M2PBlog

Explore the Latest Thinking on Fintech Innovation

Nigeria NDPA & Automated Loan Decisions: What Lenders Need

Lending
Oct 07, 2026|5 min read
Nigeria NDPA & Automated Loan Decisions: What Lenders Need

Kenya and Nigeria are two of Africa's busiest digital lending markets. The Central Bank of Kenya reports that licensed digital lenders had disbursed KSh 150.56 billion across more than 8.37 million loans by May 2026. As volumes grew, both countries tightened the rules on two fronts. They brought digital lenders under formal licensing, and they passed data-protection laws that limit how far an algorithm can decide a loan without a person involved.

For a lender using AI in underwriting, that creates a clear test. A human must remain accountable for material decisions. The lender must be able to explain each outcome. And a record must exist that a regulator or borrower can ask to see. This post covers what each market requires and how an origination platform can be built to meet it.

Kenya: licensed lenders, limited automation

Kenya's Central Bank (Digital Credit Providers) Regulations, 2022 put digital lenders under CBK licensing. The CBK assesses each applicant's business model, consumer-protection practices, and the suitability of its owners and managers. By mid-2026 it had licensed over 250 providers from more than 800 applications. The regime targets expensive borrowing, abusive collection practices, and misuse of borrowers' personal data.

The Data Protection Act 2019, enforced by the Office of the Data Protection Commissioner (ODPC), adds two provisions that matter for AI-led credit:

  • Section 35: People have the right not to be subjected to a decision based solely on automated processing, including profiling, when it significantly affects them. A loan approved or declined with no human involvement falls squarely within this.

  • Section 31: A data protection impact assessment is required before high-risk processing. ODPC regulations treat automated decision-making that determines access to services as high-risk.

Enforcement is real. The ODPC has issued 184 compensation orders, 134 enforcement notices, and 20 penalty notices since the Act came into force. Digital lenders have been penalised over consent and personal-data handling.

Nigeria: a conduct crackdown and a data law with teeth

Nigeria divides oversight between two regulators.

On conduct, the Federal Competition and Consumer Protection Commission (FCCPC) issued its Digital, Electronic, Online or Non-Traditional Consumer Lending Regulations in 2025. They took effect on 21 July 2025, with a compliance deadline of 5 January 2026. Any lender operating through an app, website, or other non-traditional channel must register with the FCCPC. The rules target abusive recovery, unauthorised access to borrower data, and predatory pricing. The Federal High Court in Lagos upheld them in July 2026 after a trade body challenged the FCCPC's authority.

On data, the Nigeria Data Protection Act 2023 created the Nigeria Data Protection Commission (NDPC). Section 37 gives individuals the right not to be subject to a solely automated decision with legal or similarly significant effects, plus the right to human intervention and to contest the outcome. The Act also expects lenders to tell borrowers when automated decision-making or profiling is used. A DPIA is mandatory before high-risk processing.

The NDPC enforces actively. It fined Fidelity Bank ₦555.8 million in August 2024 for processing customer data without valid consent. In June 2026 it announced a review of the Act focused on AI, robotics, and big data.

Four expectations that apply in both markets

The regulators and statutes differ, but their expectations of AI in credit are very similar.

  1. A person stays accountable. A credit approval or rejection is the clearest example of a decision that significantly affects someone. Human oversight is how lenders stay on the right side of both laws.

  2. Decisions are explainable. If a borrower can contest an automated outcome, the lender must show what drove it.

  3. High-risk processing is assessed and documented. A DPIA presumes the lender can describe how its system uses data and reaches a result.

  4. The evidence exists. Enforcement in both markets turns on consent records, processing records, and audit trails. A lender that can't produce them can't prove compliance, however good its model is.

How M2P's Loan Origination System supports these expectations

M2P's AI-orchestrated Loan Origination System runs digital, branch, embedded, and partner-led origination on one platform. Its configurable Business Rules Engine (BRE) handles credit decisioning, supported by AI agents for documents, fraud, financial analysis, scoring, and credit appraisal memos (CAMs). Here is how that design maps to the four expectations.

What regulators expect

How the M2P LOS supports it

A human stays accountable

AI agents cut manual effort and turnaround across documents, fraud checks, financial analysis, and CAM generation, while approvals, policies, and accountability stay with the business. Straight-through workflows carry multi-level approvals and deviation management, and the Case Manager routes exceptions to people.

Explainable decisions

The BRE produces explainable decision outputs, with risk-based pricing and custom scorecards. The Credit Scoring Agent uses explainable AI, and the Policy Compliance Agent validates cases against internal credit policy and flags deviations with auditable outcomes.

Documented high-risk processing

Rules, scorecards, and pricing logic are configured explicitly, and the BRE supports back-testing against historical portfolio data. Lenders can describe and test how decisions are made before go-live, which is the groundwork a DPIA needs.

An audit trail that holds up

The BRE supports versioning and auditability for controlled policy enforcement. Case Manager keeps full audit trails with SLA and turnaround monitoring, and role-based dashboards and 100+ configurable MIS reports show decisions, deviations, and policy performance.

Controlled data handling

75+ pre-integrated APIs cover KYC, banking, bureau, documents, payments, and fraud services. M2P holds ISO 27001, ISO 22301, and PCI DSS certifications. [Product team to confirm deployment and data-residency options for Kenya and Nigeria.]

The design principle is that AI supports the decision and the business owns it. The Document Intelligence, Bank Statement Analyser, Financial Analysis, and Fraud Detection agents do the preparatory work, such as classifying documents, parsing statements, and flagging tampering and velocity anomalies. Credit and risk teams then decide within policy. That division is what the automated-decision rules in both countries push lenders toward.

The record matters most when a regulator or borrower asks for it. Because decisions run through a governed rules engine and exceptions pass through a managed case workflow, the evidence is created as the loan moves through origination. It doesn't have to be rebuilt afterwards.

Preparing for a Kenya or Nigeria launch

A few questions are worth settling early:

  • Local data sources: Identity documents, credit bureaus, and bank or mobile-money statements differ by market. Plan the integration layer first, since this is where most localisation effort goes.

  • Human review points: Decide which decisions (declines, high-value loans, borderline scores) must go to a person, and configure them as explicit rules.

  • DPIA readiness: Document data inputs, scoring logic, and exception handling before launch, not after the first regulatory query.

  • Cross-border data flows: Both countries attach conditions to moving personal data abroad. Lenders using externally hosted AI models should confirm where borrower data goes and on what basis.

  • Consent and notice: Make sure borrowers are told when automated processing or profiling is involved, and that consent records are retrievable.

Where the rules are heading

Neither regulator has finished. Nigeria has said it will update its data law to address AI directly, and Kenya's ODPC has signalled closer scrutiny of automated decision-making. The rules on how machines may decide loans are becoming more explicit, and enforcement is already live.

For lenders, the safest path is governed, explainable decisioning that keeps people in control. That meets today's rules and leaves room for what both regulators are drafting next.

Planning to lend in Kenya or Nigeria? Talk to M2P about how our Loan Origination System can bring explainable, auditable credit decisioning to your lending operations. Get in touch →

Looking for something specific? Let’s Connect