Engaging regulators is a superpower. Founders must develop this or get into trouble

About seven years ago, a Nigerian fintech found itself on the wrong side of the Central Bank, what we’d call a proper hot okro soup. It was close to losing its license entirely. The Central Bank had decided to make them walk the straight and narrow. Fortunately, word got to the founders before the letter landed.

A frantic phone call to a well-respected bank executive is what surprisingly turned things around. The man flew to Abuja and went to plead their case in person. No lawyer or press statement or strongly worded appeal came close to doing that. They survived because somebody with the right relationship intervened on their behalf. Nothing in that entire saga carried anywhere near that kind of weight.

Of course, the Central Bank didn’t let them off the hook because some big man strolled in. He offered to ensure the fintech remediate their governance and compliance issues within a short period of time. The license was tied to the banker’s 30 years of pedigree.

I’ve thought about that story a lot over the years, because it captures something founders like me don’t want to admit to themselves. The people who decide whether your business lives or dies aren’t always the investors you’re chasing or the customers you’re trying to win over. Sometimes they’re civil servants sitting in an office you’ve never visited, and most of us never bother to find out who they are until we’ve gone to pull the tiger’s tail.

The power regulators hold and why we pretend it isn’t there

Regulators, for the most part, aren’t wealthy people. There are exceptions in certain countries where regulation has become a racket, but broadly speaking, the people writing and enforcing the rules that govern your industry are bureaucrats earning civil servant salaries.

But man, the power they wield is enormous!

You saw it play out during the last World Cup, when Folarin Balogun’s red card got overturned because somebody knew somebody who knew somebody who knew somebody. Football, of all things, isn’t immune to influence and access. Business is no different, and in many ways it’s far less forgiving.

If these people truly have the power to make or unmake your company, why do so many founders walk around completely disconnected from and oblivious of them? We’ll spend months perfecting a pitch for an investor we’ve never met, but never once think to learn the name of the person who runs the department that could shut our business down with a signature.

By law, regulators exist to write regulation, enforce it, and punish whoever wants to make a monkey out of it. That’s the job description, plain and simple. And yet founders everywhere, not just in Africa, tend to operate as if these people don’t exist. We build our businesses, we chase growth, worry about competitors and product and fundraising, and somewhere along the way we forget that there’s an entire arm of government whose sole purpose is to decide what we are and aren’t allowed to do.

The less you know your regulator, the less you understand how much influence they have over your future. Founders who’ve never sat across the table from the people governing their industry tend to underestimate them badly, right up until the day a new policy lands on their desk and blindsides their entire business model.

The relationship should happen long before you need a favor

As a founder or business owner, you need to be deliberate about knowing your regulators and the people who work under them. This doesn’t happen by accident or through a single courtesy visit. I’ll have you know that it’s a relationship you must build over time, the same way you’d build a relationship with a big-pocket customer or a strategic partner. And there’s nothing illegal or shady about wanting to know your regulator or wanting to understand how they think.

The real risk sits on the other side. Skipping this relationship altogether is the genuinely dangerous position to be in. When you know your regulator and the people around them, you start to develop a feel for the kind of regulation that’s coming down the pipeline.

There’s a lot of noise out there, plenty of rumored policy changes and half formed proposals floating around industry circles, but proximity to the people who write the rules gives you a much sharper sense of what matters and what you can safely ignore. You start to understand which lines you can never cross and which grey areas still have room to move. The point isn’t to test boundaries or try to get away with something. It’s to see the regulator’s thinking clearly enough that you stop operating on assumptions.

I know this because I lived it. I started Open Banking Nigeria in 2017, talking directly to the CBN, no license, no mandate, just a group of fintechs who decided to engage properly. The director came to our events, not once but twice. And before long something funny happened. People across the industry started assuming Open Banking Nigeria was some licensed entity, treating us with the kind of respect that comes with a government stamp. It wasn’t. We were a bunch of fintechs who showed up, did the work, and engaged the regulator the way you’re supposed to. That assumption alone tells you how rare proper engagement is. When you do it, people can’t imagine you pulled it off without a title.

There’s another benefit to this closeness, and it pays off slowly but consistently. When you help a regulator succeed at their own job, you build goodwill that shows up later. And this isn’t bribery in any shape or form. It’s sincerely helping the people responsible for regulating your industry do their jobs better.

Every regulator, at some point, taps into industry expertise to figure out how a new policy might land, or how an existing one is performing once it hits the real world. They rely on input, data, and perspective from the very businesses those rules will affect. Being close to a regulator means you’re in the room, or at least in the hallway somewhere, when those conversations are happening. That proximity gives you the chance to positively influence regulation before it’s finalized, and it also gives you the early warning to prepare for whatever’s coming, rather than being caught off guard when it becomes law.

I’ve watched this play out beyond my own work. There’s a story of bankers who engaged their regulators properly and, in doing so, exposed them to technology the regulator hadn’t fully seen yet. That engagement didn’t just protect the banks. It led to better regulation, and it opened room for the whole industry to grow. That’s the part founders miss. Engagement isn’t only defensive but done well, it moves the regulator forward, and everyone downstream of that regulation benefits.

