The COFI Countdown: Harmonising Operational Risk and Conduct Regulation in South Africa’s New Financial Era
1. Executive Summary & The Legislative Landscape
1.1 The 2026 Parliamentary Milestone: From Rules to Principles
The formal submission of the Conduct of Financial Institutions (COFI) Bill to Parliament marks a defining structural transition in the history of South African financial regulation. For nearly a decade, the financial services sector viewed COFI as a looming cloud on the horizon; a deeply debated legislative draft defined by successive rounds of public commentary, technical revisions, and steady political refinement.
Now officially entered into the parliamentary pipeline, the Bill moves out of the realm of theoretical compliance and into the immediate strategic horizons of corporate boardrooms, operational risk units, and executive committees across the country.
This milestone signals the definitive end of “tick-box” compliance within the domestic market. Historically, the legislative landscape was highly prescriptive, dictating precise, rigid rules that financial entities had to follow to satisfy the regulator. Under that legacy architecture, an institution could technically meet every legislative checkmark while still manufacturing products or executing processes that resulted in severe consumer detriment.
COFI permanently dismantles this approach, replacing it with a rigorous principles-based regulatory framework.
Under a principles-based regime, the Financial Sector Conduct Authority (FSCA) will no longer judge compliance solely by whether an entity followed a specific procedural script. Instead, the regulator will assess institutions on whether their actions, corporate cultures, and operating models consistently deliver the specific, qualitative outcomes intended by the law, most notably, the fair treatment of financial customers and the promotion of market integrity.
For financial sector participants, this requires a profound paradigm shift: compliance can no longer be treated as a siloed, retrospective audit function, but must be embedded directly into the daily operational mechanics of the business.
1.2 The Twin Peaks Culmination
To understand the legal gravity of the COFI Bill, it must be viewed as the structural capstone of South Africa’s Twin Peaks regulatory model. Initiated by the promulgation of the Financial Sector Regulation Act (FSRA) of 2017, the Twin Peaks framework split financial supervision into two dedicated prongs:
Prudential Regulation: Spearheaded by the Prudential Authority (PA) within the South African Reserve Bank, focusing on the financial soundness, capital adequacy, and systemic stability of institutions.
Market Conduct Regulation: Overseen by the FSCA, focusing on how financial institutions interact with their clients and the broader market.
While the FSRA created the structural architecture for this split, the underlying sector laws remained heavily fragmented. For years, market conduct was governed by a patchwork of legacy, sector-specific statutes passed under the old regime. This included the Financial Advisory and Intermediary Services (FAIS) Act, the Long-term Insurance Act, the Short-term Insurance Act, and distinct conduct provisions embedded within the Banks Act and the Friendly Societies Act.
COFI acts as the grand consolidator. It repeals or significantly amends these fragmented statutes, bringing banks, insurers, asset managers, discretionary FSPs, fintech innovators, and credit providers under a single, overarching conduct framework.
Furthermore, COFI works in tandem with recent systemic updates, including the evolution of the old Pension Funds Act into the modern, newly aligned Financial Provisioning Funds Act under the consequential amendments of the COFI bill. By unifying these laws, the legislator eliminates regulatory arbitrage, ensuring that regardless of whether a consumer buys a banking product, an insurance policy, or a retirement annuity, they are protected by the exact same baseline of institutional conduct.
1.3 The Core Proposition: Framing COFI as an Operational Risk Imperative
As COFI is a piece of legislation, the natural corporate inclination is to hand the implementation project directly to legal and compliance teams. This approach represents a severe, potentially catastrophic misunderstanding of the Bill’s underlying mechanics. COFI is not a legal checklist; it is an Operational Risk Management (ORM) imperative.
By demanding that financial institutions prove they are delivering fair outcomes throughout the entire lifecycle of a financial product, from early design and target market identification to distribution, onboarding, servicing, and claims handling, COFI shifts conduct risk directly into the operational heart of the enterprise. If an institution boasts flawless capital reserves and an elite legal team, yet maintains a legacy IT infrastructure that creates data silos, a corporate culture that incentivises aggressive volume over client suitability, or third-party vendor agreements that neglect customer equity, it is exposed to severe operational and regulatory failure.
