FSCA Compliance Documentation for Financial Services Providers in South Africa
The FSCA regulates financial services providers under FAIS with extensive documentation requirements. Here's what's required, common on-site visit findings, and how to prepare.
The Financial Sector Conduct Authority (FSCA) regulates over 10,000 financial services providers (FSPs) in South Africa under the Financial Advisory and Intermediary Services Act (FAIS). Every FSP — from large insurance companies to independent financial advisers — must maintain documented compliance frameworks that the FSCA can inspect at any time.
FSCA on-site visits are thorough and documentation-focused. Inspectors don't just check that policies exist — they verify that policies are current, specific to the FSP's business, and supported by evidence of implementation. The gap between "we have a compliance manual" and "our compliance manual reflects our actual operations and we can prove it" is where most findings originate.
Core FAIS Documentation Requirements
1. Compliance Manual
The foundation of every FSP's compliance framework.
Must address:
| Section | Requirements |
|---|---|
| Regulatory framework | FAIS, FICA, POPIA, TCF, relevant sector-specific legislation |
| Organisational structure | Compliance function, key individuals, reporting lines |
| Licensing conditions | Category and subcategory of licence, conditions imposed |
| Fit and proper requirements | Honesty and integrity, competency, operational ability, financial soundness |
| Client engagement | Advice process, record of advice, disclosure requirements |
| Product supplier relationships | Mandates, commissions, conflicts of interest |
| Complaints management | Procedures aligned with FAIS and FSCA requirements |
| FICA/AML obligations | Customer due diligence, reporting obligations |
| Monitoring and reporting | Ongoing compliance monitoring, regulatory reporting |
| Training and development | CPD requirements, competency maintenance |
2. Conflict of Interest Management Policy
Required under the FAIS General Code of Conduct. Must be in writing and available to clients.
| Element | What to Document |
|---|---|
| Identification | All actual and potential conflicts of interest |
| Avoidance | Conflicts that cannot be managed and must be avoided |
| Mitigation | Measures to manage unavoidable conflicts |
| Disclosure | What is disclosed to clients, when, and how |
| Monitoring | How conflicts are monitored on an ongoing basis |
| Register | Gifts, entertainment, and third-party relationships register |
3. Record of Advice
For every financial product recommendation, the FSP must maintain a record of advice that includes:
| Element | Requirement |
|---|---|
| Client financial needs and objectives | Documented assessment of the client's situation |
| Products considered | Range of products evaluated |
| Recommendation and rationale | Why this specific product suits this specific client |
| Risk disclosure | Risks associated with the recommended product |
| Fees and charges | All costs disclosed to the client |
| Replacement policy disclosure | If replacing an existing product, comparison documented |
| Client signature | Acknowledgement of advice received |
Common finding: Records of advice that are generic templates with minimal client-specific information. The FSCA expects genuine, individualised advice documentation.
4. FICA/AML Documentation
FSPs must comply with the Financial Intelligence Centre Act (FICA) for anti-money laundering and counter-terrorist financing.
| Document | Requirement |
|---|---|
| Risk Management and Compliance Programme (RMCP) | Documented AML/CFT programme proportionate to the FSP's risk profile |
| Customer identification and verification | Per-client CDD records |
| Ongoing monitoring | Transaction monitoring procedures and records |
| Suspicious transaction reports | STR filing procedures and records |
| Training records | AML/CFT training for all relevant staff |
| Compliance officer appointment | Designated FICA compliance officer |
5. Treating Customers Fairly (TCF) Documentation
The FSCA's TCF framework requires documented evidence of fair customer outcomes across six outcomes:
| TCF Outcome | Documentation Required |
|---|---|
| 1. Culture | Evidence that fair treatment is embedded in the FSP's culture |
| 2. Products | Product design documentation demonstrating products meet identified needs |
| 3. Information | Clear, accurate, and timely information provided to clients |
| 4. Advice | Suitable advice based on client's circumstances |
| 5. Performance | Products perform as expected based on representations made |
| 6. Post-sale service | Accessible complaints and claims procedures |
6. Complaints Management Framework
| Document | Requirement |
|---|---|
| Complaints policy | Procedures for receiving, categorising, investigating, and resolving complaints |
| Complaints register | Log of all complaints with dates, descriptions, and outcomes |
| Resolution timeframes | Defined timeframes for acknowledgement, investigation, and resolution |
| Escalation procedures | When and how complaints escalate to the FAIS Ombud |
| Root cause analysis | Systematic analysis of complaint trends |
| Reporting | Internal and regulatory reporting of complaints data |
Common FSCA On-Site Visit Findings
Finding 1: Inadequate Records of Advice
The most frequently cited finding. Records that are templated rather than individualised, missing client financial needs analysis, or lacking clear rationale for the specific product recommendation.
