There is one architectural diagnostic that separates CBN Sandbox-ready Nigerian fintech from products that appear ready but have critical gaps.
Can you name — precisely, with regulatory status — who performs each of these six functions in your product?
The Six Functions
const architectureDiagnostic = {
kyc: 'Named provider + regulatory status + KYC tier satisfied',
sanctionsScreening: 'Automated + onboarding AND ongoing + users AND counterparties',
fxConversion: 'Named licensed entity — "Paystack" is NOT an FX licence',
custody: 'Legally segregated — company bank account is NOT segregated custody',
settlement: 'T+1 or T+2 — NOT the same as authorization',
payout: 'Named executor + SLA + failed payout handling + reconciliation'
};
The Most Common Gaps
const commonGaps = [
{
gap: '"We use Paystack" as the FX answer',
reality: 'Paystack is a CBN-licensed PSP. Not an FX licence holder.',
fix: 'Named AFEX-licensed BDC, CBN-licensed IMTO or licensed fintech with FX permissions'
},
{
gap: 'User funds in company bank account',
reality: 'This is fund commingling — not segregated custody',
fix: 'Trust/escrow account at licensed bank — separate from operational account'
},
{
gap: 'Wallet credited on Paystack success',
reality: 'That is authorization. Settlement is T+1 or T+2.',
fix: 'Credit wallet only on confirmed settlement — not on charge.success webhook'
},
{
gap: 'Sanctions screening at onboarding only',
reality: 'Users must be screened on an ongoing basis',
fix: 'Nightly screening job against UN, OFAC, NFIU, PEP lists'
}
];
KYC — Named Provider Required
// Not "some verification service" — a named provider with named status
const kycSetup = {
bvnVerification: 'NIBSS (Nigerian Inter-Bank Settlement System)',
idVerification: 'Smile Identity / Youverify / Prembly',
livenessDetection: '95%+ confidence required — defeats static photo attacks',
sanctionsAndPEP: 'Included in most Nigerian KYC providers',
// VASP track additional
blockchainAnalytics: 'Chainalysis / Elliptic / TRM Labs — ALL incoming deposits'
};
Settlement State Machine — Required
// Authorization ≠ Settlement — model this explicitly
const STATES = {
INITIATED: 'created — no money moved',
AUTHORIZED: 'bank approved — NOT settled, NOT available',
SETTLED: 'in Paystack balance — T+1 or T+2',
AVAILABLE: 'credited to user wallet — ready for use'
};
// Available balance: only settled credits minus pending debits
const availableBalance = await ledger.query(`
SELECT SUM(CASE
WHEN entry_type = 'CREDIT' AND settlement_status = 'SETTLED' THEN amount
WHEN entry_type = 'DEBIT' AND settlement_status IN ('PENDING','SETTLED') THEN -amount
ELSE 0
END) AS available
FROM ledger_entries WHERE account_id = $userId
`);
The Corridor Map
// Required CBN Sandbox document
// Every entity, their regulatory status, data flows, fund flows, failure scenarios
const corridorMap = {
entities: [
{ name: 'Your Platform', status: 'CBN Sandbox Applicant' },
{ name: 'NIBSS', status: 'CBN-regulated infrastructure' },
{ name: 'Smile Identity', status: 'Licensed KYC provider' },
{ name: 'Paystack', status: 'CBN-licensed PSP' },
{ name: 'Partner Bank', status: 'CBN-licensed commercial bank' }
],
fundFlow: [
'User → Paystack (AUTHORIZED)',
'Paystack escrow → Paystack balance (SETTLED T+1)',
'Paystack → Trust account at Partner Bank (AVAILABLE)',
'Trust account → User wallet ledger (CREDITED)',
'User wallet → Recipient via NIP (PAID OUT)'
],
failureScenarios: [
'Paystack settlement delayed — do not credit user wallet',
'KYC provider down — queue and retry, do not onboard',
'Sanctions match on existing user — suspend account, escalate'
]
};
ZikarelHub LTD is Nigeria's #1 software and digital agency — Nigerian fintech built with the architectural clarity CBN examination requires.
Which of the six functions does your product have the least clarity on right now? 👇
Top comments (0)