When money is transferred from a bank account without the customer’s authority, one of the most important questions is: Who is responsible for the loss? Is it the bank that processed the transaction? Is it the customer whose account was compromised? Is it the person who received the money? Or can more than one party be legally responsible? There is no single answer for every unauthorised bank transfer. Liability depends on how the transaction occurred, the conduct of the customer, the bank’s systems and procedures, the identity and conduct of the recipient, and the applicable legal and regulatory framework. The Central Bank of Nigeria’s Consumer Protection Framework places obligations on financial institutions to safeguard customer assets against fraud and unauthorised access, while also placing responsibilities on customers to protect their information and promptly report suspected compromise. This article explains how responsibility is determined when an unauthorised transfer occurs. What Is an Unauthorised Bank Transfer? An unauthorised bank transfer occurs where money is transferred from a customer’s account without the customer’s authority. Examples include: A fraudster transferring money through mobile banking. An unauthorised internet banking transfer. A third party using a compromised banking application. An unauthorised USSD transfer. A transfer initiated using stolen banking credentials. A fraudulent transfer resulting from a compromised device. A transaction carried out after a customer’s account information has been unlawfully obtained. The circumstances surrounding the transaction determine the appropriate legal response. Is the Bank Automatically Liable? No. A bank is not automatically liable simply because a customer disputes a transaction. At the same time, a bank cannot automatically escape liability simply by showing that the transaction passed its authentication process. The CBN’s Consumer Protection Framework requires financial institutions to establish policies and controls to safeguard consumer assets against fraud, including appropriate access controls, security measures, transaction monitoring and periodic assessment of security risks. Therefore, the question is not merely: “Was the transaction successful?” The more important question is: “Under the circumstances, did the bank discharge its legal, contractual and regulatory obligations?” When Can a Bank Be Liable? A bank can potentially be liable where the evidence establishes that the bank breached a duty owed to the customer and that breach caused or contributed to the customer’s loss. Circumstances that can become relevant include: Failure to maintain adequate security Financial institutions are expected to maintain appropriate controls to protect customer assets and information. The CBN Consumer Protection Framework expressly requires financial institutions to establish policies and controls to safeguard consumer assets against fraud. Failure to respond appropriately to suspicious activity Where a transaction displays unusual characteristics and the bank’s systems or procedures ought reasonably to have detected or addressed the activity, that can become relevant to liability. Failure to act after receiving a fraud report The bank’s conduct after the customer reports the transaction can also become relevant. For example, if a customer promptly reports an unauthorised transfer and the bank has an opportunity to take appropriate action but fails to do so, the circumstances should be examined carefully. System or security failure Where the evidence establishes that the transaction resulted from a failure in the bank’s systems or security controls, the bank’s responsibility becomes an important issue. Does Using an OTP Automatically Make the Customer Liable? No. The fact that an OTP was used does not, by itself, conclusively determine liability. The bank may rely on the OTP as evidence that the transaction was authenticated. However, the circumstances in which the OTP was obtained and used remain relevant. For example, there is a substantial difference between: A customer deliberately authorising a transfer; and A fraudster obtaining an OTP through a compromised system or deceptive circumstances. The complete transaction history should therefore be examined. What If the Customer Disclosed the OTP? This is more complicated. Suppose a fraudster impersonates a bank employee and persuades a customer to disclose an OTP. The fraudster then transfers ₦3 million from the customer’s account. The bank may argue that the customer’s own conduct enabled the transaction. That argument can be important. The customer’s duty to protect confidential banking information is recognised within the CBN’s consumer-protection framework. Customers are expected to protect their information and promptly notify their financial institution when they observe a compromise. However, whether the customer’s conduct completely eliminates the bank’s responsibility depends on the facts. The bank’s own security systems, fraud controls and response to the incident remain relevant. What If the Customer Did Not Disclose Any OTP or PIN? This can significantly strengthen the customer’s position, depending on the evidence. If the customer did not disclose security credentials and the transaction nevertheless occurred, the investigation should establish how the transaction was authenticated and executed. Relevant questions include: Was the customer’s device compromised? Was the account accessed from an unusual device? Was the transaction consistent with the customer’s normal activity? Were there unusual login attempts? Did the bank’s fraud-monitoring system detect anything unusual? Was a new device registered? Was the customer’s SIM compromised? Were there previous suspicious transactions? The answers can help determine where responsibility lies. What If the Customer’s Phone Was Stolen? A stolen phone does not automatically make the customer liable for every transaction subsequently carried out from the device. The circumstances must be examined. For example, it matters whether: The phone was protected by a password or biometric security. The banking application required additional authentication. The customer’s SIM was also compromised. The banking credentials were stored on the device. The customer promptly notified the bank and telecommunications provider. Transactions occurred before or after the bank was notified. The bank’s security obligations and the customer’s conduct must both be considered. What If the Fraudster Used the Customer’s Mobile Banking App? The use of the customer’s mobile banking application does not automatically establish that the customer authorised the transaction. The relevant question is how the fraudster obtained access and whether the bank’s authentication and security systems operated as required. This is particularly important in cases involving compromised devices, SIM-related fraud, malware, phishing or social engineering. The