When Regulation Became Infrastructure

Why Nigeria's regulatory shift is bigger than compliance.

By Oluwafemi Ofobutu

Most organisations think Nigeria is introducing more regulations.

It isn’t.

Nigeria is rebuilding the infrastructure through which trust is established.

For decades, organisations prepared for regulation the way students prepare for an examination they have been dreading.

Weeks before an audit, policies were dusted off and quietly rewritten. Evidence was gathered from folders, spreadsheets, emails, screenshots, and shared drives, much of it scattered across people who had long since forgotten why a particular decision was made. Consultants arrived with clipboards and questions. Documents were reviewed. A report was issued. A certificate was framed and hung on a wall somewhere near reception. Then life returned to normal until the next cycle began.

Compliance was an event. It had a beginning and an end, and everyone in the building knew when audit season had arrived, the way everyone knows when rain is coming.

That world is quietly ending in Nigeria, and the reason is not the one most people assume.

Most public conversation about Nigerian regulation treats it as a story about volume. More rules. More circulars. More requirements to track. That framing misses what is actually happening. The nature of regulation itself is changing, not merely its quantity. Compliance is moving from something an organisation prepares for a few times a year into something an organisation is expected to demonstrate continuously, through the way its systems operate every single day. This shift touches every regulated business in the country, and it is worth understanding clearly, because it will not reverse.

It helps to remember how recent the old model actually was, and how much sense it made at the time. A generation ago, a Nigerian insurance company or bank kept its records in filing cabinets, its risk register in a bound ledger, and its evidence of a training session in a signed attendance sheet tucked into a folder somewhere. An annual audit made sense as a rhythm because the underlying business barely changed month to month. A branch manager in Kano ran things much the same way in June as in December. A regulator visiting once a year could reasonably expect to see a fair picture of the whole institution, because the institution itself moved slowly enough for a snapshot to mean something.

None of that was careless. It was simply matched to the pace of the business it was regulating.

Trust used to be produced by buildings, signatures, and paper. Today, trust is increasingly produced by software.

The Economy Changed Before the Rules Did

Twenty years ago, a Nigerian bank largely operated inside physical branches, local data centres, and organisational boundaries that were easy to draw on a map. A customer walked in, signed a form, and a teller entered the transaction into a system that lived a few floors away.

Today, a single payment might pass through cloud infrastructure hosted on another continent, a payment processor owned by a company the customer has never heard of, an identity verification service, a fraud detection model, and several application programming interfaces connecting all of them, in less time than it takes to read this sentence. A Nigerian's identity itself now lives partly as a National Identification Number issued by the National Identity Management Commission, linked to a mobile line, a bank account, and increasingly a health record, each of them held by a different organisation, updated on a different schedule, and expected somehow to remain consistent across all of them.

And when an economy becomes something that runs on software, the regulation of that economy eventually has to become something that understands software too. Nigeria is living through that transition right now, and so is much of the rest of the continent.

Nigeria Is Not Writing More Rules. It Is Building a Digital Trust Economy.

Much of the public discussion focuses on individual instruments. The Nigeria Data Protection Act. The Nigeria Data Protection Commission. The licensing of Data Protection Compliance Organisations. The Central Bank of Nigeria's tightened requirements around money laundering and terrorism financing. Beneficial ownership registers. Supervision based on risk rather than routine. Growing expectations around cybersecurity and digital identity.

Looked at individually, each of these appears to be a separate compliance obligation, another item on an already long list. Looked at together, a different picture forms. Each one is a layer in the same underlying structure, and that structure has a single purpose. It is no longer only to punish misconduct after the fact. It is to make trustworthy behaviour something that can be measured, repeated, and demonstrated on request, not merely claimed.

Nigeria is not maintaining a growing pile of unrelated obligations. It is gradually assembling one distributed system for trust, in which identity, financial integrity, privacy, and accountability are increasingly built to reinforce each other rather than sit in separate filing cabinets.

I call this Trust Infrastructure:

the collection of systems, controls, evidence, governance, identity, and operational processes that continuously demonstrate an organisation deserves to be trusted.

That is a historic shift, even if it is arriving quietly, one circular at a time.

Consider the Nigeria Data Protection Act itself. Passed in 2023, it replaced an older regulation that had governed data protection since 2019 and established the Nigeria Data Protection Commission as an independent regulator with real enforcement power. The Act requires organisations that process personal data at meaningful scale to appoint a qualified Data Protection Officer, notify the Commission within seventy two hours of a breach likely to harm a data subject's rights, and register formally as a controller or processor of major importance.

