FAIS record-keeping: five years, from when, of what
Five years is the number, and more than one law sets it. Section 18 of the FAIS Act requires an authorised financial services provider to keep records for a minimum of five years of five listed things. Section 3(2) of the General Code of Conduct adds the duty that matters day to day: systems to record every verbal and written communication about a financial service, to store and retrieve them, to keep them safe from destruction, for five years after the product terminates to your knowledge or after the service was rendered, and to produce them within seven days of the regulator asking. POPIA then sets the other edge of the window — personal information may not be kept longer than is necessary unless retention is required by law, and the FAIS five years is exactly such a law — and FICA adds its own five years, but only for FSPs that advise on investments, not for short-term brokers. This page puts the four texts side by side and turns them into a retention schedule.
Reviewed · Broker AI team
The five-year clock: from when
Section 3(2)(b) of the Code fixes the start of the clock, and it is not the date of the advice. All such records must be kept for a period of five years after termination, to the knowledge of the provider, of the product concerned or, in any other case, after the rendering of the financial service concerned. So:
Advice that led to a product
Five years after the product terminates — and only termination you know of. A policy the client cancels with the insurer directly, without telling you, has not terminated to your knowledge; the safe assumption is that the file lives until you can show the product ended. A policy renewed every year has not terminated at all, so the file for a client you have held for a decade runs from the original inception and is still open.
A service with no product
A quote the client declined, a review that recommended no change, advice not to replace: five years after the service was rendered. The Record of Advice under section 9(1) is only required where a transaction results, but the section 3(2)(a) communications about the service are records regardless, and the five years still runs.
The FAIS Act’s own five
Section 18 sets a minimum of five years, without a start date of its own, for known premature cancellations, complaints and whether they were resolved, continued compliance with section 8 (the fit-and-proper requirements), cases of non-compliance with the Act and the reasons, and representatives’ continued compliance with section 13(1) and (2). Read it with the Code’s clock.
What section 18 of the FAIS Act lists
An authorised financial services provider must, except to the extent exempted by the registrar, maintain records for a minimum period of five years regarding:
- 01(a) known premature cancellations of transactions or financial products by clients of the provider;
- 02(b) complaints received together with an indication whether or not any such complaint has been resolved;
- 03(c) the continued compliance with the requirements referred to in section 8 — the FSP’s fit-and-proper status;
- 04(d) cases of non-compliance with this Act, and the reasons for such non-compliance; and
- 05(e) the continued compliance by representatives with the requirements referred to in section 13(1) and (2) — the representative register, competence and supervision.
What section 3(2) of the Code adds — the working rule
Section 18 is a compliance register. Section 3(2) of the General Code of Conduct is about the client file, and it is the paragraph the Ombud and the FSCA actually test against:
Systems, not intentions
A provider must have appropriate procedures and systems in place to (i) record such verbal and written communications relating to a financial service rendered to a client as are contemplated in the Act or the Code, (ii) store and retrieve such records and any other material documentation relating to the client or the service, and (iii) keep such client records and documentation safe from destruction. “Verbal” is in the text: a phone call in which advice was given is a record you must be able to produce, in whatever form you capture it.
Five years, from termination or the service
The clock in the section above.
Seven days
Providers are not required to keep the records themselves but must ensure that they are available for inspection within seven days of the registrar’s request. An outsourced archive, a cloud store, an insurer’s portal — all fine, provided a request on Monday is answered by the following Monday.
Electronic is fine
Records may be kept in an appropriate electronic or recorded format, which is accessible and readily reducible to written or printed form. A recording, a PDF, a CRM entry all qualify; a WhatsApp thread on a representative’s personal phone qualifies too — and is the one that walks out of the door when they leave.
What is in the file the five years protect
The records the five-year rule is really about are the ones a complaint turns on, and every one of them is created by another section of the Code:
- 01The needs analysis and the information it was based on (section 8(1)(a)–(b)); the limited-scope alert where the client narrowed it (section 8(4)(b)).
