
REGULATORY GOVERNANCE IN THE NIGERIAN COMMUNICATIONS INDUSTRY: AN APPRAISAL OF THE 2025 NCC GUIDELINES
This article examines the Nigerian Communications Commission's Guidelines on Corporate Governance for the Communications Industry 2025 as a shift from traditional regulation to regulatory...
Abstract
This article examines the Nigerian Communications Commission's Guidelines on Corporate Governance for the Communications Industry 2025 as a shift from traditional regulation to regulatory governance, where compliance is embedded within corporate governance and enterprise risk management. It argues that, when read alongside the Amended Internet Code of Practice 2026 and the Guidelines for Disconnection of Communications Operators 2025, the Guidelines establish an integrated regulatory framework that extends governance responsibilities to boards, management, and internal control systems. The article analyses the implications of Board oversight, regulatory reporting, data integrity, interconnection governance, and consumer protection, and considers the broader impact of the framework on regulatory certainty, innovation, and investment. It concludes that regulatory compliance in Nigeria's communications industry is increasingly a strategic governance function requiring organizational integration rather than a standalone legal obligation.
INTRODUCTION
The Nigerian communications industry is no longer regulated solely through licences, tariffs and technical standards. Increasingly, the regulator is looking beyond what telecommunications companies do and examining how they are governed, how they manage regulatory risk, how they generate and preserve data, and how their internal systems respond to obligations imposed by law and regulation.
This development is particularly evident in the Nigerian Communications Commission’s (“NCC” or the “Commission”) Guidelines on Corporate Governance for the Communications Industry 2025 (“2025 Guidelines”). The Guidelines are made pursuant to section 70 of the Nigerian Communications Act 2003 (“NCA”) and establish sector-specific governance expectations for communications licensees.
The significance of the 2025 Guidelines, however, extends beyond corporate governance in its conventional sense. When read alongside the NCC’s regulatory framework on Internet governance and interconnection, they reveal an increasingly integrated model of regulation in which responsibility for regulatory outcomes is progressively internalised by licensees.
This article considers the 2025 Guidelines not merely as a corporate-governance instrument, but as part of a broader shift towards regulatory governance; a model under which Boards, management, compliance functions, technology teams and other internal stakeholders are expected to embed regulatory requirements into the day-to-day operation of the business.
The central proposition is straightforward: for communications businesses, regulatory compliance is increasingly becoming part of corporate governance and enterprise risk management rather than a discrete legal or regulatory function.
2. THE REGULATORY GOVERNANCE LANDSCAPE
2.1 From regulation to regulatory governance
Traditional regulation generally focuses on establishing rules and enforcing compliance with those rules. Regulatory governance is broader. It concerns the structures, processes, controls and institutional arrangements through which regulated entities are expected to anticipate, manage and demonstrate compliance with regulatory requirements.
This distinction is particularly relevant to the communications industry because telecommunications and digital services involve risks that cut across conventional corporate functions. Network reliability, spectrum use, interconnection, consumer protection, data integrity, cybersecurity, service quality and technological innovation all carry regulatory implications.
The 2025 Guidelines reflect this wider conception of governance. Their stated purpose is to promote governance in the long-term interests of licensees, shareholders and other stakeholders while maintaining high standards of transparency, due process, data integrity, disclosure, accountability and ethical conduct without impeding enterprise or innovation.[i]
2.2 The relationship with CAMA and the NCCG 2018
The 2025 Guidelines do not operate in isolation. They recognise the Companies and Allied Matters Act 2020 (“CAMA”) and the Nigerian Code of Corporate Governance 2018 (“NCCG 2018”) as part of the broader governance framework, while imposing additional requirements directed at the peculiar risks of the communications industry.
The practical implication is that communications companies should approach governance through a layered framework: general company law under CAMA, general corporate-governance principles under the NCCG 2018, and sector-specific obligations under the NCC’s 2025 Guidelines.
