Category: Audit

  • What we look for when we read a Nigerian sustainability report, and why it is rarely the disclosure itself

    What we look for when we read a Nigerian sustainability report, and why it is rarely the disclosure itself

    When we are asked to look at a sustainability report before it is published, we do not start with the sustainability report; we start with the impairment model. The reason is practical rather than clever.

    The sustainability disclosures will contain a view about the future: about prices, demand, energy costs, the exchange rate, and how long the assets will keep earning. The impairment model contains a view about the same things, prepared by different people, months earlier, for a different purpose, and already audited.

    If those two views agree, most of the report will hold together. If they do not, no amount of drafting will save it, and the work that is needed is not drafting work at all.

    This is the part of the new standards that we think is least well understood in this market, and it is the part that will determine which Nigerian companies come through the first mandatory cycle without difficulty.

    Why the impairment model, and not the report

    Because impairment is where a view about the future stops being a view and becomes a number.

    A sustainability report can describe a risk in general terms and remain internally coherent. An impairment model cannot. It requires management to state what it expects a barrel, a tonne, a subscriber or a dollar to be worth, over a defined period, and then to accept the consequence in the carrying value of the assets. The assumptions are forced into figures, reviewed, and audited.

    So, the impairment model is the most reliable available record of what a company believes about its own future. Every other statement about the future in the strategy section, in the climate disclosures, in the transition plan can be read against it.

    The test is simple. If the two documents describe the same future, the report is likely to hold together under examination. If they do not, the drafting is not the problem.

    An illustration, using assumed figures rather than any company’s.

    A group prepares its climate scenario analysis on an exchange rate of ₦1,500 to the dollar. Its impairment model, run three months earlier, used ₦1,800. The budget the board approved for the same period assumed ₦2,100.

    Each is defensible in isolation. Together they mean the group carries its assets on one view of the naira, plans its spending on a second, and describes its resilience to investors on a third.

    Which of the three flatters the company depends on whether it is a net earner or a net payer of dollars and that is the point. Nobody worked out the direction, because nobody put the three numbers side by side. The disclosures are not wrong. They are unexamined, and the difference between those two things is what an assurance provider is paid to find.

    That is why the sequence of a review matters. Read the report first and it appears competent. Read the impairment model first and the report has a question to answer.

    It also makes plain what we are really asking. The question is not whether the disclosures are well drafted. It is whether the company holds one view of its own future, or several.

    Why this is a management question, not a drafting one

    The standards require the two documents to hold together. A risk named in the sustainability section must be traceable into the metrics that measure it, the targets that commit to it, the assumptions that carry it, and the effects that appear in the accounts.

    Stated that way it sounds like an instruction to whoever writes the report. In practice it is a question about how the organisation reaches its numbers.

    The assumptions in question were not created for the report. They were set months earlier, inside models that drove real decisions which projects were approved, what the assets are carried at, how much was provided for, what the company told its lenders. The report does not invent them. It gathers them.

    Which means that where the report shows those views disagreeing, the report has not created a problem. It had surfaced one that was already there.

    Why competent organisations still fail this

    We want to be clear about something, because the point is often made unfairly. Divergent assumptions are not evidence of a weak finance function. They arise in organisations where each function is doing its job carefully, and the standards anticipate as much as IFRS S1 asks for consistency between the disclosures and the financial statements precisely because it cannot be assumed.

    Treasury takes a view suited to a hedging horizon. Finance takes a view suited to a five-year impairment forecast. The sustainability team applies a published transition pathway, which is what the standard contemplates. Each is defensible. Each is reviewed by people who understand the purpose it serves.

    The gap opens because nothing in the reporting calendar ever required the views to be compared with one another. They are produced on separate cycles, for separate approvals, and reviewed by people with no reason to look sideways. In most organisations no individual has ever seen all four together.

    The annual report is the first document that forces the comparison. It does so in public.

    Three failures the Nigerian context makes likely

    The naira is the clearest case, but the same divergence appears in three other places, and reading the standards against local conditions makes each of them predictable. Everyone is a comparison that nobody was required to make.

    1. Intensity ratios that improve on their own: Emissions intensity is generally measured against revenue. Where naira revenue rises sharply without additional output, the ratio falls without anything having been done. Reported alongside absolute emissions, this is transparent. Reported alone, it credits the company with the work the currency did.
    2. Generators that appear in the accounts and not in the narrative: For many companies here, diesel is among the larger cost lines and the largest single source of direct emissions. It is common to find it discussed carefully in financial review and absent from the climate section entirely. That is not a disclosure oversight; it means two parts of one organisation described the same asset differently.
    3. Emissions reported on a different population from the accounts: For greenhouse gas purposes a group may consolidate on an equity share basis or on a control basis, and these produce genuinely different totals. All are legitimate. What is not sustainable is reporting one population in the emissions inventory and another in the financial statements without explaining how the two relate.

    None of these is a failure of effort. Each is a failure of comparison, and each becomes far easier to see once the audited assumptions are treated as the baseline against which the report is read, which is why we start there.

    2028 is not the date that matters

    Which leaves less time than most boards assume. Mandatory adoption applies to accounting periods beginning on or after 1 January 2028 for public interest entities: a definition that, in Nigeria, reaches any company with turnover of ₦30,000,000,000 and above, whether it is listed or otherwise regulated. Several companies that have not considered this to be their concern are inside that perimeter.

    But the Council requires readiness submissions before that period begins: three months before, for the first of three stages. A December year-end therefore files in the third quarter of 2027: an adoption resolution, a completed gap analysis, and a costed implementation plan the Council reviews.

    Which means the assumption register, the reporting boundary and the data pipeline must exist during 2027, not in the drafting season that follows.

    Assurance follows, under ISSA 5000, which takes effect on 15 December 2026, and escalates to reasonable assurance by the seventh year of reporting. Where assumptions have not been reconciled internally, each must be evidenced separately and every difference explained to somebody whose role is to ask. That work is chargeable, and the charge falls on the company.

    What we would suggest a board asks

    All of which is reduced to a short agenda. These are not technical questions, and none requires familiarity with the standards. Each has a factual answer, and the answers are usually available within a week.

    • Do we maintain one register of the assumptions we use about the future, recording where each one is used?
    • Did the climate scenario analysis use the same figures as the impairment model and the approved budget? Where they differ, has the reason been written down?
    • Does our sustainability reporting cover the same entities as our consolidated accounts, and if not, which are excluded and on what basis?
    • Every commitment made in last year’s report: where is each reported this year, including those not met?
    • Who in this organisation can answer the first four questions without consulting four different teams?

    The last question is the one that usually settles the matter. Where the answer is nobody, the work required is organisational rather than editorial, and it is better to begin early.

    Our view

    Nobody is asking Nigerian companies for certainty about the future. Certainty is not available, and a company that states plainly what it does not know is trusted more, not less.

    What is being asked is narrower, and it is answerable. Most of the work is a single register of assumptions, maintained through the year rather than assembled at the end of it, recording what the company believes about prices, demand, inflation, the exchange rate and the life of its assets — and where each of those beliefs is applied.

    Companies that build it during 2027 will find the first mandatory report largely a matter of assembly. Companies that do not will find it a matter of reconciliation, conducted under deadline, in front of an assurance provider.

    Where a board wants to test this before the next reporting cycle, the exercise is short. Put the assumption sets from the scenario analysis, the impairment model and the approved budget on one page and see whether they agree.
    We are happy to discuss what that exercise usually involves, and what to do where they do not.


    Regulatory statements above are taken from the Roadmap Report for the Adoption of IFRS Sustainability Disclosure Standards in Nigeria (Amended 2026) and Sustainability Reporting Guideline 1 (SRG 1) in Nigeria (2026), as published by the Financial Reporting Council of Nigeria and checked against those texts on 22 July 2026. The roadmap’s narrative and its assurance table do not agree on whether assurance is required from the third year of reporting; entities approaching that point should seek written clarification. Positions in this area change quickly.

    Stransact is a part of RSM International. This article is general commentary and is not advice for any particular entity.

  • The IIA’s 2026 Three Lines Model: What It Misses in Nigerian Board Governance

    The IIA’s 2026 Three Lines Model: What It Misses in Nigerian Board Governance

    The Institute of Internal Auditors has rewritten the Three Lines Model and pointed it at boards. For Nigerian directors, the more useful reading is not what the model says, but what it leaves for them to decide.


    The most consequential change in the Institute of Internal Auditors’ (IIA) 2026 Three Lines Model is not a word in the model. It is where the IIA filed the document. The 2013 and 2020 releases were Position Papers written for internal auditors. The 2026 release is a Statement of Position, “Assurance and Advice in Support of Effective Governance,” placed deliberately outside the International Professional Practices Framework and, in the IIA’s own words, intended for “an executive audience, rather than primarily for internal auditors.” The audience has changed. For a Nigerian board, that should register before any debate about lines and roles begins, because it means the IIA is now speaking to you directly, and having done so, it leaves the first of several questions unanswered: in a governance structure like Nigeria’s, which committee owns the assurance it wants coordinated?

    This article works through what the model misses for a Nigerian board: a second line drawn too loosely to be useful, an integrator role that strains internal audit’s independence, and, above all, the committee that should own integrated assurance and is never named. The recommendation, in one line: use the 2026 model to fix ownership of assurance, not to redraw the committee structure you already run.

    Start with the structure, because it is the fact that makes this model land differently in Lagos than in London.