For the modern risk professional, COO, or financial advisor, COFI requires a complete re-engineering of traditional risk frameworks. Operational risk can no longer be confined to classical definitions of system uptime, cyber defence, and fraud prevention. It must expand to encompass conduct risk and culture risk as core operational vulnerabilities.
Ultimately, COFI treats operational resilience and fair client outcomes as two sides of the exact same coin. The organisations that thrive in this new parliamentary era will be those that stop treating conduct as a legal constraint and begin treating it as a core discipline of operational risk management.
2. The Redefinition of Operational Risk Under COFI
The impending enactment of the Conduct of Financial Institutions (COFI) Bill represents far more than a consolidation of South Africa’s financial sector laws. For risk executives, its true impact lies in how it fundamentally shatters and rebuilds the definition of Operational Risk Management (ORM). To treat COFI as a ring-fenced compliance exercise is to misunderstand the tectonic shift occurring in our regulatory landscape. Under the Twin Peaks model, market conduct is no longer a soft, secondary consideration, it is now deeply embedded within the core of operational resilience.
2.1 Moving Beyond Basel III: The New Frontiers of ORM
For decades, financial institutions have anchored their ORM frameworks to traditional global benchmarks like Basel III. Within that legacy paradigm, operational risk was neatly categorised: the risk of direct or indirect loss resulting from inadequate or failed internal processes, people, systems, or external events. It was a framework heavily focused on system uptimes, processing errors, fraud prevention, and data security. If the systems ran smoothly and the ledger balanced, the operational risk was deemed “managed”. COFI aggressively expands this perimeter.
Under the new regime, the definition of operational risk is structurally extended to absorb two historically nebulous domains:
Legacy Basel III ORM → Processes, People, Systems, External Events
↓
COFI Extended ORM → Adds: Corporate Culture & Consumer Outcomes
The Financial Sector Conduct Authority (FSCA) is making it explicitly clear that a process can be technically flawless, highly profitable, and completely secure, yet still represent a catastrophic operational failure if it generates poor customer outcomes or reflects a predatory corporate culture. The operational risk function must now actively monitor not just how a transaction executes, but the fairness of the economic value it delivers to the end consumer.
2.2 The Non-Binary Enforcement Model: Navigating the Maturity Spectrum
Historically, compliance in South Africa was largely a binary, check-the-box affair. An institution was either compliant with a specific rule under FAIS or the Short-term Insurance Act, or it was not. Enforcement was predictable, driven by explicit, written directives.
COFI’s principles-based approach completely dismantles this binary model. The FSCA will view financial institutions through the lens of a risk management maturity spectrum.
| Regulatory View | Legacy Binary Model | COFI Principles-Based Model |
| Enforcement Focus | Strict adherence to written rules and checklists. | Evaluation of underlying intent and real-world outcomes. |
| Risk Assessment | Compliant vs. Non-Compliant. | Position on a continuous Operational Maturity Spectrum. |
| Supervisory Stance | Reactive (responding to historical breaches). | Proactive (interrogating governance and culture). |
Under this non-binary enforcement model, simply proving you followed a written procedure will no longer serve as a legal shield. Regulators will look at the maturity of your governance. They will evaluate whether your internal systems are designed to proactively identify, escalate, and remediate conduct failures. An organisation with technically zero historical breaches but a low-maturity, reactive risk culture will find itself firmly in the crosshairs of aggressive supervisory intervention.
2.3 Quantifying the Intangible: The Ultimate Risk Challenge
This evolution presents operational risk teams with an intense methodological challenge: how do you measure, monitor, and audit highly subjective parameters like “fair customer outcomes” and “corporate culture”?
Unlike credit or market risk, which rely on precise mathematical models, culture and conduct cannot be easily plugged into a spreadsheet. How do you quantify whether an advisor acted with genuine integrity, or if a product’s fee structure is inherently asymmetric?
To avoid regulatory penalties, risk officers must transition from qualitative guesswork to robust, data-led proxies. This requires translating the subjective principles of Treating Customers Fairly (TCF) into objective operational metrics. Culture can no longer be evaluated by an annual, anonymous HR survey; it must be audited via behavioural data points. Risk teams must now build frameworks that analyse structural patterns, such as employee whistleblowing rates, remuneration structures that incentivise aggressive sales, and the speed at which customer friction points are resolved. Under COFI, the intangible must become auditable, because what cannot be measured cannot be proven to the regulator.