And this repeats across every vertical. The industries where engagement is poor are exactly the ones where regulation and reality are badly misaligned, where you hear the regulated endlessly complaining about rules that make no sense to them, while doing nothing to sit at the table and shape those rules. The complaint is the symptom. Poor engagement is the disease. Show me an industry at war with its regulator and I’ll show you an industry that never bothered to build the relationship before it needed one.

Not all regulators are the same but you need all of them

Regulators exist at different layers, and if you’re only paying attention to the person at the top, you’re missing most of the picture. There are the young regulators just beginning to build their influence within the institution, the ones who’ll be running departments in five or ten years. There are the current regulators themselves, the directors, the governors, the executive vice chairmen who are actively making decisions today. And then there are the ex-regulators, the ones who’ve left the institution but carry the knowledge of how it all works.

You need relationships with all three groups, and I want to spend a moment on the third one because founders tend to underrate it badly. Ex-regulators are frequently very good at what they did, which is often exactly why they end up building consulting practices once they leave. These are the people who know where the “bodies are buried”, so to speak. They understand the internal politics and the figures that drive decisions inside these institutions. When you need direction, they’re often the ones who can point you toward the right person to speak to, or explain why a particular policy is moving the way it is. They also carry political capital they can spend on your behalf when you need someone to open a door that would otherwise stay shut.

If you’re the kind of founder who prefers to sit alone in your office and avoid all of this, you’re putting your business at serious risk. When new regulations are being drafted, your competitors who’ve done the relationship building will be in the room shaping the language, and there’s a real chance those rules get written in a way that disadvantages you and favors them.

The lines you should never cross

There are things you should never, under any circumstances, even with a gun to your head, do when building these relationships.

Never try to bribe a regulator. It’s wrong, unethical and illegal. Beyond the moral higi-haga, it’s also a fast way to destroy your business and possibly get yourself a cold floor in prison with devilish mosquitoes taking turn on you. So treat this as an absolute line rather than a grey area to be negotiated I beg of you.

Never let yourself become a slave to a regulator either. You’re allowed to have principles, and you’re allowed to disagree with a regulator’s position. When you do disagree, there’s no need for hostility or confrontation, but make your stance known clearly and respectfully. A good relationship with a regulator doesn’t require you to agree with everything they say.

Keep the relationship confidential. Regulators generally don’t want their names circulating in industry gossip, and using their name to build your own credibility is one of the worst things you can do to a relationship built on trust. If the governor of a central bank is someone you know well, that’s not something to be dropped casually in conversations to impress other founders or investors. Sharing those details around undermines the very trust that made the relationship valuable in the first place.

If you’re going to give gifts, keep them modest and ordinary. A good book, something small and thoughtful, nothing more. Don’t attempt to influence anyone with expensive items, designers, or by offering to sponsor their children’s abroad school fees. That crosses directly into bribery, however it gets dressed up, and it’s unethical regardless of the language used to justify it.

Sometimes you want to test an idea before committing resources to it, and you can share that with a regulator hypothetically. You might describe something you’re considering doing and ask, purely as a conversation, what their general stance would be. That kind of exchange gives you a read on the regulatory mood that you’ll never find published anywhere online, and it costs you nothing except the willingness to ask.

So how do you start engaging?

Regulators want to succeed at their jobs too, and many of them are working with limited resources or limited in-house expertise to solve problems that are difficult. Be ready to help. Offer guidance where you have relevant expertise, contribute to reports, support industry events and research that helps them make better informed decisions. Anything you do openly and transparently to help a regulator do their job well is fine, and often welcomed.

The trouble only begins the moment you start doing things behind closed doors, covering costs that should never be covered, or slipping into arrangements that blur the line between support and influence peddling. Keep everything visible, keep everything above board, and the relationship will serve you far longer than any shortcut ever could.

Building trust with the people who regulate your industry takes time, and it won’t show up as a line item on any growth chart you present to your board. The founders who treat this seriously instead of something only reserved for crisis moments end up with a seat at the table when the rules of their industry are being drafted, while everyone else finds out about those rules the same way the rest of us find out about a World Cup decision, after the fact, with no say in how it went.

If your best people can’t replicate themselves, you’re already dying

For years, I thought the strongest compliment I could give someone on my team was “we couldn’t run without you.” I used it in performance reviews and on calls with friends (and some enemies) when they asked who my key people were, and I wore it like a badge of honor, both for them and for me, since it meant I had built something worth depending on.

It took me a painfully long time, and a few genuinely stressful stretches where one person being unreachable for a couple of days nearly stalled a launch, to understand that I had it backwards the entire time. “We couldn’t run without you” means I let a few people become the entire company’s heroes, and never built anyone under them who could take it on.

I was celebrating the wrong thing

Every growing company has that one person, sometimes several. It might be an engineer who is the only one who understands the payments system. Or a salesperson who is the rainmaker. We call these people irreplaceable, and we say it with pride, when what we’re really describing is a ticking timebomb. It is easy to slide into this pattern, especially when you are moving fast and stopping to teach someone else the ropes feels like a detour from actually shipping.

I have come to believe heroism in a growing company is a structural failure wearing agbada and kembe of virtue. Behind almost every hero I have ever worked with, there is usually a manager who could not, or would not, develop the people underneath them, whether out of insecurity, laziness, or the very human fear of training your own replacement. I built this exact culture for years before I ever managed to diagnose it in myself.

