Skip to content

Sections & item catalogue

Assesses the organisation’s AI governance mandate, accountability, policy, inventory, roles, risk and impact governance, incidents, internal challenge, reporting and legal-change control.

Ask whether governance can stop or change a deployment, not only whether a committee exists.

NDPC Data Protection Compliance for AI — 20 items

Section titled “NDPC Data Protection Compliance for AI — 20 items”

Assesses relevant NDPA and NDPC requirements, including lawful basis, transparency, data-subject rights, automated decisions, children, data-protection impact, security, processors, transfers, breach routes, registration or audit obligations, identity and biometric context.

Do not assume that the original collection basis automatically covers a new AI use.

Assesses:

  • Fairness and non-discrimination.
  • Accessible transparency and explanations.
  • Privacy and data ethics.
  • Human-centred design.
  • Disability inclusion.
  • Nigerian language and cultural performance.
  • Ethics governance.
  • Workforce and community impact.
  • Environmental and sustainability concerns.
  • Synthetic content, copyright, election and online-harm routes.

Measure impact across relevant Nigerian populations and languages rather than relying only on an aggregate metric.

AI Adoption and Sector Compliance — 15 items

Section titled “AI Adoption and Sector Compliance — 15 items”

Assesses responsible adoption, lifecycle controls, procurement, public-sector deployment, cross-sector legal duties, incident and critical-infrastructure readiness, and route gateways for regulated activity.

This section connects a broad use case to the exact atomic duties in other sections.

Sector-Specific AI Obligations — 24 items

Section titled “Sector-Specific AI Obligations — 24 items”

Assesses conditional obligations and governance for:

  • CBN-regulated finance, credit, payments and open banking.
  • Insurance.
  • Pensions.
  • Capital markets and robo-advice.
  • Telecommunications.
  • Healthcare, health insurance and medical software.
  • Aviation and RPAS.
  • Consumer-facing and digital-lending activity.
  • Digital identity and critical services.

Sector items apply only after actor, licence, activity, product and AI function are established.

Assesses infrastructure availability, resilience, cloud and data dependencies, cybersecurity, capacity and sustainability. Readiness items support reliable and sovereign decision-making but should not be presented as enacted AI-specific obligations unless anchored to a current rule.

Assesses competence, local research and innovation, skills, inclusion, local language capability, partnership and ecosystem development. These are important national and organisational readiness themes, distinct from current-law compliance.

Each item provides:

  • Source and status.
  • Legal or policy proposition.
  • Auditor advisory.
  • Evidence to inspect.
  • Bounded audit test.
  • Decision rule.
  • Implementation guidance.
  • Cross-framework references where relevant.

Read the item advisory before selecting a result. It is designed to let the assessor complete most of the work from the assessment screen while still opening the cited primary source for legal verification.

  • A section total does not indicate legal weight.
  • Policy and current law can sit in the same section but remain status-labelled.
  • A gateway is not proof of downstream compliance.
  • One item may have several sources.
  • Crosswalks provide traceability, not equivalence.
  • Legal status must be checked at the assessment date.