A professional individual in a suit reading 'Fundamentals of Financial Planning' indoors.
Practical ICFR Guide for Nigerian Companies: Complete Implementation Roadmap

Practical ICFR Guide for Nigerian Companies: Complete Implementation Roadmap

PRACTICAL ICFR GUIDE FOR NIGERIAN COMPANIES

Introduction

Internal Control over Financial Reporting (ICFR) is no longer a voluntary best practice in Nigeria—it is a statutory obligation backed by the Financial Reporting Council of Nigeria (FRC) Act 2011 (as amended in 2023) and the Investments and Securities Act (ISA) 2007, Sections 60–63 . The regulatory landscape has tightened significantly: the Securities and Exchange Commission (SEC) requires public companies to report on ICFR from the December 2023 financial year end, while the FRC requires all Public Interest Entities (PIEs) to report effective for annual periods ending 31 December 2024 .

This shift means boards, CFOs, and CEOs now bear personal responsibility for the integrity of financial controls. The era of treating ICFR as an “audit afterthought” is over. This guide provides a practical, step-by-step approach for Nigerian companies to implement ICFR effectively, drawing on the FRC’s guidance and lessons from organisations that have navigated the journey .

Who Must Comply?

The FRC Act 2011 (as amended) defines Public Interest Entities (PIEs) broadly. Many privately held and government-linked businesses are now captured for the first time . PIEs include :

  • Governments and government organisations

  • Listed entities on any recognised exchange in Nigeria

  • Non-listed entities that are regulated

  • Public limited companies

  • Private companies that are holding companies of public or regulated entities

  • Concession entities

  • Privatised entities in which government retains an interest

  • Entities engaged by any tier of government in public works with annual contract sum of ₦1 billion and above

  • Licensees of government

  • All other entities with an annual turnover of ₦30 billion and above

Small companies as defined under CAMA 2020 are exempt, along with unit microfinance banks, insurance brokers, and non-tertiary educational and healthcare institutions .

The Pain Points: Why ICFR Implementation Fails in Nigeria

The Awareness and Knowledge Gap

A KPMG survey found that 52% of respondents cited lack of clarity and understanding as the major challenge preventing ICFR implementation, while 20% cited knowledge gaps . A separate survey by SIAO Partners revealed that while 64% of companies were aware of SEC guidelines, only 12% had commenced implementation .

The Documentation Bottleneck

Business processes and controls documentation are critical components of ICFR. The KPMG survey found that 59% of organisations were fully in the process of documenting their processes and controls, 33% were partially in the process, and 8% had not begun. Among those documenting, only 30% had reached the Risk and Control Matrix phase .

The Cost of Weak Controls

Weak internal controls are driving multi-million naira fraud across corporate Nigeria. In 2025, a midstream oil and gas services company suffered a ₦900 million fraud that built over 22 months. The board repeatedly received internal audit findings flagging procurement control weaknesses, but management dismissed them as procedural inefficiencies. When the EFCC intervened, shareholders lost 42% of company value . Firms with solid internal controls slashed their losses by half, and surprise investigations spotted trouble twice as fast as scheduled checks .

A diverse group of business professionals smiling confidently indoors.

Step 1: Establish the Foundation—Board and Management Commitment

Effective ICFR starts with management’s commitment to integrity and accountability. Without a strong tone at the top, controls are poorly designed, weakly enforced, and treated as a compliance exercise rather than a core business responsibility .

Key Actions:

  • The board of directors must take responsibility for ensuring the integrity of the entity’s financial controls and reporting

  • Management must establish a system of internal controls over financial reporting and security of assets

  • The CEO and CFO must personally certify the accuracy of financial statements

Step 2: Choose the Right Control Framework

Management must base its evaluation of ICFR on a suitable, recognised control framework. The FRC highly recommends the COSO Framework, which satisfies the criteria for a suitable framework .

The COSO Framework consists of five components supported by seventeen principles :

Component Description
Control Environment Integrity, ethical values, board oversight, organisational structure
Risk Assessment Identifying financial reporting risks, considering fraud potential
Control Activities Actions that mitigate risks, including authorisations, reconciliations, segregation of duties
Information and Communication Obtaining and using relevant information, internal and external communication
Monitoring Activities Ongoing and separate evaluations, communicating deficiencies

Step 3: Conduct a Scoping and Risk Assessment

The evaluation process should follow a top-down, risk-based approach, which is typically the most efficient and effective way to conduct the evaluation .