None of this makes the person carrying all that weight a villain. Most of them are simply chasing efficiency, trying to get things done the fastest way they know, and that instinct is exactly what turns them into a bottleneck. Showing them why that shortcut costs the business more than it saves is part of our job as leaders, and it takes patience rather than blame.

So when it dawned on me that a company’s growth will always have a ceiling when it runs through “special” people, I knew it was time to sit with my thoughts, lease some common sense, and recalibrate before everyone becomes limited by one person’s calendar, since that is a terrifying place to build a business from. 

Why I think about life as a numbers game

Now, in my quest for solutions to salvage the deep mess a business like this can unintentionally land in, I stumbled on what I call the law of networks, and the clearest way I know to explain it is through luck.

Let’s say an averagely sharp person can convert about 5% of the luck that crosses their path into something useful, an opportunity turned into a deal, a chance meeting turned into a partnership, whatever form luck takes for you. If that person has a hundred people in their network, or sees a hundred opportunities over the course of a year, they will convert around five of them. That is the ceiling for someone operating alone, a fixed number no matter how sharp they are.

Imagine that same person with a network of a hundred people, each passing along even half of the opportunities that come their way. Suddenly, you are no longer looking at just a hundred opportunities. You are looking at a much larger pool, and converting the same modest 5% of it produces results that are nowhere close to what one person working in isolation could ever achieve. The 5% conversion rate never changed. What changed was the size of the pool it was applied to, and that is the difference between linear effort and exponential outcomes.

When you are running a business by yourself, whether you are an engineer, a salesperson, or a founder wearing every hat at once, so much depends on you simply staying upright. You get tired or sick. Life happens (and life can be a bitch), in the mundane and the serious ways it always does, and when it does, everything tied to you grinds to a halt along with you. There is no backup plan when everything runs through one person.

But the moment you have a network, the moment you have people you have genuinely invested in and handed real responsibility to, the entire structure stops depending on one link holding and starts holding itself up. It grows exponentially, and it keeps growing on the days you are not in the room.

The math behind working with other people in the room

There is something I have started calling synergy, in the literal sense that 1 + 1 = 5, well past whatever the word has come to mean on a corporate poster. On your own, there is a limit to what you can produce, shaped entirely by your own bandwidth, blind spots, and your own limited hours in a day.

When you bring good people into that picture, whether by hiring them or by deliberately replicating your own capabilities in them, they often grow faster than you did, because engagement surfaces things that solitude never will. There are insights that only become visible through the friction of working alongside someone else, ones neither of you would have arrived at alone.

Think of a time you were stuck on a problem, turning it over in your head with no progress, and then you start explaining it out loud to a colleague, a friend, or someone at your workspace, and somewhere in the middle of that sentence the answer simply appears, from the act of engaging with another mind.

This, ladies and gentlemen, is the compounding effect at work, and there is friction that comes with it. Plenty of us struggle with the more mundane side of this, the part where you have to explain what you do, translate your instincts into something teachable, put language around decisions you have always made by feel. It is an uncomfortable struggle, but it is one worth working through.

The one expectation I have of every senior hire

After building this the wrong way for longer than necessary, here is where I have landed. If you are ever going to build something that outlasts your own energy and attention, whether as a manager or a business owner, you have to replicate yourself deliberately, so your effort compounds into exponential results through the people around you.

Practically, this means every senior person on my team is now measured on one thing above almost everything else: whether the people reporting to them can do a fragment of their job within eighteen months, well beyond approximating it or simply surviving without them for a week. Leaders have to actively recognize this risk in themselves and fight against it, mostly through mentoring people directly and showing them by example.

If that is not happening, what the senior person has built is a monument to their own indispensability, and a monument, by definition, does not scale. I hope this has been useful in some small way. I have my doubts about how many people will go and change how they measure their own team because of it.

Inside CBN’s new data localization circular

If you judged the CBN’s latest payments circular by the online reaction alone, you’d think the entire Nigerian financial service industry has been turned upside down considering every time the Central Bank of Nigeria releases a new circular, two things happen almost immediately: People rush to LinkedIn to declare that everything has changed, and everyone else starts wondering which companies are about to be in trouble.

The latest circular on data localization, Ultimate Beneficial Ownership (UBO) disclosure, and market structure has triggered that very same reaction.

I’ve read through the circular, spoken to people across the financial and fintech ecosystems, and my first reaction was probably less dramatic than most and sincerely it has nothing to do with underestimating the circular, which carries real weight for the industry.

The reason is straightforward: much of what people are discussing today has been in existence for years. What has changed is the CBN’s decision to bring some of these expectations together into a formal policy document, make timelines explicit, and signal that enforcement will become much more deliberate.

So, if you’re expecting a sudden shake-up across Nigerian banks and fintech, you’ll probably be disappointed. If you’re looking at what this means for the country’s long-term financial infrastructure, this circular deserves far more attention than the headlines have given it.

Data localization has always been around

One of the biggest misconceptions I’ve seen since the circular was published is the idea that the CBN has suddenly invented data localization. It hasn’t, and anyone who has spent enough time building regulated financial products in Nigeria knows regulators have always paid close attention to where critical financial data lives, how it is managed, and who ultimately has access to it.

The difference today is that the CBN has decided to state the expectation considerably more clearly. The circular requires financial institutions and payment participants to ensure payment transaction data generated within Nigeria is stored and managed in Nigeria, with full compliance expected by January 1, 2027.

