Express an interest

If you are interested & require further information, we will email you a copy of the programme brochure.

An error has occurred

Data Protection Notice

EFFECTIVE 1st SEPTEMBER 2026

What is the purpose of this document?

The Institute of Bankers in Ireland, trading as “IOB” takes privacy and the protection of our customer, affiliate, member, student and designate data very seriously. In this notice, we explain how we collect your personal information, how we use it and how you can interact with us about it.

Who are we?

When we talk about “IOB”, or “us” or “we” in this notice, we are talking about IOB and, where applicable, its wholly owned subsidiary company “IFS DAC” (trading as Institute of Financial Services Designated Activity Company).

What is this notice?

This privacy notice describes how we collect and use the personal information of individuals we engage with (such individuals are referred to in this notice as “data subject” or “you”).

The table below describes the categories of individuals who this notice applies to.

Categories of individuals this notice applies to table
Identifier Data Subject Category Description Includes
DS1 Members, Learners and Participants Individuals who engage with IOB educational, professional development, membership, examination, certification or event-related services. Members, Prospective Members, Affiliates, Designates, Students; Applicants (to IOB programmes); Event participants and registrants; Student representatives.
DS2 Website and Digital Service Users Individuals who access or interact with IOB websites, online platforms, applications, portals or digital services. Website visitors; portal users; LMS users; online account users; digital service users; users interacting with cookies or analytics technologies.
DS3 Employees, Applicants and Workforce Personnel Individuals engaged in recruitment, employment, work placement, consultancy or other workforce-related activities with IOB. IOB Employees; Job Applicants; Contractors; Consultants; Interns; Facilities Contractors; Agency Workers.
DS4 Suppliers, Service Providers and Business Contacts Individuals representing organisations that supply goods or services to IOB, partner with IOB, or interact with IOB in a professional or commercial capacity. Supplier representatives; Educational Partner representatives; Associate Faculty including lecturers, tutors, examiners, moderators, invigilators and external examiners; Speakers; Authors; Contributors; Corporate contacts; Business relationship contacts (including Corporate Portal users).
DS5 Governance, Council and Committee Participants Individuals involved in the governance, oversight, advisory, committee, council or management structures of IOB. Board members; Council Members/Officers/Directors (including FPSB); Regional Committee Members; Advisory Group Participants; Governance Office Holders; Meeting Contributors.
DS6 Enquirers, Complainants and Support Users Individuals who contact IOB to make an enquiry, submit a complaint, request assistance, exercise rights or otherwise seek support. General enquirers; complainants; support users; individuals involved in rights requests, incidents, disputes or case handling.
DS7 Visitors Individuals visiting IOB premises, attending meetings or events on-site, or otherwise entering locations operated or managed by IOB. Office visitors; meeting attendees; on-site event attendees; delivery personnel; contractors attending premises; persons captured by visitor or security systems.

This notice does not form part of any contract to provide services. We may update this notice at any time.

Supplementary Privacy Notices

IOB may provide supplementary privacy notices where particular processing activities require more detailed transparency information than is contained within this Data Protection Notice. Such notices should be read together with this Notice and may apply to recruitment and applicant activities, employment-related processing, online assessment and invigilation activities, photography, filming and audio recording, research activities and other specific processing activities where additional transparency information is appropriate.

It is important that you read this notice, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal data about you, so that you are aware of how and why we are using such data.

Data Controller

IOB is a “data controller”. This means that we are responsible for deciding how we hold and use personal data about you. We are required under data protection legislation to notify you of the information contained in this privacy notice.

Joint Controller Arrangements

For certain educational programmes, professional designations, certification schemes, accreditation activities and continuing professional development ("CPD") services, IOB may act as a joint controller with an educational institution, professional body, accreditation body or other organisation where both organisations jointly determine the purposes and means of processing personal data.

Where a joint controller arrangement applies, personal data may be exchanged between the joint controllers for purposes including:

  • programme administration;

  • learner and member support;

  • assessment and certification activities;

  • designation administration and renewal;

  • CPD monitoring and compliance activities;

  • quality assurance and governance;

  • regulatory reporting;

  • audit and compliance activities; and

  • the exercise, establishment or defence of legal claims.

Examples of organisations with which IOB may act as a joint controller include educational partners, professional bodies, designation providers, accreditation organisations and examination bodies (e.g. UCD, the Compliance Institute, the Central Bank of Ireland, Insolvency Service of Ireland (ISI), Chartered Institute of Bankers in Scotland (CIOBS)).

Where IOB acts as a joint controller, responsibilities for compliance with data protection legislation are allocated between the parties in accordance with applicable law. Further information regarding applicable joint-controller arrangements, including the essence of those arrangements, is available on request from the Data Protection Officer.

Workforce and Business Relationships

We process personal data for the purposes of recruitment and for the formation and administration of the contract of employment and employee relationship in support of IOB’s operations. A detailed privacy notice for IOB employees is available from Human Resources and is provided to new members of staff with their contract. Additional information regarding recruitment and employment processing is contained within the Recruitment & Applicant Privacy Notice and Employee Privacy Notice.

Suppliers, Service Providers and Business Contacts

We process personal data relating to suppliers, contractors, consultants, associate faculty, educational partner representatives and other business contacts for the purposes of supplier onboarding, due diligence, contract administration, procurement, payment processing, relationship management, regulatory compliance, governance, audit and business operations.

This may include contact details, professional information, contractual information, financial information, payment records, bank account details, taxation information and records of communications with IOB.

Further information regarding the purposes, lawful bases and categories of personal data processed is provided in the processing activities table below.

Children and Younger Learners

Some IOB programmes, educational activities or apprenticeship-related services may involve the processing of personal data relating to children or individuals under the age of 18.

Where IOB processes personal data relating to children, we will do so in accordance with applicable data protection legislation and will implement additional safeguards appropriate to the nature of the processing and the age of the individual concerned.

Where required, IOB may communicate with a parent, guardian, employer, sponsor, training provider, educational institution or other authorised representative regarding matters connected with programme administration, learner welfare, regulatory obligations, assessment activities or the provision of educational services.

Additional information regarding specific processing activities may be provided in supplementary privacy notices where appropriate.


What kind of information does IOB collect and hold about you?

Personal Data

“Personal data” means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). There are “special categories of personal data” which require a higher level of protection. These include information about a person’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health or condition or sexual life.

We collect different types of personal data depending on your relationship with us. To make this easier to understand, we have grouped personal data into the categories below.

Personal data categories table
Code Category Examples
A Identity Data Name; date of birth; nationality; country of birth; student number; member number; employee number; customer/account number; photograph used for identification.
B Contact Data Email address; postal address; mobile number; phone number; work contact details.
C Employment and Professional Data Employer; job title; department; role; qualifications; professional experience; directorships; supplier representative details; council membership.
D Account and Access Data Username; account ID; login credentials; authentication factors; access logs; account status; corporate portal access records.
E Learning and Programme Data Programme enrolments; module selections; course registrations; attendance; learning activity; LMS participation; CPD participation where not designation-specific.
F Assessment and Qualification Data Exam results; grades; assessment scripts; transcripts; awards; qualifications achieved; completion status; academic standing; exam feedback.
G Financial and Transaction Data Bank details; IBAN; payment records; invoices; supplier account details; VAT numbers; tax records; PPSN (where required); withholding-tax records.
H Interaction and Communications Data Emails; SMS; correspondence; call recordings; complaints; CRM notes; chat transcripts; case notes; query history; AI-generated interactions, prompts submitted to AI-enabled systems, responses generated by AI-enabled systems and records of interactions with virtual assistants or educational AI services.
I Technical and Usage Data IP address; browser data; device identifiers; cookies; LMS activity logs; application usage logs; system activity metadata; AI service usage logs, model interaction metadata and service performance data generated through educational technologies.
J Security, Monitoring and Integrity Data CCTV; building access logs; security logs; online invigilation data; exam monitoring flags; fraud monitoring records; access control records.
K Media and Recording Data Photographs; videos; audio recordings; lecture recordings; webinar recordings; testimonials; speaker images; event recordings.
L Governance and Organisational Data Council member data; committee records; board papers; meeting minutes; annual return records; supplier representative details; governance documentation.
M Special Category Personal Data Health information; disability information; accessibility requirements; medical certificates; GP/hospital letters; dietary requirements revealing health or religion; biometric data where used for identification.

