Nigerian compliance firm Smartcomply will demo its Compliance Exposure Score and full product stack at GITEX Nigeria 2026 after selection for the ONDI-NITDA startup delegation, as overlapping cyber, AML and data rules turn continuous digital trust into a practical growth requirement for African businesses.
The Startup Festival runs at Landmark Centre in Lagos on September 2-3 inside the wider event that opens in Abuja on August 31. More than 1,000 startups and global tech firms are expected. Founder and CEO Gbemisola Osunrinde frames the moment simply: businesses now ask whether they can trust systems, people, partners and counterparties, not only what forms go to a regulator.
Smartcomply Brings Its Full Stack to GITEX Nigeria
Smartcomply, founded in 2021 and headquartered in Lagos with offices across Africa, the UK and the US, combines compliance, risk, cybersecurity and fraud tools in one ecosystem. At the festival it will put the Compliance Exposure Score front and centre. The rapid assessment tool scores readiness across governance, third-party risk, technical security and workforce preparedness so teams see exposure without waiting for an annual audit or a breach.
The four pillars give buyers a shared language before they open any module:
- Governance readiness across policies, ownership and control design.
- Third-party risk exposure from vendors, partners and counterparties.
- Technical security posture against live threats and control gaps.
- Workforce preparedness through training and human-factor coverage.
Alongside it sit the wider platforms:
- Adhere for AI-powered AML, KYC/CDD, sanctions/PEP screening, transaction monitoring and regulatory reporting, already integrated with BVN and NIN.
- Seequre (recently rebranded from Smartcomply Secure) for GRC and cybersecurity automation.
- Oculus for continuous threat intelligence and brand/domain protection.
- Smartcomply Academy for workforce security training.
The company says its platforms already support more than 100 financial institutions and regulated businesses across Africa. Adhere alone monitors more than $1 billion in monthly transactions and has cut manual compliance workloads by about 70 percent while reducing false-positive fraud alerts by 40 percent for customers. The full Smartcomply product ecosystem and platforms will be on show to investors, enterprise buyers and officials.
That mix of score-first entry and stacked modules is meant to let a bank, fintech or remittance firm start with a quick exposure read, then switch on the controls that close the largest gaps first rather than buying a full suite on day one.
CBN Rules Turn Compliance Into a Survival Clock
The timing is not accidental. On March 10, 2026 the Central Bank of Nigeria issued circular BSD/DIR/PUB/LAB/019/002 setting Baseline Standards for Automated Anti-Money Laundering Solutions. Banks, mobile-money operators, international money-transfer operators and other financial institutions must deploy systems covering 12 minimum categories. Deposit money banks have 18 months for full compliance; other institutions have 24 months. Implementation roadmaps were due within three months of the circular.
Adhere already maps to those requirements. Osunrinde said the platform was built for exactly the African regulatory environment the CBN is now mandating, including real-time monitoring with behavioural patterns, automated KYC linked to national IDs, sanctions screening, case management with maker-checker controls, and automated STR/CTR/FTR reporting.
| Requirement area | Timeline or detail |
|---|---|
| Circular issuance | 10 March 2026 |
| Roadmap submission | Within 3 months |
| Full compliance (DMBs) | 18 months |
| Full compliance (other FIs) | 24 months |
| Core categories covered | 12 minimum standards including monitoring, KYC, sanctions, case management, reporting |
The staggered clocks matter in practice. Roadmaps had to land first, then deposit money banks face the shorter 18-month runway while other financial institutions get 24 months. Institutions that treat the three-month roadmap window as paperwork rather than a build plan will compress delivery into the back half of the deadline.
The CBN baseline standards for automated AML sit alongside tighter data-protection and cybersecurity expectations. Seventeen CBN actions in fourteen months have carried hard deadlines. A ₦15.42 billion fine on a major bank in 2025 showed non-compliance now threatens correspondent banking relationships, not only local balance sheets.
