Boards and investors are failing the founders they’re supposed to equip

Somewhere right now, a founder who raised a decent round, built a real product, and had people genuinely rooting for them is in the middle of making a decision that is going to age very badly. They do not know it yet. And the people who were supposed to know it are nowhere to be found.

I have watched this story play out enough times that the shape of it has become familiar. Smart person, good company, real momentum, and then something completely avoidable blows it all up. There is even a running joke in venture circles that landing on Forbes 30 Under 30 is really a jail sentence waiting to happen. Obviously that is an exaggeration, most people on that list worked hard and deserve to be there. But the joke has survived long enough to mean something.

The question I keep coming back to is why these founders mess up, and where everyone who was supposed to be in their corner was when it mattered.

When I reflect on my own career, from being a young person still figuring out how professional environments worked, to eventually sitting on boards myself, one pattern keeps coming back to me. Many of us who occupy board seats are actively failing the founders we are supposed to be leading. By no means are we incompetent in our own fields, we have sadly redefined the role into something much smaller than it is supposed to be. 

The board is the adult in the room

There is a formal answer for why companies have boards. Fiduciary responsibility, shareholder oversight, strategic guidance, all of that exists and matters. But underneath the governance language, a board is also meant to be a room full of people who have already made the expensive mistakes and are in a position to help the people in front of them avoid repeating the same ones. That part seems to have secretly been dropped from the job description.

I know what a board can do for a person’s development because it happened to me, and I can trace almost every meaningful thing I understand about leadership back to specific people and specific rooms.

The first time I found myself on a board that carried real weight was at SystemSpecs, right after returning from Dubai. I walked into a room with Christopher Kolade and Ernest Ndukwe, the man who effectively delivered telecoms to Nigeria at a time when every other infrastructure effort was crumbling under its own weight. These were not accomplished people in the conventional sense alone. They were men whose names meant something, whose conduct meant something, who had clearly decided long ago what kind of people they were going to be and held to it ever since.

Nobody lectured me or handed me a manual. But as I sat in that room, my brain just reset itself.  Because when I was in banking, my idea of team bonding involved taking my colleagues to places I absolutely cannot describe in writing. That version of me was not compatible with the room I had entered, and I knew it without being told. The presence of people I deeply respected did the work that no training program ever could. Nobody needed to catch me being careless, because the thought of it was already unbearable. 

What I learned, and from whom

From SystemSpecs I moved on to start Trium, the corporate venture arm of the Coronation Group, and went back to work with my former boss, Aigboje Aig-Imoukhuede. When I was eventually leaving after four years, I told him he needed to formally issue me a PhD certificate, because what I received during that period was more rigorous than most structured programs could have delivered. And I was not the only one who benefited from being in that orbit. The board around Aigboje was its own institution.

Segun Ogbonlowo was the first person who ever showed me what it looked like to carry oneself properly in a boardroom. Early on, I was in a meeting with Aigboje and I was making my case for something, probably with more confidence than I had earned at the time, and Segun pulled me aside afterward, pulled my ears like an errant school child. He walked me through how a board member is supposed to conduct themselves with their chairman, how you prepare ahead of a meeting, how you listen before you push, how the room functions when everyone is playing their role well. It was direct, private and it changed how I showed up from that point forward.

Bunmi Lawson did something different for me. She laid the foundation of how I think about risk and compliance, in a way that was practical and grounded rather than theoretical. That understanding has traveled with me to every seat I have held since, and I still draw from it more than she probably knows.

What Aigboje himself gave me is harder to compress. It was exposure, full stop. He took me to meetings with the Vice President. He brought me into rooms with the SEC. He let me watch how a person of his standing navigates high-stakes environments, which turned out to be a long and irreplaceable masterclass in how power, preparation, and restraint work in combination. My ability to engage at senior levels on something like open banking did not come from reading about it but came from standing in those rooms and paying close attention.

Paying it forward, one board room at a time 

When I was involved in setting up the board for TeamApt, which most people now know as Moniepoint, I tried to apply what I had absorbed. We brought in Professor Yinka David-West, Chidi Okpala, and Boye Ademola from KPMG. At the time, people seemed to think I was working from some careful, deliberate framework. Mostly I was translating what Aigboje and others had given me into a new context and hoping it would hold. It did, and watching that board find its footing confirmed something I had already begun to suspect.

I saw this up close at Paystack recently, when one of the bright people there was stepping away. When they called me, they spent a good portion of that conversation talking about their experience working with me and how it made them sit up. When I think about the time I have spent on the Paystack board alongside people I respect enormously, and when I hear from those inside the company about what it has meant to work with board members who genuinely show up for them, it confirms the same thing. 

Now, Paystack is already heads and shoulders above most African fintechs. But what that conversation showed me is how much what we bring to a board room, myself and the other board members I deeply respect there, matters. We navigated extremely difficult times together, and I believe some of what we built, the decisions, the process, the discipline, will end up becoming playbooks taught in MBA classes somewhere down the line. 

Too many board members have made peace with doing the minimum

Too many board members have turned their role into a supervisory checkbox. They arrive for quarterly meetings, review decks, approve budgets, and leave. That is compliance cosplaying as leadership, and it leaves out entirely any real investment in the human being sitting across the table. That gap is where founders eventually get into trouble.

Founders, especially first-time founders, are often technically brilliant. They understand their product, their market, their users. What they frequently do not have is the kind of institutional wisdom that only comes from navigating complex organizations over time, from making expensive interpersonal mistakes and surviving them, from watching how seasoned leaders carry pressure without letting it crack their judgment. That wisdom is not available online. It lives in the people around them, specifically in the people on their board, and when those people are not actively transferring it, the founder learns it the hard way. Sometimes very publicly.

