Pension Sector Training · Track 3 · Policy & MembersPaid Event

Enterprise Risk & Cybersecurity

ERM, Data & Fraud

11–13 October 2027 · 3 DaysEntebbe, Uganda (or in-country delivery)
← Back to Events

Location

Entebbe, Uganda (or in-country delivery)

Get Directions

About This Event

“Most pension fraud is not sophisticated. It is unmonitored.”

A risk and control programme covering enterprise risk management, East African data protection obligations and the fraud exposures that sit in benefit payments. It builds a risk register the board can use and the controls that stop the losses schemes actually suffer.

What You'll Explore

A populated enterprise risk register with owners and appetite statements

A cyber incident response plan tested through simulation

A fraud control matrix for payouts, claims and death benefits

A data protection gap assessment across member records and processors

Quarterly risk reporting the board can act on

Who Should Attend

Open to all qualifying staff, particularly: Risk Officers, Internal Auditors, Compliance Directors, Scheme Administrators.

Why This Course Matters

A Risk Register That Works

Build an enterprise risk register with owners, appetite statements and controls that are actually tested, rather than a spreadsheet updated once a year for the audit committee. Risks the board never sees are the ones that mature quietly.

Member Data Protected

Apply Kenyan, Ugandan, Tanzanian and Rwandan data protection requirements to member records, consent and third-party processing, and rehearse a breach notification before you need to make one under time pressure.

Fraud Stopped at the Payout

Close the gaps where pension fraud actually occurs: ghost pensioners, altered bank details, duplicate claims and death benefit diversion, using controls that hold even when the request looks legitimate.

Programme

Day 1

Enterprise risk framework and risk appetite

You will build a scheme risk register with named owners, quantified appetite and control testing, rather than an annual spreadsheet prepared for the audit committee. Sessions cover risk identification across investment, operational, regulatory and sponsor risk, scoring and escalation thresholds, control effectiveness testing, and the quarterly reporting pack the board needs in order to act.

Day 2

Data protection compliance and cyber incident response

You will apply the East African data protection statutes to member records, consent, retention and third-party processing, identifying where your scheme is currently exposed. The afternoon runs a cyber incident simulation from detection to member communication, testing backups, decision authority, ransomware decisions and the regulatory notifications required within the statutory window.

Day 3

Fraud prevention in payouts and control framework defence

You will map the fraud pathways in benefit administration, ghost pensioners, altered bank details, duplicate claims and death benefit diversion, and design controls that hold even when a request looks legitimate. You then consolidate the register, the incident plan and the fraud controls into one risk and control framework and defend it before an expert panel.

Standards & Faculty Benchmark

ISO 27001 & ISO 31000

Information security management and enterprise risk management standards applied to scheme operations.

East African data protection law

Data protection statutes in Kenya, Uganda, Tanzania and Rwanda governing member records and processing.

IOPS supervisory principles

International Organisation of Pension Supervisors principles for risk-based supervision of private pensions.

Supervisors, auditors and data protection commissioners all assess schemes against these standards.

Is This Right for You?

  • ☑You own risk, audit or compliance for a scheme
  • ☑Your scheme has never tested an incident response plan
  • ☑Benefit payments are controlled by people rather than by process

Good to Know

The cyber and data protection sessions are built for risk and audit staff rather than engineers.

The Bottom Line

Leave with the risk register, the incident plan and the payout controls that stop the losses schemes actually suffer.

Recommended For

Open to all qualifying staff, particularly: Risk Officers, Internal Auditors, Compliance Directors, Scheme Administrators.

Event Date

11–13 October 2027

3 Days

Select Tickets

Ticket Type

Individual

USD 1,500 per participant + 16% VAT

USD 1,740

Incl. 16% VAT