Banking & SACCOs

Security awareness training built around how Kenyan banking and SACCO fraud actually works

Commercial banks and savings and credit co-operatives both carry member funds and KYC data that fraudsters target directly, and both field customer calls about M-Pesa and bank-transfer scams every week. Frontline staff, call-centre teams, and loan officers need training that matches what members actually report.

What banking and SACCO staff actually face

  • Members reporting an M-Pesa or bank-transfer "wrong number, please send it back" message, and pressure to refund before verifying the sender.
  • Callers claiming to be from Central Bank of Kenya (CBK), SASRA, or a fraud department, pressuring staff to bypass verification or share account details.
  • SIM-swap attempts targeting both members and staff whose mobile line is tied to internal MFA or mobile banking.
  • Phishing and invoice-fraud emails targeting finance and loan-processing staff, often impersonating a known vendor or branch manager.
  • Social engineering aimed at tellers and loan officers who have standing access to member account and collateral data.

The Data Protection Act and Computer Misuse and Cybercrimes Act

Kenya's data protection law and the Computer Misuse and Cybercrimes Act both point toward appropriate security measures and make this kind of fraud a prosecutable crime, which staff training commonly supports. We map modules openly to both and recommend confirming current guidance with your compliance team before citing a specific clause to an examiner.

See Kenya's regulatory drivers →

Ready to see this training in action?

Book a free demo and we'll show you the exact modules your team would complete.

Frequently asked questions

Does this training satisfy CBK or SASRA cybersecurity expectations?

It is built to support the staff-awareness intent behind Kenya's Data Protection Act and the general cybersecurity obligations that apply to regulated financial institutions. We recommend confirming current CBK or SASRA guidance with your compliance team before representing this as satisfying a specific requirement.

Can tellers and loan officers get a shorter, role-specific version?

Yes. All-Staff Core covers the shared fraud patterns (M-Pesa reversal scams, SIM-swap, fake KRA messages) in short modules, and the Financial Services Add-On layers on frontline-specific content without repeating the basics.

How do you handle sensitive banking scenarios in training without real member data?

All fraud scenarios use fictional names, accounts, and phone numbers. No real member data, logos, or live links are used in simulations.