Compliance & Cyber Intelligence for Insurance
Menu
Log in ↗
PROVANTIS / RULE LIBRARY
CONDUCT LIBRARY v2026.4
Conduct rule library / 2026 edition

Every conduct rule, with its mapped source.

99 rules across 8 categories. Each carries a trigger, a citation, remediation guidance and an evidence requirement — and the same library powers both the website scanner and the self-attestation workflow, so a finding on one side means the same thing on the other.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Binder Governance
  • Insurance Broker: Binder duties apply where the broker is a binder holder and performs functions under a binder agreement. Do not infer binder-holder status from being a broker. Exact amended Binder Regulation sub-regulation numbers remain withheld pending consolidated-text review.
  • Uma Binder Holder: A UMA that is a binder holder must operate within its written binder agreement and the applicable statutory and regulatory framework. Describe only the binder functions actually authorised. Exact amended Binder Regulation sub-regulation numbers remain withheld pending consolidated-text review.
  • Insurer: An insurer using a binder arrangement remains responsible for establishing and overseeing a compliant written arrangement. Use exact current Binder Regulation sub-regulation numbers only after consolidated-text verification.
Fais Conduct
  • Insurance Broker: FAIS and the applicable conduct code govern authorised FSPs and representatives rendering covered financial services. State the firm's licensed capacity and service; do not convert a readiness scan into a legal compliance conclusion.
  • Uma Binder Holder: FAIS duties apply where the UMA is an authorised FSP or acts through representatives in a covered capacity. Do not infer the licence category or every conduct duty from the UMA label alone.
  • Insurer: FAIS duties apply to an insurer when it also acts in a capacity requiring FAIS authorisation or through covered representatives. Insurance conduct duties also arise under insurance legislation and policyholder-protection rules; do not collapse those regimes into FAIS.
Fica
  • Insurance Broker: FICA duties apply when the firm is an accountable institution for the relevant business or acts in another capacity captured by Schedule 1. Schedule 1 item 12 excludes advice or intermediary services solely in respect of a non-life insurance policy. Do not infer FICA accountable-institution status from a non-life broker label alone.
  • Uma Binder Holder: FICA duties depend on whether the UMA is an accountable institution for the relevant business or acts in another captured capacity. Non-life insurance advice or intermediary services are excluded from Schedule 1 item 12; test the firm's other activities before publishing a direct-duty claim.
  • Insurer: FICA duties depend on the insurer's business and the applicable Schedule 1 item. Distinguish life and non-life business and any other accountable-institution capacity before publishing a direct-duty claim.
Js1 2024
  • Insurance Broker: JS1 places the direct duty on the insurer. A broker providing a material outsourced function may have to supply evidence and accept contractual controls. Materiality is assessed under JS1 section 7; the broker label alone does not establish that the arrangement is material.
  • Uma Binder Holder: JS1 directly regulates the insurer. Where a UMA performs a material outsourced function, the insurer may require due-diligence evidence, contractual controls, reporting and continuity support. A binder does not automatically prove materiality. Pre-existing material arrangements transition by 1 December 2026 or earlier renewal or renegotiation.
  • Insurer: JS1 applies directly to licensed insurers, other than Lloyd's and branches of foreign reinsurers, for material outsourced functions. The insurer retains regulatory accountability. General compliance was due by 1 June 2025; qualifying pre-existing arrangements transition by 1 December 2026 or earlier renewal or renegotiation.
Popia
  • Insurance Broker: POPIA duties follow the entity's role as responsible party or operator and the personal information it processes. Do not state that consent is always the lawful basis, or that a public scan proves POPIA compliance.
  • Uma Binder Holder: POPIA duties follow whether the UMA is a responsible party or operator for the processing in question. The insurer relationship does not by itself settle POPIA role allocation; check the processing purpose, means and operator agreement.
  • Insurer: POPIA duties follow the insurer's responsible-party or operator role for each processing activity. Allocate duties for outsourced processing explicitly; the insurer cannot treat outsourcing as eliminating its own responsible-party obligations.
99
conduct rules
08
categories
29
rated critical
v2026.4
library version
01 / Priority matrix

Rule counts by category and priority

Category Critical High Medium Low Total
01FAIS Readiness 4 5 3 0 12
02TCF Fairness 1 7 4 0 12
03POPIA Privacy Governance 4 7 3 0 14
04FICA Onboarding 9 5 1 0 15
05Complaints Handling 2 6 2 0 10
06Digital Trust and UX 2 7 2 1 12
07Executive Governance 4 8 2 0 14
08Binder & Outsourcing Governance 3 6 1 0 10
TOTALS 29 51 18 1 99
02 / Category ledger

What each category covers.

Categories group rules by the instrument they come from. Your assessment groups the same rules by the job you actually do — so you answer them in the order a working week allows.

01

Licensing, competency, and ongoing conduct obligations under the FAIS Act 37 of 2002 and Board Notice 194 of 2017 (Fit and Proper Requirements).

FSCA
02

Treating Customers Fairly — embedding the FSCA's six TCF outcomes across culture, product governance, sales processes, and post-sale service.

FSCA
03

Protection of Personal Information Act 4 of 2013 — data protection compliance framework, Information Officer obligations, and data subject rights.

Information Regulator
04

Financial Intelligence Centre Act — CDD, RMCP, PEP/sanctions screening, and onboarding controls for Accountable Institutions.

FIC
05

FAIS Act, PPR, and TCF Outcome 6 — complaints management, resolution timelines, Ombud referrals, and root cause analysis.

FSCA
06

POPIA, FAIS, and TCF obligations applied to digital channels — consent design, cookie compliance, digital disclosures, and UX integrity.

FSCA · Information Regulator
07

FSRA, FAIS, POPIA, and FICA — board and senior management accountability, three lines of defence, regulatory change management, and oversight frameworks.

FSCA · FIC · Information Regulator
08

Section 48A of the Short-term Insurance Act 53 of 1998, Part 6 of the Short-term Insurance Act Regulations (Part 6 of the Short-term Insurance Act Regulations, as amended), and Joint Standard 1 of 2024 on Outsourcing by Insurers. Binder duties depend on the actual agreement and authorised functions; JS1 duties sit directly with the insurer and apply only where the outsourced function is material.

Prudential Authority · FSCA