Lead Signal
Zambia's Cyber Security Act, 2025 designates banking and finance—including payment gateways and core banking systems—as critical information infrastructure subject to registration, data localisation, annual audits and incident-reporting to the new Zambia Cyber Security Agency; non-compliance penalties up to ZMW1,200,000 and/or 10 years' imprisonment. The law's companion Cyber Crimes Act 2025 was enacted alongside it, and this pairing is assessed as the single most material operational-resilience development to emerge from this cycle's review. Zambia's central bank has direct experience of the risks the new framework targets: Bank of Zambia was hit by a Hive ransomware attack in 2022, in which it declined to pay the ransom and reported minimal system damage, and suffered a Facebook account hack in July 2023. Civil-society and legal-sector voices have already begun contesting how the new architecture is governed: the Law Association of Zambia and a wider civil-society coalition criticised the Cyber Security Agency's placement under the Office of the President as lacking independent governance and parliamentary oversight, a concern with direct bearing on how critical-payments-infrastructure oversight will be exercised in practice.
Other Developments
Zambia's payments-licensing architecture is itself mid-transition. The National Payment System Act, 2026 was enacted 8 April 2026, repealing and replacing the National Payment Systems Act 2007, but it awaits ministerial commencement via statutory instrument; the 2007 Act framework remains operative pending that instrument, and this cycle's review could not independently verify commencement status against a Gazette instrument as of the 4 July 2026 baseline. Separately, a parliamentary committee reviewing the preceding National Payment System Bill 2025 flagged that its restructuring and insolvency provisions for payment service providers could create procedural uncertainty against the existing Corporate Insolvency Act, and recommended harmonisation.
On digital money, Bank of Zambia's plan calls for establishing a CBDC framework between 2024 and 2026, including implementation and supervision regulations plus a pilot exploring possible use cases, though named pilot use-cases have not yet been published. Cryptocurrencies are not legal tender in Zambia, and the Bank of Zambia Act vests exclusive note and coin issuance in the central bank.
Corridor dynamics continue to deepen: Zambia joined the SADC-RTGS as a participant in September 2014 via BoZ and nine commercial banks, and the system interlinks with PAPSS and COMESA REPSS; PAPSS itself, launched January 2022, connects ten central banks including Zambia and supports real-time local-currency settlement, though it has not yet disrupted entrenched correspondent-banking pathways. Commercially, MTN Mobile Money Zambia launched a service enabling customers to send money directly from wallets to international bank accounts in the EU, UK and Canada, described as Zambia's first direct wallet-to-bank international transfer offering.
Industry structure shows an oligopolistic telecom/mobile-money market—Airtel Zambia holds roughly 48% subscriber share and MTN Zambia 33-35%, with state-owned Zamtel the remainder—and Airtel Networks Zambia Plc surpassed $1 billion market capitalisation on the Lusaka Securities Exchange on 8 June 2026. Standard Chartered is separately reported to be exploring a potential sale of its wealth and retail banking units in Botswana, Uganda and Zambia, an unconfirmed development that would signal a possible market-structure shift among incumbent international banks. On the consumer side, a World Bank diagnostic found Bank of Zambia lacks a dedicated, adequately resourced consumer-protection function—roughly five officers covering both banking and financial consumer protection—even as cybercrime including phishing and social-media fraud has cost the Zambian economy over K111 million, feeding political momentum for the 2025 cyber-law framework; no dedicated APP-fraud mandatory-reimbursement regime exists.
Cross-Monitor Connections
Zambia remains in FATF/ESAAMLG enhanced follow-up: a 2022 follow-up report found progress on some technical-compliance deficiencies but downgraded Recommendations 2, 5 and 7. The Financial Intelligence Centre is the designated AML/CFT supervisor for Virtual Asset Service Providers absent a dedicated VASP licensing regulator, applying FATF Recommendation 15 requirements including suspicious-transaction-report filing on attempted transactions. This AML/CFT posture, and any illicit-finance or sanctions-evasion analysis arising from it, is flagged to the Financial Intelligence Monitor rather than assessed here; the Sentinel-fed W11 material is carried in this monitor as provenance only.
Outlook
Two forward markers frame the next review window. Bank of Zambia's CBDC framework and pilot phase are expected to reach completion around 2026-Q4, closing out the 2024-2026 plan period, while the National Financial Inclusion Strategy II runs through 2028-Q4, continuing to set interoperability, agent-exclusivity and inclusion targets. The more immediate marker, however, is procedural: the ministerial commencement instrument for the National Payment System Act 2026 remains outstanding, and Bank of Zambia's Cyber Security Agency compliance-onboarding cycle is now underway following the April 2025 Cyber Security Act enactment, with annual audit and reporting obligations already active for payment gateways and core banking systems. Both threads warrant close tracking into the next cycle.