    The Nigerian board does not have one oversight body: It has three

    A Nigerian public company does not oversee its three lines through a single board or a single committee. It does so through a layered structure that the 2026 model does not contemplate. Section 404 of the Companies and Allied Matters Act 2020 (CAMA) requires every public company to establish a Statutory Audit Committee of five members: three shareholder representatives and two non-executive directors, elected annually, all financially literate, with at least one of them a member of a professional accounting body established by an Act of the National Assembly. That is an audit committee with shareholders sitting on it, elected on the floor of the annual general meeting. It has few parallels internationally.

    Above and besides, it sits the Nigerian Code of Corporate Governance 2018 (NCCG), issued by the Financial Reporting Council of Nigeria. Principle 11 directs the board to delegate to well-structured committees without abdicating its own responsibility, and it recommends four: nomination and governance, remuneration, audit at Principle 11.4, and risk management at Principle 11.5. The Board Audit Committee under Principle 11.4 is a separate body from the Statutory Audit Committee that CAMA mandates; the Code says so expressly. The Code permits a company to combine these committees where its size and needs justify it, but the position it recommends is separation. Sector codes add further obligations: banks, insurers and pension fund operators each carry their own committee requirements, and the code for licensed pension operators mandates a risk management committee outright.

    So, a listed Nigerian company may run a Statutory Audit Committee under CAMA, a Board Audit Committee under the NCCG, and a Risk Management Committee under the NCCG, each with a different composition, a different mandate, and a different reporting line. The IIA’s 2026 model collapses all of this into one defined term. It uses “board” to mean the board and any of its committees and notes only that the board may delegate to a committee “such as an audit committee.” That is a reasonable simplification in a jurisdiction with one unitary board committee for assurance. It is a material omission in ours.

    What the model became, and why

    The evolution is worth stating plainly, because each version was built to do a different job, and each should be judged against its own purpose rather than against the latest one.

    The 2013 Position Paper, “The Three Lines of Defense in Effective Risk Management and Control,” was a control map bred in financial services. It named the second-line functions without ambiguity: financial control, security, risk management, quality, inspection, compliance. It achieved its stated aim, which was to explain internal audit and its relationships. It then suffered the fate of useful diagrams. Organisations adopted it as a rigid governance structure, which its own authors say was never meant to be.

    The 2020 update dropped “of Defense,” reframed the model around creating and protecting value, and introduced “governing body” as the single point of accountability, removing an ambiguous layer of senior management that had sat between internal audit and the board. It moved from six principles built on named functions to principles built on roles. Its intent was partly achieved. The language landed. The rigidity eased. But once the named second-line functions disappeared, the second line began to blur.

    The 2026 Statement of Position extends that blurring and reorganises everything around a new spine: the distinction between assurance and advice. It cuts to five principles. It reframes independence as a continuum and warns that independence should not harden into isolation. It casts the internal audit function as the integrator of assurance across the organisation. And it adds something the earlier versions lacked: practical safeguards for the messy reality of overlapping roles, including a twelve-month interval between owning a process and providing assurance over it, and explicit board approval where a chief audit executive’s remit expands.

    That last contribution is the real one. As a conceptual model it is weaker than 2020, not stronger, because the second line is now drawn so loosely it will not hold, a failure addressed below. The operational guidance, by contrast, is genuinely new.

    The value to the board is real, but narrower than advertised

    The 2026 model does not strengthen a Nigerian audit committee’s hand. It does something more specific. By re-pointing the document at boards and executives, the IIA gives directors a plain-language account of where assurance comes from and why independence matters. That is useful to a Statutory Audit Committee whose shareholder members may not be career governance professionals, and it is useful to a Board Audit Committee weighing how much to rely on management’s own monitoring.

    But the model does not expand the audit committee’s role, and any article claiming it does has misread it. The absence of an expanded audit committee mandate is not an oversight the IIA forgot to correct. It is a deliberate silence. The model declines to allocate oversight to any committee at all: a silence that bites wherever assurance oversight is split across more than one committee, as it is across much of the continent.

    The question the model should have answered

    Here is the gap, and it is sharper in Nigeria than in jurisdictions built around a single audit committee. The 2026 model’s headline is coordination: someone must receive the integrated view, hold the assurance map: the single picture of who assures which risks and arbitrate when the second and third lines disagree. The model champions that coordination and never names the coordinator.

    In the Nigerian structure, that owner is not the audit committee. The Statutory Audit Committee is tied by CAMA to financial reporting and the external auditor; the Board Audit Committee’s centre of gravity is internal control and internal audit. Risk Management Committee mandates in Nigeria vary, and some are thin, but where a company runs one with real authority, its remit is the closest fit for integrated, forward-looking, enterprise-wide assurance. That is the committee the 2026 model never mentions, because it never descends below the word “board.”

    That the audit committee’s remit is expanding is not in dispute. The debate over audit committee overload and whether risk oversight should move to a dedicated risk committee is well established internationally, though it is framed for boards weighing whether to create such a committee at all.

    RSM’s review of audit oversight describes the pattern: as audit committees absorb cyber, sustainability and technology risk, boards carve that load off into a dedicated committee to protect the committee’s core work. Nigeria sits a step past that debate: its Code already recommends a Risk Management Committee at Principle 11.5 but has not given it the mandate so the question is not whether to create the committee, but whether to finish the job.

    So, the correct question is not whether the audit committee’s role should expand. It is whether the Risk Management Committee’s role should be strengthened to own the integrated assurance agenda the IIA now promotes, and whether Nigerian boards should give it that mandate explicitly rather than leave integrated assurance homeless between three committees. They should, and the model’s silence is an argument for doing it deliberately rather than waiting for the IIA to do it for them.

    Where the 2026 model contradicts itself

    A document written for boards should resolve its own tensions. This one defers them: it is, in its own words, “applied using professional judgment,” and it leaves at least three tensions for the reader to reconcile. Because the board defines roles, but the chief audit executive operates the overlaps, those tensions fall in practice to internal audit which is precisely where a board-facing document should not put them.

    First, the model’s stated purpose is role clarity, yet it has made its own middle line impossible to define. Having removed every named example, it describes the second line as roles providing “specialized expertise, support, monitoring, and challenge.” As Norman Marks observed on 13 July 2026, that definition sweeps in finance, information security, corporate security, and arguably senior management itself. A model built for clarity has made its second line unfalsifiable. The fix is modest: restore an illustrative, non-exhaustive list, or define the second line by a test, that it advises and challenges but does not own the control, rather than by a string of adjectives.

    Second, the model treats independence as a continuum and encourages blended roles and chief-audit-executive supervision of second-line functions to reduce duplication, then states flatly that assurance cannot be credible where the reviewer designed or operated the process. Both propositions are correct. Presented in the same neutral register, they leave a board unsure whether the IIA is endorsing the blending or warning against it. The fix is to state the default, which is separation, and to treat blending as the exception that triggers the model’s own safeguards, rather than offering both as equivalent choices.

    Third, the model asks internal audit to coordinate and consolidate assurance while avoiding ownership of second-line activities. Designing the assurance map and aligning methodologies, then auditing the framework you helped shape, is a self-review threat at the level of the framework itself. The fix is to cap the integrator role at facilitation and reporting, and to seat ownership of the assurance map with management or, in the Nigerian case, the Risk Management Committee.

    The hardest objection, and why the model still earns its place

    The strongest case against the 2026 model comes from Norman Marks, and it is fair to put it at its full strength. Marks concedes the second-line definition has improved, then asks the question that should worry the IIA: “What board or senior management action or decision does it change?” On the conceptual model, the point holds. Three lines, further diluted, changes no decision.

    But the objection misses where the value moved. It did not stay in the diagram. It moved into the reclassification, which puts a governance document in front of the people who make governance decisions, and into the overlap safeguards, which do change decisions. A Nigerian board that reads the twelve-month rule and the requirement for explicit approval of an expanded chief-audit-executive remit has been given something to act on. That is not nothing. It is simply not in the part of the document most people will quote.

    A note on independence

    One caveat belongs to the record, because it runs through the subject rather than sitting beside it. The 2026 model tolerates a chief audit executive supervising second-line functions, and it tolerates internal audit designing, operating and later assuring the same framework, provided safeguards are in place. That is the classic self-review threat, and the safeguards do not remove it; they manage it. The sound default is separation: a party should not provide assurance over a framework it designed or operates. Where a board chooses to blend the roles, it should treat the model’s safeguards as the price of the exception, not the terms of the arrangement, and satisfy itself that an independent party assures the overlap for as long as it lasts.

    What a Nigerian board should ask

    Three things, then, the model leaves undone. It defines the second line as being too loosely to be useful. It hands internal audit an integrator role that strains its own independence. And it never says which committee owns the assurance it wants coordinated. The first two are the IIA’s to fix. The third is the boards.

    So do not adopt the 2026 model as a structure. Adopt it as a prompt. Then answer the question it left open: of your Statutory Audit Committee, your Board Audit Committee, and your Risk Management Committee, which one owns the integrated view of assurance, holds the assurance map, and resolves conflicts between your second and third lines? If the honest answer is that no committee owns it, the model has done its most useful work simply by exposing the vacancy. Fill it on purpose.


