Artificial Intelligence and Compliance in South African Financial Services: What Every Compliance Professional Should Be Thinking About.

Artificial Intelligence (AI) is no longer a future consideration for financial institutions. It is already embedded across different processes such as in giving financial advice, offering customer service, fraud detection, anti-money laundering (AML), underwriting, claims management and marketing.

The question is no longer whether AI will impact the financial services industry, It is whether governance frameworks are evolving quickly enough to manage the risks associated with it. The responsibility of Compliance and Risk professionals is not only to identify and mitigate risk, but also to enable responsible innovation while safeguarding customer outcomes and market integrity.

Across the financial services sector, employees are already using tools such as ChatGPT, Microsoft Copilot, Gemini, and Claude to draft communications, analyse data, summarise reports, and support decision-making. In many organisations, this adoption has occurred informally. Employees begin experimenting with AI tools long before governance frameworks, policies, or risk assessments are fully developed. This has led to the rise of what is increasingly being referred to as “shadow AI”, which poses data privacy and accuracy risks to organisations as employees upload client information into public tools, rely on AI-generated interpretations of regulations, or distribute AI-assisted outputs without validation.

Although South Africa does not yet have a standalone AI regulatory framework, existing legislation already imposes clear obligations on financial institutions. Key frameworks include the FAIS Act, Financial Sector Regulation Act, FICA, POPIA, the Insurance Acts, Treating Customers Fairly (TCF) principles, and Joint Standards issued by the FSCA and Prudential Authority, with COFI expected to further strengthen conduct obligations.

A practical starting point for compliance teams is visibility. Many organisations do not yet have a complete understanding of what AI tools are in use, who is using them, what data is being processed, and which decisions are influenced by AI. Without this visibility, effective governance is not possible.

The second is data protection. AI systems rely on large volumes of data, and the inappropriate use of personal information presents one of the most immediate risks. POPIA requires that personal data is processed lawfully and securely. Compliance teams must understand whether customer information is being shared with AI tools, how vendors handle that data, and whether cross-border transfers are taking place.

The third is explainability. Where AI influences decisions such as underwriting, claims assessments, customer segmentation, fraud detection, or AML monitoring, organisations must be able to explain those outcomes. Decisions that cannot be explained will be difficult to defend in regulatory, legal, or customer-facing contexts.

The fourth is accountability. AI does not shift responsibility. If outcomes are biased, inaccurate, or misleading, accountability remains with the institution and its leadership. The presence of technology does not dilute this obligation.

The fifth is governance at the highest level. AI is no longer purely a technology issue. There is a growing expectation that boards and senior management understand AI use, associated risks, and the controls in place to manage them.

At Maksure, the approach to AI has been deliberate and forward-looking. Recognising that capability building is critical, a cohort of employees was sponsored to attend Henley Business School, where one of the focus areas included artificial intelligence. This initiative has contributed to building foundational understanding and encouraging critical engagement with how AI applies within a financial services and insurance brokerage environment.

In addition, Maksure has established a group of AI champions who are actively researching how AI can be implemented responsibly across the business. The focus is not only on identifying practical applications, but on ensuring that governance, ethics, and regulatory alignment remain central to any adoption. This reflects a broader commitment to engaging with AI proactively, rather than reactively, and ensuring that innovation is supported by appropriate oversight.

The role of compliance remains unchanged: to identify risk, provide independent oversight, protect customers, and support responsible growth. What is changing is the context in which that role is performed. As AI becomes more deeply embedded in financial services, the responsibility to ensure that its use is ethical, transparent, and accountable becomes increasingly important. The future of compliance is not human versus AI. It is human judgement governing AI responsibly.

Lethubuhle Geraldine Ncube, AML CPRAC (SA), is a seasoned legal and compliance professional holding Category I, II, IIA, and IV approvals across South African financial services. With a background in law and management practice, she writes on the changing dynamics of financial regulation, emerging risk management, and practical strategies for integrating AI into the modern compliance toolkit.

Maksure Risk Solutions is an Afro-Global independent specialist insurance and reinsurance broker with business footprint in Africa, Asia, East & Western Europe, South America and the Caribbean. We provide innovative and tailor-made risk solutions in Insurance and Reinsurance as well as Risk Financing and Actuarial Consulting geared towards capital management and strengthening our client’s balance sheet. Maksure is also one of the major players in Captive Management (Establishment & Management) in South Africa, Mauritius, Bermuda and various other jurisdictions. We have access into the Lloyds of London with a deep understanding of African markets. Our global nature ensures that our clients access quality capacity as well as some of the world’s latest thinking and solutions.

Ramolodi Madikane

Account Executive : Corporate and Global Markets