July 20, 2026

After June 6: What South Africa's MyMzansi Feedback Revealed (And What Implementation Actually Looks Like Now)

Craig Hills
Managing Director
at WhoYou

The public comment window on South Africa's MyMzansi digital identity draft regulations closed on June 6, 2026. Banks, civil society bodies, and security researchers submitted their analysis. Government is now working through that feedback. And financial institutions across the country are sitting with a practical problem: you can't build your H2 2026 compliance architecture around regulations that haven't been finalised.

This isn't a reason to stall. It's a reason to be precise about what you know, what remains unresolved, and which infrastructure decisions you can safely make right now.

The Four Gaps That Dominated the Comment Period

Stakeholder feedback from the June comment period coalesced around four unresolved areas. Each one carries different weight depending on your institution's specific compliance posture.

Device recovery. The draft regulations don't specify a clear, auditable protocol for what happens when a citizen loses the phone their MyMzansi credential lives on. For banks, this isn't just a user experience concern. It's a FICA liability question. If a customer can't produce their digital identity document during an account review or re-verification event, and there's no government-sanctioned recovery pathway that maintains the integrity of the original identity binding, institutions are left holding the gap.

Our earlier analysis on MyMzansi's device recovery gaps explored this in detail. The comment period confirmed it's the single most contested technical gap in the draft.

Verifier ecosystem clarity. The draft regulations address credential issuance. They don't adequately specify which categories of institution can act as verifiers, what technical obligations apply to verifiers, or how liability flows when a verification fails or is compromised. A bank accepting a MyMzansi credential as the basis for KYC needs to know whether that acceptance satisfies the Financial Intelligence Centre Act. Right now, that answer isn't in the regulations.

Biometric strength requirements. The draft references biometric authentication without specifying minimum standards for liveness detection, presentation attack detection thresholds, or algorithm performance benchmarks. ISO/IEC 30107-3 provides an international reference point, but the draft doesn't anchor to it. This matters because biometric authentication in a KYC context isn't a binary yes/no decision. The standard you set determines your exposure to spoofing, synthetic identity fraud, and regulatory challenge.

Offline usage. South Africa has real connectivity gaps. Parts of Limpopo, the Eastern Cape, and rural KwaZulu-Natal don't have the reliable data infrastructure that a purely online credential verification system assumes. Stakeholders pushed for defined offline usage parameters.

The draft doesn't settle this. Without clarity, institutions operating in lower-connectivity environments can't design compliant verification workflows for those contexts.

None of these gaps are fatal to the MyMzansi project. But they do mean that any institution treating the June 6 comment closure as a green light for MyMzansi-first architecture planning is building on assumptions, not confirmed regulatory fact.

Why the Regulatory Pressure Still Runs Hot

Understanding why these gaps matter requires stepping back from the draft itself and looking at the broader compliance environment.

South Africa's removal from the FATF grey list came with conditions. The post-delisting baseline isn't just about having the right laws on the books. It's about demonstrating that financial institutions are executing on those laws with consistent, verifiable KYC and AML verification processes. The FATF grey list exit analysis published earlier this year laid out why continued scrutiny from FATF makes identity verification infrastructure a board-level topic, not just a compliance team one.

Any MyMzansi gap that could allow identity verification to degrade in quality is a gap that FATF will eventually find.

Alongside that, the Information Regulator has been escalating its enforcement posture under POPIA. More enforcement notices are being issued. Fines are no longer theoretical. And the combination of a digital identity system that creates new categories of sensitive personal data, including biometric templates and device-binding records, without clear data minimisation and purpose limitation guidance puts institutions in a genuinely uncertain position.

These two forces, FATF's continued scrutiny of AML/KYC depth and the Information Regulator's expanding POPIA enforcement footprint, don't pause while government analyses feedback. You're operating in a live regulatory environment, with evolving obligations, while the identity framework you're supposed to integrate with is still being worked out.

What Practical Implementation Looks Like Right Now

The most defensible position in H2 2026 isn't waiting. It's building on what's certain while staying architecturally flexible for what isn't.

What's certain: the Department of Home Affairs Smart ID card is real, it's operational, and DHA database verification works. Remote onboarding built on document capture, OCR-based Smart ID recognition, face match, and liveness detection satisfies FICA's electronic verification requirements today. You don't need MyMzansi to run compliant digital identity verification. You need a workflow that captures the right data, matches it against the right source, and produces an auditable record.