The wording greatly matters here because the circular repeatedly talks about payment transaction data. It does not say every application used by financial institutions must suddenly run from Nigerian infrastructure, rather does it prohibits cloud computing infrastructures like AWS, Microsoft Azure, or Google Cloud. It focuses specifically on payment transaction data.

That distinction matters because I’ve already seen people interpreting the policy far more broadly than the document itself suggests.

Not every system is suddenly affected

When people hear “data localization,” many immediately imagine banks scrambling to move every workload into Nigerian data centres, which isn’t what this circular says.

Banks and fintechs rely on dozens of software systems every single day. Customer support teams use CRMs; Finance teams use accounting software; Employees use email platforms; Internal communication happens over collaboration tools; Product teams manage work using cloud-based applications. Most of those services are still provided by companies like Microsoft and Google.

Even the CBN itself relies on Microsoft products in different capacities, just as many banks continue to rely heavily on Microsoft 365 and many newer fintech companies operate substantial parts of their business on Google’s ecosystem.

If someone tells you every one of those systems now has to move into a Nigerian data centre overnight, they’re reading far more into the circular than is actually written.

The document is much narrower in scope, focused specifically on operators who handle  payment transaction data. Ergo, if your core business involves processing payment transactions in Nigeria, then complying with the localization requirement becomes part of doing business in the market.

All the banks are already running their core banking systems in Nigeria

Another reason I don’t expect the immediate disruption many people are predicting is because much of Nigeria’s payment infrastructure is already local. Take banking, for instance. Virtually every major Nigerian bank already operates its core banking systems within Nigeria and they have been doing that for decades.

The same applies to many of the country’s oldest payment infrastructure companies. NIBSS has always operated locally. Interswitch built its infrastructure long before cloud computing became the default choice. UPS, along with several other legacy players, developed their systems during a period when hosting data outside Nigeria simply wasn’t the standard approach.

History has already done a large part of the work this policy is trying to reinforce. That’s why I don’t expect January 2027 to suddenly produce a wave of emergency migrations across the entire financial industry. The organizations likely to spend the next several months making adjustments are those whose payment processing architecture has become more globally distributed as cloud-native infrastructure became the norm.

For everyone else, compliance may look less like rebuilding everything from scratch and more like tightening existing controls, documenting processes properly, and demonstrating that critical payment data remains where regulators expect it to be.

The UBO requirement isn’t quite new news

The other part of the circular that has generated plenty of discussion is the requirement around Ultimate Beneficial Ownership disclosures. Again, I don’t expect the reaction to match the reality.

If you’ve never gone through a CBN licensing process, this requirement may sound like a major new regulatory burden. However, if you have, your reaction is probably closer to relief that someone finally put this requirement on paper, since it’s been part of the job for years.

Anyone who has raised capital, structured shareholding, applied for licenses, or participated in regulatory engagements with the CBN knows that understanding who ultimately owns and controls a regulated institution has always mattered.

The circular requires institutions to maintain accurate and up-to-date records of their Ultimate Beneficial Owners and make that information available to the CBN when requested.

This aligns with how the regulator has approached financial oversight for a long time. The formalization matters because it creates greater consistency across the ecosystem, but I don’t see it introducing a radically different operating environment for companies that have already been taking compliance seriously.

Building local infrastructure has to start somewhere

One criticism I’ve already heard is that Nigeria simply doesn’t have the infrastructure to support a policy like this.

While we may not have cloud infrastructure at the same scale as AWS, Google Cloud, or Azure. Anyone building modern technology products knows these companies have spent decades investing billions of dollars in global infrastructure, redundancy, networking, and security. Expecting local providers to match that overnight is far from realistic.

But waiting until Nigeria has infrastructure on that scale before introducing policies that encourage local investment doesn’t make much sense either.

Every country that has built strategic digital infrastructure started somewhere. Nobody wakes up one morning with world-class data centres already built. Conditions have to be created that make investing in them worthwhile.

If regulators never communicate that local infrastructure matters, investors have very little incentive to build it. Demand remains weak, capital goes elsewhere, and years later everyone complains that the country still depends entirely on foreign providers.

At some point, someone has to make the first move, and I think that’s what this circular is trying to do. It will almost certainly create additional costs for some operators, and not every implementation will be smooth. But if Nigeria wants critical financial infrastructure to increasingly reside within its borders, then there has to be a starting point.

One thing I’d still like the CBN to fix

If there’s one area where the CBN still falls short, it has very little to do with data localization or beneficial ownership. It’s about discoverability. The CBN regulates one of the most important industries in the country, yet finding authoritative information can still be surprisingly difficult.

Today, if you’re looking for licensed commercial banks, microfinance banks, payment service providers, payment service banks, or other regulated institutions, you’ll often find yourself downloading Excel spreadsheets from different sections of the CBN website.

Those spreadsheets technically contain the information you’re looking for, but they don’t function like modern regulatory infrastructure. They’re difficult to search, harder to integrate into internal workflows, and not particularly friendly for founders, investors, journalists, researchers, compliance teams, or even regulated institutions trying to verify information quickly.

A single authoritative, searchable directory of every regulated entity would fix this. You could search by company name, license category and status, approval date, or registration number. Information could be updated in one place and consumed by everyone as the definitive reference point for all who depend on it.

