Skip to content

Governance, Risk & Compliance (GRC)

Overview

Your partners in risk resilience, fortifying governance and driving regulatory excellence.

Aluko & Oyebode’s Governance, Risk & Compliance (GRC) practice safeguards leading corporations, small and medium sized enterprises, financial institutions, and multinationals against regulatory risk, reputational damage, and enforcement exposure.

We design and implement comprehensive GRC frameworks that strengthen corporate governance, enhance board effectiveness, and ensure compliance across critical areas including AML/CFT, sanctions screening, anti-bribery programs, ESG governance, and regulatory reporting. Our clients span banks, insurers, capital markets participants, telecommunications operators, energy companies, and global multinationals navigating Nigeria’s high‑risk regulatory terrain.

What sets us apart is our ability to combine deep regulatory expertise with hands‑on implementation capability. We build compliance programs that work in Nigeria’s operating environment, training personnel, conducting audits, managing regulatory relationships, and defending enforcement actions when necessary. As regulatory scrutiny intensifies, the companies that thrive are those with robust, proactive GRC capabilities. We help our clients build exactly that.

The straightforward reason clients choose Aluko & Oyebode is depth and credibility: we pair market‑leading Nigerian regulatory insight with cross‑border execution experience on sensitive, high‑stakes mandates. That combination makes us the trusted partner of choice for organizations determined to protect value and lead with confidence in Nigeria’s regulatory landscape.

Services

We advise on AML/CFT frameworks, KYC/CDD and enhanced due diligence design, conduct independent assurance reviews, and support engagements with enforcement authorities to resolve red flags and remediation obligations. We advise on Nigeria’s AML Act 2022 and FATF standards post-Grey List removal. 

We design, benchmark, and refresh governance frameworks, charters, and committee mandates; advise on directors’ duties and conflicts; run board and C-suite training; and align governance with listing rules, investor stewardship expectations, and Nigerian regulatory prescriptions.

We serve as a licensed Data Protection Compliance Organisation (DPCO), deliver audits and gap assessments, implement technical and organizational measures, act as DPO, and guide clients through NDPC investigations and cross-border transfer strategies.

We build risk taxonomies, heat maps, and controls testing protocols, calibrating appetite and tolerances. We assess regulatory capture risks during policy or regulator transitions and embed escalation, disclosure, and remediation pathways.

We translate ESG principles into governance, disclosure, and operational controls; align with UN/IFC/OECD frameworks; and support supply-chain due diligence, sustainability reporting, and board oversight of non-financial risks.

We architect end-to-end compliance programs that operationalize Nigerian laws and international standards, including anti-bribery/anti-corruption, sanctions, export controls, financial crime prevention, ESG codes, and third-party risk management.

We secure clearances and approvals across financial services, telecoms, energy, and other regulated sectors; coordinate pre-notifications; and manage multi-jurisdictional filings with clear sequencing, documentation, and issue management.

We manage statutory and regulator-imposed reporting across regulated sectors, design the monitoring frameworks that follow consent orders, settlements and behavioural remedies, and keep clients in good standing with the relevant regulator long after the matter has resolved.

We establish secure, multi-channel reporting systems, triage protocols, investigation playbooks, and anti-retaliation safeguards, and we train teams to strengthen early detection and organizational learning loops.

We run GRC workstreams on M&A, financings, listings, and joint ventures, covering anti-corruption diligence, sanctions screening, disclosure controls and procedures, and integration of governance and compliance post-close.

Selected Experience

Advised Allianz on the combination of certain Allianz and Sanlam businesses into a South African incorporated joint venture, including Nigerian assets, governance integration, regulatory clearances, and disclosure alignment.

Advised a Brookfield-led consortium on the approximately £2.2 billion take-private of Network International Holdings Plc, a leading payments provider, Nigeria regulatory, competition interface, and compliance workstreams.

Advised Access Holdings and Coronation Group on their strategic partnership with Safaricom and M‑PESA Africa, regulatory strategy and cross-border mobile money compliance for remittance corridors.

Acted as Lead Nigerian Counsel to Guaranty Trust Holding Company Plc on LSE listing and international capital raise, governance, disclosure controls, and Nigerian regulatory compliance.

Advised Africa Finance Corporation on its debut US$500 million hybrid bond, issuer governance, disclosure, and regulatory engagement consistent with Nigerian and cross-border standards.

Client Quotes

Key Contacts

Adeolu Idowu 1
Adeolu Idowu
Co-Managing Partner
image 879
Sumbo Akintola
Partner
Olagoke Kuye 1
Olagoke Kuye
Partner

See More

Awards and Accolades

Thought Leadership

March 2025
US Executive Order Suspends Enforcement of the Foreign Corrupt Practices Act (FCPA): Implications for Nigeria’s Business Landscape and Anti-Corruption Measures
February 2025
Aluko & Oyebode Contributes to the Inaugural Edition of NDPC’s Journal
April 2025
Compliance Analysis: Considerations on the Updated Registration of Data Controllers and Processors of Major Importance and All Matters Connected Therewith 2024
September 2025
NDPC-GAID Takes Effect on 19 September – Is Your Organisation Prepared?
August 2025
The Nigeria Data Protection Commission Commences Sector-By-Sector Investigation on Companies
check

Registration Successful

Please check the confirmation email sent to your email address

image 995

Google Calendar

icons8-outlook-calendar 1

Outlook.com

image 996

Apple Calender

Registration Successful

You’re all set. Your registration for the event has been received and confirmed. We’re excited to have you join us.

Governance, Risk & Compliance (GRC)