Close-up of Scrabble tiles spelling 'data breach' on a blurred background
CORPORATE GOVERNANCE RISK AND COMPLIANCE (GRC)

CORPORATE GOVERNANCE, RISK AND COMPLIANCE (GRC)

CORPORATE GOVERNANCE, RISK AND COMPLIANCE (GRC)

Introduction

In today’s complex and rapidly evolving business environment, organizations face an increasing array of risks—regulatory compliance, financial volatility, cybersecurity threats, supply chain disruptions, and environmental challenges . To effectively navigate these dynamic conditions, it is essential to establish an integrated approach to governance, risk management, and compliance.

Governance, Risk, and Compliance (GRC) is a structured approach that aligns an organization’s governance structures, risk management processes, and compliance obligations into a unified framework . A GRC strategy helps teams work from the same playbook, so decisions are easier to coordinate and follow-up does not disappear between functions . This comprehensive guide examines the principles and practices of GRC for Nigerian businesses, covering the regulatory framework, enterprise risk management, internal controls, and practical steps for building an effective GRC program.

Wooden letter tiles forming the word 'COMPLIANCE' on a rustic wooden background.

The Pain Points: Why GRC Matters Now More Than Ever

The Disconnected Systems Problem

Many organizations struggle with GRC because teams are not sure who owns the work or how to manage it consistently. Spreadsheets, inboxes, and separate tools make it harder to trust reporting . Common obstacles include unclear ownership (teams may assume someone else is responsible for a risk, policy, or control), disconnected systems, changing requirements, and low employee awareness .

The Governance Failure Risk

Firms that experienced governance-related crises underperformed their sectors by around 35 percent on average . Only 37% of directors say their board has a strong understanding of its organisation’s crisis management framework, highlighting persistent weaknesses in preparedness, oversight, and decision-making under pressure . Nigeria’s intensifying regulatory regime is bringing heightened scrutiny to boards of directors .

The Compliance Burden

Organizations face an increasing complexity of risks—including regulatory compliance, financial volatility, cybersecurity threats, supply chain disruptions, and environmental challenges . GRC programs can be difficult to start when teams are not sure who owns the work or how to manage it consistently .

The Internal Control Gap

Weak internal controls expose organizations to fraud, errors, and inefficiencies. Without proper controls over cash, procurement, inventory, and IT systems, businesses risk financial loss and reputational damage .

The Regulatory Framework for GRC in Nigeria

Companies and Allied Matters Act (CAMA) 2020

CAMA 2020 provides the statutory foundation for corporate governance in Nigeria. Key requirements include:

Board Composition: Public companies must have at least three independent directors . The independence criteria under CAMA include that the director does not have direct or indirect ownership interest exceeding 30% in the company, has not dealt with the company in sums exceeding N20 million, and has never been an auditor of the Company .

Director Rotation: Every public company must retire at least one-third of its board at each AGM. The directors who have served longest since their last election go first. This is mandatory—not a best practice suggestion .

Nigerian Code of Corporate Governance (NCCG) 2018

The NCCG provides stricter governance requirements than CAMA. Key provisions include:

INED Tenure: Independent Non-Executive Directors in public companies should serve no longer than three terms of three years each. After nine years, independence is no longer presumed .

INED Independence Criteria: The NCCG has a “much stricter independence requirement” including that the director does not own more than 0.01% of the paid-up share capital, has not been employed by the company within the last five years, is not closely related to any of the company’s directors or substantial shareholders, and has not had a material business relationship with the company in the last five years .

Board Evaluation: The board should conduct annual evaluations of its performance, as well as that of its committees, the chair, and each individual director .

Sector-Specific Codes

Industry-specific corporate governance codes apply to regulated sectors:

  • CBN Code: For banks and financial holding companies, NEDs cap at 12 years, and MDs/Executive Directors at 10 years. A former MD cannot become Chairman of the same bank without a 3-year cooling-off period 

  • PENCOM: For pension fund operators, specific governance requirements including board evaluation, induction programs, and corporate governance evaluation reports 

Enterprise Risk Management (ERM)

What Is ERM?

Enterprise Risk Management is a structured, systematic, and integrated approach to identifying, assessing, mitigating, monitoring, and reporting risks across all organizational functions . This practice is essential for ensuring that risk management contributes meaningfully to value creation and protection, strategic alignment, and enhanced operational resilience .

The ERM Framework

According to ASTM E3502-25, Standard Practice for Enterprise Risk Management, organizations should implement the following practices :

1. Integration Across All Activities: Top management and oversight bodies shall integrate risk management across all activities, allocate resources, assign responsibilities, and align it with strategy and culture .

