Training for PFAs handling retirees' most important asset
Pension fund administrators manage long-term retirement savings for millions of contributors, under PenCom oversight and NDPA data-protection obligations. A single successful social-engineering attempt against a PFA can affect thousands of retirement accounts.
Where PFA staff are exposed
- Contributor service staff handling requests to update bank details or process withdrawals, a classic target for impersonation and pretexting.
- Finance and operations teams processing retirement benefit payments, exposed to business email compromise and wire fraud.
- Call-center staff fielding BVN, NIN, and account-verification requests that should never be confirmed to an unverified caller.
- IT and admin staff holding access to contributor records across custodian and administrator systems.
- Phishing targeting staff with access to the Retirement Savings Account (RSA) database.
PenCom guidelines and NDPA obligations
PFAs operate under National Pension Commission (PenCom) oversight alongside general NDPA data-protection duties. We cite PenCom as sector context rather than a specific numbered clause; verify current PenCom guidelines with your compliance team before making a formal compliance claim.
Read the NDPA staff training page →Recommended tracks
All-Staff Core
Baseline fraud and data-protection training including BVN/NIN/OTP scam awareness.
Finance & Payments
Callback verification for any change to contributor bank details before a payment goes out.
Managers & Executives
Deepfake and whaling awareness for leadership approving benefit disbursements.
Frequently asked questions
Does this help with PenCom compliance requirements?
The curriculum supports general data-protection and fraud-awareness good practice relevant to PFAs. We have not independently confirmed a specific numbered PenCom training clause, so we recommend verifying current PenCom guidelines directly with your compliance team before citing this as satisfying a named requirement.
How do you address requests to change contributor bank details?
The Finance & Payments track includes a dedicated callback-verification module: any change to bank details should be confirmed through a documented, independent verification step before it is actioned.
Can custodians and administrators share one training program?
Yes, both can be assigned the same All-Staff Core and Finance & Payments tracks; role-specific add-ons can be layered on per organization.