Start with the right CBN instrument

The CBN issued its final Risk-Based Cybersecurity Framework and Guidelines for Deposit Money Banks and Payment Service Banks on 31 May 2024. The circular names commercial banks, merchant banks, non-interest banks, and payment service banks. It says the 2024 framework replaces the 2018 framework for deposit money banks and payment service providers. A payment company with another licence needs a separate applicability check. Do not use this page to claim that every fintech must follow the DMB and PSB text.

Record the exact instrument title, issue date, entity class, and clause before collecting evidence. Keep the official copy with your register. Ask the compliance owner to check later CBN notices that apply to the entity. Use the actual clause text in your register. A broad label such as “risk management” is too vague to test.

Map a clause to proof

Example evidence map for a DMB or PSB
Framework partQuestion for the ownerProof to inspect
Governance and oversightWho approves and reviews the security programme?Named committee, dated minutes, and follow-up decisions
Risk managementWho owns a payment-system risk?Risk entry, decision, owner, and review date
ResilienceCan the team restore a payment service?Exercise plan, result, failed steps, and retest
Metrics and reportingWho reads a serious alert?Alert record, review time, and escalation outcome

The table gives examples of evidence to inspect. It does not quote or replace individual requirements. In the working register, add the framework page and clause beside each row. Keep three kinds of proof apart: a policy says what should happen, an operating record shows that a person did the work, and a test shows how a control behaved. One file rarely proves all three.

Keep the map current

Give the source register one owner. Review it when a CBN circular changes the rules, when the licence changes, or when the payment system adds a new channel. Keep older versions so a reviewer can see why an evidence link changed. A current policy with an old test is a visible gap. A screenshot without a system version is weak proof. This upkeep costs time, but it keeps the review honest and makes the next audit faster.

For monitoring evidence, keep event IDs, timestamps, reviewer actions, and escalation results. OWASP's logging guidance explains why application events need consistent fields and protected storage. Apply that guidance to the evidence design; it is not a substitute for CBN text. Limit access to raw logs, since they can hold private payment data.

Check a clause against a live control

Synthetic example: a PSB says its incident alert process is active. Pick one payment-system alert from the last test month. Trace it from the source event to the monitoring rule, the person paged, the time they read it, and the action they took. Compare that chain with the exact clause and local control ID in the register. A slide saying “24-hour monitoring” does not show that the alert reached a person.

If no alert fired in the review period, run an approved test event and label it as a test. Do not present it as a production incident. Keep the test event ID, alert rule version, page time, response, and any failed step. If the alert reached an inactive inbox, assign a repair owner and run the test again. The final 2024 CBN framework is the source for applicability and clause text; the example here is a way to test a local control.

Record limits of the evidence map

The circular is BSD/DIR/PUB/LAB/017/008, dated 31 May 2024, with full compliance effective 1 July 2024. Its minimum-control scope is DMBs and PSBs. Use the bank’s actual licence and the official instrument to decide direct applicability. A payment provider’s contract with a bank can add separate evidence requests; keep their source and owner visible.

A working row needs instrument ID, exact page and clause, local control, system, owner, operating period, evidence ID, result, and open gap. For a restore row, attach the approved recovery target, actual start and finish times, data-loss check, failed steps, and retest. Do not insert a clause number from a generic template: the compliance owner must check it against the retained official copy.

Check later notices too. CBN’s reforms page records a March 2026 Cybersecurity Self-Assessment Tool rollout. This 2024 mapping is one source register entry; it is not a complete list of every duty in force. Record each newer instrument and the entity classes it covers before asserting current compliance.

Sources