Go back to Blog
Jennifer Edidiong
Marketing
9 min read
Share to
Why KYC Isn’t Enough to Stop Fraud (And What Fintechs Must Do Instead) - Updated
A meaningful share of fraud on African fintech platforms happens after onboarding, not during it. A customer clears every KYC check, passes identity verification, and receives account access. Weeks later, their account is used to move stolen funds, their profile has been compromised through a SIM swap, or they turn out to be a mule recruited after they legitimately onboarded.
None of these scenarios are visible at the point of signup. All of them are detectable if the right monitoring is in place after it.
This is the gap that KYC alone cannot close: it confirms who a customer is at a single point in time, not who they become or how they behave once they are inside your platform. This article covers why that gap exists, what fraud it leaves open, and what closing it actually requires.
What KYC Actually Solves (and What It Doesn’t)

KYC is the process of verifying a customer's identity at onboarding. It confirms that the person signing up is who they claim to be, that their ID is genuine, and that they do not appear on a sanctions or watchlist at the time of verification. Done well, it is essential. Done alone, it is insufficient.
KYC answers one question: is this person legitimate at this moment?
It does not answer the questions that matter after that moment: is this account still being used by the verified person and is the activity on the account consistent with who they said they were?
The distinction matters because fraud rarely happens the moment a bad actor creates an account. It happens when the account is used.
The Gap in Traditional Fraud Prevention
The fraud patterns that KYC cannot catch are not edge cases. They are the dominant fraud methods in Nigerian and African markets today.
SIM swap and account takeover: A verified customer's phone number is ported to a new SIM without their knowledge. The attacker intercepts OTPs, resets credentials, and gains access to an account that passed every KYC check. The account itself was legitimate. The fraud happened entirely after onboarding, through the authentication layer, not the identity layer.
NIBSS confirmed SIM swap fraud as one of the fastest-evolving schemes in Nigeria's financial system in 2026, with fraud losses rising 13% between Q4 2025 and Q1 2026.
Mule accounts: A real person, fully verified, opens an account legitimately and is later recruited or coerced into receiving and forwarding stolen funds. The identity check at onboarding confirms they are who they say they are. It cannot confirm that their account will not be used as a conduit for fraud weeks or months later.
Behavioural drift: A customer's early account activity is consistent with their stated purpose. Over time, transaction patterns change, volumes increase, new counterparties appear, and activity no longer matches the risk profile built at onboarding. Without ongoing monitoring, this drift is invisible until a complaint or a loss surfaces it.
Dormant account reactivation: An account sits inactive for months before suddenly processing a high volume of transactions. This pattern is consistent with a synthetic identity that was onboarded to pass initial scrutiny and activated later, or with a compromised account being used by a different person entirely.
This is an ever-increasing risk for Nigerian fintechs. NIBSS also identified social engineering and account compromise as the most prominent fraud techniques, noting that fraudsters flagged at one institution simply move to others because incidents are not being reported.
What the CBN Now Requires on Ongoing Monitoring
The regulatory expectation in Nigeria has moved clearly beyond onboarding-only compliance.
CBN Updated Circular, issued March 10, 2026, introduced mandatory baseline standards for automated AML solutions across all regulated financial institutions. Standard 5.2 of the circular explicitly requires continuous sync between KYC records, risk profiles, and transaction monitoring, not just at onboarding, but throughout the customer relationship.
Institutions that run KYC at signup and transaction monitoring in isolation are non-compliant under this standard regardless of how many alerts their systems generate. The CBN's enforcement record underlines the stakes.
The direction is clear: KYC at onboarding is the starting point, not the compliance programme. Ongoing monitoring that connects identity data, risk profiles, and transaction behaviour is now a regulatory baseline.
What Ongoing Risk Monitoring Actually Looks Like
Ongoing risk monitoring is not a single check run periodically. It is a connected set of signals that together produce a continuously updated picture of each customer's risk level.
Continuous transaction monitoring: Every transaction is assessed against the customer's established behaviour profile, their typical transaction amounts, counterparties, timing, and frequency. Deviations from that baseline trigger alerts for review rather than waiting for a complaint or a loss to surface the problem.
Dynamic risk scoring: A customer's risk score is not fixed at onboarding. It updates as new signals arrive, new counterparties, unusual transaction patterns, changes in account behaviour, and sanctions or PEP status changes. A customer who was low-risk at signup may become high-risk six months later, and the platform needs to know that before the risk materialises into a loss.
For a deeper look at how risk scoring works in practice, see our guide on fraud risk scoring for fintechs.
