The Checklists Of Regulatory Compliance Required Of A Registered Business Entity (Company) In Nigeria
By Ayoola Hassan
Regulatory Compliance involves the process of adhering to relevant laws, regulations, procedures, guidelines and other rules issued by the government or governing authorities. Companies operating business in Nigeria are required to comply with the regulatory obligations relevant to the scope of their business. Violations usually attract penalties and this may have an adverse effect on the business operation of the company.
It is noteworthy that the nature of business and operating industry plays significant role in determining the applicable regulatory compliance to be adopted by such business. Thus, it is sacrosanct that companies seeking to operate legally and successfully in Nigeria identify the regulations applicable to their business to prevent avoidable violations. This article shall be analysed under three categories.
General Regulations
These are the regulations applicable to all businesses regardless of the industry or sector. In other words, every company operating business in Nigeria must ensure compliance with these sets of regulations or requirements even if their business operation does not require any special or specific license or requirements.
Business Registration:
The first regulatory requirement every company seeking to operate legally in Nigeria must comply with is the registration of the business with the Corporate Affairs Commission (CAC) in accordance with the statutory provisions of the Companies and Allied Matters Act, 2020. The registration process simply involves securing a unique name for the company, preparing and filing the necessary documents and forms, payment of applicable fess, and obtaining the incorporation certificate upon approval by the Commission.
Upon the successful registration of the company with the Commission, there are other post-incorporation requirements that must be fulfilled by the company to keep the company a legal going concern. This allows the company have a smooth business operation in Nigeria.
Tax Registration/Compliance:
Under the Nigerian laws, it is required that every company operating in Nigeria must obtain a Tax Identification Number (TIN) from the Federal Inland Revenue Service (FIRS) and fulfil their tax obligations and other tax related activities. The applicable taxes include Company Income tax, Value Added Tax, Withholding Tax, Industrial Training Fund and others. Some other applicable taxes are industry or transaction specific, such as, Petroleum Profit Tax, Stamp Duties, Custom and Excise Duty and others.
Labour and Employment Compliance:
Companies must ensure compliance with laws and regulations that govern their relationship with their employees. The major law that regulates the affairs of companies and employees in Nigeria is the Labour Act. The Labour Act makes comprehensive provisions in respect of employment contracts, employee rights, payment of wages, working hours, termination procedure among others.
Other applicable laws are Industrial Training Fund Act, Trade Unions Act, Employee Compensation Act, Factories Act and other labour related laws.
Compliance with these laws helps prevent avoidable disputes that may arise as a result of violation.
Data Protection Compliance:
There are data protection compliance obligations that companies in Nigeria must fulfil to ensure the protection of personal data. These obligations stem from laws and regulations such as the Nigerian Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Regulation, 2019 (NDPR), the NDPR Implementation Framework, 2020. The NDPA is the principal legislation that regulates data protection compliance obligations in Nigeria. The objective of the Act among others, is to safeguard the fundamental rights and freedoms, and the interest of data subjects as guaranteed under the Constitution of the Federal Republic of Nigeria, 1999. Companies are obligated to process and protect employees and customers/clients’ personal data in compliance with the provisions of the NDPA and other data protection regulations.
Data protection compliance obligations include: obtaining consent from data subject; providing data security; granting data subject access to their personal data; observing data retention limitation; using collected data for lawful purpose only; verifying age and consent in respect of child’s personal data.
Failure to comply with these obligations may attract sanctions such as payment of fine, payment of compensation to the data subject, prosecution, rectifying the violation.
Audits and Inspections:
Companies are required to conduct internal periodic audits to ensure compliance with the regulatory obligations and identify areas of improvement. For instance, data controllers and data processors who meet the statutory minimum thresholds are required under the NDPR to submit a yearly data protection Compliance Audit Returns (CARS) by conducting annual audit and filing annual report.
Likewise, companies are subject to inspections by regulatory bodies to ensure compliance with industry standards and regulations while also preventing unethical or fraudulent operations.
Reporting, Documentation and Retention:
Maintaining accurate record-keeping is an essential part of regulatory compliance for every company.
