Nigeria’s exams and admissions procedures currently operate at such a scale that a single technical breakdown might quickly become a national legitimacy issue. With over 2.2 million applicants processed through about 966 CBT centers in the 2026 UTME cycle, and admissions routed through JAMB’s Central Admissions Processing System (CAPS) platform, security is no longer just a back-office IT issue; it is a matter of educational equity, public trust, and administrative law.
JAMB’s 2026 disclosure of unauthorised remote access during the UTME in Warri, Delta State demonstrated exactly how insufficient access control, unvetted third-party integration, and lack of real-time monitoring can harm not only individual results but also confidence in the entire admissions pipeline.
A national examination system’s credibility depends on its capacity to demonstrate who took the test, who altered the record, and who had the right to access the data. That is the actual integrity issue with Nigeria’s computer-based testing system. JAMB is no longer in charge of a simple exam. Millions of Nigerian youths seeking admission into tertiary institutions are covered by the statewide digital examination in 2026, and CAPS is still the main hub for admissions processing and maintaining retrievable records for educational decision-making. A breach at one location is not a local inconvenience at that scale.
It poses a threat to the education nationwide. The system and national identity are becoming increasingly intertwined. In order to create a profile code and complete the registration process, JAMB needs candidates to use a National Identification Number (NIN). Additionally, its own portals now allow downstream adjustments for essential identity elements including name, date of birth, gender, and state or local government. By requiring the NIN as the primary means of identification, supporting NIMC verification, multi-factor authentication, continuous monitoring, incident response, and transaction recording, the National Information Technology Development Agency (NITDA’s) draft Digital Public Infrastructure (DPI) technical standards move in the same direction. In other words, identity is now infrastructure. When identity fails, education service delivery fails with it.
Consent and auditability are therefore more important than many officials still acknowledge. The consent flow of NINAuth, which NIMC has positioned as the official and only service for NIN-based verification and authentication, is designed to display the asking organization and the requested data prior to approval. That’s the proper course. However, in reality, consent becomes little more than a box checked on a screen if a student is unable to later demonstrate what was granted, when it was approved, and for what specific reason. That is poor governance in a high-stakes situation like admissions. The issue became tangible with JAMBS’s 2026 remote-access disclosure.
During the UTME at the College of Education, Warri, the Board’s official channels reported unauthorized remote access to candidates’ computers. According to Nigerian police, preliminary investigations connected suspects to unauthorized remote access during the exam. JAMB withheld results from some sessions in four CBT centers over manipulation, unauthorised access, and coordinated cyber-assisted fraud. When that occurs, malpractice is no longer the only problem. It becomes a legitimacy crisis. Candidates begin to ask whether scores can be trusted, institutions question the integrity of the shortlist before them, and parents lose confidence in a system that claims to separate merit from manipulation. The implications of poor controls extend beyond a terrible exam day.
Weak identification checks may allow for inaccurate onboarding during the registration or profile update phases. Inadequate account security may allow for profile takeover. It may be impossible to determine whether a change was fraudulent or authorized due to inadequate logging. A candidate may be unable to contest the sharing or use of identifying data due to inadequate consent trails. There are already warning indicators in Nigeria.
JAMB’s bulletins have documented instances when applicants paid syndicates for illicit help, and it has summoned candidates and institutions for alleged registration fraud and forged certificates. The lesson is simple: the back end of admissions becomes questionable if the front end of identity assurance is compromised. Here, policy is not lacking. It’s just not applied consistently.
The NDPR set the baseline by defining consent as freely given, specific, informed, unambiguous, as well as mandating privacy policies, designated data protection officers, and regular audits. Since 2025, the NDPC’s implementation mandate under the Nigeria Data Protection Act has served as the current enforcement framework, but the essential requirement remains the same: companies must demonstrate lawful processing and accountability. That is consistent with global practice.
NIST’s digital identification guidelines focus on rigorous identity proofing and evidence verification, whereas European authorities view valid permission and useable logs as critical to authorized processing and subsequent inquiry. Nigeria doesn’t need to create a new standard. It must apply the one it already claims to believe in. Policy responses should be direct.
It is necessary to increase, not assume, the level of verification at registration correction points. Candidates should be able to access and comprehend the detailed, time-stamped consent records. Tamper-resistant audit logs should be kept long enough to support legal proceedings, inquiries, and disputes. While NITDA PKI laws mandate protected logs and minimum retention periods, NITDA’s DPI requirements already mandate system and application logs, transaction recording, specified incident-response times, and multi-year retention for audit records. For its part, JAMB should provide more precise post-event explanations, reveal impacted workflows without waiting for rumors to dominate the story, and provide institutions and students with a verified route for independent review in cases where results or admission status are disputed. Transparency is not public PR in a nation where life prospects are determined by admissions. It is part of the security architecture.
. Adesola, CISSP Cybersecurity Professional
Join BusinessDay whatsapp Channel, to stay up to date
Open In Whatsapp