This is also not a problem that belongs only to early-stage companies. Governance failures and leadership implosions happen at every stage of growth and in every market. WeWork burned through billions with a board that watched Adam Neumann operate like a one-man religion and said nothing useful until the IPO was already on fire. Theranos had a board full of decorated names who apparently never thought to ask whether the machine actually worked. The geography and the industry keep changing but the shape of the failure stays the same. What matters is whether the people in oversight positions are actually doing the work, or collecting fees and updating their profiles.

Who you put in that room is a decision you will live with

If you are an investor and you place people on a board primarily to protect your equity and represent your interests, you are doing just a measly 10% of the job. The people you send into that room need genuine experience, real standing in the market, and the willingness to do the unglamorous work of developing the people they are serving. 

A founder with nobody in their corner doing real mentorship will eventually make a decision that costs everyone. Maybe it is a regulatory misstep or a culture failure that becomes a public mess. Perhaps it is a board blowup that turns into a cautionary story told at panels for years. These things happen on a predictable schedule at companies whose leadership has not been adequately developed, and the investors who placed inadequate board members into those seats share the outcome whether they acknowledge it or not.

The compounding benefit of doing this well is equally real. Founders who receive genuine development grow into leaders who can eventually sit on someone else’s board, contribute meaningfully, and extend the same investment to the next generation of people coming up.

Mentorship on a board should be mandatory

One-on-ones between board members and founders should be standard practice. Mentorship with specific developmental intent should be part of how a board operates, not an afterthought nobody budgets time for. Where a board does not have the bandwidth to do this internally, it should actively mandate that the company bring in executive coaches or external mentors who can fill the gap. For a founder navigating the role for the first time, that kind of support is infrastructure, and treating it as optional is how you end up reading about them in a forwarded article six months later.

The downstream effects of getting this right show up in measurable ways. Organizational drama decreases, distractions thin out, board meetings become more productive because the people presenting have been developed well enough to hold the room properly. Reports arrive in better shape and investors deal with fewer surprises. The whole system runs cleaner, and the money is considerably safer.

The inverse is equally predictable. If you are on a board right now and you are not doing this work, you are managing a countdown. The founder may be technically sound and working hard, but experience cannot be improvised under pressure, and at some point, that gap will surface in a way that is difficult to reverse after the fact.

I owe everything I understand about how to carry myself in positions of leadership to people who chose to invest in me when it would have been far easier to let me find my own way. Aigboje Aig-Imoukhuede deserves the most credit for that, without any qualification. I also owe a great deal to Segun Ogbonlowo, Bunmi Lawson, Christopher Kolade, and Ernest Ndukwe, each of whom gave me standards worth keeping, through direct intervention or through the simple example of how they showed up. I hope I never get to disgrace any of them.

Why hasn’t alternative data transformed credit in Africa?

Alternative data is going to help the African financially underserved have access to credit. At least, that was the plan. We all knew they didn’t have any credit history so getting access to their SMS, contact data, or even apps they have on their phones. That’s what we were told. But did that happen? No, possibly failed woefully.

Before I get into the part of this story that went wrong, I want to be clear about what I mean by alternative data, because the term covers a lot more ground than the one example everyone reaches for. When people talk about alternative data in African lending, they usually mean SMS and contact data scraping, since that’s the version that got the most press and the most backlash. But the category is much wider than that. 

It includes mobile money transaction history, airtime recharge patterns, utility and rent payment records, e-commerce activity, psychometric assessments that try to measure a borrower’s character through a quiz, geolocation, and social media behavior. Some of these have aged well. Some never really worked. SMS and contact data scraping is the one that did the most damage, and it’s worth understanding in detail because it shaped how an entire generation of African borrowers learned to distrust digital lending.

I’ve written before about why telco data, when released properly, is a better deal for the poor, and about the risks AI models carry when they’re trained on incomplete behavioral data. This piece sits next to both of those, because the SMS scoring story is the wake-up call that explains why I care so much about getting the next generation of alternative data right. We had a working idea, but then we broke it ourselves, and the way we broke it tells you almost everything you need to know about how not to build credit infrastructure for people who’ve never had access to it.

The credit gap that started this whole experiment

Step back about ten years and you land on the root of the problem, which is that banks across Africa simply weren’t lending to ordinary people, even though most of those people were just as capable of repaying a loan as anyone holding a salary account at a tier-one bank. The entire infrastructure for assessing creditworthiness assumed you already had a financial history worth assessing, which excluded almost everyone who’d never had access to formal credit to begin with. 

You needed a credit report which didn’t exist because bureau coverage across the continent was thin, in some markets covering less than a quarter of the adult population. Or perhaps banking data that couldn’t be pulled together because the banks themselves were fragmented and open banking hadn’t been built yet. Every door traditional underwriting expected you to walk through was locked, and most people didn’t even have the key.

So the industry improvised, the way industries always do when the obvious tools aren’t available. And the wider improvisation, the one that produced the whole category of alternative data, was reasonable on its face. If someone is sending and receiving mobile money regularly, topping up airtime on a consistent schedule, or paying their electricity bill on time month after month, those are genuine signs of financial discipline that a bureau report would never capture. 

Several of these approaches still hold up reasonably well today. Standard Chartered’s digital lending arm in Africa, for instance, leans on mobile money transaction data specifically because bureau coverage in some of its markets sits below a fifth of the adult population.

SMS became the favorite, but that didn’t end quite well

Out of all the alternative data sources available, SMS scraping became the one the largest and most aggressive lenders built their entire model around, because it was the most information-dense option on the table. A person’s SMS inbox typically houses more than just transaction alerts, there you could find loan approvals from other lenders, repayment reminders, salary credit notifications, and bill payment confirmations, all sitting in one place and readable the moment an app was granted permission. Companies like Tala and Branch led this wave, alongside a long list of local players like Quickash and dozens of others who copied the same script with smaller budgets and louder marketing. 

