ICFR Software for Nigerian Public Interest Entities
The FRC requires management of public interest entities to assess and report annually on the effectiveness of internal control over financial reporting. Doing that in spreadsheets is how a clean control environment produces a qualified report.
FRC
Guidance, Updated May 2024
PIEs
Must Report Annually
Evidence
Is The Whole Exercise
₦8M–₦25M
Typical Build Range
We reply on WhatsApp within minutes.
The Obligation, Briefly
The Financial Reporting Council of Nigeria issued its Guidance on Management Report on Internal Control over Financial Reporting in November 2022 under section 7(2)(f) of the FRC Act 2011 as amended, and updated it on 26 May 2024. It requires the management of public interest entities to implement internal controls over financial reporting, assess their effectiveness annually, and file a management report on that assessment alongside the audited financial statements.
The mandate bites for financial years ending on or after 31 December 2024. That means entities are now in the cycle where the assessment is not a first-time exercise being learned but an annual obligation whose consistency year on year is itself visible.
What actually goes wrong. Most Nigerian PIEs have decent controls. What they lack is evidence organised the way an assessment requires. The controls exist in people's heads and in practice; the documentation is a spreadsheet somebody built for last year's exercise, the testing was done in a three-week scramble before the deadline, and the evidence is scattered across email and shared drives. When a deficiency is found late there is no time to remediate and retest, so it escalates into the report. The software problem here is not control design. It is continuity, evidence and timing.
A note on scope before we go further: Musskart is a software company, not a firm of accountants, auditors or internal control consultants. We do not design your controls, judge their effectiveness, or form any opinion for your report. Your finance function, internal audit and external advisers do that work. We build the system that holds it together and makes the evidence retrievable.
What the System Has to Hold
The risk and control matrix
Financial statement line items mapped to the assertions that matter for each, mapped to the risks that could cause a material misstatement, mapped to the controls that address them. Each control recorded with its owner, frequency, whether it is preventive or detective, whether it is manual or automated, and which process and entity it sits in. This document is the backbone of the whole exercise and in most organisations it exists as one person's workbook.
Framework alignment
Controls mapped against a recognised framework so the assessment has a defensible structure, covering the control environment, risk assessment, control activities, information and communication, and monitoring. Entity-level controls tracked separately from process-level ones, because weakness at entity level undermines everything beneath it.
Testing that happens through the year
A test plan per control with method, sample size and timing, scheduled across the year rather than compressed into the final quarter. Testers assigned, results recorded with the sample evidence attached, and reviewer sign-off separate from the tester. Rolling testing is the single change that most reduces year-end pain, and it is only practical with a system driving it.
Evidence, attached where it belongs
The bank reconciliation, the approval email, the system report, the signed schedule — attached to the specific control test that relied on it, timestamped and immutable. An assessment is only as good as the evidence you can produce months later, and reconstructing it from shared drives in February is the most wasteful work in the finance calendar.
Deficiency tracking
Findings logged with severity, an owner, a remediation plan and a due date, then retested to closure with the retest evidence attached. Crucially, an aggregation view: several individually minor deficiencies in the same process can combine into something that is not minor at all, and that judgement needs the full picture in one place.
The management report
The output assembled from the underlying data rather than written from memory: scope, framework used, assessment performed, conclusion on effectiveness, and disclosure of any material weakness with its status. Every statement traceable back to the tests and evidence behind it.
The Part Most Entities Underestimate: IT General Controls
Financial reporting runs on systems, so the controls over those systems are in scope. This is consistently where Nigerian PIEs find their unpleasant surprises, because it is owned by IT rather than finance and nobody has been assessing it against a financial reporting lens.
- Access management — who can post a journal, who can approve one, who can change a master record, and evidence that access was reviewed. Segregation of duties conflicts in the ERP are the most commonly found deficiency.
- Change management — changes to financially significant systems requested, approved, tested and released with a record. A developer with production access and no change log is a finding.
- Privileged access — administrators who can alter data directly, and what compensating control exists over what they do.
- Backup and recovery — not that backups run, but that a restore has been tested.
- Interfaces — data moving between systems with completeness and accuracy checks, because an unreconciled interface is an unmonitored hole in the ledger.
- Automated controls — a three-way match or a credit limit enforced by the system is a control, and it needs testing that it is configured as documented and has not been changed.
If your ERP configuration and access model have never been examined this way, budget time for it. We build the evidence and review workflow; where remediation needs engineering in the ERP itself, that is separate work and we cover the platform side on our ERP development page. Where the finding is about security ownership more broadly, a virtual CISO is often the cheaper answer than a permanent hire.
Cost, Timeline and What to Do First
ICFR core
₦8,000,000 – ₦13,000,000
Risk and control matrix, framework mapping, control register with owners, testing plans and scheduling, evidence attachment, deficiency log with remediation tracking, and the management report pack. Three to five months.
Full GRC
₦14,000,000 – ₦20,000,000
Adds IT general controls testing, enterprise risk register, policy management with attestation, internal audit planning and fieldwork, issue management across sources, and board and audit committee reporting. Five to eight months.
Group / multi-entity
₦20,000,000 – ₦25,000,000
Several entities and subsidiaries with shared and local controls, consolidation of the group assessment, per-entity and group reporting, and segregated access. Seven to eleven months.
Do this first, before commissioning anything. Get your risk and control matrix into a defensible state with your advisers, because software that holds a bad matrix just makes the bad matrix easier to distribute. Then implement, and start rolling testing immediately rather than at the next year end — the value of the system is almost entirely in spreading the work across the year and catching deficiencies early enough to remediate and retest before the report is due.
If ICFR is arriving alongside other 2026 obligations, note that the evidence discipline overlaps heavily with ISO 27001 readiness and with NDPA compliance, and entities pursuing more than one should build one evidence library rather than three.
Why a Software Company for This
Most ICFR work in Nigeria is sold by accounting and advisory firms, and the technical judgement they bring is the part you genuinely need. Where the engagement tends to fail is afterwards. The adviser leaves a control matrix and a testing template in Excel, and twelve months later it is out of date, the tester who understood it has moved on, and the next assessment starts largely from scratch.
What we add is the continuity layer. The matrix lives in a system with version history rather than in a workbook. Testing is scheduled and chased automatically. Evidence attaches at the moment of testing instead of being gathered afterwards. Deficiencies have owners and due dates that someone is reminded about. And the report assembles from the data, so producing it is an export rather than a project.
Musskart Technology Limited is a registered Nigerian software company in Asaba with an Abuja office and 250+ projects delivered since 2020, building ERP, accounting and compliance systems for Nigerian institutions. We work alongside your auditors and advisers, to the control design they specify. We do not audit, we do not opine, and we do not sign anything.
Related Musskart Pages
Other 2026 obligations landing at the same time
If you are also handling sustainability reporting, see ESG and IFRS sustainability reporting software. For information security certification, ISO 27001 readiness. Build one evidence library rather than three.
- ESG & Sustainability Reporting Software — the other FRC and SEC reporting obligation
- Accounting & Invoicing Software — the ledger the controls sit over
- ERP Software Development in Nigeria — where most IT general control findings live
- ISO 27001 & Compliance Readiness — overlapping evidence discipline
- Virtual CISO & Managed Cybersecurity — ownership of IT general controls
- NDPA Compliance Audit & CAR Filing — the data-protection obligation alongside it
Frequently Asked Questions
Stop Rebuilding the Assessment Every Year
Tell us your entity type, your year end and whether your risk and control matrix is in a defensible state. We will scope the system around your advisers' design and get rolling testing started.