Curriculum

Ten modules. One competency: judgment over machines.

The track is sequenced so that you build from what the technology is, through how it is turned against the institution, to how it is governed. Each module carries lessons with knowledge checks, a technology-in-practice exercise, a South African anchor, an applied case file, and a timed, scored assessment.

The Core certificate covers Modules 1 to 6 (about 13 assessed hours). The Professional certificate covers all ten modules plus the applied capstone (about 22 assessed hours). Both are assessed; pass mark 70 percent.

Foundation · Free

Core certificate

02
The Threat Landscape
How AI is turned against financial institutions

This module sets out the evidence. It describes how generative and agentic AI have changed the economics of financial crime: deepfake voice and video fraud, AI-synthesised identity documents, fraud-as-a-service marketplaces, and multi-step schemes run by AI systems that plan and act with limited human input. Each attack type is anchored in published figures and named cases, including the South African evidence. By the end you can describe the principal attack types, cite the leading sources when you make the internal case for AI-risk competency, and map where your own institution is exposed.

2 hrs
5 lessons · case file · timed assessment
03
Synthetic Identity and Deepfake Defence
Detection drills and onboarding hardening

This is the first of the platform's hands-on modules. It explains how synthetic identities, forged documents and deepfake audio and video are produced, and then works through the detection of them: presentation and liveness attacks, the artefacts left in synthetic media, and the hardening of a know-your-customer and onboarding workflow against both attack classes. By the end you will have a repeatable detection routine that can be applied to any verification decision.

2.5 hrs
6 lessons · case file · timed assessment
04
AI in the AML Fight
Monitoring, network analytics and agentic laundering

This module explains how machine learning performs transaction monitoring, where that monitoring fails, and how criminals now use automation against it. It covers supervised and unsupervised detection, graph and network analytics for structuring, the false-positive problem, and the emerging threat of agent-driven laundering, all set inside the South African FICA regime and the Risk Management and Compliance Programme obligation. By the end you will be able to read, challenge and supervise a model-driven alert, and to explain the human role that FATF expects institutions to retain.

2.5 hrs
5 lessons · case file · timed assessment
05
Algorithmic Bias and Fair Lending
Auditing automated credit

This module explains how bias enters automated credit decisions through data, labels and proxy variables rather than through anyone's intention, and how to find it, measure it and explain an adverse decision lawfully. It covers the principal fairness criteria and why they cannot all be satisfied at once, the mechanics of proxy discrimination and disparate impact, a structured fairness-review routine, and the legal frame: the National Credit Act's affordability regime, POPIA section 71's automated-decision rights, and the EU AI Act's classification of credit scoring as high-risk. It is written for the South African lending environment, in which residential address still reflects the country's history of enforced segregation.

2.5 hrs
5 lessons · case file · timed assessment
06
Model Risk and Explainability
Interrogating the black box

This module is about working responsibly with a model whose internal reasoning you cannot inspect directly. It introduces model-risk management as it developed from international supervisory guidance, the main explainability methods and their limits, and the difference between an explanation that satisfies a regulator and one that satisfies an engineer, all framed for a South African institution and the expectations of the Prudential Authority. It closes the Core certificate by setting out the governance framework the earlier modules assume. The verification routine, the monitoring stack and the fairness audit each depend on professionals who can read a model's documentation, test its claims and question its conclusions, and this module develops those skills.

2 hrs
3 lessons · case file · timed assessment

Professional certificate

07
GenAI Without Leaks
Data governance, personal information and POPIA

This module covers how to use generative AI productively without disclosing the personal information that regulation protects. It sets out the four routes by which information escapes: prompts, outputs, memorisation and training reuse. It then covers the controls that address each route, namely the difference between consumer and enterprise tools, safe prompting and redaction discipline, and the POPIA mapping across security safeguards, the operator relationship, automated decisions and cross-border transfers. The practical result is a workflow that allows an adviser to use AI on a client report lawfully.

2 hrs
4 lessons · case file · timed assessment
08
The Adversarial Frontier
Poisoning, prompt injection, manipulated inputs

This module deals with security. Earlier modules dealt with models that are misused, or that fail on their own; the concern here is models that are deliberately attacked by someone who wants a particular result. It covers three attack classes: adversarial evasion, training-data poisoning, and prompt injection against AI-integrated applications. Each is connected to the financial threat of manipulated inputs submitted to fraud and underwriting models. The module returns to Module 5 to show how a manipulated application can defeat an automated credit decision, and it sets out a realistic defensive posture: what can be hardened, what cannot, and where a person must remain in the decision path.

2 hrs
3 lessons · case file · timed assessment
09
Agentic AI and Hyper-Personalisation
Robo-advice and the new advisory

This module covers what changes when an AI system moves from producing answers to carrying out tasks. It explains how agentic systems plan, use tools and act, and then applies that to advisory work: robo-advice, hyper-personalised recommendations, suitability and mis-selling risk, the competitive position of the human adviser, and the supervision duties that arise when work is handed to an agent. The module works throughout from one principle: a task may be delegated to an agent, but accountability for it stays with the institution and the professional. In South Africa the FAIS conduct regime provides the legal framework for that.

2 hrs
3 lessons · case file · timed assessment
10
Governing AI in a Financial Institution
The synthesis, with applied capstone

This module draws the course together and ends in an applied capstone. It maps the governance landscape (the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001 and 23894, and the OECD Recommendation) together with the financial-sector guidance of the FSB, BIS, IOSCO and the South African regulators. It then guides you through assembling an institutional AI-risk protocol covering scope, permitted and forbidden uses, model governance, data rules, incident response and the three lines of defence. The capstone deliverable is that protocol, built from the artefacts produced in every earlier module and assessed against the course as a whole. The work of this module is to combine the competencies of the preceding nine modules into a single governance position that an institution can defend.

2.5 hrs
4 lessons · case file · timed assessment
Assessment and certification

Every certificate module ends in a timed assessment with a 70 percent pass mark, three attempts and a 24-hour reflection period after an unsuccessful attempt. Passing all modules in a tier issues a verifiable certificate with a public verification page. The Module 10 capstone is an applied deliverable, an institutional AI-risk protocol assessed against a published marking guide.