Executive Edition

YAC-OSP Digital Compliance, Cyber-Corruption, and Data Integrity

For CIOs, IT security managers and compliance executives. In the digital age, corruption happens in SQL injections, payroll backdoors, forged PDFs and manipulated databases β€” and the OSP will treat your infrastructure as a crime scene. Learn the mandate, laws, threats, and step-by-step response protocols for seven realistic scenarios.

πŸ“š 8 Modules
πŸ“ 17 Lessons
βœ… 20-Question Quiz
πŸ† Certificate on Completion
Certificate of Completion Preview
Certificate of Completion Preview
If you experience any issues while using this application, please clear your browser's cache and cookies, then refresh the page.
If the issue persists, kindly contact request@osp.gov.gh for assistance.

Course Modules

πŸ“Œ How This Course Works

  • Complete each lesson in order β€” the next lesson unlocks after you finish the previous one.
  • After completing all 8 modules, the final quiz will unlock.
  • Score 16 out of 20 or more to earn your certificate.
  • Your progress is automatically saved in your browser.
Module 1: The OSP's Digital Mandate
When Code Becomes Corruption
The OSP's mandate extends into the digital realm

When Code Becomes Corruption

The Office of the Special Prosecutor (OSP), established under Act 959 (Office of the Special Prosecutor Act, 2017), is widely understood as an anti-corruption agency. But in the digital age, corruption no longer requires brown envelopes in parking lots. It happens in SQL injections, payroll backdoors, forged PDFs, and manipulated databases.

The OSP's mandate extends into the digital realm β€” particularly when corruption is cyber-enabled or involves digital evidence.

For CIOs, IT Security Managers, and Compliance Executives: understanding the OSP's digital mandate is not optional. When your systems facilitate ghost-name payments, when your access logs show unauthorised alterations to procurement records, or when your mobile money trails lead to politically exposed persons, the OSP will treat your infrastructure as a crime scene.

Course Learning Objectives

  1. Explain the OSP's mandate in the context of cyber-enabled corruption and digital evidence.
  2. Identify and prevent ghost-name payroll fraud, electronic document forgery, and cyber-laundering.
  3. Design and operationalise access controls, data integrity safeguards, and incident response protocols.
  4. Detect system loopholes before they become pathways for systemic fraud or OSP investigation.
Prerequisite: Basic understanding of corporate IT governance and Ghana's legal environment.
Module 1: The OSP's Digital Mandate
The Four Pillars β€” Applied to Digital Corruption
Investigation, prosecution, asset recovery, prevention

The Four Pillars β€” Applied to Digital Corruption

πŸ”Ž
Pillar I: Investigation
The OSP investigates public officers who manipulate digital systems for personal gain; private actors who create, exploit or conceal digital loopholes in collusion with public officials; and offences where digital evidence is central.
βš–οΈ
Pillar II: Prosecution
Without specific reference to the Attorney-General: corporate officers who authorise ghost-name payroll entries; IT administrators who create backdoors for financial manipulation; vendors who forge electronic documents to win public contracts.
πŸ’°
Pillar III: Asset Recovery
The OSP recovers proceeds of corruption β€” and can trace, freeze, and confiscate digital assets.
πŸ›‘οΈ
Pillar IV: Prevention
Under Section 2(c) of Act 959, the OSP must take steps to prevent corruption. The YAC programme and this portal exist to build a generation that treats digital integrity as a professional competency.
Critical Context β€” Referrals

The OSP receives referrals from the Economic and Organised Crime Office (EOCO), the Auditor-General, and other public bodies. EOCO, in turn, is mandated to investigate serious offences involving prohibited cyber activity. This means a cyber-fraud case investigated by EOCO or the CID Cybercrime Unit can be escalated to the OSP if it involves corruption.

Module 1: The OSP's Digital Mandate
Ghana's Digital Law Enforcement Ecosystem
Where the OSP's digital evidence comes from

The OSP Does Not Operate in a Vacuum

Ghana's digital corruption fight involves multiple agencies.