Where relevant, additional governance controls and safeguards may apply to certain types of personal data, including criminal offence data, government identifiers, biometric data, children's data and international transfers

Criminal Convictions and Offences Data

IOB does not routinely collect or systematically process personal data relating to criminal convictions or offences. Such data is only processed where necessary and proportionate in accordance with applicable law. Where personal data relating to criminal convictions is processed, IOB will ensure that appropriate safeguards are applied, including restricted access, strict retention controls and oversight by authorised personnel.


How does IOB collect and hold personal information about you?

We collect personal information from you, for example when you become a member; or a customer in order to create an account on IOB Learn; register to an educational programme; apply for information on our products and services; apply for a designation/CPD scheme or express an interest in one of our programmes or a programme offered in association with one of our educational partners; provide a service to IOB; become a Council member; apply for a job with IOB etc. We also collect information through our websites, web-conferencing, social media, the IOB Learn application, CCTV footage and through communication between you and IOB by telephone, email and chat (via our websites) (for example, when you make enquiries about a programme or when you are raising concerns or queries).

We will create some data internally (e.g. when we assign you an IOB customer number or you become a council member or determine assessment results or exchange correspondence with you).

We will also collect additional personal information throughout the period you remain a member or student of IOB, council member, corporate customer, or you continue to interact/work with or provide a service to IOB or purchase products/services from us.

In some circumstances, we obtain personal data about you from sources other than directly from you. The source of the information depends on your relationship with IOB and the service or activity concerned.

We may obtain personal data from:

  • employers, sponsors, educational institutions, professional bodies or other organisations that nominate, sponsor, fund or administer your participation in IOB programmes, services, membership schemes, professional designations or continuing professional development activities;

  • referees, previous employers, recruitment agencies, educational institutions, qualification-awarding bodies and other third parties involved in recruitment, employment or workforce-related processes;

  • educational partners, lecturers, tutors, examiners, moderators, invigilators, mentors and other contributors involved in the delivery, assessment or administration of educational, professional development or examination services;

  • parents, guardians or authorised representatives acting on behalf of a learner where appropriate.

  • service providers and suppliers who support the delivery of our programmes, examinations, online services, customer support, technology platforms and business operations;

  • regulators, accreditation bodies, professional standards bodies, government departments and public authorities where information is provided to us in connection with legal, regulatory or professional requirements;

  • publicly available sources, including publicly accessible registers, professional directories, company records, regulatory publications, websites and other publicly available information sources where permitted by law; and

  • individuals acting on your behalf, including authorised representatives, guardians, attorneys or other persons authorised to communicate with us in relation to your affairs.

Where we obtain personal data from third parties, we will process that information in accordance with applicable data protection legislation and provide any additional transparency information required by law, including information regarding the source of the data and how it will be used.

Cookies and similar technologies

IOB websites and digital services may use cookies and similar technologies to operate our websites, improve functionality, understand usage and support online services. Some third-party tools, including chat, help centre or analytics tools, may also use cookies or similar technologies. Further information is provided through our cookie settings or cookie notice, where applicable. Where chat or help centre functionality is provided by a third-party provider, that provider may use cookies or similar technologies in connection with that service.


How does IOB use your information?

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to perform the contract we have entered into with you;

  • Where we need to comply with a legal obligation;

  • Where we obtain your consent;

  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;

  • Where processing is necessary for the performance of a task carried out in the public interest, where applicable;

  • We may also use your personal data, which is likely to be rare, where we need to protect your interests (or someone else’s interests).

Purposes for which IOB uses your personal information

The table below describes the legal basis that applies to our purposes for processing your personal data and for the categories of individuals that applies to. Depending on the circumstances, more than one legal basis may apply.