Finding 2: Conflicts of Interest Policy Not Implemented
A policy exists on paper but conflicts are not actively identified, managed, or disclosed. No gifts register, no monitoring of third-party relationships, and no evidence of annual conflict reviews.
Finding 3: FICA Non-Compliance
Incomplete CDD records, missing risk assessments, no documented RMCP, or an RMCP that hasn't been updated for regulatory changes. The FIC conducts its own inspections in addition to FSCA visits.
Finding 4: CPD and Competency Gaps
Key individuals and representatives without complete CPD records, or CPD activities that don't meet the competency requirements for their specific categories and subcategories of licence.
Finding 5: Outdated Compliance Manual
Compliance manuals referencing superseded legislation, previous organisational structures, or products no longer offered. The FSCA expects annual reviews at minimum.
Reviewing FSCA Compliance Documentation
Record of Advice Review
| Criterion | Weight | What to Check |
|---|---|---|
| Client-specific analysis | 3 | Financial needs assessment reflects the individual client |
| Recommendation rationale | 3 | Clear link between client needs and specific product recommended |
| Risk disclosure | 2 | All material risks documented |
| Fee transparency | 2 | All fees and charges disclosed |
| Completeness | 2 | All FAIS General Code requirements met |
Compliance Manual Review
| Criterion | Weight | What to Check |
|---|---|---|
| Currency | 3 | References current legislation and regulatory guidance |
| Completeness | 3 | All required sections present |
| Specificity | 2 | Reflects the FSP's actual business model and products |
| TCF integration | 2 | TCF outcomes embedded throughout, not just a separate section |
| Practicality | 1 | Procedures are specific enough for staff to follow |
Frequently Asked Questions
How often does the FSCA conduct on-site visits?
Risk-based frequency. Higher-risk FSPs (large client base, complaints history, previous findings) are visited more frequently. All FSPs should be prepared for an on-site visit at any time. The FSCA also conducts thematic reviews targeting specific compliance areas across the industry.
What are the consequences of FSCA findings?
Depending on severity: recommendations requiring remediation within a defined period, administrative penalties, suspension or withdrawal of the FSP licence, or referral for criminal prosecution. The FSCA publishes enforcement actions — reputational impact can be severe, particularly for adviser-client trust.
How does the Conduct of Financial Institutions (CoFI) Bill affect documentation?
CoFI will consolidate and modernise financial services conduct regulation. FSPs should monitor CoFI developments and begin preparing for additional documentation requirements around product governance, distribution practices, and culture and governance standards. Documentation frameworks built now should be adaptable to CoFI requirements.
Can AI review help with FSCA compliance documentation?
AI review can check records of advice for completeness and client-specificity, verify compliance manuals address all required sections, check conflicts of interest policies for implementation evidence, and assess TCF documentation. Regulatory adequacy and advice suitability require qualified compliance professionals.
Key Takeaways
- FSCA on-site visits are documentation-focused — policies must be current, specific, and evidenced.
- Records of advice are the most inspected document — they must be individualised, not templated.
- Conflict of interest management requires active implementation — not just a policy document.
- FICA/AML compliance is a standalone requirement — the FIC inspects independently of the FSCA.
- TCF outcomes must be documented across the business — not just in a standalone TCF policy.
- Review documentation annually and after every significant regulatory change.
- AI review checks completeness, specificity, and consistency — regulatory adequacy requires qualified professionals.
This article is for informational purposes only. FSCA regulatory requirements are complex and evolve through legislation, regulations, and guidance notices. Consult a qualified compliance professional for guidance specific to your FSP's licence categories and business model.