AgencyDigital MandateIntersection with OSP
OSPCorruption and corruption-related offences involving digital evidenceReceives referrals; prosecutes high-level cases
EOCOSerious organised crime, cyber fraud, money launderingRefers corruption-linked cyber cases to OSP
CID Cybercrime Unit (Ghana Police)Cybercrime detection, digital forensics, investigationLargest provider of digital forensic evidence; supports OSP investigations
Cyber Security Authority (CSA)Regulation of cybersecurity activities; Critical Information Infrastructure (CII) protectionCollaborates with EOCO; sets standards that affect corporate compliance
Data Protection Commission (DPC)Registration, enforcement, breach notification under Act 843Ensures data integrity; breaches may reveal corruption
Key Insight: Key Insight: The CID Cybercrime Unit has a state-of-the-art Digital Forensics Laboratory and has decentralised cybercrime investigation capacity to all 25 police regions, with specialised training in digital wallet fraud, social engineering, insider threats, and file system forensics
The OSP through an EU funded project is building ultra modern digital forensic labs.
Module 1: The OSP's Digital Mandate
The Legal Framework for Digital Compliance
Acts 1038, 843, 772, 29 and 959

The Legal Framework for Digital Compliance in Ghana

LawRelevance to Digital CorruptionKey Penalties
Cybersecurity Act, 2020 (Act 1038)Criminalises unauthorised access, data interference, system interference; mandates data retention (6 years subscriber info, 12 months traffic/content); establishes CII protectionUp to 10 years imprisonment for unauthorised access to CII; corporate liability for directors/officers unless they prove lack of knowledge/consent
Data Protection Act, 2012 (Act 843)Mandates lawful processing, data security, breach notification; establishes Data Protection CommissionFines, imprisonment up to 5 years for selling personal data; enforcement notices for non-compliance
Electronic Transactions Act, 2008 (Act 772)Creates "Cyber Inspectors"; empowers seizure of computers, electronic records, programs; criminalises cyber offencesSearch and seizure of digital evidence; prosecution of electronic trafficking, denial of service
Criminal Offences Act, 1960 (Act 29)General criminal law applicable to fraud, forgery, theftApplies to digital variants of these crimes
Office of the Special Prosecutor Act, 2017 (Act 959)Corruption-specific prosecution and asset recoveryImprisonment, fines, asset confiscation
Although these are the laws governing digital compliance. It should also be noted that a person involved in corruption is liable on summary conviction to a term of imprisonment of not less than twelve (12) years and not more than twenty-five (25) years - Act 1034
Module 1: The OSP's Digital Mandate
The Human Cost of Digital Corruption
What is at stake

Before We Examine the Mechanics β€” Understand What Is at Stake

πŸ’Έ
GHΒ’14.94 million
Lost by Ghana to cybercrime in just the first half of 2025, with reported incidents jumping from 1,317 in early 2024 to 2,008 in 2025.
πŸ‘»
14,027 ghost names
Discovered on the National Service Authority (NSA) payroll in 2022 β€” saving GHΒ’120 million.
πŸ“‹
81,885 suspected ghost names
Revealed by a 2025 NSA headcount β€” nearly half the entire workforce claimed was fictitious.
πŸ“±
USD 1.3 million
Lost by Ghanaian citizens to mobile money fraud in the first quarter of 2025 alone.
Every ghost name is a stolen salary that could have paid a real nurse. Every mobile money fraud is a pension destroyed. Every forged electronic document is a contract that cheats the public. Your systems are the frontline.

Module 1 Complete

You understand the OSP's digital mandate, the agencies it works with, the laws that bind your organisation, and the human cost of failure. Module 2 maps the threat landscape.

Module 2: The Digital Fraud Landscape
Ghost Names & Payroll Manipulation
Database manipulation, compromised biometrics, HR–IT collusion

What Is a Ghost Employee?

A ghost employee is a fictitious or non-existent individual added to a payroll system to divert salaries. In the digital age, this is no longer about manual ledger entries β€” it is about database manipulation, compromised biometric systems, and collusion between HR and IT staff.

How It Works Digitally

  1. An insider with payroll system access creates a fake employee profile.
  2. The profile passes weak validation (no biometric check, no supervisor verification).
  3. Salaries are deposited into a mobile money wallet or bank account controlled by the fraudster.
  4. The ghost "employee" never shows up for work, but the system shows perfect attendance.
πŸ‡¬πŸ‡­ Ghana Context

The NSA scandal revealed that ghost names were inserted using fake index numbers, duplicated identities, and manipulated registration portals. Some fraudsters created multiple entries with identical names and qualifications.

Module 2: The Digital Fraud Landscape
Electronic Document Forgery
PDFs, invoices, contracts and credentials that lie
Module 2: The Digital Fraud Landscape
Electronic Document Forgery
PDFs, invoices, contracts and credentials that lie
 

What Is Electronic Document Forgery?

