It’s that time of year in South Africa; no, not autumn – it’s school sports festival time! You might only see us again in May…
However, our regulators have decided to keep us pretty busy with various draft changes to legislation – clearly they’re not sports fans.
From changes in the anti-money laundering frameworks to rules around private medical information, there is plenty to get on top of this month.
THE FINANCIAL SECTOR CONDUCT AUTHORITY (FSCA)
FSCA leadership reappointments confirmed
Finance Minister Enoch Godongwana has confirmed the reappointment of Unathi Kamlana as Commissioner of the FSCA for a further five-year term, effective from 1 June 2026 to 31 May 2031. Kamlana has led the market conduct regulator since June 2021 and is responsible for the FSCA’s regulatory strategy, organisational leadership, and oversight of its day-to-day operations.
The minister also reappointed Deputy Commissioners Katherine Gibson and Farzana Badat for additional five-year terms beginning in September 2026 and December 2026 respectively. Gibson oversees Regulatory Policy and Enforcement, while Badat is responsible for Conduct of Business Supervision and the Licensing and Business Centre.
Deputy Commissioner Astrid Ludin will step down at the end of her term on 31 May 2026. The minister indicated that the process to appoint her replacement, as well as a fourth Deputy Commissioner, will commence shortly.
FSCA regulatory actions
The FSCA took the following regulatory actions and published the results:
Mareo Nel was fined R1 million and banned for 15 years for providing unauthorised financial services. Nel traded forex derivatives without proper authorisation.
Key persons of N-e-FG were fined and banned for up to 30 years after it was found that they had invested clients’ funds without proper authorisation and in unregulated entities. The investigation revealed conflicts of interest and breaches of financial regulations. The FSCA may assist with related criminal cases.
Maudi Martin Lentsoane was debarred for 12 years and Lehumо Securities was fined R1 million as well as the firm’s licence also being revoked after complaints from clients and regulatory breaches. They are now banned from providing financial services or acting as key persons in financial institutions.
Gundo Wealth Solutions and Ralliom Razwinane were found guilty of breaching financial laws and giving improper investment advice. Razwinane was fined R3 million, banned from financial services for 10 years, and Gundo Wealth’s licence lapsed after liquidation.
Adell van Wyk was fined R1 million and banned for 15 years, and Wenru (Pty) Ltd was fined R100,000 for processing payments without client consent.
Shaheen Khan was fined R4.5 million and banned for 10 years for unauthorised financial services.
Luan Krige was fined and banned for 10 years for providing unauthorised forex trading advice, violating the FAIS Act.
The FSCA investigated BHI Trust and Craig Roy Warriner for unauthorised financial services from 2013–2023. Warriner was banned for 30 years from financial services roles.
F A Allard and Sons Funeral Undertakers, Mr Allard, and Mrs Roberts were fined for running unregistered insurance and financial services. Penalties totalled R120,000. The business has since complied.
The FSCA found the Praesidium Group and its directors breached financial laws, operated without proper licences, and misused client funds, resembling a Ponzi scheme. Key individuals were banned from the industry and fined. The matter will be reported to criminal authorities for likely fraud and theft.
Poneso Employee Benefits and Poneso Consulting were fined R200,000 each for not keeping client funds separate from March 2016 to October 2018, violating financial sector rules. Both companies have since corrected the issue.
FSCA Information Request 1 of 2026
The FSCA issued Information Request 1 of 2026, requiring all licensed non-life insurers that are members of the National Financial Ombud Scheme (NFO) to submit detailed data on personal lines claims reported during the 2025 calendar year.
This annual data collection supports both the NFO’s Annual Report and the FSCA’s supervisory mandate to monitor and promote fair customer outcomes. Insurers must upload the required information via the Conduct of Business Upload facility on the FSCA’s website no later than 10 April 2026.
The Conduct of Business Upload facility can be accessed by following this path: Home < Regulated Entities < E-Services < Insurer / Microinsurer < Conduct of Business Upload facility < Login with registered credentials < Go to Submission < Select a submission from the drop-down box < Select “NFO Claims 2025”.
FINANCIAL INTELLIGENCE CENTRE
Guidance on special-purpose vehicles
The Financial Intelligence Centre (FIC) has released Draft Public Compliance Communication 122 (PCC 122), offering long awaited guidance on how the FIC Act applies to special-purpose vehicles (SPVs) that qualify as accountable institutions under Item 11 of Schedule 1. SPVs are created as distinct, legally independent companies by a parent organisation to isolate financial risk or manage specific assets.
PCC 122 clarifies the characteristics of SPVs, their accountability under the FIC Act, and the practical challenges they face, particularly where SPVs operate with limited or no internal staff. The draft emphasises that both passive and operative SPVs remain fully responsible for AML/CFT/CPF compliance, regardless of outsourcing, group structures, or operational capacity.
