Why this is usually stitched together from multiple vendors
Most institutions end up buying AML/CFT training from one provider, cybersecurity-framework training from another, and governance training from a law firm or consultant — three vendor relationships, three different assessment standards, three separate records to produce when a regulator asks for evidence. None of that is a technology problem; it's a sourcing problem that a single curriculum solves.
What the fuller curriculum covers
- ✓AML/CFT/KYC — the core obligation; see our dedicated AML/CFT/KYC training guide for what this specifically needs to include
- ✓CBN Cybersecurity Framework — the technical and governance requirements CBN-regulated institutions must evidence, not just a generic cybersecurity awareness session
- ✓Consumer protection — the CBN Consumer Protection Regulations obligations that customer-facing staff and product teams need to operate against
- ✓Corporate governance — board and executive committee obligations specific to financial institutions, not a generic governance course
- ✓Sanctions and PEP screening — the practical side of AML that frontline and onboarding staff execute daily
Where international standards fit in
Banks and fintechs increasingly sit inside more than one compliance regime at once — NDPA domestically, and often ISO 27001, GDPR or PCI DSS where the business has international counterparties, card processing, or EU-linked data flows. Staff need to know what those standards require of them day to day: access discipline, data handling, incident reporting timelines. We build that awareness into the same curriculum for organisations already pursuing or maintaining that certification through a formal ISO/PCI certification body — we deliver the staff-facing training, not the certification audit itself. For NDPA specifically, our licensed DPCO status means we can go further and run the statutory audit directly — see data protection compliance services.
Fintech-specific considerations
A fintech's compliance team is usually a fraction of the size of a bank's, covering the same regulatory surface. That makes a single coordinated curriculum more valuable, not less — a two- or three-person compliance function can't run parallel training relationships the way a bank's larger team might absorb. Digital onboarding, biometric/liveness verification, and automated risk-profiling training (see our AML/CFT/KYC guide for the automated-system training mandate) tend to matter more for fintechs specifically, since so much of their customer relationship is unmediated by a physical branch.
What to ask a compliance training provider
- ✓Does the curriculum cover the full regulatory surface — AML/CFT, cybersecurity framework, governance, consumer protection — or only one piece?
- ✓Is it assessed, with a documented completion record, or just attendance-based?
- ✓Does it get updated as CBN guidance shifts, or is it a static deck reused for years?
- ✓Can international-standards awareness (ISO 27001, GDPR, PCI DSS) be layered in without a separate vendor relationship?
Build one compliance curriculum, not three vendor relationships
Tell us your institution type, current compliance posture and which regulatory regimes apply. Talk to us about regulatory compliance training and we'll scope a curriculum against your actual exposure.
