KYC Is Not a Form

KYC Is Not a Form

How Nigerian Crypto Exchanges Should Actually Build a Customer Verification Framework

A KYC form with all the fields filled in tells you a customer typed some information into some boxes. It doesn't tell you the information is true, that it belongs to the person submitting it, or that this customer's risk profile has anything in common with the next customer who filled out the identical form. Treating KYC as a form to be completed rather than a framework to be applied is the single most common reason exchanges pass their own internal checklist and still fail a regulatory examination.

Build tiers, not a single gate

A risk-based approach means calibrating the depth of verification to the risk the customer actually presents, not applying one standard check to everyone regardless of what they do with the account. Three tiers form the backbone of a defensible framework:

  • Simplified Due Diligence (SDD): for genuinely low-risk, low-value relationships. Small retail accounts with tight transaction and volume caps, where the cost of over-verifying exceeds the risk being managed.
  • Customer Due Diligence (CDD): the standard tier. Full identity verification, address confirmation, and screening against sanctions and PEP lists, applied to the general retail customer base.
  • Enhanced Due Diligence (EDD): for higher-risk relationships. PEPs and their associates, customers from higher-risk jurisdictions, high-volume traders, corporate accounts with complex ownership, and anyone whose behaviour triggers a risk escalation after onboarding.

The mistake to avoid is treating tiering as a one-time sorting exercise at signup. A customer who onboards under CDD and later starts moving volume, or trading patterns, consistent with EDD risk should move tiers. Automatically flagged, not caught six months later in an annual review.

BVN and NIN: two different checks, both now required

Nigeria's identity verification landscape tightened significantly with the NIMC Act 2026, which expanded the scope of transactions requiring a verified National Identification Number (NIN) to include investment transactions, a category crypto exchanges sit squarely inside. Under the current framework, individual account tiers determine what's required. Tier 1 accounts and wallets require at least one of BVN or NIN, while Tier 2 and Tier 3 accounts require both on file. Conducting a specified transaction without a NIN where one is required is now a criminal offence under the Act, not just a compliance gap.

The two checks answer different questions, and neither substitutes for the other:

  • BVN verification confirms the customer has an established banking identity and links them to Nigeria's banking-sector biometric record. Useful for cross-referencing against other financial relationships and prior banking history.
  • NIN verification confirms the customer's national identity directly against NIMC's civil register. The more foundational check, and now the one carrying explicit legal weight for investment-type transactions.

An exchange that verifies BVN but treats NIN as optional isn't just under-verifying. Under the 2026 framework, it may be facilitating transactions that are unlawful for the customer to make in the first place.

The difference between BVN and NIN
The Difference Between BVN and NIN

PEP screening belongs inside the framework, not bolted on after

PEP screening should run as a standard step in every onboarding flow, individual and corporate, checked against the customer's declared identity and, critically, against the UBOs of any business account. Screening once at onboarding and never again misses the PEP who acquires their status after the account is already open. Screening should re-run periodically against updated watchlists, not just at signup.

UBOs are where business account KYC actually gets tested

For corporate and business accounts, identity verification of the entity itself is the easy part. A CAC search confirms the company exists. The harder, more consequential part is identifying every individual who ultimately owns or controls the entity, typically anyone holding 5% or more depending on your risk threshold, and running full CDD or EDD on each of them individually. A business account isn't "verified" because the company's paperwork checks out. It's verified when every person who actually benefits from and directs that account has been identified and screened as though they'd opened the account personally, because in substance, they have.

Where KYC frameworks actually fail examinations

The failures that show up in regulatory findings are rarely dramatic. They're structural:

  • Verification depth that doesn't match the declared risk tier. An account flagged as EDD-worthy that received only CDD-level checks.
  • UBO identification stopping at the first corporate layer instead of tracing through to natural persons, especially where offshore holding structures are involved.
  • Static risk scoring. A customer's risk tier set once at onboarding and never revisited despite years of changed transaction behaviour.
  • No evidentiary trail. Verification that happened, but wasn't documented in a form an examiner can audit six months later. If you can't show your work, a regulator will assume the work wasn't done.
  • Screening lists that go stale. PEP and sanctions databases that were currently at integration but haven't been refreshed, so a customer who becomes a PEP after onboarding is never caught.
Reasons Why KYC Frameworks Fail Examinations
Where KYC Frameworks Fail Examinations

A KYC framework earns its name when it's a system that adapts to who the customer actually is and how their risk changes over time. Not a form that gets the same fields filled in regardless of who's answering.


This article is part of the Obiex Compliance Academy, a series built to help our business customers understand the compliance requirements behind onboarding and working with Obiex. It's for general guidance and doesn't constitute legal advice.

Share this article