Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Should Your Board Review Risk Quarterly or Monthly?Regulatory Obligations Management
5 min readFor Risk Managers

Should Your Board Review Risk Quarterly or Monthly?

The question isn't academic anymore. Between now and March 2026, the Central Bank of Nigeria, Bank of Ghana, and South African Prudential Authority have all issued directives making board-level risk governance a binding obligation. If your board sees risk reports only once a year at the AGM, you're already behind.

Here's how to structure your board's risk governance cadence based on what these regulators are actually looking for.

The Decision You're Facing

You need to decide how often your board should formally review and approve risk management decisions. This isn't about compliance theater. The CBN requires banks to meet new minimum capital thresholds by March 31, 2026, which means your board needs to approve a recalibrated risk appetite framework reflecting your new capital structure. The BoG's Risk Management Directive requires board-approved frameworks suitable for your institution's size and complexity. The South African Prudential Authority has named third-party risk management as its primary supervisory focus for 2025, so your board needs documented evidence of concentration risk decisions and operational resilience approvals.

The real question: how do you structure board engagement so it's substantive, not performative?

Key Factors That Affect Your Choice

Three variables drive your cadence decision:

Regulatory jurisdiction and scope. If you're a Nigerian bank subject to the CBN's fraud response directive (under 30 minutes for fraud incidents), your board needs visibility into operational risk metrics more frequently than an institution without real-time monitoring obligations. If you're a Ghanaian bank covered by the Climate-Related Financial Risk Directive effective January 2026, your board must review climate risk integration at least annually, but material climate exposures may require quarterly updates.

Capital adequacy pressure. If you're still working toward the CBN's March 2026 capital thresholds, your board should be reviewing capital adequacy and risk appetite monthly until you hit compliance. After that, quarterly may suffice unless your capital position deteriorates.

Third-party concentration. If you rely heavily on external service providers, the PA's 2025 supervisory focus on vendor risk means your board needs regular updates on concentration risk and resilience testing results. A single critical vendor failure can trigger supervisory action, so quarterly reviews are the minimum.

Path A: Monthly Board Risk Committee Meetings

Choose this path if:

  • You're a Nigerian bank still working toward the CBN's March 31, 2026 capital requirements
  • You operate in multiple jurisdictions with overlapping directives (e.g., CBN recapitalization plus BoG liquidity monitoring)
  • You have material third-party concentration risk and the PA is your primary regulator
  • Your institution is implementing real-time AML monitoring to meet the CBN's 2025 exposure draft requirements

Monthly cadence gives your board the granularity to approve incremental risk appetite adjustments as your capital position changes. It also creates a documented trail of board decisions on vendor risk assessments, which is exactly what the PA is looking for during examinations.

Structure monthly meetings around decision rights, not information dumps. Your board should approve:

  • Changes to risk appetite statements tied to capital adequacy
  • New material vendor relationships or changes to critical service providers
  • Operational risk incidents that exceeded impact tolerance thresholds
  • Updates to the liquidity risk strategy required under the BoG's Liquidity Risk Management Directive 2026

Use ISO 31000's risk treatment framework to organize each decision: what risk was identified, what treatment was selected, who owns the residual risk, and what monitoring is in place. Monthly meetings work when your board is actively governing risk, not passively receiving reports.

Path B: Quarterly Board Reviews with Monthly Committee Oversight

Choose this path if:

  • You've already met the CBN's capital thresholds and your position is stable
  • You're a Ghanaian institution with moderate complexity and no real-time monitoring obligations
  • You're a South African bank with diversified third-party relationships and no single-vendor concentration risk
  • Your climate risk exposure is material but not rapidly changing (e.g., you're not in a flood-prone region with deteriorating infrastructure)

Quarterly board reviews meet the BoG's requirement for annual board-level review of liquidity risk strategy while giving your board three additional touchpoints during the year. Delegate operational risk oversight to a monthly risk committee that escalates material issues to the full board quarterly.

This structure works if you pair it with clear escalation thresholds. Your risk committee should escalate to the board when:

  • Any operational risk incident exceeds your documented impact tolerance
  • A vendor risk assessment identifies concentration risk above your board-approved threshold
  • Your capital adequacy ratio drops below the buffer you set above the CBN's minimum
  • Climate risk scenario analysis reveals material exposure not previously disclosed

Use COSO ERM to connect your risk committee's work to the board's strategic priorities. Your quarterly board pack should show how operational risk decisions supported or constrained strategic objectives, not just list incidents.

Path C: Annual Board Approval with Quarterly Executive Oversight

Choose this path if:

  • You're a specialized deposit-taking institution or non-bank financial institution in Ghana (your Climate-Related Financial Risk Directive deadline is January 2027, giving you more runway)
  • You're a small or medium-sized institution with low complexity and no material third-party concentration
  • You operate in a single jurisdiction with stable regulatory expectations

Annual board approval meets the minimum regulatory expectation, but only if your executive team maintains quarterly oversight and your board receives immediate notification of material risk events. This structure only works if your risk universe is genuinely stable.

Annual approval should cover:

  • The risk management framework itself (board approval required under the BoG directive)
  • Risk appetite statements and tolerance thresholds
  • The climate risk integration plan (if you're a Ghanaian institution preparing for 2027 compliance)
  • The annual liquidity risk strategy review required by the BoG

Your executive team's quarterly reviews should focus on early warning indicators: capital trends, vendor performance metrics, operational incidents, and climate exposure changes. If any of these indicators breach your thresholds, escalate to the board immediately, don't wait for the annual cycle.

Summary Matrix

Cadence Best For Regulatory Fit Board Approves
Monthly Nigerian banks pre-March 2026; institutions with high third-party concentration CBN capital compliance; PA vendor scrutiny Risk appetite changes, vendor decisions, material incidents
Quarterly Ghanaian banks with moderate complexity; South African banks post-Basel III implementation BoG liquidity reviews; PA climate disclosure prep Strategic risk decisions, climate scenario results, capital buffer changes
Annual Low-complexity institutions; non-banks in Ghana with 2027 climate deadline Minimum BoG framework approval requirement Risk framework, risk appetite, annual liquidity strategy

The common thread across all three regulators: your board must be actively involved in risk oversight, with documented evidence. The CBN wants to see board minutes showing capital adequacy discussions. The BoG wants board approval of your risk management framework. The PA wants board-level decisions on vendor concentration risk.

If your current board pack is a 40-page risk report that no one reads, you're solving the wrong problem. Restructure your governance cadence around decision rights first, then build the reporting to support those decisions. That's what these regulators are actually looking for.

Application Security Isn’t Optional Anymore.

You Might Also Like