Nigeria’s reported digital payment fraud losses fell to N25.85bn in 2025 from N52.26bn the year before, a drop of more than half. A new compliance report says that decline is a warning, not a win. Fraud losses have climbed roughly 350 percent since 2020 even as reported incidents fell about 31 percent, meaning criminals are hitting fewer targets for far more money each time.
The report, titled The Compliance Reckoning: Regulating Financial Services in the Age of AI, was released on Friday by compliance technology firm Adhere in partnership with TechCabal. It lands as the Central Bank of Nigeria (CBN) pushes through the densest run of financial-crime regulation in the sector’s history, as a single bank absorbs the largest compliance fine in recent memory, and as global policing data shows AI-driven fraud has become dramatically more profitable than the crime it is replacing.
A Warning Dressed Up as Good News
The findings were presented at the Adhere Compliance Frontline Forum 2026 in Lagos, themed The Trust Frontier, drawing senior executives from banks, fintechs, regulators and law enforcement. Adhere, part of the Smartcomply Group, sells AI-powered transaction monitoring, identity verification and regulatory reporting tools to more than 1,000 organizations across Africa, which makes it an interested party in its own findings as much as a messenger of them.
Gbemisola Osunrinde, group managing director of Smartcomply, told the forum that a falling fraud count should not be read as falling risk.
The fall in reported fraud is welcome, but it is also a warning. When reporting drops faster than fraud, the risk does not leave the system; it leaves the record.
Osunrinde said the report’s central claim is about structure, not software. “What this report shows is that the next eighteen months will be decided by architecture, not by tools,” she said, adding that Adhere was built so a bank or fintech could see “transaction by transaction, what a quarterly review would miss” while still meeting CBN mandates.
Nigeria’s Fraud Numbers, Before and After
Set side by side, the report’s own figures do the arguing. Nigeria processes more than 10 billion real-time payment transactions a year, yet ranks 110th out of 112 countries for fraud protection, according to the report. Globally, financial fraud drained more than $442bn from the economy in 2025, per the 2026 Global Financial Fraud Threat Assessment published by INTERPOL, which found AI-enhanced schemes now run about 4.5 times more profitable than traditional fraud.
| Metric | Figure | Context |
|---|---|---|
| Reported fraud losses, 2024 | N52.26bn | Baseline year before the reported decline |
| Reported fraud losses, 2025 | N25.85bn | Down more than half year on year |
| Change in fraud losses since 2020 | Up about 350% | Despite the 2025 year-on-year drop |
| Change in reported incidents since 2020 | Down about 31% | Fewer attacks, each one costlier |
| Global fraud cost, 2025 | $442bn | INTERPOL’s 2026 threat assessment |
| Nigeria’s fraud-protection rank | 110th of 112 | Despite 10bn-plus annual transactions |
Do the arithmetic on the report’s own numbers and the picture sharpens further. If losses are up roughly 4.5 times since 2020 while incident counts dropped to about seven-tenths of their 2020 level, the average cost of a single fraud event has climbed roughly sixfold in five years. Fewer criminals are doing far more damage per attempt, which is exactly what a shift toward AI tooling, automated identity spoofing and large-scale account takeover would produce.
Zenith Bank’s Fine Shows What Compliance Failure Costs
The report cites a N15.42bn regulatory fine imposed on what it calls “a leading commercial bank” in 2025 as proof that compliance failure now carries a real price tag. It does not name the lender. Nigerian financial press coverage from that period does: the CBN levied the N15.42bn penalty on Zenith Bank, one of the country’s largest lenders, over a mix of foreign exchange infractions, anti-money-laundering lapses and cybersecurity compliance gaps, with the largest single component, N14.64bn, tied to forex examination findings.
Measured against the industry’s own 2025 numbers, that one fine is equal to almost 60 percent of all reported digital payment fraud losses nationwide for the entire year. The report argues the consequences no longer stop at the fine itself. Compliance failures, it said, are now capable of affecting a bank’s relationships with its international correspondent banking partners, the foreign banks that give Nigerian lenders access to dollar clearing and cross-border settlement.
Correspondent Banks Are Watching Too
That is not an abstract threat. Global banks have been retreating from relationships they consider too costly to police for years, a pattern the industry calls de-risking. A SWIFT information paper on the unintended consequences of de-risking found that rising compliance costs and uncertainty over how far due diligence must go push correspondent banks to simply exit relationships rather than manage the risk, with West African lenders among those affected in recent years. The Financial Action Task Force, the global anti-money-laundering standard setter, has issued its own guidance on correspondent banking risk management aimed at slowing that retreat.
The stakes of getting enforcement wrong are not unique to Nigeria’s banking sector, either. UN-linked monitoring bodies have separately found that Southeast Asia’s scam crackdowns keep losing ground against the criminal networks they target, evidence that regulatory pressure alone does not guarantee enforcement keeps pace with the crime it is chasing.
