Over the last decade, financial institutions have invested billions of dollars in strengthening compliance programmes. Yet despite increasingly sophisticated regulations, banks around the world continue to experience operational failures, foreign exchange losses, cyber incidents, third-party failures, and regulatory sanctions.
Industry observers argue that the problem is no longer the absence of compliance, it is the fragmentation of compliance.
Many institutions continue to treat enterprise risk management, regulatory compliance, treasury governance, technology risk, operational resilience, and strategic decision-making as separate disciplines. As digital banking continues to expand and fintech partnerships become increasingly common, these disconnected approaches are proving inadequate for managing today’s interconnected financial risks.
Among the professionals advocating a different approach is Nigerian enterprise risk specialist Adekunle Samuel Adekoya, whose work in banking risk governance has attracted increasing attention among practitioners and researchers alike.
Drawing on years of experience overseeing enterprise risk within one of Nigeria’s leading commercial banks, Adekoya has developed what he describes as the Enterprise Risk Compliance Architecture (ERCA)—a governance framework designed to integrate enterprise risk management, regulatory compliance, treasury oversight, foreign exchange exposure, stress testing, and executive decision-making into a unified enterprise-wide control system.
Unlike traditional compliance models that often operate independently from business operations, ERCA recognizes that modern banking risks rarely occur in isolation.
A liquidity event may quickly become a regulatory issue.
A technology integration may introduce operational, cyber, third-party, and reputational risks simultaneously.
Foreign exchange volatility can influence capital adequacy, treasury decisions, liquidity planning, and supervisory expectations within days.
According to Adekoya, organisations must therefore stop managing risks in isolated silos.
“The question should not simply be whether an institution complies with regulations,” Adekoya explains.
“The more important question is whether governance, compliance, treasury, operations, technology, and executive decision-making are working together as one coordinated risk management system.”
The idea reflects a broader shift occurring throughout the banking industry.
Following the COVID-19 pandemic, financial institutions have faced an unprecedented combination of digital transformation, heightened cybersecurity concerns, volatile foreign exchange markets, evolving regulatory expectations, and increasing reliance on third-party financial technology providers.
These developments have exposed weaknesses in governance structures built around individual risk functions rather than enterprise-wide resilience.
Professionals working within treasury operations understand this challenge particularly well.
Treasury decisions concerning liquidity, funding, foreign exchange positions, market exposure, and capital allocation influence virtually every aspect of a commercial bank’s financial stability. Effective governance therefore requires continuous coordination between treasury management, enterprise risk functions, regulatory compliance teams, operational units, technology groups, and executive leadership.
Having spent years providing enterprise-wide oversight for Treasury Operations, liquidity management, foreign exchange exposure, and regulatory compliance, Adekoya believes this coordination cannot be achieved through traditional reporting structures alone.
Instead, organizations require integrated governance architecture capable of connecting strategic decisions with real-time risk intelligence.
One of ERCA’s distinguishing features is its emphasis on enterprise visibility.
Rather than producing separate reports for operational risk, compliance, treasury, or technology functions, the framework promotes integrated risk dashboards capable of providing executives with a consolidated view of organizational exposure.
This allows senior management to evaluate relationships between risks instead of responding to isolated events after problems have already materialized.
The framework also introduces stronger alignment between an organization’s risk appetite and executive decision-making.
Adekoya argues that risk appetite should not remain a static policy document reviewed only during regulatory examinations.
Instead, it should function as a practical management tool that guides treasury activities, fintech partnerships, strategic initiatives, technology investments, and business growth on a continuous basis.
Industry practitioners say this philosophy represents an evolution from compliance-centered governance toward resilience-centered governance.
That distinction is becoming increasingly important as banks pursue partnerships with financial technology companies.
Modern payment ecosystems involve complex interactions among banks, fintech providers, cloud platforms, payment gateways, third-party service providers, and regulators. Each integration introduces interconnected operational, cybersecurity, financial, compliance, fraud, and reputational risks.
Experts note that these relationships demand governance frameworks capable of evaluating enterprise-wide consequences before implementation rather than responding after incidents occur.
Adekoya’s emphasis on integrated governance reflects practical experience gained through evaluating enterprise risks associated with treasury operations, foreign exchange management, regulatory examinations, digital banking initiatives, and complex technology integrations within Nigeria’s financial sector.
His work has also extended into academic research, where he has explored the relationship between regulatory complexity, foreign exchange volatility, and enterprise resilience in emerging-market banking systems. His published research proposes governance structures that combine board oversight, integrated compliance processes, stress testing, foreign exchange exposure management, and increasingly, AI-assisted risk analytics to strengthen institutional resilience.
As regulators around the world continue to place greater emphasis on operational resilience, enterprise governance, and integrated risk management, frameworks such as ERCA may become increasingly relevant beyond Nigeria.
For financial institutions operating in emerging markets, the future of risk management may depend less on creating additional control functions and more on connecting existing ones through coherent enterprise architecture.
“Resilient institutions are not simply those with more policies,” Adekoya says.
“They are institutions that understand how risks interact, how decisions create new exposures, and how governance can bring those moving parts together before problems become crises.”
In an industry where financial stability depends on anticipating uncertainty rather than merely reacting to it, this integrated approach offers a compelling vision for the next generation of enterprise risk governance.
Follow Us on Google News
Follow Us on Google Discover