You’d download an app, and at launch it would request a long list of permissions covering your SMS, your installed apps, your contacts, and your location. Once you granted access, the app would scrape everything it could find and feed it into a scoring model that decided, often within minutes, whether you qualified for a loan and how much.

This is where I want to be precise about what failed and what didn’t, because lumping every form of alternative data into one failed experiment would be misleading. Mobile money and airtime data, used on their own and with proper consent, have held up reasonably well across multiple markets. 

Utility payment data has done the same in places like Latin America and increasingly in Ghana, where fintechs now look at mobile money patterns alongside business registration data for market traders. SMS scraping is the branch of this tree that rotted, and it rotted specifically because of how much intimate, uncontrollable information it gave lenders access to, and how little say borrowers had in any of it.

The moment borrowers caught on, it was game over

The first crack showed up the moment customers figured out what these apps were in fact reading. Once people understood that loan officers somewhere downstream could see sent by other lenders, the obvious response followed almost immediately, with borrowers deleting loan approval texts, repayment reminders, and anything else that hinted at an existing obligation to another lender, all gone the second it landed on the device.

What turned this into a technical failure rather than just an ethical one is simple: a message deleted off the phone is gone for any app trying to read current SMS content. Some lenders tried to get ahead of this by reading messages as they arrived in real time, catching new SMS as it landed but doing nothing for anything deleted before the app was even installed.

A borrower could walk into a second loan carrying three outstanding obligations elsewhere, with an empty SMS thread and a clean-looking risk profile, all without doing anything more sophisticated than tapping delete a few times before opening the next app. The scoring model wasn’t being outsmarted by some elaborate fraud operation, ordinary people simply wanted to protect themselves.

And so, a lot of lenders treated the SMS deletion problem as a reason to reach deeper into the phone instead of an indication the model needed rethinking. If SMS alone wasn’t giving a complete picture anymore, the response was to pull contact lists too, along with call logs and the full inventory of apps installed on the device. 

Research into digital lending apps operating in markets like Kenya found exactly this pattern playing out at scale, with apps requesting access to SMS content, contact lists, call logs, and installed app data well beyond what any reasonable underwriting process required to make a lending decision.

Contacts became a weapon in their own right. Lenders started using contact lists to identify guarantors without ever asking the borrower to nominate one, and when borrowers defaulted, agents would call straight through to family members, employers, and friends, sometimes to demand repayment on someone else’s behalf and sometimes just to embarrass the borrower into paying faster. 

Very little of this was something a borrower had meaningfully consented to, even where a permissions dialog existed somewhere in the onboarding flow. What started as a reasonable workaround for missing credit data turned into something that looked a lot more like surveillance with a loan attached to it, and it gave the entire category of alternative data a reputation it’s still working to shake off.

Borrowers learned to play defense, App stores drew a line

People adapted the way people always do when they realize they’re being watched. Borrowers learned to leave contact lists sparse or fake, knowing a full address book just meant more people for a lender to harass later if repayment ever slipped. They started running separate SIM cards for separate lenders, since a fresh device profile with no shared history was harder to cross-reference against other apps tracking the same person across different platforms. 

The moment a loan was repaid, the app would come off the phone entirely, partly to reclaim storage and partly because nobody wanted yesterday’s lender lurking in the background reading tomorrow’s messages.

The cycle kept compounding from there. Every defensive move borrowers made forced lenders to reach for more data to compensate, which pushed borrowers to defend themselves more aggressively, which degraded the data lenders were collecting even further than before. 

Eventually this reached a point where the access itself became politically and technically untenable. Google reclassified SMS and call log permissions as dangerous, restricting which categories of apps could even request them, which effectively shut the door on most lending apps reading SMS content the way they had for years. 

Apple‘s ecosystem never opened that door in the first place, which meant the entire SMS scoring model was always, structurally, an Android-only phenomenon dependent on a permission system that was ultimately going to get locked down once enough abuse cases piled up against it.

This lockdown was a direct response to the kind of abusive data harvesting I just described, the contact scraping and the location tracking and the installed-app inventories that had nothing to do with assessing whether someone could repay a loan. The platforms shut this down because the industry built around this access had stopped behaving responsibly with the trust it had been given, and SMS scoring specifically paid the price for years of poor judgment by the companies using it.

The quality collapse and the desperate phase

What should have worried lenders more than it did at the time was this: as borrowers got better at managing what these apps could see, the predictive quality of the scoring models started declining, slowly at first and then sharply, leaving lenders running sophisticated algorithms on increasingly compromised data, which is about the worst combination you can build a lending business on. 

This connects to something I wrote about more broadly when looking at AI underwriting risk across developing markets, where I made the point that a model is never neutral and always reflects every decision that went into building it, including which data sources to trust and how much weight to put on them. When the underlying data becomes unreliable because the population being scored has every incentive to manipulate it, no amount of clever feature engineering fixes that problem. 

By the time the quality decline became impossible to ignore, plenty of lenders had already built their entire risk infrastructure around this approach, and ripping it out wasn’t a simple decision to make from a boardroom that had spent years and investor capital defending the model. So instead of stepping back, a lot of players doubled down, pulling even more aggressively on contacts and location and app inventories, hoping that more inputs would somehow compensate for the fact that borrowers had learned to game the core engine feeding the whole system.

This is usually how these stories go, with the honest fix requiring an admission that the original model has limits, and that admission being harder to make than simply adding one more data point and hoping it helps. The result was an industry that, for a stretch of years, looked advanced from the outside while getting worse at the one thing it needed to do, which was separate good borrowers from bad ones with any real consistency.

Default rates didn’t improve the way the marketing suggested they should. Borrower trust eroded gradually. Regulators across multiple markets started paying closer attention to what these apps were doing with the data they collected, and the reputational damage from aggressive contact harassment alone did lasting harm to how digital lending was perceived across the continent, in ways that still color how people talk about loan apps today.