2. Clear Accountability: Organizations shall incorporate an ERM framework into their management system, with clear accountability at every level. Risk owners shall be assigned to oversee risks within their respective areas .

3. Systematic Risk Identification: Organizations shall utilize systematic approaches to identify risks, hazards, threats, and sources across PESTLE domains—internal as well as external factors .

4. Risk Assessment: Risk assessments shall combine qualitative and quantitative techniques to analyze likelihood, probability, and possible repercussions. Upon applying existing risk controls, this evaluation process shall identify any remaining risk .

5. Risk Treatment: Organizations shall implement risk treatment strategies such as avoidance, reduction, transference, and acceptance to meet applicable regulatory and compliance frameworks .

6. Monitoring and Reporting: Organizations shall establish key risk indicators (KRIs), reporting mechanisms, and escalation procedures to monitor the effectiveness of controls and detect new threats .

7. Risk-Aware Culture: Organizations shall foster a risk-aware culture by encouraging transparency, training, and active engagement from all stakeholders .

Qeeva’s Risk Management Services

At Qeeva Advisory, our Risk Management Services help organizations identify and manage business interruption risks. Our dedicated teams work closely with clients to design tailored business interruption programs that include precise declared insurance values and limits for all insurable risks .

Claims Management and Advocacy: We serve as your claim preparer and loss mitigation advisor. We streamline the process by assembling all necessary documentation, performing financial calculations, offering policy guidance, and negotiating with insurers .

Loss Modeling and Risk Profiling: We determine material damage loss, aiding in setting insurance limits. This includes financial modelling to quantify risk tolerance, fire loss modelling, high-risk earthquake assessment, and natural hazard modelling .

Risk Tolerance Analysis: We conduct comprehensive financial analyses to calculate risk tolerance for unforeseen losses. This includes risk bearing capacity analysis and quantitative tolerance analysis .

Close-up of calculator, pen, and magnifying glass on financial documents.

Internal Controls and Compliance

The Internal Control Framework

Internal controls are the policies, procedures, and systems designed to safeguard assets, ensure accurate financial reporting, and promote operational efficiency. At Qeeva Advisory, we help organizations build robust internal controls across multiple domains :

Cash and Treasury Controls: We design controls over cash receipts to prevent theft and ensure accuracy, cash disbursement controls to prevent unauthorized payments, bank reconciliation controls for timely and accurate reconciliation, and treasury management controls including cash flow forecasting and counterparty risk management .

Procurement and Vendor Controls: We design vendor onboarding processes with due diligence and verification, purchase order controls with approval requirements, invoice and payment controls with three-way matching, and vendor performance monitoring systems .

Inventory and Asset Controls: We design controls for inventory receiving, storage, and issuance, stock count and reconciliation procedures, fixed asset controls, and asset disposal controls .

IT and Cybersecurity Controls: We design access control frameworks, data protection controls, system change management, and incident response procedures .

The GRC Program Framework

Building an effective GRC program requires a structured approach. According to NAVEX, organizations should follow these steps :

1. Map Your Obligations: Identify the laws, regulations, standards, contracts, and internal requirements your business needs to meet .

2. Run a Basic Risk Assessment: Map the risks that could affect your business and use the highest-priority risks to shape your core controls .

3. Assign Ownership: Give each major obligation, risk, and control a clear owner. Leadership, Compliance, HR, IT, Legal, Finance, and business owners may all carry different responsibilities .

4. Review Policies and Processes: Check whether your policies are current, accessible, and supported by the right processes .

5. Set a Review Cadence: Review the program regularly so policies, controls, and ownership stay aligned with your risks and regulatory requirements .

6. Evaluate Over Time: Review whether your current tools still support the way your GRC program works .

Close-up of hands pointing at a financial market activity chart, analyzing trends in securitization.

How Qeeva Advisory Helps with GRC

At Qeeva Advisory, we understand that effective governance, risk management, and compliance are essential for organizational success and sustainability. Our team of experienced professionals helps Nigerian businesses build robust GRC frameworks.

Our Core Services

Corporate Governance Advisory – We help you build governance frameworks that ensure effective board oversight, transparent decision-making, and accountability. Our services include Board Charters, committee mandates, diversity policies, and succession plans .

Internal Control Advisory Service – We help you build robust internal controls across cash and treasury, procurement, inventory, IT, and other critical domains. Our services include control design, testing, monitoring, and training .

Risk Management Services – We help you identify and manage risks that boards must oversee—strategic, operational, and compliance risks. Our services include claims management, loss modeling, risk profiling, and risk tolerance analysis .