3. THE 2025 GUIDELINES: A MORE SECTOR-SPECIFIC APPROACH
The 2025 Guidelines adopt a differentiated approach to their application. They apply to communications companies and establish obligations according to the relevant licence category and regulatory circumstances. The NCC also retains the ability to modify or adapt implementation to reflect the operational circumstances of different categories of Individual Licences.[ii]
This flexibility is commercially important. The Nigerian communications sector is not homogeneous. A major mobile network operator, a network facilities provider and a smaller communications licensee may present materially different operational and systemic risks. A rigid uniform approach could therefore impose disproportionate governance requirements on certain categories of businesses.
At the same time, regulatory flexibility creates a corresponding need for regulatory certainty. Businesses need to know which obligations apply to them, how compliance will be assessed and what evidence will be sufficient to demonstrate compliance. The commercial value of flexibility will therefore depend on the transparency and consistency with which the NCC exercises its discretion.
4. THE BOARDROOM BECOMES A REGULATORY FRONTIER
One of the most significant features of the 2025 Guidelines is the extent to which they place regulatory risk squarely within the responsibilities of the Board.
Paragraph 27 makes the Board primarily responsible for the risk-management process and risk governance of the licensee. The Board must establish systems for identifying, assessing, evaluating, mitigating and monitoring risks and determine the licensee’s risk appetite or tolerance. Although management remains responsible for designing and implementing the risk-management process, the Board must form its own opinion on the effectiveness of that process[iii].
This moves regulatory risk from the periphery of corporate decision-making into the Board’s oversight function. A Board that considers financial, operational and reputational risks but treats regulatory risk as an issue exclusively for the legal or regulatory department may no longer have an adequate governance framework.
4.1 Internal controls as regulatory infrastructure
The Guidelines reinforce this position by requiring the Board to establish an effective internal-control system that supports transparent financial reporting and compliance, together with periodic checks on the effectiveness of those controls[iv].
In a communications business, internal controls cannot realistically be confined to accounting controls. They must also extend to the operational data and processes through which regulatory compliance is established.
A communications company’s internal-control environment is therefore increasingly part of its regulatory infrastructure.
5. THE REGULATORY OFFICER AND THE INTERNALISATION OF COMPLIANCE
The 2025 Guidelines require every licensee to have a Regulatory Officer with primary responsibility for ensuring compliance with the NCA and subsidiary legislation. The Regulatory Officer is also accountable for regulatory filings and reporting and for handling inquiries or audits from the Commission[v].
This provision institutionalises regulatory responsibility within the organisation. The relationship with the NCC should not commence only when the Commission sends an inquiry, conducts an audit or identifies a potential breach. A mature compliance function should continuously monitor obligations, maintain evidence of compliance and escalate material risks to management and the Board.
For larger communications companies, this supports an integrated model in which the Regulatory Officer works closely with Legal, Risk and Compliance, Internal Audit, Finance, Technology, Information Security, Customer Operations and the Board or relevant Board committees.
6. COMPLIANCE REPORTING AND BOARD CERTIFICATION
The 2025 Guidelines introduce a significant accountability mechanism through periodic compliance reporting. Licensees must submit a mid-year Compliance Report by 31 July and an Annual Compliance Report by 31 January of the succeeding year. Crucially, the Board must ensure and certify the accuracy of the report before submission[vi].
The significance of Board certification should not be understated. Regulatory reporting is transformed from an administrative filing into a governance statement backed by Board-level assurance.
Boards should therefore ask: What information supports the compliance report? Who verified that information? Are unresolved regulatory issues appropriately disclosed? Can the company produce an audit trail demonstrating the basis of the certification? The appropriate governance question is not merely whether the report has been filed, but what systems and evidence support the report the Board has certified.
The Commission also reserves the right to request clarification and conduct compliance checks, reinforcing the need for an evidence-based compliance architecture[vii].
7. DATA INTEGRITY: FROM IT FUNCTION TO REGULATORY ASSET
Data integrity is a recurring theme in the 2025 regulatory architecture. The Corporate Governance Guidelines expressly identify data integrity as a governance objective, while the reporting framework requires licensees to provide operational and Industry Network/Subscriber Statistics data and other reports required by the Commission[viii].
The importance of data integrity becomes particularly apparent when the Corporate Governance Guidelines are read alongside the Guidelines for Disconnection of Communications Operators 2025.
