← Back to Portfolio

Case Study ]

Zenbridge: from Unsatisfactory to Satisfactory in seven months

ConceptualSenior BA / Process Lead7 MonthsCBN RemediationNigerian Banking OperationsLagos, Nigeria
5%SME SLA breach rateDown from 41%, three months post go-live
6.4 daysRetail cycle timeDown from 16.8 days; a 62% reduction
9.8 daysSME cycle timeDown from 23.4 days; a 58% reduction
8%Rework rateDown from 33%; a 76% improvement

01Context ]

Zenbridge Bank is a CBN-licensed Tier-2 commercial bank in Lagos handling over 1,100 onboarding cases a month. This is a conceptual case study: a 7-month remediation program in which I was brought in by the COO office as Senior BA and Process Lead to own discovery, requirements, solution design, and delivery oversight.

The trigger was a routine CBN Risk-Based Supervision examination that rated the bank's KYC process controls “Unsatisfactory”, with a 60-day deadline for a remediation plan and a follow-up review scheduled at Month 7.

02Business Problem ]

The CBN findings were specific: 41% of SME cases had no auditable BVN verification record, NFIU screening was happening after account opening in 28% of cases, and 22% of sampled accounts had no CDD verification trail at all.

Underneath the findings sat the operating model. Over 1,100 cases a month were managed entirely through shared email inboxes and three separate Excel trackers. There was no case state, no enforced sequence of checks, and no audit trail an examiner could walk. The rating was not an accident; it was the system working as built.

03Constraints ]

  • A regulator-set clockSixty days to a remediation plan, follow-up examination at Month 7. Every solution decision was tested against one question: will this be live, adopted, and auditable before the CBN returns?
  • No procurement windowBuying and implementing a KYC platform would not fit the timeline. The solution had to be built entirely within the bank's existing Microsoft 365 tenant.
  • Operations could not pauseThe 1,100-case monthly volume kept flowing through the remediation. The cutover had to be phased, supported, and reversible enough not to create its own backlog.
  • Findings define doneEach CBN finding, the BVN records, the screening sequence, the CDD trail, had to map to a specific, evidencable control in the new process. Faster operations without examiner-ready evidence would still fail the review.

04Stakeholder Landscape ]

The program was sponsored by the COO office and delivered with the Head of Internal Control, 28 KYC analysts, and 4 team leaders across Lagos and Abuja, with the CBN as the external examiner whose expectations shaped the design. The escalation chain built into the new process ran from Team Leader up to a daily breach digest on the COO's desk.

Adoption was managed deliberately: team leaders were trained as super users a week ahead of the analyst rollout, so every team had in-room support through the transition rather than a helpdesk ticket queue.

05Research ]

I ran six shadow sessions with KYC analysts in Lagos and Abuja to document the actual process, not the policy-documented version. That is where the quiet defects surfaced, including the finding that analysts were handling Nigerian name formats, Yoruba, Igbo, and Hausa, in ways the NFIU screening system did not recognise.

Before go-live, I ran a mock CBN examination walkthrough with the Head of Internal Control, selecting 10 live case files and testing them the way an examiner would. The exercise drove the final audit trail architecture: the system was designed backwards from the questions an examiner asks.

06Strategy ]

Turn every CBN finding into a gate the process cannot skip. NFIU screening moved to a pre-approval gate so it could never again happen after account opening. BVN verification became a hard gate with automated audit write-back, so the evidence creates itself. SLA breaches escalate automatically up the chain instead of relying on someone noticing.

And build it all inside the Microsoft 365 tenant the bank already owned: SharePoint as the case system of record, Power Automate as the enforcement layer, Power BI as the always-current management view. No procurement, no new vendor, no timeline risk.

07Options Considered ]

  • option 01Procure a dedicated KYC platformThe long-term textbook answer, and the wrong one for a Month 7 examination date. Procurement, implementation, and integration would consume the remediation window before a single control went live.
  • option 02Remediate with policy and training aloneRetraining analysts against the existing inbox-and-spreadsheet model might improve behaviour, but it could not produce auditable BVN records, enforced screening sequence, or a CDD trail. The findings were structural, not behavioural.
  • option 03Build the control layer on the existing M365 tenantThe chosen path. SharePoint, Power Automate, and Power BI were already licensed and deployable immediately, which put the entire schedule risk into design and adoption, the parts the program could actually control.

