Understanding the CBN Risk-Based Cybersecurity Framework

The foundation of the CBN's approach to IT auditing is the Risk-Based Cybersecurity Framework and Guidelines. It shifts the regulatory focus from merely possessing security tools to proving that a continuous, governed security process is actively managing risk.

01

Document preparation (Weeks 1-3)

Gather all core policies: Information Security Policy, Incident Response Plan, Business Continuity Plan (BCP), and Disaster Recovery Plan (DRP). Ensure these are signed by the board or executive management within the last 12 months.

02

Evidence collection (Weeks 3-5)

Policies mean nothing without evidence. Collect recent penetration test reports, vulnerability scan results, access review logs, patch management records, and employee security awareness training certificates.

03

Asset inventory alignment (Weeks 5-6)

Auditors will cross-reference your critical asset register with your security testing scope. Ensure every public-facing IP, API endpoint, and mobile application listed in the inventory was included in your recent security assessments.

What CBN auditors actually check

Auditors don't typically run technical exploits. They look for the governance trail that proves your engineering team is doing what your policies claim. Expect deep dives into the following areas:

Prepare one evidence index

List each audit request, control owner, evidence file, covered period, source system, last review date, and open gap. Use stable file names and restrict access. The index lets the audit lead answer requests without searching chat threads, inboxes, and personal folders.

Test the index before the audit. Ask a person outside the control team to select an access review, change, incident, backup test, and vulnerability fix. They should reach the source record and understand who approved it.

Run a readiness review before the audit date

Missing an independent penetration test for your upcoming CBN audit?

Schedule a CBN-Compliant Pentest

Common audit failures and how to avoid them

The "Clean" Penetration Test Report

Do not judge a report by the number of findings. Check whether the scope covered the current systems, the method matched the risk, findings include evidence, and fixes have retest records. A zero-finding report still needs enough detail to show what the tester did.

Outdated policies

A beautifully written Information Security Policy from 2021 is an automatic failure in 2026. The framework requires an annual review and board-level approval of all security policies.

Unscoped shadows IT

If your licensing application lists a new USSD service, but your penetration test report only covers the web application, the auditor will flag the gap. Ensure your testing scope accurately reflects your entire attack surface.

The CSAT submission requirement

The Cybersecurity Self-Assessment Tool (CSAT) is an annual mandate. By March 31st, Payment Service Providers (PSPs) and other licensed entities must submit a true reflection of their security posture. Falsifying this submission or failing to provide the requested evidence (like an independent pentest report) can lead to severe operational penalties from the CBN.

Key Takeaway

Audits are won in the evidence folder

Maintain a controlled repository for security evidence, access reviews, logs, and independent assessment reports. Review it during the year so the audit team can trace each claim to a current record.

Related reading

Blog: Fintech Security Audit Timing

Guides: CBN Compliance Guide · Licensing Security Requirements

Services: Penetration Testing

Frequently asked questions

What is the difference between a CBN IT examination and an external IT audit?

A CBN IT examination is conducted directly by CBN examiners to assess regulatory compliance. An external IT audit is conducted by an independent third-party firm hired by the fintech to assess controls, often serving as a prerequisite for the CBN examination.

How often does a fintech need to submit the CSAT?

The Cybersecurity Self-Assessment Tool (CSAT) must be completed and submitted to the CBN by March 31st of every year.

Can we use our internal team's security review for the audit?

No. The CBN Risk-Based Cybersecurity Framework explicitly requires independent, third-party penetration testing. Internal reviews are considered a conflict of interest.