Electronic document forgery involves the creation, alteration, or manipulation of digital documents β€” PDFs, invoices, contracts, bank statements β€” to deceive stakeholders. With tools like Adobe Acrobat Pro, Photoshop, and even AI, sophisticated forgeries can pass casual inspection.

Common Types

🧾
Altered PDF invoices
Changing amounts, dates, or vendor details.
🏦
Forged bank statements
Creating false proof of payment or liquidity.
πŸ“„
Manipulated contracts
Altering terms after signature.
πŸŽ“
Fake academic credentials
Inserting fictitious graduates into payroll systems (as seen in the NSA case).
Module 2: The Digital Fraud Landscape
Cyber-Laundering
MoMo layering, crypto mixing, fintech fronts and SIM swaps

What Is Cyber-Laundering?

Cyber-laundering is the use of digital channels to conceal the origins of illegally obtained money. In Ghana, this increasingly involves:

πŸ“±
Mobile money (MoMo) layering
Breaking large sums into small transactions across multiple wallets.
πŸͺ™
Cryptocurrency mixing
Using crypto exchanges to obscure transaction trails.
πŸ’³
Fintech exploitation
Using unlicensed lending apps or betting platforms as fronts.
πŸ“Ά
SIM swap fraud
Hijacking phone numbers to access mobile money and banking apps.
🌍 INTERPOL Context

In 2025, SIM swap fraud surged across Africa. Kenya alone detected 123,000 fraudulent SIM cards. In Ghana, mobile money fraud is the most prevalent scam, with citizens losing millions.

Module 2: The Digital Fraud Landscape
Insider Threats & System Loopholes
The fraud triangle in digital corruption

The Most Dangerous Threat Is Internal

An IT administrator with privileged access can:

  • Create undetectable backdoor accounts.
  • Alter audit logs to conceal unauthorised transactions.
  • Exfiltrate sensitive data for extortion or sale.
  • Disable security controls during "maintenance windows".

The Fraud Triangle in Digital Corruption

πŸ”₯
Pressure
IT staff with gambling debts, lifestyle pressures, or coercion from external actors.
πŸšͺ
Opportunity
Excessive privileges, lack of segregation of duties in IT, absence of logging.
πŸ—£οΈ
Rationalisation
"The company doesn't pay me enough; I'm just borrowing; everyone does it."
What comes next: The remaining lessons are the operational core of the course. Each scenario is realistic, grounded in Ghanaian context, and includes role-specific action steps for the CIO, the IT Security Manager, and the Compliance Executive.
Module 2: The Digital Fraud Landscape
The Ghost in the Machine
Ghost names in the payroll system β€” step-by-step response
πŸ“– The Situation

Your organisation has 500 employees. During a routine audit, the Compliance Executive notices that 47 employees share the same mobile money number for salary deposits. Further investigation reveals that 12 of these "employees" have no Ghana Card verification, no biometric enrolment in the attendance system, and no email communications. The HR Manager claims they are "field staff" who "don't come to the office." The IT Security Manager discovers that these profiles were created by a single HR officer who also has database administrator privileges.

The Red Flags

✦ Multiple salaries directed to one mobile money or bank account
✦ Employees with no biometric data, no Ghana Card, no digital footprint
✦ Payroll profiles created by someone with dual HR and database admin roles
✦ Vague explanations ("field staff") with no supervisor verification
✦ No corresponding leave records, performance reviews, or email accounts
Why It Matters: This is criminal fraud under Act 29 (theft, forgery) and potentially a corruption-related offence if public funds or public contracts are involved. If your organisation is a government contractor or SOE, the OSP has jurisdiction. The NSA scandal showed that ghost names can persist for years, draining millions.

πŸ‘” For the CIO

  1. Isolate the system. Immediately revoke the suspected HR officer's access to the payroll database and all related systems. Do not delete their account yet β€” preserve the audit trail.
  2. Preserve evidence. Create forensic images of the payroll database, access logs, and user creation timestamps before they can be altered.
  3. Engage external digital forensics. If your internal team is compromised, bring in an independent firm. The CID Cybercrime Unit can assist if criminal prosecution is anticipated.
  4. Report to leadership. Brief the CEO and Board Audit Committee. This is not an HR issue β€” it is a material fraud.
  5. Prepare for regulatory engagement. If public funds are involved, be ready to report to the OSP, EOCO, or the Auditor-General.

