introduction from the CBN are eligible for the issuance of USSD short codes by the Nigerian Communications Commission (NCC).[26]

A transactional limit of N100, 000 per customer, per day, is placed on all transactions conducted through the USSD channel, and a customer desirous of a higher limit will be required to execute a documented indemnity.[27]

The guidelines also require financial institutions providing use of the USSD channel to encrypt all USSD information[28] and offer customers the option to opt in/out of the USSD channel.[29]

Furthermore, no USSD channel shall be deployed for financial services unless a deactivation mechanism, which allows users to block their account from operating USSD services, is put in place.[30]

  1. Guidelines on International Money Transfer Services

The guidelines on international money transfer are important for International Money Transfer Service Operators (IMTSOs) that offer digital international money transfer services.

Any person or institution that wishes to provide international money transfer services must be licensed by the CBN.[31] Although deposit money banks are prohibited from operating as international money transfer service operators, they may act as agents.[32]

For the purpose of licensing requirements, the guideline makes provisions for four categories of international money transfer providers, to wit: Foreign International Money Transfer Operators, Indigenous International Money Transfer Operators, Foreign Technical Partners and Local Agents.

A foreign IMTO wishing to operate in Nigeria must have a minimum share capital of US$1 million in their home country[33] and a list of Licensed Agents, who are Authorized Forex Dealers, to act as local agents.[34] Furthermore, the foreign IMTO must pay a non-refundable application fee of N500, 000 (Five Hundred Thousand Naira), or such amount as the CBN may specify from time to time.[35]

On the other hand, an indigenous IMTO is required to have a minimum paid-up share capital of N2,000,000,000 (Two Billion Naira),[36] and the primary object clause of the company’s Memorandum of Association must indicate provision of money transfer services.[37]

An Indigenous IMTO may engage a foreign technical partner but must obtain the prior approval of the CBN before doing so.[38] The foreign technical partner must:

  • Be licensed in its home country to carry on international money transfer services.
  • Have a minimum net worth of US$10 million as contained in its current audited financial statement
  • Be well established and have a track record of operations in the money transfer services business.
  • Sign a Memorandum of Understanding with its Indigenous IMTO partner that clearly delineates liabilities in the event of disputes and/or process failures.[39]
  1. Guidelines on International Mobile Money Remittance Services

These guidelines were issued to facilitate foreign exchange transactions over mobile applications. It states the minimum standards and requirements for the operation of international funds remittance over mobile devices in Nigeria.[40]

In order to provide inbound or outbound international funds remittance service in Nigeria, an institution must be approved by the CBN to carry out such services.

The requirements for obtaining such approval include:

  • A licence in its home country to carry on money transfer services
  • A net worth of US$1 billion
  • A valid Mobile Money Operator’s licence
  • A presence in at least twenty countries with at least 10 years experience in the money transfer business[41]

The institution must also be in partnership with at least an Authorised Dealer bank licensed in Nigeria.[42]

The guideline identifies the participants in international money remittance as: banks, infrastructure providers, Mobile Network Operators and consumers, and states their roles and responsibilities.[43] It also provides transaction security standards[44] and risk management measures for operators.[45]

  1. Exposure Draft of New CBN Licensing Regime for Payment System Providers

In recognition of the growing level of acceptability of FinTechs and the attendant emerging risks within the financial system, the CBN recently proposed a new licensing regime for all categories of payment service providers and financial technology companies.

The regime proposes 3 licence categories of payment service providers: Super Licence, Standard Licence, and Basic Licence.

The Super Licence category, which has a tenor of 3 years, covers the following existing licence types:

  • Switching
  • Payment Solution Service Provider (PSSP)
  • Payment Terminal Service Provider (PTSP)
  • Non-bank Merchant Acquiring
  • Super Agency.

The Standard Licence category, which also has a tenor of 3 years, covers the following existing licence types:

  • Mobile Money Operators (MMO)
  • Super Agency
  • Non-bank Merchant Acquiring.