Succession Planning & Governance Advisory – We help organizations build resilient governance structures and develop effective succession pipelines. Our services include director and officer fiduciary duties advisory, codes of ethics development, crisis management, and board and CEO coaching .

Regulatory Compliance – We ensure your business meets all regulatory requirements, including CAMA 2020, NCCG 2018, and sector-specific codes.

Company Secretarial Services – We provide expert support for corporate governance, board meetings, statutory filings, and regulatory compliance.

Our Service Methodology for GRC

At Qeeva Advisory, we follow a structured, collaborative process to deliver high-impact GRC solutions.

Phase 1: Governance, Risk and Compliance Assessment

Objective: Understand your current GRC landscape and identify gaps.

What We Do:

  • Review your board structure, committee frameworks, and governance practices

  • Assess compliance with CAMA 2020, NCCG 2018, and sector-specific codes

  • Evaluate your risk management framework and risk culture

  • Review your internal control environment across all critical domains

  • Identify gaps, vulnerabilities, and opportunities for improvement

Deliverables:

  • GRC Assessment Report highlighting strengths, weaknesses, and risks

  • Priority action plan for addressing gaps

  • Compliance checklist against regulatory requirements

Related ServicesCorporate Governance Advisory and Internal Control Advisory Service 

Phase 2: GRC Framework Design

Objective: Develop a comprehensive GRC framework tailored to your organization.

What We Do:

  • Design or refine board and committee charters with clear mandates

  • Develop governance policies and procedures

  • Design enterprise risk management frameworks

  • Develop internal control frameworks across all critical domains

  • Establish compliance monitoring and reporting systems

Deliverables:

  • Comprehensive GRC framework documentation

  • Board and committee charters

  • Risk management framework

  • Internal control framework

  • Compliance monitoring procedures

Related ServicesCorporate Governance Advisory and Risk Management Services 

Phase 3: Implementation Support

Objective: Implement GRC frameworks and build organizational capability.

What We Do:

  • Train directors on governance obligations and fiduciary duties

  • Train managers on risk management and internal controls

  • Implement compliance monitoring and reporting systems

  • Establish risk registers and key risk indicators

  • Build internal GRC capabilities

Deliverables:

  • Training programs for directors and managers

  • Risk registers and KRIs

  • Compliance monitoring systems

  • GRC policies and procedures

Related Services: Succession Planning & Governance Advisory and Internal Control Advisory Service 

Phase 4: Monitoring and Continuous Improvement

Objective: Ensure sustained GRC effectiveness and continuous improvement.

What We Do:

  • Conduct periodic board evaluations

  • Test internal controls for design and operating effectiveness

  • Review risk management framework effectiveness

  • Monitor regulatory changes and update frameworks accordingly

  • Provide ongoing advisory support

Deliverables:

  • Board evaluation reports

  • Internal control testing reports

  • Risk management review reports

  • Regulatory update alerts

Related ServicesRisk Management Services and Regulatory Compliance 

Frequently Asked Questions

Q: What is GRC?
A: Governance, Risk, and Compliance (GRC) is a structured approach that aligns an organization’s governance structures, risk management processes, and compliance obligations into a unified framework .

Q: What is the difference between CAMA 2020 and NCCG 2018 for INEDs?
A: CAMA 2020 has wider independence criteria (e.g., 30% shareholding threshold), while the NCCG has a “much stricter” test (e.g., 0.01% shareholding, 5-year employment lookback) .

Q: What is enterprise risk management?
A: ERM is a structured, systematic, and integrated approach to identifying, assessing, mitigating, monitoring, and reporting risks across all organizational functions .

Q: What are the key elements of an internal control framework?
A: Key elements include cash and treasury controls, procurement and vendor controls, inventory and asset controls, IT and cybersecurity controls, and control monitoring and testing .

Q: How can my company build an effective GRC program?
A: Start by mapping your obligations, running a basic risk assessment, assigning ownership, reviewing policies and processes, setting a review cadence, and evaluating over time .

Q: What are the penalties for governance failures in Nigeria?
A: Governance-related crises can lead to significant underperformance. Firms that experienced governance-related crises underperformed their sectors by around 35 percent on average .

The Bottom Line

Corporate Governance, Risk and Compliance (GRC) is not just a compliance exercise—it is a strategic imperative that drives organizational performance, builds stakeholder trust, and ensures long-term sustainability.

Key Takeaways:

Understand the Regulatory Framework: CAMA 2020 and NCCG 2018 establish the governance requirements for Nigerian companies. Sector-specific codes may also apply .