What the rest of alternative data still gets right

It’s worth pausing here to give credit where it’s due, because the SMS story can make it sound like every form of alternative data is tainted, and that isn’t the case. Mobile money and airtime recharge data have continued to perform well as predictive signals, partly because they reflect spending and saving discipline rather than private conversations, and partly because they’re harder for a borrower to manipulate without genuinely changing their financial behavior. 

Utility payment data works on similar logic. Psychometric assessments remain more contested, since they ask a borrower to answer questions designed to infer character traits, and the jury is still out on how well that translates across different cultural and economic contexts. The common thread across the data sources that have aged well is that none of them require reading someone’s private messages or calling their relatives to collect on a debt.

None of this means the broader instinct behind alternative data was wrong. Africa needed a way to assess creditworthiness for people who had never been inside a formal credit system, and phone-based behavioral data carries real predictive value when it’s collected properly and with consent. 

I’ve made the case before that telco data like call patterns, airtime recharge behavior, mobile money activity, and data usage consistency, holds genuine signal because it reflects an economic rhythm that a decent model can read without needing to touch anyone’s private messages. The category was sound from the beginning. What collapsed, specifically within the SMS branch of it, was how the data got collected and who controlled it once it had been collected.

The fix has to start with consent that means something beyond a permissions dialog buried in an onboarding flow nobody reads before tapping accept. It has to involve data the customer can see, understand, and meaningfully control, rather than a black box scraping whatever it can reach the moment an app gets installed on a phone. And it has to come through a channel the borrower doesn’t have unilateral power to sabotage the way they could delete an SMS thread in three seconds flat. 

Telco-held data fits this far better than device-scraped data ever could, since it sits with the network operator rather than on a phone where any borrower with five minutes and a motive can edit the record clean. I laid out a version of how this kind of consent-based telco model could work in practice, and the short version is that it requires the borrower to opt in explicitly, get notified every time their data gets accessed, and retain the ability to revoke that access, none of which the SMS-scraping era ever bothered to build into the system.

This brings to mind something I think about all the time, which is that credit access is foundational to prosperity across the continent, and you don’t get there by building underwriting systems that borrowers are incentivized to defeat from the first day they install the app. You get there by building systems borrowers can trust enough to engage with honestly, which was the entire premise behind pushing for open APIs as the foundation of inclusive credit scoring long before any of us watched the SMS model collapse under its own weight.

What this should have taught the industry

If there’s one thing worth pulling out of this whole experiment, it’s that data quality and data ethics were never separate problems, even though parts of the industry spent years treating them as though they were. Every time lenders pushed further into invasive collection without proper consent, they created a reputational liability and simultaneously degraded the thing they were trying to build, because borrowers will always respond to surveillance with evasion, and evasion is corrosive to exactly the kind of clean, consistent behavioral signal that good underwriting depends on to function.

The lesson isn’t that alternative data fails in Africa as a category because some of it hasn’t, and the parts that have stayed disciplined about consent and scope are still doing useful work in markets across the continent today.

If there’s one thing worth pulling out of this whole experiment, it’s that data quality and data ethics were never separate problems, even though parts of the industry spent years treating them as though they were. SMS scraping failed because it reached too far into a borrower’s private life without giving them any real say in the matter. Contact scraping failed for a different but equally serious reason, exposing third-party information to loan transactions those people were never part of. Both paid for that overreach with the one thing a scoring model can’t survive without, which is data people haven’t been given every reason to falsify. We had ten years to learn those distinctions. I’d rather we didn’t need another ten to put them into practice across the rest of the category.

The case for Open Finance in Nigeria

When you and I get paid, the money is mostly gone within days. It goes to the landlord, the electricity disco, the pension fund, the insurer, and whatever survives finds its way into the local market on the next street. Moving money is the one thing Nigerian finance has actually done better than any other country in Africa.

What doesn’t move is everything those payments say about us. Your landlord knows you have never missed rent, your telco has seen you buying airtime for over 20 years on the same SIM, your internet provider knows you never joke with your data subscription. If you are one of the lucky few to have an HMO, they know your company is paying for you without fail. You are as low risk as they come. Any lower risk and you are probably an angel. Yet not one of them has a reason or a route to tell the bank or money lender that is about to price your loan. So you get judged as a stranger on a sliver of a life you have already documented across half the financial system, because that sliver is all the data is allowed to reach.

The argument I’m making for open finance in Nigeria is rooted in how people truly use money. Transacting cuts across payments, credit, insurance and investment, sometimes within a single day, and the infrastructure underneath all of that needs to reflect that reality. Right now it largely does not, and the consequences show up in ways that are easy to miss individually but significant in aggregate. Credit decisions get made without full context, insurance products cannot reach the people who need them, and pension data sits behind closed doors.

So while I understand why the first response to this conversation is usually some version of “but we are not done with open banking yet,” open finance is really the same idea extended, taking the principle of financial interoperability and applying it across the full surface of financial services rather than just one part of it. And that is precisely why it deserves serious attention right now, while the open banking conversation is still being shaped.

So what does open finance actually mean

Open finance is the natural extension of open banking to the full scope of a person’s financial life. Where open banking focuses specifically on bank accounts and payment data, open finance applies the same standardized, consent-based, API-driven framework to every institution that holds financially relevant data about you. That means insurance companies, pension fund administrators, investment platforms, capital market operators, mortgage providers, and in many implementations, utilities and telecommunications providers as well.

The mechanics are similar to open banking. A person grants explicit, informed consent for a specific third party to access specific data held by a specific institution, for a specific purpose, for a defined period of time. The institution is required to make that data available through a standardized API. The third party can then use that data to deliver a product or service. The person retains the ability to revoke that consent at any time. What changes is the scope of the data that can be consented to, and therefore the scope of the products and services that become possible.