Boards and investors are failing the founders they’re supposed to equip

Somewhere right now, a founder who raised a decent round, built a real product, and had people genuinely rooting for them is in the middle of making a decision that is going to age very badly. They do not know it yet. And the people who were supposed to know it are nowhere to be found.

I have watched this story play out enough times that the shape of it has become familiar. Smart person, good company, real momentum, and then something completely avoidable blows it all up. There is even a running joke in venture circles that landing on Forbes 30 Under 30 is really a jail sentence waiting to happen. Obviously that is an exaggeration, most people on that list worked hard and deserve to be there. But the joke has survived long enough to mean something.

The question I keep coming back to is why these founders mess up, and where everyone who was supposed to be in their corner was when it mattered.

When I reflect on my own career, from being a young person still figuring out how professional environments worked, to eventually sitting on boards myself, one pattern keeps coming back to me. Many of us who occupy board seats are actively failing the founders we are supposed to be leading. By no means are we incompetent in our own fields, we have sadly redefined the role into something much smaller than it is supposed to be. 

The board is the adult in the room

There is a formal answer for why companies have boards. Fiduciary responsibility, shareholder oversight, strategic guidance, all of that exists and matters. But underneath the governance language, a board is also meant to be a room full of people who have already made the expensive mistakes and are in a position to help the people in front of them avoid repeating the same ones. That part seems to have secretly been dropped from the job description.

I know what a board can do for a person’s development because it happened to me, and I can trace almost every meaningful thing I understand about leadership back to specific people and specific rooms.

The first time I found myself on a board that carried real weight was at SystemSpecs, right after returning from Dubai. I walked into a room with Christopher Kolade and Ernest Ndukwe, the man who effectively delivered telecoms to Nigeria at a time when every other infrastructure effort was crumbling under its own weight. These were not accomplished people in the conventional sense alone. They were men whose names meant something, whose conduct meant something, who had clearly decided long ago what kind of people they were going to be and held to it ever since.

Nobody lectured me or handed me a manual. But as I sat in that room, my brain just reset itself.  Because when I was in banking, my idea of team bonding involved taking my colleagues to places I absolutely cannot describe in writing. That version of me was not compatible with the room I had entered, and I knew it without being told. The presence of people I deeply respected did the work that no training program ever could. Nobody needed to catch me being careless, because the thought of it was already unbearable. 

What I learned, and from whom

From SystemSpecs I moved on to start Trium, the corporate venture arm of the Coronation Group, and went back to work with my former boss, Aigboje Aig-Imoukhuede. When I was eventually leaving after four years, I told him he needed to formally issue me a PhD certificate, because what I received during that period was more rigorous than most structured programs could have delivered. And I was not the only one who benefited from being in that orbit. The board around Aigboje was its own institution.

Segun Ogbonlowo was the first person who ever showed me what it looked like to carry oneself properly in a boardroom. Early on, I was in a meeting with Aigboje and I was making my case for something, probably with more confidence than I had earned at the time, and Segun pulled me aside afterward, pulled my ears like an errant school child. He walked me through how a board member is supposed to conduct themselves with their chairman, how you prepare ahead of a meeting, how you listen before you push, how the room functions when everyone is playing their role well. It was direct, private and it changed how I showed up from that point forward.

Bunmi Lawson did something different for me. She laid the foundation of how I think about risk and compliance, in a way that was practical and grounded rather than theoretical. That understanding has traveled with me to every seat I have held since, and I still draw from it more than she probably knows.

What Aigboje himself gave me is harder to compress. It was exposure, full stop. He took me to meetings with the Vice President. He brought me into rooms with the SEC. He let me watch how a person of his standing navigates high-stakes environments, which turned out to be a long and irreplaceable masterclass in how power, preparation, and restraint work in combination. My ability to engage at senior levels on something like open banking did not come from reading about it but came from standing in those rooms and paying close attention.

Paying it forward, one board room at a time 

When I was involved in setting up the board for TeamApt, which most people now know as Moniepoint, I tried to apply what I had absorbed. We brought in Professor Yinka David-West, Chidi Okpala, and Boye Ademola from KPMG. At the time, people seemed to think I was working from some careful, deliberate framework. Mostly I was translating what Aigboje and others had given me into a new context and hoping it would hold. It did, and watching that board find its footing confirmed something I had already begun to suspect.

I saw this up close at Paystack recently, when one of the bright people there was stepping away. When they called me, they spent a good portion of that conversation talking about their experience working with me and how it made them sit up. When I think about the time I have spent on the Paystack board alongside people I respect enormously, and when I hear from those inside the company about what it has meant to work with board members who genuinely show up for them, it confirms the same thing. 

Now, Paystack is already heads and shoulders above most African fintechs. But what that conversation showed me is how much what we bring to a board room, myself and the other board members I deeply respect there, matters. We navigated extremely difficult times together, and I believe some of what we built, the decisions, the process, the discipline, will end up becoming playbooks taught in MBA classes somewhere down the line. 

Too many board members have made peace with doing the minimum

Too many board members have turned their role into a supervisory checkbox. They arrive for quarterly meetings, review decks, approve budgets, and leave. That is compliance cosplaying as leadership, and it leaves out entirely any real investment in the human being sitting across the table. That gap is where founders eventually get into trouble.

