Nigeria’s instant-payment rails are among the busiest in Africa, and that very convenience has become the soft target. A single stolen password or intercepted code can move money in seconds. As part of its March 2026 reforms, the Central Bank of Nigeria has ordered banks and fintechs to deploy multi-factor authentication for all electronic transfers, raising the floor on what it takes to push funds out of an account.
The principle behind multi-factor authentication is to require more than one independent proof of identity, so that something the customer knows is paired with something they hold or are. A leaked PIN alone should no longer be enough. Applied across every electronic transfer rather than only high-value ones, the rule closes the gap that fraudsters have worked through small, repeated debits that slip under any single threshold. Coverage, not just strength, is the point of the order.
The operational weight falls on the providers. Banks and platforms such as OPay, Moniepoint and Flutterwave must build authentication that is strong enough to deter takeover yet smooth enough that customers do not abandon a transfer halfway. The CBN set the requirement within the same package covering BVN rules and dormant accounts, signalling that security is now a baseline expectation rather than a premium feature.
The takeaway: Nigeria is making strong authentication the default setting of digital money, and the firms that make it frictionless will keep the customers the rule is meant to protect.