πŸ” For the IT Security Manager

  1. Run a full access audit. Identify every account created or modified by the suspect in the last 24 months. Cross-reference with onboarding records.
  2. Check for backdoors. Search for hidden admin accounts, scheduled scripts, or unauthorised database triggers that might recreate ghost names after deletion.
  3. Analyse network logs. Did the suspect access the system from unusual locations or times? Remote sessions outside business hours?
  4. Verify biometric integration. If the system should validate against NIA/Ghana Card data, why did these 12 profiles bypass it? Was the API disabled? Was there a "manual override"?
  5. Implement emergency controls. Require dual authorisation for all new payroll entries. Disable "manual override" pending investigation.

πŸ“‹ For the Compliance Executive

  1. Quantify the loss. Calculate total salaries paid to ghost names over their existence, including statutory payments (SSNIT, taxes) diverted or underpaid.
  2. Review banking arrangements. Individual accounts or bulk mobile money wallets? Bulk wallets make ghost-name fraud easier.
  3. Assess criminal liability. Consult legal counsel on whether to report to Ghana Police (CID), EOCO, or OSP. Determining factor: purely internal theft, or collusion with public officials?
  4. Initiate disciplinary action. Suspend the involved HR officer pending investigation. Ensure due process.
  5. Strengthen controls. Mandate Ghana Card + biometric verification for all new hires. Implement a monthly "ghost hunt" cross-checking payroll against physical headcount, email active directory, and access control logs.

Module 2 Complete

You have mapped the digital fraud landscape and worked through your first full response protocol. Modules 3–8 each present one more scenario.

Module 3: The Forged Procurement Invoice
The Forged Procurement Invoice
Electronic document forgery β€” step-by-step response
πŸ“– The Situation

Your company receives a PDF invoice from a "vendor" for GHS 450,000 worth of IT equipment. The invoice looks professional β€” letterhead, signature, bank details. The Compliance Executive notices that the PDF metadata shows it was created 3 days ago, but the invoice date is 6 months ago. The vendor's email domain is @techsol-gh.com instead of the known @techsolutionsgh.com. The bank account is new. The CIO confirms no purchase order was issued for this amount.

The Red Flags

✦ PDF metadata mismatch (creation date vs. invoice date)
✦ Slightly altered email domain (typosquatting)
✦ New or changed bank account details
✦ No corresponding purchase order or goods receipt note
✦ Pressure to pay "urgently" to avoid "late fees"
Why It Matters: This is forgery and attempted fraud under Act 29. If the fraudster is a public contractor or the payment would involve public funds, it becomes a corruption-related offence. The OSP has investigated cases where forged documents were used to justify improper payments.

πŸ” For the IT Security Manager

  1. Analyse the PDF forensically. Use tools like ExifTool or PDF metadata analysers to check creation date and software used; author name and modification history; embedded fonts and images (forgeries often use different fonts than originals).
  2. Trace the email headers. Examine the full header to identify the true originating IP address, not just the displayed sender.
  3. Check for malware. The PDF or attachment may contain malware designed to harvest credentials. Scan with updated endpoint protection.
  4. Verify the domain. Check WHOIS records for @techsol-gh.com. When was it registered? By whom? It was likely registered recently for this scam.

πŸ“‹ For the Compliance Executive

  1. Do not process the payment. Issue a formal hold.
  2. Contact the genuine vendor using known, verified contact details β€” not the ones on the suspicious invoice.
  3. Document everything. Preserve the email, PDF, and all communications. This is evidence.
  4. Report to law enforcement. If the amount is significant or the fraudster is persistent, report to the CID Cybercrime Unit. If the fraud involves a public procurement process, report to the OSP.
  5. Issue a company-wide alert. This is likely a Business Email Compromise (BEC) attack. Other departments may have received similar forged invoices.

πŸ‘” For the CIO

  1. Review email security. Are your gateways detecting typosquatting domains? Implement DMARC, SPF, and DKIM to prevent email spoofing.
  2. Strengthen payment controls. Implement a "verified vendor master file" that cannot be altered without dual approval and direct vendor confirmation.
  3. Train finance staff. Verify invoice metadata, question urgent payment demands, and always confirm bank changes via phone using known numbers.
Module 4: The Mobile Money Laundering Trail
Scenario: The Mobile Money Laundering Trail
Cyber-laundering / SIM swap fraud β€” step-by-step response
πŸ“– The Situation

Your company's CFO receives a call from someone claiming to be from the bank's "fraud department," stating that suspicious transactions have been detected on the corporate account. The caller knows the CFO's name, recent transactions, and account balance. The CFO is instructed to "verify" the account by providing a one-time password (OTP) sent to their phone. Within minutes, GHS 2.3 million is drained from the corporate account through multiple mobile money transactions to over 50 different wallets.

