The National Pension Commission (PenCom) has introduced a new set of cybersecurity requirements for Pension Fund Administrators (PFAs) and Pension Fund Custodians (PFCs), aimed at strengthening the security of workers’ retirement records and protecting pension savings from fraud, unauthorised access, and data manipulation.
The new regulatory framework, which takes effect on 1 January 2027, requires all licensed pension operators to upgrade their information technology infrastructure and adopt advanced cryptographic safeguards to secure electronic pension records.
The directive was contained in a circular signed by the Director of the Surveillance Department, A. M. Saleem.
PenCom said the measures are designed to enhance the integrity of digital records and reinforce public confidence in Nigeria’s Contributory Pension Scheme by preventing the manipulation of contributors’ data.
According to the circular, electronically signed pension documents must be automatically protected using cryptographic hash technology, ensuring that any attempt to alter or falsify a document after signing is immediately detectable.
Speaking on the new requirements, Saleem said the commission was determined to eliminate pension record tampering.
“With this cyber lockdown, PenCom moves to stop pension record tampering once and for all, ensuring the absolute protection of contributors’ hard-earned savings,” he said.
PenCom said the transition period before the January 2027 implementation date would provide pension operators with sufficient time to modernise their technology infrastructure and comply with the new standards.
Beyond securing electronic documents, the commission directed operators to establish comprehensive audit trails for every electronic transaction involving pension records.
Under the new guidelines, pension operators will be required to automatically capture and retain information, including the signer’s Internet Protocol (IP) address, the precise date and time of each transaction, the device used, and One-Time Password (OTP) records associated with electronic signing activities.
The commission said maintaining detailed digital logs would improve transparency, strengthen accountability, and provide investigators with reliable evidence in the event of disputes or suspected fraud.
PenCom also advised operators seeking clarification on the implementation framework to engage its Surveillance Department ahead of the commencement date.
The latest directive builds on the commission’s broader efforts to strengthen governance within the pension industry.
In recent years, PenCom has revised its Information and Communication Technology guidelines for pension operators and expanded collaboration with anti-corruption agencies to improve compliance with the Pension Reform Act.
The commission said the new cybersecurity measures are expected to further safeguard workers’ retirement savings by ensuring that pension records remain secure, traceable, and protected against both internal and external threats.