The Disconnection Guidelines establish a structured framework for regulatory approval of disconnection arising, among other things, from interconnection indebtedness. They require accurate and Type-Approved billing systems and place significant importance on the exchange and reconciliation of Call Data Records (“CDRs”)[ix].
Where an operator fails to exchange reliable CDRs after the prescribed period, the CDRs of the other interconnecting party may, in the circumstances specified by the Guidelines, be deemed the proper and correct records of indebtedness[x].
The commercial implication is profound: data integrity can affect the determination of financial liability. CDRs are therefore not merely technical records maintained by a network or IT department; their integrity may have direct consequences for an operator’s commercial position and regulatory exposure.
8. INTERCONNECTION: WHEN A COMMERCIAL DISPUTE BECOMES A REGULATORY MATTER
Ordinarily, an unpaid commercial debt would be addressed through contractual enforcement or dispute-resolution mechanisms. In the telecommunications sector, however, the consequences of non-payment can extend beyond the contracting parties where non-payment threatens the continuity of interconnection.
The Disconnection Guidelines therefore establish a predetermined framework intended to promote transparency, certainty and fairness before disconnection is authorised. They require, among other things, a subsisting registered interconnection agreement, accurate Type-Approved billing systems and exhaustion of contractual dispute-resolution mechanisms[xi].
For indebtedness, the Commission considers matters including payment of regulatory fees, maintenance of a separate Interconnection Account, exchange and reconciliation of CDRs and agreement on the outstanding amount. The debt ordinarily must have remained outstanding for 30 calendar days, subject to the circumstances prescribed by the Guidelines[xii].
The framework therefore establishes a regulatory chain: corporate governance → internal controls → billing and data integrity → interconnection indebtedness → regulatory intervention.
This is why interconnection governance should be treated as a Board-level risk rather than solely as a commercial or technical matter.
9. INTERNET GOVERNANCE AND THE EXPANDING REGULATORY PERIMETER
The amended Internet Code of Practice provides another dimension of the emerging regulatory-governance framework. The Code records that the NCC commenced a consultation process in July 2025 involving national and international stakeholders and subsequently issued the amended Code to define the rights and obligations of Internet Access Service Providers and guide licensees in managing subscribers and consumers[xiii].
The Code’s objectives include protecting the right of Internet users to an Open Internet, regulating traffic-management practices, protecting consumers’ personal data, addressing offensive and potentially harmful content, protecting minors and vulnerable audiences, and establishing governance rules for Online Platforms and Digital Services[xiv].
9.1 Open Internet and traffic management
The Code recognises users’ rights to access and distribute information and content, use applications and services and use appropriate terminal equipment. It provides that lawful content, applications and services should not be blocked or discriminated against by an Internet Access Service Provider[xv].
The Code also regulates reasonable network-management practices. Such practices must have a legitimate and demonstrable technical need, a specific technical goal, a proportionate effect, full disclosure sufficient to enable consumers to understand the impact on their service, and a basis in globally accepted standards.
The commercial implication is that technical network decisions can have regulatory and consumer-protection consequences. A decision to throttle, prioritise or otherwise manage traffic should therefore be capable of being justified within the applicable regulatory framework and supported by appropriate records.
10. CONSUMER PROTECTION AS AN OUTCOME OF REGULATORY GOVERNANCE
The ultimate purpose of communications regulation is not merely institutional compliance. It is also to ensure that consumers receive reliable, transparent and appropriately protected services.
The Corporate Governance Guidelines require the Board to recognise the importance of the communications sector to society and the economy, maintain a commitment to excellent customer service and ensure effective processes for dealing with service failures.
The Internet Code complements this by addressing users’ rights, transparency, traffic management, privacy and harmful content. It also establishes compliance reporting requirements for Internet Access Service Providers and affected entities[xvi].
Consumer protection should therefore be understood not as a separate regulatory silo but as one of the principal outcomes of sound regulatory governance.
11. THE NCC AS REGULATOR, SUPERVISOR AND MARKET ARCHITECT
The evolution of the NCC’s regulatory framework requires a broader understanding of the Commission’s role.
