By Musskart Technology Editorial Team Published: Updated: Reviewed by Musskart Senior Engineers

FRC

Guidance, Updated May 2024

PIEs

Must Report Annually

Evidence

Is The Whole Exercise

₦8M–₦25M

Typical Build Range

We reply on WhatsApp within minutes.

The Obligation, Briefly

The Financial Reporting Council of Nigeria issued its Guidance on Management Report on Internal Control over Financial Reporting in November 2022 under section 7(2)(f) of the FRC Act 2011 as amended, and updated it on 26 May 2024. It requires the management of public interest entities to implement internal controls over financial reporting, assess their effectiveness annually, and file a management report on that assessment alongside the audited financial statements.

The mandate bites for financial years ending on or after 31 December 2024. That means entities are now in the cycle where the assessment is not a first-time exercise being learned but an annual obligation whose consistency year on year is itself visible.

What actually goes wrong. Most Nigerian PIEs have decent controls. What they lack is evidence organised the way an assessment requires. The controls exist in people's heads and in practice; the documentation is a spreadsheet somebody built for last year's exercise, the testing was done in a three-week scramble before the deadline, and the evidence is scattered across email and shared drives. When a deficiency is found late there is no time to remediate and retest, so it escalates into the report. The software problem here is not control design. It is continuity, evidence and timing.

A note on scope before we go further: Musskart is a software company, not a firm of accountants, auditors or internal control consultants. We do not design your controls, judge their effectiveness, or form any opinion for your report. Your finance function, internal audit and external advisers do that work. We build the system that holds it together and makes the evidence retrievable.

What the System Has to Hold

The Part Most Entities Underestimate: IT General Controls

Financial reporting runs on systems, so the controls over those systems are in scope. This is consistently where Nigerian PIEs find their unpleasant surprises, because it is owned by IT rather than finance and nobody has been assessing it against a financial reporting lens.

  • Access management — who can post a journal, who can approve one, who can change a master record, and evidence that access was reviewed. Segregation of duties conflicts in the ERP are the most commonly found deficiency.
  • Change management — changes to financially significant systems requested, approved, tested and released with a record. A developer with production access and no change log is a finding.
  • Privileged access — administrators who can alter data directly, and what compensating control exists over what they do.
  • Backup and recovery — not that backups run, but that a restore has been tested.
  • Interfaces — data moving between systems with completeness and accuracy checks, because an unreconciled interface is an unmonitored hole in the ledger.
  • Automated controls — a three-way match or a credit limit enforced by the system is a control, and it needs testing that it is configured as documented and has not been changed.

If your ERP configuration and access model have never been examined this way, budget time for it. We build the evidence and review workflow; where remediation needs engineering in the ERP itself, that is separate work and we cover the platform side on our ERP development page. Where the finding is about security ownership more broadly, a virtual CISO is often the cheaper answer than a permanent hire.

Cost, Timeline and What to Do First

ICFR core

₦8,000,000 – ₦13,000,000

Risk and control matrix, framework mapping, control register with owners, testing plans and scheduling, evidence attachment, deficiency log with remediation tracking, and the management report pack. Three to five months.

Full GRC

₦14,000,000 – ₦20,000,000

Adds IT general controls testing, enterprise risk register, policy management with attestation, internal audit planning and fieldwork, issue management across sources, and board and audit committee reporting. Five to eight months.

Group / multi-entity

₦20,000,000 – ₦25,000,000

Several entities and subsidiaries with shared and local controls, consolidation of the group assessment, per-entity and group reporting, and segregated access. Seven to eleven months.

Do this first, before commissioning anything. Get your risk and control matrix into a defensible state with your advisers, because software that holds a bad matrix just makes the bad matrix easier to distribute. Then implement, and start rolling testing immediately rather than at the next year end — the value of the system is almost entirely in spreading the work across the year and catching deficiencies early enough to remediate and retest before the report is due.

If ICFR is arriving alongside other 2026 obligations, note that the evidence discipline overlaps heavily with ISO 27001 readiness and with NDPA compliance, and entities pursuing more than one should build one evidence library rather than three.

Why a Software Company for This

Most ICFR work in Nigeria is sold by accounting and advisory firms, and the technical judgement they bring is the part you genuinely need. Where the engagement tends to fail is afterwards. The adviser leaves a control matrix and a testing template in Excel, and twelve months later it is out of date, the tester who understood it has moved on, and the next assessment starts largely from scratch.

