Interesting Developments in Financial Technologies and Data Security in South Africa - A Three Part Series
September 13, 2024
Interesting Developments in Financial Technologies and Data Security in South Africa - A Three Part SeriesSeptember 13, 2024 Part 3: Tech Related Cross Sector Joint Standards Published by the FSCAIn the second publication of the three part series on Developments in Financial Technologies and Data Security, we discussed the publication of the 2024 FSCA 3-year Regulation Plan (2024 Regulation Plan) as it relates to open finance and other financial technologies. The article briefly touched on technology related cross-sector project deliverables in the form of joint standards. This third and final publication provides an overview of legislative intervention in the form of joint standards that have been issued or that are being considered by the Financial Sector Conduct Authority (FSCA) and the Prudential Authority to meet the objectives of the 2024 Regulation Plan. 1. Joint Standard 1 of 2023– Information Technology governance and risk managementThe Joint Standards on Information Technology Governance and Risk Management (Joint Standard 1) established by the FSCA, and set to commence on 15 November 2024, outlines the principles and minimum requirements for Information Technology (IT) governance and risk management that financial institutions must follow. Joint Standard 1 emphasises the importance of sound practices and compliance with relevant financial sector laws. Additionally, it mandates that IT risk management policies and procedures, especially those involving sensitive or confidential information, undergo independent reviews. These reviews can be conducted by internal or external audit functions or another independent control function within the financial institution. The governing body, as defined in section 1 of the Financial Sector Regulation Act, 2017, must ensure that financial institutions comply with the following requirements set out in Joint Standard 1, when establishing a robust IT risk management framework, and clearly defined roles and responsibilities for IT risk oversight:
2. Joint Standard 2 of 2024 - Cyber security and cyber resilience requirementsThe Joint Standard on cyber security and cyber resilience requirements (Joint Standard 2) sets out the requirements for practices and processes relating to cybersecurity and cyber resilience for financial institutions, and is set to commence on 1 June 2025. The governing body must ensure that financial institutions comply with the following requirements set out in Joint Standard 2 when establishing a cybersecurity and risk management framework to maintain a robust cybersecurity strategy and cyber resilience:
3. Joint Standard – Culture and Governance requirements for financial institutions:Although not yet published, the FSCA, in collaboration with the Prudential Authority, is considering integrating high-level governance principles related to Artificial Intelligence (AI) and Machine Learning (ML) into the Joint Standard for Culture and Governance requirements for financial institutions. This integration aims to ensure that financial institutions adhere to appropriate governance standards when using AI and ML. The FSCA will engage with stakeholders through targeted and formal consultation processes to discuss these topics further. Additionally, the FSCA may look at how existing frameworks, which are based on outcomes and principles, can be adapted to guide the application of AI and ML. Overall, the series highlighted the impact digital transformation has on the financial sector and the proactive steps taken by the FSCA to manage the risks arising from technology. These regulations and standards must be read and applied in conjunction with the relevant financial sector laws, taking into account the nature, size, complexity and risk profile of the financial institution. If you are a Fintech start-up or any other licensed financial services provider and want to know more about the topic or managing the data privacy risks associated with digital technology, you can get in touch with our Technology, Media, and Telecommunications team, who can assist you with any queries. Latest Insights
Latest News
Latest Events
client news June 02, 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... firm news June 01, 2026 Shaping the Future firm news June 01, 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... firm news June 01, 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... virtual UK employment law training June 09, 2026 1pm - 4pm (BST) Virtual virtual Nordic (Denmark, Finland, Norway and Sweden) employment law training June 16, 2026 12.45pm - 4pm (BST) Virtual virtual Webinar: Conquering the US Market June 23, 2026 17.00-18.00 virtual Introduction to Swiss employment law June 23, 2026 2pm - 5pm (GMT) Virtual |