A growing business can be commercially active and still carry avoidable compliance gaps. The purpose of a compliance checklist is not to create paperwork for its own sake; it is to make responsibilities, deadlines and evidence visible before a regulator, bank, investor or transaction exposes the gaps.
1. Corporate and CAC records
- Confirm the company or business-name status and registered details.
- Keep directors, shareholders, persons with significant control, registered office and business activities current where applicable.
- File annual returns and required post-incorporation changes.
- Maintain board, shareholder and statutory records appropriate to the entity.
2. Tax registrations and recurring filings
- Confirm taxpayer identification and registration details under the current 2026 tax framework.
- Map the taxes that actually apply to the business, including VAT, company income tax, PAYE and withholding obligations where relevant.
- Use a calendar with preparation, review, filing and payment dates rather than only statutory deadlines.
- Retain filed returns, payment receipts, reconciliations and correspondence.
3. Accounting and financial reporting
- Record transactions promptly and reconcile bank accounts regularly.
- Maintain receivables, payables, fixed-asset and other supporting schedules.
- Prepare management accounts at a frequency appropriate to the business.
- Assess year-end financial-statement and audit or assurance requirements early rather than after the reporting date.
4. Payroll and workforce compliance
- Keep employee records, contracts and approved remuneration current.
- Calculate payroll consistently and document deductions and approvals.
- Review applicable PAYE, pension and other employment-related statutory obligations based on the workforce and jurisdiction.
- Control access to employee personal data.
5. Data protection and information governance
- Know which customer, employee and vendor personal data the business holds.
- Document purposes and lawful bases for material processing activities.
- Provide appropriate privacy information and a process for data-subject requests.
- Review vendor, cloud and cross-border data arrangements.
- Maintain reasonable security and incident-response procedures.
6. Contracts and legal documentation
- Use written contracts for material customers, suppliers, employees, consultants, leases and partnerships.
- Ensure the person signing has authority to bind the business.
- Review renewal, termination, payment, liability, confidentiality and dispute provisions.
- Keep corporate records aligned with material ownership or governance agreements.
7. Licences and sector requirements
Identify licences, registrations, permits, professional requirements and sector regulators that apply to the actual activity of the business. A general CAC registration does not replace sector-specific approvals where those are required.
8. Assets, insurance and operational evidence
- Maintain an asset register for significant equipment, vehicles and property.
- Review insurance cover appropriate to the business risks.
- Keep evidence for major purchases, disposals, repairs and asset custody.
- Periodically verify significant physical assets and inventory.
9. Governance and authorisation
- Set approval limits for spending, payments, contracts and borrowing.
- Separate preparation, approval and reconciliation roles where practical.
- Document related-party transactions and exceptional decisions.
- Escalate regulatory notices, disputes and control failures promptly.
10. Evidence and follow-through
A compliance task is not complete merely because someone says it was done. Store the acknowledgement, receipt, filed return, approval, licence, contract or other evidence in a structured repository. Unresolved items should have a named owner and next action.
A useful review rhythm
Monthly reviews should focus on filings, payments, reconciliations and exceptions. Quarterly reviews can address corporate changes, contracts, data, licences and control issues. The annual review should consider financial statements, annual returns, tax-year obligations, insurance, governance documents and the next year’s compliance calendar.
Source trail
This checklist reflects recurring obligations arising from the Companies and Allied Matters Act 2020, Nigeria’s 2025 tax reform laws now operating in 2026, the Nigeria Data Protection Act 2023 and GAID 2025, and applicable financial-reporting and sector requirements.
Publication note: Not every item applies to every entity. Thresholds and obligations depend on legal form, turnover, assets, workforce, sector, location and the nature of transactions. Confirm the requirements applicable to the specific business.