1. Introduction

This is the conflict of interest management policy of Savvyly (Pty) Ltd (registration 2020/858524/07). Section 3A(2) of the General Code of Conduct for Authorised Financial Services Providers and Representatives requires every authorised financial services provider to adopt, maintain and implement such a policy, and sets out what it must contain. The firm is not yet authorised: its application for a licence covering KASI COIN is in progress, and the Code's duties bind it from the date the licence is granted. The board adopts this Policy now, so that the firm operates it before authorisation rather than starting on the day of it, and the Policy applies in full — including the duties that are the Code's own, such as publication and the report to the Authority — from authorisation. The firm applies it to the whole of its business — not only to the financial service its licence application covers — because the conflicts that matter most to the firm's clients arise where its two businesses meet.

The Policy builds on the conflicts and related-party procedure in the Corporate Governance Framework (SAV-GOV-001) §4.2 and §4.3 and is consistent with it. That Framework states the board's accountability and the directors' duties under section 75 of the Companies Act; this Policy states how the firm identifies, avoids, mitigates and discloses conflicts in its dealings with clients, and what everyone who acts for the firm must do.

1.1 The Policy in brief

What this Policy means, in plain words

A conflict of interest is any situation in which Savvyly, or someone acting for Savvyly, has an interest that could get in the way of treating a client fairly and in the client's interest.

We look for conflicts actively: everyone who acts for us declares their interests when they join, every year, and whenever something changes, and we check for conflicts before we take on a new product, provider or institution.

Where we can avoid a conflict, we avoid it. Where we cannot, we say why, put measures in place to stop it affecting the client, and tell the client in writing what the conflict is and what we have done about it.

We do not accept gifts or benefits that could influence us. From the parties the General Code names, nothing above R1 000 a year is accepted unless it is paid for at fair value, and every such benefit is recorded, whatever its value.

We run two businesses — KASI COIN, a financial service, and a core-banking software service for cooperative financial institutions — and we keep them apart where they meet, so that neither is used to gain an advantage in the other at a client's expense.

This Policy is published on our website and a copy is available free of charge on request. Breaking it has consequences, up to dismissal, termination of a contract or debarment.

1.2 Document control

1.3 Approval

1.4 Revision history

1.5 Relationship to the other governing documents

2. Scope

2.1 Who it applies to

The Policy binds the firm and every person who acts for it: both directors; every employee from the first appointment; every representative the firm appoints under its licence; every individual contractor; and every person a provider makes available to the firm. It also reaches the firm's associates and the directors' associates, in this sense: section 3A(3) of the General Code forbids the firm or a representative from avoiding, limiting or circumventing section 3A through an associate or an arrangement involving one, and a benefit routed to a spouse, a relative, a partner or a company a person controls is treated as a benefit to that person.

2.2 Both platforms

Savvyly runs two businesses. KASI COIN, a rand-backed stablecoin on the Stellar public ledger, is the financial service the firm's licence application covers, and the General Code will apply to it in full from authorisation. The Savvyly core-banking platform is a software service for cooperative financial institutions and is not a financial service under the FAIS Act (Client Conduct and TCF Framework, SAV-CLI-001 §2.1). The Policy nonetheless applies to both, for three reasons. The same people run both; a conflict arising in the core-banking business can affect how the firm treats a KASI client; and an institution may be a client of both businesses at once, which is where the firm's interests are most likely to pull against a client's. Where this Policy uses "client" it means a client of the KASI business in the General Code's sense; where it refers to an institution using the core-banking platform it says so.

2.3 What a conflict of interest is

The Policy uses the General Code's definitions in section 1, which are summarised here in plain words and govern where the summary falls short.

3. Principles

Five principles govern everything that follows. Avoid first. A conflict that can be avoided is avoided; mitigation and disclosure are for the conflicts that cannot be, and the reason is recorded (s.3(1)(b)). The client's interest comes first. Where the firm's interest and a client's differ, the client's interest is given appropriate priority (s.3(1)(d)). Disclosure is not a cure. Telling a client about a conflict does not make an unfair outcome fair; it is required in addition to avoidance or mitigation, never instead of them. Nothing through the back door. An arrangement that would be forbidden if made directly is forbidden if made through an associate, a provider or the other platform (s.3A(3)). The record is the control. A conflict that is not in the register is not managed, and a decision taken by a person with an undeclared interest is reopened.

4. Identifying conflicts

4.1 How conflicts are identified

The firm identifies conflicts through the following mechanisms (s.3A(2)(b)(i)(aa)), each of which produces an entry in the conflicts register or a recorded "nothing to declare".

4.2 The conflicts the firm has identified

The conflicts below are structural: they follow from what the firm is, and they will exist for as long as it does business in this form. Each is in the conflicts register with the measures in §5 and the disclosure in §8.