- 02The Record of Advice (section 9(1)) and the evidence the client received it in writing (section 9(2)) — where a transaction resulted.
- 03The disclosures (section 7): the product’s material terms, exclusions, excesses and waiting periods, your remuneration, the FSP’s status.
- 04For a replacement: the section 8(1)(d) disclosures and the section 9(1)(d) comparison and reasons; for a long-term risk policy, the FSCA replacement advice record.
- 05Every communication about the service — emails and proof they were delivered, call recordings or notes, messages, the renewal notices and the mid-term condition changes an insurer sent through you (section 3(2)(a)).
- 06Complaints and their outcome (FAIS Act section 18(b)); the client’s instructions where they went against your advice (section 8(4)(c)).
POPIA: retention is a duty, hoarding is not
The Protection of Personal Information Act pulls the other way, and the two are reconciled in one sentence. Section 14(1) of POPIA: records of personal information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed, unless (a) retention of the record is required or authorised by law, (b) the responsible party reasonably requires the record for lawful purposes related to its functions or activities, (c) retention is required by a contract between the parties, or (d) the data subject has consented. The FAIS five years is retention required by law, so keeping the advice file for that period is not only permitted but compulsory. What POPIA changes is the end of the window:
- 01Section 14(3): where a record was used to make a decision about a data subject — every advice file is — it must be kept for the period required by law or a code of conduct, or, failing that, long enough for the data subject to request access to it.
- 02Section 14(4): once you are no longer authorised to retain a record you must destroy, delete or de-identify it as soon as reasonably practicable. A client file at year six with no open complaint and no live product is a POPIA exposure, not an asset.
- 03Section 14(5): destruction or deletion must be done in a manner that prevents reconstruction in an intelligible form — emptying a folder is not destruction; shredding and a wiped backup are.
- 04Section 3(3) of the Code sits alongside: no confidential information from a client may be disclosed without written consent, unless disclosure is required in the public interest or under any law. The Ombud and the FSCA asking for the file is “under any law”; a prospective buyer of your book is not.
FICA: five more years, but only for some FSPs
The Financial Intelligence Centre Act lists accountable institutions in its Schedule 1. Item 12, as amended in 2022, covers a person who carries on the business of a financial services provider requiring authorisation under the FAIS Act to provide advice or intermediary services in respect of the investment of any financial product — and expressly excludes a non-life (short-term) insurance policy, reinsurance and a medical scheme benefit. A broker licensed only for short-term lines is therefore not an accountable institution under that item; an adviser on investments, retirement products or long-term insurance is. For those, FICA sections 22 and 23 require the customer due diligence and transaction records to be kept for at least five years from the date the business relationship is terminated or the transaction was concluded. The clock is different from the Code’s, the records are different (identity and verification, not advice), and both run.
A retention schedule that satisfies all four
One table, per client, with a trigger date and a destruction date:
Advice file
Needs analysis, Record of Advice, disclosures, replacement comparison, every communication about the service. Trigger: termination of the product to your knowledge, or the date of the service. Source: Code s3(2)(b).
Complaints register
Each complaint, its date, whether and how it was resolved, the Ombud correspondence. Trigger: resolution. Source: FAIS Act s18(b); Ombud Rule 6.
Premature cancellations
Known early cancellations of products by clients, with the reason where known. Source: FAIS Act s18(a).
FSP and representative compliance
Fit-and-proper evidence for the FSP (s18(c)), non-compliance cases and reasons (s18(d)), the representative register and each representative’s competence and supervision records (s18(e)).
Customer due diligence (accountable institutions only)
Identity and verification records and transaction records. Trigger: termination of the business relationship or the transaction. Source: FICA s22–23.
Destruction
At the destruction date, with no open complaint and no live product: destroy, delete or de-identify irreversibly (POPIA s14(4)–(5)) and log that you did.
