AI for brokers

Risk scores and AI in a brokerage: what POPIA section 71 actually requires

The FSCA and PA have mapped AI use in the sector. What POPIA section 71 and FAIS ask of a brokerage that scores client risk and drafts replies with AI.

Published on 8 min readFCB.ai
Contents
  1. What the regulators found, and why it matters to a small FSP
  2. Section 71: the line between a score and a decision
  3. Five things to write down before the scoring goes live
  4. What supervised scoring looks like in a WhatsApp inbox
  5. Frequently asked questions

Most brokerages in South Africa are already running automated profiling, whether or not anyone in the office would call it artificial intelligence. A churn model in the insurer's portal, a lead-scoring column in a spreadsheet, a CRM that turns a client red the day a debit order bounces — each of these takes personal information, produces a judgement about a person, and changes what happens to that person next. That is profiling, and South African law has had something to say about it since long before the current wave of generative AI.

In November 2025 the Financial Sector Conduct Authority and the Prudential Authority published their first joint study of AI use across the financial sector. It is not a rulebook, and it does not create new obligations for a five-person brokerage. What it does is signal where supervision is heading — and remind FSPs that the instruments that already bite are the FAIS General Code of Conduct and section 71 of POPIA.

What the regulators found, and why it matters to a small FSP

The FSCA–PA study drew on roughly 2 100 voluntary responses gathered across banking, insurance, retirement funds, payments and lending. At the time of the survey, just over one in ten respondents reported using AI at all; banks and payment providers sat above half, while insurers were at the bottom of the table, with most planning only modest spend. The risks respondents cited most often were not exotic: data privacy and protection first, then cybersecurity, model inaccuracy and consumer harm. The two authorities said they would follow the report with a discussion paper and stakeholder engagement.

Three practical conclusions for a brokerage principal:

  • Nothing new is required of you today. There is no AI licence, no AI return, no registration. The existing conduct and data rules cover the ground.
  • Explainability is the expectation being set. Supervisors are asking institutions whether they can describe what a model does, who checks it and what happens when it is wrong. That question will reach FSPs through the ordinary channels: a compliance visit, an FAIS Ombud file, a client complaint.
  • Data privacy is the sharp end. The risk the sector itself flags most often is the one POPIA already governs.

Section 71: the line between a score and a decision

Section 71(1) of POPIA says a data subject may not be subject to a decision which results in legal consequences for them, or which affects them to a substantial degree, where that decision is based solely on the automated processing of personal information intended to provide a profile — including their performance at work, credit worthiness, reliability, location, health, personal preferences or conduct.

Two words carry the weight. Solely: if a competent person reviews the output and makes the call, section 71(1) is not engaged. Substantial: ranking who gets a phone call this week is not the same as declining someone's cover. Section 71(2) then carves out decisions taken in connection with the conclusion or execution of a contract where the data subject's request has been met, or where appropriate measures protect their legitimate interests. Section 71(3) defines those measures: an opportunity for the person to make representations about the decision, and enough information about the underlying logic for those representations to be meaningful.

Mapped onto what actually happens in a brokerage inbox:

What the system doesSection 71 territory?What you should have in place
Scores attrition risk to rank this week's call listNo — a person decides and actsRecorded purpose, minimal data, an internal explanation of what drives the score
Classifies an incoming WhatsApp reply as a complaint, an opportunity or a churn signalNo, but it routes a clientHuman review of anything flagged, and a route for misclassified messages
Sends an auto-reply under rules, without a person reading it firstRarely — but it is a communication made in the FSP's nameWritten thresholds, escalation on negative sentiment, retained records
Declines, prices, cancels or excludes a client automaticallyYes, very likelyHuman review before the outcome lands, representations route, logic disclosure

Almost everything a brokerage does with AI on WhatsApp falls in the first three rows. That is a comfortable place to be, but it is only true for as long as a human genuinely stays in the loop. The moment a score silently removes a client from a renewal campaign, or an automated rule ends a conversation, the honest answer to "did a person decide this?" changes.

