South Africa's Draft National AI Policy, currently moving through Cabinet approval before the March 2026 public consultation, adopts a distributed approach to AI governance. Instead of establishing a standalone AI regulator, the policy integrates oversight within existing sector authorities. For GRC leaders managing cross-border AI deployments or evaluating governance models, this offers a practical alternative to comprehensive regulatory regimes.
Checklist for Aligning with South Africa's AI Governance
This checklist helps organizations operating in or with South Africa align AI governance practices with the emerging multi-regulator model. It focuses on readiness activities you can complete before sector-specific strategies take effect in 2027/2028, using existing compliance frameworks as a foundation.
Prerequisites
Before using this checklist, ensure you have:
- Current AI inventory: A documented list of all AI systems in production, including vendor-supplied models and internally developed tools.
- Ownership clarity: Identified business owners and technical custodians for each AI deployment.
- Existing compliance baseline: Understanding of your obligations under POPIA, sector-specific conduct rules, and applicable prudential standards.
- Access to training data lineage: Documentation of datasets used to train or fine-tune models, including geographic origin and demographic composition.
Readiness Checklist
1. Map AI Deployments to Regulatory Frameworks
Identify which current regulator oversees each AI system based on its function and sector context.
Done when: Every AI system has a documented regulatory touchpoint (ICASA for communications infrastructure, prudential regulators for financial services risk models, sector conduct authorities for customer-facing decisioning). Systems spanning multiple regulators are flagged.
2. Classify Systems by Impact Level
Determine which AI deployments qualify as "high-impact" under a human-centered deployment standard.
Done when: You've assigned risk tiers to each system based on the consequence of failure, reversibility of decisions, and affected population size. High-impact systems (credit decisioning, medical diagnosis support, employment screening) are clearly flagged and subject to enhanced governance.
3. Document Model Explainability Mechanisms
Assess whether you can articulate how each AI system reaches its outputs, particularly for high-impact applications.
Done when: For every high-impact system, you can produce documentation explaining input features, decision logic, and confidence thresholds in terms a non-technical regulator would understand. "Black box" models requiring remediation or replacement are identified.
4. Audit Training Data for Imported Bias
Review whether AI models trained on non-South African datasets produce discriminatory outcomes when applied to local demographics.
Done when: You've tested high-impact models against representative South African demographic segments and documented performance disparities. A remediation plan for models showing bias is established, including retraining on local datasets or implementing bias correction layers.
5. Align AI Governance with King IV Principles
Verify that AI oversight sits within your existing governance framework rather than operating as a separate program.
Done when: Your board or equivalent governance body receives regular AI risk reporting. AI accountability is integrated into existing risk management structures, not siloed in IT or innovation teams. Roles and responsibilities for AI-related decisions are documented in governance charters.
6. Verify POPIA Compliance for AI Data Flows
Confirm that AI systems' data collection, processing, and retention practices meet existing data protection obligations.
Done when: Every AI system has a current Data Processing Register entry. Legal bases for processing (including special categories of data if applicable), retention periods, and Individual Rights procedures specific to AI-generated decisions are documented. Automated decision-making that produces legal or similarly significant effects has appropriate safeguards.
7. Establish Accountability for AI-Driven Outcomes
Clarify who remains responsible when AI systems cause harm, regardless of automation level.
Done when: Human oversight requirements for high-impact systems are documented. Override procedures exist and are tested. Incident response plans explicitly address AI-related harm scenarios. Insurance coverage has been reviewed for AI liability gaps.
8. Prepare for Sector-Specific Strategy Consultation
Identify which aspects of the Draft AI Policy will most affect your operations and prepare substantive input.
Done when: A lead for the 60-day public comment period starting March 2026 is designated. Positions on explainability standards, oversight models, and compliance timelines relevant to your sector are drafted. Coordination with industry associations is done where appropriate.
9. Assess Compute and Skills Capacity
Evaluate whether your current AI infrastructure and talent base can support responsible local development.
Done when: Compute resources (including GPU capacity for model training) are inventoried and gaps identified. Your team's capability to develop, validate, and maintain AI systems using South African datasets is assessed. A skills development plan aligned with the policy's capacity-building pillar is created.
10. Document Cultural and Linguistic Considerations
For customer-facing AI systems, verify that language models and interfaces serve South Africa's linguistic diversity.
Done when: AI systems support required languages for your customer base. Voice interfaces, chatbots, or content generation tools are assessed for equitable performance across language groups. Systems that may marginalize speakers of indigenous languages are flagged.
Common Mistakes
Treating this as a standalone AI compliance program: The multi-regulator model means AI governance integrates with existing obligations. Creating a separate AI compliance team disconnected from POPIA, prudential, or conduct compliance creates gaps and duplication.
Waiting for final regulations before acting: Sector-specific strategies won't arrive until 2027/2028. Organizations that defer readiness work will face compressed implementation timelines and limited influence during consultation periods.
Assuming vendor AI systems are compliant by default: Third-party AI tools and models carry the same accountability requirements as internally developed systems. Your organization remains responsible for outcomes even when using vendor solutions.
Focusing only on technical controls: The policy's emphasis on human-centered deployment and ethical AI requires governance, not just technical fixes. Documentation, oversight procedures, and accountability structures matter as much as model performance.
Ignoring the bias testing requirement: Models trained on Global North datasets frequently underperform or discriminate when applied to South African populations. This isn't just an ethical concern; it's a regulatory risk under the responsible governance pillar.
Next Steps
The 60-day public consultation period is your clearest opportunity to shape sector-specific implementation. Prepare substantive comments based on your readiness assessment, focusing on practical implementation challenges rather than general principles.
Between now and 2027, use existing regulatory touchpoints to validate your approach. Engage your current sector regulator on AI governance expectations. Most authorities are developing AI oversight capabilities within their existing mandates; early dialogue helps both parties.
Finally, recognize that this distributed oversight model creates coordination complexity but also flexibility. Unlike comprehensive AI regimes, you can tailor governance intensity to actual risk. A low-stakes internal productivity tool doesn't require the same controls as a customer-facing credit model. The multi-regulator approach rewards proportionate, risk-based governance over checkbox compliance.




