When money is transferred from a bank account without the customer’s authority, one of the most important questions is: Who is responsible for the loss? Is it the bank that processed the transaction? Is it the customer whose account was compromised? Is it the person who received the money? Or can more than one party be legally responsible? There is no single answer for every unauthorised bank transfer. Liability depends on how the transaction occurred, the conduct of the customer, the bank’s systems and procedures, the identity and conduct of the recipient, and the applicable legal and regulatory framework. The Central Bank of Nigeria’s Consumer Protection Framework places obligations on financial institutions to safeguard customer assets against fraud and unauthorised access, while also placing responsibilities on customers to protect their information and promptly report suspected compromise. This article explains how responsibility is determined when an unauthorised transfer occurs. What Is an Unauthorised Bank Transfer? An unauthorised bank transfer occurs where money is transferred from a customer’s account without the customer’s authority. Examples include: A fraudster transferring money through mobile banking. An unauthorised internet banking transfer. A third party using a compromised banking application. An unauthorised USSD transfer. A transfer initiated using stolen banking credentials. A fraudulent transfer resulting from a compromised device. A transaction carried out after a customer’s account information has been unlawfully obtained. The circumstances surrounding the transaction determine the appropriate legal response. Is the Bank Automatically Liable? No. A bank is not automatically liable simply because a customer disputes a transaction. At the same time, a bank cannot automatically escape liability simply by showing that the transaction passed its authentication process. The CBN’s Consumer Protection Framework requires financial institutions to establish policies and controls to safeguard consumer assets against fraud, including appropriate access controls, security measures, transaction monitoring and periodic assessment of security risks. Therefore, the question is not merely: “Was the transaction successful?” The more important question is: “Under the circumstances, did the bank discharge its legal, contractual and regulatory obligations?” When Can a Bank Be Liable? A bank can potentially be liable where the evidence establishes that the bank breached a duty owed to the customer and that breach caused or contributed to the customer’s loss. Circumstances that can become relevant include: Failure to maintain adequate security Financial institutions are expected to maintain appropriate controls to protect customer assets and information. The CBN Consumer Protection Framework expressly requires financial institutions to establish policies and controls to safeguard consumer assets against fraud. Failure to respond appropriately to suspicious activity Where a transaction displays unusual characteristics and the bank’s systems or procedures ought reasonably to have detected or addressed the activity, that can become relevant to liability. Failure to act after receiving a fraud report The bank’s conduct after the customer reports the transaction can also become relevant. For example, if a customer promptly reports an unauthorised transfer and the bank has an opportunity to take appropriate action but fails to do so, the circumstances should be examined carefully. System or security failure Where the evidence establishes that the transaction resulted from a failure in the bank’s systems or security controls, the bank’s responsibility becomes an important issue. Does Using an OTP Automatically Make the Customer Liable? No. The fact that an OTP was used does not, by itself, conclusively determine liability. The bank may rely on the OTP as evidence that the transaction was authenticated. However, the circumstances in which the OTP was obtained and used remain relevant. For example, there is a substantial difference between: A customer deliberately authorising a transfer; and A fraudster obtaining an OTP through a compromised system or deceptive circumstances. The complete transaction history should therefore be examined. What If the Customer Disclosed the OTP? This is more complicated. Suppose a fraudster impersonates a bank employee and persuades a customer to disclose an OTP. The fraudster then transfers ₦3 million from the customer’s account. The bank may argue that the customer’s own conduct enabled the transaction. That argument can be important. The customer’s duty to protect confidential banking information is recognised within the CBN’s consumer-protection framework. Customers are expected to protect their information and promptly notify their financial institution when they observe a compromise. However, whether the customer’s conduct completely eliminates the bank’s responsibility depends on the facts. The bank’s own security systems, fraud controls and response to the incident remain relevant. What If the Customer Did Not Disclose Any OTP or PIN? This can significantly strengthen the customer’s position, depending on the evidence. If the customer did not disclose security credentials and the transaction nevertheless occurred, the investigation should establish how the transaction was authenticated and executed. Relevant questions include: Was the customer’s device compromised? Was the account accessed from an unusual device? Was the transaction consistent with the customer’s normal activity? Were there unusual login attempts? Did the bank’s fraud-monitoring system detect anything unusual? Was a new device registered? Was the customer’s SIM compromised? Were there previous suspicious transactions? The answers can help determine where responsibility lies. What If the Customer’s Phone Was Stolen? A stolen phone does not automatically make the customer liable for every transaction subsequently carried out from the device. The circumstances must be examined. For example, it matters whether: The phone was protected by a password or biometric security. The banking application required additional authentication. The customer’s SIM was also compromised. The banking credentials were stored on the device. The customer promptly notified the bank and telecommunications provider. Transactions occurred before or after the bank was notified. The bank’s security obligations and the customer’s conduct must both be considered. What If the Fraudster Used the Customer’s Mobile Banking App? The use of the customer’s mobile banking application does not automatically establish that the customer authorised the transaction. The relevant question is how the fraudster obtained access and whether the bank’s authentication and security systems operated as required. This is particularly important in cases involving compromised devices, SIM-related fraud, malware, phishing or social engineering. The
Can You Sue a Bank for an Unauthorised Transaction in Nigeria?