Purposes Functional Area Category of Data Subject Category of Personal Data Lawful basis for processing
Create your account on IOB Learn, provide access to learning content, communities, discussion areas and channels relevant to your membership, programme or designation, send you notifications via IOB Learn (if notifications are enabled) and otherwise facilitate your use of IOB Learn in accordance with our Terms and Conditions. Member Services DS1 - Members, Learners and Participants; DS5 - Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users Categories A, B, C, D, E, F, I and M (where applicable) Performance of a contract with you
To process and administer your membership Member Services DS1 Members, Learners and Participants Categories A, B, C, D, H and I  Performance of a contract with you;Necessary for our legitimate interests to keep our records updated and ensuring that our services are provided
To process and administer your IOB programmes Student Services DS1 Members, Learners and Participants Categories A, B, C, D, E, H and I  Performance of a contract with you; Necessary for our legitimate interests to ensure that our services are provided
To process and administer CPD schemes, professional designations, designation applications, designation renewals, annual returns, audits, compliance reviews, designation reinstatements, designation resignations, fitness and probity related processes, fee arrangements, designation verification, employer confirmations, regulatory reporting and associated governance requirements. Designate Services / CPD Governance DS1 Members, Learners and Participants Categories A, B, C, D, F, G, H and I, and M where applicable Performance of a contract with you; Necessary for our legitimate interests in administering professional designations and compliance processes; and, where applicable, necessary to comply with legal or regulatory obligations.
The provision of student disability and equality services. The provision of reasonable accommodations. Student Services / Learner Support  DS1 Members, Learners and Participants  Categories A, B, E, F, H and M Performance of a contract with you; and, where special category data is processed, Article 9 GDPR condition as applicable, including explicit consent where required.;Article 6(1)(a) / 9(2)(a) GDPR: “the data subject has given consent / explicit consent to the processing of his or her personal data for one or more specific purposes”. Article 6(1)(d) GDPR: “processing is necessary in order to protect the vital interests of the data subject or of another natural person” (vital interests of the individual). Performance of a contract. Statutory requirement.
If necessary due to a medical emergency. The protection of vital interests. The protection of public health Duty of Care  DS1 Members, Learners and Participants; DS7 Visitors   Categories A, B, H, J and M (where applicable Vital interests; and, where applicable, compliance with legal obligations relating to health, safety and incident response. 
Managing our relationship with you including notifying you of changes to our terms or privacy policy or asking you for your feedback on our services/products, recording our communications with you, for regulatory purposes, delivering our services to you Member Services DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users; DS7 Visitors  Categories A, B, C, D, E, F, G, H, I, J, K, L and M (where applicable) Performance of a contract with you; Necessary for our legitimate interests to maintain our relationship with you, keep our records updated, to study how you use our products/services and ensuring that our services are provided; and Necessary to comply with a legal obligation
Manage IOB governance, banking and investment activities Governance & Corporate Secretariat DS5 Governance, Council and Committee Participants Categories A, B, L Necessary to comply with a legal obligation
Manage pension auto-enrolment contributions  Human Resources / Payroll DS3 Employees, Applicants and Workforce Personnel  Categories A, B, G, H and I  Necessary to comply with a legal obligation
To register you on our programmes including (a) managing and processing payments, fees and charges for such programmes; and (b) collecting and recovering money owed to us Student Services / Finance  DS1 Members, Learners and Participants Categories A, B, E, G, H and I Performance of a contract with you; Necessary for our legitimate interests to recover debts due to us
Verify your identity as the test taker/exam candidate, to ensure compliance by you with our Examination Regulations, for any investigations and appeals and to contact you to provide assistance during the online exams  Assessment & Examination Services DS1 Members, Learners and Participants  Categories A, B, D, E, J and K (where online invigilation or identity verification involves monitoring or recording)  Performance of a contract with you; Necessary for our legitimate interests for running and maintaining our business, performance of our examination function and ensuring compliance with IOB and UCD Student and Exam Regulations
To run, administer, monitor and support examinations, assessments, online examinations, invigilation, academic integrity processes, appeals, reviews, rechecks, script viewing, exam board processes and compliance with IOB, UCD and applicable examination regulations. Assessment & Examination Services DS1 Members, Learners and Participants  Categories A, B, D, E, F, J and K, and M where applicable Performance of a contract with you; Necessary for our legitimate interests for running and maintaining our business, performance of our examination function and ensuring compliance with our Examination Regulations
Conduct surveys, obtain feedback, review services, evaluate programmes, assess learner, member, employee or stakeholder experience and improve IOB services. Research, Quality Enhancement & Service Improvement DS1, DS2, DS3, DS4, DS5 and DS6, as applicable Categories A, B, C, E, H and I, and M where applicable Consent where required; otherwise legitimate interests in reviewing, improving and developing our services.
Retention of academic data and data of archival value in the public interest.  Academic Registry & Records Management DS1 Members, Learners and Participants Categories E, F and L Necessary to carry out IOB’s objectives and functions as a “linked provider” under the Qualifications and Quality Assurance (Education and Training) Act 2012; Permitted by section 42 of the Data Protection Act 2018. Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, where applicable.
Administration, organisation, planning and monitoring the delivery of seminars, conferring ceremonies, training and events, such as to reserve a place for you at such events and to ensure that the events are properly hosted and attended; communicating with you in relation to our events; prepare and produce table/seating plans; prepare and produce attendee lists and/or conferring booklets; seeking your feedback  Events & Professional Development DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts; DS7 Visitors  Categories A, B, C, D, E, G, H and K (where events are recorded or photographed)  Performance of a contract with you; Necessary for our legitimate interest in running, planning and monitoring the delivery of our events to ensure the needs of attendees as well as operating and growing our business; Necessary for the legitimate interest of companies who host, run or cater our events to ensure that they run smoothly
Administration, organisation, planning and monitoring the delivery of educational courses, seminars, tutorials, lectures, classroom sessions and events (including online), recording attendance, producing audio and video recordings of sessions, making recordings available through the Learning Management System for educational purposes, supporting flexible learning arrangements and facilitating programme completion. Recordings may also be used to support revision, accessibility, continuity of learning, absence management and other reasonable educational needs of learners Education Delivery & Learning Services DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts  Categories A, B, C, D, E, I and K Performance of a contract with you; Necessary for our legitimate interest in running, planning and monitoring the delivery of our educational services, ensuring compliance with our Examination Regulations, in performance of our examination function as well as operating and growing our business; Necessary for the legitimate interest of companies who provide IT, webcasting and hosting services to ensure that the online events run efficiently
Taking individual or group photographs of you at our events for use on our website and in our publications; recording and/or broadcasting our events. Communication and Promotion DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts; DS7 Visitors  Categories A, B and K Necessary for our legitimate interest in running and growing our business.
Your dietary requirements so as to determine the food and beverages to be served at our events and/or to determine your accessibility or attendance needs (including disability hearing or speech needs) and to facilitate your attendance at our events Events Management & Accessibility Services DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts; DS7 Visitors  Categories A, B and M (where dietary or accessibility information reveals health, disability or religion)  Article 6(1)(a) / 9(2)(a) GDPR: “the data subject has given consent / explicit consent to the processing of his or her personal data for one or more specific purposes”.
The administration of CCTV (footage of you at our events or on our premises) for safety and security purposes; and access control systems for security purposes. Health & Safety; Protection of Assets DS1 Members, Learners and Participants; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS7 Visitors  Category J  Comply with our legal obligations regarding safety; Necessary for our legitimate interests to ensure safety and security at our events.
Assignment of mentors to students (at their request) to provide them with educational, professional development, networking and career support.  Learner Support & Mentoring DS1 Members, Learners and Participants  Categories A, B and H  Consent
To respond to reference requests, status verification requests, qualification verification requests and other confirmation requests where authorised by you, required by law or otherwise permitted under applicable data protection legislation. Customer & Support Services DS1 Members, Learners and Participants; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts Categories A, B, C, E, F and H Consent where required; Performance of a contract with you; Legitimate interests in responding to verification and confirmation requests.
Performing enquiries, investigations and complaints and gathering evidence for possible disciplinary hearing Governance, Compliance & Investigations DS1 Members, Learners and Participants; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users  Categories A, B, C, D, E, F, G, H, I, J, K and M (where relevant)  Performance of a contract with you; Necessary for our legitimate interest for running, maintaining and growing our business
Administration of the Learning Management System which monitors students’ participation in our programmes, courses and online modules  Learning Technology Services DS1 Members, Learners and Participants  Categories A, B, D, E and I  Performance of a contract with you
Respond to your queries and assist you with your requests  Customer & Support Services DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users; DS7 Visitors Categories A, B, C, D, E, F, G, H, I and M (where applicable) Performance of a contract with you; Necessary for our legitimate interest in running and maintaining our business
Managing subscriptions to our products and services Member Services DS1 Members, Learners and Participants  Categories A, B, C, F, G, H and I Performance of a contract with you
Managing our relationship with your employer/membership body where they pay your membership, programme or CPD scheme fees to include providing data to them on your engagement with IOB programmes, as well as information on your attendance at our assessments and courses and your assessment results as well as working with them in relation to your compliance with our regulations (including CPD requirements) and in the cases where you contravene our Examination Regulations (to include providing them with any personal data or documents containing personal data that may indicate contravention of such regulations)  Corporate & Educational Partner Services DS1 Members, Learners and Participants  Categories A, B, C, D, E, F, H and I Performance of a contract with you; Necessary for our legitimate interest in running and maintaining our business, ensuring compliance with our regulations and studying the engagement with our programmes and; Necessary for legitimate interest of our corporate customers or educational partners for running and maintaining their business
To process and deliver orders for our products/services including (a) manage payments, fees and charges; (b) collect and recover money owed to us Finance & Commercial Operations DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts  Categories A, B, C, D, F, G, H and I  Performance of a contract with you; Necessary for our legitimate interests to recover debts due to us
Supplier onboarding, supplier due diligence, supplier account creation, contract administration, procurement, payment processing, audit, financial control, taxation compliance and supplier relationship management. Finance & Procurement DS4 Suppliers, Service Providers and Business Contacts Categories A, B, C, G and H Performance of a contract with you or your organisation, or steps taken prior to entering into a contract; Compliance with legal obligations relating to taxation, financial reporting, accounting, audit, company law and regulatory requirements. ; Necessary for IOB's legitimate interests in supplier management, procurement administration, business operations, fraud prevention, financial control and the establishment, exercise or defence of legal claims.
To procure and process payments for suppliers to IOB including (a) manage payments, fees and charges; (b) collect and recover money owed to us.  Finance & Procurement DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts  Categories A, B, C, D, F, G, H and I  Performance of a contract with you; Necessary for our legitimate interests to recover debts due to us
To send you relevant communications including marketing and to make suggestions and recommendations to you about products/services that may be of interest to you Marketing & Communications DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS4 Suppliers, Service Providers and Business Contacts  Categories A, B, C, D, H and I Necessary for our legitimate interests to develop our products/services and grow our business
Administering the contract we have entered into with you  Contract & Relationship Management DS1 Members, Learners and Participants; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users; DS7 Visitors  Categories A, B, C, D, E, F, G, H, I, L and M (where applicable)  Performance of a contract with you
Business operation, management and planning, including accounting and auditing  Corporate Services & Finance DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users; DS7 Visitors  Categories A, B, C, D, E, F, G, H, I, J, K, L and M (where applicable)  Necessary for our legitimate interests for running, managing and growing our business; Necessary to comply with a legal obligation
Education, training and development requirements Human Resources & Learning Development DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts  Categories A,B,C,D,E Performance of a contract with you
Dealing with legal disputes Legal DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users; DS7 Visitors  Categories A, B, C, D, E, F, G, H, I and M (where applicable) Performance of a contract with you; Necessary for our legitimate interests for running and maintaining our business; Necessary to comply with a legal obligation
To prevent fraud Legal DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users; DS7 Visitors  Categories A, B, C, D, E, F, G, H, I, J, K, L and M (where applicable)  Necessary for our legitimate interests for running, maintaining and protecting our business; Necessary to comply with a legal obligation
To monitor your use of our information and communication systems to ensure compliance with our IT policies and regulations Information Governance & Compliance DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users Categories A, B, C, D, H, I and J Performance of a contract with you; Necessary for our legitimate interests for running and maintaining our business; Necessary to comply with a legal obligation
To ensure network and information security, including preventing unauthorised access to our computer and electronic communications systems and preventing malicious software distribution  Information Security & Cyber Security DS1 Members, Learners and Participants; DS2 Website and Digital Service Users; DS3 Employees, Applicants and Workforce Personnel; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants; DS6 Enquirers, Complainants and Support Users Categories A, B, D, I and J  Performance of a contract with you; Necessary for our legitimate interests for running and maintaining our business; Necessary to comply with a legal obligation
Carry out and support research, surveys, quality assurance, programme review and educational enhancement activities. Where personal data is processed by IOB for the purposes of research, detailed information about how personal data will be used will be provided to research participants prior to the collection of the relevant personal data or shortly after if the data is obtained from a third party. Where possible, personal data collected for research purposes will be pseudonymised so that the participant is no longer identifiable. Research & Academic Development  DS1 Members, Learners and Participants; DS4 Suppliers, Service Providers and Business Contacts; DS5 Governance, Council and Committee Participants   Categories A, B, C, E, F, H, I, K, L and M (where applicable)   Where research involves personal data, the relevant lawful basis and transparency information should be set out in the specific research notice or participant information provided for that activity. 
Monitoring learner participation, attendance, engagement and progression in order to identify students who may require additional academic, administrative or learner support, and contacting students where appropriate to provide assistance and facilitate successful programme completion. IOB may also analyse learner engagement information on an individual and aggregated basis to evaluate programme delivery, improve learner support services, improve educational effectiveness, identify trends and reduce unnecessary learner attrition. Engagement indicators are reviewed in a supportive context and are not used to make solely automated decisions about learners. Learner Success & Educational Analytics   DS1 Members, Learners and Participants  Categories A, B, D, E, I and K (where engagement information is derived from access to recorded educational content). Performance of a contract with you; and where appropriate, our legitimate interests in supporting student success, maintaining academic standards, improving educational services and reducing unnecessary learner attrition. Such monitoring is undertaken in a proportionate and supportive manner.
To assess, investigate, manage and respond to data protection enquiries, complaints, personal data breaches, data subject rights requests and regulatory matters, and to maintain records demonstrating compliance with applicable data protection legislation. Data Protection & Privacy Management DS1-DS7, as applicable. Categories A-M, as applicable Compliance with a legal obligation; establishment, exercise or defence of legal claims where applicable; legitimate interests in managing privacy, security and compliance activities; and, where necessary, reasons of substantial public interest in accordance with applicable data protection legislation.
To provide AI-enabled educational support services, virtual tutoring, information retrieval, study assistance, guided learning activities and related learner-support services; to improve educational delivery; and to monitor service quality, security and appropriate use. Learning Technology Services DS1 – Members, Learners and Participants A, B, D, E, H and I Performance of a contract with you; and legitimate interests in improving educational services, learner support and educational effectiveness.