3: Product Governance: Risk Management at the Design Phase
The traditional boundary line for operational risk in financial distribution has historically been the point of sale. If an intermediary mis-sold a policy or an advisor glossed over a critical exclusion, the breakdown was treated as a localised compliance failure or an isolated training deficiency. Under the Conduct of Financial Institutions (COFI) framework, this reactive approach is obsolete. COFI forces a profound paradigm shift: risk management is moving aggressively upstream, embedding itself directly into the product development laboratory long before a product ever meets a consumer.
3.1 Shifting Risk Upstream: Governance by Design
Under the incoming regime, the Financial Sector Conduct Authority (FSCA) places primary accountability for consumer outcomes on product manufacturers; the banks, insurers, and asset managers who design financial instruments. Senior leadership can no longer shield themselves behind the defence that an independent broker mis-sold their product. If a product yields consistently poor outcomes, the regulator’s first question will not be “How was it sold?” but rather “How was it designed?”
This means that Product Governance is now a critical pillar of Operational Risk Management (ORM). Middle and senior management must establish robust, documented gateways at the design phase. A new financial product cannot be launched simply because it is highly profitable or fills a competitive gap. It must pass through rigorous risk testing to ensure it inherently supports the principles of Treating Customers Fairly (TCF). Risk officers must be empowered to stress-test products against behavioural scenarios, hidden cost complexities, and structural vulnerabilities before signing off on commercial production.
3.2 Target Market Identification (TMI) Controls
At the heart of upstream product governance is the concept of Target Market Identification (TMI). Under COFI, defining a target market is no longer a broad, optimistic exercise for the marketing department; it is a strict, documented operational control.
Product manufacturers must explicitly define and document exactly who a product is for and, critically, who it is not for.
Product Design Lab →Clear TMI Controls (Who it IS for vs. Who it IS NOT for)
↓
Distribution Phase →Automated Monitoring & Risk-Based Adjustments
For instance, an investment product with high volatility and steep early-exit penalties cannot simply be marketed to “the general public.” The TMI documentation must explicitly state that this product is entirely unsuitable for low-income consumers, retirees needing liquidity, or risk-averse individuals.
For senior management, the operational risk challenge lies in enforcing these boundaries through the distribution chain. These TMI definitions must be hard coded into distribution agreements, training manuals, and digital onboarding platforms so that the system inherently rejects sales that fall outside the approved parameters.
3.3 The Operational Risk Workflow: Monitoring and Mandated Adjustments
To ensure TMI controls remain effective in the real world, institutions must implement a continuous, data-driven operational workflow. This moves product governance from a static, annual review to an active, tech-enabled surveillance loop.
- Automated Target Market Flags: Risk teams must deploy automated data triggers within their CRM and sales systems. If a sudden spike in sales occurs in a demographic outside the defined target market, or if demographic variances show a high concentration of products being sold to vulnerable consumers, the system must automatically flag this trend for immediate executive intervention.
- Mandatory Lifecycle Reviews: Products can no longer be launched and forgotten. COFI mandates continuous, scheduled lifecycle reviews. Risk officers must design operational triggers based on real-world consumer outcomes.
| Operational Trigger Event | Required Risk Action |
| Early-stage lapse/cancellation rates exceed a pre-set 10% threshold. | Immediate Freeze: Pause distribution and audit the onboarding disclosures. |
| Ombud complaints for a specific product line spike by 15% quarter-on-quarter. | Root-Cause Review: Interrogate whether product complexity is causing systemic consumer confusion. |
| Real-world data reveals the product consistently delivers negative real returns after fees. | Product Withdrawal: Mandate product adjustment or structured withdrawal from the market to prevent further consumer detriment. |
Ultimately, under COFI, product design is no longer just a business driver; it is the first line of defence in an institution’s operational risk architecture.
4. The Distribution Chain and Outsourcing Vulnerabilities
In the legacy regulatory environment, large financial institutions frequently managed distribution and operational costs by outsourcing key functions to a vast ecosystem of third parties. Independent broker networks, Third-Party Administrators (TPAs), outsourced call centres, and independent Financial Services Providers (FSPs) allowed institutions to scale rapidly. Crucially, when things went wrong down the value chain, product manufacturers could often insulate themselves by treating the failure as an isolated, third-party breach. Under the Conduct of Financial Institutions (COFI) Bill, this insulation is entirely dismantled.