First, the NCC is a rule-maker. Section 70 of the NCA provides the statutory basis upon which subsidiary legislation and guidelines are made, including the 2025 Corporate Governance Guidelines[xvii].
Second, it is a supervisor and enforcer. The Corporate Governance Guidelines contemplate compliance checks and regulatory review, while the Internet Code provides for monitoring, requests for information, remediation of non-compliance and enforcement under the Nigerian Communications (Enforcement Processes, etc.) Regulations 2019[xviii].
Third, the NCC is increasingly a market architect. Its regulatory activity does not merely respond to existing market conduct; it also creates frameworks within which new technologies and business models can develop. This is important to the commercial legitimacy of sector regulation.
12. A CRITICAL APPRAISAL OF THE 2025 FRAMEWORK
12.1 From Reactive to Preventive Regulation
A principal strength of the 2025 framework is its preventive character. By requiring Boards to oversee risk, licensees to appoint Regulatory Officers and companies to maintain systems capable of producing accurate compliance reports, the NCC is attempting to address regulatory risk before it becomes regulatory failure.
12.2 Evidence-based compliance
The framework also reflects a move towards evidence-based regulation. Compliance must increasingly be demonstrated through reports, system data, governance processes and documentary records. For regulated businesses, the practical lesson is that compliance should be designed to be demonstrable, not merely asserted.
12.3 Proportionality versus regulatory certainty
The NCC’s ability to adapt the Guidelines to different licence categories is commercially sensible, but regulatory flexibility must be balanced against certainty. Businesses make long-term investment decisions on the basis of assumptions about the regulatory environment. Predictability in implementation is therefore important to investment, financing, transactions and technological deployment.
12.4 Regulatory overlap and coordination
The communications sector increasingly intersects with data protection, cybersecurity, consumer protection, competition and digital-platform regulation. The Internet Code itself contemplates engagement with relevant regulatory and governance structures. The effectiveness of the framework will therefore depend partly on coordination between regulators and on clear allocation of regulatory responsibilities.
12.5 Regulation and innovation
The 2025 Guidelines expressly seek to maintain governance standards without impeding enterprise or innovation. This balance should remain central as the industry develops through artificial intelligence, satellite connectivity, cloud infrastructure, Internet of Things applications and advanced wireless technologies.
13. PRACTICAL IMPLICATIONS AND RECOMMENDATIONS FOR INDUSTRY PARTICIPANTS
13.1 Boards and directors
Boards should treat regulatory compliance as an enterprise-risk matter. At a minimum, Boards should:
· receive periodic reports on material regulatory risks;
· ensure that internal controls address regulatory and interconnection liabilities;
· satisfy themselves as to the integrity of regulatory information;
· scrutinise compliance reports before certification;
· monitor significant service-quality and consumer issues; and
· ensure that the Regulatory Officer has sufficient access, authority and resources.
The relevant governance question should not merely be whether the company is compliant, but how the company knows that it is compliant.
13.2 Telecommunications operators
Operators should conduct periodic regulatory health checks covering:
· licence conditions and regulatory filings;
· NCC correspondence and compliance reports;
· interconnection agreements and indebtedness;
· billing and CDR systems;
· quality-of-service obligations;
· consumer complaints and service failures;
· data governance;
· Type Approval and spectrum obligations; and
· outstanding remedial actions.
13.3 Internet Access Service Providers
IASPs should ensure that technical, legal and commercial teams jointly assess material changes to network-management practices. Particular attention should be given to traffic management, transparency of service terms, lawful access to content and applications, throttling and discrimination, consumer data, service performance and compliance reporting[xix].
13.4 Technology businesses, investors and financiers
Businesses introducing new communications technologies should undertake regulatory analysis at the product-development stage. Investors and financiers should expand traditional legal due diligence to include licence status, regulatory compliance, NCC correspondence, enforcement history, interconnection liabilities, spectrum rights, Type Approval, consumer complaints, service-quality issues and the target’s regulatory-governance structures.
For transactions involving communications companies, regulatory risk should therefore be treated as a core transaction risk rather than an ancillary diligence issue.
