NDPA and CBN Compliance for Nigerian Fintechs
Nigeria's fintech
regulators are not
waiting on you.
Blaecwood Systems Limited is a Data Protection Compliance Organisation licensed by the Nigeria Data Protection Commission. We work out which NDPA and CBN requirements reach you, document where you stand, and prepare the reports a licensed DPCO has to prepare.
Both regulators turn on the same thing: what you can show, in the form they expect to see it. Three services below, three different starting points. Find the one that describes your situation.
Data Protection
NDPA & DPCO Compliance
Qualifying controllers and processors of major importance carry annual audit, registration and reporting obligations, and a Compliance Audit Report can only be prepared with a licensed DPCO. Whether any of it reaches you depends on how the NDPC classifies your organisation. That is the first question to settle.
The classification check is an indicative self-assessment. It is not an NDPA compliance audit and does not constitute a compliance opinion.
Financial Regulation
CBN Regulatory Readiness
CBN's 2026 supervisory agenda covers Open Banking participation and a proposed APP fraud liability regime still at exposure draft stage. We assess your controls against what CBN expects and document the gaps in the order they matter. Your team executes the changes, and we validate and record them.
A Regulatory Readiness Review walks through your licensing stage and current controls, and maps what CBN will expect next.
Payments
Payments Partner Ready
Payment companies rarely face one requirement at a time. NDPA obligations, CBN expectations, partner security reviews, PCI DSS scope questions and SOC 2 requests can land in the same growth cycle. Payments Partner Ready starts from the approval you are trying to reach and works back from it.
Why Blaecwood
Licensed to do
the part that counts.
Blaecwood Systems Limited is licensed by the Nigeria Data Protection Commission as a Data Protection Compliance Organisation, reference NDPC/DPCO/17469. That licence is what allows a Compliance Audit Report to be prepared and verified before it reaches the Commission, and it is verifiable with the NDPC.
Our work is assessment, documentation and validation. We do not implement your controls for you, and we would rather say so here than halfway through an engagement.
Licensed DPCO Registered with the Nigeria Data Protection Commission, reference NDPC/DPCO/17469
Two regulators, one team NDPA and CBN readiness run by the same practitioners
Assessed, documented, validated You execute remediation, we verify and record it
Prepared to submission standard Compliance audit reports and DPIAs written for filing, not for a folder
Assurance note
Readiness work does not guarantee a licence, certification, audit result or partner decision. Blaecwood's advisory and readiness work is separate from its DPCO assurance work.
The formal NDPA compliance audit, DPCO Verification Statement and Compliance Audit Return filing are contracted separately, with separate scope and review. SOC 2 examinations are performed by an eligible independent CPA or equivalent. PCI DSS validation follows the applicable SAQ, ASV or QSA route.
Start with what
actually applies.
Book a call and we will work through which NDPA and CBN requirements reach your business, and what is outstanding before your next filing or examination.
The classification check is an indicative self-assessment. It is not an NDPA compliance audit and does not constitute a compliance opinion.
Book a call
Choose a time below. The calendar is requested from Cal.com only once you ask for it, so nothing third party loads before then.
Loading the booking calendar.
Prefer a separate tab? Open the booking page on Cal.com.