The Red Flags

✦ Unsolicited call claiming to be from the bank
✦ Caller has detailed knowledge of account activity (prior data breach or insider information)
✦ Request for OTP or PIN (banks never ask for these)
✦ Rapid dispersal of funds across multiple mobile money wallets (layering)
✦ Transaction pattern designed to stay below reporting thresholds
Why It Matters: This is money laundering and fraud under Act 29 and the Anti-Money Laundering Act, 2020 (Act 1044). If the stolen funds are proceeds of corruption or are used to bribe public officials, the OSP has jurisdiction. The Cybersecurity Act 2020 also criminalises unauthorised access and system interference.

πŸ” For the IT Security Manager

  1. Immediately freeze all accounts. Contact the bank's fraud hotline and mobile money providers to freeze the corporate account and trace the receiving wallets.
  2. Preserve logs. Capture all email logs, phone records, and network traffic from the CFO's devices for the 48 hours preceding the incident.
  3. Check for SIM swap. Contact the telecom provider to determine if the CFO's SIM was swapped or cloned β€” a common precursor to mobile money fraud.
  4. Scan for malware. The CFO's phone or laptop may be compromised. Conduct a full forensic scan.
  5. Check for data exfiltration. Did the attacker gain access to other corporate data? Review DLP (Data Loss Prevention) logs.

πŸ“‹ For the Compliance Executive

  1. Report to the bank immediately. File a formal fraud report. Request transaction traces for all 50+ receiving wallets.
  2. File a police report. Report to the CID Cybercrime Unit. For amounts over GHS 100,000, also notify EOCO.
  3. Assess regulatory reporting. If customer or employee personal data was compromised, notify the Data Protection Commission within a reasonable time under Act 843.
  4. Notify insurers. If you have cyber insurance or fidelity bonds, initiate the claims process.
  5. Do not negotiate with the fraudster without law enforcement involvement.

πŸ‘” For the CIO

  1. Implement MFA immediately. All financial transactions must require multi-factor authentication that does not rely solely on SMS (vulnerable to SIM swap). Use app-based authenticators or hardware tokens.
  2. Review privileged access. Who has access to the CFO's calendar, transaction history, or contact list? This information may have been harvested internally.
  3. Conduct a social-engineering drill. Test staff susceptibility to vishing (voice phishing) and smishing (SMS phishing).
  4. Establish a verification protocol. No payment instruction received via email or phone alone is valid. It must be confirmed through a second, independent channel.
Module 5: The Ransomware Attack
Scenario: The Ransomware Attack on Financial Records
Critical Information Infrastructure / data integrity β€” step-by-step response
πŸ“– The Situation

At 2:00 AM, your organisation's financial management system is encrypted by ransomware. A message demands $500,000 in Bitcoin for the decryption key. The attackers threaten to publish 5 years of payroll, procurement, and tax records on the dark web if payment is not made within 72 hours. Your organisation is a government contractor, and the leaked data includes sensitive employee information and details of public contracts.

The Red Flags

✦ Sudden encryption of critical systems
✦ Ransom demand in cryptocurrency
✦ Threat to publish stolen data (double extortion)
✦ Attack timed during low-activity hours
✦ Evidence of prior reconnaissance (attackers knew which systems held financial data)
Why It Matters: Under the Cybersecurity Act 2020 (Act 1038), your system may qualify as Critical Information Infrastructure (CII) if it supports essential public services or national security. Failure to protect CII can result in severe penalties. If you pay the ransom, you may be funding organised crime. If you don't, sensitive public contract data may expose corruption β€” or be used to extort public officials.

πŸ‘” For the CIO

  1. Activate the Incident Response Plan immediately. Isolate affected systems from the network to prevent lateral movement. Do not shut down systems if it will destroy forensic evidence.
  2. Do not pay the ransom yet. Paying does not guarantee decryption and may invite future attacks. It may also violate anti-money laundering laws if the attackers are sanctioned entities.
  3. Engage a cybersecurity incident response firm. They can assess the ransomware strain, determine if a decryption tool exists, and negotiate if necessary.
  4. Preserve evidence. Capture memory dumps, network traffic logs, and disk images before cleanup. The CID Cybercrime Unit or private forensics firms will need these.
  5. Assess CII obligations. If your organisation operates CII, you must report the incident to the Cyber Security Authority (CSA) under Act 1038.

