Why Nigeria’s financial institutions should treat data localisation as a strategic foundation for trusted AI, not simply a compliance exercise
Artificial intelligence is becoming embedded in the systems and decisions that power modern financial services, moving from experimentation to execution at scale. Banks, fintechs and payment providers are using AI to detect fraud, assess risk, personalise services, automate operations and make faster decisions.
But as AI becomes more embedded in financial services, a parallel question is becoming increasingly important: who controls the data, infrastructure and AI systems that organisations are building their businesses around?
This is the question at the heart of the global shift towards digital sovereignty and stronger AI governance, and it is becoming particularly relevant in Nigeria as financial institutions prepare for the Central Bank of Nigeria’s (CBN) data localisation requirements taking effect from January 1, 2027.
The CBN directive should therefore be viewed in a broader context. It is not simply about where payment data is stored. It is part of a wider movement towards greater control, accountability and resilience across the technology environments that underpin financial services.
The Global Shift: From AI Adoption to AI Governance
Governments and businesses around the world are increasingly recognising that AI cannot be scaled without trusted foundations. Effective governance must address data, infrastructure, security, accountability and risk so organisations can deploy AI responsibly and at scale.
In the United States, the National Institute of Standards and Technology’s AI Risk Management Framework provides organisations with a structured approach to identifying and managing AI risks across the lifecycle of AI systems. Its principles cover areas including reliability, security, transparency, explainability, privacy and fairness.
The European Union has taken a more regulatory approach through the EU AI Act, establishing a risk-based framework for AI and introducing obligations around how higher-risk systems are developed and deployed.
Singapore has taken a practical, implementation-focused approach. Its Model AI Governance Framework provides guidance on internal governance, human involvement, operations management and stakeholder communication. In 2026, Singapore extended this approach to agentic AI, emphasising risk assessment, human accountability, technical controls and transparency.
Saudi Arabia provides another relevant example of how data and AI governance can be connected to national digital transformation. The Saudi Data and AI Authority (SDAIA) has made advancing the data regulatory environment, responsible AI adoption, digital infrastructure, cybersecurity and cloud services part of its strategic objectives.
The approaches differ, but the direction is consistent: AI governance is becoming inseparable from data governance and digital infrastructure.
For financial institutions, this means governance cannot sit solely with legal, compliance or technology teams. It needs to be considered when organisations choose where data is stored, where AI workloads run, how information moves between environments and which third parties have access to critical systems.
For technology providers operating across markets, this shift is already changing how digital environments are designed. TeKnowledge’s experience across global markets shows that organisations increasingly need operating models that connect governance, data, infrastructure and AI execution. Businesses must maintain local control and regulatory compliance without limiting access to the technologies and ecosystems that drive innovation. This requires architectures that provide control where required while preserving the connectivity, scalability and access to global technology ecosystems that modern financial services depend on.
What This Means for Nigeria
Nigeria’s financial services sector has been one of the country’s strongest engines of digital innovation. The rapid growth of digital payments and fintech has created new opportunities for financial inclusion, while also increasing the volume and sensitivity of data being generated and processed.
CBN’s localisation requirements therefore have implications beyond data residency. Financial institutions need visibility and control across their technology environments, ensuring that data, AI workloads and third-party services operate within appropriate regulatory and security parameters.
AI governance starts with knowing what data AI systems use, where it resides and who controls it. Without that foundation, organisations may struggle to scale AI beyond pilot projects and realise meaningful business value. For financial institutions, this requires strong data governance, clear accountability and continuous oversight as AI becomes embedded in critical functions.
Data sovereignty does not mean abandoning global cloud platforms. Financial institutions can use hybrid and multi-cloud architectures to keep sensitive workloads within required jurisdictions while retaining access to global technology and innovation. This also makes network sovereignty and resilience important: organisations need visibility and control over data not only at rest, but as it moves across networks, including during failover and recovery.
Beyond Data Residency: Building the Trusted Foundations for AI Execution and Long-term Value
For Nigerian financial institutions, the challenge is not simply determining where data resides. It is creating the trusted foundations that allow AI to move from experimentation to execution and deliver measurable value. Governance, security, infrastructure and data management all play a role in ensuring organisations can innovate responsibly while meeting regulatory requirements.
While data sovereignty is driving today’s agenda, the broader opportunity is to build an ecosystem ready for trusted AI adoption at scale. By treating the CBN’s requirements as an enabler of long-term capability rather than a compliance exercise, Nigeria can strengthen resilience, accelerate innovation and create the conditions for sustainable growth. This is ultimately a leadership issue: the immediate requirement may concern the location and control of payment data, but the executive responsibility is broader, to ensure that the organisation’s data, infrastructure and governance are capable of supporting trusted AI at scale. CEOs and boards do not need to make every technical decision, but they must set the intent, establish accountability and ensure that innovation does not move faster than the organisation’s ability to govern it.