The typical global organization with operations in Nigeria offers a well-resourced and technically functional hotline for employees to make internal reports about wrongdoing. Trouble is, the country’s laws don’t yet protect such individuals from retaliation. Legal and governance researcher Obongodu Paul Unanam explores what this important distinction means for Western companies operating in the country.
Multinational corporations commonly implement internal reporting infrastructure as a standardized global system. This typically includes a hotline number, a web portal, often managed by a third-party vendor, and a policy document that guarantees confidentiality and assures protection against retaliation. The underlying assumption guiding this architectural approach is that the legal environment in each operating country provides roughly equivalent conditions for its effective functioning. While this assumption may hold weight in jurisdictions like the United States, the United Kingdom, and South Africa, it demonstrably falters in Nigeria.
This critical deficiency often remains invisible within a company’s documented compliance programs. While a Nigerian subsidiary will possess the mandated hotline number, and its employees will technically have the means to access it, the system cannot replicate the essential legal safeguards that transform the act of reporting serious wrongdoing into a rational decision for an employee.
A primary reason for this disconnect is the absence of statutory whistleblower protection law in Nigeria. Although the Nigerian government launched a whistleblowing policy in December 2016, which offered financial incentives ranging from 2.5% to 5% of recovered funds for tips leading to asset recovery, this policy did not establish any legal protection against retaliatory actions. It remains a policy document, not enforceable legislation. Consequently, it cannot guarantee anonymity, compel agencies to act upon reported information, or prevent an employer from terminating the employment of an individual who utilizes the system. A compliance program that fails to acknowledge this fundamental legal gap is not merely incomplete; it actively generates a false sense of security.
Real-World Implications: The Stark Reality for Whistleblowers
The consequences of this legal void are far from theoretical. The case of Yisa Usman, formerly a deputy director at Nigeria’s Joint Admissions and Matriculation Board (JAMB), starkly illustrates the risks faced by those who speak out. Usman reported procurement fraud and administrative irregularities within the agency through official channels. His actions, however, led to his dismissal from his position in July 2023, followed by criminal charges. Usman subsequently reported that police officers attempted to abduct him from his residence in July 2025, even while multiple lawsuits stemming from his disclosures were still pending before the courts. Despite these severe repercussions, Usman was later recognized as the runner-up for the prestigious Ellsberg Whistleblower Award, an international honor named after Daniel Ellsberg, the Pentagon Papers whistleblower. Regrettably, due to the ongoing legal proceedings against him, Usman was unable to travel to receive the award.
Usman’s harrowing experience underscores the documented outcome of a system that incentivizes tips without providing any commensurate legal recourse or protection. Echoing the urgent need for robust legal frameworks, the chairman of Nigeria’s Economic and Financial Crimes Commission (EFCC), Ola Olukoyede, recently appealed to the National Assembly to enact a comprehensive whistleblower protection law. He highlighted that among the 15 member states of the Economic Community of West African States (ECOWAS), only Ghana and Senegal have legislated protections for individuals who report illicit activities.
When a compliance officer at a multinational corporation assures employees within a Nigerian subsidiary that the company’s internal reporting channel is a safe avenue for reporting misconduct, they are making a promise that is not substantiated by the country’s legal landscape. The risk calculus for an employee in Lagos who witnesses procurement fraud differs significantly from that of an employee in Chicago or London. While the reporting channel might be technically anonymous, the law offers no recourse if the company or an associated government agency decides to exert pressure or make the employee’s professional life difficult. The very information that is most valuable to a compliance program is precisely the type most likely to be suppressed in such an environment, where the personal cost of disclosure can be exceedingly high.
The Paternalistic Blind Spot: A Global Compliance Framework’s Local Deficiency
A significant factor shaping compliance thinking regarding markets like Nigeria is an often unacknowledged assumption: that program design is primarily a response to enforcement pressures in the United States or the United Kingdom, and that local legal environments are largely incidental background noise. This perspective carries a corollary that is rarely articulated explicitly: the operational norms in the US or UK are considered the default standard, and any deviation is viewed as a deficiency within the local market rather than a genuine design constraint that the global program must accommodate. The prevailing global compliance framework was largely developed in Washington D.C. and London, and it tends to be exported with the expectation that legal environments elsewhere will eventually align.
