FICA Compliance in South Africa 2026: KYC and Identity Fraud After the Grey List Exit
FICA compliance is the set of obligations under South Africa’s Financial Intelligence Centre Act (Act 38 of 2001, as amended) that require accountable institutions to identify and verify clients, assess money laundering, terrorist financing and proliferation financing risk, monitor transactions, keep records and submit regulatory reports to the Financial Intelligence Centre.
The law looks very familiar. The 2026 test is more practical.
South Africa left the FATF grey list on 24 October 2025 after 32 months under increased monitoring and the completion of all 22 items in its action plan. The FATF decision improved the country’s external risk standing. The European Union followed, removing South Africa from its list of high-risk third-country jurisdictions with effect from 29 January 2026. That decision removed the automatic enhanced-due-diligence requirement linked to the EU listing, while each EU institution retained discretion to maintain or adjust its own risk policies towards South Africa.
South Africa’s exit from the FATF and EU lists reads like a border crossing stamp in the Compliance Traveller’s passport: the country has cleared one checkpoint, but every institution still needs its own papers in order.
Fraud pressure rose at the same time. SABRIC members reported approximately R2.72 billion in actual financial-crime losses during 2024. The report identifies synthetic identities, AI-generated documents and mule networks as current methods. It places the main digital attack route in social engineering and human manipulation, while banking platforms remained technically intact; deepfake voice and video are also beginning to appear in fraud cases.
The grey-list exit closed one chapter. The next test happens inside the institution: can it explain each decision and produce the evidence?
What is FICA compliance in 2026?
FICA compliance starts with a risk-based approach. An accountable institution must register with the FIC, identify and verify clients, establish beneficial ownership, determine whether a client is a politically exposed or prominent person, screen against targeted financial sanctions, monitor transactions, keep records, train staff and submit the required regulatory reports.
Section 42 of FICA requires the institution to develop, document, maintain and implement a Risk Management and Compliance Programme, the RMCP. Such RMCP must explain the money laundering, terrorist financing and proliferation financing risks the institution faces and the controls used to manage them: customer due diligence, enhanced due diligence, reporting, record keeping, monitoring and the way risk decisions are taken across the business. Section 42A separates accountability from support. Where the institution has a board, the board must ensure compliance with FICA and the RMCP. Where there is no board, that responsibility rests with senior management or the person exercising the institution’s highest authority, depending on its legal structure. A legal-person accountable institution must also have a compliance function and assign a person with sufficient competence and seniority to ensure that the function is effective. In practice, senior management turns the approved RMCP into business processes, ownership, escalation and reporting. The compliance function advises, monitors and challenges the business, follows up on weaknesses and keeps the evidence connected. The board or senior management remains accountable for the result.
The RMCP sets the rules. The customer files, alerts and decisions show how those rules were applied.
FICA works through continuing obligations. Registration, an approved RMCP and signed declarations support the compliance file. The proof comes from the client records, risk assessments, screening results, alert histories, reports and approvals that show how the institution applied its controls.
FICA compliance after the grey list exit: the evidence test
South Africa left increased monitoring alongside Burkina Faso, Mozambique and Nigeria at the October 2025 FATF plenary, marking a meaningful regional shift.
National Treasury framed the next phase around continued commitment through measurable outcomes, including successful investigations, prosecutions and sanctions. It also called for stronger institutions, more effective enforcement and sustainable governance improvements.
Treasury was equally precise about the EU decision. The removal of South Africa from the EU list ended the legislative requirement for automatic enhanced due diligence on South African-related transactions. EU institutions remain free to maintain or adjust their own risk policies and to apply stronger controls where the customer, ownership structure, corridor or transaction pattern justifies them.
The next examination is already scheduled. South Africa entered a new FATF evaluation round in 2026, with the final report due at the October 2027 plenary. Treasury also published the draft General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Bill for comment in January 2026. The proposal points towards wider FIC information powers, lifestyle audits and stronger beneficial-ownership enforcement through the Companies Act. Its current status is a draft, giving institutions a clear view of regulatory direction while existing law continues to apply.
The FIC is also collecting entity-level evidence through Directive 11. The 2026 risk and compliance return covers three reporting periods from 2023 to 2026. The first deadline passed on 30 June 2026 for specified credit providers, the Postbank, the South African Mint, crypto asset service providers, trust and company service providers and casinos. Legal practitioners, estate agents, high-value goods dealers and non-casino gambling businesses have until 31 July 2026. In a 17 June 2026 media release, the FIC reported that 655 of the 5,614 registered entities in the first-deadline group had filed, a submission rate of 11.66%. The FIC classifies late or absent submissions as non-compliance and may impose administrative sanctions.
The question is now more demanding: “What does the RMCP say about your business, and can you show how it operates?”
Who is an accountable institution under FICA?