Learner Engagement Information

IOB uses information generated through its educational systems, learning management systems, educational platforms and associated learning technologies to help administer programmes, support learners and improve educational services. Engagement information may include attendance records, participation in online learning activities, access to learning resources, viewing of recorded educational content, completion of learning activities, assessment participation and other indicators of academic engagement. Such information is reviewed by appropriately authorised staff and is used to support learners and enhance the quality and effectiveness of IOB's educational services. IOB does not make decisions producing legal or similarly significant effects based solely on automated analysis of learner engagement information.

Educational Technologies and Assessment Systems

IOB uses a range of educational, assessment and examination technologies to support the delivery of programmes, assessments, academic integrity processes, online examinations, identity verification, examination monitoring, online invigilation and learner support activities. Additional information regarding these activities, including the categories of personal data processed, applicable retention periods, recipients and safeguards, is provided in relevant supplementary privacy notices where applicable.

IOB may use AI-enabled educational technologies to support learning, revision, information retrieval, learner engagement and student support activities. Such systems may process information submitted by learners during their interactions with the service, together with associated usage and technical information. Where AI-enabled services are deployed, IOB will implement appropriate governance, security and human oversight measures and will provide additional information in supplementary privacy notices where required.

Direct marketing and preferences

IOB may contact you with information about our membership services, professional designations, educational programmes, examinations, events, CPD activities, publications and other products or services which may be relevant to your relationship with IOB.

Such communications may be provided by post, telephone, email, SMS or other digital communication channels where permitted by law.

You may update your marketing preferences at any time through available self-service facilities, where provided, or by contacting IOB directly.

Photography, Filming and Audio Recording

IOB may capture photography, film and audio recordings in connection with educational activities, conferences, events, ceremonies, promotional activities and organisational communications. Additional information regarding the purposes, lawful bases, retention arrangements, publication of images and the exercise of privacy rights is available in the IOB Photography, Filming and Audio Recording Privacy Notice.

If you fail to provide personal data

If you fail to provide certain data when requested, we may not be able to perform the contract we have entered into with you (such as paying you or providing a service to you) or we may be prevented from complying with our legal obligations.

Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.


How do we use special categories of personal data?

“Special categories of personal data” require higher levels of protection. We have in place appropriate safeguards which we are required by law to maintain when processing such data. We may process your special categories of personal data, in limited circumstances, with your explicit written consent. Within this notice, these data types are classified as Category M - Special Category Personal Data

Less commonly, we may process this type of data where it is needed in relation to legal claims or where it is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent, or where you have already made the information public.

The situations in which we will use your special categories of personal data in are as follows:

  • We will consider your physical or mental health information, or disability status, to determine eligibility of students for special assistance requirements for assessments or the postponement of programmes (Leave of Absence applications “LOA”) or deferral of assessments/programme modules (Extenuating Circumstances applications “IX”).

  • We will consider your physical or mental health information to determine eligibility of members, students, designates for fee waivers.

  • We will consider your physical or health information to assess the eligibility of designates for reduced CPD requirements (Pro-rata applications).

  • We may consider health, disability, medical, welfare or other special category information where you provide it in connection with an appeal, complaint, academic integrity process, disciplinary matter, extenuating circumstances request, special considerations request, fee waiver, pro-rata CPD application or other support request.

  • We will consider information about your health for the purpose of determining food and beverages that should be served at our events, provide you with information about accessibility to our events and/or your attendance needs at our events as well as to facilitate same.

Supporting medical evidence submitted in connection with any of these processes will only be accessible to authorised personnel with a legitimate need to know and will be retained only for as long as necessary to assess and administer the application, after which it will be securely deleted in accordance with IOB's Records Retention Schedule.

Additional information regarding the processing of special category personal data in specific contexts may be provided in supplementary privacy notices.

Do we need your consent?

We do not need your consent if we use special categories of your personal data in accordance with the provisions set out under law. However, in certain circumstances, we may approach you for your written consent to allow us to process certain particularly sensitive data. If we do so, we will provide you with full details of the information that we require and the reason we need it, so that you can carefully consider whether you wish to consent. You should be aware that it is not a condition of your contract with us that you agree to any request for consent from us.


Data about criminal convictions

We will collect information about criminal convictions where we are notified of this directly by you or we are notified of this by third parties. We will only use your personal data when the law permits us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to comply with a legal obligation.

  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.

We will use information about criminal convictions and offences in the following ways:

  • With your explicit written consent

  • Where it is necessary to perform a contract with you or to take steps at your request prior to entering into a contract with you

  • Where it is needed to obtain legal advice or for the purposes of or in connection with legal claims or legal proceedings (including prospective claims or proceedings)

We have in place appropriate safeguards which we are required by law to maintain when processing information about criminal convictions.


Automated decision-making

Examinations are marked by human markers who access exam scripts and mark the questions according to the marking standard specified by IOB. The online invigilation system will flag activities that could indicate suspected non-conformance with Examination Regulations. However, no automated decisions will be made based on these flags.

IOB uses Multiple Choice Questions (MCQs) for some assessments. These questions are marked using automated software against an answer key which is developed by the Examiner. The evaluation methods are regularly reviewed and tested to ensure they remain fair, effective and unbiased. As part of our Quality Assurance (QA), the questions are reviewed by an external examiner for accuracy and fairness. You may ask us not to make decisions about you that are based solely on automated processing.

We do not envisage that any decisions will be taken about you using automated means. However, we will notify you in writing if this position changes.


Data Sharing

Why might IOB share your personal data with third parties?

We will share your personal data with third parties where required by law, where it is necessary to administer the working relationship with you or where we have another legitimate interest in doing so.

Which third-party service providers process my personal data?

“Third parties” includes third-party service providers (including contractors and designated agents). The following activities are carried out by third-party service providers: payroll and administration, hosting CRM systems, customer support and case management platforms, credit card and payment providers, providers of online registration and direct debit forms, media monitoring, printers, IT service and support providers, online assessment/exam and online invigilation, webcasting and video hosting providers, educational technology providers and cloud service providers.

Examples of service providers used by IOB include:

  • Learning Management System providers

  • Video learning and lecture recording platforms

  • Online examination and invigilation providers

  • Customer relationship management platforms

  • Customer support and case management systems

  • Cloud hosting providers

  • Web conferencing platforms

  • Finance and payment service providers

  • Communications and marketing platforms

How secure is my data with third-party service providers?

All our third-party service providers are required to take appropriate security measures to protect your personal data in line with our policies. We do not allow our third-party service providers to use your personal data for their own purposes. We only permit them to process your personal data for specified purposes and in accordance with our instructions.

When will you share my data with third parties?

