1. Home
  2. Blog
  3. AI for Nigerian Businesses
  4. AI Governance for Nigerian Businesses: A Practical Operating Model

AI Governance for Nigerian Businesses: A Practical Operating Model

African business colleagues planning in an office — an article about AI governance for Nigerian businesses

Governance sounds like a large-company word, and that is why most Nigerian SMEs skip it until something goes wrong: a sales assistant pastes a customer list into a free chatbot, a support bot quotes a price that does not exist, or an AI-generated contract clause goes out to a client. None of those are technology failures. They are decision failures — nobody had said who may do what.

This article is about the operating model rather than the document. If you are looking for the written rules staff sign, that is the AI policy; governance is the structure around it that decides what the policy should say and checks that it is working. The two fit together, and a small business can run both on one page each.

What AI governance actually means

AI governance is the management system that decides and supervises how a company uses artificial intelligence. It answers five questions in writing: what AI are we using, why, with what data, who approves it, and how do we know it is still behaving. It is not a technical control and it is not a legal document — it is a small set of recurring management habits.

Three things make AI different from ordinary software and worth governing separately:

  • It produces output nobody wrote. A spreadsheet formula is predictable; a language model composes a new answer each time, and its errors look plausible rather than obviously broken.
  • It ingests whatever staff paste into it. The risk surface is not the vendor contract, it is the copy-and-paste habit of a sales executive at 9pm.
  • It spreads without procurement. Most AI tools in a Nigerian office arrived on someone's personal account, so the usual purchase controls never fired.

Governance closes that gap without banning the tools, which never works.

Governance, policy and compliance: how they differ

These three words get used interchangeably and cause real confusion in board discussions. The distinction is practical.

TermWhat it isTypical artefactWho owns it
GovernanceThe structure that decides and supervisesAI register, risk tiers, approval gates, review calendarMD or a small AI committee
PolicyThe written rules staff must followA two-page AI use policy signed at onboardingHR with management sign-off
ComplianceMeeting external obligationsNDPA records, sector regulator requirements, contract termsData protection lead or compliance officer
SecurityTechnical protection of systems and dataAccess control, logging, vendor assessmentIT or the technology partner

A company can have a policy and no governance — rules nobody checks. It can have compliance paperwork and no governance — a filed document and an ungoverned shadow of AI tools in daily use. Governance is what makes the other three stay true over time.

The five decisions governance must settle

Before writing anything, settle these. They take one meeting.

  1. Scope. Which AI counts? The practical answer for most Nigerian companies: any tool that generates content, makes or influences a decision, or processes customer or staff data using AI — whether bought, built, embedded in software you already pay for, or used free by staff.
  2. Decision rights. Who may approve a new AI use? In a 10-person business, the MD. In a 100-person business, a department head for low-risk uses and a small committee for the rest.
  3. Data boundaries. What data may never be pasted into or connected to an external AI service without approval — for example customer bank details, BVN or NIN, staff records, unreleased pricing, client legal documents.
  4. Human oversight rule. Where a person must approve AI output before it reaches a customer, a payment, a regulator or an employment decision.
  5. Review cadence. How often the register is reviewed and by whom. Quarterly is enough for most SMEs; monthly during a heavy adoption period.

Write the answers on one page. That page, plus the register below, is a functioning governance framework for a business under 200 staff.

Step 1: Build an AI use register

The register is the foundation. It is a simple table — a spreadsheet is fine — listing every AI use in the organisation. Most companies discover between eight and thirty entries on the first pass, and are surprised by half of them.

Ask each department head for anything their team uses that writes, summarises, answers, predicts, scores, transcribes or generates images. Include tools embedded in software you already pay for, because those are governed too.

