Before an AI tool touches your client book: the POPIA questions to put to a vendor
A demo tells you nothing about where client data goes. The POPIA operator, security and cross-border questions a South African brokerage should ask in writing.
The FSCA and PA have mapped AI use in the sector. What POPIA section 71 and FAIS ask of a brokerage that scores client risk and drafts replies with AI.
Most brokerages in South Africa are already running automated profiling, whether or not anyone in the office would call it artificial intelligence. A churn model in the insurer's portal, a lead-scoring column in a spreadsheet, a CRM that turns a client red the day a debit order bounces — each of these takes personal information, produces a judgement about a person, and changes what happens to that person next. That is profiling, and South African law has had something to say about it since long before the current wave of generative AI.
In November 2025 the Financial Sector Conduct Authority and the Prudential Authority published their first joint study of AI use across the financial sector. It is not a rulebook, and it does not create new obligations for a five-person brokerage. What it does is signal where supervision is heading — and remind FSPs that the instruments that already bite are the FAIS General Code of Conduct and section 71 of POPIA.
The FSCA–PA study drew on roughly 2 100 voluntary responses gathered across banking, insurance, retirement funds, payments and lending. At the time of the survey, just over one in ten respondents reported using AI at all; banks and payment providers sat above half, while insurers were at the bottom of the table, with most planning only modest spend. The risks respondents cited most often were not exotic: data privacy and protection first, then cybersecurity, model inaccuracy and consumer harm. The two authorities said they would follow the report with a discussion paper and stakeholder engagement.
Three practical conclusions for a brokerage principal:
Section 71(1) of POPIA says a data subject may not be subject to a decision which results in legal consequences for them, or which affects them to a substantial degree, where that decision is based solely on the automated processing of personal information intended to provide a profile — including their performance at work, credit worthiness, reliability, location, health, personal preferences or conduct.
Two words carry the weight. Solely: if a competent person reviews the output and makes the call, section 71(1) is not engaged. Substantial: ranking who gets a phone call this week is not the same as declining someone's cover. Section 71(2) then carves out decisions taken in connection with the conclusion or execution of a contract where the data subject's request has been met, or where appropriate measures protect their legitimate interests. Section 71(3) defines those measures: an opportunity for the person to make representations about the decision, and enough information about the underlying logic for those representations to be meaningful.
Mapped onto what actually happens in a brokerage inbox:
| What the system does | Section 71 territory? | What you should have in place |
|---|---|---|
| Scores attrition risk to rank this week's call list | No — a person decides and acts | Recorded purpose, minimal data, an internal explanation of what drives the score |
| Classifies an incoming WhatsApp reply as a complaint, an opportunity or a churn signal | No, but it routes a client | Human review of anything flagged, and a route for misclassified messages |
| Sends an auto-reply under rules, without a person reading it first | Rarely — but it is a communication made in the FSP's name | Written thresholds, escalation on negative sentiment, retained records |
| Declines, prices, cancels or excludes a client automatically | Yes, very likely | Human review before the outcome lands, representations route, logic disclosure |
Almost everything a brokerage does with AI on WhatsApp falls in the first three rows. That is a comfortable place to be, but it is only true for as long as a human genuinely stays in the loop. The moment a score silently removes a client from a renewal campaign, or an automated rule ends a conversation, the honest answer to "did a person decide this?" changes.
None of this needs a consultant. It needs a page in the compliance file that a key individual has signed and dated.
The outbound side of the same question — thresholds for auto-replies, what a model may never say, who signs it off — is covered in our guide to what a compliance officer should sign off on AI drafts. If you are still deciding whether to automate at all, the chatbot versus supervised AI comparison sets out the trade-off.
In ORIS, each customer record carries an attrition risk score and an engagement score. They do two things and no more: they filter Customers & Segments when you build a campaign, and they order the Opportunities & Risks list so the highest-risk clients surface first. Incoming replies are classified by the AI, which also proposes a draft; negative sentiment always produces a draft for a human rather than an automatic send, and messages that need a person raise a notification. Every action lands in the audit log and every conversation stays attached to the client record, which is what makes the section 71 answer easy: a person decided, here is the thread, here is when.
Two habits keep it that way. First, never let a score be the reason a client hears nothing — an at-risk client who drops out of every campaign has been decided about, silently. Second, treat the score as an internal working tool: it belongs in your system and your CSV export, not in a message to the client. Nobody wants to be told a machine rated them a churn risk.
The honest summary is that AI in a brokerage is a governance question with a small technology component. Get the page in the compliance file right, keep a person in the loop where it counts, and a supervisory discussion paper becomes a reading exercise rather than a scramble. If you want to see how the scoring and the human step fit together in practice, book a demo.
Yes. A score attached to an identifiable person, derived from their behaviour and used to make judgements about them, is personal information in the same way their premium history is. It falls within your retention policy, a data subject can ask for access to it, and it must be kept accurate — a stale score built on data you no longer hold is its own compliance problem.
POPIA does not contain a general "declare your AI" obligation, and section 71 bites only on solely automated decisions with substantial effect. But the FAIS General Code of Conduct requires clear, factual and not misleading communication, and treating customers fairly cuts against letting someone believe a person typed a message that a model produced. Most brokerages settle on a short line in the privacy notice plus honesty on request — and a rule that anything sensitive is written by a human.
Both of you, for different things. The insurer answers for the model; you answer for what you do with the output, because the client-facing decision and the advice are yours. Ask the insurer, in writing, what drives the score and what its known limitations are. If they cannot tell you, you cannot answer a client's representations under section 71(3), and you should be slower to act on it.
A policy document is not required by any current instrument. What is worth having is one signed page covering purpose, inputs, the human step, the representations route and the review cycle. That page answers the questions a compliance visit or an ombud file will ask, and it takes an afternoon rather than a project.
Read it, then check your page against it — do not rebuild anything in advance of a consultation document. The findings so far point at governance, accountability and data privacy rather than new licensing, so a brokerage that can already name who is accountable for each automated behaviour is unlikely to face a large adjustment.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
A demo tells you nothing about where client data goes. The POPIA operator, security and cross-border questions a South African brokerage should ask in writing.
Section 35 of the Data Protection Act, the DPIA that automated decisions trigger, and the ODPC registration a small Kenyan brokerage cannot skip.
Sentiment models score lower on isiZulu and Sesotho than on English. How a brokerage should test its WhatsApp classifier before letting it reply on its own.