Financial services providers already report information to regulators, maintain records, prepare financial statements, and meet various notification requirements. The Conduct of Financial Institutions (COFI) Bill would change the role that information plays in this process.
Moonstone Compliance says Chapter 9 would bring reporting, record-keeping, financial statements, data governance, public disclosure, and auditor oversight into a broader supervisory information framework. The objective would be to give the Financial Sector Conduct Authority clearer and more continuous visibility into how financial institutions are managed, governed, and controlled.
The significance, therefore, is not simply that reporting obligations would increase. It is that information itself would become central to supervision.
This is the fourth article in our series examining the potential impact of COFI on FSPs. In Part 1, we looked at the Bill’s outcomes-based approach to conduct regulation; Part 2 considered product governance, advertising, and disclosure; and Part 3 examined the proposed changes to the safeguarding of client assets.
As with the previous articles, this article refers to the 2020 draft version of the Bill, because the version that will be introduced into Parliament has not yet been published.
From reporting deadlines to supervisory readiness
Under the current FAIS environment, reporting is largely periodic or event-driven. Compliance reports, financial statements, and regulatory notifications are generally submitted at prescribed intervals or when particular events occur.
Moonstone Compliance says COFI would place these requirements within a broader and more active supervisory relationship.
Chapter 9 would create an ongoing obligation to provide information to the FSCA in the form, manner, and frequency prescribed. FSPs would therefore need systems and processes capable of producing accurate, reliable, and regulator-ready information when required, rather than treating reporting simply as a deadline-driven exercise.
The quality of the information would also become a regulatory concern in its own right.
Information provided to the FSCA would need to be complete, consistent, comparable, reliable, and not misleading. Moonstone Compliance notes that inaccurate, inconsistent, or incomplete information could create regulatory risk even where there is no underlying conduct failure.
The FSCA could challenge information it considers incomplete, incorrect, false, or misleading, and require it to be corrected, replaced, or independently verified.
Greater visibility beyond the FSP’s own reporting
Chapter 9 would also expand the information available to the regulator and, in some circumstances, to the public.
COFI would introduce a formal public disclosure framework requiring financial institutions to disclose prescribed quantitative and qualitative information annually. For many FSPs, particularly smaller businesses, this could create a new compliance responsibility involving the collection, validation, approval, and publication of information.
Certain significant developments could also trigger public disclosure. Moonstone Compliance identifies material non-compliance and certain reviews, investigations, or verification processes required by the FSCA as examples.
Where disclosure is required, information about causes, consequences, and remedial measures may also have to be made public.
Moonstone Compliance says this introduces a different dimension to regulatory risk because compliance failures could become visible not only to the regulator, but also to clients, business partners, and competitors.
FSPs would therefore need clear internal processes for determining when information must be disclosed, who approves it, and how public disclosures are managed.
Ownership and financial information become part of the supervisory picture
COFI would also give the FSCA greater visibility into ownership and control structures.
The regulator would be entitled to require information about shareholders, beneficial owners, and individuals exercising direct or indirect influence over an institution. The focus would extend beyond legal ownership to understanding who ultimately controls or influences decision-making.
This would require FSPs to maintain accurate beneficial-ownership records and be able to provide comprehensive ownership information when requested.
Financial reporting would similarly take on a broader supervisory role.
Moonstone Compliance notes that COFI retains many existing FAIS requirements concerning accounting records and annual financial statements but would place those records within a wider supervisory information framework. Financial statements would support not only assessments of financial soundness, but also reporting, disclosure, investigations, and regulatory risk assessments.
The FSCA could also prescribe additional reporting requirements and determine the format in which financial information must be presented.
Auditors and data become part of the framework
The supervisory role of information would extend to assurance.
Under COFI, certain regulatory information could be subject to audit or independent review. Moonstone Compliance says this reflects the FSCA’s focus on ensuring that information used for supervision is accurate, reliable, and independently verified.
Auditors could also have more direct responsibilities within the supervisory framework, including reporting certain governance failures, internal-control weaknesses, and contraventions by significant owners to the governing body and the FSCA.
The FSCA would have greater involvement in matters such as auditor approval, suitability, and ongoing fitness and propriety.
Data management would likewise extend beyond simply retaining records for prescribed periods.
Moonstone Compliance says COFI would require formal data and record-retention frameworks aligned with the Protection of Personal Information Act, conduct standards, and other applicable legislation. FSPs would need to manage information throughout its lifecycle, including its collection, storage, access, protection, retention, and destruction.
This would be particularly relevant where information is held by third-party service providers, software platforms, or cloud-based systems.
Moonstone Compliance notes that records and data would remain the property of the financial institution even when maintained by a third party and would need to remain accessible to the institution. FSPs should therefore review outsourcing arrangements to ensure that contracts provide appropriate rights of ownership, access, retrieval, and availability.
What this means for FSPs
Taken together, Moonstone Compliance says Chapter 9 would represent a substantial shift in regulatory expectations.
The key issue would no longer be simply whether a report was submitted on time. FSPs would increasingly need to ensure that the information supporting their reporting is accurate, reliable, accessible, and capable of supporting ongoing regulatory oversight.
For FSP owners, this means reviewing reporting capabilities, data governance, record-keeping, ownership information, financial reporting, auditor arrangements, outsourcing agreements involving data, and internal processes for responding to regulatory information requests.
For smaller FSPs, the challenge may be less about the complexity of individual requirements than about moving from informal or manual compliance processes towards more structured and system-based arrangements.
The broader message of Chapter 9 is that information would become part of the supervisory relationship itself.
Rather than being produced primarily to satisfy periodic reporting requirements, information would give the FSCA an ongoing view of an institution’s governance, controls, financial position, ownership, and conduct.
For FSPs, being “reporting compliant” under COFI would therefore mean more than submitting information when required. It would mean having the systems, controls, and governance processes to ensure that the information provided to the regulator is reliable, available, and capable of standing up to scrutiny.



