Sections & item catalogue
AI Governance Framework — 16 items
Section titled “AI Governance Framework — 16 items”Assesses the organisation’s AI governance mandate, accountability, policy, inventory, roles, risk and impact governance, incidents, internal challenge, reporting and legal-change control.
Ask whether governance can stop or change a deployment, not only whether a committee exists.
NDPC Data Protection Compliance for AI — 20 items
Section titled “NDPC Data Protection Compliance for AI — 20 items”Assesses relevant NDPA and NDPC requirements, including lawful basis, transparency, data-subject rights, automated decisions, children, data-protection impact, security, processors, transfers, breach routes, registration or audit obligations, identity and biometric context.
Do not assume that the original collection basis automatically covers a new AI use.
Responsible and Ethical AI — 19 items
Section titled “Responsible and Ethical AI — 19 items”Assesses:
- Fairness and non-discrimination.
- Accessible transparency and explanations.
- Privacy and data ethics.
- Human-centred design.
- Disability inclusion.
- Nigerian language and cultural performance.
- Ethics governance.
- Workforce and community impact.
- Environmental and sustainability concerns.
- Synthetic content, copyright, election and online-harm routes.
Measure impact across relevant Nigerian populations and languages rather than relying only on an aggregate metric.
AI Adoption and Sector Compliance — 15 items
Section titled “AI Adoption and Sector Compliance — 15 items”Assesses responsible adoption, lifecycle controls, procurement, public-sector deployment, cross-sector legal duties, incident and critical-infrastructure readiness, and route gateways for regulated activity.
This section connects a broad use case to the exact atomic duties in other sections.
Sector-Specific AI Obligations — 24 items
Section titled “Sector-Specific AI Obligations — 24 items”Assesses conditional obligations and governance for:
- CBN-regulated finance, credit, payments and open banking.
- Insurance.
- Pensions.
- Capital markets and robo-advice.
- Telecommunications.
- Healthcare, health insurance and medical software.
- Aviation and RPAS.
- Consumer-facing and digital-lending activity.
- Digital identity and critical services.
Sector items apply only after actor, licence, activity, product and AI function are established.
AI Infrastructure Readiness — 6 items
Section titled “AI Infrastructure Readiness — 6 items”Assesses infrastructure availability, resilience, cloud and data dependencies, cybersecurity, capacity and sustainability. Readiness items support reliable and sovereign decision-making but should not be presented as enacted AI-specific obligations unless anchored to a current rule.
AI Ecosystem and Talent — 8 items
Section titled “AI Ecosystem and Talent — 8 items”Assesses competence, local research and innovation, skills, inclusion, local language capability, partnership and ecosystem development. These are important national and organisational readiness themes, distinct from current-law compliance.
Using the catalogue
Section titled “Using the catalogue”Each item provides:
- Source and status.
- Legal or policy proposition.
- Auditor advisory.
- Evidence to inspect.
- Bounded audit test.
- Decision rule.
- Implementation guidance.
- Cross-framework references where relevant.
Read the item advisory before selecting a result. It is designed to let the assessor complete most of the work from the assessment screen while still opening the cited primary source for legal verification.
Catalogue cautions
Section titled “Catalogue cautions”- A section total does not indicate legal weight.
- Policy and current law can sit in the same section but remain status-labelled.
- A gateway is not proof of downstream compliance.
- One item may have several sources.
- Crosswalks provide traceability, not equivalence.
- Legal status must be checked at the assessment date.