top of page

COFI-Ready by design: Part 2

Writer: Craig Grasko
Craig Grasko
10 hours ago
7 min read


By Sean Barrett, Co-founder & CEO, FSPHub, and Craig Grasko, Director, FSPHub



For most small brokerage principals, COFI arrives as a feeling before it arrives as legislation.


The feeling is familiar: Another regulatory wave is coming, it will demand more documentation, more evidence, more process, and a practice of five or fifteen people will be expected to carry it with the same rigour as an institution with a compliance department of forty. The admin already crowds out client time. Now the load is about to grow.


That fear is understandable. It is also, we'd argue, based on a false assumption: that COFI readiness must be a separate project; a new layer of work bolted onto the practice. It doesn't have to be. For a well-organised brokerage, COFI readiness can be a by-product of the way the business already runs. The practices that will find the transition hardest aren't the small ones. They're the disorganised ones, of any size.


This article unpacks what COFI will actually ask of financial services providers, why the conventional "compliance project" approach fails small practices, and how to build a business that produces its compliance evidence automatically, as a side effect of doing the work.


A note before we start: this is an operational perspective, not legal advice. COFI's final requirements will be settled by the promulgated legislation and subsequent conduct standards - work with your compliance officer on the specifics. What follows is about how to be structurally ready for whatever those specifics turn out to be.



What is COFI, and how does it differ from FAIS?


The Conduct of Financial Institutions (COFI) Bill is the incoming framework for conduct regulation across South Africa's financial sector. Where FAIS regulates the advice process, licensing, fit-and-proper requirements, disclosure, records of advice, COFI shifts the regulatory centre of gravity to outcomes: whether customers are actually treated fairly, and whether the institution can demonstrate it.


The practical difference is best captured in one sentence: FAIS asks whether you have the right policies and processes in place; COFI asks whether you can prove they consistently produce fair outcomes for clients and or whether, policies claimed to be in place, actually change organisational behaviour, and improve overall conduct, resulting in better outcomes for customers”


That word, prove, is the operational heart of the change. Under COFI, the governing body of an FSP carries explicit accountability for embedding a Treating Customers Fairly culture. Governance, leadership decisions, client engagement, and operational transparency all come under greater scrutiny. Having a TCF policy in a file won't be enough; the regulator's interest moves to whether your day-to-day conduct, across every client and every interaction, reflects it. Much of the work done under FAIS remains relevant. COFI is an evolution, not a reset. But the burden of demonstration is new in degree, and it lands on your records.



When is COFI coming, and why prepare before it's law?


At the time of writing, the COFI Bill has not yet been promulgated. Industry consensus, however, is that it's a matter of when, not if, and that once enacted, practices will get a transition period to align. This was a central theme when FSPHub joined a COVER-hosted panel on COFI preparation alongside Anton Swanepoel of Trusted Advisers and Jaco Moolman of Lighthouse Risk Consulting.


The panel's message was consistent: waiting for the final legislation before starting is a trap. The practices that begin now can spread the effort over months of normal operation; the practices that wait will compress the same work into a pressured transition window, on top of business as usual. There's a second reason to move early, that's less discussed: evidence has a start date. COFI will ask practices to demonstrate consistent conduct.


A brokerage whose systems have been capturing complete communication records, workflow histories, and decision trails for two years walks into the transition with an evidence base already built. A brokerage that starts capturing at promulgation starts from zero. You cannot retroactively create a track record.



Why does the "compliance project" approach fail small brokerages?


The conventional response to new regulation is to treat it as a project: appoint someone, write policies, build registers, create checklists, add reporting. For large institutions with compliance departments, this works, expensively. For a small brokerage it fails, predictably, for one structural reason: Anything that exists as a separate layer of work competes with client work and loses.


When compliance means extra filing, extra registers, and extra documentation done after the real work, it gets done late, thinly, or not at all. Not because the team doesn't care, but because the day is already full. The compliance file becomes an ongoing reconstruction exercise: assembling evidence after the fact from inboxes, memories, and scattered documents.


This is the same admin trap we've written about in the context of efficiency; disconnected tools forcing humans to bridge the gaps manually, now wearing a regulatory costume. And it points to the same conclusion: the answer isn't more manual effort. It's changing where the work lives. The panel discussion put it plainly: compliance cannot sit outside the advice process as a separate function. It must be embedded in how the business operates.