πŸ” For the IT Security Manager

  1. Identify the attack vector. Phishing email? Unpatched vulnerability? Compromised remote desktop protocol (RDP)? Close the entry point immediately.
  2. Check backup integrity. Verify that offline backups are clean and restorable. If backups are also encrypted, the attack had inside knowledge or long dwell time.
  3. Scan for persistence. Ransomware actors often leave backdoors. Check for new user accounts, scheduled tasks, or remote access tools.
  4. Coordinate with legal. Determine if you have a legal obligation to report the breach to affected parties, regulators, or law enforcement.

πŸ“‹ For the Compliance Executive

  1. Assess data breach notification obligations. Under Act 843, notify the Data Protection Commission and affected data subjects "as soon as reasonably practicable."
  2. Evaluate corruption exposure. If the leaked data reveals irregularities in public contracts, ghost names, or inflated invoices, you must self-disclose to the OSP before the data becomes public. Proactive disclosure demonstrates good faith.
  3. Review cyber insurance. Initiate claims. Document all response costs.
  4. Prepare public communications. If the breach becomes public, control the narrative with transparency.
  5. Post-incident audit. Commission an independent forensic audit of the attack and your cybersecurity posture. Share results with the Board.
Module 6: The IT Admin's Backdoor
Scenario: The IT Admin's Backdoor
Insider threat / privilege abuse β€” step-by-step response
πŸ“– The Situation

Your IT Security Manager discovers that a senior database administrator (DBA) has created a hidden "service account" with full system privileges. The account was created 18 months ago and has been used to run SQL queries during off-hours (11 PM – 4 AM). The queries extract payroll data, vendor payment schedules, and employee bank details. The DBA has recently purchased a luxury vehicle and moved to an upscale neighbourhood. When questioned, the DBA claims the account was for "emergency maintenance" and the data extraction was for "performance optimisation."

The Red Flags

✦ Hidden service account with excessive privileges
✦ Off-hours database access not tied to scheduled maintenance windows
✦ Data extraction queries targeting sensitive financial and personal data
✦ Unexplained lifestyle changes (pressure/opportunity convergence)
✦ Defensive or vague explanations when questioned
Why It Matters: This is unauthorised access and data theft under Act 1038 and Act 772. If the stolen data is sold to competitors, used for extortion, or facilitates ghost-name fraud, it becomes a corruption-related offence. The DBA may be acting alone, or may be part of a larger criminal network.

πŸ” For the IT Security Manager

  1. Do not confront the DBA alone. This could trigger data destruction or escalation. Coordinate with HR and legal first.
  2. Preserve forensic evidence silently. Capture all SQL query logs from the service account; network traffic to and from the DBA's workstation; USB device connection logs; email and chat logs.
  3. Disable the service account during a planned "system maintenance" window to avoid alerting the DBA.
  4. Check for additional backdoors. Search for other unauthorised accounts, SSH keys, or VPN configurations.
  5. Review the DBA's access history. What other systems did they touch? Did they access systems outside their job scope?

πŸ‘” For the CIO

  1. Suspend the DBA's access immediately. Place them on administrative leave pending investigation.
  2. Engage external forensics. Given the DBA's sophistication, internal staff may miss evidence. The CID Cybercrime Unit or a certified digital forensics firm should handle the investigation.
  3. Assess data exposure. Which records were extracted? How many employees, vendors, or customers are affected? This determines breach notification and regulatory obligations.
  4. Review the hiring process. How was this DBA vetted? Were background and reference checks conducted?
  5. Implement "zero trust" architecture. No user should have standing access to all systems. Use just-in-time (JIT) access β€” elevated privileges granted only for specific tasks and automatically revoked.