Where record-keeping fails
The shapes that turn a record-keeping rule into a lost complaint:
- 01The advice was given on the phone and nobody wrote it down. Section 3(2)(a)(i) names verbal communications; a note dated the same day is the minimum.
- 02The email was sent but cannot be shown to have arrived. Recent Ombud determinations treat a bulk mailer without delivery evidence as a notice never given — keep the audit trail your system already produces.
- 03The representative left and the mailbox, the phone and the WhatsApp threads went with them. Records belong to the FSP, not the individual (section 3(2)(a)(iii)).
- 04Everything is kept forever. Past the window, an old file is a POPIA liability, and a breach discloses a decade of clients instead of five years.
- 05The archive exists but a seven-day request cannot be met — a backup that has never been restored, a former provider’s system nobody can log into.
Build the file as you advise, not after
Broker AI drafts the Record of Advice, the needs analysis and the policy comparison from the documents you upload, dated and stored with the schedule and the disclosures — so the five-year file exists on the day the advice is given, and can be produced in seven days without a search.
Frequently asked questions
- How long must a broker keep client records under FAIS?
- Five years. Section 18 of the FAIS Act sets a minimum of five years for the records it lists, and section 3(2)(b) of the General Code of Conduct requires the client’s advice records and communications to be kept for five years after the product terminates to your knowledge or, where no product resulted, after the service was rendered.
- From when does the five years run?
- From termination of the product, to the provider’s knowledge — not from the date of the advice — or, for a service with no product, from the date the service was rendered. A policy that is still in force keeps its file open.
- Can records be kept electronically?
- Yes. Section 3(2)(d) of the Code allows an appropriate electronic or recorded format that is accessible and readily reducible to written or printed form. You need not hold them yourself, but they must be available for inspection within seven days of the regulator’s request (section 3(2)(c)).
- Do phone calls and WhatsApp messages count as records?
- Yes. Section 3(2)(a)(i) requires systems to record verbal and written communications relating to a financial service. A call in which advice was given must be captured — a recording or a contemporaneous note — and a message thread is a written communication that belongs to the FSP’s file, not to the representative’s phone.
- Does POPIA stop me keeping records for five years?
- No. POPIA section 14(1)(a) permits retention that is required or authorised by law, and the FAIS five years is such a requirement. POPIA governs what happens after: once the period ends and nothing else authorises retention, the record must be destroyed, deleted or de-identified irreversibly (section 14(4)–(5)).
- Does FICA’s five-year rule apply to a short-term broker?
- Not by reason of item 12 of Schedule 1, which covers FSPs advising on the investment of financial products and expressly excludes non-life (short-term) insurance. Advisers on investments, retirement products and long-term insurance are accountable institutions and must also keep FICA’s customer due diligence and transaction records for five years from the end of the relationship or the transaction.
This page is general information about FAIS, POPIA and FICA record-keeping rules, not legal or compliance advice. Statutory wording is from the consolidated texts named in the sources; one secondary source (the FICA Schedule 1 amendment summary) is marked as such. Check the current texts before relying on them.
Sources
- 01Financial Advisory and Intermediary Services Act 37 of 2002 — section 18, Maintenance of records (consolidated text on SAFLII)
- 02General Code of Conduct, Board Notice 80 of 2003 as amended to Board Notice 706 of 26 June 2020 — section 3(2)(a)–(d), section 3(3), sections 7, 8 and 9 (consolidated text hosted by Masthead)
- 03Protection of Personal Information Act 4 of 2013 — section 14, Retention and restriction of records (text of the Act as reproduced by popia.co.za)
- 04Financial Intelligence Centre Act 38 of 2001 — sections 22 and 23 (FIC’s consolidated booklet)
- 05Masthead — “Amendments to FICA Schedules finalised” (the 2022 amendment to Schedule 1 item 12; secondary source summarising the Government Notice)
