Shadow AI Risk Calculator for Financial Services | Cuumulo Nymbis
Cuumulo Nymbis

Calculate the cost of unmanaged AI in your organisation

Estimate what your organisation could face in POPIA penalties if AI usage isn't governed.

1. Your team size
50
51,000
2. Do you believe anyone in your organisation could be inputting sensitive client, employee, or financial information into AI tools?
3. Which of these sounds familiar? (select any that apply)
4. How many clients does your firm serve?

That's good to hear. But are you sure?

Most organisations that say this discover the opposite once they look closer. Studies show that up to 80% of employees use unapproved AI tools at work.

A 30-minute conversation costs nothing. Not having one could cost millions.

Source: UpGuard, 2024 Shadow IT and AI Survey.

Your estimated POPIA exposure
In practice, enforcement outcomes are often settled at a fraction of statutory exposure, in some cases around 50% or less. This figure represents an estimate and is not a guaranteed outcome.
What this means for your firm
Shadow AI users in your firm
Regulated data transfers per year
Estimated fine per infringement
Compliance risk
POPIA Precedent: R5M Fine
The Department of Justice was fined R5 million for failing to renew basic security software, a passive oversight. Actively uploading client portfolio data and bank statements to foreign AI servers represents a deliberate transfer of personal information the Regulator has signalled it will treat with increasing severity.
Source: Information Regulator media statement, July 2023; Regulator's 2026/27 enforcement priorities.
How your data sovereignty is being violated
When your team uses consumer AI tools, client portfolio valuations, claims histories, bank statements, and personal financial records are transferred offshore. Each time an advisor pastes a client's financial data into one of these tools, it constitutes a potential infringement: personal information transferred to a foreign processor without adequate safeguards. Under POPIA Section 72, transborder transfers require binding corporate rules, consent, or contractual necessity. Consumer AI terms satisfy none of these.
Financial services regulatory risk
FSCA and FICA exposure
Neither the FSCA nor FICA prohibit AI usage in financial services. The issue is how consumer AI tools handle the data. Under the FAIS General Code of Conduct, financial services providers must maintain adequate controls over client information and ensure proper risk management procedures. FICA (Financial Intelligence Centre Act 38 of 2001) requires accountable institutions to safeguard client identification and verification records. When that data is processed through consumer AI platforms with terms that permit foreign storage and model training, your firm loses control of records it is legally required to protect. The FSCA can suspend or withdraw an FSP licence under the Financial Advisory and Intermediary Services Act for inadequate governance. AI is not the problem. Using AI without proper data governance is.
This can also mean: Loss of FSP licence, halting all advisory and intermediary activity. Personal liability for directors and key individuals under FAIS. Professional negligence claims from affected clients. Reputational damage that drives client attrition across your book.

Keep your data on South African soil

Find out how to keep every major AI model available to your team, with all data staying on South African soil.

This calculator provides illustrative estimates only and does not constitute legal, financial, compliance, or any other form of professional advice. The figures shown represent potential exposure under POPIA's enforcement framework. They are not predictions of actual fines, settlements, or penalties. Actual enforcement outcomes depend on the Regulator's discretion, the specific circumstances of each case, the degree of cooperation, and potential settlement negotiations. Consult qualified legal counsel for advice specific to your organisation. © Cuumulo Nymbis.

Powered by Nymbis