None of that would matter much if it stayed on paper. It has not stayed on paper. In July 2025, the Commission imposed a penalty of roughly seven hundred and sixty six million naira against MultiChoice for transferring personal data across borders without a lawful basis, one of the largest enforcement actions taken under the Act to date. That single case changed how seriously investors and enterprise buyers now assess regulatory exposure in Nigerian digital markets. A regulation that only existed on paper could never have produced that outcome. A regulation with the power to inspect actual systems and actual data flows could.

The Act also created something unusual by international standards, a licensed class of organisations called Data Protection Compliance Organisations, established under Section 33 of the Act. These are law firms, consultancies, and technical service providers accredited by the Commission to audit, train, and advise on data protection compliance, and every filing an organisation makes under the Act must be accompanied by a verification statement from one of these licensed bodies. In effect, Nigeria has built a professional layer of independent auditors directly into its data protection regime, rather than leaving verification entirely to self reporting. That is not the behaviour of a government simply adding paperwork. It is the behaviour of a government building infrastructure for ongoing verification.

The Central Bank's expectations follow the same pattern from a different direction. Under the current Anti Money Laundering, Counter Financing of Terrorism, and Counter Proliferation Financing Regulations, financial institutions are required to maintain a comprehensive compliance programme with board level oversight and a senior compliance officer who reports directly to that board, not buried three levels down an organisational chart. Customer due diligence rules set out precisely when extra scrutiny is triggered, for occasional transactions above a defined threshold, for wire transfers, and whenever there is genuine doubt about a customer's identity. Suspicious transactions must be reported to the Nigerian Financial Intelligence Unit promptly, and large currency transactions within a set number of days of the transaction itself.

Read as a checklist, these requirements look like more of the same. Read as a system, they describe something else entirely. They describe an expectation that a bank can, at any moment, reconstruct exactly what happened with a specific customer, on a specific date, and show the reasoning behind every decision that followed. That is not a documentation requirement. It is an evidence requirement, and evidence requirements can only be satisfied by systems that produce evidence as they operate, not by teams that assemble it afterward under deadline.

Beneficial ownership transparency belongs in the same conversation, even though it rarely gets discussed alongside data protection or money laundering rules. Since the Companies and Allied Matters Act was updated in 2020, Nigerian companies have been required to identify and register the individuals who ultimately own or control them, not merely the corporate entities that sit on the surface of an ownership chart. The intent is straightforward. A shell company can hide behind another shell company almost indefinitely, but a person cannot. Once regulation insists on reaching the actual human being behind a structure, it is no longer regulating paperwork. It is regulating reality, and reality has to be verified rather than declared.

Supervision based on risk follows the same logic from yet another angle. Older regulatory models tended to apply the same intensity of scrutiny to every institution of a given size, regardless of what it actually did or how exposed it actually was. A risk based approach asks a harder question first. Where is the actual exposure concentrated, and does the institution's own monitoring reflect that concentration. A small lending platform serving low income borrowers and a large custodian bank holding pension assets are not exposed to the same risks, and treating them as though they were wastes supervisory attention on the wrong places. This approach demands more from the institution being supervised, because it can no longer point to a generic policy binder as proof of compliance. It has to show that its own risk assessment is current, specific, and reflected in how it actually allocates attention day to day.

Modern regulation no longer asks what organisations intended.

It asks what their systems can continuously demonstrate.

Regulation Is Moving From Documents to Systems

For a long time, a regulator's central question to a regulated organisation was some version of, do you have a policy for this. Increasingly, the question has changed to something harder to answer with a document. Can you show that this policy is actually operating.

That single change in the question rearranges everything downstream of it. A policy becomes a control. A control becomes a process embedded in daily operations. That process, if it is well designed, generates evidence simply by running. The evidence, if it is connected properly, becomes continuous rather than something reconstructed once a year. Trust stops being a claim. It becomes observable.

An organisation can own beautifully written policies and still fail an examination, because the examiner is no longer asking about intention. The examiner is asking about execution, and execution leaves a different kind of trace than a policy document does, or it leaves no trace at all, which is itself increasingly treated as a finding.

Named plainly, the shift looks like this.

From Documents to Systems

Policy
Control
Execution
Evidence
Continuous Assurance
Trust
Old Model New Model
A policy document A control that actually runs inside a system
A spreadsheet updated once a quarter A dashboard updated as events happen
An annual audit Continuous monitoring that never fully stops
Collecting evidence after the fact Generating evidence as a byproduct of normal work
A compliance team working in isolation A responsibility shared across engineering, operations, and finance
A periodic review An assurance that holds every day of the year, not only in the weeks before an inspection
Governance, once mostly a matter of committees and sign offs An operational discipline embedded in how systems are actually built
Documentation Evidence a machine can verify without a person retyping it into a different format

None of these transitions happen instantly, and none of them happen everywhere at once. But taken together, they describe where the direction of travel is heading, and an organisation that understands the direction early has time to build toward it deliberately, rather than being dragged toward it by an enforcement action.