The Tools Behind the Compliance Exposure Score
The Score itself is positioned as the entry point. Organisations get a fast read on four pillars rather than a thick consultant report months later. That continuous view is the company’s core claim: measure and manage exposure in real time instead of discovering gaps at audit time or after a breach.
Seequre handles the governance and control layer. Oculus watches external threats and dark-web signals. Academy closes the people gap that Nigerian institutions repeatedly cite. The stack is sold as purpose-built for African data realities and identity rails rather than a global product retrofitted after the fact. Earlier in 2026 Smartcomply joined the Mastercard Engage Partner Program as a verified technology provider and became an Associate Participating Organisation of the PCI Security Standards Council, one of the first African compliance tech firms with a formal seat at that table.
BVN and NIN integration inside Adhere is part of that local design choice. Automated KYC linked to national IDs, behavioural transaction monitoring and maker-checker case controls are framed as answers to the same 12 minimum categories the CBN listed, not as optional extras bolted on for a single market tour.
Fraud Losses Fell but Attacks Got Costlier
Reported digital payment fraud losses in Nigeria dropped more than 50 percent to ₦25.85 billion in 2025 from ₦52.26 billion in 2024, according to the Compliance Reckoning report co-produced by Adhere and TechCabal. Yet losses remain roughly 350 percent higher than 2020 levels even as case numbers fell about 31 percent. Attacks are fewer, more targeted and more expensive per incident. AI-enhanced fraud is estimated 4.5 times more profitable than traditional methods. Globally, financial fraud reached an estimated $442 billion in 2025.
Nigeria processes more than 10 billion real-time transactions a year yet ranks 110th of 112 countries for fraud protection and faces a cybersecurity workforce gap near 90 percent. Check Point data put average weekly cyberattack attempts on Nigerian organisations at 4,361 in June 2026, second in Africa only to South Africa. Kaspersky recorded 1.6 million web-based attack attempts on Nigerian users in the first half of the year.
- ₦25.85 billion digital payment fraud losses in 2025 (down from ₦52.26 billion)
- ~350 percent rise in losses since 2020 despite fewer reported cases
- 4,361 average weekly cyberattack attempts on Nigerian organisations (June 2026)
- ~90 percent cybersecurity workforce gap
That pattern of falling headline numbers masking higher per-incident cost is exactly the dynamic tracked in Nigeria fraud losses masking costlier threats. The report’s warning is blunt: when reporting drops faster than fraud, risk leaves the record rather than the system. Architecture, not just tools, will decide which institutions survive the next eighteen months.
A market that clears more than 10 billion real-time transactions a year while ranking near the bottom of fraud-protection league tables is structurally exposed. Fewer cases with higher average loss and AI methods estimated 4.5 times more profitable than older ones push institutions toward continuous detection rather than periodic review.
Banks and Fintechs Face the Same Exposure Gap
The pressure hits deposit-money banks, mobile-money operators, international money-transfer operators, payment-service providers and licensed fintechs equally. Overlapping obligations now cover data protection (NDPA/NDPR), AML/CFT, KYC, cybersecurity frameworks and third-party risk. For companies trying to scale remote onboarding, cross-border corridors or new product lines, control quality can matter as much as capital or customer acquisition.
The same institution can face all of these at once:
- Data protection under NDPA/NDPR
- AML/CFT programme duties
- KYC and customer due diligence
- Cybersecurity framework controls
- Third-party and vendor risk oversight
UK remittances to Sub-Saharan Africa exceed £4 billion a year while average send costs remain about 8.5 percent, more than double the UN SDG target of 3 percent. Smartcomply’s UK registration and Adhere launch target exactly those corridors, giving British institutions local African data understanding instead of generic global screens. The company is already in discovery talks with UK electronic-money institutions and remittance firms.
Smaller institutions and newer fintechs feel the resource pinch hardest. Many still run policy documents without live systems that enforce them. Auditors and regulators increasingly want evidence of continuous monitoring, explainable alerts and model governance rather than annual attestations.
From Lagos Roots to PCI and UK Corridors
The company’s path tracks the same pressures it now sells against.
- 2021 Smartcomply founded in Lagos.