    Source: Norman Marks, “Is Risk Management a 2nd line function in the updated Three Lines Model?”, writing on his personal governance blog, 13 July 2026. https://normanmarks.wordpress.com/2026/07/13/is-risk-management-a-2nd-line-function-in-the-updated-three-lines-model/

    Source: On audit committee overload and the case for moving risk oversight to a dedicated risk committee, see RSM US, “Audit oversight in 2024” (a Corporate Board Member roundtable in partnership with RSM, 10 January 2024), and, for the independent view, “Are Audit Committees Overloaded?” (Columbia Law School Blue Sky Blog, 2019).

    RSM article: https://rsmus.com/insights/services/audit/audit-oversight-in-2024.html

  • What the four early adopters disclosed, and what IFRS S1 and IFRS S2 will require in 2028

    What the four early adopters disclosed, and what IFRS S1 and IFRS S2 will require in 2028

    Boards preparing for mandatory adoption should begin with three artefacts that cannot be produced in a quarter: a scenario analysis that yields a result, a position on the amount and percentage of assets vulnerable to physical climate risk, and internal control over the data that produces both. The reasoning follows.

    Adoption of the IFRS Sustainability Disclosure Standards becomes mandatory for public interest entities in Nigeria for accounting periods beginning on or after 1 January 2028. Four entities have reported ahead of that date: Access Bank Plc, Fidelity Bank Plc, MTN Nigeria Communications Plc and Seplat Energy Plc.

    This article sets out what those four disclosed in their 2025 annual and sustainability reports, measured against the four content pillars of IFRS S1 and IFRS S2 — governance, strategy, risk management, and metrics and targets and against the readiness requirements of Sustainability Reporting Guideline 1 (SRG 1) in Nigeria (2026). Every observation comes from the companies’ own published documents.

    First, the status of the four reports

    Paragraph 72 of IFRS S1 provides:

    “An entity whose sustainability-related financial disclosures comply with all the requirements of IFRS Sustainability Disclosure Standards shall make an explicit and unreserved statement of compliance. An entity shall not describe sustainability-related financial disclosures as complying with IFRS Sustainability Disclosure Standards unless they comply with all the requirements of IFRS Sustainability Disclosure Standards.”

    The four describe their reporting basis in compliance-oriented terms, each with a qualifier.

    MTN states that its sustainability-related financial disclosures “are prepared in accordance with the IFRS Sustainability Disclosure Standards” an unqualified in-accordance-with statement, made notwithstanding that the disclosures are themselves presented as “abridged”. Abridgement does not by itself defeat compliance; it invites the question whether all required disclosures remain present.

    Seplat heads its section “Basis of Statement of Compliance” and states that its abridged disclosures are “an extract from the Group’s general Sustainability Report prepared in accordance with IFRS Sustainability Disclosure Standards,” adding that the abridged version “equally complies”. That is a dual claim: compliance asserted for a general sustainability report that does not form part of the reviewed pack, and separately for the abridged version that does.

    Access states that the Standards are its “primary reporting basis,” within a report that blends IFRS-based financial-materiality disclosures with broader impact-materiality disclosures aligned with the GRI Standards. IFRS S1 permits the use of other frameworks, so the GRI overlay does not qualify the IFRS claim; the report presents the Standards as its primary basis while pursuing wider sustainability-reporting objectives alongside.

    Fidelity states that it “applied IFRS S1 and IFRS S2 as issued by the ISSB” — a statement of application rather than of compliance with all requirements.

    What none of the four presents is the clean paragraph 72 statement the Standard describes: an explicit and unreserved statement that the disclosures comply with all the requirements. MTN’s in-accordance-with claim carries the “abridged” qualifier; Seplat’s compliance statement is made principally for a report not in evidence; Access’s is a primary-basis claim within a multi-framework report; Fidelity’s is application language.

    This article does not seek to resolve whether any of the four in fact satisfies every requirement needed to support paragraph 72 statement. That would require a full compliance review of each report against the Standards.

    The practical question for boards is the useful one. Whether these reports are treated as compliant, as substantially applied, or as works in progress, the same exercise answers the board’s question: comparing what the four disclosed against the requirements of IFRS S1, IFRS S2 and SRG 1 shows what a Nigerian public interest entity must build before reporting becomes mandatory and subject to assurance in 2028.

    The transitional reliefs: an open question, and evidence pointing to an answer

    The transitional reliefs are specific, and each is worth knowing by paragraph.

    IFRS S1 Appendix E. Paragraph E2 fixes the date of initial application as the beginning of the annual reporting period in which an entity first applies the Standard. Paragraph E3 removes the requirement to disclose comparative information in that first period. Paragraph E4 permits sustainability-related financial disclosures to be published after the financial statements. Paragraph E5 permits disclosure of only climate-related risks and opportunities in the first period and requires the entity to disclose that it has used the relief. Paragraph E6 extends comparative relief into the second period for non-climate disclosures.

    IFRS S2 Appendix C. Paragraph C2 uses the same trigger. Paragraph C4(b) permits an entity, in the first annual reporting period in which the Standard applies, not to disclose Scope 3 greenhouse gas emissions, including certain financed-emissions information for financial institutions. Paragraph C4(a) permits continued use of a non-Greenhouse-Gas-Protocol measurement method carried forward from the preceding period.

    Every one of those reliefs attaches to the first annual reporting period in which an entity applies the Standard. Not to a fixed date. Not expressly to first mandatory application.

    That is where the question arises.

    MTN, Seplat and Access state that their disclosures are prepared in accordance with, or on the primary basis of, the Standards; Fidelity describes application of them. Whether any of the four has thereby entered its first period of application, for the purposes of the transitional reliefs, is not settled — and the answer may bear differently on an entity that has asserted in-accordance-with preparation than on one that has described application. The availability of first-period reliefs may therefore depend partly on the nature of the claim an entity has already made about its sustainability disclosures.

    The interpretation is not settled. One view is that entities already reporting in accordance with the Standards may have commenced application and therefore may have exhausted some or all of the first-period reliefs before mandatory adoption. Another view is that the reliefs remain available upon mandatory adoption in Nigeria, notwithstanding earlier voluntary reporting.

    The construction of SRG 1 bears on the question. The second-stage readiness submission that is due not more than three months after the beginning of the reporting date requires entities to identify and apply transitional reliefs. The requirement assumes that boards will make deliberate decisions about which reliefs to use and when those reliefs expire.

    If voluntary reporting before 2028 automatically exhausted those reliefs, the requirement would have limited practical significance for many early adopters and for much of the voluntary-reporting cohort. The structure of the readiness framework therefore provides at least some support for the view that transitional reliefs may still be available at mandatory adoption.

    That is not conclusive as a matter of IFRS interpretation, and no inference is drawn regarding the FRC’s intention. It does narrow the request considerably: the FRC should state clearly how the transitional reliefs apply to entities that reported voluntarily before the mandate takes effect.

    Whatever the answer, one practical point remains for every board. Relief is a deadline deferred, not a deadline removed. A disclosure omitted in the first period because of relief is generally a disclosure omitted in a later period. A board that has not decided which reliefs it intends to use has not decided its implementation timetable.

    Pillar one: Governance

    IFRS S1 requires identification of the body or individual responsible for oversight of sustainability-related risks and opportunities; disclosure of how that responsibility is reflected in terms of reference, mandates, role descriptions and other policies; how the body determines whether appropriate skills and competencies are available to oversee the responsive strategies; how and how often it is informed; and how it oversees target-setting and monitors progress, including whether related performance metrics are included in remuneration policies.

    What the four disclose. Each identifies a responsible board committee and describes its oversight. Seplat states that its board is ultimately accountable for overseeing sustainability and climate strategy, that these considerations are integrated into risk management and financial decision-making in line with IFRS S1 and IFRS S2, and that dedicated committees meet quarterly.

    On the remuneration requirement, Seplat discloses that 30 per cent of the key performance indicators on its 2025 corporate scorecard were dedicated to sustainability targets, with a 5 per cent component tied to completion of the end-of-routine-flaring programme for the onshore assets.

    What is less developed across the four. The Standard does not require publication of a committee charter. It requires disclosure of how sustainability oversight is reflected in mandates, terms of reference, role descriptions and related policies. The four reports provide governance structures, oversight responsibilities and varying levels of information on board competence, training and remuneration linkage. What is less consistently developed is direct visibility of the underlying governance instruments themselves, and the degree to which the disclosures explain how those instruments are updated, tested and embedded in governance practice. Boards may therefore find that the governance architecture exists before the reporting architecture is fully visible.

    Governance arrangements mature overboard cycles rather than reporting cycles. Where boards intend to strengthen sustainability oversight, clarify committee mandates, or expand director competence, waiting until the year of adoption may leave insufficient time for those changes to become embedded in practice.

    Pillar Two: Strategy

    IFRS S1 requires disclosure of the sustainability-related risks and opportunities that could reasonably be expected to affect the entity’s prospects; their effects on the business model and value chain, on strategy and decision-making, and on financial position, performance and cash flows for the period, with the anticipated effects over the short, medium and long term.

    IFRS S2 paragraph 22 requires the entity to use climate-related scenario analysis to assess its climate resilience, using an approach commensurate with its circumstances: its exposure, and the skills, capabilities and resources available to it — and to explain how and when the assessment was carried out.

    The proportionality condition governs everything in this section. The Standard prescribes no single method, and an upstream oil producer’s exposure is not a bank’s or a telecommunications operator.