4.1 Total Accountability Architecture
COFI introduces a strict framework of Total Accountability Architecture. The Financial Sector Conduct Authority (FSCA) has made its stance unequivocal: a financial institution can outsource its operational tasks, but it can never outsource its regulatory accountability. Large banks, insurers, and asset managers remain fully liable for how their products are distributed, serviced, and adjudicated, regardless of how many intermediaries sit between the institution and the end consumer.
Product Manufacturer→Third-Party Administrator/Broker→ End Consumer
│ ↑
└─────────────────── TOTAL ACCOUNTABILITY ───────────────────┘
Regulatory liability remains pinned to the Manufacturer and cannot be outsourced down the chain.
This represents a massive shift in institutional liability. Senior management can no longer rely on indemnity clauses or basic legal disclaimers to shield the parent company from conduct failures occurring within independent distribution networks. If an outsourced administrator mishandles claims or an independent broker network systematically mis-sells a policy, the FSCA will hold the product manufacturer co-responsible for failing to oversee its value chain.
4.2 Revamping Third-Party Risk Management (TPRM)
Because liability remains pinned to the top tier, traditional Third-Party Risk Management (TPRM) frameworks must be radically overhauled. Historically, TPRM was handled as a technical and legal exercise. Risk teams focused heavily on:
- Service Level Agreement (SLA) uptimes and system availability.
- Data security protocols and POPIA (Protection of Personal Information Act) compliance.
- Financial stability audits of the vendor.
Under COFI, these metrics, while still necessary, are completely insufficient. Operational risk teams must transition to continuous, conduct-led surveillance of third parties.
This means auditing how the third party interacts with the consumer. For outsourced call centres, risk teams must implement automated data analytics to monitor call-sentiment trends, non-disclosure rates, and customer drop-offs. For claims handlers, metrics must shift from mere turnaround times to analysing the equity and consistency of claims repudiations. TPRM is no longer a static quarterly check; it is an active, data-driven surveillance loop.
4.3 Navigating Legal and Operational Friction
This shared responsibility model introduces significant operational friction, particularly between product manufacturers (e.g., large product providers) and independent FSPs who value their commercial autonomy.
Historically, independent brokers resisted heavy-handed oversight from product providers, viewing it as an infringement on their business. COFI forces both sides into a mandatory partnership of co-responsibility, requiring a delicate balance of control and cooperation:
| Friction Point | Legacy Dynamic | COFI Operational Mandate |
| Data Sharing | Intermediaries ring-fenced client data; manufacturers only saw final sales. | Open-Data Pipelines: Continuous, real-time sharing of conduct metrics and client feedback loops. |
| Oversight | Broad annual reviews of FSP licensing status. | Deep-Dive Audits: Manufacturers must actively review the advice-giving processes of their distributors. |
| Contractual Terms | Focused on volume targets, commission structures, and clawbacks. | Conduct-Aligned SLAs: Contracts must mandate explicit Treating Customers Fairly (TCF) performance targets. |
Middle and senior management must navigate this friction by re-engineering distribution agreements. Contracts must be rewritten to give manufacturers the explicit right to audit third-party conduct, access raw data streams, and immediately suspend distribution rights if real-world consumer detriment is detected. In the COFI era, a weak link in your distribution chain is no longer just a vendor issue; it is a direct threat to your institution’s license to operate.
5. Re-Engineering Corporate Governance and the Risk Appetite Statement
The ultimate test of any regulatory framework is not found in the manuals of the compliance department, but in the discussions of the corporate board and the architecture of the Risk Appetite Framework (RAF). Historically, market conduct was treated by many boards as a qualitative narrative; a soft metric reviewed annually through a Treating Customers Fairly (TCF) dashboard. The Conduct of Financial Institutions (COFI) framework radically disrupts this, transforming conduct and culture from fluffy corporate governance concepts into hard, quantifiable, and legally binding operational risk parameters.
