Insights

SA Banks With London Desks Face Three AI Governance Regimes and No Integration

South Africa’s major banking groups all run FCA-authorised operations in the City, and every one of them answers to Johannesburg for the same models.

Standard Advisory London Limited sits on the FCA Register with around 150 staff across investment banking, transactional products and client service. Absa Securities United Kingdom Limited holds authorisation. Investec Bank PLC is FCA-regulated. Nedbank has traded from London since 1906. All of them also answer to the JSE and the Prudential Authority at home, and the moment a trade touches an EU counterparty through correspondent banking or a subsidiary relationship, the AI Act joins the conversation.

Research and drafting for this article were AI-assisted. Every figure is linked inline to the source that published it. Editorial responsibility is mine.

Silhouette skylines of Johannesburg and the City of London against a dark navy background, with overlapping gold and electric-blue circles glowing where the two skylines meet, representing converging AI governance regimes.
Produced by Gemini-Nano-Banana

So a head of trading with desks in both cities carries three concurrent AI governance regimes. They do not conflict on paper, which is what makes the problem easy to miss. They disagree about something more fundamental: who, exactly, is answerable when a model goes wrong.

Three illustrated towers labelled firm, individual and system: a gold tower patterned with building silhouettes, a white tower filled with rows of tiny human figures, and a blue tower filled with mechanical gears.
Produced by Gemini-Nano-Banana

Three Theories of Who Is Responsible

The JSE moved its algorithmic trading and market-access requirements into the rulebook proper in May 2026, with senior management accountability for design, testing and monitoring, and brokers carrying responsibility for client activity reaching the market through their access. The theory is firm-level accountability underneath exchange-level surveillance. The firm governs its algorithm; the exchange watches the market.

The FCA works the other way. Under the senior managers regime, reformed by PS26/6 in April 2026, it is not sufficient that the firm has arrangements. A named individual is answerable for the AI operating inside their area, and Ropes & Gray reads the current direction as a shift from asking whether a framework exists to asking whether it works. The joint statement issued on 15 May 2026 by the Bank, the FCA and the Treasury raised that bar again, requiring boards and senior management to show sufficient understanding of frontier AI risk and arrangements that operate effectively in practice.

The AI Act is not interested in either. It attaches obligations to the system. Creditworthiness assessment and credit scoring sit in Annex III, which brings conformity assessment, technical documentation, registration in the EU database and human oversight requirements with them. The duty follows the model, not the firm and not the person.

Firm-level. Individual. System-level. Three architectures of responsibility, generating three sign-off chains and three sets of documentation over one piece of code.

Abstract diagram of a glowing blue central hub connected to four branching paths of stylised document icons in gold, pale blue and white, representing one model generating separate evidence packs for different regulatory audiences.
Produced by Gemini-Nano-Banana

One Model, Three Evidence Packs

Take a concrete case. A London desk prices counterparty credit risk on a trade with a European bank using a machine learning model. That single model can:

  • fall inside the JSE requirements where it shapes execution parameters on the exchange
  • create individual accountability in London for the function holder who owns the desk
  • trigger Annex III obligations where it performs creditworthiness assessment on an EU natural person

Each regime wants evidence of governance. None wants the same evidence.

The exchange wants pre-trade control documentation, design records, testing logs and management sign-off. The FCA wants proof that a named individual understands the system, holds adequate oversight arrangements, and can show those arrangements functioning rather than existing. Brussels wants a conformity assessment, technical documentation, a quality management system and a database entry.

Three teams, three documentation standards, three audit cycles, one model underneath all of it.

Now add the domestic layer, which is the part most cross-border analyses leave out. The SARB and FSCA joint study published in November 2025 put banks ahead of the local market on adoption, at 52%, while noting that most independent validation functions have not built machine learning capability internally. The Prudential Authority’s D12-2025 roadmap requires written sign-off in advance of any material change to an internal model, and a retraining run is a material change.

