March 2026 introduced a number of regulatory and industry developments that continue to shape South Africa’s financial services landscape. Key updates this month span data protection, market conduct reform, supervisory enforcement, insurance risk interpretation, and employment law reform, reflecting a continued focus on strengthening regulatory frameworks and their practical application across the sector.
New POPIA Health Information Regulations Now in Force
New regulations under the Protection of Personal Information Act 4 of 2013 (POPIA), relating to the processing of health information, came into effect on 6 March 2026.
Published by the Information Regulator, these regulations aim to clarify the interpretation of section 32(6) of the Act, enhance transparency regarding the use of health information, and provide a framework for the Information Regulator to enforce compliance.
The final regulations reflect meaningful changes following public consultation and introduce more structured requirements for handling health-related information. For insurers and financial services providers, this highlights the need to review data governance practices, particularly where health data forms part of underwriting, claims, or client servicing processes.
Cabinet Approves Submission of COFI Bill to Parliament
Cabinet has approved the submission of the Conduct of Financial Institutions (COFI) Bill, 2025 to Parliament. The Bill introduces a unified framework for regulating the market conduct of financial institutions as part of South Africa’s shift towards a Twin Peaks regulatory model, which separates prudential oversight from market conduct and consumer protection functions.
The COFI Bill aims to strengthen consumer protection, promote fair treatment, and support financial sector transformation and stability. It also requires institutions to align with the Financial Sector Code and introduces a differentiated licensing framework aimed at facilitating market entry and competition, including for new players such as financial technology firms.
FSCA FICA Inspections Highlight Common Weaknesses
The insights in this section are drawn from a recent industry analysis of FSCA FICA compliance inspections published by Moonstone. The full article is available at the following link: Moonstone – Six key themes from the FSCA’s FICA compliance inspections.
The analysis highlights an increase in the Financial Sector Conduct Authority’s’ (FSCA) supervisory activity under the Financial Intelligence Centre Act (FICA), with recurring areas of weakness identified across accountable institutions.
These inspections have identified several recurring issues, including:
- Misalignment between Risk Management and Compliance Programmes (RMCPs) and actual practices
- Weak or incomplete risk assessments and customer due diligence processes
- Poor record-keeping and version control
- Gaps in governance, training, and accountability
The analysis further notes a challenge in relation to remediation, particularly uncertainty among institutions on how to effectively address findings.
Overall, the FSCA’s supervisory approach reflects a shift toward assessing operational effectiveness and real-world implementation, rather than reliance on documented compliance frameworks alone.
High Court Clarifies Claims-Made PI Cover
A recent High Court judgment has clarified the operation of claims-made professional indemnity (PI) policies, confirming that indemnity is triggered by the making and notification of a claim to the insurer, rather than the date on which the underlying event giving rise to the claim occurred.
In the matter considered by the Court, the claim was only reported during a subsequent policy period. As a result, it fell to be assessed under that later policy, which contained a COVID-19 exclusion, leading to the repudiation of the claim.
The judgment reinforces key principles relevant to insureds and intermediaries, including the importance of understanding the distinction between claims-made and occurrence-based cover, the need for prompt notification of claims and potential circumstances, and the potential consequences of delayed notification, which may result in the application of different policy terms or the loss of indemnity.
Labour Law Amendments: Moving Toward Shared Parental Leave
Proposed amendments to South African labour legislation seek to introduce a more flexible and inclusive parental leave framework.
These reforms follow a Constitutional Court ruling which found aspects of the current parental leave regime to be discriminatory and have prompted a reassessment of how leave entitlements are structured under labour law and the Unemployment Insurance Fund (UIF).
The proposed changes include the introduction of a more flexible parental leave model allowing for the sharing of leave between parents, as well as a shift toward a broader, gender-neutral parental benefits framework administered through the UIF. The reforms also contemplate greater alignment of adoption and related leave provisions within this consolidated framework.
While the amendments aim to promote greater equity and flexibility in the workplace, they will require employers to review and update internal policies, HR systems, and administrative processes to ensure alignment with the revised leave framework once implemented.
Final Thoughts
This month’s developments highlight how a range of regulatory and legal changes continue to influence day-to-day operations across the financial services sector.
Staying ahead will require not only understanding regulatory changes, but also translating them into practical, effective actions within the business.
Regulatory change is inevitable; being unprepared is optional.







