Regulation pack v1
Every finding cites its exact basis in CBN Circular PSS/DIR/PUB/CIR/001/004 or the NDPA 2023 — never an opaque risk score. Expand a rule to see why it carries the severity it does.
Regulatory basis
Circular §2
Why this severity
The most direct expression of the circular's core requirement. No reasonable defence is available to the institution — treat as an unambiguous, first-order violation.
Regulatory basis
Circular §2, "stored and managed"
Why this severity
In direct market engagement, this is the single most commonly triggered rule — replication and backup configurations are rarely revisited once set, and are the least visible part of a data estate to a team working from documentation rather than live infrastructure.
Regulatory basis
Key-custody analysis under "managed"
Why this severity
Rated high rather than critical because the legal position on key custody specifically is less definitively settled than physical data location — but taken seriously given the plain reading of "managed."
Regulatory basis
"Managed in Nigeria"
Why this severity
An organisational-contractual risk, not a purely technical one. Frequently the hardest finding to resolve quickly, since it depends on vendor contract renegotiation rather than a technical change the customer controls unilaterally.
Regulatory basis
NDPA 2023 cross-border rules
Why this severity
Ensures rule-engine coverage extends beyond the CBN circular into the parallel NDPA cross-border transfer regime, since a customer resolving CBN findings alone might otherwise overlook a distinct compliance obligation.
Regulatory basis
Prudential / resilience posture
Why this severity
A resilience and prudential concern rather than a direct textual violation, but taken seriously given the "no offshore DR" implication of a strict reading of the circular.
Regulatory basis
Contract remediation requirement
Why this severity
Contractual hygiene — necessary but rarely urgent in isolation.
Regulatory basis
NDPA security duty
Why this severity
Technical hygiene — necessary but rarely urgent in isolation.
Regulatory basis
Flags exposure to future guidance
Why this severity
Deliberately advisory rather than a hard severity, reflecting genuine legal uncertainty around several data categories (derived analytics, tokenised card data, fraud-model features). Prompts a documented institutional position, not a specific remediation action.