Build the Right Board: Public companies must have at least three independent directors. INEDs should serve no longer than nine years under the NCCG .

Implement Enterprise Risk Management: Adopt a structured, systematic, and integrated approach to identifying, assessing, mitigating, monitoring, and reporting risks across all organizational functions .

Strengthen Internal Controls: Build robust controls across cash and treasury, procurement, inventory, IT, and other critical domains .

Build an Effective GRC Program: Map obligations, run risk assessments, assign ownership, review policies, set review cadence, and evaluate over time .

Your job is to be prepared. Understand the GRC requirements. Build an effective board. Implement ERM. Strengthen internal controls. Seek professional guidance.

With the right approach and the right partner, you can turn GRC from a compliance burden into a strategic advantage for organizational success.

Suggested Reading from Our Blog

Boardroom Practices That Strengthen Governance – Understand how effective boardroom practices are the foundation of strong corporate governance. This article covers board composition, committee structures, and governance frameworks that drive sustainable growth .

Internal Control Advisory Service – Learn how to build robust internal controls across cash and treasury, procurement, inventory, IT, and other critical domains. This service includes control design, testing, monitoring, and training .

Risk Management Services – Explore how Qeeva Advisory helps organizations identify and manage business interruption risks through claims management, loss modeling, risk profiling, and risk tolerance analysis .

Succession Planning & Governance Advisory – Discover how to build resilient governance structures and develop effective succession pipelines. This article covers director fiduciary duties, codes of ethics, crisis management, and board coaching .

Regulatory Compliance In Nigeria – Comprehensive overview of tax and regulatory compliance requirements for Nigerian businesses.

Reference Links / Sources

Qeeva Advisory – Internal Control Advisory Service – Cash and treasury controls, procurement and vendor controls, inventory and asset controls, IT and cybersecurity controls, control monitoring and testing, and training and capacity building 

NAVEX – Updated Governance, Risk & Compliance (GRC) Guide for 2026 – GRC definition, common challenges, industry-specific considerations, and step-by-step program implementation guide 

LinkedIn – Director Tenure in Nigerian Public Companies – CAMA 2020 Section 285 (one-third rotation), NCCG Principle 7.2.9 (9-year INED ceiling), CBN Code 2023 (12-year NED cap, 3-year cooling-off period), and practical implications for company secretaries 

ASTM International – Standard Practice for Enterprise Risk Management (ERM) – Structured framework for identifying, assessing, treating, monitoring, and communicating risk; integration into governance, strategy, and operations; PESTLE-based risk identification; risk treatment strategies; KRIs and monitoring 

PENCOM – Corporate Governance for PFOs – Sector-specific governance requirements including board evaluation, induction programs, and corporate governance evaluation reports 

Qeeva Advisory – Risk Management Services Nigeria – Claims management and advocacy, loss modeling and risk profiling, risk tolerance analysis, and business interruption programs 

Qeeva Advisory – Succession Planning & Governance Advisory Service – Director and officer fiduciary duties, codes of ethics and conduct, crisis management and litigation avoidance, board and CEO coaching, and governance assessment methodology 

Mondaq – The Independent Director Qualification: CAMA 2020 vs NCCG 2018 – Comparative analysis of CAMA 2020 and NCCG 2018 independence criteria, including CAMA’s 30% shareholding threshold vs NCCG’s 0.01% threshold, employment lookback periods, and family relationship restrictions 

Qeeva Advisory – Boardroom Practices That Strengthen Governance – Qeeva’s Corporate Governance Advisory, Advisory Services, Risk Management Services, Training and Capacity Building, and Company Secretarial Services 

BusinessDay – Anti-Money Laundering: How to build an effective compliance framework – Elements of an effective anti-money laundering program including policies and procedures, governance, KYC programs, sanctions screening, transaction monitoring, and regulatory filing compliance 

Let’s Talk About Your GRC Needs

Building effective governance, risk management, and compliance frameworks is essential for organizational success and sustainability. At Qeeva Advisory, we understand the challenges faced by Nigerian businesses in navigating regulatory complexity and managing risk.

Whether you need help with governance assessment, risk management, internal controls, or compliance support, we are here to support you.

📞 Call us: (+234) 802 320 0801, (+234) 807 576 5799

📧 Email: info@qeeva.com

📍 Visit us: 5, Ishola Bello Close, Off Iyalla Street, Alausa, Ikeja, Lagos, Nigeria

Contact us today to schedule a consultation. Let us help you navigate GRC with confidence.

Your journey to stronger governance starts with a conversation. Let’s talk.

Related Posts

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted