Bank of Ghana Is Signalling That One Technology Expert on a Bank Board May No Longer Be Enough

[Want to get automatic updates on ethel cofie’s blog post of Africa, technology, ecosystems and doing business in Africa sign up here ]

Bank of Ghana Is Signalling That One Technology Expert on a Bank Board May No Longer Be Enough

The Bank of Ghana has rewritten the job description of a bank board

I have sat on enough boards to know how technology usually reaches the agenda. As a capital request. As a quarterly risk report. Or as an incident that management is now explaining.

In March 2026, the Bank of Ghana changed that. Its revised Cyber and Information Security Directive (CISD 2026) replaces the 2018 framework and, in Section 5(3), requires every board to appoint a Board Committee on Cyber and Information Security risks. It then goes further. It states that “at least one member of the Board shall possess verifiable qualification or expertise” in cyber and information security risk management.

This is not guidance. It is a mandate. The directive applies to institutions licensed under the Banks and Specialised Deposit-Taking Institutions Act (Act 930), the Payment Systems and Services Act (Act 987), the Non-Bank Financial Institutions Act, the Development Finance Institutions Act, the Credit Reporting and Foreign Exchange Acts, and the 2025 virtual asset law (Act 1154). Failure to comply attracts sanctions.

Now read past Section 5. The same directive requires institutions to treat artificial intelligence and machine learning as a category of institutional risk (Section 16(2)). It requires supply-chain mapping that captures concentration risk (Section 16(6)). It requires cloud risk assessments that cover vendor lock-in, portability and data egress (Section 19(2)(c)). It devotes whole parts to cloud services, digital innovation and AI systems. And Section 61(5) expects the board itself to demonstrate informed oversight of AI and machine learning deployment, aligned to its risk appetite.

The Governor framed the directive around six pillars. AI and machine learning governance came first. Cloud security came second. Board accountability came fourth.

The question now is whether technology expertise is represented on the board, but whether the expertise around the table reflects the decisions directors are expected to make

Or more plainly one qualified director satisfies Section 5(3). Can one director also carry the board’s judgement on AI, cloud and the business models being built on both?

Technology has moved from the budget line to the boardroom

The directive formalises a shift the numbers already show.

Ghana’s mobile money system processed a provisional GH¢4.5 trillion in 2025, up from GH¢1 trillion in 2022, GH¢1.9 trillion in 2023 and GH¢3 trillion in 2024. In December 2025 alone, mobile money moved GH¢518.4 billion. Cheques cleared GH¢37.3 billion. Active mobile money accounts reached 26.7 million against more than 80.5 million registered.

[Want to get automatic updates on ethel cofie’s blog post of Africa, technology, ecosystems and doing business in Africa sign up here ]

The risk has scaled with the volume. The Bank of Ghana’s 2024 Fraud Report recorded 16,733 fraud cases across banks, SDIs and payment service providers, with roughly GH¢99 million at risk. Identity theft losses rose from GH¢0.6 million to GH¢5.7 million in a single year. Cyber and technology-related fraud losses climbed from GH¢8.9 million to almost GH¢10 million.

For most of my career, technology decisions were taken by the CTO and the executive committee. Boards met them as an investment paper, a risk dashboard or an incident post-mortem. CISD 2026 moves that line. Look at the business decisions sitting behind three of its themes.

AreaThe business decision behind the technologyWhat CISD 2026 already asks
AI and machine learningWho gets credit, on what terms, and whether the bank can explain a declineAI treated as an institutional risk category; model-specific testing; board AI and ML literacy (Sections 16, 61, 100, 122)
Cloud infrastructureCost, vendor concentration, resilience, data sovereignty and how hard it is to leaveShared-responsibility mapping; lock-in, portability and exit risk; high residual cloud risk escalated to the board (Sections 19, 82 to 88)
Emerging technologiesWhich new business models the bank enters, and what risk it imports with themDigital innovation governance; API and third-party due diligence (Sections 42, 98 to 100)

Three ideas connect these. Accountability: the board owns the outcome. Capability: the board must understand enough to challenge management. Continuity: that understanding must survive director rotation.

Let me be precise about where the regulation ends and my argument begins. The directive requires one director with verifiable cyber expertise, and a board that oversees AI, cloud and innovation risk. It does not prescribe anything further on board composition. My argument is about effective governance, not compliance.

Boards have always been accountable for their institutions. What is changing is the depth of informed judgement that accountability now demands.

Technology expertise is not one competency

Banking already understands specialisation. No nomination committee assumes that an investment banker is an audit expert, or that a credit specialist is automatically a market-risk specialist. We separate those competencies because the judgements are different.

Yet cybersecurity, AI governance, cloud economics and digital transformation are routinely filed under one word on the skills matrix. Technology.

They are different disciplines. An accomplished CISO understands threat actors, resilience and incident response. That is not the same as judging whether a machine learning credit model is fair, explainable and commercially sound. Equally, a seasoned digital transformation leader may understand platform economics and cloud migration, yet not hold the verifiable cyber risk qualification Section 5(3) demands.

The Bank of Ghana already draws this distinction one layer down. Section 9(2) requires the cybersecurity budget to sit separately from the general IT budget, so that security never competes with technology management for funds. Section 10 requires a dedicated CISO who holds no conflicting role. The regulator has decided that security and technology are different jobs in management. Boards should ask why they would be the same competency in the boardroom.

These competencies are complementary. They are not interchangeable.

I am not arguing for one director per technology discipline. That would be impractical and unnecessary. I am questioning whether board competency assessments are precise enough to see the gaps.

Africa’s regulators are converging on the problem, not the solution

Ghana is not acting alone. But the mechanisms differ, and the differences are instructive.

CountryInstrumentBoard-level mechanism
GhanaCISD 2026 (March 2026)Mandatory: at least one director with verifiable cyber and information security risk expertise; board cyber committee; board AI and ML literacy expected
NigeriaCBN Corporate Governance Guidelines (effective 1 August 2023); Risk-Based Cybersecurity Framework (31 May 2024)At least two non-executive directors, one independent, with knowledge in fintech, ICT or cybersecurity; board risk or IT committee oversight of cyber
South AfricaJoint Standard 1 of 2023 on IT governance (compliance from 15 November 2024); Joint Standard 2 of 2024 on cybersecurity (effective 1 June 2025)Governing body accountable for IT strategy and cyber resilience, under two separate standards
KenyaCBK Guidance Note on Cybersecurity (August 2017); 2025 AI surveyAll board members expected to understand cyber threats; AI guidance note in development

Nigeria chose numbers. The CBN guidelines require at least two non-executive directors, one of them independent, with requisite knowledge in innovative financial technology, ICT “and/or” cybersecurity. That small conjunction matters. A board can satisfy the rule with fintech depth and no cybersecurity depth at all. Breadth is permitted. Specialisation is not guaranteed. The CBN’s 2024 cyber framework then adds board-level committee oversight and quarterly cyber reporting.

South Africa chose separation. The Prudential Authority and the Financial Sector Conduct Authority issued IT governance and cybersecurity as two distinct joint standards, a year apart, with the governing body ultimately accountable for both. Same board. Two disciplines. Two rulebooks. That is the competency distinction written into supervisory architecture.

Kenya chose collective literacy, and is now confronting AI. The CBK’s 2017 Guidance Note expects every board member to understand the institution’s business and its cyber threats. Its 2025 survey shows why literacy alone is being tested. Half of surveyed institutions had adopted AI, rising to 66% of commercial banks. Among AI users, 65% applied it to credit risk assessment. Only 30% had a formal AI strategy. And 44% of adopters said they could not adequately explain how their models work. 93% asked the CBK for comprehensive AI guidance, which it is now developing.

The pattern is clear. African regulators are formalising expectations for technology governance. They are not converging on a single board composition rule. Ghana mandates a named competency. Nigeria mandates a count. South Africa mandates accountability across separate disciplines. Kenya relies on collective understanding. Every route ends at the same boardroom table.

Bank boards have not evolved as fast as banking

Technology now determines how a bank acquires customers, distributes products, prices risk, allocates capital and competes with telcos and fintechs. Ghana’s December 2025 data make the point: mobile money carried almost fourteen times the value of cheques in a single month.

The traditional board competencies remain essential. Finance. Audit. Legal. Risk. Executive leadership. None of that changes. What changes is that technology is no longer a support function. It is the operating model.

So the question for nomination committees is direct. If technology shapes how the bank creates value, manages risk and competes, why is it still assessed as a single, undifferentiated competency?

Some of Africa’s largest banks are already answering it. Standard Bank Group’s 2025 Governance Report asks its 15 directors to rate themselves on four levels, from limited to thought leader, and assesses digital transformation as a separate competency from technology and cybersecurity. Its board technology committee reviewed business units’ data and AI strategies during 2025, while a separate model approval committee approved a Responsible AI Framework. Its 2026 board education agenda names AI, cyber risk and digitisation. That is a board treating technology as several competencies, governed through several committees.

I draw no conclusion about any board’s real capability from a biography. Disclosures tell us how a board measures itself, not how well it judges. But measurement matters. What a skills matrix cannot see, a succession plan cannot fix.

Director development and external advice are legitimate tools. CISD 2026 itself requires AI and ML education that reaches the board. Most bank boards can commission independent specialist advice at the institution’s expense. Use both. But be clear about the difference. Training raises the floor. Advisers inform the debate. Neither sits at the table when the board decides. Collective competence is what the board brings to the vote.

Compliance is the immediate test. Capability is the larger one.

The immediate task for every regulated institution in Ghana is concrete. Confirm that a director holds verifiable cyber and information security risk expertise. Constitute the board cyber committee with a proper charter. Meet the reporting, testing and education obligations. Some clocks are already running: Section 36(4) gives institutions two years from the directive’s issue to retire legacy systems that cannot support multi-factor authentication.

Do all of that well. But do not let Section 5(3) become the ceiling of the board’s ambition.

One qualified cybersecurity director is necessary. It does not automatically give a board the collective judgement to govern AI-driven credit, concentrated cloud dependency and the business models being built on both.

So when your board next opens its skills matrix, which question will it answer: has the cybersecurity requirement been met, or does this board have the collective expertise to govern the bank it is becoming?

Sources and policy links

Ghana

Nigeria

South Africa

Kenya