Key Activities:

  • Identify financial reporting elements (accounts, disclosures) that could materially affect the financial statements

  • Consider “what could go wrong” within each element to identify sources and likelihood of misstatements

  • Include consideration of fraud risk, including fraudulent financial reporting, misappropriation of assets, and corruption

  • Define materiality thresholds based on qualitative and quantitative factors

Common Challenge: Defining materiality and performing scoping and risk assessment are among the major challenges companies face. Diffuse ownership of processes leads to evidence gaps and control drift .

Step 4: Document Processes and Controls

Documentation is the foundation of ICFR evidence. Management must document business processes, including the flow of transactions from initiation through authorisation, processing, recording, and reporting.

Key Documentation Components:

  • Process Narratives: Written descriptions of how transactions flow through the system

  • Flowcharts: Visual representations of processes

  • Risk and Control Matrix (RCM): The core document mapping financial reporting risks to controls that address them

Types of Controls to Document :

  • Manual Controls: Controls that do not rely on IT application-produced information

  • IT-Dependent Manual Controls: Manual controls dependent on complete and accurate IT processing

  • Application Controls: Automated actions of IT applications

  • IT General Controls: Controls supporting the continued functioning of automated controls, including access management, program changes, and IT operations

Step 5: Test Controls for Design and Operating Effectiveness

Management must document the testing of controls to support its assessment. This includes both testing of design and testing of operating effectiveness .

Testing of Design: Assess whether the control, if operating as intended, provides reasonable assurance that control objectives are being met.

Testing of Operating Effectiveness: Assess the functionality and effectiveness of controls in place.

Key Considerations:

  • When adequate IT general controls exist and their operation is effective, automated controls may be more efficient to evaluate than manual controls

  • Management may consider the efficiency with which evidence of a control’s operation can be evaluated when selecting which controls to test

Step 6: Evaluate Deficiencies and Conclude

Management must evaluate any deficiencies identified during testing to determine whether a material weakness exists .

Critical Rule: Management is not permitted to conclude that ICFR is effective if there are one or more material weaknesses that have not been fully addressed or mitigated .

Key Definitions:

  • Significant Deficiency: A deficiency or combination of deficiencies in ICFR that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight

  • Material Weakness: A deficiency or combination of deficiencies in ICFR such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis

Step 7: Prepare the Management Report and CEO/CFO Certification

Management’s Annual Assessment Report

The entity’s annual report must include an internal control report of management containing :

  1. A statement of management’s responsibility for establishing and maintaining adequate ICFR

  2. A statement identifying the framework used by management (e.g., COSO Framework)

  3. Management’s assessment of the effectiveness of ICFR as of the end of the most recent fiscal year, including disclosure of any material weaknesses

  4. A statement that the external auditor has issued an attestation report on management’s assessment

CEO/CFO Certification

The CEO and CFO must certify that :

  • The signing officer has reviewed the report

  • Based on the officer’s knowledge, the report does not contain any untrue statement of material fact or omit to state a material fact

  • The financial statements fairly present in all material respects the financial condition and results of operations

  • The signing officers are responsible for establishing and maintaining internal controls

  • They have designed such internal controls to ensure material information is made known to them

  • They have evaluated the effectiveness of internal controls within 90 days prior to the report

  • They have presented their conclusions about the effectiveness of internal controls

  • They have disclosed to the auditors and audit committee all significant deficiencies and material weaknesses

  • They have identified whether there were significant changes in internal controls subsequent to the evaluation date

Step 8: External Auditor Attestation

The external auditor of a PIE must issue a statement as to the existence, adequacy, and effectiveness or otherwise of the internal control system .

Key Requirements:

  • The auditor must use the same suitable, recognised control framework as management

  • The attestation report must be filed as part of the annual report

  • The auditor is required to maintain independence—they should not be involved in the design and implementation of ICFR

Reporting: On the audit report, external auditors will issue two opinions—one on the financial statements and another on the ICFR .

