Curriculum

Ten modules. One competency: judgment over machines.

The track is sequenced so that you build from what the technology is, through how it is turned against the institution, to how it is governed. Each module carries lessons with knowledge checks, a technology-in-practice exercise, a South African anchor, an applied case file, and a timed, scored assessment.

The Core certificate covers Modules 1 to 6 (about 13 assessed hours). The Professional certificate covers all ten modules plus the applied capstone (about 22 assessed hours). Both are assessed; pass mark 70 percent.

Foundation · Free

Core certificate

02
The Threat Landscape
How AI is turned against financial institutions

The evidence module. It walks you through how generative and agentic AI have rewritten the economics of financial crime: deepfake voice and video fraud, AI-synthesised identity documents, fraud-as-a-service, and multi-step, agent-driven schemes — anchored in the numbers and the named cases, including the South African picture. You leave able to describe the principal attack types, cite the leading evidence to make the internal case for AI-risk competency, and map your own institution's exposure surface.

2 hrs
5 lessons · case file · timed assessment
03
Synthetic Identity and Deepfake Defence
Detection drills and onboarding hardening

The first of the platform's signature hands-on modules — and one nothing else in the South African market offers. It explains how synthetic identities, forged documents and deepfake audio and video are generated, then drills the detection of them: presentation and liveness attacks, artefacts in synthetic media, and the hardening of a know-your-customer and onboarding workflow against them. You leave with a repeatable detection routine.

2.5 hrs
6 lessons · case file · timed assessment
04
AI in the AML Fight
Monitoring, network analytics and agentic laundering

How machine learning actually does transaction monitoring, where it fails, and how criminals now use automation against it. The module covers supervised and unsupervised detection, graph and network analytics for structuring, the false-positive problem, and the emerging threat of agent-driven laundering — all grounded in the South African FICA regime and the Risk Management and Compliance Programme obligation. You leave able to read, challenge and supervise a model-driven alert, and to articulate the human role that FATF expects to remain.

2.5 hrs
5 lessons · case file · timed assessment
05
Algorithmic Bias and Fair Lending
Auditing automated credit

How bias actually enters automated credit decisions — through data, labels and proxies rather than intent — and how to find it, measure it and explain an adverse decision lawfully. The module teaches the principal fairness criteria and why they cannot all be satisfied at once, the mechanics of proxy discrimination and disparate impact, a structured fairness-review routine, and the legal frame: the National Credit Act's affordability regime, POPIA section 71's automated-decision rights, and the EU AI Act's classification of credit scoring as high-risk. It is written for a South African lending environment, where geography carries history.

2.5 hrs
5 lessons · case file · timed assessment
06
Model Risk and Explainability
Interrogating the black box

The discipline of not trusting a model you cannot interrogate. It introduces model-risk management in the lineage of supervisory guidance, the main explainability methods and their genuine limits, and the difference between an explanation that satisfies a regulator and one that satisfies an engineer — framed for a South African institution and its Prudential Authority expectations. It closes the Core certificate by giving every prior module its governance spine: the verification routine, the monitoring stack and the fairness audit all assume a professional who can read, stress and challenge a model's documentation. This module builds that professional.

2 hrs
3 lessons · case file · timed assessment

Professional certificate

07
GenAI Without Leaks
Data governance, personal information and POPIA

How to get the productivity of generative AI without leaking the personal information that regulation protects. The module shows how information actually escapes — through prompts, outputs, memorisation and training — then teaches the controls: the consumer-versus-enterprise distinction, safe prompting and redaction discipline, and the full POPIA mapping across security safeguards, the operator relationship, automated decisions and cross-border transfers. It is the module that lets an adviser safely use AI for a client report.

2 hrs
4 lessons · case file · timed assessment
08
The Adversarial Frontier
Poisoning, prompt injection, manipulated inputs

The security module. It covers how models are attacked rather than merely misused — adversarial evasion, training-data poisoning, and prompt injection against AI-integrated applications — and connects each to the concrete financial threat of manipulated inputs against fraud and underwriting models. It closes the loop with Module 5 by showing how a manipulated application defeats an automated decision, and it sets a realistic defensive posture: what can be hardened, what cannot, and where a human must remain in the loop.

2 hrs
3 lessons · case file · timed assessment
09
Agentic AI and Hyper-Personalisation
Robo-advice and the new advisory

What changes when AI stops answering and starts acting. The module explains agentic systems and tool use, then applies them to the advisory frontier: robo-advice, hyper-personalised recommendations, suitability and mis-selling risk, and the competitive position of the human adviser — alongside the supervision duties that agentic delegation creates. Delegation without abdication is the theme, and the FAIS conduct regime is the frame.

2 hrs
3 lessons · case file · timed assessment
10
Governing AI in a Financial Institution
The synthesis, with applied capstone

The synthesis module, culminating in an applied capstone. It maps the governance landscape — the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001 and 23894, the OECD Recommendation — and the financial-sector guidance of the FSB, BIS, IOSCO and the South African regulators, then guides the learner to assemble a real institutional AI-risk protocol: scope, permitted and forbidden uses, model governance, data rules, incident response and the three lines of defence. The capstone deliverable is that protocol, built from the artefacts every prior module produced and assessed against the whole course. This is where nine modules of competencies become one governable position.

2.5 hrs
4 lessons · case file · timed assessment
Assessment and certification

Every certificate module ends in a timed assessment with a 70 percent pass mark, three attempts and a 24-hour reflection period after an unsuccessful attempt. Passing all modules in a tier issues a verifiable certificate with a public verification page. The Module 10 capstone is an applied deliverable, an institutional AI-risk protocol assessed against a published marking guide.