When a fintech or a lender or an insurance provider can see your full financial picture, with your permission, the products they can build for you stop being generic and start being genuinely relevant to your actual situation. The shift is from financial services that treat you as a category to financial services that understand you as a person.

We’ve seen what open banking can do, and it’s only the beginning 

Open banking has always been simple to describe and difficult to land. At its core, it is about giving people a standardized and regulated way to grant access to their own bank accounts, their transaction data, their balances, their payment rails, to third parties of their choosing. The key words there are “standardized” and “consented.” The whole model runs on open APIs and a regulatory framework that defines how that data can be accessed and used.

The reason open banking captured so much attention when it first started gaining traction globally is that the underlying idea is genuinely powerful. Giving people portable, programmable access to their own financial data fundamentally shifts the power dynamic between individuals and institutions. Before open banking, your financial history lived inside your bank and your bank alone, and if you wanted to do anything useful with it, you had to go through that same bank. 

Open banking broke that monopoly and said your data belongs to you, you should be able to take it wherever it creates the most value for your life. Once you accept that logic, the obvious next question is why it should stop at banking. The financial footprint of a person’s life runs through far more institutions than just their bank. 

The countries that recognized this early are already operating at a different level. Australia built the Consumer Data Right, a national framework that started with banking and has been deliberately extended to energy and telecommunications, with other sectors to follow. The architecture was designed from the beginning to be sectoral, meaning each new industry plugs into the same consent and data portability infrastructure rather than building its own from scratch. 

The UK’s open banking implementation, one of the most mature in the world, has generated an entire ecosystem of financial products that simply couldn’t have existed when data was locked inside individual institutions. The EU’s PSD2 directive created a regulatory baseline across multiple countries that forced banks to open their APIs and, in doing so, triggered a wave of fintech innovation that is still accelerating. In each of these cases, the governments involved made a deliberate decision that the benefits of data portability were significant enough to justify the disruption of building toward it.

What becomes possible when open finance works, and why we can’t afford to wait

When I think about why this is worth the difficulty, I keep coming back to the use cases that only become possible when financial data flows freely and with consent across sectors. And then I think about how long we’ve already been waiting, and the urgency becomes harder to ignore.

Today, most credit decisions in Nigeria are made using a fairly narrow data set, primarily bank transaction history, and often not even that for people without formal banking relationships. If you’re a salaried worker who pays all their bills on time, maintains a pension, and has a clean insurance record, none of that information typically factors into whether someone will lend to you or what rate they’ll offer. 

A lender operating in an open finance environment could, with your permission, look at your electricity payment history, your pension contributions, your insurance behavior, and your mobile money activity alongside your bank transactions. The credit picture becomes dramatically more accurate and dramatically more inclusive, particularly for the large share of Nigerians who are underserved or excluded by the current system.

Think about cash flow management for individuals. A fintech built on open finance infrastructure can monitor your wallet balance, your upcoming bill payments, your salary schedule, and your airtime usage all at once. When your airtime is about to run out, it can top it up automatically from the right account at the right time. When a bill payment is coming in three days and your balance is tight, it can show you a short-term credit option before you’re already in trouble. 

The same logic extends to insurance, to investment, to virtually every financial product. Personalization at scale requires data at scale, and data at scale requires the kind of interoperability that only a proper open finance framework can deliver.

Which brings me to the argument I keep hearing: let’s get open banking right first, and then we can talk about open finance. I’ve heard it, probably even made a version of it at some point. The problem is that the infrastructure decisions being made right now in open banking will either make open finance easier to build later or annoyingly harder. If we design the open banking architecture without any consideration for how insurance, pensions, and capital markets might eventually plug into it, we’ll spend years retrofitting things that could have been built with extensibility in mind from the start. Every month we delay that conversation is a month of technical decisions being locked in without the benefit of that longer view.

Beyond the architecture concern, there’s a timing reality that doesn’t get discussed enough. The regulatory appetite and political attention that goes into building standards tends to cluster. Getting stakeholders, regulators, and industry players to agree on a framework and actually implement it requires a sustained and concentrated push. If we exhaust all of that energy on open banking and then have to restart from scratch for open finance, we are setting ourselves up for another nine to ninety year cycle, and we’ve already seen what that looks like.

Who’s supposed to run this thing?

Here is where things get genuinely complicated, and I want to be direct about it because it’s the kind of issue that gets talked around rather than addressed.

Open finance is not a single-regulator problem. Banking falls under the Central Bank of Nigeria. Insurance falls under NAICOM. Pensions fall under PenCom. Capital markets fall under the SEC. Telecommunications, which is increasingly central to financial identity and behavior in Nigeria, falls under the NCC. For open finance to work, all of these bodies need to operate from a common data standard, the same definitions, the same APIs, the same rules about what consent looks like and how data can be used.

The CBN has been working on open banking for nine years and we’re still not at a fully operational, standardized, live system. Given that, what is the realistic probability that five or six different regulators, each with their own mandate, their own timelines, their own institutional interests, will spontaneously coordinate themselves into a coherent open finance framework? Probably not in the next decade, and very possibly not in the next several decades if history is any guide.

Inter-regulator coordination simply cannot be the primary mechanism here. The answer has to come from above the regulators. My view is that this is something the Federal Government itself needs to own, specifically the Ministry of Finance in its role overseeing the financial sector broadly, working in concert with the NCC given the centrality of telcos to any realistic data infrastructure in Nigeria. 

What this would look like in practice is a national standard-setting body, something at the government level with a cross-sector mandate, that defines the open finance framework, sets the technical standards, and has the authority to bring each regulator and their respective industries into alignment. That’s the architecture that could actually work, because it doesn’t rely on regulators voluntarily ceding ground to each other and gives them a common structure to operate within.

There is no version of this that is not hard

I want to be clear-eyed about the difficulty here. Building a national open finance framework in Nigeria is truthfully hard. The coordination, technical work and the political will required is substantial. Not to mention the process of getting every vertical, banking, insurance, pensions, capital markets, telcos, to build to a common standard while also managing their existing operations. Anyone who tells you otherwise is either not thinking carefully about the problem or is trying to sell you something.

The difficulty of a thing is not, by itself, an argument against doing it. Nigeria has a large population, a young demographic, a growing fintech sector, and a financial inclusion challenge that won’t be solved by the current disconnected architecture. The countries that build coherent, interoperable financial data infrastructure now are the ones that will have the most capable fintech ecosystems in ten years. The ones that wait for the perfect moment, or let the coordination problem become an excuse for indefinite deferral, will spend that same decade watching the gap widen.

We don’t have the luxury of doing this slowly just because it’s complicated.

The Fintech Act is a bad idea with good intention

Every few years, Nigeria tries to tidy up its financial system with a new idea that sounds orderly at first glance and truthfully there is something genuinely worth acknowledging in the motivation behind the newly proposed Fintech Act. The legislators who have championed it are responding to a real and visible problem: Nigeria’s financial technology sector has grown faster than the regulatory thinking applied to it, and the resulting patchwork of guidance, enforcement, and oversight has created genuine uncertainty for investors, operators, and consumers alike. The intention to bring coherence to this scene deserves credit. However, the method chosen to achieve it deserves serious scrutiny.

And yet, good intentions are not a sufficient foundation for sound policy. The proposed Fintech Act, which seeks to create an entirely new regulatory body to oversee fintech companies in Nigeria, reflects a fundamental misunderstanding of what the problem actually is and, consequently, proposes a solution that would make things considerably worse. The bill, which passed through the House of Representatives and subsequently stalled in the Senate, where lawmakers signalled the need for substantial revision, should not simply be reworked. The core premise that another regulator is the answer deserves to be challenged outright.

The very framing of “financial technology” as a unified category requiring its own standalone regulator reveals a conceptual confusion at the heart of the proposal. Finance and technology are not a single industry. They are two distinct domains whose intersection produces services that already fall within the mandates of Nigeria’s existing regulatory architecture. The Central Bank of Nigeria oversees banking and payments. The National Pension Commission governs pension fund administration. The National Insurance Commission regulates insurance. The Securities and Exchange Commission covers capital markets. The Federal Competition and Consumer Protection Commission handles consumer protection and market competition. Each of these bodies already has jurisdiction over the fintech activities that touch its domain.

No country with a mature, well-functioning financial system has resolved the complexity of fintech by collapsing all financial regulation into a single omnibus authority. The United Kingdom distributes regulatory responsibility between the Financial Conduct Authority, the Prudential Regulation Authority, and the Payment Systems Regulator, among others. In the United States, fintechs operate within a layered framework involving the Federal Reserve, the Office of the Comptroller of the Currency, the Consumer Financial Protection Bureau, and state-level regulators depending on the nature of their activities. These are not accidents of history or bureaucratic inertia. They reflect a deliberate understanding that different financial activities carry different risks and require different regulatory philosophies.

To suggest that Nigeria should do what no serious financial jurisdiction has done i.e create a single, all-encompassing fintech regulator, is to propose a solution with no precedent in the markets Nigeria aspires to emulate. The argument that technology ties all of these activities together and therefore justifies a unified regulator misunderstands what regulation is actually for. Regulation is not organised around the medium of delivery. It is organised around the nature of risk. Lending, insurance, capital raising, and payments each carry distinct risk profiles, require distinct supervisory competencies, and serve distinct segments of the public. Technology is simply the channel through which these activities now happen to be delivered, and changing the channel does not change the underlying economic function or the regulatory logic that should govern it.

Beyond the conceptual problem lies a practical one that would have real and measurable consequences for Nigeria’s economy: the cost of regulatory friction. Every time a fintech company operating in Nigeria must navigate an additional regulatory relationship, seek an additional approval, comply with an additional set of reporting requirements, or resolve an ambiguity between overlapping regulatory mandates, it incurs a cost. That cost is passed on to investors in the form of higher risk premiums, to employees in the form of slower growth, and ultimately to consumers in the form of higher prices and reduced access to services.

This is in no way a theoretical concern. The World Bank’s Doing Business indicators, before the index was retired, consistently documented how regulatory complexity translated into direct economic disadvantage for Nigeria. The country ranked 131st out of 190 economies in the 2020 Doing Business index, with burdensome start-up procedures and licensing requirements cited as significant contributors to that ranking. During the Buhari administration, the Presidential Enabling Business Environment Council under Vice President Yemi Osinbajo made the reduction of this kind of friction a central policy priority precisely because the evidence was overwhelming: friction does not just slow businesses down, it drives them toward informal or offshore alternatives, reducing tax revenues, employment, and financial inclusion in the process.

The lesson from successful reforms elsewhere in Nigeria is instructive. When the Minister of Interior, Olubunmi Tunji-Ojo, undertook the reform of Nigeria’s passport issuance system, he made the process faster and more predictable, and in doing so he was able to raise prices substantially while still generating public approval. Nigerians did not complain about paying more for passports because they were no longer paying the invisible tax of time wasted, trips repeated, bribes solicited, and uncertainty absorbed. The sticker price went up; the real cost went down. Friction, in other words, is itself a form of taxation, one that falls disproportionately on those who can least afford it.

Nigeria’s fintech sector has grown precisely because the digital infrastructure that underpins it has reduced certain kinds of friction dramatically. The country now has one of the most vibrant fintech ecosystems on the African continent, with over 200 active fintech companies as of recent estimates and a digital payments market that processes transactions worth trillions of naira annually. This growth has happened in an environment of regulatory imperfection, which is itself a testament to the sector’s dynamism. A new regulatory body sitting atop the existing framework would not eliminate the imperfections. It would add to them.