Implementation Roadmap: Five Practical Steps

Based on the FRC guidance and lessons from Nigerian companies, here is a practical implementation roadmap :

Stage Key Activities Timeline
1. Gap Analysis, Scoping & Risk Assessment Identify financial reporting risks, define materiality, determine scope of evaluation 2-3 months
2. Documentation of RCM & Test of Design Document processes, build Risk and Control Matrix, assess control design 3-4 months
3. Remediation Address control deficiencies identified during design testing Ongoing
4. Test of Effectiveness Test operating effectiveness of controls, gather evidence 2-3 months
5. Certification Management assessment, CEO/CFO certification, auditor attestation 1-2 months

Critical Success Factors :

  • Define materiality early and keep it consistent. If you don’t, scoping becomes politics.

  • Assign one owner per process (Revenue, P2P, Payroll, Close). Diffuse ownership is where evidence gaps and control drift show up.

  • Treat evidence like an asset: standard folders, naming rules, retention, and a simple workflow so controls can be re-performed and re-proved without panic.

Common Pitfalls to Avoid

Pitfall Consequence Solution
Over-reliance on external auditors Assuming audit opinions equate to strong controls Management owns ICFR; auditors provide independent assurance
Outdated process documentation Controls tested against processes that no longer exist Review and update documentation annually
Manual controls dominating complex environments Higher error rates, harder to evidence Automate where possible; use IT general controls
Compromised segregation of duties Fraud risk increases Enforce role-based access; no single person controls a transaction end-to-end
IT general controls treated as “tech issues” Access, change management, and backups are not connected to financial reporting risks Integrate IT controls into ICFR scope
Involving external auditors in design Independence impairment Keep auditors out of design and implementation

How Qeeva Advisory Helps with ICFR Implementation

At Qeeva Advisory, we understand that ICFR implementation requires technical expertise, disciplined project management, and robust documentation. Our team of experienced professionals helps Nigerian businesses navigate the ICFR journey from scoping to certification.

Our Core Services

Internal Control Advisory Service – We help you build robust internal controls across cash and treasury, procurement, inventory, IT, and other critical domains. Our services include internal control review, internal control testing, and control components including risk assessment, control activities, information and communication, and monitoring. Our team of professionals helps you build, test, and improve your internal controls through internal control review and internal control testing .

Corporate Governance, Risk and Compliance (GRC) – Explore how effective governance, risk management, and compliance frameworks are essential for organizational success, including enterprise risk management and internal control frameworks. Our GRC services help you build governance frameworks that ensure effective board oversight, transparent decision-making, and accountability.

Advisory Services Nigeria – Our advisory professionals help you understand ICFR requirements, assess your current compliance posture, and develop implementation strategies.

Regulatory Compliance – We ensure your ICFR documentation meets all regulatory requirements under the FRC and SEC guidance. Our regulatory compliance services include regulatory mapping to identify all applicable regulations, agencies, and requirements for your business .

Bookkeeping Services – Accurate records are the foundation of effective ICFR. Our bookkeeping services ensure your financial data is accurate and complete.

Risk Management – We help you identify and manage risks associated with ICFR, including financial reporting risks and control effectiveness risks. Our risk management services help you develop early warning systems and monitor key risk indicators.

Our Service Methodology for ICFR Implementation

At Qeeva Advisory, we follow a structured, collaborative process to deliver high-impact ICFR solutions.

Phase 1: ICFR Readiness Assessment

Objective: Understand your current ICFR posture and identify gaps.

What We Do:

  • Review your current internal control environment and documentation

  • Assess compliance with FRC and SEC ICFR requirements

  • Evaluate your risk assessment processes and control activities

  • Assess your IT general controls and application controls

  • Identify gaps in your ICFR documentation

Deliverables:

  • ICFR Readiness Assessment Report

  • Gap analysis and priority action plan

  • Implementation roadmap

Related Services: Internal Control Advisory Service and Advisory Services Nigeria

Phase 2: ICFR Framework Design

Objective: Develop a tailored ICFR framework and documentation structure.

What We Do:

  • Design your ICFR evaluation strategy and methodology

  • Develop process documentation (narratives, flowcharts, process maps)

  • Build your Risk and Control Matrix (RCM)

  • Design control testing procedures and documentation templates

  • Develop entity-level and IT general controls documentation

  • Design management’s annual assessment report and CEO/CFO certification templates

Deliverables:

  • ICFR Evaluation Strategy Memorandum

  • Process documentation

  • Risk and Control Matrix

  • Control testing templates

  • Management assessment report templates

Related Services: Internal Control Advisory Service and Corporate Governance, Risk and Compliance (GRC)

Phase 3: Implementation Support

Objective: Implement ICFR documentation and build organisational capability.