πŸ“‹ For the Compliance Executive

  1. Quantify the risk. If payroll data was stolen, are ghost names being created? If vendor data was stolen, are fake invoices being generated?
  2. Notify affected parties. If personal data was compromised, comply with Act 843 breach notification requirements.
  3. Report to law enforcement. File a report with the CID Cybercrime Unit. If the data was used to facilitate fraud involving public funds, report to the OSP.
  4. Review insurance coverage. Fidelity insurance may cover losses from employee dishonesty.
  5. Strengthen the insider threat programme. User behaviour analytics (UBA) to detect anomalies; mandatory vacation policies for privileged IT staff; separation of duties (no single DBA can create accounts AND modify audit logs).
Module 7: The Compromised Vendor Portal
Scenario: The Compromised Vendor Portal
The Compromised Vendor Portal

The Red Flags

✦ Similar vendor names with slight variations (shell company creation)
✦ Identical addresses and bank accounts for supposedly different vendors
✦ Portal access from foreign IP addresses
✦ Use of legitimate but compromised credentials (credential stuffing or phishing)
✦ Payments to new vendors without proper due diligence
Why It Matters: This is procurement fraud and money laundering facilitated by cyber means. If the compromised procurement officer colluded with the attackers, or if the payments involve public contracts, the OSP has jurisdiction. The Cybersecurity Act 2020 holds corporate officers liable if they cannot prove they were unaware of the offence.

πŸ” For the IT Security Manager

  1. Immediately disable the compromised account and force a password reset for all procurement portal users.
  2. Analyse the access logs. When did the foreign IP first access the portal? How long was the dwell time? What data was viewed or modified?
  3. Check for credential compromise. Was the officer's password weak or reused from a breached site? Implement passwordless authentication or MFA for the portal.
  4. Scan the portal for malware. The attackers may have planted a web shell to maintain access.
  5. Verify portal security. Is it patched? Does it have WAF (Web Application Firewall) protection? When was the last penetration test?

πŸ“‹ For the Compliance Executive

  1. Freeze all payments to the three suspicious vendors immediately.
  2. Conduct vendor due diligence. Are these companies registered with the Registrar-General's Department? Check tax clearance certificates. Visit the registered address.
  3. Trace the funds. Where did the GHS 1.8 million go after reaching the vendor bank account? Request bank cooperation through legal channels.
  4. Report to law enforcement. This is organised fraud. Report to CID and EOCO. If public funds are involved, report to the OSP.
  5. Review vendor onboarding controls. Mandatory physical verification of new vendors; dual approval for vendor creation; automatic flagging of similar names/addresses/bank accounts; quarterly vendor master file audits.

πŸ‘” For the CIO

  1. Assess third-party risk. Your vendor portal is a supply chain vulnerability. Conduct a security assessment of all third-party platforms with access to your financial systems.
  2. Implement network segmentation. The vendor portal should not have direct access to your ERP or payroll systems.
  3. Enhance monitoring. Deploy SIEM (Security Information and Event Management) to detect anomalous login patterns, especially from foreign IPs.
  4. Require security certifications. Vendors handling your data must demonstrate compliance with Act 1038 and Act 843.
Module 8: The Deepfake CEO Fraud
Scenario: The Deepfake CEO Fraud
AI-enabled cyber-corruption β€” step-by-step response
πŸ“– The Situation

The Chief Accountant receives a WhatsApp video call from someone who looks and sounds exactly like the CEO. The "CEO" is in a "confidential acquisition meeting" and urgently needs a GHS 800,000 transfer to a "lawyer's escrow account" to secure the deal. The video is convincing β€” the background looks like the CEO's office, the voice is identical, and the "CEO" references a real upcoming board meeting. The Chief Accountant initiates the transfer. Hours later, the real CEO denies making the call.

The Red Flags

✦ Urgent, unusual request via video call
✦ Request to bypass normal approval processes ("I'm in a meeting, just do it")
✦ New bank account not in the vendor master file
✦ Use of deepfake technology to impersonate leadership
✦ Request for secrecy ("don't tell anyone until the deal is announced")
Why It Matters: This is advanced fraud using AI. INTERPOL's 2026 African Cyberthreat Assessment reports that deepfake technology is being used across Africa to impersonate business leaders and political figures for financial gain. In Ghana, where mobile money and fintech adoption is high, these scams are evolving rapidly.

πŸ‘” For the CIO

  1. Educate the C-suite immediately. Deepfake threats target senior leadership. Their public videos, photos, and voice recordings can be used to create convincing fakes.
  2. Implement out-of-band verification. No financial instruction received via video, voice, or email alone is valid. It must be confirmed through a second channel (a call to a known number, or in-person confirmation).
  3. Deploy deepfake detection tools. Audio and video analysis tools can detect synthetic media, though this technology is still maturing.
  4. Limit executive digital exposure. Reduce publicly available high-resolution video and audio of senior leaders that can train deepfake models.

