Fintech News

How a Nigerian innovator Developed a Governance Model for Pan-African Banking Cloud Adoption

Nigerian innovator Developed a Governance Model

A Nigerian innovator, Oluwasile Adesanya developed the CARG framework to connect central-bank mandates with decision rights, engineering controls, continuous assurance and value tracking. Drawing on her account of a multi-country banking transformation, the model gives regulated institutions a reusable route for scaling cloud adoption.

June 2025

Cloud computing can give financial institutions faster access to infrastructure, flexible capacity and a platform for digital services. Regulated banks also have to show who approved each workload, where sensitive data resides, how third-party risk is managed and which evidence demonstrates that controls remain effective. Those governance questions determine whether cloud adoption can move from a limited engineering programme into a dependable operating capability.

The Financial Stability Board has identified operational, governance and oversight considerations around financial institutions’ use of cloud providers, including cross-border dependencies and concentration among a small number of providers. It also recognises potential gains in resilience, scale and flexibility. [3] The commercial opportunity and the control burden therefore arrive together.

Pan-African banking groups add a further layer of complexity. A single group may operate across several national regimes while maintaining common platforms, shared risk standards and group-level investment decisions. A cloud workload can become a simultaneous engineering, audit, data-residency, outsourcing and executive-accountability decision.

The regulatory gap inside generic cloud frameworks

Provider adoption frameworks and global control catalogues give teams valuable technical structure. They describe landing zones, security, platform operations and migration practices. A bank still has to connect those practices to the clauses, responsibilities and evidence expected by its own supervisors. That translation can become a repeated negotiation between engineering, risk, audit and business teams.

Nigeria’s Central Bank makes the governance requirement explicit. Its Risk-Based Cybersecurity Framework assigns oversight to the board, implementation responsibilities to senior management, independent roles to risk, compliance and internal audit, and governance duties to an information security steering committee. The framework also requires alignment among cybersecurity, business objectives, legal duties and regulatory requirements. [2] A workable cloud model must carry that accountability into everyday technical decisions.

Adesanya identified this operating gap through her cloud-transformation work. Her paper argues that the pace of regulated cloud adoption is often set by unclear decision rights and retrospective evidence assembly. Her proposed answer is to treat the supervisory mandate as structured input to the operating model, so the control environment begins with named obligations and produces evidence during normal operation. [1]

The innovation: turning regulatory obligations into an operating model

The Cloud Adoption Reference Governance model, or CARG, is organised into five connected layers. The Regulatory Mandate Layer records supervisory obligations as testable clauses. The Governance and Decision-Rights Layer assigns approval authority and investment gates. The Control and Assurance Layer maps each obligation to a testable control and evidence source. The Platform and Engineering Layer implements those controls through landing zones, identity, encryption and observability. The Adoption and Value Layer manages workload onboarding and tracks operational benefit. [1]

Three ideas give the model its distinctive shape. Mandate-as-origin makes the regulator’s requirement the starting point for design. Evidence-by-construction produces assurance records as a normal output of the platform. Reference-not-bespoke keeps the five-layer structure reusable while allowing each institution to substitute its own regulator clauses, risk appetite and organisational roles. [1]

CARG also introduces a standing steering forum, a RACI-based sequence of investment gates and an exception register. Each exception has a rationale, compensating control, accountable owner and expiry date. In a multi-country group, the paper proposes a federated pattern in which the group owns the common reference model and each jurisdiction maintains a local mandate addendum. [1]

Adesanya’s contribution begins with the research itself. She authored a detailed reference model that integrates regulatory mandate, enterprise decision rights, technical control implementation, assurance and value realisation. The paper supplies a worked control-catalogue extract, steering-forum charter, KPI catalogue, maturity rubric, phased implementation roadmap and exception-register template. These artefacts turn the conceptual model into a toolkit that practitioners can examine and adapt. [1]

In the paper, Adesanya describes leading enterprise cloud-transformation work inside a top-tier pan-African banking group. She reports that she owned the operational transformation roadmap and translated Central Bank of Nigeria regulatory and audit obligations into a structured cloud-adoption strategy. [1]

Her innovation lies in joining responsibilities that are often handled separately. CARG connects a regulator clause to a control owner, a platform implementation, an evidence source, an approval gate and a value measure. This integration across regulatory, technical and commercial layers is the paper’s central innovation.

