NIGERIAN AUDITORS WARN CYBER FRAUD AND AI MISUSE ARE CREATING NEW RISKS FOR INSTITUTIONS

By Iroyin Yoruba Television

The Institute of Internal Auditors Nigeria has warned that the rapid adoption of digital technology and artificial intelligence is creating new cybersecurity and financial-fraud risks for Nigerian organisations, urging institutions to strengthen their internal controls before vulnerabilities are exploited.

The warning was issued on Friday, October 2, 2026, during the Institute of Internal Auditors Nigeria 2026 Conference, where professionals examined the changing risk environment facing organisations as technology becomes increasingly central to business operations.

The conference focused on cybersecurity, artificial intelligence, digital transformation and global volatility, bringing together internal auditors and other professionals to examine how organisations can prepare for threats associated with increasingly technology-driven operations.

Chief Executive Officer of IIA Nigeria, Don Umeha, said the movement from manual systems to technology-driven operations had produced significant gains in productivity, accuracy and speed but had simultaneously created new vulnerabilities.

According to him, organisations are increasingly exposed to risks involving weak passwords, intercepted transactions, manipulated records and other weaknesses in digital systems.

He warned that a single vulnerability could result in financial losses and disrupt wider organisational operations.

The warning comes as Nigerian businesses, government institutions and other organisations increasingly rely on digital platforms for financial transactions, communication, record keeping, customer management and other activities.

Digital transformation has changed the way organisations operate.

Transactions that once required physical documentation can now be completed electronically.

Records that were previously stored in paper files can be held in cloud systems and databases.

Employees can work remotely and access corporate systems from different locations.

Customers can make payments through mobile applications and other electronic channels.

These changes can improve efficiency, but they also create additional points at which criminals can attempt to gain unauthorised access.

Cybercriminals can target passwords, devices, payment systems, email accounts and databases.

A successful attack can result in financial losses, exposure of sensitive information or disruption to an organisation's operations.

The expansion of artificial intelligence introduces another layer of complexity.

AI systems can analyse information, generate content, automate tasks and assist with decision-making.

Organisations are increasingly incorporating such tools into their daily operations.

However, AI systems can also be misused by criminals or deployed without adequate controls.

Umeha warned that the rapid expansion of AI was creating additional vulnerabilities, particularly when organisations adopt the technology without establishing appropriate safeguards.

The issue is not that artificial intelligence itself is inherently harmful.

Rather, the risk can arise from how the technology is designed, deployed and controlled.

An organisation that introduces an AI system without understanding what information it can access may unintentionally expose sensitive data.

Similarly, employees who use AI tools without appropriate policies could upload confidential information into systems that have not been approved by their organisations.

AI-generated material can also be used in fraudulent activities.

Criminals can use increasingly sophisticated digital tools to create convincing messages, manipulate information or automate aspects of cybercrime.

This can make it more difficult for individuals and organisations to distinguish legitimate communications from fraudulent ones.

The IIA Nigeria conference therefore placed emphasis on preventive controls.

Umeha argued that organisations should not wait until a cyberattack, financial loss or data breach occurs before identifying weaknesses.

Instead, institutions should establish systems capable of identifying vulnerabilities before they are exploited.

That approach represents a shift from reactive risk management to preventive risk management.

Traditional auditing has often focused on reviewing transactions and processes after they have taken place.

Auditors examine records, identify irregularities and determine whether established procedures were followed.

But the increasing use of technology means that organisations need stronger systems for identifying risks while operations are taking place.

Digital systems can generate enormous quantities of information.

Transaction patterns can be monitored automatically.

Unusual activity can potentially be identified more quickly than through manual reviews.

AI and data-analysis tools can also assist auditors in examining large datasets for anomalies.

However, those same technologies require appropriate controls.

If an organisation relies on automated systems without understanding their limitations, errors or vulnerabilities could remain undetected.

The conference therefore highlighted the need for internal auditors to understand emerging technology rather than treating digital systems as the exclusive responsibility of IT departments.

Umeha said auditors must develop the skills and foresight required to understand emerging threats and changing operational realities.

That means internal-audit professionals increasingly need knowledge of cybersecurity, artificial intelligence, data governance and digital systems.

The traditional role of checking historical transactions is becoming less sufficient in an environment where many transactions and decisions are processed electronically.

An auditor who understands how digital systems operate can potentially identify weaknesses that might otherwise remain hidden.

For example, an auditor could examine how user permissions are assigned, whether sensitive data is properly protected and whether automated systems are being monitored.

