Skip to content

Evidence request lists

Nigeria Open Banking Regulatory Framework (CBN, 2023)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

API Operations

NGOB-4
API Performance, Availability, and Service Level

Maintain API performance per Operational Guidelines including 99.5% minimum availability + p95 latency under 1.5 seconds + p99 latency under 3 seconds + throughput targets per tier + reporting of all API operations metrics monthly to CBN. Maintain Service Level Agreements (SLAs) with API consumers + performance dashboards + incident communications + maintenance window notifications.

Artefacts an auditor will ask for
  • Performance dashboard
  • 99.5% availability evidence
  • Latency metrics
  • Monthly CBN reporting
  • SLA register
  • Maintenance window log
Where this commonly fails
  • Availability below 99.5%
  • No latency monitoring
  • Missing CBN reports
  • No SLAs

API Security

NGOB-3
API Security Standards, mTLS, and Encryption

Implement Open Banking API security per Common Banking Industry API Standards + OAuth 2.0 + OpenID Connect (OIDC) + FAPI 2.0 (Financial-grade API) + Mutual TLS (mTLS) client authentication. Apply encryption: TLS 1.3 in transit + AES-256 at rest. Use signed JWTs with detached signatures per FAPI requirements. Apply API rate limiting + token expiration + nonce + audience claims. Coordinate with Open Banking Nigeria Ltd standardisation body.

Artefacts an auditor will ask for
  • FAPI 2.0 conformance certificate
  • mTLS configuration
  • TLS 1.3 deployment
  • AES-256 evidence
  • Open Banking Nigeria alignment
Where this commonly fails
  • No FAPI conformance
  • Weak mTLS
  • Outdated TLS
  • No standardisation alignment

Consent Management

NGOB-2
Customer Consent Management and Lifecycle

Implement customer consent capture per Operational Guidelines Section 3 with informed + specific + freely given + revocable consent + clear data scope + retention + sharing partners + purpose. Maintain consent records for audit and replay. Provide customer-accessible consent dashboard. Honour revocation within 24 hours. Apply Strong Customer Authentication (SCA) per CBN Risk-Based Cybersecurity Framework for Open Banking aligned with PSD2 RTS + SCA elements (knowledge + possession + inherence).

Artefacts an auditor will ask for
  • Consent capture flow
  • Consent records register
  • Customer consent dashboard
  • SCA implementation
  • 24-hour revocation tracking
Where this commonly fails
  • No dashboard
  • Late revocation
  • Weak SCA
  • Missing records

Customer Protection

NGOB-6
Customer Notification, Liability Allocation, and Data Localisation

Notify customers of data sharing with third parties per Operational Guidelines + transparency obligations + opt-out mechanisms. Allocate liability between API Provider + API Consumer + customer per CBN Open Banking liability framework including unauthorised transactions + technical failures + fraud + breach. Apply data localisation requirements for sensitive personal data and financial data per CBN Foreign Exchange Manual + NDPA cross-border restrictions + NITDA data localisation directives. Coordinate NDPR/NDPA alignment for personal data protection.

Artefacts an auditor will ask for
  • Customer notification procedures
  • Liability allocation matrix
  • Data localisation evidence
  • CBN FX Manual compliance
  • NDPA/NDPR cross-walk
Where this commonly fails
  • No customer notification
  • Unclear liability
  • No localisation
  • Missing NDPA alignment

Fraud and Incident Response

NGOB-5
Fraud Monitoring, Incident Notification, and Reporting to CBN

Implement fraud monitoring per CBN Risk-Based Cybersecurity Framework + behavioural analytics + transaction monitoring + suspicious activity detection + sanctions screening. Notify CBN of cybersecurity incidents within 24 hours per Risk-Based Cybersecurity Framework + Nigeria Inter-Bank Settlement System (NIBSS) coordination + Nigeria Police Force Cybercrime Division per Cybercrimes Act 2015. Maintain incident register with severity + cause + remediation. Coordinate Customer Complaints and Dispute Resolution per Operational Guidelines.

Artefacts an auditor will ask for
  • Fraud monitoring deployment
  • 24-hour CBN notification capability
  • Incident register
  • NIBSS coordination
  • Cybercrimes Act compliance
  • Complaints management system
Where this commonly fails
  • No fraud monitoring
  • Late CBN notification
  • No incident register
  • Inadequate complaints

Governance and Continuity

NGOB-8
Board Oversight, Business Continuity, and Open Banking Risk Governance

Establish Board oversight of Open Banking risk through Board Audit Committee + Board Risk Committee with quarterly reporting + executive responsibility + Open Banking Manager appointment + risk appetite statements. Implement Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) specific to Open Banking operations including RTO under 4 hours + RPO under 1 hour for critical APIs + annual testing + customer communications during outages. Maintain regulatory liaison with CBN + Bankers Committee + Payment Service Operators committee.

Artefacts an auditor will ask for
  • Board Committee minutes
  • Open Banking Manager appointment
  • Risk appetite statement
  • BCP/DRP for Open Banking
  • Annual BCP/DRP test reports
  • CBN liaison records
Where this commonly fails
  • No Board oversight
  • Missing Manager
  • No BCP/DRP
  • Weak liaison

Logging and Assurance

NGOB-7
Logging, Audit Trail, Independent Assurance, and Sandbox Testing

Maintain comprehensive logging and audit trails for all API operations including customer consent + transactions + data sharing + access attempts + retained for minimum 7 years per CBN requirements. Conduct annual independent assurance reviews by ICAN-certified auditor + CBN-licensed CISA + AICPA SOC 2 Type II equivalent. Use the CBN Regulatory Sandbox for new API products with testing scenarios + isolated environments + customer protections before production deployment.

Artefacts an auditor will ask for
  • Comprehensive log retention 7 years
  • Annual independent assurance report
  • SOC 2 Type II equivalent
  • CBN Sandbox participation
  • Test scenarios
Where this commonly fails
  • Inadequate logging
  • No independent assurance
  • No sandbox use
  • Test gaps

Registry and Tiering

NGOB-1
Open Banking Registry Participation, Tiered Categorisation, and KYP

Comply with the Nigeria Open Banking Regulatory Framework issued by the Central Bank of Nigeria (CBN) March 2023 + Operational Guidelines for Open Banking December 2023. Register as Open Banking participant (API Provider or API Consumer or both) via the Open Banking Registry (OBR) administered by CBN. Apply tiered API risk categorisation: Tier 0 Product Information (PIST) + Tier 1 Merchant Information (MIT) + Tier 2 Personal Financial Data (PIFT) + Tier 3 Scoring and Analytics (PAST). Conduct Know-Your-Partner (KYP) due diligence on API counterparties including identity verification + corporate structure + regulatory licensing + cyber security maturity + financial soundness.

Artefacts an auditor will ask for
  • OBR registration certificate
  • API tier classification register
  • KYP due diligence reports
  • Annual review of registration
Where this commonly fails
  • No OBR registration
  • Missing tier classification
  • Incomplete KYP
  • Stale review
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nigeria Open Banking Regulatory Framework (CBN, 2023) framework page.