← All regulators

Regulator profile · FIC

Financial Intelligence Centre

Anti-money laundering, counter-terrorist financing, and counter-proliferation financing. Collecting, analysing, and disseminating financial intelligence.

At a glance

Established
2001
Parent act
Financial Intelligence Centre Act 38 of 2001 (FICA)
Penalty ceiling
R10 million or 10% of gross annual turnover (whichever is greater)
Key register
FICA Accountable Institutions Register
Website
https://www.fic.gov.za

Scope of supervision

  • Banks and mutual banks
  • Long-term and short-term insurers and their intermediaries
  • Collective investment scheme managers
  • Authorised dealers in foreign exchange
  • FSPs authorised under FAIS (certain categories)

Governing legislation

Acronym Full name and description
FICA
Financial Intelligence Centre Act 38 of 2001
Primary AML/CFT/CPF legislation. Amended significantly by Act 1 of 2017 to align with FATF standards.
FATF
Financial Action Task Force Standards
International standards-setting body for AML/CFT. SA is a FATF member subject to mutual evaluation.
Reg 21A
FIC Regulation 21A
Prescribes requirements for electronic funds transfer reporting.
Reg 24
FIC Regulation 24
Prohibits dealing with entities on UN Security Council sanctions lists.
GN 7
FIC Guidance Note 7
Guidance on electronic or digital CDD — acceptable verification methods for remote onboarding.

Risk Management and Compliance Programme — required components

Component Description Frequency
Enterprise Risk Assessment Risk identification across products, services, clients, geographies, and delivery channels. Must be documented, board-approved, and updated regularly. Annual minimum; updated on material changes
CDD Policies and Procedures Step-by-step procedures for identification, verification, beneficial ownership, and ongoing monitoring. Review annually; update on regulatory change
Reporting Obligations Internal process for identifying, escalating, and filing STRs, CTRs, and PATA reports with the FIC. Ongoing; STR within 15 days, CTR within 2 business days
Record Keeping Retention policy ensuring CDD records are kept for a minimum of 5 years after relationship termination. Ongoing; records audit annually
Training Programme Annual AML/CFT training for all relevant staff with records of completion maintained. Annual minimum
Compliance Officer Designated FICA Compliance Officer accountable for RMCP implementation, with clear terms of reference. Appointment reviewed at succession or annually
Internal Audit / Testing Independent review of FICA compliance controls with findings reported to governance. Annual
Sanctions Screening Process for automated screening of clients against Targeted Financial Sanctions (TFS) lists at onboarding and ongoing. At onboarding and daily/continuous monitoring

Key obligations on regulated entities

  1. Document, board-approve, and implement a written RMCP
  2. Conduct and document an enterprise-wide ML/TF/PF risk assessment
  3. Apply CDD at client onboarding — identify, verify, and understand every client
  4. Identify beneficial owners at 25%+ ownership threshold for legal entities
  5. Apply EDD to all PEPs and high-risk clients
  6. Screen all clients against TFS/sanctions lists at onboarding and on an ongoing basis
  7. Assign a risk rating (CRR) to every client based on documented methodology
  8. File Suspicious Transaction Reports (STRs) within 15 days of suspicion
  9. File Cash Threshold Reports (CTRs) within 2 business days for cash > R49,999
  10. Retain CDD records for a minimum of 5 years post relationship termination
  11. Conduct annual AML/CFT training for all relevant staff
  12. Appoint a FICA Compliance Officer with documented terms of reference

Enforcement powers

  • Administrative sanctions — cautions, reprimands, financial penalties
  • Penalties up to R10 million or 10% of gross annual turnover
  • Public naming of sanctioned entities
  • Criminal prosecution for serious non-compliance
  • Supervisory on-site visits

Key register: FICA Accountable Institutions portal