What We Do:

  • Train finance and business process teams on ICFR requirements

  • Support control testing and evidence gathering

  • Assist with documentation of control operation

  • Support management’s assessment process

  • Coordinate with external auditors

Deliverables:

  • Training programs for staff

  • Control testing support

  • Documentation support

  • Management assessment support

Related Services: Bookkeeping Services and Regulatory Compliance

Phase 4: Monitoring and Continuous Improvement

Objective: Ensure sustained compliance and continuous improvement.

What We Do:

  • Monitor regulatory changes and update documentation accordingly

  • Conduct periodic ICFR reviews

  • Support internal and external audits

  • Provide ongoing advisory support

Deliverables:

  • Regulatory update alerts

  • Periodic ICFR review reports

  • Ongoing advisory support

Related Services: Risk Management and Regulatory Compliance

Frequently Asked Questions

Q: Which organisations must implement ICFR in Nigeria?
A: All Public Interest Entities (PIEs) as defined in the FRC Act 2011 (as amended), including listed entities, public limited companies, regulated non-listed entities, private companies with turnover of ₦30 billion and above, and others .

Q: What is the deadline for ICFR compliance?
A: SEC requires public companies to report on ICFR from December 2023 financial year end. FRC requires PIEs to report effective for annual periods ending 31 December 2024. A one-year waiver was granted to government agencies for 2024, with compliance required in 2025.

Q: What framework should be used?
A: The FRC highly recommends the COSO Framework, consisting of five components and seventeen principles .

Q: What is the Risk and Control Matrix?
A: The RCM is the core document mapping financial reporting risks to the controls that address them, including control type, frequency, owner, and evidence of operation.

Q: Can management conclude ICFR is effective if material weaknesses exist?
A: No. Management is not permitted to conclude that ICFR is effective if there are one or more material weaknesses that have not been fully addressed or mitigated.

Q: What must the CEO and CFO certify?
A: They must certify that they have reviewed the report, it contains no untrue statements, financial statements are fairly presented, they are responsible for internal controls, they have evaluated effectiveness within 90 days, and they have disclosed all significant deficiencies and material weaknesses to auditors and the audit committee.

Q: How does the external auditor attest to ICFR?
A: The external auditor issues a statement on the existence, adequacy, and effectiveness of the internal control system, using the same control framework as management. Two opinions are issued—one on financial statements and one on ICFR.

Q: How can Qeeva Advisory help with ICFR implementation?
A: We provide ICFR readiness assessment, framework design, implementation support, and ongoing monitoring. Our services include ICFR evaluation strategy, process documentation, Risk and Control Matrix development, control testing templates, management assessment report templates, and training. Our internal control services help you safeguard assets, improve the reliability of financial information, and establish and maintain compliance measures .

The Bottom Line

ICFR has moved from good practice to board-level compliance risk for Nigerian PIEs. The implementation journey requires disciplined project management, robust documentation, and a commitment to continuous improvement. Companies that treat ICFR as a compliance exercise will struggle; those that treat it as a strategic governance asset will build credibility and trust.

Key Takeaways:

Board and Management Ownership: The board is responsible for ensuring the integrity of financial controls. Management owns ICFR; auditors provide independent assurance.

COSO Framework: The FRC highly recommends the COSO Framework as the evaluation framework .

Top-Down, Risk-Based Approach: Start with scoping and risk assessment, focusing on the highest risks to reliable financial reporting.

Documentation is Critical: Process narratives, flowcharts, and the Risk and Control Matrix are the foundation of ICFR evidence.

Test Design and Operating Effectiveness: Document both design and operating effectiveness testing to support management’s assessment .

Material Weaknesses Preclude Effectiveness Conclusion: If material weaknesses exist and are not remediated, management cannot conclude ICFR is effective.

Start Now: The deadlines are real. Companies that have not begun implementation face significant compliance risk.

Your job is to be prepared. Assess your readiness. Build your documentation. Test your controls. Document your conclusions. Seek professional guidance.

With the right approach and the right partner, you can turn ICFR from a compliance burden into a foundation for reliable financial reporting and stakeholder trust.