An accountable institution is a business category listed in Schedule 1 of FICA because its services can be abused for money laundering, terrorist financing or proliferation financing. The list includes banks and mutual banks, life insurers, legal practitioners, estate agents, casinos and other gambling businesses, credit providers, crypto asset service providers, money or value transfer providers, trust and company service providers, certain financial services providers and dealers in high-value goods, among others.
Schedule 1 follows the service being provided. For a fintech, the underlying activity determines whether Schedule 1 applies. A payments or lending business enters the perimeter when it performs a listed activity, and a group running several products must map which legal entity performs each activity and which obligations follow.
Each sector carries a different risk profile. A retail bank, an estate agency, a legal practice and a crypto asset service provider need RMCPs that describe the business they actually run: their customers, products, channels, geographies and delivery models. A tailored RMCP makes that connection visible.
The FICA compliance officer: the job is in the evidence
FICA places compliance responsibility on the board and senior management. The compliance function supports that responsibility through a person with sufficient competence, seniority and access to make the work effective.
The title is the starting point.
Can the FICA compliance officer explain why one customer was rated high risk? Which identity evidence was accepted at onboarding? Who is the beneficial owner behind the corporate client? Was the sanctions alert a false positive, and who approved the decision? Why did a monitoring alert remain open beyond the required period? Was the suspicious transaction report filed within 15 days? What information reached the board, and when?
The answers live in the customer journey, the risk model, the alert history, the escalation record and the reporting trail. A compliance officer can defend a decision when onboarding, fraud, AML operations, cybersecurity and product teams preserve one connected version of the evidence.
The FICA Risk Management and Compliance Programme: the document has to match the business
A strong RMCP describes the institution as it operates: where customers enter, which documents are accepted, how identity is verified, when enhanced due diligence applies, how beneficial ownership is established, what expected activity looks like, which scenarios raise alerts and how cases are escalated and reported.
Fraud pressure enters at every one of those points.
A synthetic identity can pass onboarding and leave behind a customer file that looks complete. A genuine customer can be manipulated into approving a fraudulent payment. A dormant account can receive funds from unrelated parties and empty within minutes. A company can present several independent shareholders while one person controls the structure through nominees.
FICA gives institutions flexibility to choose their identity-verification technology, biometric method and monitoring platform. That flexibility comes with a clear standard: the chosen method should be reasonable for the risk, operate as designed and produce records that can be retrieved when a supervisor, auditor or court asks.
KYC and identity fraud after the grey list exit
The SABRIC figures show why KYC in South Africa now operates as an ongoing risk process.
Digital banking fraud incidents rose from 52,584 in 2023 to 97,975 in 2024, with gross losses increasing 74% to R1.888 billion. Banking apps accounted for 65.3% of reported digital incidents. SABRIC identifies social engineering and human manipulation as the main route through which the fraud succeeded, while banking platforms remained technically intact.
Application fraud moved in the same direction. Reported unsecured-credit application fraud rose 57.6% to 62,346 cases. Banks declined 90% of the flagged applications, and actual losses more than doubled, from R87.9 million to R221.7 million. SABRIC identifies synthetic identities, AI-generated documents and cross-border laundering among the methods in use and expects real-time deepfake audio and video to feature more often.
The pattern matters for FICA compliance because each case activates an obligation. A genuine customer may act under a criminal’s control. A generated document may pass a superficial check. A matching face may arrive through an injected capture. An account opened for legitimate use may later become a mule account.
Each case extends the control chain beyond onboarding.
At onboarding, the institution needs reliable identity data and a defensible verification result. During the relationship, it needs to recognise when behaviour, devices or transactions diverge from the expected profile. A material change in risk may trigger repeated due diligence, stronger authentication, investigation or reporting. Section 21C of FICA calls this ongoing due diligence. The fraud data explains why it has to work in practice.
Technology can strengthen each link in the chain. The institution remains responsible for the customer decision, the escalation and the regulatory report.
FICA penalties for non-compliance: what the 2025 bank sanctions show
The recent sanctions record makes the operational test visible: customer reviews, reporting dates and alert queues.
In January 2025, the Prudential Authority imposed a R13 million penalty on Standard Bank following a 2022 inspection. The inspection identified missing ongoing due-diligence reviews for two clients in 2018 and 2019; absent records of the submission dates for 43 suspicious transaction or activity reports; late filing of 1,466 cash transaction or cash transaction aggregation reports and 17,259 suspicious transaction or activity reports; one omitted suspicious transaction report; 75,729 automated transaction-monitoring alerts still unattended after 48 hours; and 94,558 alerts closed after the 15-day reporting period.
In April 2025, Absa received a R10 million penalty from the same inspection cycle. The R7 million customer due-diligence component covered inadequate CDD on four foreign prominent public official files and two politically exposed person files involving state-owned enterprises, together with inadequate EDD on three domestic prominent influential person files and five foreign prominent public official files. The R3 million alert-handling component covered 8,559 reported automated monitoring alerts and four non-reportable alerts still unattended after 48 hours, plus two non-reportable STR/SAR alerts closed after the 15-day reporting period. The sanction also included two cautions and a reprimand.
