Insights

The SARB-FSCA AI Report Exposes a Governance Gap SA Banks Are Scaling Into

Earlier this year South Africa withdrew its draft national AI policy, after at least six of the 67 academic references in it were found to be fabrications produced by an AI. The document meant to establish how the country governs artificial intelligence was itself undone by ungoverned use of it. A revised version is targeted at Cabinet in November 2026 and publication for comment in January 2027.

That episode got the coverage. The more consequential document came out four months earlier and got much less.

Research and drafting for this article were AI-assisted. Every figure is linked inline to the source that published it. Editorial responsibility is mine.

A steeply rising cyan arrow representing AI investment breaking away from a flat orange line representing governance maturity, separated by a jagged gold crack.
Produced by Gemini-Nano-Banana

What the Survey Found Underneath the Headline

In November 2025 the Prudential Authority and the FSCA published the first comprehensive picture of AI adoption across the South African financial sector, drawn from roughly 2,100 survey responses. The line that travelled was that banks lead adoption at 52%.

The line that should have travelled: only 5% of institutions report mature AI oversight, and 20% have no AI governance framework whatsoever.

Then the spending. In 2024 most institutions put under ZAR 1 million into AI. For 2026, more than 45% of participating banks intend to exceed ZAR 30 million. Capitec’s IT expenditure alone rose 17.5% to R3 billion in its most recent reporting period, and the other large groups are scaling across credit risk, fraud detection and customer servicing.

Nobody is experimenting cautiously any more. The governance was built for the ZAR 1 million era and is being asked to hold a thirtyfold increase.

Cliffe Dekker Hofmeyr’s read of the underlying data fills in why that matters. Fifty-three per cent of staff lack the AI training they need. Forty-one per cent of institutions name transparency and explainability as a constraint. And 21% have no explainability method for their AI systems at all.

Sit with that last one. A model influencing credit decisions, with no method of explaining any individual outcome, is a black box making consequential judgements about people’s financial lives. It is the exact scenario the FSCA’s Treating Customers Fairly framework exists to prevent, and one institution in five is running one.

An exponential cyan curve labelled AI investment climbing away from a flat orange line labelled governance maturity, the widening gold area between them labelled gap.
Produced by Gemini-Nano-Banana

Three Instruments, No Map

South African firms are now caught by three separate conduct and prudential requirements touching AI, issued under different instruments, with nothing published on how they interact.

Treating Customers Fairly requires continuous demonstration of fair treatment across the product lifecycle. Where AI shapes credit assessment, insurance pricing or collections, the framework expects a firm to explain how the decision was reached and show the outcomes are fair. Current, enforceable, and not waiting for anything.

The Prudential Authority’s Basel III framework, working through directives including the D12-2025 credit risk roadmap, requires validation, ongoing monitoring and board oversight for internal models. AI-driven credit risk models, potential future exposure and CVA calculations all fall inside it, and each material retraining needs the PA’s written approval first.

The COFI Bill, approved by Cabinet for submission to Parliament in March 2026, will introduce a separate conduct licence and AI-specific transparency obligations covering how AI decisions are made, explained and audited across the customer lifecycle. For an institutional desk, that means conduct-regime requirements sitting alongside prudential model governance, two obligations from two regulators, which is what Twin Peaks was always going to produce.

No bank has published a framework showing where these three overlap, where they pull against each other, or where satisfying one leaves a hole under another. Ask three different teams inside the same institution and you will get three different scoping assumptions.

Three tall blue bars rising past their dashed outlines, each overlaid with faint question marks and topped with small amber markers.
Produced by Gemini-Nano-Banana

A Standard That Is Years Away

The joint report signalled that draft AI Joint Standards would go out for public consultation. No timetable has been confirmed. Precedent from previous joint standards in this market suggests a long road from consultation to effect, which puts binding AI-specific rules some way out. [SOURCE NEEDED: the specific precedent timeline for Joint Standard 2 of 2024 on cybersecurity is not in the logged sources and should be verified before publication.]

Which leaves risk officers somewhere genuinely odd. Their regulators have published evidence that governance is inadequate, and said standards are coming. The standards are not close, and the national policy above them has reset to a blank page.

Waiting is a decision, and it is the expensive one. Every month of thirtyfold spending growth adds to the estate that will eventually need retrofitting.

The Global Comparison Is Not Comforting

South Africa’s gap is not unique. It is sharper than most.

The Cambridge alternative finance centre’s 2026 global study found 81% of surveyed financial services firms adopting AI, with 48% of regulatory authorities worldwide still exploring it or not engaged at all. Buried in the same data is something more pointed: firms in emerging markets report higher deployment than those in advanced economies. Faster adoption, without the governance depth that usually travels with it.

Domestic measurement agrees. The AI maturity framework developed by SAICA with the CSIR and the University of the Western Cape found seven of its eight domains still early. Local fintechs average 3.45 out of 5, and not one has reached full deployment maturity.

What Is Worth Doing Before the Rules Arrive

Four things, and none of them require knowing what the Joint Standards will say.

Classify every AI system against all three instruments, because the exercise itself is the finding. It will surface systems triggering obligations under more than one, and it will surface systems that no team currently owns. That second list is usually the shorter and more alarming one.

Treat explainability as a floor rather than an ambition. The FSCA has pointed at SHAP and LIME as the kind of methods it expects, and the 21% operating without any method are carrying a risk that crystallises the first time a TCF examination asks how a specific decline was reached.

Build continuous monitoring now rather than later. Data drift, feature drift, performance degradation, output distribution shifts, adherence to conduct guardrails. Retrofitting monitoring into live systems is disruptive in a way that designing it in is not.

And close the literacy gap before it becomes an audit finding. With over half of staff lacking AI training, three lines of defence does not function for AI, because a second line that cannot challenge a first-line model builder is not a second line. It is a countersignature.

Four cyan icons labelled classification, explainability, monitoring and literacy above a gold minimum-threshold bar that runs solid beneath the first three and turns dashed beneath the fourth.
Produced by Gemini-Nano-Banana

The Report Is Not a Forecast

The joint report is often discussed as a warning about where the sector is heading. It is not. It is a description of where the sector already is, taken from the institutions themselves.

Five per cent mature. Twenty per cent with nothing. Spending multiplying by thirty. Three instruments converging with no integration guidance, above a national policy that had to be withdrawn because nobody checked what a language model had written.

The regulators have been unusually candid about all of it. When the standards do arrive, that candour will not translate into patience for firms that read the evidence and chose to wait.

Regulatory position as at May 2026. The FSCA and PA AI Joint Standards remained unpublished at that date, and the revised national AI policy had not reached Cabinet.

Sources Consulted

AI GovernanceSouth AfricaFinancial Services