Three FSPs sanctioned over FICA compliance failures

Posted on Leave a comment

The Financial Sector Conduct Authority has fined three financial services providers for different failures under the Financial Intelligence Centre Act, ranging from deficient compliance programmes and customer due diligence (CDD) to sanctions screening, registration, and failures to provide information to the regulator.

Mmela Financial Services was sanctioned R450 000, although R225 000 of its penalty was conditionally suspended for three years; Mbuli Finance received a R220 000 penalty; and Sithembile Holdings was fined R100 000, the Authority said in a statement on 9 September 2026.

All three firms are licensed under the Financial Advisory and Intermediary Services Act and are accountable institutions under FICA.

Mmela sanctioned for CDD and RMCP failures

The regulator found that Mmela’s Risk Management and Compliance Programme (RMCP) did not comply with sections 42(1) and 42(2) of FICA.

Accountable institutions must develop, document, maintain, and implement RMCPs dealing with anti-money laundering, counter-terrorist financing, and counter-proliferation financing. These programmes must enable an institution to identify, assess, monitor, mitigate, and manage the risk that its new and existing products or services may involve or facilitate these activities.

Although Mmela had an RMCP when the FSCA conducted its inspection, the programme failed to provide for one or more of the processes and procedures required under FICA.

The FSCA also found that Mmela failed to conduct the required CDD on its clients. Customer due diligence includes identifying and verifying customers, establishing the identity of people acting on their behalf, obtaining information about the nature of the business relationship, and obtaining beneficial ownership information.

Mmela also failed to keep records of CDD information in the format required by FICA.

In addition, the firm failed to scrutinise information about its clients against the United Nations Security Council’s Targeted Financial Sanctions (TFS) lists.

Accountable institutions must screen current and prospective clients against these lists. If a client or prospective client is listed, the institution must report the person or entity to the FIC and freeze the relevant accounts, assets, and services.

The FSCA’s statement identifies failures in Mmela’s compliance controls. It does not state that the firm had a client who appeared on a TFS list or that Mmela was involved in money laundering, terrorist financing, or proliferation financing.

Mbuli fined for five compliance failures

The FSCA fined Mbuli for contraventions involving its RMCP, client and employee screening, registration with the FIC, and compliance with the FSCA’s 2024 Directive to Provide Information (DPI).

Like Mmela, Mbuli had an RMCP at the time of the inspection, but the programme failed to provide for one or more of the processes and procedures contemplated in sections 42(1) and 42(2) of FICA.

Mbuli also failed to scrutinise information about its clients against the TFS lists. As with Mmela, the FSCA identified a failure to carry out the required screening. It does not say that Mbuli had a client who appeared on a sanctions list or was involved in the criminal activities that FICA is intended to combat.

The regulator identified a separate failure involving one of Mbuli’s key employees.

Directive 8 of 2023, read with Public Compliance Communication 55, requires accountable institutions to screen prospective and current employees periodically for competence and integrity, using a risk-based approach. Institutions must also scrutinise information about prospective and current employees against the TFS lists.

At the time of the inspection, Mbuli had not screened an employee who served as both its key individual under the FAIS Act and its money laundering control officer under FICA against the sanctions lists.

Mbuli had also failed to register with the FIC. Section 43B of FICA requires accountable institutions to register with the Centre within the prescribed period and in the prescribed manner.

The fifth finding concerned Mbuli’s failure to provide the information required under the FSCA’s DPI within the prescribed period.

Section 43A(3) of FICA empowers the FIC or a designated supervisory body to issue a written directive requiring accountable institutions to provide specified information within a stipulated period.

The FSCA issued the DPI on 27 May 2024. It was a mandatory online information-gathering exercise requiring accountable institutions supervised by the authority to submit information relevant to their compliance with FICA. FSPs were required to complete and submit the DPI through the FSCA’s FAIS e-portal.

The original submission period ran from 27 May to 31 July 2024. The FSCA subsequently reopened the DPI from 4 to 29 November 2024 for institutions that had failed to submit it or had completed it only partially. Communication 40 of 2024 described the November exercise as a “final request”.

The statement does not specify which submission deadline Mbuli missed or whether the firm failed to submit the DPI at all or completed it only partially. It states that Mbuli did not provide the information required by the directive within the prescribed period.

Sithembile failed to provide information before planned inspection

The FSCA fined Sithembile for failing to comply with a separate directive requiring it to provide information to the regulator.

On 27 February 2026, the FSCA issued the directive under section 43A(3) of FICA, requiring Sithembile to submit specified information in preparation for a planned onsite inspection. The firm did not provide the requested information.

Firms directed to remedy deficiencies

In determining the sanctions, the FSCA said it considered factors applicable to each institution, including the nature, size, and complexity of its business.

The regulator also issued directives requiring all three firms to remedy the identified deficiencies.

Mmela has paid the applicable financial penalty. Mbuli has entered a payment arrangement with the FSCA, while Sithembile has not yet paid its penalty.

The FSCA said the sanctions served as a reminder that it would not tolerate non-compliance with FICA. It urged accountable institutions to review and strengthen their anti-money laundering and terrorist-financing controls continually and to conduct thorough risk assessments regularly.

 

Leave a Reply

Your email address will not be published. Required fields are marked *