Suggested Reading from Our Blog

Public Interest Entity, Financial Reporting Council Act and ICFR Implementation in Nigeria – This article explains the concept of Public Interest Entities (PIEs), the Financial Reporting Council (FRC) Act, and the requirements for implementing Internal Control over Financial Reporting (ICFR) in Nigeria. It covers the expansion of the PIE definition under the FRC Amendment Act 2023, the market demand for ICFR-ready organisations, and the licensing and documentation requirements for compliance .

ICFR Nigeria Archives – Qeeva’s dedicated archive of ICFR resources, including articles on Public Interest Entities, FRC Act requirements, and practical implementation guidance for Nigerian companies .

Internal Control Advisory Service – Learn how to build robust internal controls across cash and treasury, procurement, inventory, IT, and other critical domains. Our internal control services help you safeguard assets, improve the reliability of financial information, and establish and maintain compliance measures .

Corporate Governance, Risk and Compliance (GRC) – Explore how effective governance, risk management, and compliance frameworks are essential for organizational success, including enterprise risk management and internal control frameworks.

Regulatory Compliance Service – Comprehensive overview of regulatory compliance requirements for Nigerian businesses, including regulatory mapping, compliance audits, risk assessment, and sector-specific advisory .

Reference Links / Sources

FRC Nigeria – Guidance on Management Report on ICFR – Management’s annual assessment requirements, control framework requirements, material weakness considerations, and auditor attestation requirements

FRC Nigeria – Guidance on Management Report on Internal Control over Financial Reporting (ICFR) – CEO/CFO certification requirements, duty of directors on internal controls, and management’s annual assessment report contents

ICAN – ICFR Implementation Process at a Glance – COSO Framework components and principles, categorisation of controls, and control objectives

SEC Nigeria – Guidance on the Implementation of Sections 60-63 of ISA 2007 – Personalised certification, duty of directors, management’s annual assessment, and external auditor reporting requirements

FRC Nigeria – Evidential Matter to Support the Assessment – Reasonable support for management’s assessment, documentation of methods and procedures, and multiple location considerations

FRC Nigeria – Guidance on Assurance Engagement Report on ICFR – Assurance engagement standards, auditor independence, and material weakness definition

SEC Nigeria – Circular on Compliance with Sections 60-63 of ISA – Filing requirements for ICFR reports for 2023 and subsequent years

FRC Nigeria – National Repository of Financial Statements – Electronic filing requirements through the National Repository Portal effective January 2025

FRC Nigeria – One-Year Waiver for Public Sector Agencies – Waiver for government agencies for 2024 ICFR submission, compliance required in 2025

First Fiduciary – Governance and Compliance Digest – PIE definition, registration requirements, filing deadlines, and penalties

KPMG – A Guide to Implementing ICFR in Nigeria – Survey findings on awareness gaps, documentation progress, and implementation challenges

BusinessDay – Corporate Nigeria at Risk: Weak Internal Controls Driving Multi-Million Naira Fraud – Case studies of fraud enabled by weak controls and the financial impact

SIAO Partners – Detailed Guide on Implementing ICFR – Survey findings on awareness (64%) and implementation rates (12%), and implementation readiness steps

LinkedIn – ICFR Requirements for CFOs, CEOs & Auditors – 14 practical points on ICFR implementation, including materiality, evidence management, and common pitfalls

LinkedIn – Nigeria’s Financial Reporting Integrity: ICOFR’s Quiet Governance Test – Analysis of why ICOFR fails and the role of boards and internal audit

Qeeva Advisory – Internal Control Advisory Service – Internal control review, testing, and control components including risk assessment, control activities, information and communication, and monitoring

Qeeva Advisory – Corporate Governance, Risk and Compliance (GRC) – Enterprise risk management, internal control advisory, risk management services, and GRC methodology

Let’s Talk About Your ICFR Needs

Implementing ICFR is a significant undertaking that requires disciplined project management, robust documentation, and a commitment to continuous improvement. At Qeeva Advisory, we understand the challenges faced by Nigerian businesses in meeting ICFR requirements.

Whether you need help with scoping and risk assessment, documentation, control testing, or management assessment support, we are here to support you.

📞 Call us: (+234) 802 320 0801, (+234) 807 576 5799

📧 Email: info@qeeva.com

📍 Visit us: 5, Ishola Bello Close, Off Iyalla Street, Alausa, Ikeja, Lagos, Nigeria

Contact us today to schedule a consultation. Let us help you navigate ICFR implementation with confidence.

Your journey to reliable financial reporting starts with a conversation. Let’s talk.

Related Posts

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted