Safeguarding client assets under COFI: familiar rules, new expectations

Posted on Leave a comment

Safeguarding client assets has long been a cornerstone of South Africa’s financial regulatory framework. The Conduct of Financial Institutions (COFI) Bill does not seek to replace those familiar obligations. Instead, it reframes them within a broader fiduciary framework, linking the protection of client assets more closely to governance, operational resilience, and customer protection.

Under the current FAIS regime, requirements relating to client funds and assets are spread across legislation, subordinate legislation, and the General Code of Conduct. Moonstone Compliance says Chapter 8 of the COFI Bill would bring these familiar obligations into a single conduct framework centred on “trust property”.

This is the third article in a series examining the potential impact of COFI on financial services providers. Part 1 looked at the Bill’s outcomes-based approach to conduct regulation, and Part 2 examined how COFI links product governance, disclosure, and customer outcomes. As with the previous articles, this article refers to the 2020 draft version of the Bill, because the version introduced into Parliament has not yet been published.

From compliance rules to fiduciary responsibility

Moonstone Compliance says one of the most significant developments envisaged by Chapter 8 is that it brings existing duties relating to client assets into a single fiduciary framework centred on trust property.

Under the current FAIS framework, requirements dealing with client mandates, record-keeping, segregation, accounting controls, and safeguarding arrangements are often approached as individual compliance obligations. COFI would treat these as different aspects of the same responsibility: protecting assets that belong to financial customers.

Chapter 8 would place duties on financial services providers, governing body members, employees, and agents who receive, hold, administer, or otherwise deal with trust property. These persons would be expected to act in utmost good faith, exercise appropriate care and diligence, comply with client mandates, and administer trust property in a way that protects the interests of financial customers.

For many FSPs, the significance may not lie in the introduction of entirely new operational requirements. Rather, Moonstone Compliance says COFI changes the way familiar obligations are viewed. Safeguarding client assets would become more than a collection of technical compliance requirements; it would become a fiduciary responsibility underpinning the relationship between FSPs and their customers.

Evidence becomes part of compliance

Moonstone Compliance also highlights the greater role that transparency, accountability, and documented evidence would play under Chapter 8.

FSPs already maintain transaction records, provide confirmations where required, and retain documentation relating to client assets and agreements. Under COFI, however, those documents would have a broader compliance function. They would serve as evidence that client assets have been handled appropriately, that client instructions have been followed, and that the institution has fulfilled its fiduciary obligations.

Moonstone Compliance says the focus would no longer be solely on whether policies and procedures exist, but also on whether FSPs can demonstrate that those controls operate effectively in practice. Informal arrangements or undocumented practices that may previously have been accepted could become harder to justify where there is insufficient evidence to support them.

Moonstone Compliance notes that Chapter 8 also reinforces the principle that client assets must be kept separate from those of the FSP. It notes that trust property would be required to remain separate, identifiable in financial records, and excluded from the institution’s own assets. This would require accounting systems, operational processes, and legal arrangements to support the identification and protection of client assets throughout their lifecycle.

Governance extends beyond operations

Moonstone Compliance says Chapter 8 would also strengthen governance expectations where decisions involving trust property are concerned.

Although conflict-of-interest management is already well established under the FAIS framework, COFI would integrate these requirements more directly into governance processes. Where a direct or indirect financial interest exists in a proposed investment involving trust property, that interest would have to be disclosed and formally recorded before the decision is taken.

The management of conflicts would therefore no longer be viewed primarily as a disclosure exercise. It would form part of the broader responsibility of governing bodies to oversee decisions involving client assets and to ensure those decisions are made in the interests of financial customers.

This reflects a wider shift in the treatment of client asset protection. It would no longer be viewed solely as an operational function. It would also become a governance responsibility, requiring ongoing oversight of how risks relating to trust property are identified, managed, monitored, and addressed.

Financial soundness and operational resilience are part of the same broader framework. Existing fit and proper requirements already require FSPs to maintain adequate financial resources and monitor their financial position. Moonstone Compliance says COFI would place these obligations within the conduct framework by recognising that an FSP’s financial resilience is integral to its ability to protect customers and continue providing financial services.

Operational capability would receive similar emphasis. Safeguarding client assets depends not only on policies, but also on the systems, people, and processes that support service delivery. Appropriate IT systems, secure record-keeping, business continuity, disaster recovery measures, and oversight of outsourced functions would all form part of the environment needed to protect client assets. Moonstone Compliance says operational resilience would therefore be positioned as a conduct requirement, rather than merely an internal business consideration.

Preparing for a more proactive regulator

According to Moonstone Compliance, Chapter 8 envisages a more structured approach to regulatory intervention where financial soundness concerns arise.

FSPs may be required to notify the Authority, develop remediation plans, implement corrective measures within specified timeframes, and provide progress reports. The FSCA may also require independent reviews, impose licence conditions, restrict certain activities, or direct additional remedial action until identified concerns have been addressed.

Moonstone Compliance says this represents a shift away from a supervisory approach focused primarily on identifying instances of non-compliance after they have occurred. Instead, Chapter 8 contemplates a more structured and proactive model of supervision, with greater emphasis on early intervention, remediation, and ongoing engagement between FSPs and the regulator.

For smaller FSPs, the practical effect may be less about creating entirely new systems and more about formalising existing practices. Many smaller FSPs may already meet the substance of several requirements through current arrangements relating to record-keeping, financial soundness, and conflict management. The greater challenge may be ensuring that these arrangements are consistent, properly documented, and capable of demonstrating effective oversight.

Moonstone Compliance notes that this does not mean smaller FSPs would be expected to implement governance structures comparable to those of larger institutions. COFI recognises proportionality. However, all FSPs would need to demonstrate that appropriate controls exist and that those controls operate effectively to protect financial customers.

Although COFI has not yet commenced, Chapter 8 indicates the direction of South Africa’s conduct framework. FSPs should therefore assess whether their asset-safeguarding arrangements remain appropriate, whether governance structures provide effective oversight of trust property, whether operational controls support resilience and continuity, and whether documentation clearly evidences compliance. Early alignment with these expectations should place FSPs in a stronger position as the COFI framework develops.

 

Leave a Reply

Your email address will not be published. Required fields are marked *