South African financial services information hub

Clear answers. Primary sources. Practical next actions.

The questions below reflect recurring search demand around COFI, FSCA licences, fit and proper requirements, CPD and FICA. Each answer separates what is in force from what is proposed and links back to the official source.

Last reviewed 1 September 2026 Primary sources first Monthly formal review

Featured guides

These guides answer the highest-intent questions with a checklist, status note and official source shelf.

COFI status

Is the COFI Bill law yet, and what should an FSP do now?

Understand the 17 April 2026 notice, what it does not mean, and which readiness work is sensible before commencement.

Read the COFI status guide

FSCA licence maintenance

What evidence should an FSP keep current?

Use a defensible checklist across licence profile, people, competence, customer outcomes, reporting and public claims.

Open the FSP checklist

FICA RMCP

What belongs in a risk management and compliance programme?

Translate the FIC's requirements into a practical structure, evidence file and review rhythm.

Open the RMCP guide

Frequently asked questions

The questions people are searching for.

COFI Bill

What is the COFI Bill in South Africa?

The Conduct of Financial Institutions Bill is intended to create a consolidated and consistent conduct framework for licensed financial institutions, supervised entities and representatives. The official explanatory summary covers compliance arrangements, governance, transformation, fitness and propriety, advertising, disclosure, reporting and a consolidated licensing framework.

Source: Government Gazette 54520
Is the COFI Bill law yet?

A notice of introduction and explanatory summary was published on 17 April 2026. That is a major legislative step, but it does not by itself make the Bill an Act in force. The FSCA's 2026 three-year Regulation Plan is a roadmap, not a commencement notice. Continue meeting the laws, licence conditions and standards that apply now, and track the formal parliamentary and commencement process.

Read the full status explanation Source: FSCA 2026 three-year Regulation Plan
When will the COFI Bill take effect?

Do not plan around an unverified effective date. An effective date depends on the Bill completing the legislative process, being enacted, and the relevant commencement and transition arrangements being published. Use milestone-based planning instead of treating an industry forecast as law.

What should an FSP do now to prepare for COFI?

Build an activity and licence map, trace customer journeys and outcomes, document governance and accountability, review advertising and disclosures, and test whether representative, fit and proper, complaints and reporting evidence can be produced. Label this work as readiness until final obligations are known.

FSCA licensing

How do I check whether an FSP is licensed by the FSCA?

Open the official FSCA FSP Search and search by the FSP number first, or by the business name if the number is not available. Match the result to the exact legal or trading name and FSP number being used.

Then compare the authorised categories with the product, advice or intermediary service being offered. A number printed on a website or message is only a claim until it matches the FSCA record. If the name, number or category does not match, pause the transaction and verify it through the FSCA's official channels.

Open the official FSCA FSP Search
What are the requirements for an FSCA licence application?

The correct requirements depend on the financial service, product categories, business model, key individuals and operating structure. Start by mapping the proposed activities to the applicable licence categories, then build the governance, competence, operational ability and financial-soundness evidence for that application.

See licensing support
What does FSCA licence maintenance include?

It is the ongoing control of the licence profile, authorised categories, key individuals and representatives, fit and proper evidence, reporting, complaints, disclosures, FICA controls where applicable, and proof that changes were handled correctly.

Use the evidence checklist

Fit & Proper and CPD

What are the FSCA fit and proper requirements?

The FSCA describes honesty, integrity and good standing; competence; continuous professional development; operational ability; and financial soundness. Competence includes experience, qualifications, regulatory examinations, class of business training and product-specific training.

Source: FSCA Fit and Proper
Who must complete the FSCA regulatory examinations?

The applicable examination follows the person's regulated role and the FSP's licence category. RE1 applies to FSPs, key individuals and compliance officers across Categories I, II, IIA, III and IV. FSPs and key individuals in Categories II and IIA must also complete RE3, while those in Category III must also complete RE4.

RE5 applies to representatives across FSP categories, subject to the exceptions stated by the FSCA for certain funeral and friendly-society benefits, Tier 2-only services and execution-of-sales-only roles. Confirm the person's actual appointment, category and any applicable exception before selecting an exam.

Source: official FSCA regulatory-examination FAQ
What evidence should an FSP keep for CPD?

Keep role and gap assessments, the selected CPD activities, attendance or completion evidence, competence register updates and proof that the learning was relevant to the person's functions. The evidence should show a controlled competence process, not only a collection of certificates.

FICA and RMCP

What is an RMCP under FICA?

An RMCP documents an accountable institution's money laundering, terrorist financing and proliferation financing risks and the controls used to manage them. It should reflect the institution's actual risk, clients, products, delivery channels and operations.

Source: FIC compliance obligations
What must an RMCP contain?

The FIC points to the institutional risk assessment, policy documents, governance, customer due diligence, sanctions and prominent-person controls, account monitoring, reporting and record keeping. The detail must be proportionate to the institution's business and risks.

Read the RMCP structure guide
How often should an RMCP be reviewed?

Treat it as a living control. Review it when risks, clients, products, services, delivery channels, systems, legislation or guidance change, and on a documented periodic cycle. Record what was reviewed, who approved the change and how it was implemented.

POPIA, PAIA and websites

Do POPIA and PAIA apply to an FSP website?

They can. A site may collect personal information through forms, analytics, cookies, applications or enquiries, while a private body may also have PAIA and information-officer obligations. The wording and controls must match what the business actually collects, why it collects it, who receives it and how requests are handled.

Source: Information Regulator FAQs