The argument for the Fintech Act rests on a legitimate diagnosis: Nigeria’s existing regulators have, in a number of documented instances, been slow to respond to fintech innovation, inconsistent in their guidance, and inadequately equipped to handle the cross-cutting questions around data privacy, cybersecurity, fraud, and consumer protection in digital environments. The Nigeria Data Protection Act of 2023 has gone some way toward addressing the data dimension, but enforcement capacity remains thin. Regulatory sandboxes have been established but have not always translated into clear licensing pathways.

The error lies in concluding that because the existing regulators have gaps, the solution is a new regulator. Creating a new institution does not fill gaps in existing ones. It creates new ones, along with new coordination problems, new jurisdictional ambiguities, and new opportunities for regulatory arbitrage. The question that deserves to be asked is not how to add to the regulatory architecture, but how to make the existing architecture function at the speed and sophistication that the industry now demands.

The presidency already has the constitutional and institutional authority to do what actually needs to be done. Rather than creating a new regulator, the Federal Government should establish a high-level, cross-agency Fintech Regulatory Coordination Committee, convened under the authority of the Office of the President and tasked with producing binding minimum standards that all relevant regulators must meet in their dealings with the fintech sector.

Those standards should address several specific and measurable failures. Every regulator with jurisdiction over fintech activities should be required to operate a single, publicly accessible portal through which all licensing applications, compliance filings, and correspondence can be submitted and tracked. Where regulators maintain separate portals, those portals should conform to common standards of interface design, document requirements, and processing transparency so that companies operating across multiple regulatory relationships do not face entirely different experiences with each. Application timelines should be published, automated, and monitored. When a regulator fails to respond to an application within the stipulated period, the outcome should default in favour of the applicant, or at minimum trigger an automatic public notification that creates accountability.

The Auditor General of the Federation, whose office is constitutionally empowered to audit government agencies, should be given both the mandate and the technical capacity to audit regulatory compliance with these standards. This would require investment in the Auditor General’s office specifically in digital literacy, technology auditing competencies, and independent analytical capacity, but this is an investment of a categorically different order from the capital expenditure, staffing costs, and institutional inertia that a new regulatory body would generate.

Beyond coordination, there is a case for targeted capacity building within each existing regulator. The Central Bank, SEC, and NAICOM each need fintech desks staffed by people who genuinely understand distributed ledger technology, algorithmic credit scoring, embedded finance, and the other technical realities of modern financial services. This is a training and recruitment challenge, and it is one that is far more tractable than the challenge of building an entirely new institution from the ground up.

Nigeria’s fintech sector is no longer a marginal sideshow. It has now become increasingly central to the country’s financial inclusion agenda, its foreign direct investment story, and its capacity to deliver financial services to the more than 38 million Nigerian adults who, according to the EFInA Access to Finance Survey, remained outside the formal financial system as recently as 2023. Every policy decision that affects the cost and ease of operating in this sector carries a direct human consequence.

The legislators who have championed the Fintech Act deserve credit for recognising that the regulatory status quo is not adequate to the moment. Their diagnosis is not wrong. Their prescription, however, risks compounding the problem they are trying to solve. Adding a new regulator to a system already characterised by overlapping mandates and uneven enforcement capacity does not produce clarity. It produces more of the same, with additional overhead.

Nigeria has an opportunity to take a different approach; one that draws on the existing authority of the presidency, the existing mandate of established regulators, and the existing dynamism of a sector that has already demonstrated what it can achieve under conditions that are far from optimal. That approach requires coordination, standardisation, and accountability rather than institutional proliferation. It requires the political will to hold existing regulators to a higher standard rather than the administrative convenience of delegating that problem to a new body.

The Senate was right to pause on this bill. The pause should be used not to refine the mechanics of a new regulator, but to reconsider whether a new regulator is the right answer at all. Nigeria’s fintech sector does not need more regulation, it only needs smarter governance of the regulation it already has.

Why are Nigerian banks afraid of open banking?

I’ve had this conversation too many times in private rooms with bankers I respect, people who have built real institutions and seen multiple cycles of this industry. So let me say it plainly: the fear is real, and it is not irrational.

A lot of the senior people in Nigerian banking today have been here long enough to watch the entire fintech story play out from the front row. Some of them started their careers around the same time I did. They remember when companies like Paystack*, Moniepoint, and Flutterwave were early-stage experiments run by small, hungry humans still figuring things out. At the time, these companies looked like side projects that banks could afford to ignore or even casually support.

Then things changed.

Those same “small boys” now sit on valuations and transaction volumes that rival, and in some cases quietly threaten, the dominance of traditional banks. That shift did not happen gradually enough for comfort. It happened fast enough to make anyone who has spent decades building a bank pause and rethink their life choices.

So when you ask why banks are nervous about open banking, you have to start from that lived experience. They have seen what happens when you underestimate speed.

“We’ve seen this movie before, and we didn’t like the ending”

There is also some institutional memory at play here that people don’t talk about enough.

The Nigerian banking industry has already fought one major defensive battle in the past. When mobile money was expanding across Africa, telcos were the dominant players in many markets. In Nigeria, banks pushed back aggressively. Leaders like Segun Agbaje and others were part of that resistance, and it worked. Telcos were kept out of fully owning mobile money in the way they did elsewhere.

That decision bought banks time. It allowed them to grow digital capabilities on their own terms and maintain control over customer relationships.

Now, from their perspective, open banking feels like opening the gates they spent years protecting.

So the hesitation is not just about technology or regulation, but about pattern recognition. They have seen what happens when new players get too much room to operate, and they are not eager to repeat that experience under a different label.

Open banking removes friction, and that is exactly the problem

Let’s strip this down to the core issue in a more honest way. Open banking standardizes access across board, and once that happens, a lot of the protective layers banks have relied on for years start to thin out. Data becomes easier to share in structured formats, payment initiation becomes more accessible, and integrations no longer require the same level of back-and-forth or commercial gatekeeping that used to slow things down. Third parties can plug into banking infrastructure with far less resistance, and they can start building customer-facing products without needing to negotiate every step of the journey.