FieldExample entry
Use caseDraft replies to customer enquiries on WhatsApp
OwnerCustomer service lead
Tool or modelLLM-powered assistant in the support platform
Data usedCustomer name, order history, message content
Data leaving Nigeria?Yes, vendor processes outside Nigeria
Risk tierMedium
Human reviewAgent approves before sending
Approved byMD, March 2026
Next reviewQuarterly

Two rules keep the register honest. First, nothing goes live without an entry — the register is the approval trail, not documentation written afterwards. Second, unapproved tools found in use are not punished on discovery; they are registered, tiered, and either approved or replaced. Punishment drives shadow use underground, which is the outcome you are trying to avoid.

Step 2: Assign a risk tier to each use

Tiering is what stops governance becoming a tax on every small thing. Three tiers are enough.

Low risk. AI output that stays internal, is checked by the person using it, and touches no personal or confidential data. Drafting a social post, summarising your own meeting notes, rewriting an internal memo. Governance requirement: covered by the general policy, no individual approval, listed in the register by category rather than by instance.

Medium risk. Output that reaches a customer, or processing that involves personal data, but where a human sees it before it takes effect. Drafted customer replies, AI-assisted marketing copy, lead scoring that a sales person acts on, transcription of client calls. Governance requirement: named owner, documented data boundary, human review before the output leaves the company, quarterly check.

High risk. AI that acts without a human in the loop, or that influences money, credit, employment, health, legal outcomes or regulatory filings. Autonomous agents that issue refunds, automated credit or eligibility decisions, CV screening, anything giving customers health or legal guidance. Governance requirement: written approval by management, documented testing, logging of every decision, an appeal or override route for the affected person, and a periodic accuracy review. Some of these should simply not be deployed by an SME.

A short decision test: if this output were wrong and nobody noticed for a week, what would it cost us in naira, in customer trust, or in regulatory exposure? Small and reversible is low; embarrassing but fixable is medium; expensive, unfair or reportable is high.

Step 3: Set approval gates and human oversight

An approval gate is a defined point where a person must say yes. Three gates cover most businesses.

  1. Before adoption. A new AI use case is registered, tiered and approved by the right level. For medium and high tiers, the approver confirms what data the tool receives and where it is processed.
  2. Before output takes effect. For medium and high tiers, a named role reviews output before it goes to a customer, a payment system or a public channel. Define what "review" means in practice — reading the whole message, or spot-checking one in ten — so it is not theatre.
  3. Before expansion. Moving an AI use from one team to the whole company, or from suggesting to acting, is a new approval, not a continuation of the old one. This is the gate companies most often skip, and it is where autonomous agents quietly acquire authority nobody granted.

Human oversight only works if the reviewer has the time, information and authority to say no. A support agent told to approve 400 AI drafts an hour is a rubber stamp, not an oversight control. Set review volumes a person can genuinely handle, or reduce the AI's autonomy instead.

Step 4: Monitor, review and handle incidents

Governance without monitoring decays within a quarter. Keep it light but real.

  • Log what matters. For medium and high-tier uses, keep a record of inputs, outputs and who approved. Most business platforms can export this; if a tool cannot, treat that as a mark against it.
  • Track three numbers per use case. Volume (how often it runs), correction rate (how often a human changes the output), and escalation or complaint rate. A rising correction rate is the earliest warning that a model, prompt or business process has drifted.
  • Sample manually. Once a month, pull ten real outputs per medium or high-tier use and read them. Automated metrics miss tone, cultural mismatch and quiet nonsense.
  • Review quarterly. Go through the register: what is still in use, what changed, what should be retired, what moved tiers. Retire unused entries — a stale register is worse than none because people stop believing it.

Have a written incident route before you need it: who is told, within how long, who can switch the AI off, how affected customers are contacted, and how the fix is recorded. For incidents involving personal data, the Nigeria Data Protection Act 2023 and guidance from the Nigeria Data Protection Commission set expectations for how breaches are handled — confirm current requirements with the NDPC or your legal adviser rather than relying on a generic template.

Governing vendors, models and data

Most Nigerian businesses will not train their own models. Governance therefore mostly means governing suppliers.