This framing is not only intellectually simplistic but also leads to tangible compliance failures. If the gap in Nigeria is treated as a temporary local anomaly rather than a structural characteristic of the operating environment, organizations will fail to redesign their programs to adequately address it. They will deploy their standard infrastructure, perhaps document the deficiency in a risk register, and then move forward without implementing substantive changes. In this scenario, the employee in the Nigerian subsidiary who witnesses wrongdoing and remains silent is not failing the compliance program; rather, the compliance program is failing them by not providing the necessary protection to encourage reporting.
Developing Compensating Controls: Designing for the Nigerian Reality
The absence of explicit whistleblower protection laws in Nigeria does not render the implementation of an effective compliance program impossible. However, it necessitates a design approach that is tailored to the specific operating environment, rather than being solely dictated by the familiar standards of headquarters.
Firstly, any compliance program operating in Nigeria must be transparent and honest about the capabilities and limitations of its reporting channels. Training materials and internal communications directed at Nigerian employees should refrain from perpetuating standard language regarding legal protection against retaliation, as such protection does not exist within Nigerian law. To assert otherwise is not merely inaccurate; it is a misrepresentation that erodes credibility, especially when an employee who relied on such assurances subsequently faces adverse consequences.
Secondly, the compliance program should actively monitor the legislative landscape. A whistleblower protection bill has been introduced in Nigeria’s National Assembly on multiple occasions. While it has not yet been enacted, the possibility of its future passage remains. A Chief Compliance Officer (CCO) overseeing Nigerian operations should diligently track these developments and understand the implications of a statutory protection regime for their program’s design and implementation.
Thirdly, reliance should not be placed on a single reporting channel. In environments where the domestic legal framework offers no protective backstop, the efficacy of external reporting mechanisms becomes paramount. Some multinational corporations have adopted anonymous reporting pathways that route directly to international compliance infrastructure, bypassing local management. This strategy is a direct response to the documented reality of local retaliation risks.
Fourthly, proactive due diligence is essential, preceding rather than following an investigation by the Economic and Financial Crimes Commission (EFCC). The EFCC reported a significant number of convictions – 4,111 in 2024 alone – and substantial asset recoveries, indicating that Nigerian enforcement actions are not merely hypothetical. If a subsidiary’s internal reporting infrastructure cannot reliably surface procurement concerns from within, the organization is effectively operating blind in an environment where the enforcement consequences of such blindness are well-documented and recent.
The Unasked Due Diligence Question: Identifying Truly Functional Reporting
Standard third-party due diligence questionnaires for Nigerian operations typically inquire about anti-bribery policies, training records, and acknowledgment of the code of conduct. However, a critical question that is almost universally omitted is: "What happens to an employee at a Nigerian counterparty who reports internally?" This question is crucial for discerning whether a reporting infrastructure is genuinely functional or merely ceremonial.
A counterparty that lacks a clear answer to this question, or whose response consists of a policy document devoid of legal enforceability, is a counterparty whose internal reporting environment mirrors the structural limitations of the national legal framework. Historically, kickback arrangements in Nigerian federal contracting have often transacted through intermediaries who are several steps removed from the primary counterparty. If no individual within this chain has a tangible, protected incentive to report malfeasance, such arrangements are likely to persist unchallenged.
The solution to this complex challenge is not inherently complicated. It requires a fundamental acknowledgment that compliance infrastructure designed for a legally protected environment cannot be seamlessly transferred to one where such protections are absent. It necessitates a candid assessment of the actual risks an employee in a Nigerian subsidiary faces when utilizing the company hotline, followed by a program design that honestly addresses those risks.
As Yisa Usman continues his legal battles and the whistleblower protection bill remains pending in the Nigerian National Assembly, the threat of an EFCC inquiry looms. For global organizations operating in Nigeria, the time to confront these realities and redesign their compliance strategies is now. The efficacy of their reporting mechanisms, and ultimately their exposure to significant legal and reputational risks, hinges on their willingness to move beyond standardized global policies and embrace the nuanced realities of the local operating environment.
