Regulation pack v1

Nine rules. Zero guesswork.

Every finding cites its exact basis in CBN Circular PSS/DIR/PUB/CIR/001/004 or the NDPA 2023 — never an opaque risk score. Expand a rule to see why it carries the severity it does.

CBN-LOC-001Regulated data hosted in a system located outside Nigeriacritical

Regulatory basis

Circular §2

Why this severity

The most direct expression of the circular's core requirement. No reasonable defence is available to the institution — treat as an unambiguous, first-order violation.

CBN-LOC-002Regulated data flowing to a destination outside Nigeria (backup, replication, log shipping)critical

Regulatory basis

Circular §2, "stored and managed"

Why this severity

In direct market engagement, this is the single most commonly triggered rule — replication and backup configurations are rarely revisited once set, and are the least visible part of a data estate to a team working from documentation rather than live infrastructure.

CBN-LOC-003Regulated data whose encryption key is held outside Nigeriahigh

Regulatory basis

Key-custody analysis under "managed"

Why this severity

Rated high rather than critical because the legal position on key custody specifically is less definitively settled than physical data location — but taken seriously given the plain reading of "managed."

CBN-LOC-004Vendor with offshore support access touching regulated systemshigh

Regulatory basis

"Managed in Nigeria"

Why this severity

An organisational-contractual risk, not a purely technical one. Frequently the hardest finding to resolve quickly, since it depends on vendor contract renegotiation rather than a technical change the customer controls unilaterally.

NDPA-XB-001Cross-border personal-data flow with no documented legal transfer basishigh

Regulatory basis

NDPA 2023 cross-border rules

Why this severity

Ensures rule-engine coverage extends beyond the CBN circular into the parallel NDPA cross-border transfer regime, since a customer resolving CBN findings alone might otherwise overlook a distinct compliance obligation.

CBN-LOC-005Regulated system with no in-Nigeria disaster-recovery replicamedium

Regulatory basis

Prudential / resilience posture

Why this severity

A resilience and prudential concern rather than a direct textual violation, but taken seriously given the "no offshore DR" implication of a strict reading of the circular.

CBN-LOC-006Vendor contract with no Nigerian data-residency commitmentmedium

Regulatory basis

Contract remediation requirement

Why this severity

Contractual hygiene — necessary but rarely urgent in isolation.

CBN-LOC-007Regulated data not encrypted at restmedium

Regulatory basis

NDPA security duty

Why this severity

Technical hygiene — necessary but rarely urgent in isolation.

CBN-LOC-008Interpretation-pending data category hosted offshoreadvisory

Regulatory basis

Flags exposure to future guidance

Why this severity

Deliberately advisory rather than a hard severity, reflecting genuine legal uncertainty around several data categories (derived analytics, tokenised card data, fraud-model features). Prompts a documented institutional position, not a specific remediation action.

See exactly how these rules get evaluated.