NDPA modules · Impact assessments
Risk drops on paper the moment somebody promises a fix.
Eight assessments, plotted where they started and where they claim to be now. Asiri only lets a risk move once the fix that moves it is in place — so the credit scoring model still sits at critical, not at high.
- Credit scoring model v2
- Facial recognition at sign-up
- Call centre recording
- Loan collections outreach
- Agent network expansion
- Merchant analytics dashboard
- Customer support chatbot
- Staff device monitoring
Before and after, per assessment
Two are held in place because the fixes are only promises
Five of the eight show the same rating before and after, and they are not the same story. Two are low or dormant with nothing left to reduce. One was sent back unfinished. The two in red are the ones that matter: the fixes that would move them exist only on paper.
Facial recognition stays at high because biometric data cannot be made less sensitive, only less widely held — and the credit model stays critical because nobody has been assigned to review a decline.
Credit scoring model v2
DPIA-2026-0004 · launch planned 15 Aug · Ngozi E.
criticalcriticalFacial recognition at sign-up
DPIA-2026-0002 · submitted 3 weeks ago · Tunde A.
highhighCall centre recording
DPIA-2025-0018 · sent back 2 months ago · Ngozi E.
mediummediumLoan collections outreach
DPIA-2025-0016 · signed off Feb · Tunde A.
highmediumAgent network expansion
DPIA-2026-0003 · updated 5 days ago · Segun O.
mediumlowMerchant analytics dashboard
DPIA-2026-0001 · signed off 6 weeks ago · Blessing U.
mediumlowCustomer support chatbot
DPIA-2025-0014 · signed off Jan · Blessing U.
lowlowStaff device monitoring
DPIA-2026-0005 · started yesterday · Segun O.
nonenone
DPIA-2026-0004 · credit scoring model v2
Five fixes agreed. Two of them exist
Launch is planned for 15 August. Eri's note to the approver is one sentence long: human review of declines and the appeal route are both only planned — ask for those two before anything else, they are what makes the residual risk defensible.
Until they land, this model decides who gets credit with no person in the loop and no way to contest it. That is the version of §37 the NDPC cares about.
- In place
Delete scoring inputs 12 months after the decision
Built into the retention rules and running.
- In place
No health or disability data in the model
Enforced at the feature layer, verified by Asiri against the field list.
- Planned only
A person reviews every decline
The fix the whole residual rating depends on. Nobody has been assigned to do the reviewing.
- Planned only
An appeal route customers can actually use
Promised in the assessment, absent from the product. Zainab Yusuf has already asked for one.
- Planned only
The privacy notice mentions automated decisions
Notice v4 does not say a model decides on loans. It has to, before launch.
When it stops being optional
An assessment written after launch is a report, not an assessment
The point of the exercise is that it can still change the design. Asiri asks the four questions when you connect a system or add a purpose — while the answer is cheap — rather than producing the document once the thing is already live.
And where the risk stays high after your fixes, the NDPC has to be consulted before you launch. Allow four to six weeks. That is a calendar fact, not a formality.
A machine decides something that matters
Credit, employment, access to a service. If a person is not in the loop, an assessment is compulsory and so is a way to contest the outcome.
Biometrics, health, or anything special
A face match, a fingerprint, a sick note. Sensitivity is not reduced by good intentions or by strong encryption.
Systematic monitoring of people
Staff device logging, agent activity tracking, public-space cameras. The question is proportionality, and it needs answering in writing.
Children, or data at real scale
Anything aimed at under-18s, and anything touching a large share of your customers. Both push an ordinary purpose into assessment territory.
Twelve templates, and none of them let you skip the hard question
Credit decisions, a new AI feature, face or fingerprint checks, identity at sign-up, marketing to existing customers, behaviour tracking, call recording, branch cameras, a new supplier, moving data abroad, staff device monitoring, health or disability data. Each arrives with its risks and fixes pre-filled, and each refuses to reduce a risk on a promise.