Nigeria’s banks have largely completed the localisation of their payment transaction data ahead of the Central Bank of Nigeria’s (CBN) January 2027 deadline, but fintech companies, digital banks and other financial institutions that still host data overseas are racing against time to comply, according to Krishnan Ranganath, chief executive officer of UniCloud Africa.
- +Banks ready, fintechs lag as Nigeria’s 2027 data localisation deadline nears
- +Banks ahead, fintechs face tougher transition
- +Existing contracts slowing migration
- +Hidden risks beyond compliance
In an interview with BusinessDay, Ranganath said while the CBN’s directive has strengthened interest in local cloud infrastructure, the industry remains in the early stages of implementation as many financial institutions continue to evaluate migration strategies, infrastructure readiness, cybersecurity risks and compliance with the Nigeria Data Protection Act (NDPA).
In an interview with BusinessDay, Ranganath said while the CBN’s directive has strengthened interest in local cloud infrastructure, the industry remains in the early stages of implementation as many financial institutions continue to evaluate migration strategies, infrastructure readiness, cybersecurity risks and compliance with the Nigeria Data Protection Act (NDPA).
“It is still a bit premature. This has been on the cards for some time and is essential not only because of the CBN directive but also in line with NDPA requirements. Many financial services institutions are still weighing their options and assessing the risks and implications,” Ranganath stated.
He said the discussions have yet to translate into major contract awards for cloud providers, adding that, “It is too early to talk about signed contracts. We are still giving potential clients clarity on our infrastructure, data handling processes and NDPA compliance.”
The CBN’s directive requires all payment transaction data generated by regulated institutions to be domiciled in Nigeria by January 2027. The policy is designed to strengthen regulatory oversight, improve data sovereignty and reduce dependence on foreign jurisdictions for critical financial information. It also aligns with Nigeria’s broader push to build domestic digital infrastructure and retain more value from its rapidly expanding digital economy.
Banks ahead, fintechs face tougher transition
According to Ranganath, most Tier-1 and Tier-2 commercial banks have already localized their transaction data, making fintech companies, digital banks and other financial institutions hosting workloads abroad the primary focus of the ongoing migration.
“As I understand it, the majority of Tier-1 and Tier-2 banks have already localized their data. The area to watch is fintechs and new generation banks who are still hosting data abroad,” he affirmed.
Whether every institution can comply before January 2027 remains uncertain, Ranganath said, even as he affirmed that, “This is a CBN directive, so compliance is expected. Some leniency or an extension may be possible, but that should come only after substantial progress has been made.”
Beyond regulation, Ranganath described data localisation as an issue of national security, arguing that payment data has become strategic national infrastructure that should remain within Nigeria’s borders.
Existing contracts slowing migration
While the policy has broad industry support, Ranganath said institutions are quietly grappling with challenges that are not widely discussed publicly.
Many fintech firms have existing long-term agreements with international cloud providers such as Amazon Web Services and Microsoft Azure, making migration expensive and operationally complex.
“There are existing contracts, so moving comes with real financial implications,” he said.
Another challenge is confidence in local infrastructure, Ranganath posited, stating that, “There is also a major trust factor. Institutions want assurance around infrastructure resilience and cybersecurity.”
Although few industry players are willing to criticize the directive publicly, Ranganath said many privately believe the six-month implementation window is extremely ambitious.
“The directive raises important questions around infrastructure readiness, disaster recovery capabilities, migration complexity and long-term financial implications,” he said.
Despite concerns over the timeline, Ranganath believes Nigeria already has sufficient infrastructure to accommodate the migration.
The CBN circular requires 100 percent of payment transaction data to be domiciled locally. Based on industry estimates, the resulting demand could range from 14 megawatts (MW) under a conservative scenario to 24MW in a base case and as much as 30MW under a high-growth scenario.
According to him, Nigeria’s existing commercial data centres already have approximately 20MW of available IT capacity, with an additional 15MW to 20MW capable of being fitted out within existing facilities as demand increases.
“Existing data centres can handle these capacities,” he said.
The figures suggest that infrastructure capacity itself may not be the biggest obstacle. Rather, the challenge lies in executing large-scale migrations without disrupting critical payment services.
Hidden risks beyond compliance
Ranganath warned that the industry’s biggest challenge is whether institutions can migrate safely without weakening the resilience of Nigeria’s financial system.
He said disaster recovery remains one of the most underestimated risks.
According to him, many institutions may establish secondary data centres simply to satisfy regulatory requirements without conducting rigorous failover testing under peak transaction loads.
“There is a big difference between saying you have a disaster recovery site and proving it can support three times your peak transaction volume,” he said.
Power reliability is another concern.
Unlike many countries that have introduced localisation policies, Nigeria still struggles with electricity supply. Although Tier III and Tier IV facilities mitigate this through redundant systems and captive gas or renewable power generation, Ranganath warned that some institutions may opt for lower-cost facilities simply to meet the deadline.
He also identified a shortage of skilled personnel as another emerging risk.
Moving from global cloud platforms to locally managed infrastructure transfers responsibility for patch management, cybersecurity monitoring, incident response and system scaling to Nigerian technical teams.
“If those teams have never managed infrastructure at that scale before, the biggest risk is not the migration itself but what happens months after migration,” he said.
Cybersecurity risks are also likely to increase during the transition period.
Migration often requires organisations to run old and new environments simultaneously while granting temporary access to vendors handling the transition.
Historically, Ranganath noted, this temporary operating environment is when cyber breaches are most likely to occur.
Another overlooked challenge is vendor concentration risk.
If only a handful of local infrastructure providers are responsible for migrating most of the financial industry’s systems, operational failures or capacity constraints at one provider could have ripple effects across multiple financial institutions.
