Skip to main content

ABOUT

Certifications & Accreditations

CAC registration under RC 1870949, statutory tax, pension, industrial training and employee compensation clearances, and current partner status with Microsoft, Cisco, AWS, Fortinet and Oracle.

Why Certification Matters in Nigerian Public Procurement

In public procurement, a certificate is not decoration — it is an eligibility gate. A tender for a public IT project will typically require evidence of incorporation with the Corporate Affairs Commission, a current tax clearance certificate for three years, pension and industrial training fund compliance, registration with the Bureau of Public Procurement, and, for information technology projects above the prescribed threshold, clearance from the National Information Technology Development Agency. A bid missing any one of these is not scored down; it is disqualified at the opening stage, however good the technical proposal behind it.

Beyond eligibility, documented procedure does work that a reference cannot. A written estimating, change control, testing and close-out discipline tells an evaluator that the work follow a documented process that an external auditor checks every year, rather than depending on which project manager happens to be assigned. A written information security policy tells a bank or a health institution that the way we handle their data is governed by a risk-assessed control set with defined owners, and that we have been audited against it. Both are increasingly requested by private buyers too, particularly in financial services.

We therefore treat compliance as an operational discipline rather than a bid-time scramble. The Director, Public Sector Business maintains a registration and clearance calendar with renewal dates and owners; certificates are renewed ahead of expiry, not after a tender exposes a lapse. Every document in the due diligence pack is version-controlled, and a complete, current pack can be issued to a buyer within one working day of a request.

Registrations and Statutory Clearances

What the company actually holds, with the issuing body for each. Certified copies are released to buyers on request. Where a clearance is due for renewal we say so rather than let a buyer discover it during evaluation.

Document Issuing body Reference Status
Certificate of Incorporation Corporate Affairs Commission RC 1870949 — Brilliant Esystems Limited, incorporated 8 December 2021 Current
Certificate of Incorporation Corporate Affairs Commission RC 1023637 — Mannir e-Systems Nigeria Limited Current
Tax Clearance Certificate Federal Inland Revenue Service Assessment years 2022, 2023 and 2024 Renewal due
Certificate of Compliance Industrial Training Fund Employer compliance, 2024 contribution year Renewal due
Pension Clearance Certificate National Pension Commission Employer compliance under the Pension Reform Act 2014 Renewal due
ECS Clearance Certificate Nigeria Social Insurance Trust Fund Employer compliance under the Employees’ Compensation Act 2010 Renewal due

What we do not hold

We are not ISO certified. This page previously claimed ISO 9001:2015 and ISO/IEC 27001:2022, and those claims have been removed. We work to the disciplines those standards describe and will say so in those terms, but we will not imply a certificate we do not have.

If ISO certification is a hard requirement in your evaluation criteria, tell us early. We would rather lose a tender on an honest answer than win one on a claim that fails at due diligence.

On technology partner tiers

This page previously listed five vendor partner tiers. Those were not held and have been removed. Partner status with a major vendor is earned through certified headcount, delivered revenue and audited customer references, and it is trivially checkable in the vendor’s own partner directory, so claiming one you do not hold fails at the first search.

The organisations we do work with, and the platforms we build on, are set out under Partners.

How the ISO Management System Actually Works in Delivery

Certification is only useful if it changes what engineers do on a Tuesday. Here is where the management system touches an engagement.

1

Bid and estimate under a controlled procedure

Estimates follow a documented method with a defined approval path by value. Scope assumptions, exclusions and risks are recorded at bid stage, so what is later called a change really is a change and can be evidenced as one.

2

Risk assessment and security classification

Before work starts, the engagement is assessed against our information security risk methodology. Data classification, access requirements, hosting location and any NDPR obligations are agreed in writing and reflected in the data processing agreement.

3

Design review and sign-off

Solution designs above a defined value go to the Architecture Review Board chaired by the Chief Technology Officer. Departures from the approved technology list require an explicit, minuted decision rather than a quiet substitution on site.

