Case study
48 Credentials, Ten Months On: A CFA Society Nigeria Case Study
What happened to 48 credentials after they were issued: 505 recorded events across eight months of tracking, two thirds of them on mobile, most of the traffic arriving from LinkedIn, and the numbers that were less flattering than we expected.
Last updated · 9 min read · Published with CFA Society Nigeria's permission
What was issued
On 25 October 2025, CFA Society Nigeria issued 48 credentials across three awards: the CFA Ethics Challenge, and winner and finalist badges for the Industry Practitioners' Ethics Challenge. Every recipient received a PDF, a high-resolution image, and a permanent verification page carrying a digital signature.
Then the interesting part, which is the part almost nobody measures. Everyone in this industry can tell you how many certificates they sent. Very few can tell you what happened next. Because these credentials live at their own addresses rather than as attachments in an inbox, we can.
This is one issuer and one cohort. Read the limits section before quoting anything here.
What 48 credentials did
Between 9 December 2025, when tracking began, and 17 August 2026, when this data was pulled:
| Measure | Value | Note |
|---|---|---|
| Credentials issued | 48 | three awards, one day |
| Recorded events | 505 | 9 Dec 2025 to 17 Aug 2026 |
| Views | 302 | from 251 distinct sessions |
| Credentials viewed at least once | 38 of 48 | 79% of the cohort |
| Signature verifications | 133 | none failed |
| Added to a LinkedIn profile | 23 | clicks on the profile button |
| PDF downloads | 22 | |
| Shares and link copies | 15 | 6 LinkedIn, 9 copied links |
| Mobile share of activity | 336 of 505 events | 67% of activity |
505 events from 48 credentials is roughly ten recorded interactions per credential. For a cohort of this size that is a lot more than the industry assumption, which is that a certificate is looked at once and filed.
The part we did not expect
We assumed the shape would be a spike and then nothing. Credentials go out, everyone opens them that week, and the page is never visited again.
The spike is real. The nothing never arrived.
265 of the 505 recorded events, or 52%, happened after the first month visible in the data. Monthly activity fell from 240 to a band between 16 and 54 and then simply stayed there. In August 2026, ten months after issuance, these credentials were still being opened 29 times in seventeen days.
That tail is the whole commercial argument for a hosted credential, and it is the one thing a PDF attachment cannot do. A recipient applying for a job in June 2026 does not go looking through an email from the previous October. They send a link, and someone opens it. Every bar after the first one is a credential doing work eight months after the issuer had forgotten about it.
We should be careful about one thing here. Tracking started six weeks after issuance, so the true peak is not in this data and was probably higher. That makes the first bar an underestimate, not the tail an overestimate, so the direction of the error runs against the point we are making rather than for it.
Where the traffic came from
Two findings, both of which changed how we think about what a credential page has to be good at.
Two thirds of all activity was on a mobile device, 336 events of 505. Not a slight majority. If a credential page is designed on a desktop and checked on mobile as an afterthought, it is being built backwards. A certificate is something people pull up on a phone, in a queue, to show somebody.
LinkedIn is where credentials go to live. Of the 125 events that carried a referrer at all, 76 came from LinkedIn, including a substantial share from its mobile app, against 36 from email clients, 6 from Google, and 7 from elsewhere on this site. Add the 23 clicks on the add-to-profile button and the pattern is clear: a credential is issued by email and then moves to LinkedIn, which is where it is seen from then on.
The remaining 380 events carried no referrer, which is what a direct visit, a typed URL, a scanned QR code or a privacy-stripped link all look like. That is most of the traffic, and we cannot tell you where it came from. Adding a certificate to LinkedIn is the guide we point recipients at.
What verification was actually used for
133 signature verifications ran across the period, and every one passed. There has never been a signature failure on a credential issued through this platform in production.
Here is the number that is less flattering, and we would rather publish it than leave it out: only 10 of 302 views opened the verification detail panel. Roughly three in a hundred. The overwhelming majority of people who open a credential look at it and move on without inspecting anything.
We think that is fine, and it is worth being clear why rather than defensive about it. Verification is not a feature people want to use. It is a feature they want to exist, for the one occasion when something looks wrong or a decision is expensive enough to justify checking. A fire extinguisher that is never discharged has not failed. What would be damning is a verification step that failed when someone finally used it, and across 133 checks that has not happened.
It also has a practical consequence for anyone doing the checking. How employers verify certificates quotes this figure against our own argument: publishing a verification route does not make people use it, so an employer who wants the check done has to decide, in advance and per role, that it will be.
The signature runs on page load regardless, which is why 133 is so much larger than 10. Most recipients are protected by a check they never consciously requested. Verifying a certificate online covers what the check actually establishes.
The ten that nobody opened
38 of 48 credentials were viewed at least once. Ten never were, in ten months.
We do not know why, and we are not going to guess prettily. Plausible explanations include an email that bounced or went to spam, a recipient who changed jobs, a wrong address on the original list, or simple disinterest. We cannot distinguish between them from this data, and anyone claiming a precise reason for a number like this is telling you a story rather than a finding.
It is worth stating because it sets a realistic expectation. A fifth of any cohort may never engage at all, and an issuer planning on every recipient opening their credential is planning around something that did not happen here.
What this is not evidence of
This is one issuer, one cohort of 48 credentials, one country, one professional field, and one point in time. It is a worked example, not a study.
- It cannot tell you what issuers generally see. We have no second issuer to compare against. Anything here could be specific to this audience, which is a professional finance community with unusually strong reasons to display a credential.
- 48 is a small number. Ten unviewed credentials out of 48 is a fifth of the cohort, but it is also just ten. Small samples move a lot.
- Awards differ. An ethics competition credential is not a mandatory compliance certificate, and there is no reason to expect the same behaviour from both.
- We are not a neutral party. We built the platform, we hold the data, and we chose which cuts to publish. The method below is there so you can judge that for yourself.
When there are enough issuers to say something about the market, we will say it then. Until then this is one organisation's data, published because it is more useful than the assertions it replaces.
How these numbers were produced
Every figure is a count of rows in our analytics table for this issuer's 48 credentials. Nothing is modelled, projected, or averaged across issuers.
- Window. 9 December 2025 to 17 August 2026. Tracking began on the first of those dates, six weeks after issuance, so activity in that gap was never recorded. August is a partial month.
- One session was excluded. Our own development testing on 19 December 2025, 11 events against a single credential from a local machine. That removal is also why the signature figures are clean: all six recorded signature failures anywhere in the table — not just in this cohort — belonged to that session, so there have been none in production. The raw table holds 516 events; 505 are published.
- Sessions, not people. A "distinct session" is a random identifier held in browser storage. One person on a phone and a laptop is two sessions; one person returning weeks later is also two.
- Time-on-page is excluded entirely. Only 29 events carry it and the largest is over two days, which is a tab left open rather than a reader. A median drawn from that would look like evidence without being any.
- No personal data was used. The analytics table stores no names, no email addresses and no IP addresses, and nothing here was joined back to recipient records.