Day: 15 May 2025

  • CRS DEADLINE ALERT OBLIGATIONS FOR FINANCIAL INSTITUTIONS

    CRS DEADLINE ALERT OBLIGATIONS FOR FINANCIAL INSTITUTIONS

    CRS DEADLINE ALERT – KEY OBLIGATIONS FOR FINANCIAL INSTITUTIONS

    The Common Reporting Standard (“CRS”), implemented under the Income Tax (Common Reporting Standards) Regulations, 2019, forms part of Nigeria’s commitment to automatic exchange of financial information with over 100 jurisdictions worldwide as part of the OECD Multilateral Competent Authority Agreement. 

    According to the regulations:

    • Annual returns must be filed with FIRS on or before 31 May 2025.
    • Institutions must perform due diligence to identify reportable accounts and report relevant data.
    • Where no reportable accounts exist, Reporting Financial Institutions (“RFIs”) are still obligated to submit a NIL return.
    • Non-compliance attracts a penalty of ₦10 million for the first month of default, with ₦1 million added for each subsequent month.

    WHAT IS A REPORTABLE ACCOUNT?

    A reportable account is an account held by an individual or entity that meets the criteria under the Common Reporting Standard (CRS) and must be reported to tax authorities. These accounts typically belong to account holders who are tax residents in jurisdictions that participate in CRS. Financial institutions must identify these accounts through due diligence and submit relevant information, including the account holder’s details, tax identification number, and account balance, to the tax authority annually.

    WHO MUST COMPLY

    • Depository Institutions: Banks, Microfinance Banks
    • Custodial Institution: Trustees, Brokerage Firms
    • Investment Entity: Asset Managers, Fintech Wallets, Private Equity (“PE”) Funds
    • Specified Insurance Companies: Life/Investment-linked Insurance Firms 

    CRS COMPLIANCE EXPECTATIONS

    1. Self Certification Form: RFIs must obtain a Self-Certification Form during onboarding for new accounts, capturing key customer information. 
    2. Due Diligence: RFIs must conduct due diligence to identify reportable accounts and classify customers into old accounts (pre-July 1, 2019) and new individual or entity accounts.
    3. Reporting: RFIs must file annual CRS  returns via the FIRS  portal for reportable accounts, including non-residents (CRS) and U.S. persons (FATCA), ensuring the information matches KYC data and reflects any changes, with FIRS auditing for accuracy and timeliness.
    4. CRS Policy Document: RFIs must maintain a CRS Policy Document outlining compliance procedures and prepare a CRS Due Diligence Report summarizing account classifications and actions taken.

    Immediate Internal Action Points

    1. Assess client base for any RFI classification (especially Fintechs, Insurers, Trustees).
    2. Review onboarding processes — ensure self-certification forms are in use and stored.
    3. Draft or update CRS Policy Documents for applicable clients.
    4. Prepare Due Diligence Reports and begin assembling 2024 CRS return data.
    5. Test XML filings ahead of the 31 May deadline to avoid last-minute errors.

    In addition, FIRS has directed that all outstanding CRS returns for prior years must be filed on or before 31 May 2025. Institutions that fail to comply may face further penalties, reputational risk, and audit scrutiny.

    We encourage all RFIs to assess their current compliance standing, regularize outstanding obligations, and ensure adequate internal controls are in place to meet these regulatory requirements going forward.

  • UI SPOOFING

    UI SPOOFING

    WHAT IS UI SPOOFING

    UI spoofing, or User Interface spoofing, is a cyberattack where malicious actors manipulate a user interface’s visual elements to deceive users, tricking them into actions they wouldn’t normally perform. This manipulation is designed to elicit sensitive information, such as login credentials, financial details, or personal data; induce clicks on malicious links that lead to malware downloads or phishing websites; and authorize unauthorized transactions by mimicking legitimate transaction screens.

    How UI Spoofing Works:

    1. Mimicking Legitimate Interfaces:
      In the context of cybersecurity, cybercriminals use fake UIs, mimicking trusted platforms, for spoofing and phishing.
    2. Deceptive Overlays:
      Deceptive overlays trick users by placing a fake, often hidden layer over a real app’s UI, leading them to interact with the fake instead. Common types include clickjacking, fake logins, overlay captchas, and imposter alerts.
    3. Manipulating Visual Cues:
      Visual cue manipulation deceives users by altering or creating misleading visual elements, like fake icons or warnings. For example, they might make a malicious file look like a harmless image or display a fake security warning to scare users into taking action.
    4. Exploiting User Trust: 
      Is a manipulation tactic used by cybercriminals and other malicious actors to deceive individuals by leveraging their inherent trust in familiar systems, people or situations.Essentially, it’s a form of social engineering that targets human psychology rather than technical vulnerabilities.

    Ways to Prevent UI Spoofing:

    1. By securing all communications with HTTPS and forming an encrypted tunnel that protects against data alteration.
    2. Make sure you have a consistent design and layout across your site that enables you to identify any discrepancies suggesting a spoofed interface.
    3. Implementing a multi-factor authentication(MFA) and having multiple forms of verification is important.
    4. Before providing credentials you should always  verify the website’s URL to ensure they are not on a spoofed site.
    5. Website owners should monitor networks for unusual activity to detect and prevent potential UI spoofing attempts.
    6. Have a secure anti robust security system to protect and prevent any form of UI spoofing.
    7. Implementation of strict permission management is important to have in order to reduce the risk of UI spoofing and ensure interface security.