The pattern is visible in the customer files and alert queues. Review cycles, reporting dates and escalation records all have to hold together.
Section 45C gives supervisory bodies a range of administrative sanctions, including cautions, reprimands, remediation directives, restrictions or suspension of business activities, and financial penalties of up to R10 million for a natural person and R50 million for a legal person. The remediation programme, supervisory attention and internal reconstruction of events often carry the longer operational cost.
What operational FICA compliance looks like
A legal obligation becomes real when the institution can produce the evidence behind it. The comparison below connects each requirement with the record a supervisor should be able to see.
| Requirement | What FICA expects | Evidence the institution should produce |
| Risk-based approach and RMCP | Risks identified, assessed, managed and documented under section 42. | Institutional risk assessment, approved RMCP, named control owners, change history and proof of implementation. |
| CDD and beneficial ownership | Clients and beneficial owners identified and verified according to risk before the relationship is established. | Customer data, source documents, verification results, ownership analysis, risk rating and approvals. |
| PEP and sanctions controls | Politically exposed and prominent clients identified; targeted financial sanctions obligations applied. | Screening results, match investigation, escalation, senior approval and rescreening history. |
| Monitoring and reporting | Activity scrutinised; cash threshold reports, terrorist property reports and suspicious transaction reports submitted on time. | Alert history, analyst notes, case decisions, filing dates and report references. |
| Record keeping | Client, transaction and reporting records retained for at least five years and readily retrievable. | Complete customer file, transaction trail, report history and system audit logs. |
Biometrics, liveness detection, device intelligence and AI-based monitoring can strengthen these controls. The institution combines those tools with legal analysis, governance and evidence it can retrieve.
A FICA compliance readiness test for 2026
A practical review starts with the customer journey. The policy index then helps confirm that the written rules match what happens in the business.
☐ Can we state which Schedule 1 items apply to each legal entity and activity in the group?
☐ Does the RMCP describe the products, channels, customers and risks we have today?
☐ Can we retrieve a complete customer file, including beneficial-ownership analysis and approvals, within hours?
☐ Do fraud, AML, sanctions, identity and cybersecurity teams share one case view?
☐ Are transaction-monitoring alerts reviewed within the required periods, with system records proving the timing?
☐ Can the compliance officer explain to a supervisor why two similar cases received different treatment?
☐ Does board reporting show where risk is moving as well as the volumes being processed?
☐ Where the 2026 risk and compliance return applies, was it submitted on time and does the business match the information declared?
Frequently asked questions
FICA compliance is the set of obligations under South Africa’s Financial Intelligence Centre Act (Act 38 of 2001, as amended) requiring accountable institutions to identify and verify clients, assess money laundering, terrorist financing and proliferation financing risk, monitor transactions, keep records and submit regulatory reports to the Financial Intelligence Centre.
No. South Africa left the FATF grey list on 24 October 2025 after 32 months under increased monitoring and the completion of all 22 items in its action plan. The European Union removed South Africa from its list of high-risk third-country jurisdictions with effect from 29 January 2026. South Africa’s next FATF evaluation is scheduled to conclude at the October 2027 plenary.
SABRIC members reported approximately R2.72 billion in actual losses across the financial-crime categories covered in its 2024 report. Digital banking fraud alone generated 97,975 reported incidents and R1.888 billion in gross losses, increases of 86% and 74% on 2023. Banking apps accounted for 65.3% of reported digital incidents.
Schedule 1 of FICA includes banks, life insurers, legal practitioners, estate agents, casinos and other gambling businesses, credit providers, crypto asset service providers, money or value transfer providers, trust and company service providers, certain financial services providers and dealers in high-value goods. Each accountable institution must implement an RMCP, identify and verify clients before establishing a business relationship or concluding a single transaction, and apply ongoing risk-based due diligence throughout the relationship.
FICA is the Financial Intelligence Centre Act, the law that establishes South Africa’s AML/CFT/CPF framework and places obligations on accountable institutions. The FIC is South Africa’s financial intelligence unit and supervises the sectors allocated to it. Other bodies, including the Prudential Authority, supervise FICA compliance within their own sectors.
The operational test after the grey list
Leaving increased monitoring was a real achievement. It removed an important external risk marker and improved South Africa’s standing with international counterparties. The EU decision also removed the automatic enhanced-due-diligence requirement attached to the high-risk listing, while each institution retained discretion to maintain or adjust its own risk policies.
The next phase happens inside the institution: customer files, alert queues, investigations and board reporting.
The next FATF evaluation reports in October 2027. The FIC is collecting risk and compliance returns. The Prudential Authority is publishing penalties built on alert queues and client files. The fraud figures show criminals working at the points where identity, access and transaction behaviour meet.
The institutions that handle 2026 well will be those that answer the practical questions from existing records: who was the customer, what did the institution know, which risk changed, who decided, when was the report filed and where is the evidence stored?
The policy sets the standard. The customer file, alert history and reporting record show whether the institution met it.