The Nigerian Fintech Regulatory Commission (NFRC) Bill 2025 is a significant legislative attempt towards centralising the regulatory framework governing financial technology in Nigeria. The bill proposes establishing a statutory body, the Nigerian Fintech Regulatory Commission (NFRC), to license and regulate fintech companies and financial services providers in the country.
The bill was introduced in the House of Representatives in 2025 as House Bill 2389. This bill has passed the first reading. It passed the second reading in October 2025 and was open to stakeholders for a public hearing on March 2, 2026.
The proposed legislation adopts a broad definition that applies to all entities that deploy technology to provide financial services, including payment services, digital lending platforms, digital asset services, financial data infrastructure, and other tech-enabled financial solutions.
Under the bill, the proposed Nigerian Fintech Regulatory Commission's jurisdiction would extend to domestic and foreign entities that offer Fintech services within Nigeria. Another important point about this bill is its coverage of fintech operators and service providers that support the use of fintech infrastructure. This means that companies providing payment processing, financial APIs, or even digital identity solutions could fall within the Commission's regulatory ambit.
One of the most significant features of the bill is the establishment of the Nigerian Fintech Regulatory Commission as a central supervisory authority responsible for regulating and licensing Fintech operators. The Commission would have the authority to issue licences to Fintech operators.
In addition to licensing powers, the Commission would be empowered under Section 4 to issue regulatory guidelines, supervise fintech operations, conduct inspections, and enforce compliance with applicable laws, among other functions set out in the proposed section above.
To manage the complex intersection of finance, technology, and communications, the Bill establishes the National Fintech Management (NFM) Council. The Council is chaired by the Minister of Finance and includes representatives from the Central Bank of Nigeria (CBN), the Securities and Exchange Commission (SEC), the Nigerian Communications Commission (NCC), the National Information Technology Development Agency (NITDA), the Nigeria Data Protection Commission (NDPC), among others.
Fintech companies would be required to obtain regulatory approval before offering their services to Nigerians. They would also be expected to comply with operational standards set by the Commission, including requirements related to data security and, most especially, risk management. The bill requires fintech companies to establish and maintain dedicated internal compliance teams. This is to ensure that the companies have institutional capacity to meet their regulatory obligations on an ongoing basis. However, beyond the above-mentioned obligations, the bill also introduces market conduct rules:
Anti-competitive practices: The Commission has the power to direct licensees to cease conduct that substantially lessens competition in the fintech market.
Interconnection: Licensees are obligated to interconnect their systems and platforms with other operators on non-discriminatory and transparent terms. This requirement seeks to ensure "open banking", financial inclusion, and interoperable practices, and prevents dominant players from locking out smaller innovators.
Fintech companies will also be required to conduct compliance audits that could extend to cybersecurity, system resilience, load (stress) testing, and NFRC technical standards.
The NFRC bill does not exist in a vacuum; it seeks to overlay a new governance structure on a sector already governed by a dense web of established laws. This creates several "jurisdictional friction points" that could lead to legal uncertainty if not reconciled through explicit legislative amendments.
A. The BOFIA and CBN Act Conflict
The most significant intersection is with the Banks and Other Financial Institutions Act (BOFIA) 2020 and the Central Bank of Nigeria (CBN) Act 2007.
Licensing conflict: Section 3 of the Bill grants the NFRC “responsibility for licensing, regulation, and supervision of the Fintech industry in Nigeria.” The breadth of this mandate directly conflicts with the CBN’s established authority under sections 1 and 2 of BOFIA 2020, which vest in the CBN the power to license banks and banking business, and section 57 of BOFIA, which extends that authority to “other financial institutions”, including Payment Service Providers and digital banks.
Dual compliance: Without a "savings" clause, fintechs currently licensed by the CBN would be forced into a "dual licensing" regime, incurring additional fees and potentially conflicting directives between capital adequacy and operational conduct.
B. Competition Law: Section 90 vs. the FCCPA 2018
The bill introduces a specialised competition regime for the fintech sector.
Jurisdictional clashes: Section 90 of the Bill purports to grant the NFRC "exclusive competence" over competition matters within the fintech market. This directly intersects with the Federal Competition and Consumer Protection Act (FCCPA) 2018, which established the FCCPC as the primary authority for all competition matters across Nigeria.
Legal precedent: Judicial precedents across healthcare, aviation, fintech, and telecommunications sectors have consistently held that the FCCPA, as the later-enacted and more specialised competition law, takes precedence over sector-specific competition clauses.
C. Capital Markets and Virtual Assets (ISA 2025)
The Investments and Securities Act (ISA) 2025 already empowers the SEC to regulate digital assets and capital market-facing fintech. However, we see a bureaucratic triple-play, as fintechs offering digital investment products (like "wealthtech" apps) would find themselves at the intersection of three regulators: the SEC for their products, the CBN for their payment rails, and the NFRC for their general "fintech" status.
D. Institutional Harmonisation: The NFM Council vs. FSRCC
The Bill proposes a National Fintech Management (NFM) Council to coordinate these intersections. This Council closely mirrors the existing Financial Services Regulation Coordinating Committee (FSRCC), which already serves as the statutory platform for the CBN, SEC, and other regulators to harmonise policies. Rather than resolving fragmentation, the NFM Council "institutionalises overlapping authority" by adding yet another layer of high-level bureaucracy.
Sections 73 to 78 grant the Commission dispute resolution authority. Section 78(2) provides that the Commission’s decisions are enforceable by the courts “...as if the decision is a judgment of such Court...” This formulation raises a direct concern under section 6 of the Constitution of the Federal Republic of Nigeria 1999, which vests judicial powers exclusively in the courts. The Commission is not a court. Whether this dispute resolution structure is constitutionally sound and whether it adequately separates the Commission’s roles as regulator, prosecutor, and adjudicator are questions the Bill does not address.
Sections 108 to 111 empower the Commission to approve tariffs and charges for fintech services. Section 108(1) prohibits licensees from imposing “any tariff or charges for the provision of any service until the Commission has approved such tariff rates and charges.” This is direct price control over financial services, and it cuts squarely across the CBN’s existing role in setting interest rate caps, transfer charges, and payment service fees.
Section 107 compounds this by empowering the Commission to determine a list of “required application services” and to direct classes of fintech service providers to offer them. The list explicitly includes payment services, mobile banking, lending assistance, and digital wallets. This means the Commission could, in principle, direct entities to enter markets they did not choose. This is a significant market intervention that the Bill does not justify.
The foundational defect of the Bill is not any individual provision; it is the definition from which every provision flows. Section 122 defines "fintech" as "financial technologies or applications used to deliver financial services through digital devices." That definition contains no limiting principle. It does not distinguish between a technology-native startup and a deposit money bank that has built a mobile application. It does not carve out entities already licensed under BOFIA, ISA, or any other financial sector legislation. It does not require that the technology be the primary business model rather than merely a delivery channel. The consequence is that every USSD shortcode, every internet banking portal, every mobile application through which a CBN-licensed deposit money bank extends its services to customers falls, on a plain reading, within the statutory definition of "fintech", and every entity operating such a channel becomes, by operation of Section 3 of the Bill, subject to NFRC licensing.
Section 122 defines “Minister” as “the Minister for the time being charged with the responsibility for Finance.” This is a deliberate institutional choice that locates fintech regulation under the Ministry of Finance rather than under the Ministry of Communications, Innovation and Digital Economy, which oversees NITDA, the NDPC, and Galaxy Backbone. This aligns the supervising ministry with the CBN’s reporting line but distances it from the digital economy infrastructure. It also creates jurisdictional tension with the Minister of Communications, Innovation and Digital Economy, who has been the dominant voice on technology policy under the current administration.
Section 31(2) provides for imprisonment of up to one year for operating “a fintech system or facility” or providing a “fintech service” without a licence. Read alongside the dangerously broad definition of “fintech” in section 122, this creates a substantial risk of over-criminalisation. Under the current draft, a bank employee operating a mobile banking application could, on a plain reading, be exposed to criminal liability for activities that the same employee is already licensed and regulated to perform under BOFIA. This criminal dimension is one of the most consequential operational features of the Bill.
Fintech is one of the highest-risk areas for anti-money laundering and counter-terrorism financing (AML/CFT) globally. The Bill is silent on AML obligations, on coordination with the Economic and Financial Crimes Commission (EFCC), the Nigerian Financial Intelligence Unit (NFIU), and the Special Control Unit against Money Laundering (SCUML), and on Nigeria’s commitments under the Financial Action Task Force (FATF) mutual evaluation framework. Any serious fintech regulatory framework must address these obligations. The omission is particularly striking for a Bill that presents itself as a comprehensive regime capable of displacing existing regulatory structures; the absence of an AML/CFT framework suggests the legislation is not, in fact, fit for that purpose.
Nigeria's payment interoperability architecture is an already functioning, multi-layered system administered entirely by the CBN, and the NFRC Bill's interconnection provisions sit directly atop it without acknowledgement or coordination. At its centre sits the Nigeria Inter-Bank Settlement System (NIBSS), shared infrastructure owned by all licensed banks and regulated by the CBN, which provides the switching, settlement, and identity verification infrastructure that allows different financial institutions, from traditional banks to fintech startups, to interact, exchange data, and move money. Above this settlement layer, switching companies form the routing infrastructure that keeps transactions alive across the system, and the Nigeria Central Switch (NCS) operationally provides interconnectivity and interoperability among approved electronic funds transfer switch initiatives, banks, mobile money operators, and other Payment Service Providers in Nigeria, under the direction of the CBN.