The Basic Licence category has a tenor of 2 years and covers the following existing licence types:

  • Super Agency
  • Payment Solution Service Provider (PSSP)
  • Payment Terminal Service Provider (PTSP)

Each of the three licence categories are required to have a minimum shareholder fund of N5, 000,000,000 (five billion naira), N3, 000,000,000 (three billion naira) and N100, 000,000 (one hundred million naira), respectively. However, the Super Agency licence under the Basic Licence category is required to have a minimum shareholder fund of N50,000,000 (Fifty Million Naira) and not N100,000,000 (one hundred million naira).

Although the new licence regime is yet to be implemented at the time of publishing, when it is implemented, companies shall be expected to notify the CBN before starting any new activity under their licence category. For example, a Super Licence holder who initially had been approved for only PSSP and Switching Operations must inform the CBN (for information purposes only) if it subsequently decides to commence PTSP operations.[46]

It is noteworthy that the Card Scheme service and Switching service, as well as, Mobile Money Operators service and Switching service, are mutually exclusive services, such that an entity rendering one of the services will not be licensed to render the other.[47]

7. Regulation for Direct Debit Scheme

By this regulation, a direct debit is a cashless form of financial settlement which facilitates a recurring payment. It permits the originator of the instruction, known as ‘Biller’ to collect amounts due from a ‘Payer’ through the Payer’s bank by leveraging on instruction or mandate provided by the Payer.[48]

The regulation recognizes the existing and emerging multi-channel options applied for direct debiting and attempts to define the operational standards expected in the direct debiting process.

It identifies 5 participants: the Biller, the Biller’s bank, the Payer, the Payer’s bank and the Payment Service Provider, and states their roles in the debiting process.[49]

A Biller is required to be an entity incorporated or registered to carry on business in Nigeria.[50] Both a Biller and Payer’s Bank shall be members of the Nigeria Clearing System or integrated with Payment Service Providers that accept Direct Debit for processing.[51]

Furthermore, Payer’s Banks, Billers, and Payment Service Providers shall keep records of all direct debit transactions for a period of not less than six years from the date of cessation of the Direct Debit Mandate.[52]

BLOCKCHAIN AND VIRTUAL CURRENCIES

In light of the emergence of virtual currencies and the risks associated with virtual currency exchanges and virtual currency activities, the Central Bank of Nigeria, by a circular,[53] drew the attention of banks and other financial institutions to these risks and required them to take the following actions pending substantive regulation by the CBN:

  • Ensure they do not use, hold, trade or transact in virtual currencies, such as Bitcoin, Ripples, Litecoin, Onecoin, etc.
  • Ensure that existing bank customers that are virtual currency exchangers have effective Anti-Money Laundering/Combating Financing of Terrorism controls that enable them to comply with customer identification, verification and transaction monetary requirements.
  • Where banks or other financial institutions are not satisfied with the controls put in place by the virtual currency exchange customers, the relationship should be discontinued; and
  • Any suspicious transaction should immediately be reported to the Nigerian Financial Intelligence Unit (NFIU).

Any financial institution that ignores the above caution does so at its own risk.

In a further press release[54], the CBN reiterated its position that cryptocurrencies and virtual Exchanges are neither licensed nor regulated in Nigeria, and dealers or investors in any kind of cryptocurrency in Nigeria are not protected by law.

DATA SECURITY AND CYBERSECURITY CONCERNS

The FinTech innovation cannot be separated from cybersecurity and privacy issues. Many FinTech companies collect and process a vast amount of data in order to provide financial services efficiently and inexpensively. Most of these data are highly sensitive information that can be misused if they fall into the wrong hands, thus, it behooves on FinTech companies to ensure compliance with data protection and cybersecurity laws[55].

