Compliance & Cyber Intelligence for Insurance
Menu
Log in ↗
PROVANTIS / RULE LIBRARY
← BACK TO LIBRARY
← Conduct rule engine

Category 04

FICA Onboarding

Financial Intelligence Centre Act — CDD, RMCP, PEP/sanctions screening, and onboarding controls for Accountable Institutions.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Fica
  • Insurance Broker: FICA duties apply when the firm is an accountable institution for the relevant business or acts in another capacity captured by Schedule 1. Schedule 1 item 12 excludes advice or intermediary services solely in respect of a non-life insurance policy. Do not infer FICA accountable-institution status from a non-life broker label alone.
  • Uma Binder Holder: FICA duties depend on whether the UMA is an accountable institution for the relevant business or acts in another captured capacity. Non-life insurance advice or intermediary services are excluded from Schedule 1 item 12; test the firm's other activities before publishing a direct-duty claim.
  • Insurer: FICA duties depend on the insurer's business and the applicable Schedule 1 item. Distinguish life and non-life business and any other accountable-institution capacity before publishing a direct-duty claim.

Key legislation

  • FICA 38 of 2001 (as amended)
  • FATF Recommendations
  • FIC Guidance Note 7

Readiness guidance

Request the RMCP and verify board approval date. Test a sample of client files for completeness of CDD documentation. Confirm sanctions and PEP screening logs are available and current. Review the STR register and CTR submission log against actual reportable transactions identified.

Rules in this category

15 rules

FIC-01

RMCP — documented, board-approved, and current (reviewed within 12 months)

Critical
Trigger
RMCP absent, not board-approved, or not reviewed within 12 months
Section
FICA s.42
Evidence
['Signed RMCP', 'Board approval resolution', 'Last review date']
Remediation
Develop RMCP covering all s.42 components. Present for board approval. Set annual review date.

FIC-02

Enterprise Risk Assessment — conducted and documented for all relevant risk factors

Critical
Trigger
Risk Assessment absent or not updated following material changes
Section
FICA s.42A
Evidence
['Risk Assessment document', 'Board sign-off', 'Last assessment date']
Remediation
Conduct full ML/TF/PF risk assessment across products, clients, channels, and geographies.

FIC-03

FICA Compliance Officer — formally appointed with clear mandate

Critical
Trigger
No Compliance Officer appointed or appointment not documented
Section
FICA s.42A(2) read with s.43
Evidence
['Appointment letter', 'Terms of reference', 'Reporting structure documentation']
Remediation
Appoint FICA Compliance Officer. Document terms of reference and reporting line.

FIC-04

Client Identification — all clients identified using FICA-prescribed documentation

Critical
Trigger
Clients onboarded without prescribed identification documentation on file
Section
FICA s.21
Evidence
['Client file sample (ID documents)', 'Onboarding checklist', 'CRM record audit']
Remediation
Audit existing client files. Remediate gaps. Enforce documentation checklist at onboarding.

FIC-05

Client Verification — identity verified against reliable, independent sources

Critical
Trigger
Verification not performed or performed using non-compliant methods
Section
FICA s.21A / GN 7
Evidence
['Verification system records', 'Verification policy', 'Failed verification log']
Remediation
Integrate verification API (credit bureau or government database). Document verification outcomes.

FIC-06

Beneficial-owner identification — ownership-and-control cascade completed for every legal entity

Critical
Trigger
CDD treats PCC 59's 5% screening guidance as the binding test, or does not continue through the s.21B cascade: controlling ownership, control by other means, and finally the person exercising executive control when no earlier natural person can be identified
Section
FICA s.21B / FIC PCC 59 (5% screening guidance)
Evidence
['Beneficial-owner declaration forms', 'Ownership and control structure charts', 'Cascade decision record', 'Verification records per identified natural person']
Remediation
Apply and document the binding s.21B cascade for every legal entity. Use PCC 59's 5% screen as a guidance-based aid to identify candidates, then establish controlling ownership, control through other means, and finally the natural person exercising executive control if still unresolved. Verify every person identified.

FIC-07

PEP / prominent-person screening — foreign prominent public officials (FPPOs, s.21F), domestic prominent influential persons (DPIPs, s.21G), and their family members and known close associates (s.21H) screened at onboarding and periodically thereafter

High
Trigger
No PEP screening process, or screening does not cover all three statutory categories (FPPOs / DPIPs / family members and close associates), or PEP status not documented
Section
FICA s.21F–s.21H
Evidence
['PEP/DPIP/FPPO screening system records', 'PEP register covering all three statutory categories', 'Periodic screening log', 'Escalation and disposition records']
Remediation
Integrate a screening database covering FPPOs (s.21F), DPIPs (s.21G), and their family members and known close associates (s.21H). Screen all three categories at onboarding and on periodic refresh cycle. Document screening outcomes and escalation decisions.

FIC-08

Sanctions screening — automated screening against TFS lists at onboarding and ongoing

Critical
Trigger
No sanctions screening solution or screening not performed at onboarding
Section
FICA s.26A / FICA Reg 24
Evidence
['Screening system records', 'TFS list update frequency', 'Hit disposition log']
Remediation
Implement automated TFS screening solution. Screen all clients at onboarding and on ongoing basis.

FIC-09

Client Risk Rating (CRR) — risk score assigned and documented for every client

High
Trigger
Clients without a CRR or CRR methodology undocumented
Section
FICA s.21
Evidence
['CRR methodology document', 'Client risk rating records', 'High-risk client register']
Remediation
Document CRR methodology. Assign and record risk rating for all clients. Implement periodic refresh.

FIC-10

Enhanced Due Diligence — applied to all high-risk clients and PEPs

Critical
Trigger
High-risk client or PEP onboarded without EDD measures applied
Section
FICA s.21F–s.21H
Evidence
['EDD procedure', 'Completed EDD files per high-risk client', 'Senior management approval records']
Remediation
Implement EDD procedure. Review all PEP and high-risk client files for EDD completeness.

FIC-11

STR reporting — suspicious transactions reported to FIC within prescribed timeframe

Critical
Trigger
Known suspicious transactions not reported or reported late
Section
FICA s.29
Evidence
['STR register', 'FIC submission receipts', 'Internal escalation records']
Remediation
Review transaction monitoring alerts. Report any outstanding suspicious transactions immediately.

FIC-12

CTR reporting — cash transactions above R49,999 reported within 2 business days

High
Trigger
Cash threshold transactions not reported or reporting delayed
Section
FICA s.28
Evidence
['CTR report log', 'FIC submission receipts', 'Cash transaction records']
Remediation
Implement automated CTR trigger in cash processing system. Review and file outstanding CTRs.

FIC-13

Record retention — CDD records retained for minimum 5 years post relationship termination

High
Trigger
CDD records destroyed before 5-year retention period or no retention policy
Section
FICA s.23
Evidence
['Retention policy', 'Records management system', 'Disposal authorisation records']
Remediation
Implement retention policy with 5-year minimum. Audit existing record disposal practices.

FIC-14

AML/CFT Training — all relevant staff trained annually with records maintained

Medium
Trigger
No training programme or staff without current training on record
Section
FICA s.43
Evidence
['Training material', 'Completion records', 'Assessment results']
Remediation
Implement annual AML/CFT training programme. Track completion by staff member.

FIC-15

Ongoing monitoring — transaction monitoring applied to all client accounts

High
Trigger
No transaction monitoring system or monitoring alerts not reviewed
Section
FICA s.21C
Evidence
['TM system configuration', 'Alert disposition log', 'Escalation records']
Remediation
Implement transaction monitoring rules. Establish alert review and disposition workflow.