Real-time decisioning: When a transaction triggers an alert, the platform needs to act in real time, not after the funds have moved. Real-time decisioning connects the monitoring output to a defined action, hold the transaction, step up authentication, flag for compliance review, or block outright, before the window for intervention closes.
Audit trail and case management: Every alert, review, and decision needs to be documented. Under CBN Standard 5.9, institutions must be able to produce, in real time, who closed a specific alert, when, and why. An audit trail that cannot answer those questions fails the regulatory examination regardless of how well the monitoring itself performed.
KYC vs. Ongoing Risk Monitoring: What Each One Covers
KYC at Onboarding | Ongoing Risk Monitoring | |
| When it runs | Once, at signup | Continuously, throughout the customer lifecycle |
| What it confirms | Identity is genuine at this moment | Account behaviour remains consistent with the verified identity |
| Fraud it catches | Identity fraud at the point of onboarding | Account takeover, mule activity, behavioural drift, dormant reactivation |
| Regulatory coverage | Meets CBN KYC requirements | Meets CBN Standard 5.2 continuous monitoring requirements |
| What it misses | Everything that happens after signup | Nothing, if the monitoring is connected to identity data |
The table makes the gap visible. KYC and ongoing monitoring are not alternatives. They are two connected steps, and the second step is where the majority of fraud is actually happening.
How Dojah’s Profiled Risk Closes the Gap

Dojah’s Profiled Risk is built specifically for the monitoring layer that KYC alone leaves open. It connects identity data, transaction signals, and behavioural patterns into a single, continuously updated risk profile for each customer, giving fraud and compliance teams visibility across the full customer lifecycle.
- Continuous behavioural monitoring. Profiled Risk tracks every transaction, login, and account event against each customer's established behaviour profile. When activity deviates from the baseline, whether in amount, timing, counterparty, or pattern, it surfaces as an alert before funds move rather than after.
- Dynamic risk scoring that updates in real time. A customer's risk score in Profiled Risk is not a snapshot taken at onboarding. It updates continuously as new signals arrive, including transaction behaviour, device signals, counterparty patterns, and external risk data. A customer whose risk level changes after onboarding is flagged automatically, not discovered manually.
- Real-time decisioning connected to your workflows. Profiled Risk supports automated actions triggered by risk signals, step-up authentication, transaction holds, compliance escalations, and webhook notifications to internal tools, so the monitoring output connects directly to the response rather than sitting in a queue.
- Audit-ready case management. Every alert, review, and decision is logged and retrievable, supporting the CBN's Standard 5.9 requirement that institutions be able to produce documented evidence of alert investigation and resolution at any point during a regulatory examination.
For African fintechs and financial institutions building the monitoring layer that fraud patterns demand and the CBN now requires, Profiled Risk connects KYC data, behavioural signals, and compliance workflows in one place.
Sign up on Profiled Risk to see how continuous monitoring works across your customer lifecycle.
FAQs
1. Why is KYC not enough to prevent fraud on its own?
KYC confirms a customer's identity at the point of onboarding. It cannot detect fraud that happens after the account is created, including SIM swap-enabled account takeover or mule account activity that indicates a change in how the account is being used. Most fraud in Nigerian and African markets happens post-onboarding, not at signup.
2. What does the CBN require on ongoing monitoring beyond onboarding KYC?
CBN Circular (March 2026) explicitly requires continuous sync between KYC records, risk profiles, and transaction monitoring under Standard 5.2. This means KYC data and transaction monitoring cannot operate in isolation. Institutions that run them as separate systems are non-compliant under the current baseline standards.
3. What is dynamic risk scoring and why does it matter?
Dynamic risk scoring means a customer's risk level is updated continuously as new signals arrive, rather than being fixed at onboarding. A customer who appeared low-risk at signup may show high-risk signals months later through changes in transaction behaviour. Dynamic scoring ensures those changes are detected before they result in a loss.
4. How do mule accounts pass KYC if they are used for fraud?
Mule accounts pass KYC because the person opening the account is genuinely who they say they are. The fraud happens after onboarding, when the account is used to receive and forward stolen funds. KYC cannot detect this because it only evaluates identity at signup.
5. What is the difference between transaction monitoring and ongoing risk monitoring?
Transaction monitoring checks individual transactions against rules or thresholds to flag suspicious activity. Ongoing risk monitoring is broader: it connects transaction signals to the customer's verified identity, behavioural history, and risk profile to produce a continuously updated picture of each customer's risk level.
NB:
This article was originally published in April 2026 and updated in September 2026 to reflect current CBN guidance and add regional context on post-KYC fraud in Africa.
Start using Dojah for all your business needs