2014-08-14 | BPS/DIR/GEN/CIR/01/011

Circular on the Review of Operations of the NIBSS Instant Payment (NIP) System and Other EPayment Options with Similar Features

The Central Bank of Nigeria (CBN) has issued new directives regarding online funds transfers and electronic payment options. The directives aim to strengthen the risk aversion measures for NIBSS Instant Payment (NIP) system and other similar systems. These include categorizing online funds transfer into three categories based on security levels, setting daily limits, implementing SMS/email transaction alerts, introducing hardware tokens and soft tokens, mandating banks to establish internal procedures or policies, and requiring customers to issue a written indemnity for transactions exceeding the specified limits. Banks are expected to implement these changes by 31st December 2014 and communicate the new policies clearly to their customers before implementation.

CENTRAL BANK OF NIGERIA Central Business District P.M.B. 0187, Garki, Abuja. +234 - 0946238445 BANKING AND PAYMENTS SYSTEM DEPARTMENT BPS/DIR/GEN/CIR/01/011 August 13, 2014 To: All Banks CIRCULAR ON THE REVIEW OF OPERATIONS OF THE NIBSS INSTANT PAYMENT (NIP) SYSTEM AND OTHER ELECTRONIC PAYMENTS OPTIONS WITH SIMILAR FEATURES In order to further strengthen the risk aversion measures put in place for the operations of the NIBSS Instant Payment (NIP) system, and other electronic payments options with similar features, the Central Bank of Nigeria hereby issues the following directives: A categorization of online funds transfer from low security to highly secured transfer, with limits 1.

as specified below.

S/NCategoryRequired ControlDaily Limit forDaily Limit for Next
Instant ValueWorking Day Value
i.HighlySecured-HardwareTokenIndividual: ₦1mIndividual: N10m
OnlineFundTokenCorporate: N10MCorporate: N100m
Transfer-Behavioural Monitoring
(WEF-Jan15,BSMS/Email Trans Alert
2015)-User Name/Password
eAnti-phishing Solution
ii.Moderately Secure.Hardware/Soft TokenIndividual: ₦500kIndividual: N1m
OnlineFund-User ID and PasswordCorporate: A45mCorporate: N10m
TransferESMS/Email Trans Alert
(WEF-Jul30,uAnti-phishing Solution
2014)
iii.Basic SecurityOTP
"(One-Time-Individual: N200kIndividual: ₦1m
(WEF-Jul30,Password).
2014)uUser ID and Password
uSMS /Email Trans Alert
iv.Low SecurityuUser ID and PasswordIndividual: N20kIndividual: ₦100k
(WEF-Jul30,uSMS/Email Trans Alert
2014)

Banks are expected to achieve "Highly Secured Online Funds Transfer" status within six (6) months, i.e. with a deadline Of 31st December 2014.

Limits of N1million (Instant value) and N10million (Next day value) shall be applied for NIP and NEFT respectively, and other electronic payments options with similar features, initiated by individuals, with effect from 1st September, 2014. There shall be no limit on the amount that can be received into a customer's bank account from the platform.

For same day value (NIP), the maximum amount that can be transferred by an individual (cumulative) is N5 million.

  1. A customer shall issue a written indemnity to the bank, where they chooses to initiate transactions above the limits specified in item 1 above, subject to maximums of ₦5 million and N100 million for individual and corporate customers respectively 6. Banks are to establish internal procedures/policies for variants of the N5 million limits.

Transactions above the N1 million limit could be delayed by the receiving bank for not more than one (1) hour (as opposed to the current 2 minutes), before applying credit.

  1. Limits of N10 million (Instant value) and N100 million (Next day value) shall be applied for NIP and NEFT, respectively, and other electronic payments options with similar features, initiated by corporates with effect from 1st September 2014.

  2. Transfers above N100 million shall be effected through the Real Time Gross-Settlement System (RTGS)

  3. Banks are expected to return unapplied funds within 10 minutes, where their fraud/risk management systems flag such as suspicious or fraudulent.

  4. Banks are also expected to communicate the aforementioned policies clearly to their customers and give adequate notice, before implementation 11. Banks should encourage customers to pre-register beneficiaries of online transfers 12. Banks are encouraged to confirm all email transfer requests via the accounts officers

Best Regards, Director, Banking & Payments System Department

Tags
payments
infosec
fraud