
South Africa’s regulatory landscape for financial services is changing. The proposed Conduct of Financial Institutions (COFI) framework reframes how firms are authorised and supervised: where the FAIS regime authorised financial services providers based primarily on the products they sold (insurance, investment products, long‑term savings, etc.), COFI shifts the focus to the activities firms perform, giving advice, bringing products to market, providing discretionary portfolio management, or acting as intermediary platforms. The practical effect is that firms will be regulated for what they do, not only for the product lines they carry. This has important consequences for verification and screening processes across the sector.
COFI’s reach is broad; it will cover banks, insurers, long‑term and short‑term insurers, asset managers, administrators, investment platforms, brokers, independent financial advisers, wealth managers, fintechs that facilitate advice or distribution, and any firm that conducts regulated financial activities (including outsourced service providers when they carry out regulated tasks).
In short, if your organisation gives advice, sells or arranges financial products, or makes discretionary decisions affecting clients’ money, COFI will apply.
COFI emphasises consumer protection, fair treatment, and the integrity of financial markets. To achieve that, regulators will require firms to demonstrate that their people, processes, and systems are fit for purpose. Verification is not merely HR due diligence; it is a governance imperative that supports conduct‑risk management, prevents fraud, ensures competence, and protects customers. Firms will need robust, auditable verification processes at onboarding, during employment, and across the lifecycle of client interactions.
Core verification processes that every affected firm should implement
- Verify employee identities using official identity documents and ensure that you can demonstrate work permits for non-citizen employees. These checks reduce the risk of impersonation and support KYC for client‑facing staff.
- COFI will require firms to ensure that staff in regulated roles are “fit and proper.” This includes criminal‑record checks, credit and insolvency screening for roles with financial responsibility, verification of previous employment, and checks for adverse media or regulatory sanctions. For senior managers and those in key control functions, enhanced vetting (including directorship checks, conflicts of interest, and lifestyle indicators) is appropriate given the potential impact of misconduct.
- Verify academic qualifications and professional licences directly with issuing institutions and regulatory bodies (e.g., SAICA, SAIPA, IISA, HPCSA, where relevant for employee roles intersecting with regulated professions). Under COFI, proof of competence and continuous professional development will be scrutinised, so firms should keep certified records and renewal alerts.
- Beyond static credential checks, firms must test competence through structured assessments, observed work samples, and role‑specific scenario testing (e.g., treating clients fairly in practice scenarios). Maintain records of training, assessments, and CPD to demonstrate ongoing capability.
- Screen employees and third parties against domestic and international sanctions, PEP lists, and regulatory enforcement databases. Firms must prevent the use of regulated functions by persons who present unacceptable conduct or reputational risk.
- Grant system access and transaction authorities in accordance with verified roles and segregation-of-duties principles. Verification should feed into identity and access management: no elevated privileges without enhanced vetting and documented approvals.
- Many firms outsource regulated activities. COFI will hold firms accountable for outsourced functions, meaning vendors and suppliers must be verified. Conduct supplier risk assessments, contractual controls, right-to-audit clauses, and ongoing monitoring of third-party performance and compliance.
- Verify relationships between staff, clients, and suppliers. Require declarations of interest, and screen for undisclosed business links or familial relationships that could compromise impartial advice or procurement.
- Verification is not a once‑off. Implement periodic re-screening for critical roles and event-triggered checks on promotion, transfer, disciplinary actions, or when staff move into higher-risk duties. Use automated alerts for licence expiry, criminal record updates, and adverse‑media mentions.
- All verification activities involve personal data and must comply with POPIA. Obtain informed consent, limit data collection to what is necessary, secure records, and define retention periods. Keep an auditable trail of who performed checks and when.
COFI’s focus on activities elevates the importance of verification in financial services. Firms will need to prove that the people who give advice, sell products, operate platforms, or make discretionary decisions are competent, honest, and properly supervised.
Verification processes must be systematic, proportionate, and auditable, combining identity checks, fit‑and‑proper screening, competency assessments, ongoing monitoring, and third‑party due diligence, all implemented with respect for POPIA and employment law. Organisations that adopt rigorous, risk‑based verification now will be better placed to meet COFI’s expectations, protect customers, and reduce conduct‑related risks as the regulatory regime evolves.
