
FSPs sanctioned for FICA failures – fines totalling R700 000
The FSCA found both firms lacked effective risk management capabilities, including deficient RMCPs, poor customer due diligence, and failures to screen against the sanctions lists.

The FSCA found both firms lacked effective risk management capabilities, including deficient RMCPs, poor customer due diligence, and failures to screen against the sanctions lists.

As South Africa prepares for a tougher FATF evaluation, FSPs must master risk-based compliance – balancing security, cost, and strong partnerships to target real threats and protect legitimate customers.

The updated guidance gives concrete examples of compliance failures and explicitly states that poorly documented RMCPs may be treated as non-compliant.

From funeral policy breaches to crypto non-compliance and weak AML measures, the regulator’s latest report outlines its key priorities – with online harm topping the list.

The owner of MIKA Finansiële Dienste shares four key takeaways after successfully remediating the deficiencies in its RMCP.

What the Authority expects from financial services providers when it conducts Financial Intelligence Centre Act inspections.

An RMCP must set out the processes for identifying, investigating, and reporting suspicious transactions, and for screening clients against the sanctions lists.

An inspection identified inadequate implementation of the RMCP and deficient customer due diligence processes.

The Centre, through inspections and compliance monitoring, will test an RMCP against the legislative requirements.

Financial institutions that proactively embed governance, technology, and culture to meet evolving regulatory standards will not only avoid penalties but also strengthen credibility, build resilience, and drive long term value.

One of the sanctioned FSPs says it’s important to request virtual meetings with the FSCA after each feedback round to ensure all compliance expectations are met.

But institutions that file their RMCPs after the deadline are regarded as non-compliant and may be sanctioned.

They must submit a copy of their RMCP to the Financial Intelligence Centre by 12 March.

The Guidance Note reflects significant amendments relating to an accountable institution’s RMCP.

Guidance Note 7A provides further guidance to accountable institutions about their Risk Management and Compliance Programme obligations.

Standard Bank’s compliance failures include the untimely submission of suspicious activity reports and neglecting system alerts.

Risk management failings, inadequate customer due diligence, and lack of senior management oversight are key lessons for the industry.