5.1 Redrafting the Corporate Board Mandate
Under COFI, the role of the board shifts from passive oversight to active, data-driven attestation. In the legacy environment, directors could reasonably rely on receiving periodic assurances from the compliance function that “no material breaches occurred.” This retrospective, check-the-box reporting structure is no longer acceptable to the Financial Sector Conduct Authority (FSCA).
The board mandate must be fundamentally redrafted to reflect ongoing accountability for institutional culture and consumer equity. Boards must now proactively interrogate the operational data. Directors are required to actively attest that the institution’s business model, incentive structures, and operational processes are designed to deliver fair outcomes. This demands that board packs evolve away from dense legal opinions and move toward real-time, granular conduct dashboards that expose systemic friction points before they manifest as regulatory breaches.
5.2 Integrating COFI into the Risk Appetite Framework (RAF)
To make this governance effective, middle and senior management must translate high-level COFI principles into the primary steering mechanism of the firm: the Risk Appetite Statement. If an institution’s RAF only measures capital adequacy, liquidity ratios, and credit defaults, it is fundamentally blind to conduct risk.
Institutions must establish quantifiable Key Operational Risk Indicators (KRIs) for conduct, setting clear thresholds for acceptable risk variance.
Risk Appetite Statement →Sets Hard Conduct Thresholds
↓
Key Operational Risk Indicators →Real-Time Monitoring of Operational Metrics
(Claims, Complaints, Drop-offs, Fees)
Modern, COFI-aligned KRIs must track operational behaviours that act as leading indicators of consumer detriment. Examples of these metrics include:
- Asymmetric Fee Margins: Monitoring whether specific client segments are paying disproportionately high fees relative to the economic value delivered.
- Root-Cause Complaint Trends: Tracking spikes in ombud or internal complaints clustered around specific product lines or individual advisors, rather than just measuring total complaint volumes.
- Onboarding Drop-off Percentages: Analysing where and why clients abandon digital onboarding journeys, which can signal confusing disclosures or overly aggressive digital sales nudges.
- Claims Turnaround Deficiencies: Measuring the tail-end distribution of claims processing times to ensure delayed payouts are not being used as a covert liquidity management tool.
5.3 Key Persons Obligations: The Reality of Personal Liability
Perhaps the most significant psychological shift brought about by COFI is the sharpening of the Key Persons regime. For middle and senior management, including risk officers, operational heads, and trustees, the incoming regime introduces strict, ongoing “fit and proper” requirements coupled with heightened personal accountability.
| Attribute | Legacy Compliance Framework | COFI Key Persons Regime |
| Liability Focus | Institutional penalties and corporate fines. | Personal accountability for executives and operational heads. |
| Oversight Scope | Point-in-time “Fit and Proper” assessment at registration. | Continuous, dynamic monitoring of competence and integrity. |
| Enforcement Target | Corporate entity fines and institutional penalties. | Statutory debarment, personal fines, or operational disqualification. |
Under COFI, if a systemic conduct failure is traced back to a severe lack of operational oversight, a flawed product design process, or a toxic corporate culture, the regulator will look past the corporate shield. Key Persons can be held personally liable for failing to implement adequate operational controls.
This reality shifts the corporate governance conversation entirely. Implementing robust operational risk indicators is no longer just about protecting the institution’s balance sheet, it is an absolute necessity for protecting the career and personal liability of its leadership.
6. Data Integrity and Cognitive Tech as Operational Armor
A principles-based regulatory framework sounds abstract in theory, but in practice, its enforcement is entirely binary: you either have the data to prove fair outcomes, or you do not. Under the Conduct of Financial Institutions (COFI) Bill, the Financial Sector Conduct Authority (FSCA) is undergoing a massive internal evolution to become a highly proactive, data-driven regulator. For middle and senior management, this means that the historical approach of manually compiling retrofitted compliance spreadsheets is over. Data integrity and cognitive technology must now become the primary defensive armour of the operational risk framework.
6.1 The Data-Driven Regulator: The Metric of Truth
Under the COFI regime, the burden of proof is completely reversed. It is no longer the regulator’s job to discover misconduct; it is the institution’s job to continuously demonstrate compliance. The FSCA will increasingly demand raw, aggregate, and real-time operational data to verify Treating Customers Fairly (TCF) outcomes.