Founders, especially first-time founders, are often technically brilliant. They understand their product, their market, their users. What they frequently do not have is the kind of institutional wisdom that only comes from navigating complex organizations over time, from making expensive interpersonal mistakes and surviving them, from watching how seasoned leaders carry pressure without letting it crack their judgment. That wisdom is not available online. It lives in the people around them, specifically in the people on their board, and when those people are not actively transferring it, the founder learns it the hard way. Sometimes very publicly.

This is also not a problem that belongs only to early-stage companies. Governance failures and leadership implosions happen at every stage of growth and in every market. WeWork burned through billions with a board that watched Adam Neumann operate like a one-man religion and said nothing useful until the IPO was already on fire. Theranos had a board full of decorated names who apparently never thought to ask whether the machine actually worked. The geography and the industry keep changing but the shape of the failure stays the same. What matters is whether the people in oversight positions are actually doing the work, or collecting fees and updating their profiles.

Who you put in that room is a decision you will live with

If you are an investor and you place people on a board primarily to protect your equity and represent your interests, you are doing just a measly 10% of the job. The people you send into that room need genuine experience, real standing in the market, and the willingness to do the unglamorous work of developing the people they are serving. 

A founder with nobody in their corner doing real mentorship will eventually make a decision that costs everyone. Maybe it is a regulatory misstep or a culture failure that becomes a public mess. Perhaps it is a board blowup that turns into a cautionary story told at panels for years. These things happen on a predictable schedule at companies whose leadership has not been adequately developed, and the investors who placed inadequate board members into those seats share the outcome whether they acknowledge it or not.

The compounding benefit of doing this well is equally real. Founders who receive genuine development grow into leaders who can eventually sit on someone else’s board, contribute meaningfully, and extend the same investment to the next generation of people coming up.

Mentorship on a board should be mandatory

One-on-ones between board members and founders should be standard practice. Mentorship with specific developmental intent should be part of how a board operates, not an afterthought nobody budgets time for. Where a board does not have the bandwidth to do this internally, it should actively mandate that the company bring in executive coaches or external mentors who can fill the gap. For a founder navigating the role for the first time, that kind of support is infrastructure, and treating it as optional is how you end up reading about them in a forwarded article six months later.

The downstream effects of getting this right show up in measurable ways. Organizational drama decreases, distractions thin out, board meetings become more productive because the people presenting have been developed well enough to hold the room properly. Reports arrive in better shape and investors deal with fewer surprises. The whole system runs cleaner, and the money is considerably safer.

The inverse is equally predictable. If you are on a board right now and you are not doing this work, you are managing a countdown. The founder may be technically sound and working hard, but experience cannot be improvised under pressure, and at some point, that gap will surface in a way that is difficult to reverse after the fact.

I owe everything I understand about how to carry myself in positions of leadership to people who chose to invest in me when it would have been far easier to let me find my own way. Aigboje Aig-Imoukhuede deserves the most credit for that, without any qualification. I also owe a great deal to Segun Ogbonlowo, Bunmi Lawson, Christopher Kolade, and Ernest Ndukwe, each of whom gave me standards worth keeping, through direct intervention or through the simple example of how they showed up. I hope I never get to disgrace any of them.

Why hasn’t alternative data transformed credit in Africa?

Alternative data is going to help the African financially underserved have access to credit. At least, that was the plan. We all knew they didn’t have any credit history so getting access to their SMS, contact data, or even apps they have on their phones. That’s what we were told. But did that happen? No, possibly failed woefully.

Before I get into the part of this story that went wrong, I want to be clear about what I mean by alternative data, because the term covers a lot more ground than the one example everyone reaches for. When people talk about alternative data in African lending, they usually mean SMS and contact data scraping, since that’s the version that got the most press and the most backlash. But the category is much wider than that. 

It includes mobile money transaction history, airtime recharge patterns, utility and rent payment records, e-commerce activity, psychometric assessments that try to measure a borrower’s character through a quiz, geolocation, and social media behavior. Some of these have aged well. Some never really worked. SMS and contact data scraping is the one that did the most damage, and it’s worth understanding in detail because it shaped how an entire generation of African borrowers learned to distrust digital lending.

I’ve written before about why telco data, when released properly, is a better deal for the poor, and about the risks AI models carry when they’re trained on incomplete behavioral data. This piece sits next to both of those, because the SMS scoring story is the wake-up call that explains why I care so much about getting the next generation of alternative data right. We had a working idea, but then we broke it ourselves, and the way we broke it tells you almost everything you need to know about how not to build credit infrastructure for people who’ve never had access to it.

The credit gap that started this whole experiment

Step back about ten years and you land on the root of the problem, which is that banks across Africa simply weren’t lending to ordinary people, even though most of those people were just as capable of repaying a loan as anyone holding a salary account at a tier-one bank. The entire infrastructure for assessing creditworthiness assumed you already had a financial history worth assessing, which excluded almost everyone who’d never had access to formal credit to begin with. 

You needed a credit report which didn’t exist because bureau coverage across the continent was thin, in some markets covering less than a quarter of the adult population. Or perhaps banking data that couldn’t be pulled together because the banks themselves were fragmented and open banking hadn’t been built yet. Every door traditional underwriting expected you to walk through was locked, and most people didn’t even have the key.