08Trade-offs ]

  • Platform pragmatism over best-of-breed toolingSharePoint and Power Automate are not a purpose-built KYC suite, and the design absorbed that: six flows carried the enforcement logic a platform would have provided natively. In exchange, the bank hit a regulator's deadline with software it already owned.
  • Hard gates over analyst discretionThe BVN and screening gates removed flexibility analysts previously used to keep cases moving. That was the point: discretion in the old process is exactly what produced unauditable records. Cycle time still fell, because rework fell faster.
  • A phased 3-day cutover over a clean switchRunning cutover in phases with hypercare stretched the transition and required double-tracking cases briefly, but it protected 1,100 monthly cases from a big-bang failure and let super users absorb issues team by team.

09Delivery Process ]

  1. 01. Process observationSix shadow sessions across Lagos and Abuja documenting the real process, surfacing the Nigerian name format handling that NFIU screening did not recognise.
  2. 02. Requirements and rulesBuilt the Business Requirement Document, Business Rules Register, and the Nigerian KYC Document Requirements Matrix covering all customer types, including the Business Name versus Limited Company distinction driving SME rework.
  3. 03. Flow designDesigned six Power Automate flows: the NFIU pre-approval screening gate, the BVN hard gate with audit write-back, and the SLA escalation chain from Team Leader through to the COO daily breach digest among them.
  4. 04. Mock examinationRan the mock CBN walkthrough with the Head of Internal Control on 10 live case files, and fed the gaps straight into the audit trail architecture.
  5. 05. Change managementTrained the 4 team leaders as super users a week ahead of rollout to the 28 analysts, so each team transitioned with support from inside the room.
  6. 06. Cutover and submissionCoordinated the phased 3-day cutover with hypercare, decommissioned the 5 shared email inboxes, and supported the bank's CBN submission for the follow-up targeted review.

10Technical Architecture ]

SharePoint Online holds the case as the single source of record. Six Power Automate flows enforce the controls: NFIU screening before approval, BVN validation through the NIBSS API with audit write-back, NIN checks against the NIMC portal, CAC-based routing that separates Business Name from Limited Company cases, and automatic SLA escalation. Power BI refreshes every 15 minutes, giving management a live view where three Excel trackers used to disagree with each other.

Case Management

SharePoint Online (M365)

Automation

Power Automate (6 flows)

Analytics

Power BI (15-min refresh)

BVN API

NIBSS Validation API

Screening

NFIU + UN/OFAC + OFAC SDN

NIN

NIMC Verification Portal

CAC

Business Name / Ltd Co routing

Tracking

Jira + Confluence + Miro

11Outcomes ]

At the Month 7 follow-up examination, the CBN re-rated the bank's KYC process controls “Satisfactory”, the program's target outcome, achieved on schedule.

The operational numbers moved with it. The SME SLA breach rate fell from 41% to 5% within three months of go-live. Retail cycle time dropped from 16.8 to 6.4 days and SME cycle time from 23.4 to 9.8. Rework fell from 33% to 8%, with the single Business Name versus Limited Company routing rule cutting SME rework from 41% to 7% on its own. Five shared email inboxes were decommissioned.

Artefacts delivered

Process Observation Reports
CBN Compliance Register
Business Requirement Document
Power Automate Flow Specs
SharePoint Architecture Spec
Business Rules Register
KYC Document Requirements Matrix
UAT Test Cases
Mock CBN Examination Report
Benefits Framework

12Metrics ]

5%SME SLA breach rateDown from 41%, three months post go-live
6.4 daysRetail cycle timeDown from 16.8 days; a 62% reduction
9.8 daysSME cycle timeDown from 23.4 days; a 58% reduction
8%Rework rateDown from 33%; a 76% improvement

13Lessons Learned ]

  • Shadow the work, not the policy. The name-format screening gap and the real rework drivers were invisible in every process document and obvious within six observation sessions.
  • Design the audit trail from the examiner's chair. The mock CBN walkthrough on live case files was worth more than any requirements review; it converted "auditable" from an adjective into an architecture.
  • One precise rule can outperform a system. The Business Name versus Limited Company routing distinction was a single row in the requirements matrix and the largest single driver of the rework improvement.