Experience applied through cross-functional delivery

Adesanya’s experience described in the paper spans technology, operations and regulated decision-making. The model requires engineering teams to expose machine-readable control attributes, risk and compliance teams to own regulatory mapping, internal audit to review assurance, business owners to remain accountable for workload value, and an executive forum to approve investment and residual risk. This is an operating-model role with a substantial technical foundation.

The worked payments example shows the type of coordination involved. A workload is classified at intake, mapped to residency, encryption, access, resilience and logging requirements, assessed for exceptions, deployed through a governed landing zone and reviewed through continuous evidence. Each stage carries a named accountable function. The sequence gives technical teams a clear route into production and gives assurance teams a traceable record of why the workload was accepted. [1]

This combination of architecture, governance and organisational design is relevant to financial technology because infrastructure choices directly affect the ability to launch and operate regulated digital services. A cloud platform gains commercial usefulness when product teams can adopt it predictably and control owners can evidence its operation.

Commercial impact: converting governance into delivery capacity

CARG frames commercial impact through reduced friction, predictable onboarding, reuse and risk visibility. A common mandate register and control catalogue can reduce repeated interpretation. Published decision rights can shorten approval cycles. A governed landing zone can make compliant controls reusable across workloads. The value layer then measures governed-adoption share, onboarding time, bottleneck reduction, open exceptions, evidence coverage and audit findings. [1]

The paper reports that the source programme served more than 25 million customers across ten countries and that governed adoption was associated with a 40 percent aggregate reduction in operational process bottlenecks. It also reports that every onboarded workload remained inside the institution’s audit perimeter. [1]

Adesanya further reports that the governance model became an internal benchmark across the group’s ten-country footprint. That reuse extends its commercial relevance beyond a single workload by giving multiple markets a common route for governed cloud adoption. The paper expresses commercial effect through operational efficiency, controlled adoption and reusable capability. [1]

Ecosystem impact: a reusable technical governance toolkit

Adesanya’s wider ecosystem contribution is a documented, reusable governance structure. CARG gives cloud engineers, security specialists, auditors, risk teams and business leaders a common vocabulary. Its control catalogue connects policy language to technical evidence. Its exception register creates a shared method for managing deviations. Its maturity rubric and KPI catalogue give institutions a way to discuss progress beyond infrastructure deployment alone.

The paper is careful about the limit of that contribution. Its evidence comes from one institution, the function-level charts are illustrative, and external adoption across other banks has not been demonstrated. It identifies multi-institution testing, validated maturity measures and comparative research as the next steps. That boundary matters because a model’s technical reusability and its observed ecosystem adoption are different evidence claims. [1]

CARG could reduce duplicated governance work where regulated institutions face similar needs for decision rights, clause-level assurance and cross-border accountability. This transferability remains to be tested. The framework’s modular design provides a concrete basis for that testing because institutions can retain the layers and replace the mandate content.

Relevance to the UK regulated-technology ecosystem

The United Kingdom’s own supervisory direction makes this work timely. The current version of the Prudential Regulation Authority’s SS2/21 addresses outsourcing and third-party risk management for banks and other regulated firms. It links cloud adoption with operational resilience and expands on data security, business continuity and exit planning. [4] The details of the mandate differ from the CBN context, while the need to connect obligations, technical controls and evidence remains visible.

A UK adaptation of CARG could give banks, fintech infrastructure teams and regulated technology providers a structured way to map PRA expectations into platform controls and governance gates. The paper does not report a UK deployment; this remains a prospective application of the framework.

Adesanya’s research contribution is therefore specific and testable. She has proposed an integrated model, documented its components, connected them to a real regulatory setting, reported programme-level outcomes and stated the model’s limitations. Future evidence can now examine external adoption, independent performance data and cross-jurisdiction implementation. That progression from operational experience to a reusable and falsifiable framework is a practical route through which enterprise technology work can contribute to a wider ecosystem.

Sources

[1] Adesanya, Oluwasile. ‘A Reference Governance Model for Cloud Adoption in Regulated Pan-African Financial Institutions: The CARG Framework and Evidence from a 25-Million-Customer Banking Group.’ Author’s research paper.

[2] Central Bank of Nigeria. Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Providers. Source page Issued 2018; .

[3] Financial Stability Board. Third-party dependencies in cloud services: Considerations on financial stability implications. Source page Published 9 December 2019;

[4] Bank of England, Prudential Regulation Authority. SS2/21: Outsourcing and third party risk management. Source page Current version published 15 November 2024 and effective 31 December 2024;

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This