Data localisation is often framed as keeping data in-country and protecting it, but the Central Bank of Nigeria’s new rules are about whether banks and fintechs can access critical data, recover services, and keep processing payments when their infrastructure fails.
“Localisation is not the same thing as resilience,” said Dr Rakiya Yusuf, Director of the Payment System Supervision Department at the CBN, at TechCabal’s Insights Power Brunch, organised by TechCabal’s research and intelligence arm in collaboration with Amazon Web Services (AWS) on Thursday, September 10.
In June, the CBN directed banks, payment companies, switches, and other payments-system participants to store and manage payment data generated in Nigeria locally by January 1, 2027. In 2025, Nigeria processed more than ₦1.2 quadrillion ($880.51 billion) worth of transactions, and the CBN said this rapid growth drove its localisation move.
As digital payments grow, central banks including India and Uganda are seeing that concentrating critical financial data and infrastructure on foreign cloud providers could leave parts of their financial system exposed to disruptions, dependencies, and decisions outside their control.
Financial institutions in Nigeria must now examine who controls their infrastructure, where backups sit, how dependent they are on technology providers, and whether they can recover or migrate their data when something goes wrong.
“If an institution moves its primary database to Nigeria but retains its backup offshore, have we achieved resilience? If production is local but the institution remains completely dependent on an offshore control plane, have we achieved sovereignty? If an institution moves workloads to one local provider but creates a concentration risk across the financial sector, have we strengthened systemic resilience?” Yusuf asked.
The CBN’s interest, she said, extends to how data is governed, protected, processed, recovered, and supervised. This covers the full lifecycle of the data, giving financial institutions visibility into where their data is, how it is handled, and enabling them to react quickly when systems are disrupted or come under stress.
Banks should know their data
Yusuf said financial institutions must take executive ownership of the transition rather than treating it as a technology or information-security project.
“This should not be delegated entirely to the chief information officer (CIO), chief technology officer (CTO) or information-security team. The implications cut across technology, risk, compliance, legal, operations, business continuity and finance,” she said.
This starts with understanding what data an institution holds: where it originates, where it is processed and stored, where it is backed up, who can access it, and what happens when a technology-provider relationship ends.
Institutions also need to understand their dependence on cloud providers, data centres, connectivity providers, software vendors, managed services, and other third parties, according to Yusuf.
The CBN’s 2024 risk-based cybersecurity framework identifies lack of visibility as one of the risks of using cloud services and requires financial institutions to maintain records of their cloud providers and other third parties. A CBN publication noted that a typical Nigerian bank had 200 or more tier-one business partners in its supply chain, showing how many third parties banks may need to keep track of.
Financial institutions must also test what happens when the primary site goes down, connectivity is disrupted, or a provider becomes unavailable, and how quickly critical services and data can be recovered or migrated. The aim is to ensure that a failure at one provider or piece of infrastructure does not leave an institution unable to process payments or access critical data, potentially turning an isolated outage into a wider disruption to the financial system.
With the deadline fast approaching, Yusuf said institutions should not wait for complete regulatory certainty before starting. Data discovery, data-flow mapping, workload and vendor assessments, contract and architecture reviews, business-continuity and cybersecurity assessments, and governance work should already be underway.
“The CBN’s expectation is that institutions approach this as a structured transformation programme, rather than as a last-minute compliance exercise,” she said.
But the industry still has questions about implementation, including what constitutes payment transaction data, how hybrid environments should be treated, whether cross-border processing will be permitted, and how disaster recovery, cloud arrangements, and existing technology architectures will be handled.
“These are not unreasonable questions. They are exactly the questions that arise when a policy moves from principle to implementation,” she said. “The Central Bank has therefore continued to engage stakeholders and is working towards additional implementation guidance addressing the practical issues that have emerged. I will not pre-empt that guidance today.”
Nigeria is not closing the door to global technology
However, Yusuf said data sovereignty does not mean Nigeria is turning away from international technology companies. Government agencies maintain partnerships with global providers: Microsoft works with the Economic and Financial Crimes Commission (EFCC), the country’s anti-graft agency, on cloud-based AI and machine-learning analytics, while Amazon Web Services partners with the Federal Ministry of Education on cloud computing and AI certification programmes.
“Data sovereignty should not be interpreted as Nigeria turning its back on global technology,” she said. “It is not about saying that foreign technology is inherently undesirable. It is not about replacing every international technology provider with a Nigerian provider.”
Nigeria remains open to global technology, capital, expertise, and innovation, Yusuf said. But international providers serving critical financial institutions must be able to operate within Nigeria’s requirements for regulation, resilience, security, and sovereignty.
Ultimately, she said, the CBN does not want success measured by the number of servers physically located in Nigeria. It wants critical payment systems to become more resilient, institutions to recover faster from disruptions, regulators to have better visibility into critical dependencies, and critical data to be recoverable and migratable when necessary.
True scale demands moving beyond surface-level integrations to robust execution. We’ve filtered the noise out of Moonshot 2026, optimising the conference strictly for high-calibre connections between startup founders, global financial operators, enterprise leaders and individuals rewiring Africa’s technical frameworks.
Get 20% off Early Bird tickets for a limited time.

from TechCabal https://ift.tt/Ctb7gJP
via IFTTT
Write your views on this post and share it. ConversionConversion EmoticonEmoticon