SPVs conducting credit provision or similar Schedule 1 activities must register independently with the FIC, even when operating within a group structure.
Delegation structures on the goAML platform may be permitted for passive SPVs linked to a parent institution through ownership or mutual control, allowing the parent to support customer due diligence, reporting, and monitoring functions.
SPVs must maintain their own Risk Management and Compliance Programme aligned to group frameworks but tailored to the SPV’s specific money laundering (ML) / terrorist financing (TF) / proliferation financing (PF) risk profile.
The FIC outlines several risk indicators and expects SPVs to demonstrate robust governance, even where operational functions are performed by the parent institution.
Draft Directive 11: New FIC Risk and Compliance Return requirement
The FIC has released Draft Directive 11 (2026) for consultation. The Directive introduces a mandatory Risk and Compliance Return (RCR) for specified accountable institutions under Schedule 1 of the FIC Act.
The requirement applies to the following institutions: Legal practitioners, trust and company service providers, property practitioners, gambling businesses, credit providers (excluding banks), Postbank, high-value goods dealers, the SA Mint Company, and crypto asset service providers (CASPs).
Banks, mutual banks, and co-operative banks acting as credit providers are explicitly excluded.
The RCR will collect institution-level information to help the FIC understand ML, TF, and PF risks as well as strengthen its risk-based supervisory approach and improve monitoring across financial and non-financial sectors.
Depending on the institution type, the RCR covers one of two periods:
- 1 April 2023 – 31 March 2026 (legal practitioners, trust and company service providers, property practitioners, and gambling businesses)
- 1 July 2023 – 31 March 2026 (credit providers (excluding banks), Postbank, high-value goods dealers, the SA Mint Company, and CASPs)
The proposed submission deadlines are
- 30 April 2026 by 17:00: For trust and company service providers, gambling businesses (casinos), credit providers, Postbank, SA Mint Company, and CASPs.
- 30 May 2026 by 17:00: For legal practitioners, property practitioners, gambling businesses (non-casinos), and high-value goods dealers.
The RCR is an automated electronic return, completed directly on the FIC’s designated RCR platform. Institutions must answer all questions based on their ML/TF/PF risk understanding and current risk‑based controls.
Draft PCC 5E – Updated registration requirements
The FIC released Draft Public Compliance Communication 5E (PCC 5E), providing updated guidance on registration requirements for accountable institutions under section 43B of the Financial Intelligence Centre Act.
The draft replaces PCC 5D and introduces enhanced guidance aligned with Draft Directive 10 of 2025, which requires institutions to submit detailed geographic information on their local and international head offices, branches, and subsidiaries via the FIC’s online platform.
Registration with the FIC remains a mandatory legal obligation for all accountable institutions, with non-compliance potentially resulting in administrative sanctions. The PCC emphasises that each accountable institution, whether part of a group, division, or operating across multiple business lines, must register appropriately, often requiring separate registrations.
Most importantly, existing institutions will be required to update their registration details within 90 days of Draft Directive 10 coming into effect.
PRUDENTIAL AUTHORITY (PA)
Banks Directive D1 of 2026 (Governance Tenure)
The PA issued Directive D1 of 2026, replacing Directive 4 of 2018, introducing enhanced corporate governance requirements for banks, with a particular focus on board independence and director tenure.
The Directive strengthens expectations around the appointment and ongoing suitability of directors and executive officers, requiring institutions to implement robust board-approved governance policies that promote independence, effective oversight, and sound decision-making.
A key development is the formal clarification of tenure limits for independent non-executive directors, who will generally cease to be regarded as independent after nine years of service, unless an exceptional extension (up to 24 months) is approved by the PA.
Additional requirements include stricter cooling-off periods, clearer criteria for determining independence, enhanced processes for director selection and assessment, and stronger safeguards against conflicts of interest. Board and committee chairpersons are expected to be independent non-executive directors, subject only to limited regulatory exemptions.
The Directive aligns South African banking governance standards with evolving Basel Committee, OECD, and local governance principles, while anticipating the forthcoming Joint Governance Standard being developed by the PA and the FSCA to harmonise governance requirements across the financial sector.
Banks and controlling companies will be assessed on implementation as part of ongoing supervisory reviews, with remediation required where governance deficiencies are identified.
PA fees – 2026
The PA notified the industry of its revised fees on 2 March 2026. The notice confirms that fees are inclusive of VAT (which is often an issue) and breaks down the amounts for the specific transactions.
The amounts can be pretty “eye-watering”, given that the fees are applicable at product provider, market infrastructure, and controlling company level!
