Understanding the CBN Risk-Based Cybersecurity Framework
The foundation of the CBN's approach to IT auditing is the Risk-Based Cybersecurity Framework and Guidelines. It shifts the regulatory focus from merely possessing security tools to proving that a continuous, governed security process is actively managing risk.
Document preparation (Weeks 1-3)
Gather all core policies: Information Security Policy, Incident Response Plan, Business Continuity Plan (BCP), and Disaster Recovery Plan (DRP). Ensure these are signed by the board or executive management within the last 12 months.
Evidence collection (Weeks 3-5)
Policies mean nothing without evidence. Collect recent penetration test reports, vulnerability scan results, access review logs, patch management records, and employee security awareness training certificates.
Asset inventory alignment (Weeks 5-6)
Auditors will cross-reference your critical asset register with your security testing scope. Ensure every public-facing IP, API endpoint, and mobile application listed in the inventory was included in your recent security assessments.
What CBN auditors actually check
Auditors don't typically run technical exploits. They look for the governance trail that proves your engineering team is doing what your policies claim. Expect deep dives into the following areas:
- Access control logs: Records showing that terminated employees lose access within 24 hours.
- Incident Response Capability: Evidence of tabletop exercises and post-incident reports.
- Third-Party Risk Management: Security questionnaires and SLAs for all integrated vendors (payment processors, cloud hosts).
- Continuous assessment: Annual independent penetration test reports and regular vulnerability scan records.
Prepare one evidence index
List each audit request, control owner, evidence file, covered period, source system, last review date, and open gap. Use stable file names and restrict access. The index lets the audit lead answer requests without searching chat threads, inboxes, and personal folders.
Test the index before the audit. Ask a person outside the control team to select an access review, change, incident, backup test, and vulnerability fix. They should reach the source record and understand who approved it.
Run a readiness review before the audit date
- Match the system inventory to the current production environment.
- Close departed-user access and explain every privileged account.
- Trace critical findings to fix tickets and retest evidence.
- Check that policies name the people who perform each control.
- Record open gaps with an owner, due date, and approved risk decision.
Missing an independent penetration test for your upcoming CBN audit?
Schedule a CBN-Compliant PentestCommon audit failures and how to avoid them
The "Clean" Penetration Test Report
Do not judge a report by the number of findings. Check whether the scope covered the current systems, the method matched the risk, findings include evidence, and fixes have retest records. A zero-finding report still needs enough detail to show what the tester did.
Outdated policies
A beautifully written Information Security Policy from 2021 is an automatic failure in 2026. The framework requires an annual review and board-level approval of all security policies.
Unscoped shadows IT
If your licensing application lists a new USSD service, but your penetration test report only covers the web application, the auditor will flag the gap. Ensure your testing scope accurately reflects your entire attack surface.
The CSAT submission requirement
The Cybersecurity Self-Assessment Tool (CSAT) is an annual mandate. By March 31st, Payment Service Providers (PSPs) and other licensed entities must submit a true reflection of their security posture. Falsifying this submission or failing to provide the requested evidence (like an independent pentest report) can lead to severe operational penalties from the CBN.
Audits are won in the evidence folder
Maintain a controlled repository for security evidence, access reviews, logs, and independent assessment reports. Review it during the year so the audit team can trace each claim to a current record.
Related reading
Blog: Fintech Security Audit Timing
Guides: CBN Compliance Guide · Licensing Security Requirements
Services: Penetration Testing
Frequently asked questions
What is the difference between a CBN IT examination and an external IT audit?
A CBN IT examination is conducted directly by CBN examiners to assess regulatory compliance. An external IT audit is conducted by an independent third-party firm hired by the fintech to assess controls, often serving as a prerequisite for the CBN examination.
How often does a fintech need to submit the CSAT?
The Cybersecurity Self-Assessment Tool (CSAT) must be completed and submitted to the CBN by March 31st of every year.
Can we use our internal team's security review for the audit?
No. The CBN Risk-Based Cybersecurity Framework explicitly requires independent, third-party penetration testing. Internal reviews are considered a conflict of interest.