SLCB Achieves ISO/IEC 27001:2022 Certification, Strengthening Its Digital Banking Journey
The achievement reflects the Bank’s strategic focus on technology, resilience and information security, under the leadership of Managing Director Yusufu Abdul Silla and the technical direction of its CISO
Sierra Leone Commercial Bank Limited (SLCB) has reached an important milestone in its ongoing transformation with the successful certification of its Information Security Management System (ISMS) to ISO/IEC 27001:2022.
The certification, issued by MQA Certification UK Ltd, formally took effect on 30 September 2026 and is valid until 29 September 2029, subject to the requirements for maintaining certification.
For SLCB, the achievement represents an important step in strengthening the systems and processes through which the Bank protects information, manages information-security risks and supports the delivery of its banking services.
It is also a significant achievement for Sierra Leone’s indigenous banking sector, demonstrating the Bank’s commitment to aligning its information-security practices with an internationally recognised standard.
A strategic priority for the Bank
The achievement comes against the backdrop of SLCB’s continuing efforts to modernise its operations and strengthen its capacity to operate in an increasingly digital banking environment.
Under the leadership of Managing Director, Mr. Yusufu Abdul Silla, technology, digitalisation and operational resilience have become increasingly important elements of the Bank’s strategic direction.
As customers make greater use of digital banking channels and financial services become increasingly technology-driven, protecting information and maintaining the security and reliability of banking systems have become essential to the Bank’s operations.
The ISO/IEC 27001 certification is therefore closely aligned with this broader direction.
It provides SLCB with a structured framework for identifying information-security risks, applying appropriate controls, monitoring their effectiveness and continually improving the Bank’s information-security management practices.
Leadership from the Information Security function
A key driver of the certification journey has been the Bank’s Chief Information Security Officer (CISO), Mrs. Bintu Jonah, whose leadership has been central to bringing the certification process to completion.
Reacting to the achievement, the CISO described the occasion as a proud moment, noting:
“Humbled and proud to present our first-ever ISO/IEC 27001 certificate! I’m honoured to serve as CISO of Sierra Leone’s first indigenous bank to achieve this certification. Congratulations to us all on this remarkable achievement!”
The statement captures both the personal significance of the milestone and its wider institutional importance.
Achieving certification requires much more than putting technical security measures in place. It involves the development and implementation of policies, processes, controls, risk assessments, monitoring arrangements, staff awareness and governance mechanisms that work together as an Information Security Management System.
The CISO and the Information Security team have therefore played an important role in coordinating the technical and operational aspects of this work.
A Bank-wide achievement
One of the notable features of SLCB’s certification is the breadth of its scope.
The certified Information Security Management System covers all business processes and supporting functions involved in the delivery of the Bank’s products and services.
These include:
- Corporate Banking;
- Retail Banking;
- Digital Banking;
- Risk Management;
- Information Security Operations; and
- IT Operations.
The scope also extends to the information, people, processes, technology and supporting resources associated with these functions.
This is significant because information security is not confined to the ICT environment. The way information is created, accessed, processed, stored and shared involves people and processes across the entire organisation.
The certification therefore reflects a bank-wide effort involving Management, ICT and Information Security, Risk Management, Operations, Internal Audit, Human Resources and other business and support functions.
Why ISO/IEC 27001 matters
ISO/IEC 27001 is an internationally recognised standard for managing information security.
At its core is a systematic approach to understanding an organisation’s information-security risks and putting appropriate measures in place to address them.
For a financial institution, this has particular relevance.
Banks handle significant volumes of sensitive customer and institutional information and depend heavily on technology for the delivery of their services. Maintaining the confidentiality, integrity and availability of that information is consequently an important part of maintaining customer confidence and operational continuity.
SLCB’s certification provides a formal framework through which these responsibilities can continue to be managed and improved.
Part of a wider transformation
The certification should also be viewed within the wider transformation taking place across SLCB.
The Bank has been investing in digital banking, technology, infrastructure and operational resilience as it seeks to improve the way it serves customers and conducts its business.
In that context, information security is not an isolated initiative. It is an important component of the Bank’s digital journey.
The stronger the Bank’s digital capabilities become, the more important it is to ensure that the systems supporting those capabilities are appropriately protected and managed.
The ISO/IEC 27001 certification provides an important foundation for that work.
Management and Board commitment
The achievement also reflects the importance attached by the Bank’s leadership and governance structures to strengthening risk management, technology and operational resilience.
While the CISO and Information Security function have provided the specialist leadership required for the certification, the process has required cooperation across the Bank.
It is, ultimately, an institutional achievement.
The role of Management has been to provide the direction and support necessary for the Bank to pursue the certification, while the Board’s oversight provides an important governance dimension to the Bank’s approach to information security and technology risk.
The work continues
Obtaining the ISO/IEC 27001:2022 certification is an important milestone, but it is not the end of the journey.
Maintaining the certification requires the Bank to continue operating and improving its Information Security Management System and to remain responsive to changes in technology, emerging risks and the evolving digital banking environment.
For SLCB, therefore, the certificate represents both an achievement and a commitment.
It demonstrates that the Bank has established an information-security management framework that has been assessed against an internationally recognised standard. More importantly, it provides a platform for continued improvement.
For the Bank’s Management, staff and customers, the achievement is a moment to recognise the work that has gone into strengthening SLCB’s information-security environment.
For the CISO and the teams that worked on the certification, it marks the successful completion of an important phase of that journey.
And for SLCB as an institution, it is another step towards building a more secure, resilient and digitally capable bank.
A milestone for SLCB
The ISO/IEC 27001:2022 certification adds another important achievement to SLCB’s continuing transformation.
It reflects the strategic direction of the Bank’s leadership, the technical leadership of the CISO, the contribution of staff across different functions and the institution’s commitment to strengthening the way it manages information and technology.
For SLCB, the certificate is not simply recognition of what has been achieved. It is a commitment to maintaining the standard and continuing to build a secure and resilient foundation for the Bank’s future.