14. RECOMMENDATIONS FOR A MORE EFFECTIVE REGULATORY GOVERNANCE MODEL
The 2025 framework provides a strong foundation, but its effectiveness can be strengthened through continued attention to four areas.
Regulatory certainty. The NCC should, as far as practicable, provide clear implementation expectations where the Guidelines permit differentiated application. Predictability assists operators in structuring compliance systems and making long-term investment decisions.
Proportionality. Differentiated regulatory obligations should continue to reflect the size, licence category, operational complexity and risk profile of the relevant operator.
Regulatory coordination. Given the increasing intersection between communications regulation, data protection, cybersecurity, consumer protection and digital-platform governance, coordination between regulators will become increasingly important.
Regulatory dialogue. Consultation processes accompanying major regulatory initiatives remain important because the communications industry is technologically complex and commercially dynamic. Stakeholder engagement can assist the NCC in identifying unintended consequences before regulatory requirements are finalised.
15. CONCLUSION
The 2025 NCC Guidelines mark an important development in the regulation of Nigeria’s communications industry. Their significance lies not simply in the number of governance requirements they introduce, but in the direction of regulatory responsibility.
The NCC is increasingly establishing standards that must be internalised by the businesses it regulates. Boards must oversee regulatory risk. Regulatory Officers must manage compliance. Internal controls must support regulatory obligations. Compliance reports must be certified. Data must be sufficiently reliable to support commercial and regulatory decisions. Technical and operational decisions may carry direct consumer and regulatory consequences.
The wider regulatory framework reinforces the same direction. Interconnection rules demonstrate how commercial disputes can become regulatory matters where network continuity is implicated. Internet governance demonstrates the extension of regulation into the digital experience of consumers.
The emerging model is therefore best understood as regulatory governance rather than regulation in its traditional form.
For industry participants, the commercial message is clear: regulatory compliance can no longer be treated as a post-facto legal exercise. It must increasingly form part of the architecture through which the business is governed, its risks are managed and its strategic decisions are made.
For consumers, the objective is equally important: stronger governance should translate into greater transparency, more reliable services, responsible network management and better protection of their interests.
The success of the framework will ultimately depend on maintaining the right equilibrium between accountability and innovation, regulatory discretion and certainty, and consumer protection and commercial viability.
[i]Guidelines on Corporate Governance for the Communications Industry 2025, paras. 1–2.
[ii]Guidelines on Corporate Governance for the Communications Industry 2025, Part I, para. 4 ( 3)
[iii] Guidelines on Corporate Governance for the Communications Industry 2025, para. 27(1)–(5).
[iv]Guidelines on Corporate Governance for the Communications Industry 2025, para. 28(1).
[v] Guidelines on Corporate Governance for the Communications Industry 2025, para. 26(4).
[vi] Guidelines on Corporate Governance for the Communications Industry 2025, para. 37(1)–(6).
[vii] Guidelines on Corporate Governance for the Communications Industry 2025, para. 37(5)–(6).
[viii] Guidelines on Corporate Governance for the Communications Industry 2025, paras. 1–2 and 34(3)–(4).
[ix] Guidelines for Disconnection of Communications Operators 2025, paras. 1(4) and 5.
[x] Guidelines for Disconnection of Communications Operators 2025, para. 5(5)–(6).
[xi] Guidelines for Disconnection of Communications Operators 2025, paras. 1–2.
[xii] Guidelines for Disconnection of Communications Operators 2025, para. 5(1)–(4).
[xiii] Amended Internet Code of Practice, 2026, Chapter 1, paras. 1.1–1.2.
[xiv] Amended Internet Code of Practice, 2026, para. 1.3.
[xv] Amended Internet Code of Practice, 2026, para. 1.5.
[xvi] Amended Internet Code of Practice, 2026, paras. 7.1–7.3.
[xvii] Guidelines on Corporate Governance for the Communications Industry 2025, legal basis; Amended Internet Code of Practice, 2026, para. 1.2.
[xviii] Guidelines on Corporate Governance for the Communications Industry 2025, para. 37(5); Amended Internet Code of Practice, 2026, para. 7.1.
[xix] Amended Internet Code of Practice, 2026, paras. 1.5, 2.7 and 7.3.