A bank that cannot validate a model at home is not in a position to evidence it to three supervisors abroad.

The Deadline That Might Move, and Might Not

There is a live uncertainty here that firms are quietly using as a reason to wait, and it does not bear the weight being put on it.

Under the Digital Omnibus provisional agreement, Annex III high-risk deadlines would be deferred to 2 December 2027. That agreement has not been formally adopted or published in the Official Journal. Until it is, the binding date in the Regulation as enacted remains 2 August 2026.

So the planning position is a fork, not a delay. Either sixteen months of extra runway, or a deadline that has already passed by the time most firms finish arguing about it. A treasury function would hedge that exposure without being asked twice. Compliance functions, in my experience, tend to pick the branch they prefer and build a plan around it.

Three classical stone columns, one gold, one white marble and one blue, each fracturing at the same point with sparks flying, illustrating three governance structures cracking under the same pressure.
Produced by Gemini-Nano-Banana

Why Splitting It Across Three Teams Fails

The instinctive organisational answer is to hand each regime to whoever is closest to it. Market risk takes the exchange rules. London compliance takes the senior managers regime. A project team takes Annex III. That is roughly how every firm I have looked at is currently arranged.

It breaks at the first model change.

The regimes interact at the level of the artefact, not the org chart. A material retraining triggers obligations under all three at once. If the Johannesburg team approves an updated model without telling London, the individual accountability chain in London is broken before anyone notices, because the named person is now answerable for a system they did not sign off. If the conformity assessment was performed against a version that has since been retrained under the PA’s process, the assessment describes something that no longer exists.

None of those failures show up in any single team’s controls. They are failures of the joins, and joins have no owner.

A single gold bar at the top with three blue arrows pointing down to three separate coloured squares, representing one AI model's oversight being split across three disconnected teams.
Produced by Gemini-Nano-Banana

The only structure that survives is a layer sitting above all three: one model inventory, one change-management process, one evidence repository capable of generating whichever documentation set a given supervisor asks for from a common record. That is not best practice. It is the minimum that can be made to work.

The Constraint Is People, Not Law

Cross-border AI governance reads like a legal problem and behaves like a capacity problem.

Cliffe Dekker Hofmeyr’s reading of the SARB and FSCA data found 53% of financial institution staff without sufficient AI training. Globally, the Cambridge alternative finance centre put 48% of regulatory authorities as still exploring AI or not engaged with it at all. The May joint statement acknowledged that frontier capabilities already exceed what skilled practitioners can do unaided.

A desk in this position needs someone who can work the exchange rulebook, articulate individual accountability for a model under UK rules, prepare an Annex III conformity assessment, and translate between all three when the same model serves every jurisdiction at once.

Those people are rare enough that the Big 4 have absorbed most of them into practices priced for global banks rather than for the South African corporate and investment banking operations that need them most.

An hourglass with gold sand falling past glowing blue icons of shields, gears and scales of justice, representing the narrowing time before overlapping AI governance deadlines converge.
Produced by Gemini-Nano-Banana

Build Once or Build Three Times

The timelines are converging whether or not anyone is ready. The exchange rules are live. The FCA’s practical guidance is expected before the end of 2026. Annex III arrives in August 2026 or December 2027 depending on a legislative process nobody controls. The SARB and FSCA have signalled AI Joint Standards with no date attached.

A firm that maps each AI system against every applicable regime now, marking where obligations converge and where they pull apart, builds the evidence base once and reuses it three times.

A firm that waits builds it three times under pressure, with three sets of examiners already asking questions, and discovers the contradictions in front of the people least inclined to be relaxed about them.

That choice is still open. It closes on somebody else’s timetable.

Regulatory position as at July 2026. The Digital Omnibus had not been formally adopted at that date, so the enacted August 2026 deadline still applied.

Source List

AI GovernanceCross-borderFinancial Services