For most of banking history, fraud was a private matter. A loss to be quietly absorbed, a customer to be quietly settled, an incident to be quietly investigated, and, if at all possible, a story to be kept out of the press. The instinct was understandable. Fraud is embarrassing, and trust is fragile.
That era is ending in Nigeria, and it is ending by design.
Under the 2026 reporting regime, the CBN and NIBSS are now mandated to report fraud to the National Assembly on a quarterly basis. Not a vague summary. The reporting covers fraud value and volume by channel, which institutions complied with their reporting obligations, and what enforcement was taken against those that did not. The House Committee on Digital and Electronic Banking has been urged to hold public oversight hearings, drawing in NIBSS, the CBN, the NFIU, banks, payment providers and security agencies to examine the drivers of electronic-payment fraud and the gaps in detection and response.
Read that carefully, because it is a structural change, not a procedural one. Fraud is being moved from the category of private embarrassment into the category of public, legislative record.
The incentives that flow from that are worth thinking through, whichever side of the table you sit on.
First, silence stops working as a strategy. When your fraud numbers, your reporting compliance and any enforcement against you are headed for a committee of the National Assembly, quietly absorbing a loss is no longer a way to make it disappear. The number will surface. What you can control is whether, when it surfaces, your institution looks like one that detected the fraud early, responded within the mandated window, and can show exactly what happened, or one that found out late and cannot explain itself.
Second, auditability becomes a competitive advantage. In a world of quarterly public reporting, the institutions that look strongest are the ones whose fraud and AML systems produce clean, timestamped, real-time evidence on demand. Who moved what, when, why it was flagged, what was held, what was released and by whom. That is not paperwork you generate after the fact. It is a property of the system you run, or it is not there when you need it. Manual processes and scattered logs do not survive that kind of scrutiny. The institution that can answer the committee in an afternoon will be trusted more than the one that needs three weeks and a consultant.
Third, and this is the part I find most healthy, transparency raises the whole market. Right now, one of the quiet reasons fraud persists even as totals fall is that institutions do not share fraud intelligence fast enough. Fraud data-sharing gaps are estimated to cost the industry billions. Public, standardised reporting starts to close that gap. When everyone's numbers are visible, patterns that no single bank could see become obvious, and the mule network operating across ten institutions stops hiding in the space between them. The CBN and NIBSS naming more than 13,000 fraud suspects on a shared portal is an early move in exactly this direction.
The uncomfortable side is real. Public reporting means public accountability, and some institutions will not enjoy the light. But I would argue that is the point. A financial system that just came off the FATF grey list on the strength of its effectiveness cannot let effectiveness slip back into the dark. Sunlight is how you keep a standard once you have earned it.
The practical takeaway is simple. If your fraud and AML controls cannot produce clean, real-time, auditable evidence on demand, you are now exposed in a new way, not just to fraudsters, but to the record. This is one reason we built Omniguard around case management with full audit trails and maker-checker controls, so that every decision it makes, every transaction it holds and every one it lets through, is logged, timestamped and explainable. When the question comes, and increasingly it will come from the legislature, you should be able to answer it with evidence, not apologies.
Fraud in Nigeria is becoming a matter of public record. The institutions that treat that as a threat will spend the next few years defending. The ones that treat it as a standard to meet will spend those years being trusted. I know which I would rather be.
Sources
