Fintech Licensing Pathways under the CBN and SEC Nigeria
By Chukwudi Anyanwuocha, Dealtran Legal
Why licensing sequence matters
Fintech products in Nigeria rarely sit under a single regulator. A payments feature may engage the Central Bank of Nigeria (CBN). An investment or crowdfunding product may engage the Securities and Exchange Commission (SEC). Data processing triggers the Nigeria Data Protection Act and Nigeria Data Protection Regulation (NDPR) framework. Consumer-facing apps may also attract competition, advertising, and sector-specific rules.
Founders and investors often underestimate how early product design locks in licensing pathways. Building first and licensing later creates costly pivots: entity restructuring, shareholder changes to meet ownership thresholds, or product cuts to exit a regulated activity. Mapping the licence stack before raising a Series A (or even a seed round aimed at a regulated launch) is usually cheaper than rebuilding later.
This note offers a high-level map of common pathways, a practical sequencing checklist, common pitfalls, and guidance on when to instruct counsel. It is educational only and does not replace tailored regulatory advice.
Legal and regulatory backdrop in Nigeria
CBN. The CBN regulates banks and many non-bank payment and financial services activities. Depending on the product, relevant regimes may include payment service provider categories, switching, mobile money, agent banking frameworks, and other circulars or guidelines that define permissible activities, capital, governance, and IT controls. Which licence or approval applies turns on what the product actually does with customer funds, settlement, and payment instructions.
SEC. The SEC regulates capital-market activities. Crowdfunding, fund management, digital asset offerings that are securities, exchanges or platforms dealing in investment instruments, and related intermediaries can fall within SEC rules and registration categories. Token or "platform" branding does not remove a securities analysis if the economic substance is an investment contract or other regulated instrument.
NDPR / data protection. Almost every fintech processes personal data. Controllers and processors must meet registration, privacy notice, security, cross-border transfer, and breach-response expectations under the data protection framework supervised by the relevant authority. Data protection is not a "later" workstream; it affects vendor contracts, cloud location, and analytics design.
Other touchpoints. Corporate form and filings sit under CAMA and the Corporate Affairs Commission (CAC). Tax, foreign-exchange rules for inbound capital and repatriation, consumer protection, and anti-money laundering (AML) and know-your-customer (KYC) obligations cut across most models. Some products also interact with the Nigerian Communications Commission or other sector regulators when telecoms channels are central.
Practical checklist: sequencing a licence pathway
Write an activity map, not a pitch deck. List every flow of money, data, and instruction. Identify who holds customer funds, who settles, who gives investment advice or offers, and who custody digital assets.
Classify each activity. Separate CBN-facing payments or banking-adjacent activities from SEC-facing investment or securities activities. Flag hybrid features that may need both or that should be deferred.
Choose the entity early. Confirm whether a Nigerian company is required, whether foreign ownership limits or local-partner expectations apply for the relevant licence, and whether a group structure (opco / holdco) will help multi-product roadmaps.
Sequence applications to the product roadmap. Launch with the narrowest regulated activity you can support operationally. Park features that would force a second regulator until capital and compliance capacity exist.
Build the compliance spine in parallel. AML/KYC policies, board composition, IT security, customer complaints handling, and data protection documentation are often licence conditions. Do not treat them as post-approval chores.
Align fundraising documents. Investor rights, change-of-control clauses, and option pools should not conflict with licence conditions on ownership, key persons, or prior regulatory consent.
Contract vendors with regulatory risk in mind. Payment processors, cloud providers, KYC vendors, and white-label partners should accept audit, data, and termination terms that your licence will require.
Plan for ongoing supervision. Licences are the start. Reporting, capital maintenance, fit-and-proper updates, and product-change notifications continue after go-live.
Common pitfalls
Assuming "fintech" is one licence. It is not. Payments, lending, savings, investments, and digital assets can sit in different boxes, sometimes at once.
Lagos-centric product assumptions. Regulatory analysis is national. Customer acquisition across states does not create a separate licensing regime, but state consumer and tax touchpoints can still matter operationally.
Raising on a product that cannot be licensed as drawn. Marketing language that promises yield, pooling, or custody can force an SEC analysis even if the team thought it was "just payments."
Ignoring data protection until diligence. Investors and enterprise customers increasingly ask for NDPR-aligned policies, DPIAs for high-risk processing, and clear processor contracts.
Change of control surprises. Selling a stake or bringing in a strategic investor without checking licence consent conditions can breach approval terms.
Under-capitalising the compliance function. Licence fees are visible. The ongoing cost of AML, cybersecurity, and reporting is what sinks thinly staffed teams.
When to instruct counsel
Instruct regulatory counsel when you are defining MVP scope for a regulated launch, before filing a licence application, before a fundraising term sheet that may change control, or when adding a product line that introduces a second regulator. Counsel should help classify activities, choose entity and ownership structure, prepare application packs, and align commercial contracts with licence conditions.
Technology and corporate counsel should sit with regulatory counsel when shareholder agreements, employee equity, or vendor stacks could undermine licence fitness requirements.
Closing
Successful Nigerian fintech licensing is less about hunting a single "fintech permit" and more about honest activity mapping, sequenced applications, and a compliance operating model that matches the product. CBN and SEC regimes, read together with data protection and CAMA requirements, reward teams that design for supervision from the start.
Dealtran Legal advises founders, boards, and investors on fintech licensing pathways, entity design for multi-product roadmaps, and compliance programmes that can scale with the business across Nigeria.
This article is general information about Nigerian law and practice at the date of publication. It is not legal advice.