A recovered ₦42.5 million in Kaduna, a £2 million ban in London and a Federal Court declaration in Melbourne all point to the same gap. We check who the customer is. We rarely check when the customer has become exposed. The story of Mrs Margret Taye Odofin, a 70-year-old widow and retiree, caught my attention for a particular reason.
On 6 November 2025, the Economic and Financial Crimes Commission handed her a bank draft of ₦42.5 million at its Kaduna Zonal Directorate. The money had been recovered from her former account and investment officer at a new generation bank. According to the EFCC, Mrs Odofin petitioned the Commission in December 2024. She alleged that the officer had lured her into a Ponzi scheme in late 2020 with the promise of quarterly returns of ₦1.7 million, and that ₦47 million was moved out of her account into various accounts without her authorisation. The officer is reported to have left the country before the case was resolved.
The recovery was a good outcome. But it raises an uncomfortable question. What happens when the money cannot be recovered?
For someone in retirement, losing that amount is not simply another fraud statistic. It may represent thirty or forty years of work, pension contributions and savings. A younger person who suffers a major financial loss may still have years of employment ahead to rebuild. For somebody already in retirement, that opportunity may be much smaller. This is why I believe we need to look at retirement fraud differently.
The question should not only be whether a transaction was properly authenticated or apparently authorised. Financial institutions should also be asking whether there were warning signs that something was wrong before the money moved. The pattern is not peculiar to Nigeria
On 19 January 2026, the UK’s Financial Conduct Authority announced that the Upper Tribunal had upheld its decision to ban former financial adviser Darren Antony Reynolds and fine him £2,037,892. The FCA found that he had been dishonest in the pension transfer advice and investment recommendations he gave. He encouraged members of the British Steel Pension Scheme to transfer out of their defined benefit scheme while knowing the advice was wholly unsuitable, recommended high-risk and unsuitable products, concealed high exit fees and falsified documents. More than £17.6 million has been paid in compensation to over 470 affected customers, many of whom lost more than the statutory compensation limits allowed them to recover. The wider scandal gives a sense of scale.
The FCA has said that at least £106 million in redress has been offered to 1,870 former British Steel Pension Scheme members, and that more than 6,500 former members have been supported by the regulator, the Financial Ombudsman Service or the Financial Services Compensation Scheme. It restated those figures in March 2026, when it responded to the Complaints Commissioner’s report on its handling of the scheme. Australia offers a more recent example.
On 20 August 2026, the Federal Court declared that two Netwealth entities had contravened the Corporations Act in relation to the First Guardian Master Fund. The declarations were made by consent, on the basis of agreed facts and admissions.
The Court found that the trustees did not obtain or assess sufficient information about the fund, did not make sufficient independent enquiries into the investment risk, and did not inform members that the fund could become illiquid. The Australian Securities and Investments Commission said approximately A$128.5 million had been invested in the relevant First Guardian classes by 1,303 members between March 2021 and December 2022. When the fund manager froze redemptions in May 2024, more than a thousand members still had over A$100 million exposed.
ASIC did not ask the Court for a financial penalty, because Netwealth had already paid more than A$100 million to over 1,000 affected members in January 2026. ASIC’s message was the part that matters for us. Superannuation trustees are a critical safeguard for people’s retirement savings. They must carry out rigorous due diligence before making investment options available, and they must identify and respond to investment risk before members suffer harm. Different countries, different financial systems, but there is a common lesson. We cannot place the entire responsibility for protecting retirement money on the customer. By the time law enforcement, regulators or financial institutions begin trying to recover lost funds, the damage may already have been done.
We already hold the information
Having worked across different areas of banking and financial crime, I have always believed that one of the industry’s biggest advantages in fighting fraud is the amount of information we already hold about our customers. A bank that has served somebody for twenty years probably knows that person’s normal transaction pattern, regular beneficiaries, typical payment values and how the account generally operates. A Pension Fund Administrator understands the customer’s pension relationship.
An investment firm should understand the customer’s objectives and risk profile. The real question is whether we are using that information effectively enough when something suddenly changes.
This is where I believe a Retirement Vulnerability Check could add value. It should not mean automatically labelling somebody vulnerable because they are 65 or 70. Age alone tells us very little about a person’s ability to manage money. What matters is what is happening around the customer, and whether their financial behaviour has changed in a way that deserves attention. Suppose a customer who has rarely made large transfers suddenly liquidates a long held investment and wants to move a substantial part of their retirement savings to a beneficiary created that morning. Perhaps the investment came through somebody they recently met online.
Perhaps they have been told the opportunity will disappear unless payment is made immediately. The customer may know the PIN. The OTP may be correct. The biometric authentication may work.
That does not necessarily mean the transaction is safe. A genuine customer can genuinely authorise a payment and still be sending money to a fraudster. We do not need another twenty-page form. The industry already has enough forms. What we need is to use existing information more intelligently. An unusually large transaction involving retirement savings should be considered in the context of the customer’s previous behaviour.
Sudden investment liquidation, a new beneficiary, a change of contact details, an unfamiliar device or an unusual payment pattern can all provide useful signals. Sometimes the intervention can be remarkably simple. Before processing an exceptional investment payment, a trained member of staff could ask a few questions. How did you hear about this investment?
Have you independently checked the company? Has anybody asked you to make this payment urgently?
Do you understand how and when you can get your money back? Those few questions may tell an institution far more than another authentication code. Nigeria already has the building blocks
The Central Bank of Nigeria regulates banks and the payments system. The National Pension Commission regulates the pension industry. Pension Fund Administrators and pension fund custodians manage different parts of the retirement journey. The Nigerian Financial Intelligence Unit, the EFCC and other relevant agencies form part of the country’s financial crime architecture. The opportunity is to make those different parts work more closely around the customer.
When pension money leaves a retirement arrangement and enters a bank account, the need to protect that money does not disappear. When it subsequently moves into an investment product, protection should not disappear there either. Protection should follow the money. For banks, this means bringing relevant vulnerability indicators into fraud monitoring and customer service. For Pension Fund Administrators, it means making scam and fraud awareness a practical part of retirement education.
For investment firms, it means paying proper attention to suitability, liquidity, fees, conflicts of interest and how products are sold to people approaching or already in retirement. It also means paying attention to employees and advisers. The Kaduna case is a reminder that the person creating the risk may not always be an anonymous criminal sitting behind a computer.
Sometimes the customer trusts the person because of the institution they represent. From KYC to KYV
We have practised KYC, Know Your Customer, in banking for decades.
Perhaps it is time to add another dimension. KYV, Know Your Vulnerability.
KYC tells us who the customer is. KYV would encourage us to understand when circumstances around that customer have changed, and when the person may be more exposed to manipulation, unsuitable advice or financial exploitation. It is not about taking control of people’s money away from them.
It is about knowing when to ask one more question. Nigeria has made significant progress in KYC, identity infrastructure, transaction monitoring and digital payments. As financial crime becomes more sophisticated, our approach to customer protection also has to evolve. The best fraud control is not always the one that generates the most alerts. Sometimes it is the person or the system that notices that something does not look right, and acts before the money disappears.
We have spent years asking a single question. Do we know this customer?
Perhaps we should also start asking a second one. Do we know when this customer may be vulnerable? For someone about to lose the savings of a lifetime, that question could make all the difference.
About the author
Adedayo F. Aluko, MBA · MSc · SMP (Lagos Business School) · ACIB, is a management consultant working in financial crime compliance, anti-money laundering and governance, risk and compliance. He is the author of Clean Hands, Bright Future: A Youth Guide to Avoiding Financial Crime in Africa.