Pre-deployment testing needed for AI in Nigerian fintech systems
Context-Aware Pre-Deployment Evaluation of AI Systems: A Regulatory Framework for Nigerian Fintech
Artificial IntelligenceComputers and Society
Summary
AI systems helping banks in Nigeria to detect fraud often fail to recognize normal bank messages properly and can even create fake fraud scenarios. The authors found that current safety tests miss these problems because they don’t focus on Nigerian financial details. They built a special test called SafeAlert to check AI models on Nigerian banking messages and showed these hidden issues. They suggest Nigerian and African regulators create clearer rules to require such local testing before AI systems are used.
What this means in practice
- •For fintech compliance teams: Evaluate AI fraud detection tools against Nigerian banking communications to catch hidden false positives before deployment.
- •For financial regulators: Set specific pre-deployment testing standards for AI systems based on local Nigerian financial messaging to improve oversight.
Authors
Andrew Anogie Uduimoh, Hadiza Umar Yusuf, Oluwafemi Osho
Abstract
Commercial large language models are increasingly deployed across African fintech infrastructure for fraud detection and customer communication, yet no Nigerian or African continental regulatory instrument specifies what pre-deployment evaluation such systems must undergo before procurement. This paper reviews African fintech AI governance across global, continental, and Nigerian instruments, and shows that safety is affirmed as a principle while pre-deployment evaluation is operationally unspecified. Generic safety benchmarks cannot surface the failure modes most relevant to this domain, since none contain Nigerian institutional content or test for false positive misclassification of legitimate financial communications. These claims are demonstrated using SafeAlert, a purpose-built evaluation kit applied to six commercial models across three system prompt conditions. Results show that models resisting generic harmful content requests still produce complete fraud scripts under specific framing, and that several models misclassify most legitimate Nigerian bank communications as suspicious or fraudulent, a failure invisible to standard safety evaluation. The paper concludes with a regulatory framework proposing pre-deployment evaluation requirements for the CBN, NITDA, SEC, and the AU, arguing that the identified gap reflects an absence of regulatory specification, not a shortage of technical or financial resources.