We may share your personal data with:

  • affiliate associations with whom IOB operate joint qualification schemes in order to support and administer such schemes or with whom IOB co-host events and seminars (such as the Chartered Accounts Ireland, Chartered Institute of Management Accountants, the Association of Chartered Certified Accountants, the Society of Trust and Estate Practitioners Ireland, the Institute of Management Consultants and Advisers and LIA)

  • your employer, sponsor or membership body, where they pay or administer your membership, programme, examination, CPD scheme or designation fees, or where this is otherwise necessary to administer the relevant arrangement. This may include sharing registration status, attendance, assessment participation, assessment results, awards, CPD/designation status, engagement with IOB programmes, use of learning resources, viewing of online lectures or recorded learning content, and compliance with applicable programme, examination or CPD requirements. Such information may be shared with nominated HR, learning and development, regulatory, compliance or corporate portal contacts, where appropriate.

  • Such information may also be shared for the purposes of confirming qualification status, programme participation, designation status, CPD compliance or other matters where the employer, sponsor, educational partner or professional standards body has a legitimate interest in receiving the information and sharing is permitted by law.

  • third parties involved in hosting or organising an event such as hotels where you book beverages, food and/or accommodation for an event or conference through IOB, catering companies, hospitality staff at event location.

  • other event attendees/delegates by way of an attendee/delegate list, seating plan or conferring booklets.

  • personal data relating to suppliers may be shared with banks, payment service providers, auditors, legal advisers, taxation authorities and other professional advisers where necessary.

  • our professional and legal advisors and other third parties in order to investigate complaints and disciplinary matters or to establish, exercise or defend our legal rights.

  • Internal and external auditors

  • third party companies that distribute our publications on our behalf.

In the case of students, we may also share certain personal data with your mentors, subject to obtaining your prior consent. We may also share your personal data with lecturers for the purposes of their confirming your attendance at our courses.

Where an individual participates in a professional designation, certification scheme or CPD programme administered jointly with another professional body, accreditation organisation or educational partner, IOB may share personal data relating to registration, designation status, qualification status, CPD compliance, assessment results, regulatory requirements, membership status and related administrative matters with that organisation where necessary to administer the relevant arrangement.

We may also need to share your personal data with a regulator, law enforcement authorities or to otherwise comply with the law.

Professional Bodies, Accreditation Organisations and Joint Controllers

IOB may share personal data with professional bodies, accreditation organisations, designation providers, educational partners and joint-controller organisations where necessary to administer qualifications, professional designations, CPD schemes, examinations, accreditations, regulatory obligations and associated governance activities.

Transferring Data outside the EEA (European Economic Area)

We may transfer your personal data outside the EEA. This may occur where we use service providers, educational technology providers, cloud platforms, professional advisers, educational partners, employers, sponsors, faculty members, corporate partners or other recipients located outside the EEA.

IOB delivers educational, membership, designation and professional development services both within and outside the EEA. In doing so, personal data may be shared with employers, sponsors, educational partners, learners, faculty members and service providers located outside the EEA.

These countries may include jurisdictions in the Middle East and Asia-Pacific regions where IOB delivers programmes or maintains educational, professional or employer relationships, including (from time to time) the United Arab Emirates, Qatar, Singapore, India and the Philippines.

If we do, we will only transfer your personal data outside the EEA if one of the following conditions applies:

  1. The EU has issued regulations confirming that the country to which we transfer the personal data ensures an adequate level of protection for your rights and freedoms; or

  2. Appropriate safeguards are in place such as binding corporate rules, standard contractual clauses, an approved code of conduct or a certification mechanism, a copy of which can be obtained from us; or

  3. You have provided explicit consent to the proposed transfer after being informed of any potential risks; or

  4. The transfer is necessary for one of the other reasons set out in the GDPR including the performance of a contract between us and you, for reasons of public interest, to establish, exercise or defend legal claims or to protect your vital interests where you are physically or legally incapable of giving consent and, in some limited cases, for our legitimate interest.

Should this arise, we will update this Notice and/or notify you.


Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.


Data Retention

How long will we keep your personal data?

IOB retains personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, educational, accounting, audit, quality assurance and reporting requirements. Different categories of personal data are retained for different periods depending on the nature of the relationship with IOB and the purpose for which the data is processed.

As a provider of professional education, membership, examinations, designations and continuing professional development services, IOB may retain certain educational, assessment and qualification records for extended periods where necessary to:

  • verify qualifications, awards, examination outcomes and academic standing;

  • maintain the integrity of professional education records;

  • respond to regulatory, accreditation and quality assurance requirements; and

  • protect the interests of members, learners, employers and educational partners.

In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case we may use such data without further notice to you.

Typical Retention
Record Category Typical Retention Approach
Membership and learner administration records Duration of membership/student relationship plus an appropriate post-membership retention period.
Programme participation and learning records Retained for as long as necessary to administer programmes, support learners and demonstrate educational compliance.
Assessment, examination, qualification and award records May be retained long-term or permanently where necessary to evidence academic achievement, professional qualifications and historical educational records.
CPD, designation and certification records Retained for the duration of the designation relationship and for an appropriate period thereafter to support verification and regulatory requirements.
Pro-Rata CPD applications and supporting evidence Administrative records relating to Pro-Rata CPD decisions may be retained for evidential, audit and compliance purposes in accordance with IOB's Records Retention Schedule. Supporting medical evidence will be retained only for as long as necessary to assess and administer the application and will thereafter be securely deleted.
Financial and transaction records Retained in accordance with legal, accounting and taxation obligations.
Complaint, investigation and disciplinary records Retained in accordance with legal, regulatory and risk-management requirements.
Recruitment records Retained for an appropriate period following completion of the recruitment process unless a longer period is required by law or with the individual's consent.
CCTV and visitor management records Normally retained for a limited period unless required for security investigations, legal proceedings or incident management.
Marketing preferences and communication records Retained until no longer required for the relevant purpose or until consent is withdrawn, where consent is the lawful basis.
Data protection rights requests, complaints, breach and incident records. Retained for an appropriate period to manage the request, complaint or incident and to demonstrate compliance with legal and regulatory obligations.
IT, access, security and system logs. Retained for a limited period appropriate to the security, audit, investigation or operational purpose, unless required for a longer period in connection with an incident, investigation or legal obligation.
Supplier and procurement records Duration of relationship plus 7 years, unless legal or regulatory obligations require longer retention.
Review and deletion

When personal data is no longer required, IOB will securely delete, anonymise or otherwise dispose of the data in accordance with its Records Retention Schedule, Records Management Policy and information security requirements.

Your duty to inform us of changes

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your working relationship with us.

Your personal information rights

When your personal information is handled by IOB in relation to a product or service, you are entitled to rely on a number of rights. These rights allow you to exercise control over the way in which your personal information is processed, subject to applicable exemptions.

For example, we may help you in:

Accessing your personal information: You can ask us for a copy of the personal information we hold about you.

Correcting and Updating your personal information: If you believe that any personal information we hold about you is inaccurate or out of date, you can look for the information to be corrected at any time.

Withdrawing consent: You can change your mind wherever you give us your consent, such as for direct marketing, or using your sensitive information, such as medical or biometric data.

Restricting our use of your personal information: You have the right to restrict our use of your personal information in certain circumstances, such as where our use of it is not compliant with applicable law.

Objecting to our use of your personal information: You have the right to object to us using your personal information, where we are doing so based on this being necessary for the performance of a task carried out in the public interest or for the purposes of a legitimate interest. Where you exercise this right to object, we will be obliged to stop using your personal information in that way, unless there are compelling legitimate grounds for us to continue to do so, despite your objection.

Not to be subject to automated decision making: You have a right (subject to limited exceptions) not to be subject to a decision based solely on automated processing of information, including profiling, which produced significant legal effects concerning you or otherwise significantly affects you.

Deleting your information (your right to be forgotten): You may ask us to delete your personal information.

Moving your information in electronic form (your right to Portability): You may request (in certain cases) that your personal information is transferred to you or another organisation in digital form.


How to Exercise your rights?

You may execute any of these rights by contacting us:

Phone: + 353 1 6116500

Email: [email protected]

When you exercise your data protection rights, make a complaint, or contact us about a data protection matter, we may ask you to identify yourself. This is to help protect your information. We will process the personal data you provide, together with relevant information we hold about you, for the purpose of assessing, managing, responding to and documenting your request, complaint or enquiry.

Once we are satisfied that we have effectively verified your identity, we will respond to the majority of requests without undue delay and within a one month period (i.e. 30 calendar days) of receipt of the request. IOB will action your request to have your personal information corrected within 10 calendar days. These periods may be extended in exceptional circumstances and we will inform you where the extended period applies to you along with an explanation of the reasons for the extension.

No fee usually required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

Right to withdraw consent

In circumstances where you may have provided your consent to the collection, processing and transfer of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact [email protected]. Once we have received notification that you have withdrawn your consent, we will no longer process your data for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law.