FinTech and Data Protection in Nigeria:

The Nigerian Data Protection Regulation[56] issued by the National Information Technology Development Agency (NITDA) in January 2019 lays down regulations for the processing of data. These regulations apply to persons of Nigerian descent residing in or outside Nigeria. It provides that data may only be collected and processed for a specific lawful process upon the grant of consent by the Data Subject.[57]

Furthermore, data may only be stored for the period within which it is reasonably needed[58] and must be secured against all foreseeable hazards.[59] One of the numerous measures to protect data under the Regulation is data encryption, which is also a data protection requirement under the CBN regulatory framework for the use of USSD. The USSD regulation provides that USSD-based financial transactions and data stored by the USSD application at Financial Institutions shall be encrypted.[60]

The CBN Consumer Protection Framework for Banks and other Financial Institutions also regulates the protection of consumer assets and privacy. It provides that consumers’ financial and personal information shall be securely stored at all times[61] and shall not be released to a third party without the written consent of the consumer.[62] A third party here includes a subsidiary or an associated company.[63]

In addition, the Nigerian Communications Commission (NCC) Draft Consumer Code of Practice Regulations[64] requires Licensees to adopt and implement a Protection of Consumer Information Policy, which shall provide for the proper collection, use and protection of information[65] and be made available to its consumers in a readily accessible form and easy to read manner.[66]

FinTech and Cybersecurity in Nigeria:

The general law on Cybersecurity in Nigeria is the Cybercrime (Prohibition, Prevention, Etc) Act[67] which prescribes punishment for actions such as phishing, hacking, electronic theft, cyberstalking, cybersquatting, and cyber terrorism. The Act, however, is silent on mechanisms institutions need to put in place to strengthen their cyber defenses.

In response to this, the CBN recently issued the Risk-Based Cyber-Security Framework and Guidelines for Deposit Money Banks and Payment Service Providers,[68] which took effect on 1 January 2019, to outline the minimum cybersecurity baseline to be put in place by Deposit Money Banks (DMBs) and Payment Service Providers (PSPs) in order to enhance their cybersecurity resilience.

The guidelines make provision on Cybersecurity Governance and Oversight, Cybersecurity Risk Management System, Cyber Resilience Assessment, Cybersecurity Operational Resilience, Cyber-Threat Intelligence and Metrics, Monitoring and Reporting.

REGULATORY SANDBOX FOR FINTECH COMPANIES IN NIGERIA

In 2018, the Central Bank of Nigeria launched a regulatory sandbox for tech start-ups tagged ‘Financial Industry Sandbox’.[69] The purpose of the sandbox is to enable innovation by allowing for experimentation and rapid cycles of adjustments in a contained environment without full compliance with all regulations. However, the sandbox is yet to begin operation.[70] The CBN is expected to compile a list of interventions for which a regulatory sandbox is necessary and define eligibility criteria for the interventions to be allowed to run in the sandbox.

CONCLUSION

Regulation has often been seen as an enemy of innovation and the challenge usually faced by regulators is how to regulate innovation without killing it. A school of thought has argued that since innovation precedes regulation, innovation should be permitted to develop without hindrances. However, government action can further facilitate innovation by fostering a supportive environment, through the use of regulatory measures, for innovation to thrive. It appears that the challenge is always where to draw the line; to what extent should government regulate innovation?

The FinTech innovation, while improving financial inclusion and market efficiency, also brings along cybersecurity and data protection concerns, amongst others. In response to these challenges, the Central Bank of Nigeria has issued several guidelines to regulate various aspects of the FinTech industry and promote financial inclusion. This paper has identified and examined these guidelines, as well as laws, which influence the FinTech landscape, such as the Cybersecurity Act and Data Protection Bill.

RECOMMENDATIONS

While the CBN’s attempt to use regulation to drive financial inclusion is commendable, the piece-meal approach adopted by the Bank creates a fragmented regulatory framework. Although, it is conceded that this approach may have been adopted for regulation to progressively catch-up with the fast growing FinTech innovation and to avoid stymieing the nascent FinTech industry in Nigeria, yet it is this writer’s view that the various guidelines and laws that affect the industry must be integrated and harmonized to form a unified FinTech policy. There is no gainsaying that a cohesive framework will increase the ease of doing business in the Nigerian FinTech ecosystem, promote regulatory certainty and boost investors’ confidence in the industry. However, this framework must be flexible enough to accommodate further growth and stimulate innovation, rather than frustrate it.