Auditors can also examine whether organisations have procedures for responding to cyber incidents.

A strong cybersecurity system does not eliminate all risk.

Instead, it attempts to reduce the probability of successful attacks and limit the damage if an incident occurs.

Organisations therefore need both preventive and response mechanisms.

This includes controlling access to systems, protecting passwords, monitoring unusual activity, maintaining secure backups and establishing procedures for responding to suspected breaches.

Employee awareness is also important.

Many cyberattacks begin with attempts to deceive individuals into providing information or clicking malicious links.

Training employees to recognise suspicious communications can therefore form an important part of an organisation's security strategy.

The growing sophistication of AI-generated communications could make that task more difficult.

Fraudsters can potentially create highly convincing messages that appear to come from colleagues, customers or senior executives.

This increases the need for organisations to establish verification procedures for sensitive transactions.

For example, financial requests involving large transfers may require confirmation through an independent communication channel rather than relying solely on an email or message.

Such controls can reduce the possibility that an employee will act on a fraudulent instruction.

The conference also examined the implications of artificial intelligence for the internal-audit profession itself.

AI can assist auditors by processing large volumes of information and identifying patterns that may require further examination.

Instead of manually reviewing every transaction, auditors can use technology to identify unusual transactions and focus their attention on higher-risk areas.

This can potentially improve efficiency.

However, auditors must also understand the limitations of automated analysis.

An AI system may identify a pattern without understanding the context behind it.

It may also produce inaccurate conclusions if the underlying data is incomplete or unreliable.

Human oversight therefore remains important.

The use of AI in auditing should complement professional judgement rather than eliminate it.

Auditors need to understand how automated systems arrive at their results and how those results should be interpreted.

This is particularly important when AI is used in high-impact decisions.

An organisation that relies on an automated system to identify fraud, approve transactions or assess customers must ensure that the system is properly governed.

The system's inputs, outputs and decision-making processes should be subject to appropriate oversight.

Data quality is another major consideration.

AI systems depend heavily on the data used to train or operate them.

If the data contains errors, biases or gaps, the system may produce unreliable results.

Organisations therefore need processes for maintaining accurate and secure data.

The growth of digital operations has also increased the importance of data governance.

Businesses hold information about customers, employees, suppliers and other stakeholders.

Protecting that information is both a cybersecurity responsibility and a governance issue.

A data breach can expose individuals to fraud or identity theft while also creating financial and reputational consequences for the organisation involved.

The IIA Nigeria warning therefore comes at a time when digital trust is becoming increasingly important to Nigeria's economy.

Electronic payments, online banking, e-commerce and digital government services are expanding.

More Nigerians are using smartphones and internet-based platforms to conduct everyday activities.

As digital adoption increases, the security of the systems supporting those activities becomes increasingly important.

Financial institutions face particularly significant risks because they manage large volumes of electronic transactions.

Fintech companies also process sensitive customer information and financial data.

Other sectors, including healthcare, telecommunications, education and manufacturing, increasingly depend on connected digital systems.

A cyberattack against any of these sectors can disrupt services.

The consequences can extend beyond the organisation directly targeted.

For example, an attack on a company providing critical digital infrastructure could affect customers and other businesses that depend on its services.

This interconnectedness means cybersecurity is increasingly an organisational and national issue rather than simply an IT department concern.

The IIA Nigeria conference also highlighted the need for stronger regulation of artificial intelligence.

Umeha called for adequate rules and appropriate penalties to deter practices that cause financial losses or violate ethical standards.

AI regulation remains a developing area in Nigeria and internationally.

Governments are attempting to balance technological innovation with safeguards against misuse.

Too little oversight can allow harmful applications to develop without adequate controls.

Excessively restrictive rules could, depending on their design, create challenges for innovation and adoption.

The challenge is therefore to develop frameworks that support responsible use while addressing genuine risks.

Umeha also urged young Nigerians to use AI for productive and innovative purposes rather than fraud or other unethical activities.

The comment reflects the growing accessibility of advanced digital tools.

AI systems that were once available mainly to specialised organisations can now be accessed by individuals through consumer applications.

That accessibility creates opportunities for education, entrepreneurship and innovation.

It also means that harmful uses can become easier to carry out.

The response therefore requires both technical controls and public awareness.

Young technology users need opportunities to develop legitimate skills and build businesses using AI and other digital tools.

At the same time, organisations need systems capable of detecting and preventing fraudulent activity.

