Wema Bank pushes stronger cyber-risk controls

Wema Bank Plc has called for stronger governance, cybersecurity and internal audit controls to protect the banking industry from emerging risks associated with artificial intelligence (AI) and digitalisation.

Managing Director, Wema Bank, Mr Moruf Oseni, made the call while hosting the 65th Quarterly General Meeting (QGM) of the Association of Chief Audit Executives of Banks in Nigeria (ACAEBIN) in Lagos.

He spoke at the meeting, themed: ‘Auditing the Future: Governing AI, Cyber Risks and Digital Trust in an Era of Intelligent Banking.’

Oseni, who was represented by the Executive Director, Digital Bank, Tunde Mabawonku, said AI-enabled fraud, cyberattacks and data breaches were becoming tangible threats as financial institutions deepened their reliance on technology.

According to him, as customers increasingly interacted with financial institutions through digital channels, preserving digital trust had become an enterprise-wide priority.

‘Technology may change the way we bank, but trust remains the currency upon which banking is built,’ he said.

Oseni said addressing emerging risks required responsible innovation, resilient technology infrastructure, robust cybersecurity, sound data governance and effective internal controls.

He added that internal audit functions must evolve from predominantly retrospective assurance to a more forward-looking, technology-enabled and insight-driven function.

According to him, the bank recognised that ‘innovation and governance must advance together,’ assuring that Wema Bank remained committed to leveraging technology responsibly, strengthening resilience and maintaining the confidence of its customers and stakeholders.

Representing the ACAEBIN Chairperson, Aina Amah, the association’s First Vice President, Mogbitse Atsagbede, said the meeting was particularly relevant as AI, digitalisation, automation and interconnected platforms continued to reshape the banking industry.

She said ACAEBIN had expanded the capacity-building programmes of its Training Academy to cover artificial intelligence, blockchain and smart contracts, fraud risk assessment and forensic auditing, data analytics, as well as the auditing of financial institutions and fintech companies.

Amah said the association was also examining the development of an Audit Management Framework for Nigeria and strengthening mentorship programmes for chief audit executives.

She added that ACAEBIN had recently engaged the top management of the Nigerian Police Force National Cybercrime Centre on cybercrime, fraud trends and intelligence sharing.

She stressed that addressing emerging risks required collective action and coordinated institutional responses.

The meeting featured presentations by the Nigerian Police Force (NPF) and Deloitte Nigeria on digital fraud, AI governance, cyber resilience and the evolving role of internal audit.

Presenting on behalf of the NPF, Winner Martins said the NPF Vigilant application, launched by the Inspector-General of Police, Olatunji Disu, on September 1, had been developed by the Force’s ICT Department to strengthen collaboration among banks, customers and the police in combating digital and financial fraud.

He said the platform comprised a mobile application for members of the public and an administrative platform for banks and the police.

According to him, customers could report suspected fraud, upload supporting evidence and track complaints, while bank fraud desks could communicate directly with police officers when enforcement action was required.

Martins urged banks to onboard their fraud desks and use the platform in real time, saying its integration with the judicial system would facilitate the processing of digital court orders and reduce turnaround time in fraud-related cases.

Also speaking, Senior Partner, IT and Assurance Services, Deloitte Nigeria, Amalachukwu Udo, who was represented by the firm’s Senior Manager, IT and Control Assurance, Chisom Odobeatu, said internal audit functions must evolve alongside banks’ transition from traditional banking to digital services and AI.

Udo urged banks to maintain inventories of AI systems, establish clear accountability for their deployment and ensure that the models were scalable, explainable and based on reliable data, with continuous human oversight.

On cyber resilience, she said banks should move beyond preventing attacks to ensuring that they could withstand, respond to and recover from incidents involving core banking systems, ransomware, cloud services, system downtime and compromised privileged accounts.

Udo further warned that growing reliance on cloud providers, fintech companies and other third-party technology partners meant that banks could not limit their assurance activities to their internal environments.

She recommended stronger contractual requirements, independent certifications, audit rights and joint testing to provide greater assurance over third-party controls.

Leave a Reply

Your email address will not be published. Required fields are marked *