Our Expert in Nigeria
No results available
Who this is for: Boards, chairpersons, general counsel, heads of compliance, company secretaries and senior executives of Nigerian companies, with particular relevance to financial services and fintech.
Purpose: Rapidly assess the 2026 regulatory picture, assign board and general counsel responsibilities, build a practical compliance and ethics programme, and respond effectively to enforcement.
Corporate compliance nigeria has moved from a back-office function to a boardroom priority in 2026, driven by intensified enforcement, expanded anti-money laundering rules and clearer regulator expectations on corporate ethics. Boards, general counsel and in-house teams can no longer treat governance as a paper exercise; regulators are scrutinising director-level conduct, and the reputational and financial cost of failure is rising. This article is a practitioner playbook: it maps the current regulatory landscape, clarifies who is responsible for what, supplies ready checklists, and sets out how to respond when a regulator comes knocking. Read it as an operational guide, not a survey of the law.
The framework governing corporate compliance nigeria is shaped by an interlocking set of regulators. The Corporate Affairs Commission (CAC) administers company law and filings under the Companies and Allied Matters Act 2020. The Financial Reporting Council of Nigeria (FRC) issues governance standards, including the Nigerian Code of Corporate Governance 2018. The Securities and Exchange Commission (SEC) governs public companies and capital markets disclosure. The Central Bank of Nigeria (CBN) oversees banks and payment-service providers, including anti-money laundering and countering the financing of terrorism (AML/CFT) obligations. Enforcement is led principally by the Economic and Financial Crimes Commission (EFCC) and the Independent Corrupt Practices and Other Related Offences Commission (ICPC), with the Nigerian Financial Intelligence Unit (NFIU) handling suspicious transaction reporting.
For 2026, the practical message for boards is that these bodies increasingly coordinate and increasingly examine individual accountability, not just corporate fines. Regulatory compliance in Nigeria has become a cross-functional discipline: a lapse in AML controls can attract CBN, NFIU and EFCC attention simultaneously, while a governance failure can draw both FRC and SEC scrutiny for a public entity.
A clear enforcement trend is director-level scrutiny. Where investigations once concentrated on the corporate entity, agencies increasingly examine the conduct and knowledge of individual directors and senior officers. The EFCC has pursued financial-crime matters against companies and their principals, and public guidance signals openness to remediation and cooperation where firms self-report and put things right. The ICPC continues to press the anti-corruption framework, with expectations that corporates maintain preventive controls rather than react after the fact.
The practical takeaway for anti-corruption compliance Nigeria is that a documented, functioning programme can itself operate as a mitigating factor. Boards that can evidence risk assessments, training, monitoring and prompt remediation are in a materially stronger position than those relying on informal assurances. Business integrity Nigeria is no longer a slogan, it can be the difference between a manageable regulatory dialogue and a personal-liability exposure for directors.
Under CAMA 2020, directors owe fiduciary duties to the company, including to act in good faith and in the company’s best interests, and to exercise reasonable care, skill and diligence. The Nigerian Code of Corporate Governance 2018 layers on oversight expectations: the board should set the tone at the top, oversee the ethics and compliance programme, and ensure adequate risk management. Corporate governance Nigeria therefore combines a statutory duty floor with a code-based standard of good practice that regulators and the market treat as a reference point.
The board’s core legal duties break down into a few enforceable categories. Directors must avoid conflicts of interest and must not misuse corporate opportunities or information. They must ensure the company keeps proper records and makes required statutory filings, a duty operationally carried by the company secretary but owned at board level. The company secretary’s role under CAMA is substantial: maintaining statutory registers, preparing board papers and minutes, and filing annual returns and change notifications with the CAC. Failures here are among the most common and most avoidable compliance breaches. (Note that CAMA 2020 removed the mandatory requirement for a small company to appoint a company secretary, though many companies still choose to.)
Director liability in Nigeria runs across three vectors. Civil liability arises where breach of duty causes loss to the company, exposing directors to claims and, potentially, personal restitution. Regulatory liability flows from sector rules, a bank director may face CBN sanctions, a public-company director SEC action. Criminal liability attaches to specified offences under CAMA and the financial-crime statutes, and can result in prosecution and disqualification. The through-line is that “I did not know” is a weak defence: the FRC Code’s oversight expectations mean boards are expected to have systems that would have surfaced the problem.