The conference's focus on internal auditing reflects the role that professional oversight can play in that process.

Ibukun Beecroft, Chair of the IIA Nigeria board, said the changing risk environment required internal auditors to assume a more strategic role.

She identified AI, cybersecurity, environmental, social and governance issues, digital transformation and global volatility as emerging challenges requiring greater professional preparedness.

The changing environment means auditors may need to understand risks that were not central to their profession in previous decades.

Cybersecurity is one example.

An internal auditor does not necessarily need to become a cybersecurity engineer, but must understand enough about digital risks to ask relevant questions and assess whether an organisation has adequate controls.

AI presents a similar challenge.

Auditors need to know where AI is being used, what information it can access, how its outputs are reviewed and what safeguards exist against misuse.

The role also involves examining accountability.

Organisations need to know who is responsible for decisions made with the assistance of AI.

If an automated system produces an incorrect result, there should be procedures for identifying the error and correcting it.

If a cyberattack occurs, the organisation should know who is responsible for activating its incident-response plan.

These governance questions become increasingly important as technology becomes more deeply embedded in business processes.

The conference's warning also highlights the economic consequences of cybercrime.

Financial losses can affect the ability of businesses to invest, employ workers and expand.

A serious cyberattack can force an organisation to suspend operations while systems are restored.

The cost may include lost revenue, recovery expenses, legal costs and potential regulatory penalties.

Customers may also lose confidence if their information is compromised.

For smaller Nigerian businesses, the consequences can be particularly difficult because they may have fewer resources available for cybersecurity.

Small businesses often rely on basic digital tools and may not have dedicated security teams.

They can nevertheless hold valuable customer information and financial accounts.

Cybersecurity awareness and affordable security tools are therefore important across the entire business ecosystem.

The IIA Nigeria warning is relevant to both large institutions and smaller organisations because many vulnerabilities arise from basic weaknesses.

Weak passwords, poorly controlled access and unverified transactions can create opportunities for criminals regardless of the size of an organisation.

Improving security does not always require sophisticated technology.

Clear procedures, staff training, regular system updates and appropriate access controls can reduce common risks.

More advanced tools can then be used to monitor systems and identify sophisticated attacks.

The growing use of AI may also provide opportunities to strengthen cybersecurity.

AI can assist with detecting unusual patterns, analysing large quantities of security information and identifying potential threats.

But organisations must ensure that AI-based security systems themselves are properly protected.

An attacker who compromises a security system could potentially manipulate its outputs or prevent it from detecting malicious activity.

This creates a continuing cycle in which new technology produces both new defensive capabilities and new risks.

Nigeria's technology sector is therefore likely to face increasing demand for cybersecurity professionals and services.

Businesses need people capable of understanding both technology and organisational risk.

Universities, training institutions and technology programmes can help build that workforce.

The development of local cybersecurity expertise can also reduce dependence on external providers and strengthen the country's broader digital resilience.

The IIA Nigeria conference's message is ultimately that technological progress needs to be accompanied by stronger governance.

Digital transformation can improve productivity and create new opportunities.

Artificial intelligence can support research, business development, automation and innovation.

But those benefits depend on organisations understanding and controlling the risks associated with the technology.

The challenge is not to reject technological development but to ensure that institutions are prepared for the vulnerabilities it creates.

For Nigerian organisations, that preparation increasingly includes cybersecurity policies, AI governance, staff training, internal controls, data protection and continuous monitoring.

The IIA Nigeria has urged institutions to move toward earlier detection of vulnerabilities rather than waiting for financial losses or cyber incidents to expose weaknesses.

As Nigeria's digital economy continues to expand, the ability to protect digital systems will become increasingly important.

The warning issued at the 2026 conference therefore comes at a significant time for the country's technology ecosystem.

Artificial intelligence and digital transformation are creating new opportunities for businesses and institutions, but they are also changing the nature of the risks those organisations must manage.

For auditors, the challenge is to understand those risks before they become crises.

For management teams, it is to establish controls that can detect and prevent vulnerabilities.

For technology professionals, it is to build systems with security and responsible use in mind.

And for users, it is to understand that digital convenience comes with the responsibility of protecting access to sensitive information.

The IIA Nigeria has called for stronger preventive controls, better professional preparedness and appropriate regulation as the country moves deeper into an AI-driven digital economy.

The message from the conference is clear: technological progress can deliver significant benefits, but institutions must strengthen their defences at the same pace as their digital transformation.