The CBN's Guidelines on Transactions Switching further compel every switching company to open its network for the reciprocal exchange of transactions and messages with the NCS, and require the NCS to maintain minimum technical standards on interoperability, messaging, network connectivity, security, disaster recovery, fraud management, and programming interfaces. Layered on top of this is the CBN's open banking framework. Against this backdrop, the NFRC Bill's interconnection obligation transplants verbatim from the structure of the Nigerian Communications Act, where "interconnection" denotes physical network linkage between telecommunications operators. Unlike in telecoms, making fintech operators and banks talk to each other through a centralised mandatory interface risks turning an industry-led, standards-based interoperability effort on its head, and the CBN has already settled, through a dense body of subsidiary legislation, how that interaction must occur and on what terms. A fintech company subject to both the NFRC's interconnection directive and the CBN's Switching Guidelines, NCS operational rules, and Open Banking Operational Guidelines would face genuinely irresolvable compliance conflicts, not because the rules are duplicative in form, but because the NFRC provision is borrowed from a regulatory tradition that is not aligned with digital financial services.
The most fundamental weakness of the Bill lies not in any specific provision but in its foundational assumption: that “fintech” constitutes a discrete sector warranting its own dedicated statutory regulator.
Technology is being deployed across every part of the economy, and the “[x]tech” label travels with it. Agrotech, proptech, insurtech, healthtech, agritech, edtech, regtech, legaltech, etc, all describe the same phenomenon: digital tools applied to a traditional sector. If the legislative response to each is a dedicated commission, Nigeria’s institutional architecture becomes definitionally unstable (the categories would overlap and expand indefinitely), administratively duplicative, and vulnerable to capture by whichever industry body lobbies most effectively for its own dedicated regulator. The Bill’s own breadth of definition illustrates the problem: on its face, the NFRC would license every digital banking application in Nigeria, including those operated by CBN-licensed deposit money banks.
The correct organising principle for financial regulation is activity and risk, not a technology label. The Basel Committee’s “same activity, same risk, same regulation” principle, the Financial Stability Board’s recommendations on crypto-asset activities, and the converging positions of IOSCO and the IAIS all reflect this. The operative question is not “is this fintech?” but “what is the activity, what are its risks, and which existing authority is the appropriate supervisor?” Deposit-taking sits with the CBN regardless of the delivery channel. Securities dealing sits with the SEC. Personal data processing sits with the NDPC. Competition sits with the FCCPC. Adding the NFRC on top of these does not change the regulatory analysis of any specific activity; it only multiplies the regulatory interfaces that operators must navigate and expands the compliance perimeter.
The Bill’s stated rationale is that existing regulators have failed to coordinate. Its response is institutional addition rather than institutional reform. This does not cure the operational deficits in the existing agencies. It dilutes regulatory capacity by spreading scarce supervisory expertise across an additional body, raises compliance costs for the regulated, and creates fresh jurisdictional disputes of exactly the kind the Bill purports to resolve.
Comparable jurisdictions that handle digital financial services well achieved this result by clarifying the mandates of existing regulators, not by creating new ones: the UK FCA’s regulatory perimeter approach, Singapore MAS’s activity-based licensing framework, and Australia’s twin-peaks model under APRA and ASIC are all examples. The lighter-footprint alternative is available and obvious: strengthen the FSRCC; embed dedicated fintech supervision units within the CBN and SEC, supported by cross-agency secondments; and require formal cooperation agreements between the financial regulators and the NDPC, modelled on section 105 of the FCCPA. The Bill does not engage with this alternative at all. That omission is itself a weakness, suggesting the drafter began with the conclusion that a new agency was needed rather than asking whether one was warranted.
The Bill’s aim suggests that a dedicated regulator could produce a more coherent environment for fintech operators. That will be difficult to sustain in light of the structural analysis this review has provided. If enacted, the Bill will result in the proliferation of overlapping obligations, regulatory uncertainty, and increased compliance costs.
The compliance cost dimension is also significant. With the advent of the NFRC, licensing costs will be an additional line item for fintech operators, in addition to existing obligations to the CBN and SEC. Regulatory audits under the new framework will compound this cost burden. The Bill poses a real risk of raising the cost of market entry to the point that it stifles the innovation it ostensibly seeks to promote.
The Nigeria Fintech Regulatory Commission (NFRC) Bill 2025 is one of the most ambitious legislative efforts to reform Nigeria's financial technology sector. It seeks to address concerns about the complexity of compliance in the industry. However, as this analysis demonstrates, the Bill’s ambition outpaces its drafting and is removed from the realities of the financial sector.
The Bill's mandatory compliance requirements would increase compliance costs for startups, inadvertently stifling the very innovation it seeks to promote. A collaborative oversight model anchored in the existing institutional mandates, rather than a purely additive institutional architecture, is essential for Nigeria to maintain and build on its position as a leading fintech market on the continent.