Furthermore, it is suggested that the existing and proposed laws regulating the Nigerian FinTech ecosystem be aligned with the CBN’s National Financial Inclusion Strategy (NFIS)[71] to create a harmonized regulatory and policy thrust.

In addition, the long-awaited regulatory sandbox for FinTech start-ups is overdue and ripe for launch by the Nigerian government. The presence of a sandbox will help FinTech start-ups manage their regulatory risks, experiment with innovative financial products and contain the consequences of failure. A sandbox may also be used to test the effect of policies on FinTech companies before widespread application. Regulatory sandboxes have been adopted by other countries, including the UK, Singapore, Australia, Canada, Hong Kong and South Korea.

Innovation offices, which are more cost-effective than regulatory sandboxes, may also be set up to create a platform for innovators and regulators to collaborate. Through innovation offices, regulators are able to engage with and provide regulatory clarification to financial service providers that offer innovative products and services, while learning more about the industry and obtaining clarity for further regulation. Examples of innovation offices include the Estonian Financial Supervision Authority (EFSA) and Indonesia’s OJK Innovation Centre for Digital Financial Technology.

The African tech landscape is attracting huge attention from investors across the globe. With a rising population and a large percentage of unbanked people, Nigeria is an attractive hive for FinTech innovation. However, innovation can only thrive within a nurturing environment and well-guided regulations and policies can play a huge role in creating this environment.

 

 

 

_______________________________________________________________________

For further information on this article and area of law, please contact

Olayanju Phillips at: S. P. A. Ajibade & Co., Lagos by Telephone

(+234 1 472 9890), fax (+234 1 4605092)

Mobile (+234.814.468.3333) or

Email (ophillips@spaajibade.com).

www.spaajibade.com

 

[1] Olayanju Phillips, Associate Intern, SPA Ajibade & Co., Abuja Office, Nigeria.

[2]       NITDA, Nigeria Data Protection Regulation, 2019 made pursuant to the powers granted to NITDA under sections 6(c) and 32 of the National Information Technology Development Agency (NITDA) Act, 2007.

[3]       Exposure Draft of the Risk-based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Providers, 2018.

[4]       Paragraph 5.0, CBN Guidelines on Mobile Money Services in Nigeria, 2009.

[5]       Paragraph 5.0(a).

[6]       Paragraph 5.0(b).

[7]       Paragraph 8.0.

[8]       Paragraph 14.0.

[9]       Paragraph 7.0.

[10]     Paragraph 7.1, CBN Guidelines on Mobile Money Services in Nigeria, 2009.

[11]     Guidelines on Automated Teller Machine (ATM) Operations, Paragraph 1.0 of the CBN Guidelines on Operations of Electronic Payment Channels in Nigeria.

[12]     Guidelines on Point of Sale (POS) Card Acceptance Services, Paragraph 2.0 of the CBN Guidelines on Operations of Electronic Payment Channels in Nigeria.

[13]     Guidelines on Mobile Point of Sale (MPOS) Acceptance Services, Paragraph 3.0 of the CBN Guidelines on Operations of Electronic Payment Channels in Nigeria.

[14]     Guidelines on Web Acceptance Services, Paragraph 4.0 of the CBN Guidelines on Operations of Electronic Payment Channels in Nigeria

[15]     Paragraphs 2.4, 3.3 – 3.4, 4.4 – 4.5 of the CBN Guidelines on Operations of Electronic Payment Channels in Nigeria.

[16]     Paragraph 1.1.

[17]     Paragraph 1.2.

[18]     Paragraph 2.3.

[19]     Paragraph 2.9.

[20]     Paragraph 3.2.

[21]     Paragraph 3.9.