How do everyday operations become a compliance evidence base?


Here is the reframe that changes everything for a small practice: The evidence COFI will ask for is mostly a record of work you're already doing. Client communications. Follow-ups. How a complaint was handled. Whether the renewal process happened consistently.


Who did what, when, and what the client was told. The problem was never that this work doesn't happen. The problem is that it happens in places that don't keep records - individual inboxes, phone calls, WhatsApp chats, people's heads. Demonstration fails not at the conduct stage but at the capture stage.


So, the operational logic runs: You cannot demonstrate what you cannot see. You cannot see what was never captured. And nothing gets captured reliably when it depends on someone filing as a separate task. The structural fix is to run client work through systems that record it as a side effect:


Email inside the client record


When every client email files itself against the client's record automatically, your communication history, the single richest source of conduct evidence, builds itself. No filing discipline required, no inbox archaeology when evidence is needed. The same architecture extends to WhatsApp and other channels: same routing, same record, same audit trail. (This matters more than many practices realise as informal channels are precisely where conduct risk hides when they sit outside the system.)


Workflows as living documentation


COFI rewards consistent, documented processes. When your claims intake, renewals, and complaints processes exist as workflows in a system, with steps, owners, and timestamps, the process of documentation and the proof of adherence are the same thing. You don't document the process and then separately evidence that you followed it; the workflow history is both.


A single client view as the demonstration layer


When a compliance officer, an auditor, or a regulator asks "show me this client's history," the answer becomes one screen: Every communication, every task, every document, every decision, timestamped. The difference between producing that in minutes versus reconstructing it over days is the difference between compliance as a by-product and compliance as a burden. One honesty note, and it's an important one: systems alone don't solve compliance. Technology can't fix weak governance or supply a fair-treatment culture that leadership doesn't model. What it can do, and what small practices need most, is to remove the operational complexity of demonstrating the good conduct that's already happening.



How should a small brokerage start? Breaking down the elephant


The panel's most practical advice was to stop seeing COFI as one enormous project. Broken into foundations, the sequence looks like this, and deliberately mirrors the sequence for escaping the admin trap, because it's the same sequence:


1. Consolidate the client record

One place where each client's communications, documents, policies, and tasks live. This is simultaneously your efficiency foundation and your evidence foundation.


2. Bring email (and then other channels) inside

Automatic capture of client communication is the single largest evidence gap closed for the smallest behavioural change; the team keeps working exactly as before.


3. Systematise your two or three core processes

Claims, renewals, complaints. In-system workflows give you consistency, visibility, and self-writing adherence records at once.


4. Review governance with your compliance officer

Map who is accountable for what, and check that the operational records your systems now produce line up with what COFI-era oversight will want to see. This is where the specialist compliance advice belongs, on a foundation that can actually support it.


5. Build the habit of demonstration

Periodically ask the practice's own version of the regulator's question: pick a client, and see how quickly and completely you can tell their story from the system. Where it's slow or gappy, you've found your next fix, before anyone official asks.



Can compliance actually become a competitive advantage?


It can, and for small brokerages, it may be the most underused positioning available. In a relationship business, trust is the differentiator, and demonstrable good conduct is trust with receipts. A practice that can show a prospective client, or a prospective acquirer, or a product provider, clean records, consistent process, and full communication histories is signalling something rivals can't fake quickly.


There's also a quieter advantage: the same visibility that satisfies a regulator gives the owner oversight, where work is sitting, where service is slipping, which clients are going quiet. The evidence base and the management information are the same data.


That's the real conclusion of the COFI story for small practices. Regulation is forcing you to build something: complete records, consistent process, operational visibility, that you should have wanted anyway, because it's also what growth runs on. The brokerages that treat COFI as a prompt to fix their foundations won't just pass the transition. They'll come out of it running better businesses.


FSPHub is a practice management platform built for South African financial services providers. It brings client communications, workflow, and compliance capture into one system, so that demonstrating good conduct becomes a by-product of daily work rather than a separate burden.


If you'd like to see what a self-building audit trail looks like in practice, get in touch for a demonstration.





 
 
 

Comments


bottom of page