Executive summary
South Africa’s proposed Conduct of Financial Institutions (COFI) Bill would consolidate financial-sector conduct requirements into a technology-neutral, activity-based and outcomes-focused framework. Its relevance to AI and open finance lies in the way it connects customer outcomes, governance, accountability and data capability across increasingly digital financial-services ecosystems.
Core entities and their roles
National Treasury
Responsible for policy development and drafting the proposed legislation.
Financial Sector Conduct Authority
The FSCA is the market-conduct regulator expected to supervise conduct standards and customer outcomes within the COFI framework.
Financial institutions and supervised entities
Organisations and representatives performing regulated financial activities, including participants in digital and platform-based customer journeys.
Financial customers
People and organisations whose treatment, disclosures, product outcomes and access to remedies sit at the centre of the proposed framework.
Important COFI concepts
Activity-based regulation: regulation focused on the financial activity being performed rather than only the traditional category of institution performing it.
Technology neutrality: conduct expectations that remain applicable as delivery technologies and business models change.
Outcomes-focused supervision: evaluation of whether customers experience fair and appropriate results, not merely whether a checklist was completed.
Open finance: a connected ecosystem in which authorised data sharing, APIs and digital platforms allow multiple providers to contribute to a financial-service journey.
Data-driven supervision: the use of reliable information and reporting to identify emerging conduct risks and assess customer outcomes.
How AI fits into the proposed framework
AI can support credit assessment, fraud detection, customer service, personalisation and operational decision-making. A technology-neutral framework means organisations remain accountable for customer outcomes even when a model, platform or external technology provider contributes to the decision.
AI governance should therefore connect:
- Purpose and permitted use of data
- Data quality and representativeness
- Model ownership and human oversight
- Customer explanations and disclosures
- Testing for unfair or harmful outcomes
- Monitoring, incident handling and remediation
How open finance changes accountability
An open-finance journey may involve a financial institution, data provider, technology platform, identity-verification service and embedded-finance partner. Customers nevertheless experience these components as one service.
A COFI readiness programme should identify each participant, the activity it performs, the data it receives, its decision rights and its responsibility when something goes wrong.
A six-part readiness framework
- Customer journey mapping: document products, channels, decisions and third parties.
- Data governance: establish lineage, quality, consent, access and retention controls.
- AI governance: record model purpose, limitations, testing and oversight.
- Outcome monitoring: track complaints, exclusions, exceptions and remediation.
- Accountability: assign ownership across boards, executives, product teams and providers.
- Evidence: retain auditable records showing how customer fairness is designed and monitored.
Current status
The COFI Bill remains proposed legislation. Institutions should use current official sources for legal status and implementation dates. Read the ITWeb report that informed the original Datanamix News Watch item.
This article provides general information and is not legal advice.