    Seplat discloses a quantitative climate modelling assessment across its value chain, comparing the net present value of its portfolio under selected scenarios against a base case. It discloses the driving assumption — a net-zero oil price outlook averaging approximately $25 per barrel by 2050, against a constant base case of $65 — and the result: no major short-term revenue effect, medium-term revenue falling by over $1 billion, and long-term by more than $3 billion. Named scenarios, stated assumptions, and a result. Among the four reports reviewed, it is the only disclosure that presents a fully quantified modelled outcome.

    Access discloses a 2023 pilot climate transition risk assessment conducted with the International Finance Corporation and 1in1000, using the 1in1000 TRISK platform — an asset-level, bottom-up climate stress-testing tool — alongside the Paris Agreement Capital Transition Assessment. In 2025 it screened all commercial and industrial loans and project finance transactions under the Equator Principles. The scenario work described is a pilot performed in 2023 and reported without evident update in 2025. Paragraph 22 asks for an assessment of resilience at the reporting date.

    Fidelity sets out how physical and transition risks may affect financial position, performance and cash flows, and states that it responds through climate scenario analysis, stress testing, and integration of climate risk into credit monitoring, pricing and collateral valuation. It describes a transition plan of key actions, assumptions, dependencies and resources. The disclosure describes the process; it does not present the result of the analysis under a named scenario over a stated horizon.

    MTN states that scenario analysis was conducted in line with IFRS S2 and discloses scenario-specific operational, financial and strategic consequences under different temperature pathways.

    The distinction is narrower than when it first appears. All four entities describe climate scenario analysis or resilience assessment, and Seplat and MTN both disclose named scenarios and scenario outcomes. The difference lies in the level of specificity. Seplat provides quantified portfolio impacts under stated oil-price assumptions. MTN provides scenario-specific operational, financial and strategic consequences under different temperature pathways. Access and Fidelity place greater emphasis on the assessment process, governance arrangements and risk-management response than on the disclosure of scenario outputs.

    A result need not be a monetary figure. It may be a strategic conclusion, an operational consequence, a portfolio reallocation or a capital deployment decision. The closer a disclosure comes to explaining what the scenario analysis produced, the easier it becomes for investors and boards to assess resilience. On that measure, Seplat and MTN presently provide more visibility into outcomes than Access and Fidelity.

    Pillar three: Risk management

    IFRS S1 requires disclosure of the processes used to identify, assess, prioritise and monitor sustainability-related risks, including the inputs and parameters used, whether and how scenario analysis informs identification, how the entity prioritises those risks relative to other types of risk, and whether and how the processes are integrated into and inform the overall risk management process.

    What the four disclose. Fidelity describes a framework for identifying sustainability and climate-related risks and opportunities, evaluation of impacts on business continuity, financial resilience and long-term strategic positioning, and continuous monitoring against key performance indicators. Seplat states that sustainability and climate considerations are fully integrated into its overall risk management and financial decision-making frameworks. MTN states that transition risks across its supply chain, operations and energy-intensive infrastructure are systematically identified, assessed and managed within its broader enterprise risk management framework. Across the four, integration into enterprise risk management is now largely stated rather than implied. The question that remains less visible is how sustainability and climate-related risks are prioritised once they enter that framework.

    The most limited disclosure across the four relates to prioritisation. How climate-related risk ranks relative to other enterprise risks is ultimately a question about the risk register: where climate sits, who owns it, what tolerance applies, and through which escalation pathway it is managed. While the reports describe integration into enterprise risk management, they provide less visibility into how climate risk is prioritised against credit, operational, cyber, liquidity, regulatory or other principal risks.

    Integration is easier to assert than to demonstrate. A climate risk recorded on the enterprise risk register, with a named owner, a defined tolerance and an escalation pathway, demonstrates integration. A statement that climate is integrated into enterprise risk management describes it. An assurer will look for the former.

    SRG 1’s third-stage readiness submission requires an Enterprise and Sustainability Risk Management Framework, together with evidence of board approval. The emphasis is noteworthy. Sustainability risk is not presented as a parallel system. The expectation is a framework through which sustainability risks are identified, assessed, monitored and governed alongside other enterprise risks, using a common taxonomy and a board-approved risk architecture.

    Pillar four: Metrics and targets

    IFRS S2 paragraph 29 sets out cross-industry metric categories every entity must disclose regardless of sector. These include absolute gross Scope 1, Scope 2 and Scope 3 greenhouse gas emissions measured in accordance with the Greenhouse Gas Protocol Corporate Standard, together with the Scope 3 categories used (29(a)); the amount and percentage of assets or business activities vulnerable to climate-related physical risks (29(c)); the amount and percentage vulnerable to climate-related transition risks (29(d)); the amount and percentage aligned with climate-related opportunities (29(e)); the amount of capital expenditure, financing or investment deployed towards climate-related risks and opportunities (29(f)); whether and how an internal carbon price is applied (29(g)); and whether and how climate-related considerations are reflected in remuneration (29(h)). Paragraph 32 requires industry-based metrics derived from the SASB Standards.

    Paragraph 29(c) calls for a monetary amount and a percentage. The requirement is unusually specific. It is not satisfied by identifying vulnerable assets or activities alone. Metric requires quantification. A reader should be able to see both the scale of exposure and its relative significance within the business.

    What the four disclose.

    MTN reproduces the metric in its cross-industry metrics table, quoting the Standard’s requirement for “the amount and percentage of assets or business activities vulnerable to climate-related physical risks”, with the unit of measure stated as “the amount and percentage”. The disclosure states that telecommunications towers, data centres, operational vehicles and freehold and leasehold buildings are vulnerable, and that the towers, being the most vulnerable, have been outsourced to third-party partners, reducing financial and operational exposure. The asset classes are identified. The amount and percentage are not disclosed.

    Fidelity states that it has conducted physical and transition climate risk assessments to determine the amount and percentage of portfolio assets vulnerable to climate-related risks. Elsewhere, the same determination appears as an objective, including evaluation of the proportion of the portfolio exposed to high-risk sectors and regions. The resulting figure does not appear in the report.

    Access discusses climate-related risks, transition assessment and portfolio screening activities, but does not appear to disclose the amount and percentage of assets or business activities vulnerable to climate-related physical risks required by paragraph 29(c).

    Seplat provides qualitative concentration disclosures, identifying operations and infrastructure exposed to climate-related impacts, including production facilities and oil and gas assets in vulnerable regions. It does not disclose a monetary amount or percentage.

    The amount and percentage required by paragraph 29(c) do not appear to be disclosed in any of the four reports reviewed, notwithstanding broader discussions of climate-related physical risk exposure.

    Materiality governs. A company may assess its exposure to physical climate risk, conclude that it is not material, and decide not to quantify the metric. That can be a legitimate conclusion and, for some entities, maybe the correct one.

    None of the four explicitly states that conclusion. A reader therefore cannot distinguish between a metric omitted because management concluded that the exposure is not material and a metric that has not yet been produced or disclosed. Those are different positions. One communicates a judgement. The other leaves the judgement unknown.

    The practice to adopt now costs nothing. Where a required cross-industry metric is not quantified, state why. A materiality conclusion, together with its basis, is a complete disclosure. Silence is not.

    Elsewhere in this pillar, the four disclose more than is often recognised. Fidelity reports financed emissions under Category 15 of the Scope 3 framework using the Partnership for Carbon Accounting Financials (PCAF) Global GHG Accounting and Reporting Standard for the Financial Industry. MTN discloses Scope 1, Scope 2 and Scope 3 emissions and restates its 2024 comparative figures.

    On internal carbon pricing, paragraph 29(g) asks whether and how a carbon price is applied. MTN states that it does not currently operate an internal carbon pricing policy and is evaluating the approach in accordance with IFRS S2. Fidelity states that it is actively exploring implementation. Both disclosures answer the question being asked.

    One point for 2028. Scope 3 emissions benefit from a first-period relief under IFRS S2 paragraph C4(b). They are also excluded from limited assurance during the fourth and fifth years of the SRG 1 roadmap. Both reliefs expire. The data that will eventually be assured is already being collected today.

    Connectivity

    IFRS S1 requires an entity to provide information that enables primary users to understand the connections between sustainability-related risks and opportunities and the entity’s financial statements. The objective is not simply consistency of narrative. The sustainability disclosures and the financial statements should relate to the same reporting entity and the same reporting period, be published at the same time, and be based on consistent data, assumptions and judgements.

    The route to the financial statements differs by sector. For Seplat, it runs through revenue and asset valuation. A scenario produces an oil price assumption, the assumption affects projected cash flows, and the cash flows affect portfolio value. For a bank, the route typically runs through expected credit loss modelling, provisioning, sectoral concentration limits, collateral valuation and capital allocation. Fidelity’s disclosure identifies that route when it describes integrating climate risk into credit monitoring, pricing and collateral valuation. For a telecommunications operator, connectivity may emerge through asset impairment, resilience-related capital expenditure, energy costs or business interruption.

    What the four disclose

    Seplat provides the clearest numerical illustration of connectivity. Its scenario analysis is linked directly to projected financial effects through portfolio valuation outcomes under stated assumptions. The disclosure connects climate assumptions to estimated impacts on future revenues and asset values, allowing the reader to follow the path from climate risk to financial consequence.

    MTN also provides examples of connectivity. The report discloses approximately ₦91.8 million of climate-related infrastructure damage during the year and identifies approximately ₦8.1 billion of energy-related savings from gas-powered electricity initiatives, together with additional savings from efficiency measures. Climate-related risks and opportunities are discussed in terms of their effects on financial position, performance and cash flows.

