COFI status
Is the COFI Bill law yet, and what should an FSP do now?
Understand the 17 April 2026 notice, what it does not mean, and which readiness work is sensible before commencement.
Read the COFI status guideSouth African financial services information hub
The questions below reflect recurring search demand around COFI, FSCA licences, fit and proper requirements, CPD and FICA. Each answer separates what is in force from what is proposed and links back to the official source.
Featured guides
These guides answer the highest-intent questions with a checklist, status note and official source shelf.
COFI status
Understand the 17 April 2026 notice, what it does not mean, and which readiness work is sensible before commencement.
Read the COFI status guideFSCA licence maintenance
Use a defensible checklist across licence profile, people, competence, customer outcomes, reporting and public claims.
Open the FSP checklistFICA RMCP
Translate the FIC's requirements into a practical structure, evidence file and review rhythm.
Open the RMCP guideFrequently asked questions
The Conduct of Financial Institutions Bill is intended to create a consolidated and consistent conduct framework for licensed financial institutions, supervised entities and representatives. The official explanatory summary covers compliance arrangements, governance, transformation, fitness and propriety, advertising, disclosure, reporting and a consolidated licensing framework.
Source: Government Gazette 54520A notice of introduction and explanatory summary was published on 17 April 2026. That is a major legislative step, but it does not by itself make the Bill an Act in force. Continue meeting the laws, licence conditions and standards that apply now, and track the formal parliamentary and commencement process.
Read the full status explanationDo not plan around an unverified effective date. An effective date depends on the Bill completing the legislative process, being enacted, and the relevant commencement and transition arrangements being published. Use milestone-based planning instead of treating an industry forecast as law.
Build an activity and licence map, trace customer journeys and outcomes, document governance and accountability, review advertising and disclosures, and test whether representative, fit and proper, complaints and reporting evidence can be produced. Label this work as readiness until final obligations are known.
Use the FSCA's public FSP Search and compare the business name, FSP number, licence status and authorised categories with the service being offered. A licence reference on a website is not enough on its own.
Open the FSCA FSP SearchThe correct requirements depend on the financial service, product categories, business model, key individuals and operating structure. Start by mapping the proposed activities to the applicable licence categories, then build the governance, competence, operational ability and financial-soundness evidence for that application.
See licensing supportIt is the ongoing control of the licence profile, authorised categories, key individuals and representatives, fit and proper evidence, reporting, complaints, disclosures, FICA controls where applicable, and proof that changes were handled correctly.
Use the evidence checklistThe FSCA describes honesty, integrity and good standing; competence; continuous professional development; operational ability; and financial soundness. Competence includes experience, qualifications, regulatory examinations, class of business training and product-specific training.
Source: FSCA Fit and ProperKeep role and gap assessments, the selected CPD activities, attendance or completion evidence, competence register updates and proof that the learning was relevant to the person's functions. The evidence should show a controlled competence process, not only a collection of certificates.
An RMCP documents an accountable institution's money laundering, terrorist financing and proliferation financing risks and the controls used to manage them. It should reflect the institution's actual risk, clients, products, delivery channels and operations.
Source: FIC compliance obligationsThe FIC points to the institutional risk assessment, policy documents, governance, customer due diligence, sanctions and prominent-person controls, account monitoring, reporting and record keeping. The detail must be proportionate to the institution's business and risks.
Read the RMCP structure guideTreat it as a living control. Review it when risks, clients, products, services, delivery channels, systems, legislation or guidance change, and on a documented periodic cycle. Record what was reviewed, who approved the change and how it was implemented.
They can. A site may collect personal information through forms, analytics, cookies, applications or enquiries, while a private body may also have PAIA and information-officer obligations. The wording and controls must match what the business actually collects, why it collects it, who receives it and how requests are handled.
Source: Information Regulator FAQs