Proposed Directive on banking reporting requirements
The PA has issued a Proposed Directive outlining updated reporting obligations for auditors of banks, controlling companies, and branches of foreign institutions under Regulation 46 of the Regulations relating to banks. The Directive clarifies which BA returns must be audited, reviewed, or subject to limited assurance engagements, reflecting amendments to the Regulations that took effect on 1 July 2025.
The updated framework aligns the required audit work with the latest illustrative regulatory reports issued by the Independent Regulatory Board for Auditors (IRBA), covering both South African and foreign operations. These reports span audit, review, and limited assurance engagements across various BA return categories.
Auditors will be required to follow a detailed audit matrix when submitting reports for financial years ending on or after 1 July 2025, ensuring consistency with IRBA’s approved report formats.
INFORMATION REGULATOR (IR)
New regulations on the processing of health information under POPIA
The South African Information Regulator has published new regulations under the Protection of Personal Information Act, 2013 (POPIA), governing how certain institutions may process the health information of data subjects. The regulations were published in the Government Gazette on 6 March 2026 and came into effect immediately upon publication.
The regulations aim to clarify the interpretation of section 32(6) of POPIA, which deals with the processing of health-related personal information, and provide the IR with a clearer framework for enforcing compliance in relation to the processing of health information.
The regulations apply to organisations involved in health-related data processing, including: insurance companies, medical schemes, medical scheme administrators, managed healthcare organisations, pension funds, employers and administrative bodies, and institutions acting on behalf of these entities.
This means that many organisations in the insurance, healthcare funding, and employee benefits sectors will need to review their data handling practices.
The regulations reinforce and operationalise existing POPIA obligations, including:
- Restrictions on processing special personal information
Health information remains classified as special personal information, meaning it may only be processed under the conditions permitted by POPIA.
- Mandatory security safeguards
Responsible parties must implement appropriate technical and organisational measures to ensure confidentiality and integrity of health records, as well as protection against loss, damage, unauthorised destruction, or unlawful access. This entails the secure handling of both physical and electronic health records and proper disposal procedures to prevent unauthorised disclosure after records are destroyed.
- Confidentiality obligations
Processing must occur under a duty of confidentiality, whether arising from law, professional obligations, employment, or contractual agreements.
- Cross-border data transfers
Health information may not be transferred outside South Africa unless the requirements for international data transfers in POPIA (section 72) are satisfied.
Organisations should review their information security controls as well as their data governance policies for health information and cross-border data transfer arrangements. Contracts with operators and service providers handling health data should also be reviewed.
A-PROOFED
There’s a moment, usually just before a document goes out, when someone asks, “Has everyone read this?”
And, almost without fail, the answer is yes.
There may be a pause. A few nods. Someone scrolls quickly through the last page, just to be safe. But broadly speaking, the room agrees. It’s been read.
What’s rarely said out loud is this: Everyone has looked at it. Not everyone has seen it.
Because by the time a document reaches that stage, it’s already familiar. The key points have been discussed. The structure is known. The sentences feel predictable. The brain fills in the gaps before the eyes have fully done their job.
So the reading becomes lighter.
A paragraph is skimmed because it “looks right.”
A sentence is accepted because it “sounds fine.”
A figure is trusted because it was correct in the previous version.
And in that very efficient, very human process, small things slip through.
Not dramatic errors. Nothing that leaps off the page. Just the kind of details that sit quietly and wait. A word that has been used twice. A line that no longer quite matches the section above it. A sentence that made sense in an earlier draft, but now reads slightly differently. A version number that belongs to last week.
No one notices, because everyone has already understood what the document is supposed to say.
And that is the problem.
Because once the document leaves the building, it’s read by someone who doesn’t have that context. Someone who wasn’t in the discussion. Someone who doesn’t know what the sentence was meant to mean.
They only have what is on the page.
This is where things start to get interesting.
A small ambiguity becomes a genuine question. A slightly unclear instruction becomes a follow-up email. A missing detail becomes a delay.
And suddenly, a document that felt clear internally begins to create friction externally.
Not because the content was wrong, but because it was never seen with completely fresh eyes.
Proofreading is, in many ways, the only stage in the process where a document is treated as new again.
It’s the point at which familiarity is set aside, and every word is asked, quietly and without assumption, “Is this actually what you mean?”
It’s slower than a final skim. Slightly more pedantic. Occasionally inconvenient.
But it’s also the difference between a document that feels finished, and one that is finished.
A proofreader’s role isn’t to rewrite or reinterpret, but to see what has become invisible to everyone else in the room.
Because “everyone has read it” is not quite the same as “nothing has been missed.”
A-Proofed
Fresh eyes for documents that are too familiar.
Let’s talk.
083 657 3377 | kim@a-proofed.co.za
www.a-proofed.co.za