Imagine checking your bank account and discovering that ₦2 million has been transferred without your permission. You immediately report the transaction to your bank and request a reversal. The bank investigates and tells you that the transaction was successfully authenticated. It then refuses to refund the money. At this point, two important questions arise: Can you sue a bank for an unauthorised transaction in Nigeria? And if the bank refuses to refund the money, what can you do to recover it? The answer is yes, a bank can be sued where the facts establish a valid legal claim against it. However, the mere fact that a customer did not personally initiate a transaction does not automatically make the bank liable. The circumstances surrounding the transaction must be examined carefully. This includes how the transaction was initiated, what authentication was used, whether the customer’s credentials were compromised, whether the customer disclosed any security information, what the bank’s systems detected, how quickly the transaction was reported and what the bank did after receiving the complaint. This article explains when a bank may be liable for an unauthorised transaction, whether a bank is required to refund the money, what evidence you need, what to do if the bank refuses to reverse the transaction and when legal proceedings may be appropriate. What Is an Unauthorised Bank Transaction? An unauthorised bank transaction is a transaction carried out on a customer’s account without the customer’s authority. It can include: Unauthorised bank transfers. Unauthorised ATM withdrawals. Unauthorised POS transactions. Unauthorised card payments. Unauthorised online payments. Unauthorised debits. Transactions resulting from compromised banking credentials. The circumstances differ from case to case. For example, a person may gain access to a customer’s banking application, obtain the customer’s card details through fraud, compromise the customer’s account or use other means to initiate a transaction. The legal consequences depend substantially on how the transaction occurred. Can You Sue a Bank for an Unauthorised Transaction? Yes. A customer can sue a bank where the facts establish a legally recognisable claim. However, the customer must establish the basis of the claim. A court will not simply order a bank to refund money because the customer says, “I did not authorise the transaction.” The evidence surrounding the transaction must be examined. Relevant questions include: How was the transaction initiated? What authentication was used? Was the customer’s device compromised? Was an OTP used? Was the customer’s PIN used? Did the customer disclose any security credentials? Did the bank detect unusual activity? Did the bank comply with applicable security requirements? When did the customer notify the bank? What action did the bank take after receiving the complaint? Can the recipient of the funds be identified? These questions can determine whether a claim against the bank is likely to succeed. Will a Bank Refund an Unauthorised Transaction? Not automatically. Whether a bank is required to refund an unauthorised transaction depends on the circumstances in which the transaction occurred and whether the bank breached a legal, contractual or applicable regulatory obligation. A bank is entitled to investigate a disputed transaction before deciding whether to reverse or refund it. However, the bank should not treat the fact that a transaction was successfully authenticated as automatically ending the customer’s claim. The relevant questions include: How was the transaction initiated? Was the customer’s PIN, OTP, password or other authentication credential used? Did the customer disclose any security credentials? Was the customer’s device or account compromised? Did the transaction display unusual or suspicious characteristics? Did the bank’s systems detect or respond appropriately to the transaction? How quickly did the customer report the transaction? What steps did the bank take after receiving the complaint? Therefore, the answer to “will a bank refund an unauthorised transaction?” depends on the evidence. Where the evidence establishes that the bank was responsible for the loss or breached a duty owed to the customer, the customer can pursue appropriate reliefs, including recovery of the money and, where justified, damages or other consequential relief. On the other hand, where the evidence establishes that the customer’s own conduct caused or materially contributed to the loss, the bank may rely on that conduct in defending the claim. The correct approach is therefore to establish how the transaction occurred and who bears legal responsibility, rather than assuming that either the bank or the customer is automatically liable. What If the Bank Says the Transaction Was Authenticated? This is one of the most common responses from banks. The bank may say that: Your PIN was correctly entered. Your OTP was successfully used. Your mobile banking application was used. The transaction came from your registered device. The transaction passed the bank’s authentication system. That evidence is relevant, but it does not necessarily end the dispute. Authentication establishes that the bank’s system received the required credentials. It does not, by itself, answer every question concerning who actually initiated the transaction or whether the transaction resulted from fraud, compromise or another circumstance for which the bank may bear responsibility. The particular facts must therefore be examined. What If You Gave the Fraudster Your OTP? This can significantly affect the case. Suppose a fraudster impersonated your bank and persuaded you to disclose an OTP. The fraudster then used the OTP to transfer money from your account. The bank may argue that you authorised the transaction or were negligent in disclosing the OTP. Whether that argument succeeds depends on the circumstances. The customer’s conduct is important, but so are the bank’s security, fraud-detection and customer-protection obligations. A customer should therefore provide the complete facts when reporting the incident rather than withholding information that may later become relevant. What If You Did Not Give Anyone Your PIN or OTP? That can strengthen the customer’s position, particularly where the evidence indicates that the transaction occurred despite the customer’s security credentials not being disclosed. The bank may still investigate how the transaction was completed. However, where there is evidence of a compromised account, security failure, unusual transaction activity or other