What's also certain: the biometric layer you build now will need to integrate with MyMzansi later. That's actually good news for institutions that invest in strong identity verification infrastructure now. A face match and liveness detection layer that meets ISO/IEC 30107-3 standards today will be the same layer MyMzansi's verifier obligations will likely require tomorrow. You're not building twice; you're building once, with a clear upgrade path.

What's uncertain: which specific MyMzansi verifier architecture will prevail, what the offline fallback requirements will be, and whether the device recovery protocol will require institutions to hold any secondary credential data as a recovery anchor. These unknowns don't require you to stop building. They require you to build modular components rather than hardcoded integrations.

The Decision Framework: Wait for MyMzansi or Build a Parallel DHA Strategy

There's a four-variable framework that helps institutions make this call without guessing.

Your regulatory deadline. When is your next FIC or FSCA compliance review? If it's before Q2 2027, you can't bet your KYC architecture on MyMzansi being fully specified and implementable in time. Build on DHA verification now.

Your current onboarding friction. What's your digital onboarding dropout rate? If it's above 20%, you have a business problem that costs you customers every month. That's a problem you can solve today with face match, selfie verification, and liveness detection, none of which require MyMzansi to function.

Your POPIA data posture. If your institution is already under Information Regulator scrutiny or operates in a high-sensitivity data category, adding an unspecified new data flow via MyMzansi before the POPIA obligations around that flow are clear is a risk you might not want to take. DHA verification, via a POPIA-compliant provider, is a known quantity.

Your integration capacity. MyMzansi, when it arrives in implementable form, will require integration work. So does a DHA Smart ID verification layer. The difference is that one is available now and one isn't. If you have the engineering capacity to build one integration in H2 2026, building on what exists and designing it to extend to MyMzansi later is the lower-risk choice.

Institutions that score high urgency on two or more of those variables shouldn't wait. Build the DHA Smart ID verification layer. Design it modularly. When MyMzansi's verifier standards are confirmed, extending the architecture costs far less than starting from scratch under regulatory pressure.

What the Architecture Needs to Handle Either Way

Regardless of which path institutions choose in H2 2026, certain architectural requirements hold across both scenarios.

Biometric verification with active liveness detection isn't optional. Fraud prevention in South Africa has moved beyond document forgery into synthetic identity attacks and presentation fraud. Any verification stack that doesn't include presentation attack detection is a liability waiting to materialise. This is true whether your customers are presenting a Smart ID card or a future MyMzansi credential.

AML verification workflows need to integrate with identity data in near-real-time. The days of batch-processing identity checks against sanctions lists and PEP databases are behind us. FATF's post-delisting expectations, combined with FIC's ongoing guidance on transaction monitoring, mean that the identity layer and the AML layer need to share data efficiently and log that sharing in a way that survives audit.

Audit trails need to be comprehensive and POPIA-compliant simultaneously. That's a harder engineering problem than it sounds. You need to record enough to satisfy an FIC examiner and retain data only as long as POPIA's purpose limitation principle requires. Getting that balance right requires deliberate design, not afterthought.

After the Feedback Period Closes, the Work Begins

The June 6 comment period closing isn't the end of the MyMzansi regulatory process. It's the beginning of the consolidation phase, and government may take several months to produce revised draft regulations or a final implementation framework. In the meantime, your institution's compliance obligations don't pause. Your customers don't stop needing to be onboarded.

Fraudsters don't stop probing identity verification gaps. The practical answer to "what does implementation look like now" is this: build a verified, biometric-anchored, FICA-compliant identity verification stack on the infrastructure that exists today. Design it to extend. When MyMzansi's unresolved gaps get answers, you integrate those answers into a foundation that's already working.

If you're mapping out your H2 2026 identity verification architecture and want to understand where DHA Smart ID verification, face match, and liveness detection can close your current compliance gaps, talk to the WhoYou team. The clarity you can act on is already available.

Craig Hills

Managing Director
Craig Hills is the Managing Director of WhoYou, where he leads the company’s vision and strategy to solve complex digital identity challenges and drive innovation in identity verification and compliance.
Connect on Linkedin

Related articles