Skip to content
Data Localisation Isn't Just About Data. It's About Control.
BusinessContinuity dataprivacy datasafety

Data Localisation Isn't Just About Data. It's About Control.

Jude Adiefe
Jude Adiefe
Data Localisation Isn't Just About Data. It's About Control.
9:03

Why the Central Bank of Nigeria's localisation directive marks the beginning of a new governance era for financial institutions.

Every major regulation tells us something about where an industry is headed.

Basel III reshaped how banks thought about capital. GDPR elevated privacy from a legal obligation to a boardroom priority. More recently, the European Union's Digital Operational Resilience Act (DORA) has reframed operational resilience as a strategic capability rather than an IT concern. The most influential regulations rarely introduce entirely new ideas; they formalise shifts that have already begun.

The Central Bank of Nigeria's data localisation directive should be viewed through the same lens.

Much of the industry has understandably focused on the practical implications of the new directive: cloud migration, infrastructure investment and implementation timelines. Those conversations matter, but they risk obscuring the more important signal. The directive is not fundamentally asking institutions to simply move data. It is asking them to demonstrate control over it. That is a very different challenge, and one that extends well beyond technology.

Nigeria's financial services sector has become one of Africa's defining digital success stories. In 2024, the country processed more than ₦1.5 quadrillion in electronic payment transactions, underlining both the scale and strategic importance of its digital economy. Yet industry estimates suggest that approximately 90% of enterprise cloud workloads within regulated sectors remain hosted outside Nigeria, while the country continues to manage 26 operational (and planned) data centres with no native AWS, Azure, or GCP cloud region.

Those figures are often discussed independently. They should not be.

Together, they reveal an economy generating enormous digital value while relying heavily on infrastructure beyond its immediate regulatory jurisdiction. The customers are Nigerian. The transactions are Nigerian. The regulatory obligations are Nigerian. Yet much of the data underpinning that activity is governed elsewhere. Whether that model remains sustainable is no longer simply a commercial question. It is becoming a regulatory one.

The directive reflects a broader shift in governance

It is tempting to interpret localisation as another compliance requirement—a deadline to meet, another programme to fund, or another audit to prepare for. But that interpretation overlooks the direction that regulation is taking globally.

Financial regulators are placing increasing emphasis on demonstrable governance rather than declared compliance. The expectation is no longer that institutions can produce evidence during an examination; it is that governance is already operating continuously, with evidence generated as a by-product of normal operations. The institutions best prepared for this shift will not necessarily be those with the largest compliance functions, but those capable of proving, at any point in time, where regulated data resides, how it moves, who has access to it and whether those activities remain within policy.

This is where the distinction between cybersecurity and governance becomes important. Security seeks to protect systems from compromise. Governance seeks to establish accountability over information throughout its lifecycle. An organisation may invest heavily in security controls yet still struggle to answer fundamental governance questions about data residency, jurisdiction or ownership. Increasingly, those are the questions regulators, boards and institutional customers care about most.

The challenge is compounded by the pace at which modern financial institutions now operate. Cloud environments scale automatically, AI systems influence operational decisions, and customer data flows continuously across platforms, vendors and geographic regions. Yet many governance processes still depend on periodic reviews, manual evidence collection and point-in-time assessments—an operating model designed for infrastructure that changed far more slowly.

The localisation directive therefore signals something larger than domestic hosting requirements. It reflects a recognition that governance itself must evolve. In an environment where infrastructure changes continuously, governance cannot remain episodic. Visibility must become continuous. Assurance must become continuous. Ultimately, trust must become continuous.

Why visibility has become a strategic capability

Perhaps the greatest governance risk facing financial institutions today is not a lack of controls but a lack of visibility.

Most executive teams understand their application landscape. Far fewer possess the same level of confidence in the data flowing beneath it. They cannot always determine, without significant effort, where regulated information resides, how it traverses jurisdictions, whether existing controls continue to operate as intended or how quickly those questions could be answered under regulatory scrutiny. As cloud adoption accelerates and third-party ecosystems become more interconnected, that uncertainty compounds.

Visibility therefore becomes more than an operational convenience. It becomes an executive capability. Institutions that continuously understand the state of their data estate are better positioned to manage regulatory change, strengthen board oversight and make faster, more informed strategic decisions. Those that lack this visibility increasingly find themselves reacting to governance events rather than anticipating them.

This is the broader lesson embedded within the CBN's directive. Localisation should not be viewed as the destination. It is one milestone in a wider transition toward continuous governance, measurable operational resilience and demonstrable digital trust. The institutions that treat it purely as a compliance exercise may satisfy today's requirements. Those that use it to modernise how governance operates will be better prepared for the regulatory environment that follows.

That may ultimately prove to be the directive's most enduring impact. Not that it changed where data is stored, but that it changed how financial institutions think about governing one of their most valuable strategic assets.

From periodic compliance to continuous governance

If the CBN's data localisation directive is pointing financial institutions in one direction, it is towards a governance model that is continuous, evidence-driven and measurable by design.

Meeting that expectation requires more than relocating workloads or updating policies. It requires the ability to continuously understand where regulated data resides, map it against applicable regulatory obligations, monitor control performance in real time and produce defensible evidence without relying on manual preparation ahead of every audit. As regulatory requirements become increasingly dynamic, governance itself must become operational rather than administrative.

This is the challenge that Cybervergent was built to solve.

Cybervergent provides an AI-native governance orchestration platform that continuously correlates compliance, risk and data security signals across enterprise environments, giving institutions a single, real-time view of their governance posture. Rather than treating Compliance Posture Management, Risk Posture Management and Data Security Posture Management as independent activities, the platform brings them together into one continuously monitored operating model.

For executive teams, the outcome is not simply better visibility—it is greater confidence. Confidence that regulated data can be located and governed. Confidence that control performance can be demonstrated as environments evolve. Confidence that board reporting reflects current risk rather than last quarter's assessment. And confidence that regulatory examinations become exercises in verification rather than evidence collection.

Digital trust is no longer measured by the policies an institution publishes. It is measured by the confidence with which it can prove governance in real time. That is the future Cybervergent is helping organisations build.

The CBN's localisation directive is unlikely to be the last regulatory shift that demands greater visibility, stronger governance and continuous assurance. Financial institutions that begin building those capabilities today will be better positioned for whatever comes next. If your organisation is evaluating its readiness or looking to modernize its governance operating model, we'd welcome the conversation. Connect with the Cybervergent team at cybervergent.com/contact-us to discuss your priorities and explore the best path forward.

Share this post