Data Protection Policy

IOB, as a provider of Professional Education, CPD (Continuing Professional Development) and Membership Services to the financial services sector in Ireland and beyond, processes personal data for a variety of purposes relating to its members, employees, service providers and other third-parties involved with the organisation. IOB is therefore a data controller, and in some cases a data processor, and is subject to data protection legislation and regulation. IOB's Data Protection policy (available here) sets out data protection requirements which must be complied with by anyone who processes personal data for or on behalf of IOB.

Data Protection Officer

IOB’s Data Protection Officer oversees how we collect, use, share and protect your information to ensure your rights are fulfilled. You may contact our Data Protection Officer at [email protected] or by writing to: Data Protection Officer, IOB, 47-49 Pearse Street, Dublin 2

Making a complaint

If you have a complaint about the use of your personal information, please let a member of staff know, giving them the opportunity to correct things as quickly as possible. If you wish to make a complaint you may do so in writing and by email [email protected]. Please be assured that all complaints received will be fully investigated. We ask that you supply as much information as possible to help our staff resolve your complaint quickly.

You may also contact the Data Protection Commission in Ireland to lodge a complaint (details below).

Data Protection Commission,6 Pembroke Row, Dublin 2, D02 X963, Ireland Web: dataprotection.ie


Updates to this notice and policy

We keep this notice and policy under regular review and will make changes from time-to-time, particularly when we change how we use your information, and change our technology and products or services. We will inform you of material changes to the contents of this Data Protection Notice, through a notification posted on our website or through other communication channels.

Before you continue...

As you are not registered with us, you will need to upload proof you can enrol to this programme.

I know, let’s sign upI have an account, let me sign in first
  • Duration
  • 3 to 4 years
  • Programme
  • 24 modules
  • Study
  • Part-time, online
  • Fees
  • From €470 per module
  • Level
  • NFQ 8, 180 ECTS
  • At a glance

    The Bachelor of Financial Services (BFS) Degree programme addresses the educational needs of those who wish to develop management and senior management careers in financial services. The BFS provides those who work in banking with an ideal opportunity to acquire a level 8 university degree, which is recognised and supported by the financial services industry.

    Awarding Body

    University College Dublin

    While providing a broad business foundation, this programme also examines contemporary issues of importance to the financial services industry. A key feature of this programme is that it merges academic knowledge with relevant professional skills and has been developed by both industry and academic subject leaders.

    Who is this programme for?

    The BFS is designed with those working full-time in mind, and is flexible so that candidates can continue to pursue their career goals while studying.


    How will you benefit

    Upon successful completion of the BFS degree graduates are expected to be able to;

    • Broaden and deepen their technical understanding of the main activities in banking and associated risks

    • Develop a highly marketable and transferable skill set, including decision-making, problem-solving, communication and analytic skills

    • Enhance your critical awareness and understanding of the contemporary issues in financial services

    • Apply concepts and techniques to evaluate complex business problems to aid decision-making

    • Develop and critically evaluate strategy and the sustainability of business models in banking and financial services

    • Integrate learning into professional practice to take responsibility for personal and professional development.


    Continuous Professional Development

    If you hold an IOB designation or a designation managed by IOB, CPD hours may be awarded on successful completion of this programme.


    For prospective students:

    If you are considering this programme, please note that this programme is being discontinued and all modules must be completed by September 2029.

    If this is not feasible, we would be happy to discuss alternative options that may meet your learning or development needs. These may include other relevant IOB offerings.

    If you have any questions, or if you would like to discuss your options, please contact the programme manager, Susan Freeney at [email protected] and she will be happy to help.


    Delivery

    Online.


    Assessment

    Combination of continuous assessment and written exams.

    IOB programmes are largely delivered and assessed online. Students should ensure they have appropriate equipment (laptop), and that appropriate software (including MSOffice: Office and Word) is available to them to participate in the programme and related assessments (continuous assessments and exams).


    BFS Pathway

    To view the BFS Pathway in detail CLICK HERE

    The BFS has three stages. Students must complete 60 ECTS (academic credits) at each stage to achieve the award of Bachelor of Financial Services. Students must complete each stage before progressing onto the next stage.

    * To be eligible to enrol to the BFS programme at Stage 2, you need to have completed 60 credits at NFQ level 7.


    Award

    When you successfully complete this programme, you will be awarded Bachelor of Financial Services from UCD.

    This is a major award and a level 8 qualification on the National Framework of Qualifications.


    Progression

    The Professional Education Framework is a flexible education pathway that provides learning and development opportunities wherever you are in your career. You can access the framework at any step to take specialist qualifications depending on your career and learning need. View the full Professional Education Framework -->


    *Core textbooks are not included in your registration fee and must be purchased separately. The Programme Manager will provide details of the required core textbooks before each module commences.


    Next intake

    • Autumn Trimester - (September 2026 - January 2027)

    Trimester start date

    • 28 September 2026

    When will IOB trimesters take place?


    Closing dates

    • Application closing date - 18 September 2026

    • Registration closing date - 30 September 2026

    What is the difference between the application and registration closing date?


    Contact

    For more information please contact the Programme Manager, Susan Freeney at [email protected]


    Modules and learning outcomes


    Stage 1: Complete 6 core modules below, plus 6 of the optional modules below (totalling 60 ECTS credits at NFQ level 7).

    Core:

    QFA Regulation

    (NFQ Level 7, 5 ECTS)

    Identify the different forms of Regulation relating to financial service providers.

    Identify the main regulatory bodies in Ireland and their functions.

    Discuss the range of regulatory rules that apply to intermediaries and/or product providers in their dealings with clients.

    Describe the impact of legislation relating to consumer protection, money laundering, distance marketing, data protection & privacy, Investor compensation, unfair terms in consumer contracts and tax evasion.

    Explain the functions and powers of the Financial Services Ombudsman and the Pension Ombudsman.

    Specific areas covered:

    Why financial service providers are regulated

    Authorisation

    Minimum Competency Code

    Consumer Protection Code

    MiFID

    Data protection

    Anti-money laundering.

    QFA Loans

    (NFQ Level 7, 5 ECTS)

    Describe the personal financial need for a loan, and the different ways in which such a need can be met by different types of loans and consumer credit on offer.

    Explain the features, benefits, limitations, security requirements and taxation treatment of consumer loans and credit arrangements, and their associated insurances.

    Discuss and demonstrate the impact of regulation on the provision of housing loans and different forms of consumer credit.

    Detail the steps and documentation involved in obtaining a housing loan and evaluate and recommend an appropriate housing loan option from those on offer.

    Identify the issues and processes involved in debt restructuring and equity release and describe the process and protocols to be adopted for the recovery of loan arrears.

    Specific areas covered:

    Types of housing loans

    Central bank requirements

    Regulation

    Loan application

    Housing loan insurances

    Arrears

    Consumer credit.

    QFA Investment

    (NFQ Level 7, 5 ECTS)

    Discuss the operation of the financial services markets and the impact of government economic and monetary policy on Investments.

    Describe the features, benefits, limitations and risks associated with the different classes of investment assets available within the industry.

    Identify and discuss the basic investment principles.

    Demonstrate the knowledge and understanding of investments required to effectively advise clients.

    Specific areas covered:

    Markets

    Asset classes

    Shares

    Bonds

    Deposits

    Collective investment schemes

    Unit-linked savings

    Regulation.

    QFA Pensions

    (NFQ Level 7, 5 ECTS)

    Explain the need for retirement provision.

    Describe the taxation, legislation and regulatory framework for pensions.

    Identify the features, benefits and risks of pension product options available to clients.

    Display the skills and competencies required to effectively advise clients in all areas of Pensions.

    Specific areas covered:

    State pensions

    Personal pension plans

    Employer pension schemes

    AVCs

    ARFs

    Annuities

    Quantifying pension needs

    Investment

    Regulatory bodies.

    QFA Life Assurance

    (NFQ Level 7, 5 ECTS)

    Describe the main life assurance needs of the consumer at all life stages.

    Explain the main features, benefits, limitations, and risks of different types of life protection policies.

    Detail the issues involved in starting a policy and in paying out benefits.

    Identify the constituents in a valid will and know the impact of the Succession Act.

    Discuss financial mathematics principles that underpin personal life assurance and pension products and perform related calculations.

    Specific areas covered:

    Why protection is needed

    Term assurances

    Income protection

    Serious illness

    Business insurances

    Estate planning

    Unit-linked savings and bonds

    Quantifying protection needs

    Regulation.

    QFA Financial Planning

    (NFQ Level 7, 5 ECTS)

    Analyse and appraise a clients’ financial needs and attitude to risk.

