Lagos, Nigeria — On August 20, 2026, forensic and financial crimes expert Oyindamola Aboaba laid bare what she believes is Nigeria’s most pressing hurdle in the digital finance space. Speaking to BusinessDay’s Oluwatobi Ojabello, Aboaba declared, “Nigeria’s biggest virtual asset challenge is knowing who is behind the wallet.”
This statement cuts right to the heart of the country’s ambitious new guidelines for taxing virtual assets, highlighting the intricate dance between regulation and enforcement.
Oyindamola Aboaba’s crucial insight on Nigeria’s virtual asset challenge
Her assessment reveals the profound difficulties regulators face in tracing illicit funds and catching financial criminals within a digital landscape that grows more fragmented by the day. Aboaba didn’t just identify a problem; she outlined the practical implications for Nigeria’s financial transparency and its ongoing fight against an evolving tide of digital malfeasance.
Aboaba quickly moves to qualify any broad assumptions about virtual assets being inherently anonymous or criminal. She points out that transactions on many public blockchains actually leave a permanent, verifiable trail. The real investigative puzzle, she explains, lies in connecting that digital footprint to the actual human being who controls a specific crypto wallet.
She draws a sharp distinction between the traditional financial system and the emerging virtual asset world. Banks, for instance, have established control points: they know who opens an account, meticulously record transactions, conduct ongoing monitoring, and readily respond to law enforcement inquiries. But Aboaba observes that virtual assets tend to fracture these very control points.
The battle for attribution in a fragmented digital world
An individual can move value across international borders within minutes, she details, transferring assets between multiple wallets, engaging with platforms spanning different jurisdictions, or funneling funds into self-custodied wallets. This entire process can unfold without ever touching a regulated intermediary.
Add to this the complexity of peer-to-peer transactions, numerous exchanges, and the rapid movement across different assets or blockchains, and an investigation can quickly become a labyrinth. The vulnerability isn’t simply “crypto is anonymous,” Aboaba contends.
Instead, it’s the potent combination of speed, global reach, and deeply fragmented identity information that creates opportunities for exploitation.
This reality underscores why international bodies like the Financial Action Task Force (FATF) require Virtual Asset Service Providers (VASPs) to implement preventive measures comparable to financial institutions, including robust customer due diligence and suspicious transaction reporting, much like the way Nigeria divides its wealth through established frameworks.
Tax IDs: A step forward, but significant gaps remain
Nigeria’s new NRS guidelines mandate that VASPs collect tax identification numbers (TINs) during onboarding and maintain continuous transaction records. Aboaba acknowledges these measures can significantly improve traceability, creating a stronger link between a customer’s identity and their platform activity. From a forensic perspective, this is a crucial step.
She explains that while an investigator might observe funds moving between wallets on a public blockchain, the wallet address itself reveals nothing about its controller. Reliable customer information becomes the vital missing piece.
By mandating TIN collection, the new rules theoretically allow investigators to move from a specific transaction to an account, then to a verified individual or business, and finally to their broader transaction history.
But the expert also highlights important gaps that persist. A tax ID doesn’t automatically confirm that the person presenting it is the legitimate owner of that identity. Funds can still flow from regulated Nigerian platforms into self-custodied wallets, peer-to-peer networks, or offshore platforms, where Nigerian VASPs have little to no oversight.
Aboaba stresses that knowing who conducted a transaction doesn’t necessarily tell an investigator where the funds originated, why they were moved, or who might ultimately benefit from them. So, while new requirements provide a foundational layer, tax ID collection and record-keeping must sit within a broader framework of identity verification, transaction monitoring, risk assessment, and investigation.
Distinguishing collection from genuine verification
Aboaba argues that the distinction between merely collecting information and genuinely verifying it is critical. If someone types a tax ID into an onboarding form and the platform simply stores it, that’s just data collection. Verification means establishing through an authoritative source that the Tax ID is valid, belongs to the individual, and is consistent with other identity information.
For an individual, this ideally means checking the tax ID against the underlying identity information associated with the National Identity Number (NIN) and reconciling details like name and date of birth. For a corporate customer, the same principle should extend to Corporate Affairs Commission (CAC) information, and ultimately to the people who own or control the business.
The NRS itself states that individual tax IDs are derived from NIN information, while business tax IDs are linked to CAC registration. A mature process should also include exception rules for when names don’t match, and clear, logged protocols for overrides and information refreshing.
