back to top

SILENT GUARDIANS: The Unremarked Role of IT Auditors

SILENT GUARDIANS: The Unremarked Role of IT Auditors

Date:

By Christian C. Ekeigwe      

While economists debated and regulators scrambled over the sudden implosion of banks, a small, unheralded community of IT audit pioneers performed a service indispensable to the survival of Nigeria’s financial system—and its economic sovereignty.

On 16 January 1998—the “Mass Burial” day—the Central Bank of Nigeria simultaneously revoked the licences of twenty-six banks. Thirty-four institutions were technically insolvent; depositors ruined; the sector convulsed. Yet the deepest breach was invisible to the public eye: it was unchecked cybercrime.

Racing to computerise through the late 1980s and 1990s, Nigerian banks unwittingly created an unguarded attack surface. Internal control and audit departments possessed no methodology for penetrating the interiority of computerised systems, they were auditing merely around the computer. This opacity proved catastrophic. IT personnel lacked strong system security hygiene. Our team often detected default passwords on central servers hosting billions in customer deposits.

This systemic blindness was pervasive. The Chief Inspector of one of Nigeria’s Top 3 banks candidly confided that his auditors were completely blind inside the computer, a complaint echoed by the Committee of Chief Inspectors industry-wide at the time. Without technical illumination, governance was operatively blind, labouring in the obscurity of systems whose interiority it could neither enter nor interrogate. What society observed as sudden bank implosions was actually the eruption of computer frauds accumulating unseen as capital funds and customer deposits evanesced without accountability.

The instrument of illumination was the body of IT audit expertise that I cultivated and diffused across Nigeria’s professional community, with proof-of-concept IT audit laboratory, equipping auditors to penetrate computerised systems with digital forensic rigour. Within this discipline, Audit Command Language (ACL) enabled the interrogation of 100 percent of an institution’s transactions—eschewing sampling for absolute visibility. Deployed at a Top 3 bank by EDP Audit & Security Associates, our team detected hundreds of millions in hidden irregularities, enabling the bank to recover over US$110 million—an engagement unprecedented in Nigerian banking history.

The reverberations altered the financial landscape. Major banks acquired ACL and engaged EDP Audit & Security Associates urgently, shifting the paradigm from auditing around the computer to auditing decisively through it. Consequentially, the Central Bank of Nigeria and the Nigeria Deposit Insurance Corporation engaged us to train their internal auditors and bank examiners. The logic was irrefutable: examiners who cannot see inside the computer cannot credibly supervise institutions whose entire operations run within it.

As this expertise proliferated through ISACA certifications and EDP Tecknowledge programmes and IT audit labs, its institutional consolidation reached the summit of Nigeria’s accountancy establishment. Appointed founding Chairman of the inaugural IT Committee of the Institute of Chartered Accountants of Nigeria (ICAN), I ensured that technology competence became a structural obligation of the profession. That every member of that inaugural Committee—save the ICAN Registrar—was a certified IT auditor and ISACA member demonstrates that IT auditors galvanized technology literacy in the local profession.

I ideated a program I called Technology Competence Initiative by which ICAN mandated IT literacy for every newly inducted chartered accountant. Armed with relevant technology literacy, IT auditors mapped control architectures, disrupted cybercriminals, and minimised systemic losses. The sector stabilised and the economy breathed, yet no journalist recognised this quiet act of nation-guarding. History owes that acknowledgment to IT auditors.

Throughout my pioneering endeavour, I animated my advocacy with a mantra of deceptive simplicity: Bridging the Knowing-Doing Gap, borrowed from the title of a book. It embodies the conviction that theoretical knowledge and operational competence must be discharged in concert to achieve praxis. Three decades later, I am invoking this same refrain for artificial intelligence: auditors must understand AI architectures, training data, and decision logic sufficiently to penetrate their interiority. An AI system that lacks auditability cannot be governed. In the era of algorithmic governance, the knowing-doing gap is a systemic crisis in formation.

What Nigeria’s financial infrastructure gained was not merely fraud detection, but the structural conditions under which corporate malfeasance becomes progressively harder to sustain. IT auditors reconfigured the architecture of institutional accountability, embedding IT audit discipline that regulatory examination previously lacked.

The ISACA Lagos Chapter—marking its thirtieth anniversary this August 2026—stands as the most enduring institutional expression of this commitment. By equipping Nigeria’s first generation of certified IT auditors, ISACA enabled an act of critical nation-building: reconstructing trust in a collapsed financial system and fortifying sovereign infrastructure. To ISACA, financial governance in Nigeria owes a debt no balance sheet can render—the debt of a discipline not merely taught, but lived.

The solution today remains unchanged: not raw technological acquisition, but deliberate, disciplined professional transformation. Digital trust is not accrued by virtue of technology investments; it is earned by those who refuse to remain outside the machine when governance trust demands entering its interiority.

Audit is Trustworthy, Not Perfect.

Christian C. Ekeigwe, FCA, CPA (Mass.), CISA, is the pioneer of IT auditing in Nigeria, Founder of EDP Audit & Security Associates and its IT Audit Laboratory, and Founder of the ISACA in Nigeria. He served as Pioneer Chairman of the inaugural ICAN IT Committee and designed the Technology Competence Initiative (TCI), by which ICAN mandated IT literacy for all newly qualified accountants.    

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Subscribe

Popular

More like this
Related

China Chengxin International Credit Rating Affirms Afreximbank’s AAA/Stable Rating for Second Consecutive Year

The CCXI affirmation follows S&P Global Ratings’ assignment earlier...

Africa’s Next Financial Decade Will Be Decided in the Classroom

As digital assets edge toward everyday use the way...

WIMBIZ Celebrates 25 Years, Invites Women to Join Leadership Community

Women in Management, Business and Public Service (WIMBIZ) is...