Ask every AI vendor, and every software vendor who has switched on AI features, the same six questions:

  • What data of ours does the feature send to the model, and can we turn specific fields off?
  • Is our data used to train the vendor's models, and can we opt out in writing?
  • Where is the processing performed, and what is the retention period?
  • What logging and export do we get, so we can audit decisions later?
  • What happens to our data and our configurations if we stop paying?
  • Which sub-processors are involved, and are they disclosed?

Record the answers in the register. Where a vendor cannot answer in writing, treat that as your answer. Also govern the boring path: staff using free personal accounts. The realistic control is not prohibition but provision — give the team an approved tool on a business account with data settings configured, and the personal-account habit largely disappears.

What changes for Nigerian businesses

Several governance factors look different here, and generic international frameworks will not tell you about them.

The NDPA 2023 applies to AI use like any other processing. If an AI tool processes personal data of people in Nigeria, the usual obligations — lawful basis, purpose limitation, data subject rights, security, and registration duties for data controllers of major importance — do not pause because the processing is clever. The NDPC publishes current guidance; verify your specific obligations with the Commission or a qualified adviser rather than assuming.

Cross-border processing is the default, not the exception. Almost every AI model your business will use runs outside Nigeria. Governance should record that fact for each use case and check the contractual safeguards, instead of pretending the data stays local.

Sector regulators sit above you. Banks, fintechs, insurers, hospitals, schools, pharmacies and law firms answer to the CBN, NAICOM, professional councils, NUC and similar bodies. An AI use that is fine for a fashion retailer may need specific approval in a licensed business. Check before deployment, not after.

Costs are USD-denominated and volatile. Model and API usage is billed in dollars, so a naira budget approved in January can be materially tight by June. Governance should include a spending cap per use case and an alert when usage exceeds it — this is one of the few controls that pays for itself immediately.

Connectivity and power shape design. If an AI-dependent process has no manual fallback, a bad network day becomes a business outage. Every high-tier use should have a documented manual path.

Language and context accuracy needs local testing. Customers write in Nigerian English, Pidgin, and mixed languages, with local place names and abbreviations. Test with real Nigerian message samples before approving any customer-facing AI, and re-test after model changes.

Example (hypothetical): governance at a 60-staff Lagos logistics company

This is an illustrative scenario, not a Linestech client.

A Lagos haulage and last-mile delivery company with 60 staff discovers, during a management meeting, that AI is already in use in four places: the customer service team drafts WhatsApp replies with a free chatbot, the marketing officer generates social captions, an operations analyst pastes delivery data into a chatbot to summarise weekly performance, and the new dispatch software has an AI route suggestion feature nobody evaluated.

They spend one meeting settling the five decisions, then build the register.

Use caseTierControl applied
Drafting customer WhatsApp repliesMediumMoved to a business account; agent approves every reply; no bank details pasted
Social media captionsLowCovered by policy; no approval needed
Weekly operations summariesMediumClient names and addresses stripped before pasting; owner named
AI route suggestion in dispatch softwareMediumVendor questioned in writing; dispatcher confirms each route
Proposed: auto-refund agent for failed deliveriesHighNot approved; refunds remain human until logging and caps exist

Ongoing cost: the operations manager spends about two hours a month on sampling and the register, and the MD spends an hour a quarter on review. The single most valuable outcome was not any of the controls — it was discovering that customer addresses and phone numbers had been going into a free personal chatbot account for months, and stopping it.

What AI governance costs and who does the work

Governance is mostly time, not money. Indicative 2026 ranges; actual costs vary with scope, vendor and exchange rate.

ComponentSmall business (under 25 staff)Mid-sized (25–200 staff)
Initial setup: register, tiers, policy, one workshop₦0 internally, or ₦300,000–₦1,500,000 with an external adviser₦800,000–₦4,000,000 with an external adviser
Ongoing management time2–4 hours per month1–3 days per month across roles
ToolingUsually a spreadsheet, ₦0Existing GRC or ticketing tool, often no new spend
Staff training session₦0–₦400,000₦400,000–₦2,500,000 depending on cohorts
Logging or audit work in custom systems₦300,000–₦2,000,000 if development is needed₦1,000,000–₦6,000,000+

Who does it: in a business under 25 staff, the MD or operations lead owns the register personally. Between 25 and 200 staff, appoint one accountable owner — typically operations, IT or compliance — plus a standing group of two or three department heads meeting quarterly. Above that, it belongs with whoever already owns data protection. Do not create a committee larger than the number of AI use cases you have.

