A March 2026 CBN circular adds user-choice, fraud-monitoring and device-security functionality to Nigeria’s instant-payment system, effective 1 July 2026. The important change is not one control—it is the combination of customer agency and stronger evidence around a transaction.
Primary source: Central Bank of Nigeria, Additional Functionalities for Instant Payment System, 12 March 2026.
What changes
The circular directs banks, other financial institutions and payment service providers to implement additional functionality including:
- a voluntary opt-out and opt-in route for instant payments, with multi-factor authentication for the choice;
- customer-controlled transaction limits;
- enterprise-grade fraud monitoring;
- liveness checks as part of relevant identity and authentication controls;
- binding a mobile account to one device; and
- a 24-hour maximum of ₦20,000 after a new device is introduced.
User control moves into the rail
Opt-out and voluntary limits make customer preference part of payment-system design rather than an afterthought inside a banking app. The interface has to explain the consequence, authenticate the choice and make restoration possible without creating a social-engineering shortcut.
A new device becomes a risk event
One-device binding and a temporary cap treat device change as materially different from ordinary use. Product teams need a clear recovery path for lost or replaced phones, while risk systems need to connect the device event to transaction monitoring and customer communication.
Liveness is only as strong as the process around it
A liveness check can reduce some impersonation risk, but it also creates biometric, accessibility, vendor and exception-handling questions. Teams should document where it is used, what data is retained, how false rejection is handled and what alternative exists for a legitimate customer who cannot complete it.
Our read
The circular makes “instant” a broader product promise. Speed now sits beside customer control, device integrity, fraud detection and recoverability. A successful transaction path should therefore be reviewed with its failure and recovery paths at the same time.
The effective date is 1 July 2026. Organisations subject to the circular should rely on the official text and their own legal, risk and compliance interpretation; this note is a product-analysis summary, not legal advice.