If an institution’s data is fragmented, dirty, or manually manipulated, its operational risk profile instantly skyrockets. Why? Because poor data architecture signals to the supervisor that the executive team has no real control over its operational reality. Regulators will interpret a lack of clear, auditable data pipelines as a deliberate attempt to obscure systemic misconduct, leading to immediate supervisory intervention and heightened capital add-on penalties.
6.2 The Operational Danger of Legacy Tech Silos
The single greatest operational obstacle to COFI readiness for large, established institutions is the fragmentation of their legacy IT architecture. Over decades of mergers, acquisitions, and organic growth, most large financial institutions have built rigid product silos.
Legacy Banking Stack Legacy Insurance Stack Legacy Wealth Stack
│ │ │
Siloed Client Siloed Client Siloed Client
└───────────────────────┬───────────────────────────────────┘
↓
FRAGMENTED, INCONSISTENT VIEW
High Operational Risk Under COFI Framework
In this siloed environment, a customer may be a private banking client on one platform, a short-term insurance policyholder on another, and an active investor on a third. Because these systems rarely speak to each other in real-time, the operational risk team is fundamentally blind to the total client experience.
An insurance claim could be unfairly repudiated on one side of the business while a wealth manager is aggressively cross selling an aggressive investment product to that exact same client on the other. This systemic blindness creates a severe conduct risk vulnerability. COFI mandates an integrated, holistic look at client treatment, forcing institutions to rapidly upgrade their middleware and unify their data layers to create a “single source of truth.”
6.3 The Role of RegTech and AI as Predictive Armour
To survive in this high-scrutiny environment, forward-thinking risk officers are turning to Regulatory Technology (RegTech) and cognitive AI tools to shift their defensive posture from reactive to predictive.
| Cognitive Tech Tool | Operational Risk Application | COFI Preventive Outcome |
| Natural Language Processing (NLP) | Continuous scanning of advisor-client emails, chat logs, and recorded call centre interactions. | Instantly flags high-pressure sales tactics or misleading product verbal disclosures before a complaint is logged. |
| Machine Learning (ML) Anomalies | Analysing transaction patterns, fee charging frequencies, and cancellations across vast client bases. | Proactively identifies systemic over-charging or asymmetric product performance trends across specific demographics. |
| Predictive Risk Dashboards | Aggregating employee behavioural data, whistleblowing trends, and internal audit findings. | Allows senior management to intervene and remediate toxic sub-cultures before they spark regulatory enforcement. |
By embedding AI and NLP directly into the operational risk infrastructure, middle and senior management can establish an internal early-warning system. These cognitive systems scan the operational landscape 24/7, pinpointing conduct vulnerabilities and compliance variances long before they show up on the regulator’s radar. In the COFI era, technology is no longer just an efficiency driver; it is the ultimate shield for institutional reputation and operational resilience.
7. Transformation and Market Development
One of the most defining characteristics of the Conduct of Financial Institutions (COFI) Bill is its unique structural divergence from global regulatory templates. While international frameworks focus almost exclusively on consumer protection and market stability, COFI is explicitly designed within the South African socioeconomic context. Under this regime, the Financial Sector Conduct Authority (FSCA) is given an explicit, statutory mandate to drive broad economic transformation and enforce alignment with the Financial Sector Code. For senior leadership, this means transformation is no longer a separate corporate social responsibility (CSR) exercise; it is now a direct legislative component of market conduct licensing.
7.1 COFI’s Unique Mandate: Convergence of Conduct and Transformation
Historically, Broad-Based Black Economic Empowerment (B-BBEE) compliance and market conduct regulation operated in distinct, separate silos. An institution could face commercial pressures for poor empowerment credentials, but its regulatory license to provide financial services was never explicitly contingent upon its transformation metrics.
COFI permanently fuses these two domains. The FSCA will have the legislative authority to review, interrogate, and potentially decline or restrict an institution’s operating license based on its commitment to, and execution of, transformation objectives.
The regulatory philosophy here is clear: a financial sector cannot be considered genuinely fair or consumer-centric if it structurally excludes the majority of the population from equitable participation or fair economic value. Consequently, transformation performance is now a core component of institutional risk management.