The Spreadsheet Is Quietly Losing Its Job

Few tools have shaped corporate compliance as thoroughly as the ordinary spreadsheet. It has served as the universal language of audits, risk registers, control libraries, asset inventories, and remediation trackers for as long as most compliance officers have been in the profession.

But a spreadsheet was built to record information at a moment in time. It was never built to answer the questions modern regulation increasingly asks. Which controls failed today. Which systems changed since yesterday. Who accessed sensitive customer information this morning, and why. Where is the evidence that a specific safeguard was actually tested last quarter, not merely described in a policy binder.

These are operational questions about a living system, and a static file cannot answer operational questions about a living system, no matter how carefully it is maintained. The future of compliance work is unlikely to be organised around spreadsheets passed between departments once a quarter. It will be organised around dashboards connected directly to the systems generating the underlying evidence, updated as those systems run rather than reconstructed when someone finally asks.

This is not simply a better piece of software replacing a worse one. It is a change in the philosophy of governance itself, from governance as a periodic review of the past to governance as a continuous property of the present.

The pattern is not confined to banking, even though banking tends to dominate the conversation. A telecommunications operator registering millions of subscribers under rules set by the Nigerian Communications Commission faces the same underlying question as a bank, whether it can prove, for any single subscriber, when a SIM was registered, whose identity was verified, and what happened when that verification failed. A hospital or health insurance administrator operating under the newer national health insurance framework faces a version of the same question about patient records that increasingly move between clinics, laboratories, and insurers rather than staying inside one filing room. A government agency issuing a digital certificate or processing a citizen's request online faces it too, because a citizen who cannot get a satisfying answer about how their information was used will not distinguish between a private company and a public one. They will simply stop trusting digital services generally, and that erosion is far more expensive to repair than any single fine.

Put simply, the shift described in this essay is not a banking story that happens to be told through banking examples. It is an economy wide story, and banking is only the sector where it became visible first, because banking was regulated most heavily to begin with.

Compliance Becomes an Everyday Habit, Not a Season

One of the stranger side effects of the old model was psychological. People behaved differently during audit season than they did the rest of the year. Documents were suddenly updated. Processes tightened. Attention sharpened. Then the season ended, and much of that discipline quietly faded until the next one arrived.

The healthiest organisations I have encountered do not experience that rhythm at all. Their controls do not intensify because an auditor is arriving next week. They operate the same way in March as they do in September, because trust is embedded in how the work gets done, not switched on in anticipation of being watched.

That distinction matters more than it sounds. A culture cannot be turned on for an inspection any more than a habit can be practiced only when someone is checking. The organisations that will do well over the next decade in this market are the ones where compliance stops being an annual project performed by a separate department and becomes an ordinary characteristic of how engineering, operations, and finance already work together.

Trust Infrastructure Is a Business Capability

Organisations that engineer trust continuously tend to move faster in procurement, shorten security reviews, reduce audit preparation costs, and become easier for partners, regulators, and investors to evaluate. Trust Infrastructure is therefore not only a compliance capability—it is increasingly a business capability.

Trust stops being a claim. It becomes observable.

Artificial Intelligence Changes the Question Again

A great deal of public attention is focused on how artificial intelligence itself should be regulated. That is a fair question, and an important one. But a quieter and arguably more consequential question is how artificial intelligence changes regulation as a discipline.

Put plainly, artificial intelligence changes the economics of continuous evidence. Work that once required a team of people reviewing logs for weeks can increasingly be monitored, correlated, and verified as it happens, at a cost that keeps falling. That is the real significance of the shift, not that software has become clever, but that continuous evidence, once expensive enough that only the largest institutions could afford it, is becoming something a much smaller organisation can build into its own systems from the start.

Used well, it can flag an anomaly in transaction behaviour before a human analyst would ever notice the pattern. It can assist with continuous monitoring, with mapping a regulatory requirement onto an actual technical control, and with organising evidence that would otherwise sit scattered across a dozen systems. None of this requires treating artificial intelligence as magic, and it should not be marketed that way. It is simply becoming another layer of infrastructure, the way cloud computing became infrastructure a decade earlier, unremarkable once it is working properly.

There is an important caution buried inside that promise, and it deserves to be stated plainly rather than glossed over. A model that flags an anomaly is not the same thing as evidence that the anomaly was properly investigated. An organisation that replaces a tired human reviewer with an untested algorithm has not necessarily become more trustworthy. It has simply moved the risk somewhere less visible, from a person who can at least be asked to explain a decision to a system that may struggle to explain itself at all. The regulators paying closest attention to this shift are already asking a version of the same question they ask about every other control. Not whether artificial intelligence is present, but whether its use can itself be demonstrated, tested, and accounted for. Automation does not exempt anyone from the underlying expectation. If anything, it raises the bar, because a claim of automated diligence that cannot be verified is a weaker claim than the manual process it replaced.