    Fidelity describes how physical and transition climate risks are considered within credit monitoring, pricing, collateral valuation, stress testing and transition planning. The disclosure explains the mechanism through which climate considerations affect financial outcomes, although it provides less visibility into the resulting financial effects.

    Access discusses climate risk assessment, portfolio screening and sector-level climate considerations, demonstrating how sustainability-related matters enter lending and risk-management decisions. The linkage between sustainability matters and financial outcomes is described, although less emphasis is placed on quantified financial effects.

    The distinction is therefore narrower than it first appears. All four reports attempt to connect sustainability-related risks and opportunities to financial consequences. The difference lies in the extent to which the resulting financial effects are disclosed. Seplat provides quantified scenario-driven outcomes. MTN discloses current financial effects and cost impacts. Fidelity and Access describe the mechanisms through which sustainability matters affect financial performance but provide fewer quantified outcomes.

    Connectivity ultimately ends in financial statements. That is reflected in SRG 1’s third-stage readiness submission, which requires disclosure of the current financial effect of sustainability-related risks and opportunities. Whatever route connectivity takes within a particular sector — revenue, impairment, capital expenditure, provisioning, financing costs or operating expenditure eventually reaches the accounts. At that point, sustainability reporting ceases to be solely a sustainability exercise and becomes a finance exercise as well. A sustainability function may identify the risk, but the financial effect ultimately must be measured, supported and reported through the finance function.

    The word “robust” appears

    Language and evidence

    31 times in the Access report and 25 times in Fidelity’s. “Committed to” appears 36 times in Fidelity’s and 23 times in MTN’s. Seplat, whose disclosures are generally the most quantified of the four reports reviewed, uses both expressions less frequently.

    Word counts do not establish non-compliance. A company can comply and write poorly; a company can write elegantly and omit what is required. The observation is offered as a signal rather than a finding.

    The signal is this. Boilerplate tends to accumulate where decision-useful evidence would otherwise appear. Phrases such as “systematically identified, assessed and managed within our broader enterprise risk management framework” provide context. Standing alone, they provide little that can be independently verified, measured or assured. The Standards were written for existing and potential investors, lenders and other creditors. Where such language appears, the useful question is what evidence sits behind it.

    Four constructions are worth retiring before they become house style:

    “We are committed to …” state the target, the baseline year, the metric and the progress against it.

    “Robust framework” name the framework, identify the approving body and state when it was approved.

    “Actively exploring” state whether the instrument exists. MTN’s disclosure that it does not currently operate an internal carbon pricing policy directly answers IFRS S2 paragraph 29(g); a statement that an entity is exploring one does not answer the same question.

    “Integrated into our enterprise risk management framework” identify the relevant risk, the risk owner, the escalation route and, where appropriate, the relevant risk tolerance or appetite.

    Each substitution replaces an assertion with a fact.

    The FRC has made a related point in SRG 1. In discussing content that obscures sustainability information, the guideline identifies disclosures of interviews, pictures of corporate social responsibility activities, pictures of awards, and appendices that merely reproduce standard requirements as examples of material that can obscure material sustainability information.

    The principle extends beyond those examples. Sustainability disclosures become more useful when assumptions, metrics, judgements, financial effects and progress against targets occupy the space that would otherwise be filled by promotional material, generic narrative or unsupported assertions.

    Ultimately, investors are not being asked to assess commitment. They are being asked to assess performance. Performance is evidenced by data, judgements and financial effects, not adjectives.

    Internal control over sustainability reporting

    SRG 1 paragraph 17 states that Internal Control over Sustainability Reporting (ICSR) must not be interpreted as the same as Internal Control over Financial Reporting (ICFR). Instead, it describes the controls needed to ensure that sustainability information can be trusted, defended, independently verified and assured. Examples include clear ownership of sustainability data by responsible officers, documented methodologies such as greenhouse gas calculations, review and approval of assumptions and estimates, data validation and reconciliation checks, and audit trails with evidence retention.

    A Scope 3 emissions figure has no ledger and no trial balance. The underlying evidence often originates outside the finance function, outside the entity and, in many cases, outside the jurisdiction. The controls that make a financial figure auditable — segregation of duties, reconciliation to control accounts and established approval hierarchies — have no natural equivalent and frequently need to be designed specifically for sustainability reporting.

    The most effective place to build those controls is at the point of data collection. Once source data has been aggregated, adjusted and reported, deficiencies in ownership, methodology, validation or evidence retention become significantly harder to repair.

    The FRC’s timing is instructive. SRG 1 places Internal Control over Sustainability Reporting within the readiness assessment, not within the assurance timetable. By the third stage of the readiness process, entities are expected to submit Internal Control over Sustainability Reporting alongside scenario-analysis models, their Enterprise and Sustainability Risk Management Framework, board approvals and evidence of current financial effects.

    The assurance path is deliberately later. SRG 1 provides for limited assurance in the fourth and fifth years after reporting, excluding Scope 3 emissions, scenario analysis and transition plans. Those items enter limited assurance in the sixth year, with reasonable assurance over all disclosures expected in the seventh year.

    The sequence is logical. Assurance does not create reliable data. It tests the reliability of data that already exists. Controls must therefore precede assurance.

    Data gathered without appropriate controls may prove difficult, costly and, in some circumstances, impracticable to assure retrospectively through systems implemented years later. The risk is particularly acute for Scope 3 emissions, where evidence often resides within suppliers’ systems and may not be retained for future assurance purposes.

    That is why the FRC places Internal Control over Sustainability Reporting in the readiness test rather than the assurance timeline. The Council’s message is implicit but clear: entities should not wait until assurance is required before building the controls that will make assurance possible.

    The dates

    The binding date is not 1 January 2028.

    SRG 1 paragraph 14 establishes a three-stage readiness process measured from the beginning of the reporting period, not from the publication date of the sustainability disclosures.

    First stage: Three months before the beginning of the reporting period. Required submissions include a board resolution approving adoption of the IFRS Sustainability Disclosure Standards, a gap analysis report and an implementation plan. For a 31 December year-end entity, the deadline falls on 30 September 2027. Each submission requires preparation in advance of the board meeting at which it is considered and approved.

    Second stage: Not more than three months after the beginning of the reporting period. Required submissions include IFRS Sustainability Disclosure Policies; identification and application of transitional reliefs; identification and materiality assessment of sustainability-related and climate-related risks and opportunities; evidence of an established governance structure for sustainability reporting; evidence of board approval of the disclosure policies; and evidence of sustainability reporting training for directors, management and preparers delivered by an organisation recognised by the FRC.

    Third stage: Not more than six months after the beginning of the reporting period. Required submissions include evidence of registration of the entity and the sustainability reporting professionals engaged in the reporting process with the FRC; a description of scenario-analysis models; an Enterprise and Sustainability Risk Management Framework with evidence of board approval; a description of cross-industry and industry-specific metrics and targets with evidence of board approval; disclosure of the current financial effect of sustainability-related risks and opportunities; and Internal Control over Sustainability Reporting.

    Four of those submissions require board approval. The roadmap is therefore not primarily a reporting exercise. It is a governance exercise with reporting consequences.

    One point of construction matters for entities without a 31 December year-end. SRG 1 paragraph 18 provides that mandatory reporting applies to accounting periods beginning on or after 1 January 2028. An accounting period that begins in 2027 and ends in 2028 does not fall within the mandatory regime. A company with a 31 March or 30 June year-end therefore enters mandatory reporting later than a 31 December reporter and will have correspondingly later readiness deadlines. The first step in any implementation plan is to establish the entity’s own dates rather than assume someone else’s.

    One further requirement is easily missed. SRG 1 paragraph 15 requires sustainability disclosures to be signed by the member of management responsible for sustainability reporting, together with that individual’s FRC registration number. Paragraph 16 requires entities engaging sustainability professionals or firms for corporate reporting purposes to verify that those professionals are registered with the FRC.

    What to build, and in what order

    Three building blocks cannot be produced in a quarter. Begin with them.

    A scenario analysis that produces a result. A named scenario, stated assumptions, and an outcome that can be evaluated financially, strategically or operationally. The approach must be commensurate with the entity’s circumstances. Seplat’s methodology is not a template for a bank. What its disclosure illustrates is what an outcome looks like.

    A position on paragraph 29(c). Either disclose the amount and percentage of assets vulnerable to climate-related physical risk, or disclose a materiality conclusion explaining why the metric is not presented. Both are complete disclosure outcomes. Silence is neither.

    Internal Control over Sustainability Reporting. Assign a named owner to each significant data stream. Document the methodology supporting each metric, including emission factors and estimation methods. Maintain an assumption register with identified approvers. Retain supporting evidence. The sustainability data collected in 2028 is the sustainability data that will eventually be assured.

    Then two governance actions, one board meeting each.

    Amend the relevant committee’s terms of reference to include sustainability and climate oversight, approve the amendment and disclose it appropriately.

    Place climate-related risk within the enterprise risk register, assign ownership, define escalation arrangements and establish the applicable risk tolerance or appetite.

    And one decision to take deliberately.

    Which transitional reliefs will the entity apply in its first period of application, and when will each relief expire? That decision has disclosure consequences. IFRS S1 paragraph E5 permits climate-only reporting in the first period of application but requires the entity to disclose that the relief has been used. Relief used without disclosure is not a compliant use of relief.

