Developing a Vendor Risk Management Policy for Nigerian Financial Institutions

📖 ABSTRACT/OVERVIEW

Nigerian financial institutions rely extensively on third-party vendors for core banking software, payment processing, and cloud services, and inadequate vendor risk management creates significant cybersecurity and regulatory exposure for institutions and their customers. This study developed a vendor risk management policy for Nigerian financial institutions subject to CBN and NDIC oversight, drawing on regulatory requirements and current vendor management practice assessment. A professional policy development methodology was applied, incorporating structured interviews with 15 IT risk managers from commercial banks and insurance companies, review of CBN Vendor Risk Management Guidelines, NDIC risk assessment frameworks, and ISO/IEC 27036 supply chain security standards. Assessment of current practice showed that vendor security assessments were conducted before onboarding in only 53.3 percent of institutions, contractual cybersecurity requirements were specified in only 46.7 percent, and post-onboarding security performance monitoring was practised in 26.7 percent. The policy developed specifies vendor tiering based on criticality and access level, minimum security requirements by tier, due diligence questionnaire templates, contractual cybersecurity clauses, continuous monitoring standards, and vendor incident notification requirements. Specific provisions address fourth-party (sub-processor) risk for cloud and SaaS vendors. Expert review by ten financial sector risk and cybersecurity specialists confirmed the policy's CBN regulatory alignment. The study recommends CBN incorporate the policy framework into the Cybersecurity Framework for Financial Institutions Revision.

Keywords: vendor risk management, financial institutions, CBN, third-party security, supply chain risk

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬
Departments# Cyber Security