A company is legally obligated to keep or maintain statutory records or books that concern its business operations. This requirement stems from various laws and regulations and below are some of such records:
- Register of directors
- Register of members
- Tax and financial records
- Employee records
- Resolutions
- Annual returns
- Minutes
- Other records of compliance activities.
Furthermore, there are provisions in respect of the retention duration of these records under the various laws or regulations. For instance, section 864 of CAMA provides that “companies, firms and corporate bodies registered under this Act shall retain documents stored in pursuance of the provisions of this Act in soft copies for six years from the date of storage.”
Similarly, section 75 of the Labour Act provides that employers shall keep records of their employees and these records shall be retained for three years after the time to which they refer.
Industry-specific Regulations
There is significant variance in Regulations based on the business industry. Likewise, some industries are subject to complex regulatory requirements because of their economic impact and as such undergo stringent penalties upon violation.
Permits and Licenses:
Some businesses require specific license or permit before they can begin operations in Nigeria. However, the type of license or permit to obtain depends on the industry and scope of operation. For instance:
- Banking and Financial Institutions require Banking License from CBN; Securities Trading License from Securities and Exchange Commission (SEC); Insurance License from National Insurance Commission (NAICOM); Payment Service Provider License (PSP) from CBN.
- Telecommunications and Media companies require operating License from Nigerian Communications Commission (NCC); Broadcasting License from National Broadcasting Commission (NBC); Value Added Service License from NCC.
- Pharmaceutical and Healthcare companies require license from Pharmacy Council of Nigeria (PCN); National Agency for Food and Drug Administration and Control (NAFDAC); Lagos State Health Facility Monitoring and Accreditation Agency (HEFAMAA).
- Real Estate and Construction companies are required to obtain Building Permit from the state or local urban development authorities; Environmental Impact Assessment (EIA) Permit from the Federal Ministry of Environment; Real Estate Developer’s License.
- Sports betting companies require the National Lottery Regulatory Commission (NLRC) License issued by the NLRC. Also, Lagos State require additional licensing from the Lagos State Lotteries Board (LSLB) to operate legally within the state.
- Companies into transportation and logistics business are required to obtain Road Transport License from the Federal Road Safety Corps (FRSC) for commercial vehicles; Freight Forwarding License from the Nigerian Maritime Administration and Safety Agency (NIMASA) for cargo handlers; Logistic License issued by the Nigerian Postal Service (NIPOST).
- Money lending companies must obtain approval from the Federal Competition & Consumer Protection Commission (FCCPC) to operate digitally in Nigeria. Also, Money Lender’s License must be obtained from the state of operation or FCT.
Foreign Participation Regulations
By the provision of section 20(4) of CAMA, an alien or foreign company may join in forming a company in Nigeria. However, this provision is subject to compliance with some legal requirements provided by the applicable laws and regulations. Some of these requirements are:
- The company must be registered with the Corporate Affairs Commission and thereafter with the Nigerian Investment Promotion Commission before commencing operation in Nigeria – section 78 of CAMA and section 20 of the NIPC Act.
- Exemption – Section 80 of CAMA makes provision for the categories of companies that are allowed to apply for exemption from incorporation as a Nigerian company before operating in Nigeria. For instance, foreign government-owned companies engaged solely in export promotion activities; foreign companies which are in Nigeria for the execution of specific individual loan projects on behalf of a donor country or international organization.
- The minimum required paid-up capital for a company with foreign participation in Nigeria is One Hundred Million Naira (N100,000,000).
- Business Permit and Expatriate Quota must be obtained by the company from the Ministry of Interior. The Business Permit allows the company to begin business operation in Nigeria while the Expatriate Quota is necessary for the company to have foreigners as employees.
Regulatory compliance is undeniably an integral part of a business. By ensuring strict, adequate and timely compliance, companies avoid the risk of being exposed or faced with penalties from the government or regulatory bodies. Additionally, compliance positions the company as trustworthy and reliable. It is important that companies stay informed and updated about regulatory changes applicable to their business or engage experienced Attorneys for assistance in regulatory compliance.