πŸ” For the IT Security Manager

  1. Analyse the call metadata. How was the WhatsApp call routed? From the CEO's actual number, or a spoofed one? Check SIM swap records with the telecom provider.
  2. Preserve the video. It is evidence. Deepfake analysis can sometimes identify the AI model used or artefacts inconsistent with genuine video.
  3. Scan the Chief Accountant's device. The attacker may have compromised it to learn about the upcoming board meeting.
  4. Review email and calendar access. How did the attacker know the CEO was travelling or in meetings? This suggests prior reconnaissance.

πŸ“‹ For the Compliance Executive

  1. Attempt to recall the funds. Contact the bank immediately. If the funds have moved, initiate a fraud trace.
  2. File a police report. Report to the CID Cybercrime Unit. Deepfake fraud is a criminal offence under Act 29 and Act 772.
  3. Review payment authorisation limits. The Chief Accountant should not have unilateral authority to transfer GHS 800,000. Implement dual control for all transfers above a defined threshold.
  4. Update the fraud risk register. Deepfake attacks are an emerging threat. Update policies, training, and insurance coverage.
  5. Conduct organisation-wide training. Show staff examples of deepfake calls. Teach them to ask questions only the real person would know, request a callback on a known number, and never bypass approval processes based on "urgency."
Module 8: The Deepfake CEO Fraud
Guardians of the Digital Republic
Conclusion, the 6-Pillar framework and your next steps

Guardians of the Digital Republic

You have completed a rigorous journey through digital compliance, cyber-corruption, and data integrity. You understand that the OSP's mandate extends into the digital realm. You can identify ghost names, forged documents, cyber-laundering, and insider threats. You have step-by-step protocols for realistic scenarios. You have role-specific toolkits.

But in the digital age, defence is not a destination β€” it is a discipline.

The 6-Pillar Framework

Sustainable digital integrity requires a holistic framework. No single control or individual is sufficient.

✦ Identity & Access Management (IAM)
✦ Data Integrity
✦ Network & Endpoint Security
✦ Supply Chain / Third-Party Security
✦ Incident Response
✦ Organisational Culture (tone at the top)

Your Next Steps

  1. Audit your payroll system this month for ghost-name indicators (duplicate mobile money numbers, missing Ghana Cards, no biometric data).
  2. Review all legacy system connections and decommission those that are unnecessary.
  3. Test your incident response plan with a tabletop exercise involving ransomware and insider threats.
  4. Implement out-of-band verification for all financial transactions above your defined threshold.
  5. Register with the Data Protection Commission if you have not; appoint a certified data protection supervisor if you are a large data controller.
  6. Report cyber-enabled corruption to the OSP when public officials or public funds are involved.
In Ghana, we lost GHΒ’14.94 million to cybercrime in just six months of 2025. We discovered 81,885 ghost names on a single public payroll. Every cedi stolen through a backdoor, every ghost name paid through a manipulated database, every forged invoice approved through a compromised email account is a theft from the Ghanaian people. As CIOs, IT Security Managers, and Compliance Executives, you do not merely manage systems. You safeguard the digital trust upon which our nation's future depends. Build systems that are honest. Build systems that are just. Build systems that serve Ghana.

πŸŽ‰ Congratulations β€” All 8 Modules Complete!

You have completed the YAC-OSP Digital Compliance, Cyber-Corruption and Data Integrity course. You are now ready for the final assessment. Score 16 out of 20 or higher to earn your certificate.

πŸ“ Final Assessment Quiz

Test your understanding of YAC-OSP Digital Compliance, Cyber-Corruption, and Data Integrity.

πŸ“‹ 20 Questions
βœ… Pass: 16/20 correct
πŸ† Certificate on passing
Youth Against Corruption (YAC)
Integrity starts with Us

CERTIFICATE OF COMPLETION

This is to certify that

Eugene Fiifi Brown

has successfully completed the YAC-OSP Digital Compliance, Cyber-Corruption, and Data Integrity, demonstrating competence in recognizing and resisting corruption, applying ethical decision-making.

(This certificate is not issued by an academic institution and does not entitle bearer to academic credit:
It is intended for personal and professional development.)

Samuel Appiah Darko Esq.

Director in charge of YAC, OSP

Issuing Date: Issuing Date:
Progress: 0/17 Lessons
0%