On 12 May 2025 the National Bank of Ethiopia's Oversight of the National Payment System: Licensing and Authorization of Payment Instrument Issuer (Amendment) Directive No. ONPS/10/2025 took effect, more than doubling the minimum paid-up capital for a licensed payment instrument issuer, from 50 million to 100 million birr, and mandating that mobile money wallets from different providers interoperate rather than sit as closed loops. Seven months later, at the second Ethiopia Digital Payment Conference in Addis Ababa, NBE used the same stage to launch the draft National Digital Payments Strategy 2026-2030, the five-year roadmap that sets the direction every subsequent payment directive is likely to follow. Between the two, a payment instrument issuer's risk and audit function is now sitting on a materially different foundation than it was eighteen months ago.
Who this is for: Risk Managers and Internal Auditors at Ethiopian payment instrument issuers, mobile money operators, and bank-owned payment subsidiaries.
Does our paid-up capital still clear the bar?
The headline change in ONPS/10/2025 is arithmetic: 100 million birr in cash, deposited with a commercial bank in Ethiopia, up from the previous 50 million birr threshold. For an issuer licensed under the old rule, that is not a one-off top-up to file away. Capital adequacy against a threshold that has just doubled is now a standing item for the risk committee, not a licensing-day formality, because a capital position that clears the bar today can slip below it as the business grows, dividends are paid, or losses are absorbed. The practical discipline is the same one we described for insurers facing NBE's tightened board and executive standards: build the evidence file and the monitoring routine now, not the week before a renewal or an inspection asks for it, a habit we set out in more detail when Ethiopia's insurers were given a fit-and-proper deadline of their own.
Are we ready for money to move through wallets we don't operate?
Interoperability changes what a payment issuer's monitoring function actually has to watch. Under the amended directive, mobile money wallets are expected to connect to one another rather than operate as closed systems, and issuers must participate in the Ethiopian Instant Payment System (EIPS), the real-time rail NBE is building for transfers, QR payments and bulk disbursements across providers. That is good for customers and good for financial inclusion. It is also a genuine shift in what a fraud or AML monitoring model has to account for: a transaction can now originate on a rival's wallet, cross into yours through EIPS, and land with a counterparty your own onboarding process never touched. A monitoring rule tuned only to your own customer base will miss the pattern that starts somewhere else and only surfaces on your side of the rail.
Who is allowed to own how much of us?
Reporting on the directive describes an ownership structure NBE is now actively policing: no entity other than government, a telecom operator, or another licensed payment system operator may hold more than 40% of a payment instrument issuer, and any single person's combined direct and indirect stake is capped at 60%. For a founder-led fintech that has taken on investors informally, or a startup where an early backer's stake has crept up through successive funding rounds without anyone recalculating the indirect holding, this is worth checking against the current cap-table rather than assuming last year's structure still clears it. It is the same discipline NBE is applying across the financial sector as ownership and fitness questions move from informal understanding to a number a regulator checks.
What happens the moment a customer moves 5,001 birr?
Security requirements moved alongside the ownership and capital changes. Reporting on the amendment describes a two-factor authentication requirement for electronic money transactions above 5,000 birr, alongside a raised daily transaction limit of 300,000 birr and a daily e-money balance limit of 150,000 birr. For a risk or audit team, the question is not whether the control exists in the product, but whether it has actually been tested at the threshold: does a transaction of exactly 5,000 birr trigger it correctly, does the control degrade gracefully when a customer's device cannot support the second factor, and is a failed 2FA attempt logged and reviewable rather than silently retried until it passes.
What does the 2026-2030 roadmap expect from us next?
The National Digital Payments Strategy launched in December 2025 is a strategy document, not a directive, so it does not itself create a binding obligation the way ONPS/10/2025 does. Treat it instead as the clearest signal available of where the next round of directives is heading: deeper interoperability, wider digital ID integration, expanded merchant acceptance, and a payments ecosystem NBE explicitly wants to be inclusive of women, rural customers and small merchants who have been hardest to reach through licensed channels. A risk function that reads the roadmap now has a head start on the compliance obligations that follow it, the same way early movers on Ethiopia's capital market reforms are building governance infrastructure ahead of the detailed rules that will eventually bite, a pattern we traced when looking at what issuers should build before an ESX listing.
The file an examiner will actually ask for
Build this before an inspection or a licence renewal asks for it, not during one:
- Current paid-up capital position against the 100 million birr threshold, with the cash deposit evidenced at a named commercial bank, refreshed on a set schedule rather than checked once
- An up-to-date ownership register mapping direct and indirect holdings against the 40% single-category cap and the 60% single-person cap, including any funding rounds since the last review
- Interoperability and EIPS integration status, with evidence of testing against transactions originating from other providers' wallets, not just your own
- Documented, tested 2FA behaviour at and around the 5,000 birr threshold, including what happens when the second factor fails
- A monitoring model that has been reviewed for cross-provider transaction patterns since interoperability went live, not just the patterns your own customer base generates
- A one-page internal briefing on the 2026-2030 strategy's direction, so the board and risk committee are not hearing about the next directive for the first time when it is published
What this changes for bank-owned subsidiaries versus telecom-led issuers
The ownership caps land differently depending on who is standing behind the licence. A payment subsidiary set up by a bank generally has capital and governance infrastructure built for a heavier regulatory load already, so the 100 million birr threshold and the ownership caps are usually a compliance-mapping exercise rather than a structural one. A telecom-led or independent fintech issuer, often younger, leaner and carrying investors who came in on more informal terms, is more likely to find that a cap-table built for speed does not automatically clear a cap built for concentration risk. Either way, Ethiopia's mobile money base, well over a hundred million accounts and growing fast, means the volume moving through these controls is no longer a rounding error against the banking system; it is a large and rising share of it.
Turning capital, ownership and interoperability monitoring into a standing discipline rather than a licensing-week scramble is exactly what DaraCorp's Risk Management & Compliance course is built to embed in a risk team's routine, and it pairs naturally with Cybersecurity & Data Protection for the control-testing discipline a 2FA and cross-provider monitoring requirement now demands.
This article describes how payment instrument issuers are adapting to Directive No. ONPS/10/2025 and the draft National Digital Payments Strategy 2026-2030, and is not legal advice or a definitive interpretation of either. Confirm your specific capital, ownership and monitoring obligations against the primary sources at nbe.gov.et and take professional advice on your institution's particular circumstances.