    Critically evaluate different financial products offerings and assess their relevance in structuring a financial portfolio that fulfils your clients’ needs.

    Make an investment recommendation for a client on the basis of having assessed their needs, attitude to risk and match these against product offerings.

    Prepare a detailed client financial review with regard to their life stage, personal circumstances, needs and attitude to risk.

    Specific areas covered:

    Providing advice to consumers

    Consumer reviews

    Suitability statements

    Recap on retail financial products

    Taxation issues.

    Optional: (All 5 ECTS)

    Stock Exchange Regulatory Environment

    (NFQ level 7, 5 ECTS)

    • Outline the rules of Euronext Dublin (formerly Irish Stock Exchange).

    • Describe the main pieces of legislation that constitute the regulatory environment in which a stock broking firm operates in, e.g. Market Abuse. Prospectus Regulations, MiFID, Company Law, CSRD etc.

    • Explain the role and functions of statutory bodies and persons in the regulatory environment, e.g. Central Bank of Ireland, ODCE etc.

    • Describe the characteristics of the trading, settlement and clearing arrangements of Euronext Dublin.

    Stock Exchange Securities and Markets

    (NFQ level 7, 5 ECTS)

    Describe the features and characteristics of various instruments traded on exchanges, e.g. equities, bonds, money market and derivative instruments.

    Explain the issuance process, settlement process and trade reporting requirements employed for the main categories of instruments traded on an exchange.

    Outline the process to assess a client’s needs from both a private client and institutional client perspective including any sustainable finance considerations.

    Describe the operation and compute simple calculations for the following taxation regimes in Ireland; Income Tax, Capital Gains Tax, Capital Acquisition Tax and Corporation Tax.

    PDC 1 - Compliance and the Regulatory Structure

    (NFQ Level 7, 5 ECTS)

    Compliance is an established function in financial services and is recognised by regulators as an essential part of the control infrastructure. This module introduces the financial services industry and describes how it is regulated both in Ireland and internationally. To do this it looks at the concepts behind the theory of regulation and the role of the Central Bank of Ireland. It examines the role of the Compliance function in financial services organisations while also considering the ethical and fiduciary relationships involved.

    PDC 2 - Conduct of Business Rules

    (NFQ Level 7, 5 ECTS)

    This module considers the significant increase in the complexity and volume of the regulation underpinning compliance procedures. It considers conduct risk and the role of Compliance professionals in implementing conduct of business rules in financial service organisations. It also explores the regulations implemented to address consumer protection, data protection, distance marketing, financial crime and insurance mediation and their impact on financial services organisations. In essence it is designed to assist students in developing a best practice approach to their conduct and business.

    PDC 3 Legal & Regulatory Aspects of Compliance

    (NFQ level 7, 5 ECTS)

    Assess the authorisation, supervision and prudential requirements for various financial entities Describe the legal environment which applies to financial services and outline the key principles of Company, Contract, Competition and Securities Law. Explain the nature of fiduciary relationships, and evaluate their significance in a regulatory environment

    PDC 4 Compliance Management

    (NFQ level 7, 5 ECTS)

    Appraise the concepts behind compliance practice, planning and monitoring and evaluate the broadening role of compliance and the compliance officer.

    Analyse the importance of compliance reporting and devise a regulatory relations policy in relation to inspections, themed visits and routine relations.

    Critically evaluate the importance of Ethics and Reputation in the compliance function.

    Assess the system of controls, assurance and governance in an organisation and analyse the relationship between these and compliance.

    Digital Risk Management

    Over the course of the module you’ll learn how to identify risk, how to apply risk  frameworks and how to mitigate digital risk. This practical module will be immediately relevant to your role as you develop a deeper understanding of trends in RiskTech, RegTech and emerging threats through analysis of real-world case studies.  The topics include:

    • Introduction to Digital Risk Management and scope and types of digital risk

    • Cyber Risk

    • Risk FrameworksM

    • Managing Digital Risk

    • RegTech

    • The Regulatory Environment

    • Operational Resilience

    Consumer Protection and Trust in Financial Services

    (NFQ level 7, 5 ECTS)

    Consumer Protection Risk Assessment and Conduct Risk

    Consumer Protection Risk Management Frameworks (CPRMF). Conduct risk and conduct risk standards. Selling financial products appropriately - including outcomes. Understanding of customer experience. Drivers and causes of conduct risk. Constituents of conduct risk including behavioural economics. Relationship with the overall banking risk framework. Conduct risk appetite statements. Conduct risk policies and common metrics. Conduct risk impacts on customers, on employees, the financial institution and on markets.

    Culture and Behaviour

    Understanding the importance of culture in ensuring good customer outcomes. Indicators of an effective risk culture. Regulator expectations and reports. Roadmap for achieving desired culture. Governance arrangements around the design, monitoring, and analysis of culture MI. How culture can be assessed in organisations/culture audits. Understanding the role of group dynamics. Diversity, inclusion and its impact on decision making. Understanding the impact of biases when making compliance decisions. Understanding and embedding ‘Consumer Focus’ behaviour. Understanding the role of mind-set and sense-making on behaviours and how this is being applied in supervision of culture and behaviours. CPRA and Behavioural Economics.

    Ethics

    Foundational concepts of ethics, values and integrity. What it means to be ethical in financial services and how the right ethical climate supports good decision-making. What obligations does the financial services industry have to customers? What is the right thing to do?. What happens when things go wrong. How to effectively challenge and escalate.

    Digital Financial Services

    (NFQ Level 7, 5 ECTS)

    Outline the development and breadth of digital financial services and their role in supporting sustainable development

    Use recent examples to critically examine the rapid pace of developments in digital financial services provided to the marketplace

    Appraise colleagues and senior management on key issues and challenges within digital financial services

    Monitor and critically discuss trends and new developments in digital financial services to include the use of AI and the protections required for customers and other stakeholders

    Reflect on their role and professional practice in promoting ethical values and supporting diversity, equity and inclusion in digital financial services

    Apply the research and reflective skills practised in this module to identify and independently pursue personal and professional life-long learning development opportunities.

    Introduction to Data Analytics for Financial Services

    (NFQ Level 7, 5 ECTS)

    Explain how Data Analysis and Business Intelligence are being used to modernize and drive value in financial services

    Explain the conceptual foundations of Business Intelligence and describe the project frameworks for successful delivery

    Explain how data is managed, governed and controlled at enterprise scale and how a data analyst carries out data management Apply the fundamental techniques and tools for data analysis Apply the practical skills to develop Business Intelligence report and explain how BI solutions scale to enterprise level

    Applied Data Analytics

    (NFQ Level 7, 5 ECTS)

    Outline how Advanced Analytics is being used to modernize and drive value in financial services. Explain how basic descriptive statistics bring extra rigour and depth to data analysis.

    Draw conclusions from data using the basic techniques of inferential statistics. Use the powerful business technique of A/B testing to determine best outcomes. Explain how predictive modelling techniques are applied to solving real world problems Outline the wider set of analytical tools and how to choose the appropriate tool to solve your business problem.


    Stage 2: Complete the 6 core modules outlined below. (Each module is 10 ECTS credits)

    Principles and Practices of Credit Risk Management

    (NFQ Level 8, 10 ECTS)

    Key categories of risks to which banks are exposed with focus on credit risk.

    Basel principles for the management of credit risk.

    Bank risk appetite frameworks.

    Components of the credit risk management framework.

    Credit portfolio management and credit concentration risk.

    Credit risk appetite statements.

    Credit culture.

    The end to end credit process.

    Overview of the canons of lending.

    Credit application process.

    Bank capital.

    Risk weighted assets.

    Basel II & Basel III, Basel IV.

    Minimum Regulatory Requirements.

    Introduction to credit models.

    Impairment provisioning.

    Stress testing.

    Impairments and capital.

    Pricing for risk.

    Key Lessons from Irish banking crises, Honohan Report, Regling & Watson, Nyberg.

    Customer Experience Management

    (NFQ Level 8, 10 ECTS)

    On completion of this module, students will be expected to be able to: Explain what is meant by CEM. Explain the key stages in the CRM process. Demonstrate an understanding of the customer relationship cycle and the implications for financial institutions. Demonstrate an understanding of what customers value in their relationship with their financial institution. Discuss the ethical conduct underpinning interactions with customers. Assess the implications of regulation on CEM practices.