On paper, this reads like progress, and to be fair, a lot of it is. The part that makes banks uneasy sits in what follows after that access is opened up. When friction reduces across the system, the advantage starts to shift away from who owns the infrastructure and toward who controls the customer experience.

Once you get to that point, competition takes on a different shape. Speed of execution, product intuition, and the ability to iterate without heavy internal processes begin to matter more than balance sheet size or legacy distribution. Fintech companies have spent years optimizing for exactly that environment, while banks have been structured around control, risk management, and layered approvals. That difference in operating model becomes much more visible when friction is no longer acting as a buffer.

This is where the discomfort really comes from. It is not just about opening APIs or complying with a standard, but about what happens after everything is opened up, when the barriers that once slowed everyone down are no longer there to protect incumbents from faster, more adaptive players.

The speed gap is not theoretical

If open banking goes live today in a fully functional way, there is very little stopping a player like OPay or Moniepoint from aggregating multiple bank accounts into a single interface. A customer logs into one app and sees balances across different banks in real time, with transaction histories and controls sitting in one place instead of being scattered across different banking apps.

That alone starts to change behaviour in meaningful ways, because convenience tends to win over habit when given enough time.

Now take it one step further. The same app could introduce a simple toggle that automatically sweeps funds from a traditional bank account into a primary account the moment money lands, based purely on user preference and ease of use rather than any issue with the bank itself. Over time, small features like that begin to influence where customers choose to keep their money and how they interact with it daily.

This is not a far-fetched scenario. It lines up directly with how product teams in fast-moving fintech companies think and build, especially when they are given standardized access to financial infrastructure.

The uncomfortable part for banks sits in how differently these products get built. By the time a fintech product manager has designed, tested, and shipped something like this, the equivalent idea inside a bank may still be working its way through internal reviews, risk assessments, and multiple layers of approval. That difference in pace comes from how these institutions are structured and how decisions are made within them.

Fraud is no longer someone else’s problem

There is another dimension that makes this even more sensitive, and that is fraud.

Historically, when fraud happened in many fintech-driven transactions, the burden often sat with the fintech or even the customer, depending on how the flow was structured and where the failure occurred. That reality quietly influenced how aggressively some of these systems were designed, because the party taking the risk was not always the one enabling the access.

That posture is changing, and it is changing in a way banks cannot ignore.

The Central Bank of Nigeria has made its position clearer over time, even if it has not always been spelled out in one single document. The expectation now leans toward banks carrying more responsibility when things go wrong, especially as they remain the licensed custodians of customer funds. The regulatory “body language,” as people like to call it, has shifted in a direction that places more accountability on the institutions at the core of the system.

So when banks look at open banking, the question they are asking is very practical and grounded in experience. If access is widened and multiple parties can initiate transactions or pull data, what happens when something breaks along that chain, and more importantly, who ultimately absorbs the loss and manages the fallout?

That question becomes harder to answer in an environment where fraud tactics are constantly evolving, and where increased connectivity can introduce new attack surfaces that did not previously exist at scale.

The regulator is stealthily solving a different layer of the problem

Interestingly, while all of this is happening, there are parallel regulatory efforts that many people are not paying enough attention to, even though they will have just as much impact on how the system evolves.

There is already movement toward deeper integration of AML and KYC systems across institutions, and the direction is becoming harder to ignore. Within a defined timeframe, banks will be expected to make decisions using more than just transaction patterns, with a growing emphasis on richer identity data and more contextual risk signals that travel with each transaction.

This begins to change how risk is assessed in a practical way.

Instead of focusing primarily on how frequently money moves or how large the amounts are, institutions will increasingly pay attention to who is behind those transactions, whether they appear on any sanction lists, and whether their behaviour aligns with what is known about their income and profile. Over time, this kind of intelligence allows for more informed decisions, especially in an environment where transactions are moving faster and across more connected systems.

So while open banking raises valid concerns about access, speed, and control, the regulatory side is quietly building a more data-informed risk framework in the background, one that is meant to keep up with that increased connectivity.

Both developments are unfolding at the same time, and banks are left with the task of reconciling wider access with tighter expectations around risk and accountability.

So should banks resist, or should they adapt?

This is where I tend to disagree with the idea that fear should drive strategy. I understand why banks are cautious. In fact, I think the fear is justified. If I were sitting in their position, I would not dismiss these risks either.

What I would not do is assume that slowing down open banking will stop the underlying shift. Because the truth is, the ecosystem is already moving in that direction, with or without formal standardization.

Larger fintechs are growing. Their capabilities are expanding. The technical barriers to integration are getting lower over time. If the official version of open banking takes too long, the market will find unofficial ways to approximate it.

At that point, banks lose even more control over how the system evolves. What makes this situation more interesting is that banks are not as helpless as the narrative sometimes suggests.

We have already seen examples of banks building their own platforms and ecosystems. Access Bank has Hydrogen. GTBank has Habari. Stanbic has Zest. These are not small experiments but deliberate attempts to extend beyond traditional banking interfaces.

At the same time, transaction flows are already shifting. Not everything is going through the traditional NIBSS rails anymore. Banks and fintechs alike are building alternative pathways that give them more control over how money moves.

Then you have virtual accounts, which have quietly become one of the most important tools in modern lending and collections. Banks like Providus, Sterling, and Wema have played significant roles in shaping that infrastructure. A large portion of loan repayments today depends on these systems.

So it is not accurate to say banks cannot adapt. They clearly can. Because one way or another, this evolution will happen. The only real question is whether banks shape it while they still can, or spend the next decade reacting to decisions made somewhere else.
* I am currently the board chair at Paystack