About This Event
“Most pension fraud is not sophisticated. It is unmonitored.”
A risk and control programme covering enterprise risk management, East African data protection obligations and the fraud exposures that sit in benefit payments. It builds a risk register the board can use and the controls that stop the losses schemes actually suffer.
What You'll Explore
A populated enterprise risk register with owners and appetite statements
A cyber incident response plan tested through simulation
A fraud control matrix for payouts, claims and death benefits
A data protection gap assessment across member records and processors
Quarterly risk reporting the board can act on
Who Should Attend
Open to all qualifying staff, particularly: Risk Officers, Internal Auditors, Compliance Directors, Scheme Administrators.
Why This Course Matters
A Risk Register That Works
Build an enterprise risk register with owners, appetite statements and controls that are actually tested, rather than a spreadsheet updated once a year for the audit committee. Risks the board never sees are the ones that mature quietly.
Member Data Protected
Apply Kenyan, Ugandan, Tanzanian and Rwandan data protection requirements to member records, consent and third-party processing, and rehearse a breach notification before you need to make one under time pressure.
Fraud Stopped at the Payout
Close the gaps where pension fraud actually occurs: ghost pensioners, altered bank details, duplicate claims and death benefit diversion, using controls that hold even when the request looks legitimate.
Programme
Day 1
Enterprise risk framework and risk appetite
You will build a scheme risk register with named owners, quantified appetite and control testing, rather than an annual spreadsheet prepared for the audit committee. Sessions cover risk identification across investment, operational, regulatory and sponsor risk, scoring and escalation thresholds, control effectiveness testing, and the quarterly reporting pack the board needs in order to act.
Day 2
Data protection compliance and cyber incident response
You will apply the East African data protection statutes to member records, consent, retention and third-party processing, identifying where your scheme is currently exposed. The afternoon runs a cyber incident simulation from detection to member communication, testing backups, decision authority, ransomware decisions and the regulatory notifications required within the statutory window.
Day 3
Fraud prevention in payouts and control framework defence
You will map the fraud pathways in benefit administration, ghost pensioners, altered bank details, duplicate claims and death benefit diversion, and design controls that hold even when a request looks legitimate. You then consolidate the register, the incident plan and the fraud controls into one risk and control framework and defend it before an expert panel.
Standards & Faculty Benchmark
ISO 27001 & ISO 31000
Information security management and enterprise risk management standards applied to scheme operations.
East African data protection law
Data protection statutes in Kenya, Uganda, Tanzania and Rwanda governing member records and processing.
IOPS supervisory principles
International Organisation of Pension Supervisors principles for risk-based supervision of private pensions.
Supervisors, auditors and data protection commissioners all assess schemes against these standards.
Is This Right for You?
- ☑You own risk, audit or compliance for a scheme
- ☑Your scheme has never tested an incident response plan
- ☑Benefit payments are controlled by people rather than by process
Good to Know
The cyber and data protection sessions are built for risk and audit staff rather than engineers.
The Bottom Line
Leave with the risk register, the incident plan and the payout controls that stop the losses schemes actually suffer.
Recommended For
Open to all qualifying staff, particularly: Risk Officers, Internal Auditors, Compliance Directors, Scheme Administrators.
