.......The bank says its certification under the latest PCI DSS version covers card issuance, ATMs, POS transactions and payment processing, but certification does not eliminate the risk of fraud or data breaches.
Union Bank of Nigeria says it has secured certification under the Payment Card Industry Data Security Standard (PCI DSS) version 4.0.1, as Nigerian financial institutions face growing pressure to strengthen the security of electronic payments.
The certification took effect on 11 August 2026, according to the bank.
Union Bank said the assessment covered its network infrastructure, card issuance, ATM and point-of-sale transactions, payment processing, reconciliation, settlement, chargebacks, dispute resolution and retail banking operations.
The bank was assessed in the PCI DSS Service Provider category.
PCI DSS provides technical and operational requirements for organisations that store, process or transmit payment card data.
The standard aims to reduce the risk of cardholder data being exposed or misused.
But certification does not mean that customers face no risk of fraud.
It indicates that an organisation has undergone an assessment against the applicable requirements of the standard.
The PCI Security Standards Council lists version 4.0.1 as the current PCI DSS edition and provides specific assessment documentation for service providers.
What the certification means for customers
For Union Bank customers, the development matters because card payments expose banks to risks that range from stolen card details to attacks on payment infrastructure.
The certification covers several systems through which customers use cards, including ATMs and POS terminals.
The Central Bank of Nigeria has long treated payment-card security as part of its payments-system oversight.
Its payments-system framework identifies PCI DSS among the security standards applicable to Nigeria's financial services industry.
The CBN's payments framework also calls for valid certification and regular review and re-certification of relevant payment systems and infrastructure.
That means security compliance is not a one-off exercise.
Banks must continue to monitor their systems as threats, technologies and payment methods change.
A year-long assessment
Union Bank said the latest certification followed a year-long assessment involving quarterly reviews.
It said departmental, business and functional heads worked with cybersecurity firm Digital Encode during the process.
CyberCube, described by the bank as an accredited Qualified Security Assessor, conducted the final independent audit.
Union Bank's Managing Director and Chief Executive Officer, Yetunde B. Oni, said: “The security of our customers’ information is central to everything we do at Union Bank.
This certification reaffirms that our payment systems and processes meet a rigorous global standard, and it reflects the discipline of colleagues across the Bank who work every day to keep customer data safe,”
The statement presents the certification as evidence of the bank's security controls.
However, it does not provide details of any vulnerabilities identified during the assessment, or whether the auditors required corrective action before certification.
Those details are normally important when assessing how much practical protection a certification provides.
Union Bank has held PCI certification before
The latest certification is not Union Bank's first experience with PCI DSS.
The bank previously reported PCI DSS certification under older versions of the standard.
In 2018, it said it had upgraded to PCI DSS version 3.2 after first obtaining PCI DSS certification in 2014.
Union Bank also announced international certifications covering information security and business continuity in subsequent years.
The move from older PCI DSS versions to version 4.0.1 reflects changes in the global payment-security framework rather than the introduction of card-data security requirements for the first time.
The PCI Security Standards Council published version 4.0.1 in January 2025.
Why payment security matters in Nigeria
Nigeria's rapid shift towards electronic payments has increased the importance of protecting payment infrastructure.
The CBN's Payments System Vision 2025 identified safety, reliability and resilience as key objectives for the country's payments system.
It also called for stronger minimum security requirements and improved consumer protection.
The regulator has also introduced measures aimed at reducing card fraud, including requirements around transaction monitoring, authentication and protection of card information.
The wider payment ecosystem includes banks, card schemes, switches, payment processors and other service providers.
A weakness in one part of that chain can affect customers beyond the organisation where the weakness occurs.
Certification is not a guarantee against fraud
For customers, the most important distinction is between compliance and absolute security.
A PCI DSS certification shows that an organisation has met the applicable requirements assessed under the standard.
It cannot guarantee that a bank will never suffer a cyber attack, data breach or fraudulent transaction.
That distinction is increasingly important as Nigerian consumers use cards, mobile banking, POS terminals and other electronic payment channels more frequently.
Union Bank's certification therefore provides an assurance about its compliance status, but customers should still protect card details, PINs, passwords and authentication codes.
What happens next?
Union Bank says the certification maintains its PCI DSS status and reinforces its payment-security controls.
The next test will be whether the bank can sustain those controls as its systems and payment services evolve.
For regulators and customers, continued monitoring will matter as much as the certification itself.
The wider issue is whether compliance translates into fewer security incidents, stronger protection of customer data and faster responses when payment fraud occurs.
