SA Banks With London Desks Face Three AI Governance Regimes and No Integration
South Africa’s major banking groups all run FCA-authorised operations in the City, and every one of them answers to Johannesburg for the same models.
Standard Advisory London Limited sits on the FCA Register with around 150 staff across investment banking, transactional products and client service. Absa Securities United Kingdom Limited holds authorisation. Investec Bank PLC is FCA-regulated. Nedbank has traded from London since 1906. All of them also answer to the JSE and the Prudential Authority at home, and the moment a trade touches an EU counterparty through correspondent banking or a subsidiary relationship, the AI Act joins the conversation.
Research and drafting for this article were AI-assisted. Every figure is linked inline to the source that published it. Editorial responsibility is mine.
So a head of trading with desks in both cities carries three concurrent AI governance regimes. They do not conflict on paper, which is what makes the problem easy to miss. They disagree about something more fundamental: who, exactly, is answerable when a model goes wrong.
Three Theories of Who Is Responsible
The JSE moved its algorithmic trading and market-access requirements into the rulebook proper in May 2026, with senior management accountability for design, testing and monitoring, and brokers carrying responsibility for client activity reaching the market through their access. The theory is firm-level accountability underneath exchange-level surveillance. The firm governs its algorithm; the exchange watches the market.
The FCA works the other way. Under the senior managers regime, reformed by PS26/6 in April 2026, it is not sufficient that the firm has arrangements. A named individual is answerable for the AI operating inside their area, and Ropes & Gray reads the current direction as a shift from asking whether a framework exists to asking whether it works. The joint statement issued on 15 May 2026 by the Bank, the FCA and the Treasury raised that bar again, requiring boards and senior management to show sufficient understanding of frontier AI risk and arrangements that operate effectively in practice.
The AI Act is not interested in either. It attaches obligations to the system. Creditworthiness assessment and credit scoring sit in Annex III, which brings conformity assessment, technical documentation, registration in the EU database and human oversight requirements with them. The duty follows the model, not the firm and not the person.
Firm-level. Individual. System-level. Three architectures of responsibility, generating three sign-off chains and three sets of documentation over one piece of code.
One Model, Three Evidence Packs
Take a concrete case. A London desk prices counterparty credit risk on a trade with a European bank using a machine learning model. That single model can:
- fall inside the JSE requirements where it shapes execution parameters on the exchange
- create individual accountability in London for the function holder who owns the desk
- trigger Annex III obligations where it performs creditworthiness assessment on an EU natural person
Each regime wants evidence of governance. None wants the same evidence.
The exchange wants pre-trade control documentation, design records, testing logs and management sign-off. The FCA wants proof that a named individual understands the system, holds adequate oversight arrangements, and can show those arrangements functioning rather than existing. Brussels wants a conformity assessment, technical documentation, a quality management system and a database entry.
Three teams, three documentation standards, three audit cycles, one model underneath all of it.
Now add the domestic layer, which is the part most cross-border analyses leave out. The SARB and FSCA joint study published in November 2025 put banks ahead of the local market on adoption, at 52%, while noting that most independent validation functions have not built machine learning capability internally. The Prudential Authority’s D12-2025 roadmap requires written sign-off in advance of any material change to an internal model, and a retraining run is a material change.
A bank that cannot validate a model at home is not in a position to evidence it to three supervisors abroad.
The Deadline That Might Move, and Might Not
There is a live uncertainty here that firms are quietly using as a reason to wait, and it does not bear the weight being put on it.
Under the Digital Omnibus provisional agreement, Annex III high-risk deadlines would be deferred to 2 December 2027. That agreement has not been formally adopted or published in the Official Journal. Until it is, the binding date in the Regulation as enacted remains 2 August 2026.
So the planning position is a fork, not a delay. Either sixteen months of extra runway, or a deadline that has already passed by the time most firms finish arguing about it. A treasury function would hedge that exposure without being asked twice. Compliance functions, in my experience, tend to pick the branch they prefer and build a plan around it.
Why Splitting It Across Three Teams Fails
The instinctive organisational answer is to hand each regime to whoever is closest to it. Market risk takes the exchange rules. London compliance takes the senior managers regime. A project team takes Annex III. That is roughly how every firm I have looked at is currently arranged.
It breaks at the first model change.
The regimes interact at the level of the artefact, not the org chart. A material retraining triggers obligations under all three at once. If the Johannesburg team approves an updated model without telling London, the individual accountability chain in London is broken before anyone notices, because the named person is now answerable for a system they did not sign off. If the conformity assessment was performed against a version that has since been retrained under the PA’s process, the assessment describes something that no longer exists.
None of those failures show up in any single team’s controls. They are failures of the joins, and joins have no owner.
The only structure that survives is a layer sitting above all three: one model inventory, one change-management process, one evidence repository capable of generating whichever documentation set a given supervisor asks for from a common record. That is not best practice. It is the minimum that can be made to work.