Beyond paper compliance: readiness for investigation
Record-keeping is only truly useful if those records can be traced and analysed, Aboaba asserts. She poses a hypothetical scenario: a VASP is asked to explain a customer’s activity over two years following a suspicious transaction.
If those records are scattered across different systems, stored in inconsistent formats, or cannot easily be linked, then simply “having” the information is very different from being able to use it.
A real investigation demands the ability to reconstruct events. Investigators should be able to establish when a customer joined, how their identity was verified, which wallets or bank accounts were linked, what transactions occurred, what alerts were generated, and how the company responded.
There must also be a clear audit trail; if customer information was changed, the system should show what changed, when, and who approved it.
This is the distinction between paper compliance and investigation-readiness. Paper compliance asks: “Do we have the records?” An effective system, she notes, asks: “Can we use those records to explain what happened?” For regulators and investigators, the second question is far more important.
Sandbox readiness and avoiding past regulatory pitfalls
The Central Bank of Nigeria’s (CBN) Regulatory Sandbox for virtual asset operators, which closes applications on August 31, presents a critical opportunity. Aboaba believes a VASP applying shouldn’t just submit policies or describe its compliance framework. It needs to demonstrate that those controls actually work when tested under real or closely supervised conditions.
For example, can the platform identify a suspicious transaction, send an alert to the right person, and follow a clear investigation process? Is there proper governance if a customer needs to be restricted, and is it documented? If a cyber incident occurs, does the company know who is responsible for responding?
A genuinely sandbox-ready VASP should demonstrate an end-to-end operating model: a functioning product, reliable technology, clear governance, effective financial-crime controls, consumer safeguards, and the ability to provide regulators with meaningful information. The sandbox, then, should be testing a functioning control environment, not creating one from scratch.
Aboaba also points to common failures in compliance regimes across other African markets. This often happens when regulatory frameworks are in place, but the capacity for effective oversight falls short, a lesson Nigeria has learned at various points in its institutional development.
The FATF highlighted this global problem again in 2026: many jurisdictions now have virtual-asset legislation, but implementation gaps persist, and criminals exploit those gaps. For Nigeria, the lesson is clear: measure outcomes, not just compliance submissions.
Can information move efficiently between VASPs, the NRS, NFIU, CBN, SEC, and law enforcement, much like the broader institutional challenges faced by Nigeria’s shipping line in its time?
Nigeria’s standing: The stakes of effective regulation
Beyond fines, Aboaba stresses what’s truly at stake for Nigeria if VASPs fall short: the country’s standing with international banking and correspondent relationships. International financial relationships are heavily influenced by perceptions of risk. When a foreign bank decides whether to maintain a correspondent relationship with a Nigerian institution, it looks not just at that individual bank, but at the wider environment.
This includes the strength of regulation, the effectiveness of anti-money laundering controls, and the country’s ability to detect and respond to illicit financial activity. Virtual assets, she notes, increasingly form part of that picture. If significant volumes of money can move through Nigerian virtual-asset platforms without reliable customer identification, transaction monitoring, or regulatory oversight, that raises questions beyond the crypto sector itself.
The consequences, Aboaba believes, are unlikely to be as simple as one compliance failure immediately causing international banks to withdraw. But persistent weaknesses can contribute to increased scrutiny, more expensive due diligence, and greater reluctance among international counterparties to take exposure to Nigerian institutions.
Nigeria has made significant progress in strengthening its anti-money-laundering framework, and protecting that progress matters for its economic future. Ultimately, what’s at stake is confidence. Nigeria wants its banks, fintechs, and other financial institutions to participate fully in global markets.
For that to happen, international counterparties must have confidence that the systems through which value moves are properly regulated and that abuses can be identified and addressed, a journey towards transparency that continues to define Nigeria’s public life.
If Aboaba were advising a Nigerian VASP right now, her first piece of advice before enforcement begins wouldn’t be to update a compliance manual or hire more officers. Instead, she’d ask them to choose a customer and reconstruct their entire journey. Who are they? How was their identity verified? What accounts or wallets are connected? What transactions occurred? Were any unusual, and what happened next?
If answering those questions requires several teams, disconnected spreadsheets, or extensive manual work, that’s a warning sign. Her recommendation is to start with the customer-to-transaction data architecture: ensuring customer identity, transaction activity, monitoring alerts, and investigative records can all be reliably connected.
Once that foundation is sound, transaction monitoring, suspicious activity investigations, and regulatory reporting become far more effective. The goal, she concludes, isn’t just to demonstrate a compliance program, but to prove that it actually works when something goes wrong.