Nigeria’s Regulatory Calendar Just Got Crowded
Nigeria’s regulator is not waiting to find out. The report counted 17 separate CBN regulatory actions covering cybersecurity, anti-money laundering and data protection over a 14-month span, six of them carrying implementation deadlines that run from March 2026 through March 2028. Two of those actions are already public record.
- March 10, 2026: The CBN issued a circular setting a mandatory baseline standard for automated anti-money-laundering, counter-terrorism-financing and counter-proliferation-financing systems across regulated institutions, with implementation roadmaps due back to the regulator by June 10, 2026.
- March 31, 2026: The CBN introduced a mandatory Cybersecurity Self-Assessment Tool, giving deposit money banks three weeks and other regulated institutions, including microfinance banks, payment service providers and fintechs, five weeks to complete and submit it.
- Through March 2028: Six of the CBN’s 17 tracked actions carry deadlines stretching to this point, meaning the compliance load does not clear after any single filing window.
The forum’s law enforcement track reflected how seriously that calendar is being taken. Assistant Inspector-General of Police Uche Ifeanyi delivered a keynote on financial crime enforcement, and panel discussions drew representatives from the Economic and Financial Crimes Commission, the Nigeria Police Force’s Cybercrime Laboratory, NIBSS (the Nigeria Inter-Bank Settlement System, which runs the country’s real-time payment rails), and fintech operators including Paystack and PAYAZA.
Who Has the Talent to Meet the Deadlines?
Nigeria’s financial sector is trying to close a cybersecurity staffing gap the report puts at roughly 90 percent while simultaneously meeting a regulatory calendar built for institutions that already have the staff. That gap does not fall evenly. Tier-1 commercial banks have the budgets to hire or contract their way to compliance; the report’s own numbers suggest most smaller lenders, microfinance banks and fintech startups do not.
The governance problem is not confined to banking, either. A KPMG survey found tech firms racing toward AI maturity in 2026 more broadly, the same discipline the Adhere report says lenders now need to build under deadline pressure rather than at their own pace.
The report identifies four traits it says will separate institutions that hold up over the next 18 months from those that do not:
- Proactive fraud detection built for continuous, transaction-level monitoring rather than periodic review
- Comprehensive customer risk profiling that updates as behavior changes, not just at onboarding
- Robust AI model governance, so automated decisions can be audited and explained to regulators
- Greater collaboration across banks, fintechs, regulators and law enforcement on shared fraud signals
The Next Eighteen Months Test Bank Architecture
Every one of those four traits is a feature Adhere sells. That does not make the diagnosis wrong, Nigeria’s own numbers back the underlying claim, but it is worth holding the two facts together: a company that profits from selling compliance architecture is the one telling the industry that architecture, not off-the-shelf AI tools, is what survival now requires.
What is harder to dispute is the timing. A fintech sector built to move 10 billion transactions a year grew faster than the workforce and governance meant to police it, and the bill for that gap is now arriving in the form of overlapping CBN deadlines, a fine that erased more than half a year’s worth of industry-wide reported fraud losses in one stroke, and a correspondent-banking system watching for the next compliance failure. The CBN’s tracked deadlines run to March 2028. How many of Nigeria’s smaller banks and fintechs are still standing by then is the open question the report leaves unanswered.
Frequently Asked Questions
What Makes AI-Powered Fraud More Dangerous Than Traditional Fraud?
INTERPOL’s 2026 threat assessment found AI-enhanced fraud runs about 4.5 times more profitable than traditional methods because agentic AI systems can now plan and execute an entire fraud campaign on their own, from reconnaissance on a target through to cashing out, without a human operator managing each step.
How Does the Zenith Bank Fine Compare With Nigeria’s Total Fraud Losses?
The N15.42bn CBN fine tied to Zenith Bank in 2025 is equal to almost 60 percent of the N25.85bn in digital payment fraud losses reported industry-wide that same year, meaning a single regulatory penalty came close to matching what the entire sector reported losing to fraud.
What Is Correspondent Banking De-Risking?
De-risking happens when an international bank ends a relationship with a foreign lender it views as too costly or risky to monitor for money laundering, rather than managing that risk directly. For an affected bank’s customers, it can mean losing easy access to dollar clearing and paying more to move money for trade.
How Short Is Nigeria’s Cybersecurity Workforce, and Who Feels It Most?
The report puts the shortfall at roughly 90 percent. Nigerian trade press covering the CBN’s 2026 cybersecurity push has reported that many smaller banks and fintechs are trying to meet the same deadlines as tier-1 banks without a dedicated chief information security officer on staff at all.
What Happens if a Bank or Fintech Misses a CBN Compliance Deadline?
Beyond fines like the one imposed on Zenith Bank, the report warns missed compliance can strain relationships with international correspondent banks. The forum’s law enforcement track, including a keynote from Assistant Inspector-General Uche Ifeanyi and a panel featuring the EFCC, made clear that serious violations can also draw criminal investigation alongside regulatory penalties.