4.3 The point where the two platforms meet

Conflicts C-04 and C-05 are the ones this Policy most exists for, because they are the ones a client cannot see. The firm's rules are these. What crosses is limited to what the payment needs. The information that passes between the platforms is limited to what is needed to establish that a member can receive a payment and to carry an institution's own officers' approvals to them and back; the interface never carries an instruction to move value, and every call is logged with the institution, the purpose and the identifiers touched (control G1). A new crossing point is a board decision. Adding a crossing point, or changing what crosses an existing one, is a reserved matter under the Corporate Governance Framework §3.4 and is recorded in the conflicts register with its assessment. An institution's data is the institution's. Information the firm holds as an institution's operator is processed only on that institution's instructions (POPIA ss. 20–21) and is never used to market KASI, to onboard a KASI customer, or to make a KASI decision about a member; a member becomes a KASI customer only through their own relationship with the firm. KASI decisions are not commercial decisions. Screening, freezing, clawback, limits and case decisions about an institution or its members are taken by the compliance role under the Risk Management and Compliance Programme and without regard to the firm's revenue from the institution; the person who manages the institution's commercial relationship takes no part in them.

Neither relationship is a condition of the other unless the board has so decided by resolution with the reason recorded, and the institution has been told so in writing before it signs. The prices of the two services are set and disclosed separately.

5. Avoiding and mitigating conflicts

5.1 Avoid first

Before accepting an interest, a relationship or an arrangement that would create a conflict, the person concerned — and for any matter involving the firm, the board — asks whether it can simply not be done. The firm has avoided the following conflicts rather than managing them: it gives no financial advice, so no person recommends a product in which the firm has an interest (SAV-CLI-001 §2.2); it pays nobody by reference to transaction volume or throughput per institution (SAV-GOV-001 §10); it holds no ownership interest in any third party; and it does not describe itself or its services as "independent" (s.3(5)).

5.2 Where a conflict cannot be avoided

Where avoidance is not possible, section 3A(2)(b)(i)(bb) requires the reason and the mitigating measures to be stated. They are stated here for each structural conflict, and for any other conflict in its register entry.

5.3 Decisions by a conflicted person

A person with a conflict in a matter does not decide it, approve it, review it or take part in the discussion of it. The matter goes to the other director where a director is conflicted, and to the Chief Operations Officer (or, if the COO is conflicted, to the Chief Executive Officer) in every other case. The decision records that it was taken without the conflicted person. A decision later found to have been taken by a person with an undeclared interest is recorded as a breach (§11) and reopened by someone who has none.

6. Financial interests

6.1 What may be received or offered

Section 3A(1)(a) limits the financial interests a provider or its representatives may receive from, or offer to, a third party. The commissions and fees under the insurance and medical schemes legislation in items (i) to (iv) are not part of the firm's business. The firm and everyone acting for it may therefore receive or offer a financial interest from or to a third party only if it is: a fee or remuneration for a service rendered to that third party, which must be reasonably commensurate with the service, must not pay the firm twice for a similar service, must not create a conflict that is not effectively mitigated, and must not impede fair outcomes for clients (s.3A(1)(a)(v) and (d)); an immaterial financial interest (s.3A(1)(a)(vi)); or a financial interest for which fair value is paid at the time it is received (s.3A(1)(a)(vii)). Nothing else is accepted or offered. The fees the firm charges its own clients under the published fee schedule are not financial interests from a third party and are governed by the Client Conduct and TCF Framework.

6.2 Gifts, hospitality and the immaterial threshold

Because the immaterial threshold is an aggregate — R1 000 in a calendar year from the same third party — nobody can know whether it has been crossed unless everything is recorded. So every financial interest received from or offered to a third party is entered in the conflicts register when it is offered, whatever its value, with who offered it, to whom, what it was, its value, and whether it was accepted. An interest that would take the aggregate from one third party above R1 000 in the calendar year is declined, or paid for at fair value. Nothing, of any value, is accepted from a person whose matter is under decision.

The code of conduct in the Corporate Governance Framework §4.1 applies the same discipline more widely: no gift, hospitality or inducement above R1 000 in a year from any supplier, customer, institution, representative or counterparty — whether or not a third party in the Code's sense — is accepted without disclosure to the other director and an entry in the conflicts register. The two rules are read together and the stricter applies.

6.3 What the firm offers a representative

Section 3A(2)(b)(ii) requires the Policy to specify the financial interest the firm offers a representative and the basis of entitlement, and to show how it complies with sections 3A(1)(b) and (bA). The firm has appointed no representative at the date of this Policy; this section takes effect at the first appointment.

6.4 Directors, staff and contractors

Nobody who decides anything about a client or an institution is paid more for an outcome that is worse for that client: no commission on transaction volume or value, no incentive for clearing a queue, no reward for an institution's choice of KASI or for a KASI customer's choice of an institution (SAV-GOV-001 §10). Directors' remuneration is set by board resolution and disclosed in the annual financial statements. A contractor is paid for approved hours or deliverables and not by reference to the firm's business volumes.