The Constraint Is People, Not Law
Cross-border AI governance reads like a legal problem and behaves like a capacity problem.
Cliffe Dekker Hofmeyr’s reading of the SARB and FSCA data found 53% of financial institution staff without sufficient AI training. Globally, the Cambridge alternative finance centre put 48% of regulatory authorities as still exploring AI or not engaged with it at all. The May joint statement acknowledged that frontier capabilities already exceed what skilled practitioners can do unaided.
A desk in this position needs someone who can work the exchange rulebook, articulate individual accountability for a model under UK rules, prepare an Annex III conformity assessment, and translate between all three when the same model serves every jurisdiction at once.
Those people are rare enough that the Big 4 have absorbed most of them into practices priced for global banks rather than for the South African corporate and investment banking operations that need them most.
Build Once or Build Three Times
The timelines are converging whether or not anyone is ready. The exchange rules are live. The FCA’s practical guidance is expected before the end of 2026. Annex III arrives in August 2026 or December 2027 depending on a legislative process nobody controls. The SARB and FSCA have signalled AI Joint Standards with no date attached.
A firm that maps each AI system against every applicable regime now, marking where obligations converge and where they pull apart, builds the evidence base once and reuses it three times.
A firm that waits builds it three times under pressure, with three sets of examiners already asking questions, and discovers the contradictions in front of the people least inclined to be relaxed about them.
That choice is still open. It closes on somebody else’s timetable.
Regulatory position as at July 2026. The Digital Omnibus had not been formally adopted at that date, so the enacted August 2026 deadline still applied.
Source List
- Standard Bank CIB, Our footprint: United Kingdom. https://corporateandinvestment.standardbank.com/cib/global/who-we-are/about-us/our-footprint/europe/united-kingdom
- FCA Register, Investec Bank PLC. https://register.fca.org.uk/s/firm?id=001b000000MfGxWAAV
- Nedbank CIB, London. https://cib.nedbank.co.za/solutions/london.html
- Absa CIB, Absa International. https://cib.absa.africa/home/absa-international/
- African Business, JSE introduces new algorithmic trading rules, June 2026. https://african.business/2026/06/finance-services/jse-introduces-new-algorithmic-trading-rules
- News24, JSE to tighten algo-trading, market-access rules, 25 May 2026. https://www.news24.com/business/investing/jse-to-tighten-algo-trading-market-access-rules-20260525-0934
- FCA, PS26/6: Senior Managers and Certification Regime review. https://www.fca.org.uk/publications/policy-statements/ps26-6-senior-managers-certification-regime-review
- Ropes & Gray, From Principles to Practice: the FCA’s evolving expectations on AI governance, June 2026. https://www.ropesgray.com/en/insights/viewpoints/2026/06/102n7e3/from-principles-to-practice-the-fcas-evolving-expectations-on-ai-governance
- Bank of England, FCA and HM Treasury, Joint statement on frontier AI models and cyber resilience, 15 May 2026. https://www.bankofengland.co.uk/news/2026/may/boe-fca-and-hm-treasury-joint-statement-on-frontier-ai-models-and-cyber-resilience
- Gibson Dunn, EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
- Finextra, The EU AI Act’s August 2026 deadline: what financial services firms must do now. https://www.finextra.com/blogposting/31653/the-eu-ai-acts-august-2026-deadline-what-financial-services-firms-must-do-now
- FluxForce, EU AI Act Article 6: high-risk requirements. https://www.fluxforce.ai/regulations/eu-ai-act-article-6-high-risk
- SARB and FSCA, Artificial Intelligence in the South African Financial Sector, November 2025. https://www.resbank.co.za/content/dam/sarb/publications/prudential-authority/pa-public-awareness/covid-19-response/2025/artificial-intelligence-in-the-south-african-financial-sector/Artificial%20Intelligence%20in%20the%20South%20African%20Financial%20Sector.pdf
- Cliffe Dekker Hofmeyr, An overview of the Artificial Intelligence in the South African Financial Sector report, December 2025. https://www.cliffedekkerhofmeyr.com/en/news/publications/2025/Practice/Corporate-Commercial/combined-corporate-and-commercial-and-technology-and-communications-alert-3-december-An-overview-of-the-Artificial-Intelligence-in-the-South-African-Financial-Sector-report
- Cambridge Centre for Alternative Finance, 2026 Global AI in Financial Services Report. https://www.jbs.cam.ac.uk/faculty-research/centres/alternative-finance/publications/2026-global-ai-in-financial-services-report/
- Baker McKenzie, South Africa: AI adoption by the SARB and FSCA. https://connectontech.bakermckenzie.com/south-africa-ai-adoption-by-the-sarb-and-fsca-new-insights-new-risks-new-rules/
- Schellman, Cross-border AI governance and jurisdictional conflicts. https://www.schellman.com/blog/ai-services/cross-border-ai-governance-and-jurisdictional-conflicts