The table below maps who does what across the five roles that carry compliance responsibility. Use it to allocate duties precisely, ambiguity about ownership is itself a compliance risk.
| Dimension | Board (Directors) | General Counsel | In-house Legal / Compliance | Company Secretary | Head of Compliance |
|---|---|---|---|---|---|
| Legal duty & standard | Fiduciary duties under CAMA; oversight per FRC Code | Legal adviser; reporting lines to board/CEO; privileged adviser | Implementers; operational compliance | Statutory filings; corporate governance administration | Day-to-day compliance programme owner |
| Typical 2026 actions | Approve policy, allocate budget, receive escalation reports | Advise on legal risk, lead investigations, manage privilege | Risk assessments, training, monitoring, vendor due diligence | Board papers, minutes, statutory returns | AML/KYC oversight, incident response, monitoring |
| Liability exposure | Director liability (civil/criminal); regulatory sanctions | Professional/legal risk; possible accessory liability if concealing | Operational risk; employee discipline | Liability for statutory filing compliance | Regulatory action for programme failures |
| Timing / cadence | Quarterly board reviews; immediate response for incidents | Immediate on suspected breaches; report to board as needed | Continuous monitoring; monthly/quarterly reporting | Statutory deadlines and board cycles | Real-time monitoring; incident reporting timelines |
| Enforceability & remedies | Fines, disqualification, criminal prosecution | Professional sanctions; instructions to disclose | Internal sanctions; regulator notices | Fines; administrative penalties | Regulatory fines; escalation to board and regulators |
Governance frameworks fail when responsibilities are assumed rather than assigned. The three checklists below convert the duties above into concrete tasks. Treat them as the basis of a board compliance checklist and sequence the items across 30-, 60- and 90-day windows.
Immediate actions: If any of the board items above are unassigned or undated, close that gap at the next board meeting, an unowned control is a control the regulator will treat as absent.
A defensible programme for corporate compliance nigeria has the same core components regardless of company size; what scales is the depth and tooling. The essential components are: a risk assessment that drives everything else; written policies and a code of conduct; training tailored to role and risk; monitoring and testing of controls; a reporting channel including whistleblowing; a documented investigations process; remediation with tracked closure; third-party due diligence; and appropriate technology and data governance. Corporate ethics Nigeria is delivered not by a single policy document but by this operating cycle running continuously.
Smaller companies can run a credible programme with low-cost tooling: a policy management shared drive with version control, a simple case-management tool for whistleblowing intake, and manual sampling for controls testing. The non-negotiable is documentation, decisions and reviews must be evidenced. Enterprise and regulated firms need more: automated transaction monitoring, screening against sanctions and politically exposed persons (PEP) lists, a dedicated case-management system, and dashboards that feed the board. Regulated firms should also account for data-protection obligations under the Nigeria Data Protection Act 2023 when handling personal data in compliance processes. In-house legal compliance Nigeria capacity should be sized to risk, not to headcount convention; a fintech handling high transaction volumes needs monitoring capability a low-risk holding company does not.
| Company type | Indicative resourcing | Build timing | Primary compliance driver |
|---|---|---|---|
| Small private company | Part-time compliance owner; manual tooling | 2–3 months | CAMA filings; basic anti-bribery controls |
| Public / listed company | Dedicated compliance function; board reporting | 4–6 months | SEC disclosure; FRC Code governance |
| Bank / fintech | Full AML/CFT team; automated monitoring | 6–9 months | CBN AML/CFT; NFIU reporting |
These timelines assume board sponsorship from the outset and are indicative only. The single largest cause of delay is often not budget but the absence of a clear owner and an approved plan, which is why the board checklist places approval and resourcing first.
When an enquiry arrives from the EFCC, ICPC, SEC, CBN or CAC, the first hours matter. Move quickly and deliberately: preserve all potentially relevant records and suspend routine deletion; identify the scope and legal basis of the enquiry; engage counsel immediately; notify the board and, where relevant, insurers; and control communications through a single channel. Panic and unilateral action by individuals are the two failures that most often turn a manageable matter into a serious one.
