Artificial Intelligence in the South African financial Sector is a fast-growing use case. The way it will be regulated is noted in our earlier posts on the latest developments in AI regulation. South Africa will adopt a risk-based, technology-neutral and industry-specific approach. The focus of AI regulation will be on high-risk use cases rather than AI in general, with the idea being that existing legislation will apply where applicable. Where existing regulations cannot accommodate AI use cases, laws will be amended where needed. The South African National AI policy also mandates that industry bodies develop industry-specific standards and guidelines, and the FSCA AI report is a step in that direction.
An example of this practice is the Joint standards on cybersecurity and cyber resilience. It specifically applies to financial institutions, due to the high-risk nature of the sector.
AI in the South African financial sector is high-risk
AI in the South African financial sector is high-risk because it is highly regulated. Hence, regulators acted quickly after the release of the South African National AI policy and began their study. AI use is growing, illuminating existing and new risks for financial institutions. For example, AI models trained on large datasets raise the risk of identity fraud. This is an existing challenge with established risk management frameworks. However, AI tools are vulnerable to poisoning attacks, in which malicious actors “poison” training data. This means there is a Trojan horse in your system that a malicious actor can trigger at any time. Financial institutions also face more frequent and larger cyberattacks, including coordinated agentic persistent attacks. These are new risks that need risk management considerations.
The FSCA AI report aims to guide regulators, so expect these principles to become practical standards or guidelines.
Current regulations address many AI risks. However, stronger monitoring, updated policies, and better human oversight are still needed to maintain financial soundness.
Use cases for AI in the South African financial sector
The financial sector in South Africa quickly adopts new technologies, including AI. The FSCA AI report identified a wide range of AI use cases in the financial sector. For example, institutions use AI to predict default risk and expand credit access. Financial institutions also collect and process alternative data, such as mobile usage and utility bills, to make inferences. This helps them build a detailed client profile to guide decisions. However, these practices trigger Section 71 of POPIA, which protects individuals from automated profiling that may adversely affect them.
Lawful automated decision-making in this instance requires effective AI governance. People must be able to override automated decisions to prevent unfair outcomes, maintain fairness and prevent bias. More than that, humans need to be able to explain the AI tool’s decisions. This makes using explainable AI methods part of compliance, as it gives clear, auditable outputs for consumers and regulators.
Five things financial institutions can do today
The FSCA and PA have shared important lessons for setting up an AI governance framework in financial institutions.
- Establish the right team for AI governance to promote accountability for AI projects and properly manage AI risks. Take a coordinated approach to AI governance by working with the Information Officer to ensure compliance with data privacy rules.
- Focus on specific high-risk use cases first.
- Comply with existing legal duties with a special focus on POPIA and cybersecurity standards.
- In the absence of South African guidance, AI governance must uphold South Africa’s constitutional values and, where appropriate, incorporate international standards, such as the OECD AI Principles and the EU AI Act.
- Be transparent and clearly explain how AI systems work, what data they use, and any possible biases.
AI literacy is an important part of AI governance. Employee and consumer education and awareness allows organsaitions to get the most out of AI. Just think about it. An AI-literate personnel can effectively leverage AI to find innovative ways of doing things. And and AI literate user base can interact responsibly with AI products.
AI literacy is also a director due diligence under Section 76 of the Companies Act.
The road ahead for AI in the South African financial sector
Respondents to a survey conducted by the FSCA and PA identified several barriers to AI adoption. From a regulatory perspective, respondents highlighted the challenge of navigating existing laws that were not originally designed for AI. This problem is particularly relevant given the overlap between AI, data protection, and cybersecurity legal obligations. Without structured compliance with data protection and cybersecurity laws, organisations can face significant obstacles to effective AI governance.
To address these challenges, it’s a good idea to conduct a data protection and cybersecurity health check.
Actions you can take
According to the report, financial institutions can implement several specific actions and frameworks to ensure responsible AI governance.
- Brief the board on AI governance to ensure AI initiatives align with responsible practices and strategic goals.
- Establish the right team for AI governance to identify who is responsible for AI system outcomes and how those decisions are verified.
- Mitigate the risk of automated decisions by mandating human intervention points, especially in high-stakes scenarios such as credit scoring or fraud detection.
- Strengthen your POPIA and cybersecurity compliance by asking us to conduct a health check.
- Enhance transparency by asking us about how a trust centre builds consumer trust
- Manage third-party risks of AI projects and conduct thorough due diligence to assess the reliability and governance of third-party AI service providers