South Africa’s proposed Conduct of Financial Institutions (COFI) Bill is designed to modernise market-conduct regulation by replacing fragmented requirements with a more coherent, activity-based and outcomes-focused framework.
Its importance extends beyond regulatory consolidation. By emphasising technology neutrality, customer outcomes and data-led supervision, COFI could influence how financial institutions deploy artificial intelligence, collaborate with fintech platforms and participate in open-finance ecosystems.
What the proposed reform is intended to change
Under the Twin Peaks model, the Financial Sector Conduct Authority is responsible for market conduct, while the Prudential Authority focuses on financial soundness. COFI is intended to give the conduct side a consolidated legislative framework.
National Treasury describes the proposed approach as activity-based, principles-led and focused on fair treatment, transparency and accountability. The Bill remains subject to the legislative process and should not yet be treated as enacted law.
Why technology neutrality matters
Financial technology develops faster than prescriptive legislation. A technology-neutral framework avoids creating separate conduct expectations for every new platform, model or delivery channel.
The practical implication is that an institution cannot transfer responsibility for customer outcomes to an algorithm or technology supplier. Whether a decision is made by an employee, an AI model or a platform workflow, the institution must be able to govern the process and assess its effects.
AI turns conduct into a data-governance question
AI-supported financial services depend on data quality, model design and continuous monitoring. Inaccurate, incomplete or poorly governed data can lead to unsuitable recommendations, inconsistent decisions or unfair exclusion.
A conduct-focused AI programme therefore needs more than technical accuracy. It needs evidence that the system:
- Has a defined and appropriate purpose
- Uses data lawfully and responsibly
- Is tested for harmful or unfair outcomes
- Provides meaningful oversight and escalation
- Can be monitored after deployment
- Supports appropriate customer explanations and remedies
Open finance distributes the journey, not the accountability
Open finance allows multiple providers to contribute to one customer journey through APIs, authorised data sharing and embedded services. This can improve choice and innovation, but it also makes responsibility more complex.
Financial institutions will need clear agreements covering permissions, data quality, service failures, customer communication and remediation. The customer should not have to determine which hidden provider caused a poor outcome before receiving assistance.
Why regulators are emphasising data capability
ITWeb’s reporting on the FSCA Conference 2026 highlighted the expected move from reactive compliance towards proactive conduct maturity. This requires institutions to understand risks as they emerge rather than only reporting after harm has occurred.
Useful conduct data may include customer complaints, declined applications, model overrides, product exits, vulnerable-customer outcomes and the performance of third-party providers.
What readiness looks like
A credible readiness programme connects product governance, compliance, data management, technology risk and executive accountability. It maps digital journeys, identifies regulated activities, defines customer outcomes and establishes the evidence needed to demonstrate that controls work in practice.
COFI’s final obligations will depend on the legislation and accompanying conduct standards. However, stronger data governance, accountable AI and transparent partner ecosystems are valuable preparations regardless of the final commencement date.
Source: ITWeb, “New financial conduct Bill to turbocharge AI, open finance”. This article is general information and not legal advice.