7. Associates and ownership interests

Section 3A(2)(b)(iii) and (v) to (vii) require the Policy to list the firm's associates, the names of any third parties in which the firm holds an ownership interest, the names of any third parties that hold an ownership interest in the firm, and the nature and extent of those interests. They are in Appendix A as declared by the directors at the date of adoption. The board confirms Appendix A when it adopts this Policy and whenever it changes; a change is made to Appendix A, and the Policy republished, within fourteen days. The directors' own associates and outside interests are recorded in the conflicts register rather than published, because they are personal information and the Code requires the firm's associates, not the directors', to be listed; any of them that gives rise to a conflict with a client is disclosed to that client under §8.

8. Disclosure

Where a conflict cannot be avoided, the firm discloses it to the affected client in writing at the earliest reasonable opportunity (s.3(1)(c)). The disclosure states: the measures taken under this Policy to avoid or mitigate it; any ownership interest or financial interest, other than an immaterial financial interest, that the firm or its representative may be or become eligible for; and the nature of any relationship or arrangement with a third party that gives rise to the conflict, in enough detail for the client to understand exactly what it is. Every disclosure also tells the client that this Policy exists and how to obtain it.

The disclosure to KASI clients is generated from the conflicts register, so that it cannot say less than the register does, and it reaches individual customers at onboarding and in the app, not only institutions (SAV-CLI-001 §9). An institution that uses the core-banking platform and is also a KASI customer, channel or partner is told in writing, in its agreements, of conflicts C-04 and C-05 and of the rules in §4.3. Disclosure is made in plain language, in addition to avoidance or mitigation and never in place of them.

9. The conflicts register and internal controls

The conflicts register, kept on the platform, is the record of this Policy in operation (s.3A(2)(b)(i)(dd)). It holds: every declaration of interests, with its date; every identified conflict, with the measures taken, the reason where it could not be avoided, and the disclosure made; every financial interest received from or offered to a third party, accepted or declined; every recusal from a decision; and every review. An entry is never deleted; a closed conflict is closed with a date and a reason. The register is kept for at least five years after the relationship or matter it concerns ends (General Code s.3(2)), and board minutes recording a director's disclosure for seven years (Companies Act s.24).

The controls around it are these. No person is given access to the firm's systems until their declaration is recorded (a Joiner checklist item). The compliance role reviews the register monthly — new entries, financial interests against the R1 000 aggregate, declarations due, and the log of the interface between the platforms — and the review is a standing item at the monthly executive meeting. The internal-audit catalogue tests monthly that the review happened and that every decision in the period by a person with a declared interest was taken by someone else. A conflict involving a director is decided by the other director, and one involving anyone else by the Chief Operations Officer.

10. Training and awareness

Everyone acting for the firm is made aware of this Policy and trained on it (s.3A(2)(d)). It is part of the induction every person completes before access is granted (SAV-PPL-001 §6) and of the annual refresh; a provider's people complete the same module under their agreement; and a representative is trained on it before appointment. The training covers what a conflict is, how to declare one, the R1 000 aggregate and why every benefit is recorded, the rules where the two platforms meet, and the consequences in §12. Where it is appropriate, the firm's associates are told of the Policy's contents. Completion is recorded per person.

11. Monitoring, review and reporting

The firm monitors compliance with this Policy continuously through the monthly review and the internal-audit check in §9, and reviews the Policy itself annually at the fourth-quarter board meeting (s.3A(2)(e)). A breach of the Policy — an undeclared interest, a benefit accepted outside §6, a decision taken by a conflicted person, a disclosure not made — is recorded in the breach log under the Compliance Management Framework (SAV-CMP-001) §6 on the day it is found, with its root cause and corrective action.

Section 3A(4) requires a report on the Policy in the compliance reports submitted to the Authority, covering at least its implementation, the monitoring of it, compliance with it and its accessibility. From authorisation, while the firm has no compliance officer, the firm itself includes that report; once one is appointed, the compliance officer does. The report is also given to the board with the quarterly compliance report.

12. Consequences of non-compliance

A breach of this Policy is treated as serious, because a conflict that is hidden is a risk the client cannot see (s.3A(2)(b)(i)(ee)).

13. Publication and access

The firm publishes this Policy on its website, savvyly.tech — it was published on adoption on 24 September 2026, ahead of the duty that applies from authorisation — where it is easily accessible for public inspection at all reasonable times (s.3A(2)(f)), and provides a copy free of charge to anyone who asks at support@savvyly.tech. Every disclosure under §8 says where the Policy can be found. The Policy is written to be read by a client, not only by a regulator (s.3A(2)(b)(viii)); §1.1 summarises it in plain words, and a client who does not understand how it applies to them may ask and will be answered in writing.

Appendix A — Associates and ownership interests

As declared by the directors and confirmed by the board in the resolution adopting this Policy (SAV-GOV-004, 24 September 2026).

Appendix B — General Code section 3A: where each requirement is met