[22]     Paragraph 4.3.

[23]     Paragraphs 2.5 and 3.5 of the CBN Guidelines on Operations of Electronic Payment Channels in Nigeria.

[24]     Paragraphs 2.4.4 and 3.4.3.

[25]     Paragraph 3.0 of the CBN Regulatory Framework for the use of USSD for Financial Services in Nigeria.

[26]     Paragraph 5.0.

[27]     Paragraph 6.9.

[28]     Paragraph 6.4.

[29]     Paragraph 6.8.

[30]     Paragraph 9.1.

[31]     Paragraph 2.1 of CBN Guidelines on International Money Transfer Services.

[32]     Paragraph 2.7(i).

[33]     Paragraph 2.4(v).

[34]     Paragraph 2.4(ii).

[35]     Paragraph 2.4(i).

[36]     Paragraph 2.5(xvii).

[37]     Paragraph 2.5(iii).

[38] Paragraph 2.6.

[39] Ibid.

[40] Paragraph 2.0(i).

[41] Paragraph 5.0.

[42] Ibid.

[43] Paragraph 7.0 of CBN Guidelines on International Mobile Money Remittance Services.

[44] Paragraph 10.0.

[45] Paragraph 12.0.

[46]     Paragraph 2(a) of Exposure Draft of New CBN Licensing Regime for Payment System Providers.

[47]     Paragraph 3.

[48]     Preamble, CBN Regulation for Direct Debit Scheme in Nigeria (Revised), 2018.

[49]     Paragraph 2.0.

[50]     Paragraph 2.1.1.

[51]     Paragraphs 2.2.1 and 2.4.1.

[52]     Paragraph 3.1.2.

[53]     CBN, Circular to Banks and other Financial Institutions on Virtual Currency Operations in Nigeria, January 12, 2017.

[54]     CBN, ‘Virtual Currencies not Legal Tender in Nigeria’, Press Release, February 28, 2018.

[55]     See Cybercrime (Prohibition, Prevention, Etc.) Act, 2015, Nigeria Data Protection Regulation, 2019, NCC Draft Consumer Code of Practice Regulations 2018, NCC Consumer Bill of Rights, CBN Consumer Protection Framework for Banks and other Financial Institutions, 2016 and CBN Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Providers, 2018.

[56]     NITDA, Nigeria Data Protection Regulation, 2019

[57]     Paragraph 2.1(a) and 2.3(i) of the Data Protection Regulation 2019.

[58]     Paragraph 2.1(c).

[59]     Paragraph 2.1(d).

[60]     Paragraph 6.7 of the CBN Regulatory Framework for the use of USSD for Financial Services in Nigeria.

[61]     Paragraph 2.6.1(c) of the CBN Consumer Protection Framework for Banks and other Financial Institutions, 2016.

[62]     Paragraphs 2.6 and 2.6.2.

[63]     Paragraph 2.6.2.

[64]     Nigerian Communications Commission, Draft Consumer Code of Practice Regulations 2018.

[65]     Paragraph 44(1) of the General Consumer Code of Practice, Schedule to the NCC Draft Consumer Code of Practice Regulations 2018.

[66]     Paragraph 43(4).

[67]     Cybercrime (Prohibition, Prevention, Etc.) Act, 2015.

[68]     CBN, Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Providers, 2018.

[69]     The regulatory sandbox is one of the activities to be executed between 2018 and 2020 by the CBN Banking and Payment System Department (BPSD) and Nigerian Inter-Bank Settlement System (NIBSS) PLC for the achievement of the National Financial Inclusion Strategy. See CBN, National Financial Inclusion Strategy (Revised), October 2018, pp. 41, 53.

[70]     CBN Financial Inclusion Newsletter, 1st Quarter (March 2019) Volume 4, Issue 1, p. 15.

[71]     CBN, National Financial Inclusion Strategy (Revised), 2018.

 

Download PDF: An Overview of the Regulatory Framework of FinTech in Nigeria – Olayanju Phillips