Nigerian Banks Face New AI Security Challenge as Experts Demand Stronger Cyber Governance


By Simpson Global Media News Desk

Nigeria's rapidly expanding digital banking industry is entering a new phase in which artificial intelligence, automation, advanced analytics and interconnected digital platforms are changing not only how financial institutions serve customers but also the nature of the risks they must manage.

At a banking-sector meeting in Lagos, financial executives, internal auditors and technology professionals warned that cybersecurity and data governance must develop alongside technological innovation, identifying AI-enabled fraud, deepfakes, identity manipulation, cyberattacks, application programming interface vulnerabilities, data breaches and business email compromise among the emerging threats requiring stronger controls.

The discussions took place at the 65th Quarterly General Meeting of the Association of Chief Audit Executives of Banks in Nigeria, ACAEBIN, hosted by Wema Bank in Lagos and held under the theme, “Auditing the Future: Governing AI, Cyber Risks and Digital Trust in an Era of Intelligent Banking.”

The meeting placed particular attention on the changing role of internal audit.

Participants argued that traditional approaches focused mainly on examining past transactions and controls are no longer sufficient for financial institutions whose operations increasingly depend on real-time digital systems, automated decision-making, cloud infrastructure, APIs, artificial intelligence and third-party technology providers.

For banks, the challenge is therefore becoming two-sided.

They must continue adopting technologies that can make services faster and more accessible while simultaneously ensuring that the systems behind those services remain secure, explainable, accountable and resilient.

AI Is Changing the Risk Landscape

The growing use of artificial intelligence in financial services is creating new opportunities for banks.

AI can support customer service, fraud detection, data analysis, automation, credit processes and other areas of financial operations.

But the same technologies can also be exploited by criminals.

Wema Bank Managing Director and Chief Executive Officer Moruf Oseni, represented at the ACAEBIN meeting by Executive Director, Finance and Digital, Tunde Mabawonku, said the transformation of banking was being driven by artificial intelligence, advanced analytics, digital platforms, automation and other rapidly evolving technologies.

He warned that the transformation was also creating new categories of risk, including AI-enabled fraud, deepfakes, identity manipulation, cyberattacks, API vulnerabilities, data breaches and business email compromise.

The significance of those threats lies in their ability to target different parts of a bank's digital ecosystem.

A deepfake, for example, can be used to imitate a person's appearance or voice.

Identity manipulation can undermine customer verification systems.

An attack on an API can potentially exploit the connections between different software systems.

A data breach can expose sensitive information.

Business email compromise can attempt to deceive employees into authorising fraudulent transactions.

AI can potentially make some of these activities faster, cheaper or more convincing.

That creates a challenge for security teams because defensive systems must keep pace with the same technological developments being used by attackers.

Digital Trust Becomes a Banking Asset

As banking moves further away from physical branches and toward mobile applications, internet banking platforms, electronic payments and automated services, customer trust becomes increasingly dependent on technology.

Customers may never meet the people operating the systems that process their transactions.

Instead, they interact with applications, websites, automated messages and digital authentication systems.

The reliability of those systems can therefore influence whether customers trust a financial institution.

Oseni said preserving digital trust should become an enterprise-wide priority as customers increasingly interact with financial institutions through digital channels.

This means cybersecurity can no longer be viewed solely as an information-technology department responsibility.

Boards, executives, risk managers, compliance officers, internal auditors, technology teams and external partners all have roles to play.

The approach also places greater responsibility on financial institutions to understand how their technology works and where vulnerabilities may exist.

Why Internal Audit Is Being Redefined

Internal audit traditionally examines whether systems, policies and procedures are operating as intended.

But the speed of technological change is challenging that model.

By the time an audit identifies a weakness after the fact, a technology-dependent organisation may already have introduced a new system, changed an algorithm, moved data between platforms or connected another third-party provider.

At the ACAEBIN meeting, Oseni argued that internal audit must therefore move from predominantly retrospective assurance toward a more forward-looking, technology-enabled and insight-driven function.

Such a role would allow auditors to help management and boards anticipate emerging risks, challenge assumptions and make better-informed decisions.

The change is significant because artificial intelligence can alter processes faster than conventional audit cycles.

A bank may introduce an AI system and subsequently modify the data, model, vendor, user access or decision-making process.

Each change can potentially create a new risk.

Internal audit must therefore understand not just whether a control existed, but whether it remains effective as the underlying technology changes.

The Four Tests for AI Governance

The discussion in Lagos also focused on what organisations should expect from AI governance.

Chisom Odobeatu, Senior Manager for Information Technology and Control Assurance at Deloitte Nigeria, identified four areas for AI governance: explainability, data integrity, accountability and human oversight.

These principles address different stages of an AI system's operation.

Explainability

Financial institutions need to understand how important AI-driven decisions are reached, particularly where those decisions may affect customers.

An organisation that cannot explain the operation of a system may find it difficult to investigate errors, respond to complaints or demonstrate appropriate governance.

Explainability does not necessarily mean that every complex model can be reduced to a simple formula for every user.

It does mean that institutions need sufficient understanding and documentation to identify what a system is intended to do, what data it uses, what limitations it has and who is responsible for overseeing it.

Data Integrity

AI systems depend heavily on data.

Poor-quality, incomplete, outdated or improperly managed data can affect the quality of automated outputs.

Data governance is therefore closely connected to AI governance.

Banks must know where important data comes from, how it is processed, who can access it and how it is protected.

The issue becomes more complex when data moves between banks, fintech companies, cloud providers and other technology partners.

Accountability

Automation does not eliminate responsibility.

If an AI system produces an incorrect or harmful outcome, an institution still needs clearly defined ownership.

This requires organisations to establish who approves AI systems, who monitors them, who investigates failures and who can intervene when a system behaves unexpectedly.

Human Oversight

The fourth area is human oversight.

AI can automate processes, but financial institutions still require people capable of reviewing significant decisions, identifying abnormal behaviour and intervening when necessary.

Comments