Mistakes to avoid

  • Writing a 30-page framework nobody reads. Length is not rigour. One page of decisions plus a live register beats a downloaded international framework every time.
  • Banning AI outright. Staff continue using it on personal phones and you lose all visibility. Provide approved tools instead.
  • Governing pilots but not embedded features. The AI inside your accounting, HR or dispatch software is ungoverned in most companies precisely because nobody bought it separately.
  • Treating accuracy as a one-off test. Vendors update models without notice, so accuracy on the day of approval says nothing about accuracy in six months.
  • Assuming the vendor's compliance is your compliance. A supplier's certifications do not transfer your NDPA obligations to them.
  • Letting an AI tool acquire autonomy by drift. A suggestion tool that staff stop checking has become an automatic decision system without an approval.
  • No spending cap. Usage-based, dollar-priced AI with no cap is how a ₦200,000 monthly budget becomes ₦900,000 after a traffic spike.
  • No manual fallback. If the AI is down, the process must still run.

Conclusion

AI governance for a Nigerian business is not a framework download; it is a register, three risk tiers, a named approver, a human review rule for anything that touches money, customers or personal data, and a quarterly look at the whole thing. Start by finding out what AI is already running in your company — including the features inside software you already pay for — then tier it, assign owners, set spending caps, and sample outputs monthly. Keep the paperwork to two pages. The purpose is to let your team use AI confidently, not to slow them down.

If you are putting AI into customer service, sales or internal systems and want the oversight, logging and fallback paths designed in from the start, Linestech builds AI integrations for Nigerian businesses with those controls as part of the work rather than an afterthought.

Frequently asked questions

Is AI governance necessary for a business with fewer than 20 staff?

Yes, but in proportion. A 15-person company needs three things: a one-page rule on what data may not go into AI tools, a list of the AI tools actually in use with a named owner each, and a rule that anything reaching a customer is read by a person first. That takes an afternoon to set up and about an hour a month to maintain.

Who should own AI governance in a Nigerian company?

One accountable person, not a department. In small businesses, the managing director or operations lead. In larger ones, whoever already owns data protection or compliance, supported by department heads who own individual use cases. The owner's job is to keep the register current and run the quarterly review, not to approve every prompt.

Does the Nigeria Data Protection Act cover AI specifically?

The NDPA 2023 governs the processing of personal data generally, and AI processing of personal data falls within it rather than outside it. The Nigeria Data Protection Commission issues guidance that changes over time, so confirm your current obligations — including any registration duties and breach reporting timelines — with the NDPC or a qualified adviser before relying on a summary.

How is an AI policy different from AI governance?

The policy is the written rulebook staff read and agree to: what they may use, what data is off limits, when to disclose AI use. Governance is the surrounding system that decides what those rules should be, approves new uses, checks that the rules are followed, and updates them. A policy without governance goes stale within months.

What should we do about staff already using AI on personal accounts?

Register it rather than punish it. Ask each team to list what they use and for what, assess the data exposure, then provide an approved business-account alternative for the legitimate uses and switch the rest off. Companies that lead with discipline get an incomplete list and continued hidden use.

How often should the AI register be reviewed?

Quarterly is sufficient for most Nigerian SMEs, with a monthly sample check of outputs for medium and high-risk uses. Review sooner if a vendor changes its model, a new regulation lands, an incident occurs, or you move an AI use from suggesting to acting.

What is the first document we should produce?

The register. Before writing any policy, list what AI is actually in use, who owns it, what data it touches and whether a human checks it. Almost every useful governance rule in a Nigerian SME becomes obvious once that list exists.

Sources and further reading

Figures, platform rules and regulations change. These are the primary references behind this article and the places to check before you act on it.