What we add is the continuity layer. The matrix lives in a system with version history rather than in a workbook. Testing is scheduled and chased automatically. Evidence attaches at the moment of testing instead of being gathered afterwards. Deficiencies have owners and due dates that someone is reminded about. And the report assembles from the data, so producing it is an export rather than a project.

Musskart Technology Limited is a registered Nigerian software company in Asaba with an Abuja office and 250+ projects delivered since 2020, building ERP, accounting and compliance systems for Nigerian institutions. We work alongside your auditors and advisers, to the control design they specify. We do not audit, we do not opine, and we do not sign anything.

Related Musskart Pages

Other 2026 obligations landing at the same time

If you are also handling sustainability reporting, see ESG and IFRS sustainability reporting software. For information security certification, ISO 27001 readiness. Build one evidence library rather than three.

Frequently Asked Questions

The Financial Reporting Council of Nigeria issued its Guidance on Management Report on Internal Control over Financial Reporting in November 2022 under section 7(2)(f) of the FRC Act 2011 as amended, and updated it on 26 May 2024. It requires management of public interest entities to implement internal controls over financial reporting, assess their effectiveness annually, and file a management report on that assessment together with the audited financial statements. The mandate applies for financial years ending on or after 31 December 2024. The guidance covers documentation requirements, framework selection, annual assessment procedures, reporting format and the treatment of material weaknesses.

Because most Nigerian public interest entities have reasonable controls and poor evidence. The controls exist in practice and in people's heads, but the documentation is a spreadsheet built for last year's exercise, the testing happens in a three-week scramble before the deadline, and the evidence is scattered across email and shared drives. When a deficiency surfaces late there is no time to remediate and retest, so it escalates into the report. The software problem is not control design, it is continuity, evidence and timing. A system holds the matrix with version history, schedules testing across the year, attaches evidence at the moment of testing, and chases deficiency owners so findings close before year end.

An ICFR core covering the risk and control matrix, framework mapping, a control register with owners, testing plans and scheduling, evidence attachment, a deficiency log with remediation tracking and the management report pack runs 8,000,000 to 13,000,000 Naira over three to five months. A fuller governance, risk and compliance build adding IT general controls testing, an enterprise risk register, policy management with attestation, internal audit planning and fieldwork, and board reporting runs 14,000,000 to 20,000,000 Naira over five to eight months. A group build across several entities with shared and local controls and consolidated group assessment runs 20,000,000 to 25,000,000 Naira.

No to both, and the boundary matters. Musskart is a software company, not a firm of accountants, auditors or internal control consultants. We do not design your controls, judge their effectiveness, perform your testing or form any opinion that goes into your report. Your finance function, internal audit and your external advisers own all of that, and the technical judgement they bring is the part you genuinely need. What we build is the system that holds their work together: the matrix, the testing workflow, the evidence library, the deficiency tracker and the report assembly. We work to the control design they specify and we do not sign anything.

IT general controls, and specifically segregation of duties conflicts in the ERP. Financial reporting runs on systems, so controls over those systems are in scope, but they are owned by IT rather than finance and typically nobody has assessed them against a financial reporting lens. The recurring findings are access management, meaning who can post a journal, who can approve one, who can change a master record, and whether access was ever reviewed; change management, where a developer with production access and no change log is itself a finding; privileged access without compensating controls; backups that run but have never been test-restored; and unreconciled interfaces between systems, which are unmonitored holes in the ledger.

Immediately, and the reason is arithmetic rather than urgency for its own sake. The value of an ICFR system is almost entirely in spreading testing across the year so deficiencies surface early enough to remediate and retest before the report is due. If you implement three months before year end, you get a tidier scramble but the same outcome. Before commissioning anything, get your risk and control matrix into a defensible state with your advisers, because software that holds a bad matrix simply makes the bad matrix easier to distribute. Then implement and begin rolling testing straight away rather than waiting for the next cycle to start.

Stop Rebuilding the Assessment Every Year

Tell us your entity type, your year end and whether your risk and control matrix is in a defensible state. We will scope the system around your advisers' design and get rolling testing started.

Chat on WhatsApp Get a Quote Call +234 813 168 6721 See Our Full Pricing
WhatsApp