Governance

Whistleblower Policy

Speak up in confidence. Rockshield MFB provides secure, protected channels for staff, customers, vendors and the public to report suspected wrongdoing without fear of retaliation.

Last updated: 9 July 2026

Confidential

Your identity is protected end-to-end unless disclosure is compelled by law.

Protected

No retaliation. No demotion. No dismissal for a report made in good faith.

Independent

Reports go to the Board Audit Committee, independent of executive management.

1. Purpose

This policy is issued in line with the Central Bank of Nigeria Guidelines for Whistleblowing in the Nigerian Banking Industry, the NDIC Framework on Whistleblowing, the Money Laundering (Prevention and Prohibition) Act and the Bank's own Code of Corporate Governance. It provides a formal, safe and confidential means of raising concerns about actual or suspected wrongdoing at Rockshield MFB.

2. Who can blow the whistle

  • Members of staff (permanent, contract, intern or vendor-supplied).
  • Customers of the Bank.
  • Suppliers, service providers and consultants.
  • Board members, shareholders and members of the public.

3. What to report

  • Fraud, theft, embezzlement or misappropriation of funds.
  • Bribery, corruption, kickbacks or facilitation payments.
  • Money-laundering and terrorism-financing red flags.
  • Insider abuse, self-dealing or unauthorised related-party transactions.
  • Manipulation of financial records or falsification of returns to the CBN / NDIC.
  • Violation of the Bank's Code of Conduct, HR policies or credit policies.
  • Cybersecurity incidents, data breaches or IT abuse.
  • Harassment, discrimination or workplace misconduct.
  • Any action that endangers the health, safety or dignity of staff or customers.

4. How to make a report

You may report through any of the following independent channels. Please provide as much detail as possible — dates, names, amounts, locations, documents and how you came to know of the matter — so the report can be properly investigated.

5. Anonymous reports

You may choose to remain anonymous. However, providing your contact details (which will be kept strictly confidential) allows the investigation team to seek clarification and share the outcome with you.

6. Protection of whistleblowers

  • The identity of a whistleblower is kept confidential and disclosed only where required by law, court order or regulatory directive.
  • No employee will be dismissed, demoted, harassed, discriminated against or subjected to any form of retaliation for making a report in good faith.
  • Any staff member found to have retaliated against a whistleblower will face disciplinary action, up to and including summary dismissal.
  • Malicious, false or frivolous reports made in bad faith will be treated as misconduct.

7. Investigation process

  • Reports are received by the Chief Internal Auditor and forwarded to the Board Audit Committee.
  • An acknowledgement (where contact details are provided) is issued within five (5) working days.
  • Investigations are handled discreetly by an independent team and, where required, external investigators.
  • Findings are reported to the Board Audit Committee, which decides on corrective action, disciplinary measures and regulatory disclosures.
  • Material issues involving fraud or breach of CBN regulation are reported to the CBN and NDIC as required by law.

8. Record keeping

All reports, investigation files and outcomes are kept securely for a minimum of six (6) years in line with CBN record-retention requirements and are accessible only to authorised officers.

9. Review of this policy

This policy is reviewed at least once every two years, or sooner where regulation, business practice or the risk landscape changes materially.