Self-reporting is a strategic decision, not a reflex. It is generally worth serious consideration where an internal investigation confirms a material breach, where regulators are likely to discover the matter independently, and where cooperation may reduce sanction. Enforcement guidance signals that cooperation and remediation are viewed favourably, and a firm that self-reports with a credible remediation plan is often better placed than one that conceals and is later exposed. The GC should frame the decision for the board with a clear view of the legal exposure, the likelihood of discovery, and the mitigation value of cooperation, and take specific legal advice on the facts.
Legal professional privilege in Nigeria is recognised but not unlimited. To protect it, structure internal investigations so that legal advice is genuinely the dominant purpose, route sensitive communications through counsel, and mark privileged material clearly. Do not assume every internal report or compliance document attracts privilege, much operational compliance material does not. The safest practice is to plan for privilege before an incident, not to reconstruct it afterwards, and to preserve evidence comprehensively from the moment an issue is suspected.
Red flags: Deleted files after an enquiry lands; a single executive dealing with regulators alone; no legal hold in place; inconsistent internal messaging. Any of these should trigger immediate board attention.
Regulatory scrutiny is highest in financial services, where the CBN, NFIU and enforcement agencies converge. Banks and payment-service providers carry the fullest AML/CFT obligations: customer due diligence, ongoing monitoring, and suspicious transaction reporting to the NFIU. Fintechs operating under CBN licensing should build these controls in from launch, not bolt them on later. Correspondent banking and cross-border flows add sanctions and PEP exposure that require dedicated screening. For any regulated institution, regulatory compliance Nigeria in this sector is not optional infrastructure, it is typically a licence condition.
Enhanced due diligence applies where risk is elevated: PEPs, high-value or unusual transactions, and higher-risk jurisdictions. Practically, that means verifying source of funds and wealth, obtaining senior approval before onboarding high-risk customers, and applying tighter monitoring thresholds thereafter. Transaction monitoring must be calibrated so alerts are meaningful; a system that generates volumes of unreviewed alerts is a compliance failure waiting to be found. Fintechs scaling rapidly should ensure monitoring capacity grows with transaction volume, because regulators expect controls to keep pace with growth.
A six-to-nine-month phased roadmap keeps the programme moving without overwhelming the organisation. Phase one (months one to two): board approves the plan and budget, appoints owners, and completes the risk assessment. Phase two (months three to five): policies are refreshed, training is rolled out, and monitoring and whistleblowing channels go live. Phase three (months six to nine): controls testing begins, external assurance is commissioned, and the board receives its first full compliance dashboard. Each phase should carry defined milestones and KPIs, training completion rates, alert-clearance times, open-issue ageing, so progress is measurable, not asserted.
A board-ready quarterly dashboard for corporate compliance nigeria should present, on a single page: key risk indicators with a trend arrow; training completion by business unit; the number and status of open incidents and investigations; whistleblowing reports received and resolved; monitoring-alert volumes and clearance times; overdue statutory filings; and remediation items past their due date. The board’s job is to interrogate the exceptions, not admire the green lights.
An escalation matrix removes doubt about who acts when. Define tiers by severity: routine matters resolved within the compliance function; significant matters escalated to the GC and executive; and material matters, suspected fraud, regulatory enquiry, senior-officer involvement, escalated to the board immediately. Attach clear triggers and timelines to each tier. The matrix should also specify decision rights: who authorises a legal hold, who approves self-reporting, and who speaks for the company to a regulator. Documented in advance, these triggers convert a crisis into a process.
Corporate compliance nigeria in 2026 rewards boards that act early and penalises those that treat governance as a formality. Three immediate board decisions should follow from this article: approve and fund the 2026 compliance and ethics plan with named owners; confirm that escalation and evidence-preservation protocols are ready to use today; and commission a compliance risk assessment if none exists. Everything else, training, monitoring, dashboards, sector-specific controls, flows from those three decisions. Directors who can evidence oversight under CAMA and the FRC Code will not only reduce their personal exposure but will place the company in a stronger position if a regulator ever calls. Use the board compliance checklist above at your next board meeting.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Dr. Sanford U. Mba at Dentons ACAS-Law, a member of the Global Law Experts network.
posted 2 minutes ago
posted 22 minutes ago
posted 43 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message