Africa Advisory

The continent is leapfrogging into AI. The governance layer didn’t come with it.

African organisations are putting AI into live operations right now — in banks, payment rails, telcos, hospitals, energy operators and government agencies. Very few of them have anyone who can both build the thing and answer the regulator about it.

Europe built its data and technology control frameworks over twenty years, then had to retrofit AI onto them. Much of Africa is skipping that entirely — arriving at AI adoption without the legacy scaffolding, and without the legacy technical debt either.

That cuts both ways. There’s less to unpick, and genuine room to build it properly the first time. There’s also less control infrastructure to fall back on, thinner specialist capacity to hire from, fragmented regulation across jurisdictions, and international partners who increasingly want the controls evidenced rather than asserted.

The result is familiar across the continent: ambitious roadmaps, real progress, and a widening gap between what boards are being asked to attest to and what their organisations can currently demonstrate.

We close that gap from both ends — building the systems, and evidencing them.
Published research · Nigeria

Nigeria’s National AI Strategy, explained

The five pillars, the binding regulatory stack around them, the risk register, and an independent assessment of what the strategy gets right and what is missing. Status verified August 2026.

Read the explainer →
What we help with

AI first. The frameworks answer it.

AI adoption that survives a regulator’s question

Where AI can safely go in your business, what your data and licences actually permit, and what to build first.

AI enablement for your teams

Function-specific training on people’s real work, so capability is built in-house rather than rented indefinitely.

AI governance and data-usage controls

Frameworks, policies and shadow-AI discovery suited to African operating realities, not lifted from a European template.

Building the systems

Reporting, monitoring, document handling and intelligence pipelines, built to a standard you can evidence and handed over so you own them.

Regulatory readiness

NDPA (Nigeria), POPIA (South Africa), DPA (Kenya), DPA (Ghana), Rwanda’s DPP Law, and sector regulators — CBN, NCC, SEC, NCA, NITDA, ICT Authority, NDPC.

Privacy and data protection operating models

DPO functions, RoPAs, breach playbooks, and reporting to data protection authorities.

Cross-border data transfer assessments

Particularly for organisations moving data between African jurisdictions, Europe, the Gulf and Asia. Increasingly an AI question, since that’s where the models sit.

Cyber assurance and technology risk reporting

SOC 2, ISO 27001, NIST CSF, and board reporting that satisfies international counterparties.

Incident readiness and executive tabletops

Locally contextualised crisis scenarios for African executive teams.

Cyber and AI workforce development

Academy design, curriculum, and executive education.

Focus markets

Where we work

Nigeria

Primary focus market: NDPA, NDPC engagement, fintech, energy, telcos.

South Africa

POPIA, financial services, listed-company governance, mature private-sector buyers.

Rwanda

Government digitalisation, financial inclusion, regional headquarters work.

Ghana

Banking, telco, growing fintech ecosystem.

Kenya

Fintech, mobile money, regional tech HQs.

Pan-African

Multi-country groups, development finance institutions, regional regulators.

Priority sectors

Our deepest single-sector depth is physical commodity trading, energy and structured finance — crude grades and differentials, cargo operations and laytime, prepayment and borrowing-base facilities, letter-of-credit document checks.

Named engagements

Something you can take to a budget holder

Each is a bounded piece of work with a duration, not an open-ended advisory relationship.

AI engagements

3–4 weeks

AI Readiness Sprint

Where AI can safely go in your business, what your data and licences permit, and what to build first. Ends with a costed, sequenced plan.

Discuss this engagement →
2–4 weeks

AI Enablement Programme

Function-specific sessions where each person builds a working tool on their own real files and leaves able to use it without us.

Discuss this engagement →
2–3 weeks

Shadow AI Discovery

Find the AI your organisation is already using, assess what it’s touching, and decide what to sanction, secure, or shut down.

Discuss this engagement →
Half day

Board AI Governance Briefing

A half-day closed-door session bringing the board to a working understanding of AI risk, oversight, and the questions to ask management.

Discuss this engagement →
2 weeks

AI / Data Usage Policy Pack

Defensible policies for staff use of generative AI, third-party models and customer data. Deployable, not aspirational.

Discuss this engagement →
3–4 weeks

AI Assurance Review

Independent review of an AI system already in production — data flows, residency, vendor terms, approval boundaries, evaluation coverage.

Discuss this engagement →

Readiness and resilience engagements

4 weeks

NDPA Readiness Sprint

Structured assessment against Nigeria’s Data Protection Act, ending with a remediation roadmap your board can sign off.

Discuss this engagement →
3–4 weeks

Privacy Maturity Assessment

Independent benchmark against a jurisdiction-relevant framework, with a prioritised roadmap.

Discuss this engagement →
90 days

DPO Starter Pack Implementation

Stand up a credible DPO function — charter, RoPA, breach playbook, board reporting, training plan.

Discuss this engagement →
8–12 weeks

SOC 2 Readiness for African Tech Companies

Get audit-ready: scope, gap analysis, control build, evidence library, auditor introduction.

Discuss this engagement →
2–3 weeks

Cyber Resilience Tabletop Exercise

A scenario-driven executive simulation — ransomware, data breach, third-party compromise — with a written after-action report.

Discuss this engagement →
Scoped per programme

Capability Development Programme

Design or refine an academy, curriculum or workforce programme for measurable institutional impact.

Discuss this engagement →
Why us

Why Hunter McKenzie for this

We build, and we assure. Very few firms do both.

Twenty years on the assurance side of the table means the systems we build are designed by people who have spent a career finding out how systems like them fail.

International technology risk experience

Over two decades across Tier-1 banking, regulated trading technology, and one of South-East Asia’s largest digital platforms.

Practical understanding of African digital ecosystems

Sustained engagement with African regulators, media and ecosystem builders, including CNBC Africa, SABC, and the Cyber Security Indaba in Johannesburg.

Board-level and hands-on in the same engagement

Equally comfortable presenting to a board and writing the policy, or the system, that sits beneath it.

Plain business language

No acronym walls, no fear-selling, and a straight answer when the answer is that you shouldn’t build it.

In-country legal and implementation partners

We work with trusted local partners rather than parachuting in.

Start here

Let’s talk about your African operating environment.

Whether you’re putting AI into a regulated business for the first time, entering Nigeria, preparing for a regulator engagement, scaling an AI product across the continent, or building national capability — we’d welcome the conversation.