Effective 1 September 2026, retirement funds are required to report material IT and cyber incidents to the Financial Sector Conduct Authority (FSCA) using the prescribed reporting template submitted through the FSCA Joint Standards Submission Portal.
Trustees must ensure that their incident management and governance frameworks can support a three-stage reporting process for material incidents:
A critical point for trustees is that the 24-hour reporting period begins when the incident is classified as material, not when it is first detected. The requirement is measured in actual hours rather than business hours, making rapid decision-making essential.
Funds should therefore have established escalation procedures that enable key stakeholders, including the principal officer, trustees, administrators, IT and cybersecurity service providers, legal advisers, and communications teams, to assess incidents promptly and determine whether they are material.
Axiomatic’s advice is that trustees should consider whether the incident has had, or is likely to have, a severe and widespread impact on:
Although many retirement funds rely extensively on administrators and external service providers for operational processing, technology infrastructure, and cybersecurity controls, regulatory accountability remains with the board of trustees.
Trustees should also note that reporting to the FSCA does not eliminate any separate notification obligations that may arise under the Protection of Personal Information Act (POPIA) or other applicable legislation. Each regulatory framework must be considered independently.
Talk to Axiomatic about reviewing your incident response plan, governance structures, and service provider agreements before the FSCA comes knocking.
This Cookie Policy explains how we use cookies and similar technologies on our website axioconsult.com. This policy is designed to help you understand what cookies are, how we use them, and the choices you have regarding their use.
Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit certain websites. They are widely used to enhance your online experience by remembering your preferences and actions over time. Cookies are not harmful and do not contain personal information like your name or payment details.
We use cookies for various purposes, including:
You have the option to manage your cookie preferences. You can usually modify your browser settings to accept, reject, or delete cookies. Please note that if you choose to block or delete cookies, some features of our website may not function properly.
We may allow third-party service providers to use cookies on our website for the purposes outlined in Section 3. These providers may also collect information about your online activities over time and across different websites.
We may update this Cookie Policy from time to time to reflect changes in technology, law, or our data practices. Any changes will become effective when we post the revised policy on our website.
If you have any questions about our Cookie Policy or how we use cookies on our website, please contact us at
By continuing to use our website, you consent to the use of cookies as described in this Cookie Policy.