    One item for the next board agenda

    Which of the third-stage readiness submissions does this company possess today, in a form the Financial Reporting Council would accept?

    If answering that question requires more than a page, the gap analysis has already started. The board now has its implementation agenda and, more importantly, its deadline.

    Stransact Chartered Accountants advises boards on governance, risk and compliance. This commentary is based on the 2025 annual and sustainability reports of Access Bank Plc, Fidelity Bank Plc, MTN Nigeria Communications Plc and Seplat Energy Plc, as published by those companies; on IFRS S1 General Requirements for Disclosure of Sustainability-related Financial Information and IFRS S2 Climate-related Disclosures; and on Sustainability Reporting Guideline 1 (SRG 1) in Nigeria (2026). Adoption of the IFRS Sustainability Disclosure Standards is voluntary in Nigeria until accounting periods beginning on or after 1 January 2028. The view expressed on the availability of transitional reliefs is an interpretation and is not a settled position.

  • Reclaiming ICFR: Why Governance Should Not Live in the Audit Shadow

    Reclaiming ICFR: Why Governance Should Not Live in the Audit Shadow

    The introduction of Management’s Assessment of Internal Control over Financial Reporting (ICFR) under the Financial Reporting Council of Nigeria (FRCN) regime represents a fundamental shift in governance accountability. At its core, ICFR is intended to strengthen governance, reinforce management ownership, and enhance the reliability of financial statements signed by those charged with preparing them.

    Yet in practice, a subtle but significant scope creep has emerged.

    Many organisations, often guided by auditors or ICFR consultants, define the scope of management’s ICFR assessment using external audit materiality thresholds and quantitatively driven, trial‑balance logic. What begins as a governance exercise gradually morphs into a compliance‑heavy process that closely resembles a substantive audit without delivering commensurate governance value.

    This trend risks obscuring the true purpose of ICFR.

    Management’s Assessment Is Not an Audit Extension

    The FRCN framework is clear in its separation of responsibilities: ICFR is a management assessment, while the auditor’s role is to attest to management’s assessment—not to own, design, or redefine ICFR.

    Management is responsible for designing, implementing, maintaining, evaluating, and certifying ICFR. The Board and Audit Committee provide oversight and challenge. The external auditor expresses an independent limited assurance conclusion on management’s assessment, without the engagement being positioned or understood as a reasonable assurance audit of internal controls, or being treated as equivalent to one.

    Under the current Nigerian regime, external involvement in ICFR typically takes the form of a negative‑form, limited assurance conclusion, performed as at the reporting date. Evidence depth is scaled to the risk of a material weakness and not to demonstrate consistent operation of controls throughout the period.

    The issue is role clarity: when external assurance considerations are allowed to define management’s ICFR scope by default, the distinction between management assessment and auditor attestation becomes blurred.

    The Assurance Ceiling: More Effort, Same External Messaging

    A critical concept for Boards and executive management is the assurance ceiling.

    Under a limited assurance ICFR model, expanding management’s ICFR scope or increasing testing depth does not change the level of assurance communicated to users. The external conclusion remains limited assurance and continues to be expressed with reference to management’s assessment as at the reporting date.

    Accordingly, where management elects to adopt more granular scoping or deeper testing, this should be a deliberate governance decision grounded in internal risk mitigation or decision‑useful insight rather than driven by an expectation of incremental assurance outcomes.

    This distinction matters because the cost of ICFR should be justified by meaningful risk reduction, not by the volume of testing performed.

    Reframing Materiality: Back to the Primary User (With Discipline)

    ICFR scoping should be guided not by spreadsheets alone, but by the principles in IFRS Practice Statement 2: Making Materiality Judgements.

    PS2 reminds us that information is material only if it could reasonably be expected to influence the decisions of primary users of financial statements. This introduces an essential qualitative dimension to ICFR scoping.

    Management is required to ask a simple but powerful question:

    If a control failure affected this line item, would a rational investor or lender change their assessment of our financial position or performance?

    For many routine, high‑volume, mechanistic balances, the honest answer may be “not likely.” While such balances may be quantitatively significant, they may not be decision‑useful in the same way as judgment‑laden estimates, revenue recognition judgments, tax uncertainties, or complex transactions.

    However, an inspection‑defensible ICFR approach requires management to confront a second, often overlooked question:

    Even if this balance is not decision‑useful in isolation, could control failures in this process lead to accumulated misstatement risk?

    Where management scopes out granular testing based on qualitative materiality, inspection discipline requires explicit evaluation and documentation of:

    1. the risk of accumulation, and
    2. the entity‑level or monitoring controls relied upon to mitigate that risk.

    A top‑down, risk‑based ICFR methodology beginning at the financial‑statement level and cascading to significant accounts and relevant controls supports this judgment while remaining transparent to auditor challenge.

    The Strategic Role of Entity‑Level Controls (ELCs)—With Precision

    A Well‑designed entity‑level controls (ELCs), such as governance oversight and analytical review controls, can provide effective assurance over routine balances. However, defensible reliance on ELCs requires discipline: they must demonstrate sufficient precision, frequency, and documented follow‑up to detect material misstatements on a timely basis.

    This is not an argument for weaker controls. It is an argument for smarter control architecture.

    Where ELCs are precise, well‑documented, and consistently applied, management can legitimately reduce granular testing driven primarily by audit convention rather than risk relevance while remaining fully aligned with a top‑down, risk‑based ICFR approach.

    Re‑centering Management Ownership

    To meet the spirit of the FRCN framework, organisations must move from a compliance‑defensive mindset to a governance‑conscious one. Three practical resets are critical:

    1. Define management’s own ICFR materiality and scoping framework, rather than defaulting to substantive audit thresholds.
    2. Prioritise risk, judgment, and susceptibility to misstatement (including fraud and accumulation risk), not just balance size.
    3. Use ELCs intelligently and only where they demonstrate the precision and evidence required to support inspection‑defensible reliance.

    Conclusion: ICFR as Stewardship, Not Shadow Auditing

    ICFR was never intended to be an extension of the external audit. It is a statement of management stewardship, ownership, and accountability for the integrity of financial reporting.

    Ultimately, ICFR reflects how Boards and executive management discharge their fiduciary responsibility over financial reporting independent of the audit process. By grounding ICFR scoping in IFRS materiality principles and applying a disciplined top‑down, risk‑based methodology, management can focus effort where it truly matters, enhancing decision‑useful reporting for primary users while keeping audit‑driven clutter firmly in check.

    The mandate is clear: reclaim ICFR as a governance tool, not an audit shadow.


    Written by Akeem Taofik – FCA

  • IFRS S1 & S2 in Nigeria: Ready for Mandatory Adoption or Still Operating at a Compliance Level?

    IFRS S1 & S2 in Nigeria: Ready for Mandatory Adoption or Still Operating at a Compliance Level?

    Nigeria did not fail IFRS adoption. But the quality of IFRS reporting has not advanced at the same pace as compliance. IFRS adoption is largely complete, but IFRS maturity may now be the defining risk. The consequences of that gap are now becoming visible. What we have achieved in practice is compliance, while IFRS fundamentally requires judgment. 

    The Promise vs Reality 

    When IFRS was adopted, the expectation was clear: Better reporting should lead to better decisions. 

    More than a decade later, a more fundamental question must now be asked: Have we improved how we report or primarily what we report? The answer to that question matters because it directly shapes our readiness for IFRS S1 and S2. 

    A Simple but Revealing Test 

    Recently, I reviewed the financial statements of 138 out of 146 listed entities on the Nigerian Exchange (NGX) across the Main and Growth Boards. 

    The focus was deliberately narrow:
    Material accounting policies. 

    A consistent and observable pattern emerged: 

    • Extensive use of standardised language across entities 
    • Limited evidence of entity-specific articulation of accounting judgments 
    • In some instances, wording that appeared largely unchanged from pre-IFRS reporting frameworks 

    These are public interest entities, operating under full IFRS for over a decade. 

    Yet: Entity-specific, judgment-driven disclosure yet the core principle of IFRS is still uneven in practice. 

    This level of uniformity is fundamentally inconsistent with a principles-based, entity-specific reporting framework. It suggests that, in many cases, disclosure is being standardised where judgment should be differentiated. 

    This matters beyond compliance and it directly affects how investors interpret the underlying economics of these entities. 

    What This Signals 

    This is not primarily a compliance issue. It reflects a structural reality: IFRS adoption is largely complete. But IFRS maturity may now be uneven and in some areas underdeveloped. 

    This same maturity gap may now represent the central risk for IFRS S1 and S2 

    A Broader Context 

    This pattern is not unique, and similar concerns have been observed globally: 

    • Financial statements often contain significant volumes of information without proportional insight 
    • Disclosure requirements are frequently applied using a checklist mindset rather than a judgment-based approach 
    • Boilerplate disclosures can reduce the clarity and usefulness of financial reporting 

    Now Consider IFRS S1 and S2 

    Nigeria is transitioning toward mandatory sustainability disclosure standards. 

    IFRS S1 and S2 represent a step change in expectations: 

    • Forward-looking information 
    • Integration with strategy 
    • Explicit articulation of risks and opportunities 
    • Linkage to financial performance 

    This is not a routine extension of financial reporting; it is a step change in expectation. It shifts reporting from explaining the past to demonstrating future resilience. In doing so, it brings financial reporting closer to business strategy than ever before. 