Its deeper effect may be on the compliance profession itself. As machines take on more of the mechanical work of gathering evidence, the human role shifts from collecting proof toward interpreting what the proof means. The compliance officer becomes less of an administrator filing documents and more of a designer of the systems that produce trust in the first place. Accountability does not disappear in that shift. If anything, it becomes harder to hide from, because the expectation that accountability can be demonstrated continuously only grows stronger as the tools for demonstrating it improve.

This Is Not Only Nigeria's Story

The same shift is visible, at different speeds, across the wider continent. Kenya regulates data protection through its own Office of the Data Protection Commissioner, built along lines that closely resemble the European Union's General Data Protection Regulation, as do newer laws in Ghana and Rwanda. In January 2025, Rwanda formally joined the Budapest Convention on Cybercrime, becoming the seventy eighth country in the world to do so, aligning its domestic cybercrime law with an international standard rather than building an isolated framework of its own.

At the continental level, the African Continental Free Trade Area adopted its Protocol on Digital Trade in February 2024, and its eight supporting annexes, covering areas including cross border data transfers, digital identity, and financial technology, were adopted roughly a year later in February 2025. The Protocol still awaits ratification by enough member states to take legal effect, and full ratification of the older Malabo Convention on cybersecurity and data protection remains incomplete across the continent, so it would be premature to describe African digital governance as already unified. It is not. But the direction of travel is unmistakable, and it points toward the same idea taking hold everywhere at once. As commerce, payments, and data increasingly move across borders rather than staying inside them, the expectations governing privacy, security, and accountability have to become interoperable too, or trade itself begins to slow down at every border it crosses.

In that sense, regulation is becoming something closer to infrastructure for continental commerce than a set of national obligations that happen to resemble each other. A payment that clears in Lagos and settles in Nairobi within the same transaction chain needs both jurisdictions to recognise a similar standard of evidence, or neither regulator can fully trust what the other is looking at.

A New Question for a New Kind of Organisation

Every major economic transformation has required new infrastructure that was invisible until it was suddenly indispensable. Roads made commerce possible before anyone thought of them as commerce infrastructure. Electricity made industrial production possible before anyone described it that way. Telecommunications connected markets long before anyone called it market infrastructure. The internet did the same for information.

Africa's digital economy now requires something quieter but no less essential than any of those. It requires trust, not as a sentiment printed on a marketing page, and not as a slogan repeated in an annual report, but as an operational capability that can be observed, measured, and repeated on demand. Regulation, whatever else it is, is increasingly becoming one of the mechanisms through which that capability gets built into the fabric of how economies function.

The organisations that understand this earliest will stop treating compliance as an obligation imposed from outside their walls. They will start treating it as an internal capability, one that happens to strengthen resilience, speed up partnerships, improve how they are assessed during procurement, and make them easier to invest in, as a side effect of simply being well built.

The question every regulated organisation in Nigeria will eventually have to answer is quietly shifting. It used to be, are we compliant. It is becoming something else, and something considerably harder to fake. Can our systems continuously demonstrate that we deserve to be trusted, on any day, without notice, and without a season set aside to prepare.

That is a different question from the one this generation of organisations grew up answering. The ones who redesign themselves around it early will not simply pass their next audit more easily. They will find themselves operating economies, and building companies, on a foundation the rest of the market has not finished constructing yet.

§

Key Insights

  • Compliance is no longer an event—it is becoming a continuous, system-embedded capability
  • Regulators are increasingly asking for evidence of execution, not merely proof of intention
  • Nigeria is building a distributed digital trust system, not just adding more rules

Key Definitions

What is Trust Infrastructure?

Trust Infrastructure is the collection of systems, controls, evidence, governance, identity, and operational processes that continuously demonstrate an organisation deserves to be trusted.

What is Continuous Compliance?

Continuous compliance is the practice of generating and maintaining evidence of control effectiveness as a byproduct of normal operations, rather than preparing for periodic audits.

What is Evidence Architecture?

Evidence Architecture is the design pattern for how evidence of control effectiveness is created, captured, stored, connected, verified, and consumed.

What is Continuous Evidence?

Continuous evidence is evidence of control effectiveness that is generated automatically as systems operate, rather than being collected manually after the fact.

About the Author

Oluwafemi Ofobutu writes about regulatory systems, compliance engineering, and the future of trust infrastructure.

Editorial Note

This essay is part of an ongoing research series exploring Trust Infrastructure, Evidence Architecture, and the evolution of regulatory systems across Africa. Future essays will examine AI governance, evidence-native engineering, digital identity, procurement trust, and the operational foundations of modern compliance.

Continue the Research