4

Controlled build, test and change

Development follows the secure development lifecycle with peer review and automated regression testing. Infrastructure changes go through change control with a rollback plan. Every change is logged with a requester, approver and outcome.

5

Access control and least privilege

Engineer access to client environments is granted per engagement, least-privilege, time-bounded and logged. Access lists are reviewed quarterly and revoked on reassignment. Privileged actions on monitored estates generate an audit record.

6

Acceptance, handover and documentation

Acceptance is against the documented criteria agreed at design stage. Close-out delivers as-built documentation, configuration, source code where applicable, runbooks and completed training records for the client team.

7

Service operation under measured levels

In-life service runs to agreed service levels with monthly reporting of achievement, incidents and problems. Security events on monitored estates flow to the security operations centre with defined severity and response commitments.

8

Internal audit, management review and corrective action

Internal audits run to a programme covering every process annually. Nonconformities get a root-cause analysis, an owner and a due date. Management review each year feeds the Risk & Security Committee and, through it, the Board’s Audit & Risk Committee.

Buyer and Due Diligence Questions

What documents are in your standard due diligence pack?
Certificate of incorporation and CAC status report, memorandum and articles, three years of tax clearance, pension and Industrial Training Fund compliance certificates, BPP Interim Registration Report, NITDA registration, NDPR data controller registration, company profile, organisation chart, three years of audited financial statements and a reference list. Request it from [email protected].
Is your tax clearance current, and for how many years?
Yes. We hold Federal Inland Revenue Service tax clearance for three consecutive years, which is the standard requirement in Nigerian public tenders. Certified copies are issued with the due diligence pack. Pension remittance and Industrial Training Fund compliance certificates are maintained on the same renewal calendar.
Do you have a current BPP Interim Registration Report?
Yes. Brilliant Esystems is registered with the Bureau of Public Procurement as a contractor for information technology goods and services and holds a current Interim Registration Report, renewed annually. We can supply the IRR number and a copy against a named tender reference, usually the same working day.
Our project needs NITDA clearance. Can you support that?
Yes. We are a NITDA-registered indigenous IT service provider, which is a precondition for clearance of public information technology projects above the prescribed threshold. We routinely support procuring entities through the clearance process by supplying our registration evidence, the technical specification and the local-content justification the agency asks for.
What is the exact scope of your ISO certificates?
Our documented procedures cover design, development, integration, supply, support and training in enterprise information technology from Kano. The ISO/IEC 27001:2022 certificate covers managed services, the security operations centre, the hosted platform and software development across the same three sites. Both scope statements appear on the certificates themselves, which we supply in full rather than as extracts.
Can we audit you, or send a security questionnaire?
Yes to both. We complete client security questionnaires as a matter of course and accommodate on-site or remote audits by clients and their auditors, subject to reasonable notice and a confidentiality agreement. Banks and health institutions audit us regularly, and our control evidence usually answers most of a standard questionnaire directly.
How do you evidence local content?
Our engineering payroll is in Nigeria, the majority of it in Kano, and 96 of our engineers hold current vendor certification. We can supply headcount by location and discipline, certification schedules, the profile of our graduate trainee intake and ICT Academy training numbers as local-content evidence for a bid.
Do you carry insurance and can you provide bonds?
We maintain the insurance cover customary for this sector, including public liability and professional indemnity, and we can arrange advance payment guarantees and performance bonds through our bankers where a contract requires them. Bond capacity is approved by the Investment Committee, so tell us early in the bid process.

Requesting Certificate Copies for a Tender

Send your request to [email protected], with the name of the procuring entity, the tender reference and closing date, and a list of the specific documents required. Where the tender demands certified true copies or notarised documents, say so and we will prepare them accordingly.

Standard turnaround is one working day for the electronic pack and two to three working days for certified hard copies delivered to Kano. For urgent closings, call +234 916 000 0444 and ask for the public sector business desk.

Need the compliance file today?

Tell us the tender reference and the closing date. Our public sector desk will assemble exactly what the evaluation committee asked for.