    The Key Question 

    Against current reporting practices, the critical question becomes: How prepared are we for disclosures that depend even more heavily on judgment than IFRS financial statements?  

    A Likely Early Outcome 

    If reporting practices do not evolve sufficiently, the early phase will likely exhibit familiar characteristics: 

    • High-level policy statements 
    • General sustainability commitments 
    • Limited quantification or financial linkage 

    In practical terms: 

    There is a strong likelihood that at least in the early stages of transitioning from financial reporting boilerplate to sustainability reporting boilerplate. 

    Why This Risk Exists 

    This is not about intent; it reflects how systems and incentives operate. 

    1. Compliance-Oriented Reporting

    Reporting is often assessed based on: 

    • Completeness 
    • Alignment with standards 

    Less emphasis is placed on: 

    • Decision-usefulness 

    This encourages reporting that meets requirements but not necessarily insight. 

    1. Sensitivity Around Judgment

    IFRS S1 and S2 require: 

    • Assumptions 
    • Estimates 
    • Forward-looking analysis 

    In high-scrutiny environments, entities tend to favor: Conservative and generalised disclosures 

    1. Assurance Focus

    Historically, assurance prioritises whether disclosures are present more than whether disclosures are decision-useful, entity-specific, and reflective of underlying economic realities 

    An Important Shift 

    Market evidence increasingly suggests a changing dynamic: 

    • Investors are placing greater emphasis on understanding sustainability-related risks and opportunities 
    • At the same time, concerns are growing regarding the credibility and consistency of sustainability disclosures 

    The result is a widening credibility gap in sustainability reporting. Reliance without trust is a fragile foundation for capital allocation. This creates a structural tension: Greater reliance on sustainability reporting combined with increased scrutiny of its quality. 

    Nigeria: Progress and Tension 

    Nigeria is making measurable progress: 

    • Advancing IFRS S1 and S2 implementation frameworks 
    • Building institutional capacity 
    • Aligning with global reporting developments 

    However, adoption momentum currently exceeds reporting maturity. This raises a critical question: whether implementation timelines are moving faster than organisational readiness. 

    This creates a fundamental tension: Accelerated adoption alongside evolving disclosure capability 

    So, Are We Ready? 

    Short answer: Not fully, not yet. 

    A complete answer: Readiness will ultimately be defined by how quickly reporting practices evolve beyond compliance toward informed judgment. 

    What Will Define Success 

    This is where leadership and not standards will make the difference. The difference will lie in how organisations respond both strategically and operationally. The differentiator will not be adoption. 

    It will be credibility. Organizations that succeed will demonstrate: 

    1. Clear Linkage to Financial Impact

    Not just: statements of intent, but: explicit articulation of how sustainability risks affect financial performance 

    1. Stronger Governance of Narrative Reporting

    Boards and Audit Committees will need to: 

    • Engage deeply with disclosures 
    • Challenge assumptions 
    • Demand clarity and relevance 
    1. Integration of Reporting

    Sustainability disclosures must: 

    • Connect to financial reporting 
    • Be measurable and auditable 
    • Support decision-making 
    1. Evolution in Assurance

    Assurance frameworks must evolve from: completeness checks, to assessment of relevance, coherence, and consistency.

    Final Thought 

    IFRS delivered important structural improvement. However, disclosure quality has not always advanced at the same pace. IFRS S1 and S2 provide a significant opportunity: Not just to report more but to report more meaningfully. 

    The core risk is no longer non-compliance. It is replicating compliance-driven reporting without sufficient insight. And ultimately: Markets do not reward disclosure alone rather they reward clarity, consistency, and credible, decision-useful, and actionable insights. 


    Written by Akeem Taofik – FCA

  • The Active Neutrality Construct: What Independence Really Demands

    The Active Neutrality Construct: What Independence Really Demands

    In modern governance, independence is often misunderstood as standing back—a polite distance maintained to avoid “interfering” with management. In reality, true governance excellence demands something much harder: Active Neutrality. 

    Active Neutrality reframes independence from detachment to disciplined engagement without ownership, influence without control, courage without bias.

    Risk Intelligence Is a Governance Asset

    Internal Audit does not and should not make commercial or financial decisions; that responsibility rests with management. 

    Active Neutrality recognises, however, that Internal Audit is uniquely positioned to assess whether the organisation’s current risk posture remains aligned with actual exposure, especially as conditions evolve. 

    When Internal Audit uses data to challenge whether current caution (or lack thereof) remains proportionate, it is not directing outcomes; it is enhancing decision context. 

    The distinction between ownership of decisions and transparency of risk is the foundation of Active Neutrality.

    Timing: The Difference Between a Diagnosis and an Autopsy

    Risk insight delivered after a scheduled audit may confirm history.
    Risk insight delivered at the point of decision shapes the future. 

    In highvelocity environments, waiting for predetermined audit cycles means: 

    • behavioral patterns harden, 
    • valuepreserving adjustments are missed, and 
    • remediation becomes a reactive cost rather than a preventive strategy. 

    A perfect autopsy report doesn’t save the patient it only explains the funeral. 

    Active Neutrality requires Internal Audit to engage at the speed of execution, providing timely, data‑driven challenge without assuming managerial authority.

    Independence Through Clarity, Not Distance

    There is a persistent Independence Trap where Internal Audit hesitates to provide realtime insight to “protect” objectivity. This is a misunderstanding of the role. 

    Independence is not a mandate for silence.
    It is a shield that allows the auditor to speak truth to power while the risk is still manageable. 

    Independence is strengthened not weakened when Internal Audit: 

    • grounds challenge in objective data, 
    • avoids ownership of outcomes, and 
    • escalates concerns without waiting for the “proper” quarterly window. 

    The Three Principles of Active Neutrality 

    These ideas crystallise into three practical principles: 

    • Zero Ownership of Decisions: Identifying that an initiative is drifting offtrack is not “managing” it. It is reporting on the health of the asset. 
    • Zero Dilution of Facts: Independence means reporting facts as they are, not as they become comfortable. Filtering insight to preserve relationships weakens governance. 
    • Zero Waiting for the “Window”: If a material risk is crystallising today, waiting for next quarter’s report is a governance failure and not prudence. 

    The Bottom Line for the Board 

    The Board’s oversight is strong when Internal Audit is neutral in judgment, but courageous in timing. 

    An Internal Audit function practising Active Neutrality protects both downside risk and missed opportunity without compromising objectivity. 

    If Internal Audit is staying quiet to “stay independent,” it is not protecting the process; it is hiding from it. 

    A Final Reflection 

    After decades of leading audit teams and managing complex audits, one truth remains: the most valuable independence is not found in the organisational chart. 

    It is found in the willingness to be the first person in the room to say, “This doesn’t look right” long before the formal report is due. 

    Is your Internal Audit team empowered to be that voice? 


    Written by Akeem Taofik – FCA

  • Audit Velocity vs. Business Velocity: The Growing Assurance Gap

    Audit Velocity vs. Business Velocity: The Growing Assurance Gap 

    Most Boards intuitively understand speed.  If the business is moving at 100 mph and Internal Audit is constrained by static annual planning cycles is moving at 20 mph, the Assurance Gap widens every day. 

    This is not a capability issue; it is a velocity mismatch. 

    The Execution Blind Spot 

    Risks that emerge during execution, market shifts, operational shortcuts, or behavioral drift rarely wait for the next formal audit cycle. Yet, these are exactly the risks most likely to bypass assurance entirely. 

    When Internal Audit is tethered to a “point-in-time” plan, they are essentially looking at a map of where the business was, while the business is already driving through new, unmapped territory. 

    The Governance Reality Check 

    In a high-velocity environment: 

    • Accuracy without timeliness does not protect value; it merely explains losses after the fact. 
    • Retrospective assurance provides a perfect autopsy, but the Board needs a diagnosis while the patient is still on the table. 

    The real governance question for modern Boards is no longer: “Was the audit done well?” It is: “Did the insight arrive in time to matter?” 

    The Bottom Line 

    Modern assurance is not about auditing more. It is about auditing at the speed of the business. Governance excellence requires a shift from “periodic validation” to “continuous intelligence.” If your audit function isn’t moving at the speed of your strategy, you aren’t just independent, you’re out of the loop. 

    A Final Reflection

    As a professional who has led audit teams and managed complex statutory audits for decades, I’ve observed a consistent truth: the most valuable “independence” isn’t found in the organizational chart. It is found in the auditor’s willingness to be the first person in the room to say, “This doesn’t look right” long before the formal report is due. 

    Is your Internal Audit team empowered to be that voice? 


    Written by Akeem Taofik – FCA

  • Independence as a Shield, not a Hideout: A Governance Blind Spot for Boards

    Independence as a Shield, not a Hideout: A Governance Blind Spot for Boards

    In many Boardrooms, independence is rightly treated as the ultimate safeguard of Internal Audit.  Yet increasingly, independence is interpreted even within Internal Audit itself as a reason for detachment. 

    When independence becomes a wall that delays engagement with emerging risks until a formal audit cycle begins, it does not strengthen governance. It creates a visibility lag one that Boards should care deeply about. 

    Understanding the Visibility Lag 

    The IIA Global Internal Audit Standards (2024) encourage agile and continuous auditing and explicitly align Internal Audit with enterprise objectives and risk. However, in practice, many Internal Audit functions still operate on rigid annual or semiannual “bigbang” audit plans. 

