This page is for businesses that are accountable institutions under the Financial Intelligence Centre Act 38 of 2001 — the ones that must perform customer due diligence, not the customers who supply the documents.
If you are an estate agent, attorney, accountant handling client funds, financial services provider, credit provider, motor vehicle dealer, dealer in precious metals or Krugerrands, or another business listed in Schedule 1 of the Act, these obligations apply to you, and the penalties for non-compliance are substantial.
Business Requirements at a Glance
Every accountable institution must have and implement the following.
- A documented Risk Management and Compliance Programme (RMCP), which is the central obligation
- Registration with the Financial Intelligence Centre through its goAML system
- An appointed person responsible for compliance, and board or senior management oversight
- Customer due diligence proportionate to assessed risk, including identification and verification
- Identification of beneficial owners of legal persons and arrangements
- Screening against sanctions lists and identification of prominent influential persons
- Record keeping for the prescribed periods
- Reporting of cash threshold, suspicious and unusual, terrorist property and international funds transfer reports
- Training of employees on their obligations
Registration and Legal Requirements
The RMCP is where inspections begin and where most institutions fail. It is not a policy document to be filed. It must set out how your business assesses risk, what due diligence applies at each risk level, how you identify beneficial owners, how you screen, how you report, how you keep records and how you train — and your practice must match it.
A generic RMCP downloaded from the internet is worse than useless: it evidences that you have not assessed your own risks, and inspectors recognise them immediately.
The risk-based approach replaced the old checklist. You no longer apply one fixed document set to everyone. You assess risk by customer, product, delivery channel and geography, then apply simplified, standard or enhanced due diligence accordingly. That flexibility is also an obligation to think, and to document the thinking.
Ongoing due diligence means keeping customer information current and monitoring transactions for consistency with what you know about the customer. A file verified at onboarding and never revisited does not satisfy it.
Reporting obligations are time-bound and are not discretionary. Suspicious and unusual transaction reports must be filed with the Centre within the prescribed period, and you may not tip off the customer. Cash transactions above the prescribed threshold must be reported. Confirm the current thresholds and periods with the Centre.
Documents and Ownership Information Required
What an inspector will ask for, and what your files must contain.
- The current Risk Management and Compliance Programme, approved by the board or senior management
- Evidence of the business-wide risk assessment underpinning it
- Proof of registration with the Financial Intelligence Centre
- Customer files with identification and verification records, and the risk rating applied
- Beneficial ownership records for legal persons, trusts and partnerships
- Sanctions and prominent influential person screening records
- Records of ongoing due diligence and account monitoring
- Copies of reports filed with the Centre, and records of the decisions behind them
- Training records for all relevant employees, with dates and content
- Records of the appointment of the responsible person
- Internal audit or independent review reports on the compliance function
Tax, Licence and Compliance Requirements
Penalties are administrative and substantial. The Centre and supervisory bodies can impose administrative sanctions including significant financial penalties, and enforcement has intensified since South Africa’s greylisting by the Financial Action Task Force. Penalties have been imposed on institutions of every size, including small ones.
Record retention periods are prescribed and run for years after the relationship ends. Records must be retrievable within a reasonable period when requested by the Centre or a supervisory body, which has practical implications for how you store them.
Do not tip off. Where a report is filed, you may not disclose that fact to the customer. This is a criminal offence, and it catches out staff who mean well.
Training is a specific obligation and is inspected. Employees must understand their obligations and be able to recognise and escalate suspicious activity. Records of who was trained, when and on what are part of compliance.
Supervisory bodies differ by sector. The FSCA supervises financial institutions, the Prudential Authority supervises banks and insurers, the Legal Practice Council supervises attorneys, the Estate Agency function supervises property practitioners, and the Centre supervises the rest. Establish who supervises you and follow their guidance specifically.
Process, Deadlines and Ongoing Obligations
Start with a genuine business-wide risk assessment, then write the RMCP from it. Doing it in the other order produces a document that does not describe your business and does not survive inspection.
Then align practice to it: train your people, build the customer file structure, set up screening and monitoring, and test it. An internal review before an inspector arrives is considerably cheaper than the alternative.
- Establish whether you are an accountable institution under Schedule 1
- Register with the Financial Intelligence Centre through goAML
- Do a genuine business-wide risk assessment, then write the RMCP from it
- Never use a generic downloaded RMCP — inspectors recognise them
- Build customer files with risk ratings and beneficial ownership records
- Screen against sanctions lists and identify prominent influential persons
- Train staff and keep dated training records
- File reports within the prescribed periods and never tip off
- Identify your supervisory body and follow its guidance
Frequently Asked Questions
Who is an accountable institution?
Businesses listed in Schedule 1 of the Act — including estate agents, attorneys, financial services providers, credit providers, motor vehicle dealers and dealers in precious metals. Check the current Schedule.
What is an RMCP?
A Risk Management and Compliance Programme setting out how your specific business assesses risk and applies due diligence, screening, reporting, record keeping and training. It is the central obligation and where most inspections begin.
Can I use a template RMCP?
A generic template is worse than useless. It evidences that you have not assessed your own risks, and inspectors recognise them immediately.
Can I tell a customer I reported them?
No. Tipping off is a criminal offence. Where a report is filed, you may not disclose that to the customer.
Obligations, thresholds, reporting periods and retention requirements are set under the Financial Intelligence Centre Act and by supervisory bodies, and are amended. Confirm current requirements with the Financial Intelligence Centre and your supervisory body.