Compliance & Cyber Intelligence for Insurance
Menu
Log in ↗
PROVANTIS / RULE LIBRARY
← BACK TO LIBRARY
← Conduct rule engine

Category 07

Executive Governance

FSRA, FAIS, POPIA, and FICA — board and senior management accountability, three lines of defence, regulatory change management, and oversight frameworks.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Fais Conduct
  • Insurance Broker: FAIS and the applicable conduct code govern authorised FSPs and representatives rendering covered financial services. State the firm's licensed capacity and service; do not convert a readiness scan into a legal compliance conclusion.
  • Uma Binder Holder: FAIS duties apply where the UMA is an authorised FSP or acts through representatives in a covered capacity. Do not infer the licence category or every conduct duty from the UMA label alone.
  • Insurer: FAIS duties apply to an insurer when it also acts in a capacity requiring FAIS authorisation or through covered representatives. Insurance conduct duties also arise under insurance legislation and policyholder-protection rules; do not collapse those regimes into FAIS.
Popia
  • Insurance Broker: POPIA duties follow the entity's role as responsible party or operator and the personal information it processes. Do not state that consent is always the lawful basis, or that a public scan proves POPIA compliance.
  • Uma Binder Holder: POPIA duties follow whether the UMA is a responsible party or operator for the processing in question. The insurer relationship does not by itself settle POPIA role allocation; check the processing purpose, means and operator agreement.
  • Insurer: POPIA duties follow the insurer's responsible-party or operator role for each processing activity. Allocate duties for outsourced processing explicitly; the insurer cannot treat outsourcing as eliminating its own responsible-party obligations.

Key legislation

  • FSRA 9 of 2017
  • FICA 38 of 2001
  • POPIA 4 of 2013
  • Companies Act 71 of 2008

Readiness guidance

Review board committee terms of reference for compliance mandate. Examine the last four compliance MI reports for completeness and risk coverage. Assess the compliance risk register for currency. Interview the Compliance Officer regarding resources and board access. Review the regulatory change log for the last 12 months.

Rules in this category

14 rules

GOV-01

Board compliance mandate — committee with explicit compliance oversight mandate

Critical
Trigger
No board committee with explicit compliance oversight mandate
Section
FSRA s.9 / King IV
Evidence
['Board committee ToR', 'Board resolution', 'Committee minutes']
Remediation
Update Audit/Risk Committee terms of reference to include explicit compliance oversight.

GOV-02

Compliance Officer appointment — documented with terms of reference

Critical
Trigger
No formal Compliance Officer appointment or no terms of reference
Section
FAIS Act s.17 / FICA s.42A(2)
Evidence
['Appointment letter', 'Terms of reference', 'CV and qualifications']
Remediation
Appoint Compliance Officer. Document ToR including scope, authority, and reporting lines.

GOV-03

Compliance function independence — not reporting solely to business lines

High
Trigger
Compliance reports exclusively to CFO or business head without board access
Section
FSRA / King IV
Evidence
['Organisational chart', 'Board/committee access records', 'Reporting structure documentation']
Remediation
Restructure reporting line to include direct board or Audit Committee access.

GOV-04

Three Lines of Defence — documented model with clear ownership

High
Trigger
Three lines model not documented or first line accountability unclear
Section
King IV / FSCA supervisory expectations
Evidence
['Three Lines policy', 'RACI matrix', 'Staff communication records']
Remediation
Document Three Lines model. Assign compliance accountability per line. Communicate to staff.

GOV-05

Compliance MI — quarterly compliance report to board/ExCo

High
Trigger
No compliance MI to board in last 2 quarters or MI not risk-based
Section
FSCA / King IV
Evidence
['Board MI packs (last 4 quarters)', 'Compliance dashboard', 'Board resolution acknowledging MI']
Remediation
Design compliance MI dashboard. Add to standing board agenda. Include risk-based metrics.

GOV-06

Regulatory change management — process to identify, assess, and implement changes

Critical
Trigger
No regulatory change process; material regulation changes missed or unimplemented
Section
FSRA / all sector legislation
Evidence
['Regulatory change register', 'Impact assessments', 'Implementation tracking log']
Remediation
Implement regulatory change register. Subscribe to FSCA, FIC, and IR regulatory alerts.

GOV-07

Compliance risk register — documented and reviewed at least quarterly

High
Trigger
No compliance risk register or not reviewed in last 6 months
Section
King IV / FSCA
Evidence
['Compliance risk register', 'Quarterly review records', 'Risk rating methodology']
Remediation
Develop compliance risk register with heat map. Present to board quarterly.

GOV-08

Internal audit — independent annual compliance audit with tracked findings

High
Trigger
No independent compliance audit in last 12 months or findings not tracked
Section
King IV / FSCA supervisory expectations
Evidence
['Internal audit plan', 'Audit reports (last 12 months)', 'Findings tracker with closure evidence']
Remediation
Commission independent compliance audit. Implement findings tracker with due dates and owners.

GOV-09

Whistleblowing — Protected Disclosures Act-compliant mechanism in place

High
Trigger
No whistleblowing mechanism or mechanism not communicated to staff
Section
Protected Disclosures Act 26 of 2000
Evidence
['Whistleblowing policy', 'Channel setup', 'Staff communication records']
Remediation
Implement anonymous whistleblowing channel. Communicate to all staff. Include in onboarding.

GOV-10

Sanctions screening — organisation-wide screening for all counterparties

Medium
Trigger
No sanctions screening beyond client onboarding (e.g., vendors not screened)
Section
FICA s.26A
Evidence
['Vendor screening log', 'Payment screening controls', 'Screening policy']
Remediation
Extend sanctions screening to vendor onboarding and payment processes.

GOV-11

Regulatory relationships — proactive engagement with regulators; deadlines met

Critical
Trigger
Regulatory correspondence unanswered or response deadlines missed
Section
FSRA / FICA / POPIA
Evidence
['Regulatory correspondence register', 'Response tracking log', 'Deadline compliance data']
Remediation
Implement regulatory correspondence register. Assign owner per communication.

GOV-12

Board director fitness — directors assessed for fit and proper under FSRA

High
Trigger
Board director without fitness and propriety assessment on file
Section
FSRA s.9
Evidence
['F&P assessment forms per director', 'Criminal and credit check records', 'CV verification']
Remediation
Conduct and document fitness and propriety assessments for all directors.

GOV-13

Compliance budget — adequate resources allocated to compliance function annually

Medium
Trigger
Compliance function materially under-resourced relative to regulatory risk profile
Section
FSCA supervisory expectations / King IV
Evidence
['Compliance budget', 'Headcount data', 'Benchmarking report']
Remediation
Benchmark compliance resourcing against sector peers. Present gap analysis to board.

GOV-14

Outsourcing governance — material outsourcing compliant with FSCA guidance

High
Trigger
Material functions outsourced without compliant governance framework
Section
FSCA Outsourcing Guidance / FAIS Act
Evidence
['Outsourcing register', 'Outsourcing agreements', 'Oversight meeting records']
Remediation
Develop outsourcing governance framework. Execute compliant agreements with all material providers.