The Financial Intelligence Centre (FIC) has finalised Guidance Note 7B, which updates its guidance on implementing the Financial Intelligence Centre Act (FICA).
Although the final guidance differs little from the draft published for consultation in June, the accompanying feedback note provides insight into how the FIC weighed industry concerns about proliferation financing (PF), new technologies, financial inclusion, and simplified due diligence (SDD).
The guidance inserts PF alongside existing references to money laundering (ML) and terrorist financing (TF), requires accountable institutions to assess ML, TF, and PF risks when developing new products, services, delivery channels, business practices, and technologies, and clarifies when SDD must give way to enhanced due diligence (EDD).
The FIC issued GN 7B on 3 August after publishing paragraphs 7A, 37A, 40A, and 58A for consultation on 12 June.
Read: FIC consults on targeted additions to Guidance Note 7A framework
Comments were received from banks, financial services providers, crypto asset service providers, legal practitioners, property practitioners, consultants, and others. The Centre says it considered all submissions and incorporated changes into the final guidance where appropriate.
For accountable institutions, the publication of GN 7B is likely to require a review of existing Risk Management and Compliance Programmes (RMCPs) to ensure they reflect the updated guidance on PF, technology risk assessments, and customer due diligence.
No change to proliferation financing
One of the principal requests from commentators was for the guidance to expand its explanation of PF by expressly linking the definition to sections 26A, 26B, and 49A of FICA and South Africa’s international obligations relating to targeted financial sanctions.
The FIC declined to do so.
In effect, the Centre chose to keep the guidance closely aligned with the statutory definition of PF rather than expanding it to reflect the broader sanctions framework suggested by commentators.
It said the existing wording in paragraph 7A is already aligned with the statutory definition of PF contained in FICA and that no further amendments were necessary.
The final guidance therefore retains the new paragraph introducing PF into the broader risk-based framework without the additional references sought during the consultation.
Technology risk assessments remain, with clearer wording
Draft paragraph 37A attracted comments from institutions that welcomed the requirement to assess the ML, TF, and PF risks associated with new technologies, but argued that the obligation should be applied proportionately, particularly for smaller businesses with limited products and operations.
The FIC says it responded by making grammatical and sentence-construction changes to improve clarity, rather than altering the substance of the requirement.
The final guidance requires accountable institutions to identify and assess ML, TF, and PF risks arising from new products, services, business practices, and delivery channels, as well as from new or developing technologies used for both new and existing offerings. These assessments must be completed before implementation or launch and updated where material changes occur in line with the institution’s risk-based approach and RMCP.
FIC softens wording on financial inclusion
The most substantive drafting change followed comments that the proposed wording on lower-risk clients could undermine the practical use of SDD.
Commentators argued that requiring a “comprehensive” risk assessment for historically lower-risk categories, such as underserved or low-income persons, effectively removed the benefit of SDD.
The FIC accepted that concern in part. It removed the reference to a “comprehensive” assessment and clarified that SDD remains appropriate where it is justified by an accountable institution’s risk-based approach and RMCP.
The final guidance nevertheless emphasises that underserved or low-income persons should not automatically be regarded as presenting lower ML, TF, and PF risks. Institutions must still conduct a risk assessment before concluding that a business relationship or transaction qualifies for SDD.
Practical clarification on EDD
Another area of concern was the interaction between suspicious transaction reporting and EDD.
Respondents pointed out that institutions often identify potentially suspicious activity only after onboarding has been completed. They also cautioned that the draft wording could be interpreted as requiring EDD and a section 29 report every time an internal alert is generated.
The FIC clarified that this is not its view.
The Centre explains that an accountable institution should first investigate potentially suspicious activity. If it concludes that the activity is reportable under section 29 of FICA, it must submit the report. Only thereafter – and without tipping off the client – should it conduct EDD on the client profile.
The FIC also emphasises that not every internal alert will result in a report; institutions remain responsible for determining whether activity is in fact suspicious or unusual.
This clarification is reflected in the final guidance, which states that where an institution files a section 29 report because of suspected ML, TF, or PF, it must conduct EDD on the relevant business relationship or single transaction.
Guidance Note 7B replaces Guidance Note 7, Guidance Note 7A, and Revised Guidance Note 7A with effect from its publication on 3 August 2026.
The FIC notes that its guidance is authoritative: accountable institutions must take it into account or be able to demonstrate that they achieve an equivalent level of compliance.




