IMS Policy
Information Security Policy Statement
Paga is committed to protecting the confidentiality, integrity, and availability of all information and
information assets – including customer financial data, transaction records, cardholder data, and
personally identifiable information – throughout their lifecycle. The organisation applies a risk-based
approach to identifying, assessing, and treating information security risks, and implements appropriate
controls to prevent unauthorised access, use, disclosure, alteration, loss, or disruption of information
across its payment platform, agency banking network, and PAAS offerings.
Business Continuity Policy Statement
Paga is committed to maintaining the resilience of its critical payment services – including bank transfers, bill payments, airtime purchases, cash-in/cash-out operations, and remittances – by identifying potential disruptive events and their impacts, establishing appropriate continuity, response, and recovery arrangements, and maintaining the capability to restore operations within the shortest practicable timeframe following any disruptive incident.
IT Service Management Policy Statement
Paga is committed to delivering IT services that achieve and maintain the required uptime, optimisation
of IT assets and capabilities, and customer satisfaction levels aligned with agreed service levels. Paga
ensures that service management processes are designed, operated, and continually improved in
alignment with information security and business continuity requirements, supporting the seamless
delivery of services across all functions.
Commitment to Satisfying Applicable Requirements
Paga identifies, understands, and fulfils the statutory, regulatory, contractual, and other requirements
applicable to its IMS, including: CBN directives and the MMO regulatory framework; the Nigeria Data
Protection Act (NDPA) 2023 and NDPC requirements; PCI-DSS obligations applicable to payment card
processing; NIBSS interconnectivity requirements; the requirements of ISO/IEC 27001:2022, ISO
22301:2019, and ISO/IEC 20000-1:2018; and all applicable contractual obligations to customers, agents,
and partners. Where requirements change, Paga reviews and updates relevant policies, controls, and
documented information accordingly.
Commitment to Continual Improvement
Paga is committed to continually improving the suitability, adequacy, and effectiveness of the Integrated
Management System across the ISMS, BCMS, and SMS. The organisation promotes a culture of learning
in which lessons from incidents, disruptions, audits, exercises, and operations strengthen IMS
performance. Improvement opportunities are identified through:
Information security and business continuity risk assessments and business impact analyses;
Internal and external audits against all three ISO standards and management reviews by the IMS
Steering Group;
Business continuity exercises, IT service recovery tests, and corrective action tracking; and
Performance monitoring and feedback from employees, customers, agents, regulators, and
interested parties.
Improvements are prioritised by risk, impact, and alignment with Paga's financial inclusion mission, and
their effectiveness is verified through subsequent review cycles.