Five things to write down before the scoring goes live

None of this needs a consultant. It needs a page in the compliance file that a key individual has signed and dated.

  1. Purpose and lawful basis. Why the score exists and which POPIA justification you rely on — usually the performance of the client's contract or your legitimate interests as the FSP, not consent. Say so explicitly; "we always get consent" is rarely accurate and rarely necessary.
  2. The inputs. List the fields that feed the score: policy type, premium status, tenure, response history. Anything you cannot justify keeping should not be feeding a model. Special personal information — health data in particular — deserves a separate line and a harder look.
  3. The human step. Name the point where a person intervenes, and what they see when they do. "The representative reads the conversation before calling" is a control only if the tool actually shows them the conversation.
  4. The representations route. If a client asks why they were treated a certain way, who answers, within what period, and in what words. This is section 71(3) in practice and it costs nothing to prepare in advance.
  5. Records and review. Which log captures automated actions, how long it is kept, and who reviews the model's behaviour — quarterly is plenty for a small book. Under FAIS you already keep client communications; automated ones are not an exception.

The outbound side of the same question — thresholds for auto-replies, what a model may never say, who signs it off — is covered in our guide to what a compliance officer should sign off on AI drafts. If you are still deciding whether to automate at all, the chatbot versus supervised AI comparison sets out the trade-off.

What supervised scoring looks like in a WhatsApp inbox

In ORIS, each customer record carries an attrition risk score and an engagement score. They do two things and no more: they filter Customers & Segments when you build a campaign, and they order the Opportunities & Risks list so the highest-risk clients surface first. Incoming replies are classified by the AI, which also proposes a draft; negative sentiment always produces a draft for a human rather than an automatic send, and messages that need a person raise a notification. Every action lands in the audit log and every conversation stays attached to the client record, which is what makes the section 71 answer easy: a person decided, here is the thread, here is when.

Two habits keep it that way. First, never let a score be the reason a client hears nothing — an at-risk client who drops out of every campaign has been decided about, silently. Second, treat the score as an internal working tool: it belongs in your system and your CSV export, not in a message to the client. Nobody wants to be told a machine rated them a churn risk.

The honest summary is that AI in a brokerage is a governance question with a small technology component. Get the page in the compliance file right, keep a person in the loop where it counts, and a supervisory discussion paper becomes a reading exercise rather than a scramble. If you want to see how the scoring and the human step fit together in practice, book a demo.

Frequently asked questions

Is a churn or engagement score personal information under POPIA?

Yes. A score attached to an identifiable person, derived from their behaviour and used to make judgements about them, is personal information in the same way their premium history is. It falls within your retention policy, a data subject can ask for access to it, and it must be kept accurate — a stale score built on data you no longer hold is its own compliance problem.

Do we have to tell clients we use AI to draft replies?

POPIA does not contain a general "declare your AI" obligation, and section 71 bites only on solely automated decisions with substantial effect. But the FAIS General Code of Conduct requires clear, factual and not misleading communication, and treating customers fairly cuts against letting someone believe a person typed a message that a model produced. Most brokerages settle on a short line in the privacy notice plus honesty on request — and a rule that anything sensitive is written by a human.

The score comes from our insurer's system, not ours. Who is responsible?

Both of you, for different things. The insurer answers for the model; you answer for what you do with the output, because the client-facing decision and the advice are yours. Ask the insurer, in writing, what drives the score and what its known limitations are. If they cannot tell you, you cannot answer a client's representations under section 71(3), and you should be slower to act on it.

Does a small brokerage need a formal AI policy?

A policy document is not required by any current instrument. What is worth having is one signed page covering purpose, inputs, the human step, the representations route and the review cycle. That page answers the questions a compliance visit or an ombud file will ask, and it takes an afternoon rather than a project.

What should we do differently once the FSCA discussion paper lands?

Read it, then check your page against it — do not rebuild anything in advance of a consultation document. The findings so far point at governance, accountability and data privacy rather than new licensing, so a brokerage that can already name who is accountable for each automated behaviour is unlikely to face a large adjustment.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo