Select Region/Country
  • Global
  • Nigeria
  • Kenya

This website uses cookies to enhance your experience. Learn more here:

Integrated Management System Policy Statement

At Moniepoint MFB, protecting the information entrusted to us and maintaining our ability to keep serving our customers through disruption are fundamental to how we operate. This statement summarises the commitments set out in our Board-approved IMS Policy Statement, covering both our information security and business continuity management systems.

Our Information Security Commitments
  • We protect the confidentiality, integrity, and availability of information, including personal data, in line with applicable data protection law and our regulatory obligations.
  • We provide the resources needed to build, run, and continually improve our information security management system.
  • We assess and manage the security risks posed by third-party suppliers who process, store, or transmit information on our behalf.
  • We invest in ongoing training and awareness so that security is a shared responsibility across our organisation.
Our Business Continuity Commitments
  • We work to ensure the key resources our critical business activities depend on remain available, even through disruption.
  • We plan for the orderly and timely recovery of our critical business processes following a disruptive incident.
  • We actively work to reduce our highest-priority business continuity risks over time.
  • We provide business continuity training to the people who need it to respond effectively.
  • We are committed to the continual improvement of our business continuity management system.
Scope of Our Approach

These commitments extend to all employees, contractors, third-party vendors, and partners who access our information assets or support our critical business activities, and cover electronic, physical, and intellectual information and processes across all the systems, networks, cloud services, and locations involved, whether managed directly by us or by our service providers.

Governance and Accountability

Accountability for information security and business continuity sits with our Board of Directors, who approve our strategy and resource allocation. Day-to-day accountability rests with our information security and business continuity leadership, supported by our Data Protection Officer for the protection of personal data.

Alignment with Recognised Standards

Our approach is aligned with internationally recognised standards, including ISO/IEC 27001 for information security and ISO 22301 for business continuity, together with applicable regulatory frameworks including the cybersecurity guidelines issued by our regulators.

Continual Improvement

We operate a continual improvement cycle across both areas, planning our approach to risk and disruption, implementing controls and continuity arrangements, monitoring their effectiveness, and acting on the results so that our resilience keeps evolving alongside emerging threats and changes in our business. This statement, and the commitments within it, are reviewed at least annually.