- 2023-2025 Product suite expands; presence grows in Kenya, Ghana and the US; earlier leadership roles at related cyber firms feed into the group.
- Early 2026 Joins Mastercard Engage Partner Program.
- May 2026 Registers in the UK and launches Adhere for African payment corridors; reports $1 billion+ monthly monitoring volume and the 70/40 efficiency metrics.
- June 2026 Admitted as Associate Participating Organisation of the PCI Security Standards Council.
- July 2026 Hosts Adhere Compliance Frontline Forum in Lagos and releases the Compliance Reckoning report with TechCabal.
- August 2026 Selected via ONDI-NITDA for GITEX Nigeria Startup Festival; Seequre rebrand finalised for standalone GRC/cyber focus.
Serving more than 100 institutions and expanding into Francophone markets remains the stated direction. PCI membership gives an African voice inside global payment-security standard setting. The UK beachhead puts corridor intelligence next to the banks that move the money.
Correspondent Relationships Raise the Stakes Fast
Local fines are only one side of the ledger. The ₦15.42 billion penalty on a major bank in 2025 underlined that weak controls can endanger correspondent banking ties, not merely draw a domestic sanction. Once overseas partners doubt monitoring quality, payment rails and settlement access come under review.
That is why the CBN’s twelve minimum categories and the shorter clock for deposit money banks land as survival issues. Real-time monitoring, sanctions screening, maker-checker case handling and automated regulatory reporting are the evidence correspondent banks increasingly expect to see working, not promised in a policy binder.
Smartcomply’s bet on African identity rails and UK corridor coverage is aimed at that trust gap. Institutions that can show continuous controls across AML, cyber and third-party risk are better placed to keep both regulators and foreign banking partners aligned while they grow transaction volume.
Why the Eighteen-Month Window Favours Early Movers
Osunrinde has argued that compliance teams are already evaluating platforms and that the fastest movers will choose systems built for African standards rather than retrofits. The calendar backs that view. Roadmaps were due within three months of the March 2026 circular. Full compliance then lands at 18 months for deposit money banks and 24 months for other financial institutions.
| Institution type | Full compliance window |
|---|---|
| Deposit money banks | 18 months from the circular |
| Other financial institutions | 24 months from the circular |
Teams that wait for a breach, a fine or an audit finding will spend the remaining months under forced delivery. Teams that score exposure now can sequence Adhere, Seequre, Oculus and Academy against the gaps that matter most before the hard stop arrives.
The Compliance Reckoning report’s line on architecture deciding the next stretch fits the same clock. Falling reported fraud alongside costlier, more targeted attacks leaves little room for annual-cycle compliance models once the baseline standards bind.
Continuous Measurement Replaces the Audit Wait
Osunrinde’s public line has stayed consistent across the year’s announcements. At the CBN alignment moment she said compliance teams are evaluating platforms right now and that the fastest movers will pick systems built for African standards rather than retrofits. At the Frontline Forum she noted the fall in reported fraud is welcome but also a warning, and that the next stretch will be decided by architecture.
Businesses are no longer asking only what they need to submit to a regulator. They are asking whether they can trust their systems, their people, their partners and the businesses they transact with.
Gbemisola Osunrinde, CEO, Smartcomply, BusinessDay
GITEX Nigeria itself is positioned as West Africa’s large-scale tech and startup connector, with a Government Leadership & AI Summit in Abuja and the Tech Expo plus Startup Festival in Lagos. Official materials list more than 200 investors managing $200 billion in assets under management and facilitated meetings across 30-plus countries. The GITEX Nigeria Startup Festival dates and venues put Smartcomply in front of exactly the capital, enterprise and government audiences that can accelerate or stall African digital expansion.
The company’s bet is straightforward. Organisations that can score and manage exposure continuously will clear the new regulatory clocks and keep correspondent relationships and customer trust. Those that wait for the next audit, the next fine or the next successful AI-driven attack will find growth itself blocked. The Lagos demo floor in early September is simply the public stage for that shift.