So the industry improvised, the way industries always do when the obvious tools aren’t available. And the wider improvisation, the one that produced the whole category of alternative data, was reasonable on its face. If someone is sending and receiving mobile money regularly, topping up airtime on a consistent schedule, or paying their electricity bill on time month after month, those are genuine signs of financial discipline that a bureau report would never capture. 

Several of these approaches still hold up reasonably well today. Standard Chartered’s digital lending arm in Africa, for instance, leans on mobile money transaction data specifically because bureau coverage in some of its markets sits below a fifth of the adult population.

SMS became the favorite, but that didn’t end quite well

Out of all the alternative data sources available, SMS scraping became the one the largest and most aggressive lenders built their entire model around, because it was the most information-dense option on the table. A person’s SMS inbox typically houses more than just transaction alerts, there you could find loan approvals from other lenders, repayment reminders, salary credit notifications, and bill payment confirmations, all sitting in one place and readable the moment an app was granted permission. Companies like Tala and Branch led this wave, alongside a long list of local players like Quickash and dozens of others who copied the same script with smaller budgets and louder marketing. 

You’d download an app, and at launch it would request a long list of permissions covering your SMS, your installed apps, your contacts, and your location. Once you granted access, the app would scrape everything it could find and feed it into a scoring model that decided, often within minutes, whether you qualified for a loan and how much.

This is where I want to be precise about what failed and what didn’t, because lumping every form of alternative data into one failed experiment would be misleading. Mobile money and airtime data, used on their own and with proper consent, have held up reasonably well across multiple markets. 

Utility payment data has done the same in places like Latin America and increasingly in Ghana, where fintechs now look at mobile money patterns alongside business registration data for market traders. SMS scraping is the branch of this tree that rotted, and it rotted specifically because of how much intimate, uncontrollable information it gave lenders access to, and how little say borrowers had in any of it.

The moment borrowers caught on, it was game over

The first crack showed up the moment customers figured out what these apps were in fact reading. Once people understood that loan officers somewhere downstream could see sent by other lenders, the obvious response followed almost immediately, with borrowers deleting loan approval texts, repayment reminders, and anything else that hinted at an existing obligation to another lender, all gone the second it landed on the device.

What turned this into a technical failure rather than just an ethical one is simple: a message deleted off the phone is gone for any app trying to read current SMS content. Some lenders tried to get ahead of this by reading messages as they arrived in real time, catching new SMS as it landed but doing nothing for anything deleted before the app was even installed.

A borrower could walk into a second loan carrying three outstanding obligations elsewhere, with an empty SMS thread and a clean-looking risk profile, all without doing anything more sophisticated than tapping delete a few times before opening the next app. The scoring model wasn’t being outsmarted by some elaborate fraud operation, ordinary people simply wanted to protect themselves.

And so, a lot of lenders treated the SMS deletion problem as a reason to reach deeper into the phone instead of an indication the model needed rethinking. If SMS alone wasn’t giving a complete picture anymore, the response was to pull contact lists too, along with call logs and the full inventory of apps installed on the device. 

Research into digital lending apps operating in markets like Kenya found exactly this pattern playing out at scale, with apps requesting access to SMS content, contact lists, call logs, and installed app data well beyond what any reasonable underwriting process required to make a lending decision.

Contacts became a weapon in their own right. Lenders started using contact lists to identify guarantors without ever asking the borrower to nominate one, and when borrowers defaulted, agents would call straight through to family members, employers, and friends, sometimes to demand repayment on someone else’s behalf and sometimes just to embarrass the borrower into paying faster. 

Very little of this was something a borrower had meaningfully consented to, even where a permissions dialog existed somewhere in the onboarding flow. What started as a reasonable workaround for missing credit data turned into something that looked a lot more like surveillance with a loan attached to it, and it gave the entire category of alternative data a reputation it’s still working to shake off.

Borrowers learned to play defense, App stores drew a line

People adapted the way people always do when they realize they’re being watched. Borrowers learned to leave contact lists sparse or fake, knowing a full address book just meant more people for a lender to harass later if repayment ever slipped. They started running separate SIM cards for separate lenders, since a fresh device profile with no shared history was harder to cross-reference against other apps tracking the same person across different platforms. 

The moment a loan was repaid, the app would come off the phone entirely, partly to reclaim storage and partly because nobody wanted yesterday’s lender lurking in the background reading tomorrow’s messages.

The cycle kept compounding from there. Every defensive move borrowers made forced lenders to reach for more data to compensate, which pushed borrowers to defend themselves more aggressively, which degraded the data lenders were collecting even further than before. 

Eventually this reached a point where the access itself became politically and technically untenable. Google reclassified SMS and call log permissions as dangerous, restricting which categories of apps could even request them, which effectively shut the door on most lending apps reading SMS content the way they had for years.

Apple‘s ecosystem never opened that door in the first place, which meant the entire SMS scoring model was always, structurally, an Android-only phenomenon dependent on a permission system that was ultimately going to get locked down once enough abuse cases piled up against it.

This lockdown was a direct response to the kind of abusive data harvesting I just described, the contact scraping and the location tracking and the installed-app inventories that had nothing to do with assessing whether someone could repay a loan. The platforms shut this down because the industry built around this access had stopped behaving responsibly with the trust it had been given, and SMS scoring specifically paid the price for years of poor judgment by the companies using it.