7.2 The Operational Burden of Structural Adaptation
This legislative fusion introduces a complex operational layer for middle and senior risk management. Integrating B-BBEE alignment directly down the operational value chain requires strict governance frameworks that must be maintained without sacrificing commercial agility or efficiency.
| Operational Focus Area | Legacy Approach | COFI Operational Reality |
| Procurement & Supply Chain | Sourcing vendors based purely on standard commercial SLAs and cost efficiencies. | Conduct-Empowered Vendor Sourcing: Actively auditing and selecting transformed suppliers who also meet strict COFI conduct criteria. |
| Product Distribution | Focusing distribution channels on traditional, highly profitable demographic segments. | Financial Inclusion Mandates: Designing operational workflows that support financial inclusion and underserved markets. |
| Enterprise Development | Annual corporate funding allocations to external enterprise development projects. | Strategic Incubation: Integrating black-owned FinTechs and financial intermediaries directly into the firm’s core tech ecosystem. |
Risk teams must now establish continuous monitoring systems to track these metrics. If an organisation fails to hit its projected transformation targets, it can no longer be brushed off as a missed corporate target; it must be logged as a high-severity operational risk item that directly threatens the institution’s regulatory status.
7.3 Proportionality and FinTech: Shifting the Competitive Risk Posture
While COFI introduces stringent demands for large incumbents, its design also features a “proportionality principle.” This activity-based and proportional licensing framework ensures that the regulatory burden is tailored to the size, complexity, and risk profile of the business.
This proportional model is specifically designed to foster market development by opening the doors to FinTech innovators and smaller, agile black-owned financial entities. By easing the initial compliance friction for smaller players, COFI lowers the barriers to entry, driving competitive innovation across the landscape.
For senior executives at large banks and established insurers, this shifts the competitive risk posture. Incumbents can no longer rely on deep compliance pockets as a barrier to keep out smaller competitors. Instead, large institutions must adapt their operational systems to either compete directly with these highly nimble, low-cost digital players or build open-finance API frameworks that allow them to safely partner with and incubate them within the bounds of shared conduct liability.
8. Conclusion and Strategic Roadmap for Financial Institutions
The Conduct of Financial Institutions (COFI) framework is not a passing regulatory storm to be weathered with short-term fixes; it is a permanent change in the operational climate of South Africa’s financial sector. As the Bill progresses through its parliamentary milestones, the window for reactive planning is closing. For middle and senior management, the challenge now is to shift from conceptual awareness to aggressive operational execution. The institutions that emerge as leaders in this new era will be those that recognise a fundamental truth: operational resilience and fair consumer outcomes are exactly the same thing.
8.1 Navigating the Three-Year Transitional Horizon
Recognising the massive structural changes required, the framework provides a formal three-year transitional horizon. This grace period is explicitly designed to allow institutions to systematically migrate from legacy, entity-based registrations (such as standalone FAIS or Insurance licenses) over to the new, activity-based COFI licensing architecture.
Legacy Siloed Licenses → 3-Year Transition Window → Unified Activity-Based License
(FAIS, Insurance, Banks) (Systemic Migration) (Hard-Coded TCF Controls)
However, senior leadership must not mistake this transitional runway for an invitation to delay. The Financial Sector Conduct Authority (FSCA) expects to see immediate, measurable progress. The three-year window is intended for the technical migration of systems, data loops, and legal contracts; not for debating the merits of the legislation. Waiting until the formal transition window closes to re-engineer your internal frameworks is a high-risk strategy that will leave your institution operationally stranded.
8.2 A Final Thought: The Strategic Premium on Conduct
When the dust settles, COFI will reveal a stark divide in South Africa’s financial landscape. Institutions that view this shift purely through a narrow “compliance lens” will find themselves weighed down by heavy bureaucracy, frequent regulatory fines, and rigid systems that cannot adapt to market changes.
Conversely, forward-thinking organisations will leverage COFI as a powerful catalyst for modernisation. By building clean data pipelines, unifying legacy IT systems, and instilling an unyielding culture of consumer equity, these firms will unlock massive operational efficiencies. In this new financial era, robust conduct governance is no longer a cost centre; it is the ultimate strategic differentiator that secures consumer trust, commercial longevity, and an ongoing license to operate.
For more information on this key topic, watch our informative podcast below.
Responses