Nigeria's Central Bank (CBN) and the Securities and Exchange Commission (SEC) have jointly imposed a combined fine of ₦1.21 billion on Access Holdings Plc in 2025, in response to a range of infractions identified during 2024. The penalty spans anti-money laundering compliance failures, the unauthorised warehousing of government funds, and deficiencies in cybersecurity incident reporting, and represents one of the most significant regulatory enforcement actions taken against a major Nigerian financial group in recent memory.

The largest component of the fine — ₦718.5 million — was levied for breaches of anti-money laundering regulations, reflecting the primacy that the CBN places on AML compliance within its supervisory framework. A further ₦300 million was imposed for the unauthorised warehousing of government funds, a category of violation that involves the holding or deployment of funds belonging to government entities in ways that fall outside the permitted regulatory framework. An additional ₦69 million was assessed for the failure to report cybersecurity incidents within the required timeframes, with further penalties imposed for shortcomings related to targeted financial sanctions compliance.

A 217% ESCALATION FROM PRIOR ENFORCEMENT

The scale of the combined fine marks a dramatic departure from prior enforcement actions against the group. The ₦1.21 billion total represents a 217% increase compared with the ₦38 million fine imposed on Access Holdings in 2023, a disparity that illustrates the extent to which the CBN has adopted a more assertive and financially consequential enforcement posture. This shift reflects both the growing complexity of the regulatory expectations placed on systemically important financial institutions and the CBN's stated commitment to using penalties that are sufficiently material to serve as a genuine deterrent rather than a routine cost of business.

Access Holdings Plc is the parent company of Access Bank, one of the largest banks in Nigeria by assets and one of the most active in pursuing pan-African expansion. The fine applies at the group level, and the specific violations cited point to compliance infrastructure gaps that the CBN regards as fundamental failures rather than technical oversights. For a group of Access Holdings' scale and international profile, the reputational dimension of such a publicly disclosed enforcement action adds a further dimension beyond the direct financial cost.

JOINT REGULATORY ACTION SIGNALS COORDINATED SCRUTINY

The involvement of both the CBN and the SEC in the enforcement action is notable for its cross-regulatory character, bringing together the banking sector regulator and the capital markets authority in a coordinated exercise. This co-ordination signals that Nigerian authorities are prepared to deploy multiple regulatory levers simultaneously when examining the conduct of large, diversified financial groups whose activities span regulated activities overseen by different bodies.

The cybersecurity incident reporting failures are of particular concern given the growth of electronic transaction volumes in Nigeria and the rising risk of system breaches and fraud across the financial sector. Mandatory and timely reporting of cybersecurity incidents is a cornerstone of effective supervisory oversight, as it allows regulators to assess systemic risk exposures and co-ordinate responses before isolated incidents escalate into broader vulnerabilities. The ₦69 million penalty for non-disclosure reinforces the CBN's expectation that regulated entities bring relevant incidents to the regulator's attention promptly and transparently.