The quality collapse and the desperate phase

What should have worried lenders more than it did at the time was this: as borrowers got better at managing what these apps could see, the predictive quality of the scoring models started declining, slowly at first and then sharply, leaving lenders running sophisticated algorithms on increasingly compromised data, which is about the worst combination you can build a lending business on. 

This connects to something I wrote about more broadly when looking at AI underwriting risk across developing markets, where I made the point that a model is never neutral and always reflects every decision that went into building it, including which data sources to trust and how much weight to put on them. When the underlying data becomes unreliable because the population being scored has every incentive to manipulate it, no amount of clever feature engineering fixes that problem. 

By the time the quality decline became impossible to ignore, plenty of lenders had already built their entire risk infrastructure around this approach, and ripping it out wasn’t a simple decision to make from a boardroom that had spent years and investor capital defending the model. So instead of stepping back, a lot of players doubled down, pulling even more aggressively on contacts and location and app inventories, hoping that more inputs would somehow compensate for the fact that borrowers had learned to game the core engine feeding the whole system.

This is usually how these stories go, with the honest fix requiring an admission that the original model has limits, and that admission being harder to make than simply adding one more data point and hoping it helps. The result was an industry that, for a stretch of years, looked advanced from the outside while getting worse at the one thing it needed to do, which was separate good borrowers from bad ones with any real consistency.

Default rates didn’t improve the way the marketing suggested they should. Borrower trust eroded gradually. Regulators across multiple markets started paying closer attention to what these apps were doing with the data they collected, and the reputational damage from aggressive contact harassment alone did lasting harm to how digital lending was perceived across the continent, in ways that still color how people talk about loan apps today.

What the rest of alternative data still gets right

It’s worth pausing here to give credit where it’s due, because the SMS story can make it sound like every form of alternative data is tainted, and that isn’t the case. Mobile money and airtime recharge data have continued to perform well as predictive signals, partly because they reflect spending and saving discipline rather than private conversations, and partly because they’re harder for a borrower to manipulate without genuinely changing their financial behavior. 

Utility payment data works on similar logic. Psychometric assessments remain more contested, since they ask a borrower to answer questions designed to infer character traits, and the jury is still out on how well that translates across different cultural and economic contexts. The common thread across the data sources that have aged well is that none of them require reading someone’s private messages or calling their relatives to collect on a debt.

None of this means the broader instinct behind alternative data was wrong. Africa needed a way to assess creditworthiness for people who had never been inside a formal credit system, and phone-based behavioral data carries real predictive value when it’s collected properly and with consent. 

I’ve made the case before that telco data like call patterns, airtime recharge behavior, mobile money activity, and data usage consistency, holds genuine signal because it reflects an economic rhythm that a decent model can read without needing to touch anyone’s private messages. The category was sound from the beginning. What collapsed, specifically within the SMS branch of it, was how the data got collected and who controlled it once it had been collected.

The fix has to start with consent that means something beyond a permissions dialog buried in an onboarding flow nobody reads before tapping accept. It has to involve data the customer can see, understand, and meaningfully control, rather than a black box scraping whatever it can reach the moment an app gets installed on a phone. And it has to come through a channel the borrower doesn’t have unilateral power to sabotage the way they could delete an SMS thread in three seconds flat. 

Telco-held data fits this far better than device-scraped data ever could, since it sits with the network operator rather than on a phone where any borrower with five minutes and a motive can edit the record clean. I laid out a version of how this kind of consent-based telco model could work in practice, and the short version is that it requires the borrower to opt in explicitly, get notified every time their data gets accessed, and retain the ability to revoke that access, none of which the SMS-scraping era ever bothered to build into the system.

This brings to mind something I think about all the time, which is that credit access is foundational to prosperity across the continent, and you don’t get there by building underwriting systems that borrowers are incentivized to defeat from the first day they install the app. You get there by building systems borrowers can trust enough to engage with honestly, which was the entire premise behind pushing for open APIs as the foundation of inclusive credit scoring long before any of us watched the SMS model collapse under its own weight.

What this should have taught the industry

If there’s one thing worth pulling out of this whole experiment, it’s that data quality and data ethics were never separate problems, even though parts of the industry spent years treating them as though they were. Every time lenders pushed further into invasive collection without proper consent, they created a reputational liability and simultaneously degraded the thing they were trying to build, because borrowers will always respond to surveillance with evasion, and evasion is corrosive to exactly the kind of clean, consistent behavioral signal that good underwriting depends on to function.

The lesson isn’t that alternative data fails in Africa as a category because some of it hasn’t, and the parts that have stayed disciplined about consent and scope are still doing useful work in markets across the continent today.

If there’s one thing worth pulling out of this whole experiment, it’s that data quality and data ethics were never separate problems, even though parts of the industry spent years treating them as though they were. SMS scraping failed because it reached too far into a borrower’s private life without giving them any real say in the matter. Contact scraping failed for a different but equally serious reason, exposing third-party information to loan transactions those people were never part of. Both paid for that overreach with the one thing a scoring model can’t survive without, which is data people haven’t been given every reason to falsify. We had ten years to learn those distinctions. I’d rather we didn’t need another ten to put them into practice across the rest of the category.