    What this means is that audit plans often reflect the risks management identified and embedded within enterprise objectives at the point of strategy setting. As execution unfolds, management pivots in real time but Internal Audit remains tethered to a pointintime risk assessment. 

    The consequence is a timing gap: while the business adapts at speed, Internal Audit insight arrives later, bound by planning cycles. This creates a governance blind spot, where the most dangerous risks those that emerge during execution are the least likely to be audited in time. 

    Boards intuitively understand this challenge. If the business is moving at 100 mph and Internal Audit is constrained by planning cycles is moving at 20 mph, the assurance gap widens every day. 

    Objectivity of Judgment ≠ Isolation of Timing 

    Independence exists to protect objectivity of judgment, not to justify a waitandsee posture. A perfect autopsy report doesn’t save the patient; it only explains the funeral. 

    Accuracy without timeliness is a wasted investment. From a governance perspective, assurance that arrives too late may still be technically correct—but strategically irrelevant. 

    Boards should therefore ask a simple but critical question: 

    “Is our Internal Audit function staying silent on emerging risks to protect independence or providing the realtime risk intelligence needed to protect the organisation?” 

    Three Provocations for Audit Committees 

    1. Risk Intelligence Is Not Management Interference

      Identifying an emerging exposure: such as operations scaling ahead of a signed contract is not an operational decision.
      It is risk intelligence. 

    • The trap is viewing proactive signaling as encroachment.
    • The reality is that objectivity is compromised when auditors decide, not when they highlight risk. 
    1. The Danger of “Autopsy” Governance

      When Internal Audit limits itself to postevent validation, Boards are left with explanations rather than protection. A perfect autopsy report doesn’t save the patient, rather it only explains the funeral. 

    In highvelocity environments, assurance that arrives months after risk emerges may be technically correct, but strategically irrelevant. 

    • The provocation for Boards is simple:
      “Do we value retrospective accuracy more than independent foresight?” 
    1. Reframing the Mandate

      Independence should be the shield that allows Internal Audit to:

    • speak truth to power in real time, 
    • challenge management assumptions before they harden into failures, 
    • escalate concerns without hiding behind the “proper” quarterly window, and 
    • practice active neutrality: independence is not passive neutrality; it is the fearless, factual reporting of risks as they develop. 

    The Bottom Line 

    Independence should be a shield, not a hideout.  An Internal Audit function that waits until risk manifests may remain independent in form
    but risks becoming irrelevant in substance.

    True governance excellence requires Internal Audit to be independent in mind but integrated in timing.


    Written by Akeem Taofik – FCA

  • Section 57 Compliance in Nigeria: Key Governance Risks Every Subsidiary Must Address

    Section 57 Compliance in Nigeria: Key Governance Risks Every Subsidiary Must Address

    If you run a Nigerian subsidiary of a multinational and still think Section 57 of Nigeria’s updated corporate tax regime is just “one more calculation,” you’re already behind. Yes, Section 57 introduces a 15% minimum effective tax rate (ETR), neutralizing the benefit of incentives where they depress tax outcomes below the threshold. But the arithmetic is not the real story.

    Section 57 is a governance signal

    It marks the end of an era where local tax outcomes could be exceptional, lightly governed, and explained after the numbers were already consolidated.

    The Comfort That Is Now Gone

    For years, many Nigerian subsidiaries operated with quiet confidence. Incentives justified low ETRs. Group headquarters accepted Nigeria as a “special case.” Where questions arose, explanations typically came after the numbers were final.

     Section 57 disrupts that comfort

    It now asks a tougher question, one that cannot be deferred: Can Nigeria’s tax outcome be clearly and credibly defended to Group Tax and the Audit Committee without relying on technical footnotes?

    If the answer is no, the challenge is not tax complexity.

    Why This Is a GRC Issue (Before It’s a Tax One)

    From a Governance, Risk, and Compliance (GRC) perspective, Section 57 is not a tax rule; it is a stress test for control maturity, particularly Internal Control over Financial Reporting (ICFR).

    Why?

    The minimum tax threshold anchors directly to Profit Before Tax (PBT) as reported in audited financial statements. Once that linkage exists, tax is no longer a downstream calculation. It becomes a direct reflection of how disciplined or fragile the financial close process really is.

    In practice:

    • Weak controls become earnings risk: Volatile PBT caused by late adjustments, weak accrual discipline, inconsistent judgments, or provisioning gaps now creates immediate fiscal and reputational exposure.

    • Tax risk moves upstream: Tax outcomes are no longer “managed” after close. They are shaped by how well financial reporting is governed in real time.

    • ICFR maturity is exposed: Where tax has been treated as a compliance appendix rather than a governed outcome, Section 57 makes the deficiency visible.

    This is how good regulation works. It reveals institutional weaknesses without prescribing the fix.

    Audit Friction Is No Longer Tolerated

    Historically, tax incentives could often survive scrutiny through post‑hoc explanations. In the Section 57 environment, credibility is defined by the audit trail.

    Incentives that are not:

    • clearly owned,

    • embedded in control design, and

    • supported by inspectable evidence

    will struggle under Group‑level review or external audit scrutiny.

    Persistent “audit friction” is no longer an irritation. It is a governance signal.

    The Strategic Shift: From Compliance to Control

    High‑maturity organisations are already pivoting. The change is subtle but decisive:

    From: “Nigeria is compliant because our incentives are legal.”

    To: “Nigeria is controlled because its ETR is deliberate, monitored, and explainable.”

    This shift must happen before consolidation, not as a reconciliation exercise after Group questions arise. In a multinational environment, unexplained local volatility is not a local issue, it is an enterprise risk.

    The Question That Now Defines Credibility

    For CFOs and GRC leaders, the defining question has changed:

    If Group Tax or the Audit Committee asked today, ‘Why is Nigeria’s ETR what it is?’ would the response be a spreadsheet model or a governance framework embedded in ICFR?

    One signals calculation, the other signals control.

    Final Thought

    Section 57 is not asking Nigerian subsidiaries to be perfect, it is asking them to be credible.

    Credibility does not come from technical explanations delivered after consolidation. It comes from discipline, alignment, and governance maturity.

    If Nigeria is still being explained after the fact rather than positioned deliberately within the Group’s governance architecture, Section 57 isn’t the problem.

    Your GRC maturity is.


    Written by Akeem Taofik – FCA

  • When Discomfort Signals the Need for Governance Reassessment

    When Discomfort Signals the Need for Governance Reassessment

    In governance, discomfort is not always a warning sign it can be a signal worth listening to. As ICFR assurance becomes more established in Nigeria, some Boards and CFOs experience a persistent unease not because anything is demonstrably wrong, but because something no longer sits comfortably. The scope feels heavier than expected. The effort feels closer to reasonable assurance than limited assurance. The logic between work performed and conclusions reported feels less tidy than before.

    In governance, that discomfort deserves attention.

    Discomfort Often Emerges Before Failure

    A well‑functioning governance systems rarely fail without warning. More often, signals appear early in the form of questions that linger, costs that are harder to explain, or execution patterns that no longer align intuitively with first principles.

    In the context of ICFR assurance, discomfort may surface when:

    • Execution effort materially exceeds what the assurance conclusion can support.
    • scope expands incrementally without explicit Board discussion; or
    • Management can no longer clearly articulate why additional procedures are being performed, beyond precedent.

    These moments are not indicators of non‑compliance. They are indicators of governance tension.

    When Discomfort Points to a Loss of Intentionality

    Discomfort is particularly instructive when it reveals that:

    • a Board did not consciously choose the current assurance depth.
    • methodology has evolved through repetition rather than decision; or
    • The assurance model being experienced no longer reflects the one originally approved.

    In such cases, unease is not resistance, it is a signal that intentional ownership may have eroded.

    Governance strength lies not in eliminating discomfort, but in understanding what it is reacting to.

    Discomfort Is an Invitation, not a Verdict

    Importantly, feeling uneasy does not compel immediate change.

    It invites examination:

    • Is the current ICFR execution still proportionate to our risk profile?
    • Does the incremental work provide comfort we genuinely value?
    • Are we implicitly moving toward a reasonable‑assurance posture without naming it?
    • If circumstances changed, could we confidently recalibrate scope?

    When Boards can engage these questions openly, discomfort becomes productive rather than destabilising.

    The Risk of Ignoring Discomfort

    Where discomfort is consistently deferred, two governance risks emerge:

    • drift, where practice gradually moves beyond intent without accountability; and
    • inertia, where future change becomes harder because the status quo hardens into perceived necessity.

    Over time, what was once a mild unease can evolve into rigidity precisely the opposite of good governance.

    A Discipline Worth Developing

    Just as comfort can be a governance outcome when consciously chosen, discomfort can be a governance asset when properly interpreted.

    It encourages Boards and Audit Committees to:

    • revisit first principles without presuming error.
    • distinguish between regulatory requirement and inherited practice; and
    • maintain agency over assurance models, rather than inheriting them passively.

    In this sense, discomfort is not a call to disrupt but a call to reengage.

    Closing Reflection

    ICFR assurance will continue to mature. For some Boards, that journey will feel settled. For others, it will surface questions that resist easy answers.

    When discomfort arises, the objective is not to resolve it quickly, but to understand it thoroughly. In that understanding lies the capacity to decide consciously, proportionately, and with confidence whether the present course still serves the organisation’s governance intent.

    Discomfort, well‑handled, is not a threat to governance.


    Written by Akeem Taofik – FCA