    Business Economics

    This module provides students with a framework that can be used to analyse contemporary business economic issues. As a standalone economics module, the focus is on developing awareness of economic issues and their linkages to financial markets. On completion of this module, students will have:

    • Analyse a country’s macroeconomic performance using a wide range of macroeconomic data and statistics

    • Evaluate current fiscal and monetary policies in Ireland and major international trading partners elsewhere

    • Demonstrate the application of key concepts in both microeconomics and macroeconomics

    • Analyse why different market structures create differing levels of competition and business performance

    • Evaluate how businesses can leverage profitable opportunities to gain greater control over its markets and strategic rivals

    Finance and Investment Decisions

    On successful completion of this module candidates should be able to:

    • Apply Financial statement analysis and financial ratios, and their use in analysing the performance and well being of a company.

    • Value a bond and other financial assets. 

    • Apply the use of investment appraisal methods in different business decisions, including expanding the business, and international investment. 

    • Understand how derivatives including forwards, futures, and options are used for investment purposes.

    • Critically understand how the risk and return of assets and how portfolios and asset pricing models such as the CAPM can aid investments.

    • Be knowledgeable on the details for difference sources of long term and short-term financing that a firm can use. 

    • Understand whether markets are efficient and implications for market users.

    Business Management

    This module aims are to provide you with insights on management theory, thinking and practice to support the application of the knowledge and tools to manage a business or function more effectively. On successful completion of this module candidates should be able to:

    • Apply tools for analysing the business environment and assess strategic alternatives

    • Assess and recommend management approaches for effective business management.

    Operational Risk Management & Operational Resilience Practices

    (NFQ Level 8, 10 ECTS)

    Operational risk defined. The importance of operational risk and the Probability Risk and Impact SysteM (PRISM). The differences between operational risk and other types of risk. Recent failures in operational risk. Operational risk basics. Three lines of defence. Operational risk taxonomies. Operational risk management frameworks. Risk capacity. Risk appetite statements. Risk policies. Risk pricing and capital. Risk information, Key Risk Indicators (KRIs) reporting and KRI framework. Risk assessment. Risk management and action plans. Risk modelling. Insurance mitigation.

    The practical workshop areas will include inter alia: Financial crime prevention. Anti–Money Laundering/Countering of Financing of Terrorism. Know Your Customer, Irish and UK. Anti- Corruption laws. External and internal fraud. Information security, IT resilience, cybercrime. Outsourcing. Business continuity planning. Data quality and other practical areas.


    Stage 3: Complete the 6 core modules outlined below. (Each module is 10 ECTS credits)

    Principles and Practice of Banking

    (NFQ Level 8, 10 ECTS)

    On completion of this module, students will be expected to be able to: 

    • Apply their understanding of theories and core principles underpinning banking in a real-world context

    • Identify the range of risk banks are exposed to and be able to evaluate and implement risk-mitigation strategies

    • Critically evaluate the transmission of banking risks and the wider societal implications

    • Critically reflect upon their professional practice and their role and contribution within the banking profession.

    SME Credit Risk Assessment

    (NFQ Level 8, 10 ECTS)

    On completion of this module, students will be expected to be able to: Describe and explain the main features, characteristics of SMEs and various legal trading entities available to SMEs in Ireland and the features of the main sectors in which SMEs operate. Describe and discuss the features and characteristics of the main types of security for SME lending. Use a framework for SME credit analysis (adhering to the canons of lending to undertake a complete credit assessment of an SME credit proposal, including detailed financial analysis of financial accounts including sensitivity analysis, repayment capacity, security analysis, and an analysis of the business’ competitive position, its management and its core competences to form a judgement of whether to approve, defer or decline the request. Prepare and interpret Cash Flow Statements. Explain working capital management and its importance to an enterprise’s profitability and liquidity. Communicate clearly to pertinent stakeholders (internal and external) the bank’s credit policy and requirements for SME’s.

    Intelligent Digital Financial Services Transformation Essentials

    (NFQ Level 8, 10 ECTS)

    On successful completion of this module you should be able to:

    Demonstrate an appreciation of the ways in which digital product management drives digital transformation in financial services

    Appreciate the roles and responsibilities of digital product managers and their teams

    Understand the importance of digital products and services in financial services competitiveness, strategy and risk

    Understand key trends associated with the ways that data and intelligence drive financial services Product and Service Development

    Critically reflect upon your own professional role and contribution to financial organisations in the context of the application of digital technologies and systems.

    SME Financing and Distressed Credit Analysis

    (NFQ Level 8, 10 ECTS)

    • Traditional banking facilities for SME borrowers

    • Alternative sources of finance for SMEs

    • Start-up business lending

    • Agricultural lending

    • Property lending

    • Conducting the borrower loan interview

    • Writing the credit application

    • Negotiating final terms and conditions

    • Legal documentation and drawdown

    • Procedures for deciding on impairment provisions

    • Monitoring and control framework

    • Identifying and reviewing a potentially distressed customer

    • Negotiating with customers in difficulty

    • Managing arrears and restructuring

    • Cancelling facilities, collections and recoveries

    • Loan restructuring options

    • Importance of the facility letter in impairment cases

    • Legal remedies for recovery.

    Compliance for sustainable finance: building the foundation

    (NFQ Level 8, 10 ECTS)

    At the end of this module, you will understand:

    • What is sustainability and what does it mean for the economy, business and the financial sector;

    • ESG origins and evolution - you will gain knowledge of macro level sustainability issues for the economy, business and the financial sector. Examine the relevance of corporate purpose and how compliance, culture and ethics can align to support the sustainability strategy within a financial services organisation;

    • Sustainable Finance - what and why? The evolution of sustainable finance and ESG. Review the key stakeholder groups driving the sustainable finance agenda globally, why they are doing so and what specifically they are doing;

    • Climate change and climate-related financial risk and opportunity;

    • Promoting a culture of compliance; are individual accountability regimes and controlled functions aligned with supporting the sustainability strategy in financial services?;

    • Ethics, compliance and corporate culture in financial services;

    • Corporate purpose (in the context of financial services firms) and corporate sustainability strategy;

    • Primer on financial services regulatory and supervisory landscape (Ireland, EU, UK & US also international influences e.g. IOSCO, FSB, NGFS);

    • Sustainable Finance in action across financial sectors (i.e. what does ESG mean at the level of a bank, an asset manager, insurance firm, an investment fund, pension etc).

    Professional designation

    Members who complete the relevant modules, and who commit to completing Continuing Professional Development hours, will be entitled to use the designation Professional Banker.

    UPCOMING INTAKES


    Autumn Trimester (September - January)

    Trimester start date - 28 September 2026

    Application closing date - 18 September 2026 (Application Date | IOB Help Centre)

    Registration closing date - 30 September 2026 (Registration Date | IOB Help Centre )


    Spring Trimester (January - May)

    Trimester start date - 2 February 2027

    Application closing date - 22 January 2027 (Application Date | IOB Help Centre)

    Registration closing date - 3 February 2027 (Registration Date | IOB Help Centre )


    Summer Trimester (June - September)

    Trimester start date - 31 May 2027

    Application closing date - 14 May 2027 (Application Date | IOB Help Centre)

    Registration closing date - 2 June 2027 (Registration Date | IOB Help Centre )


    Key Dates Poster

    Level 7 and 8 key dates 2026/2027


    Entry Requirements

    The minimum entry requirements to Stage 1 are as follows:

    • Five passes in the Leaving Certificate, including English and Mathematics

    • Five O Level or GCSE passes, including English Language and Mathematics

    • IOB will also consider applications to Stage 1 on a mature candidate basis from applicants who are 23 years of age before the date of their application for admission to the programme.

    Progression to Stage 2 requires that students have:

    • Completed Stage 1

    or

    • Completed the University Diploma in Financial Services

    or

    • Completed the Joint Financial Services Diploma (subject to matriculation, which involves an NUI fee of €150)

    or

    • Applicants with an ordinary degree in business (or equivalent) will be considered for direct entry to Stage 2.


    Professional Body Membership

    You must be a current member of IOB, or become a member, to undertake this programme, (membership year - January to December).

    For more information on the membership fee and the benefits of being an IOB member, please click here.


    Please note, the Professional Banker designation is a fundamental acquirement for those seeking to develop and advance a career in banking, including management roles.


    English Language Requirements

    Teaching in IOB is through the medium of English; therefore, applicants must demonstrate a high level of competence in the English language to be admitted to study. Students whose native language is not English are required to demonstrate their proficiency in the language and must provide verifiable evidence of that proficiency. Further information on these requirements is provided in the IOB English Language Policy

    Your lifelong learning partner

    Join the IOB Community

    Begin your journey with IOB today and unlock exclusive member content, events and insights!

    Join IOB