The Financial Intelligence Centre Amendment Act (FICA) is South Africa’s Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) legislation. FICA governs many aspects of South Africa’s financial and commercial landscape, including the identification of accountable institutions and their obligations. The Financial Intelligence Centre (FIC) is the national regulatory body responsible for applying and enforcing FICA.
The FICA Act was promulgated in 2001 and since amended in 2017 and December 2022 to ensure that South Africa’s AML/CFT framework remains aligned with international standards set by the Financial Action Task Force (FATF).
From a consumer perspective, the legislation acts as a shield by preventing financial scams and identity theft to foster greater trust in the financial sector. In terms of national security, the Act plays a critical role in reducing the risk of terrorist attacks and impeding organised crime. Additionally, by aligning with international standards, the FIC Act promotes global cooperation, strengthening the collective effort against illegal financing. In essence, this legislation is indispensable in ensuring a resilient, secure, and inclusive financial environment for South Africa.
The FIC Act directed the establishment of the Financial Intelligence Centre (FIC). The Centre was subsequently established in 2003 as the national centre for the gathering and analysis of financial data. The Centre’s primary role is to contribute to safeguarding the integrity of South Africa’s financial system and its institutions and to make them intolerant of money laundering, terrorist financing and proliferation financing abuse, which directly underpins the integrity and stability of the financial sector. The Centre is South Africa’s financial intelligence unit.
The key obligations in terms of the FICA Act are:
- Register with the FIC.
- Appoint an Anti-Money-Laundering (AML) / Combating the Financing of Terrorism (CFT) Compliance Officer
- Develop an RMCP (Risk Management and Compliance Programme)
- Perform Customer Due Diligence
- Submit reports to the FIC.
- Record keeping
- Ongoing training
There are three types of risk assessments:
A business-level risk assessment: This assessment must be conducted at the outset, referred to as the entity-wide anti-money laundering, counter-terrorist financing and counter-proliferation financing risk assessment.
A product and services risk assessment: The institution must document how it would determine the ML, TF and PF risk weightings of the products and services offered. This should be updated when new products or services are introduced and offered to clients.
A client-level risk assessment: The institution must indicate the ML, TF and PF risks different business relationships or single transactions pose. The accountable institution must demonstrate that it has conducted client-level risk assessments before establishing a business relationship or a single transaction. A client-level risk assessment is used to determine the level of customer due diligence required, whether it is simplified due diligence, normal due diligence, or enhanced due diligence, and the associated compliance controls.
Registration with the FIC enables accountable institutions to submit regulatory reports to the FIC. Accountable institutions are required to register with the FIC within 90 days from the date the business commenced with their operations.
Registrations must be completed and submitted to the FIC electronically using the online registration and reporting system called “goAML”. Registration with the FIC is free. The failure to register with the FIC or the failure to update registration information when it has changed are offences and may result in a fine not exceeding R10 million.
Sections of the FIC Act impose obligations on accountable institutions to file regulatory reports to the FIC. The FIC uses the transactional and other data received from businesses and accountable institutions to conduct analysis to create financial intelligence reports. Where necessary and upon request, this information is shared with local and international partners in the law enforcement agencies, investigative agencies and other supervisory bodies.
The FIC obtains financial intelligence and other data in the form of reports. The three main reporting streams are:
Cash threshold reports (CTRs): On transactions, i.e., cash received or issued exceeding R49 999.99. Refer to Guidance Note 5C.
Terrorist property reports (TPRs): Where a transaction matches with one or more parties on the listings in respect of resolution adopted under Chapter VII of the Charter of the United Nations. These lists are referred to as the targeted financial sanctions list (TFS list). Refer to Guidance Note 6A.
Suspicious and unusual transaction reports (STRs): On transactions that are unusual or arouse suspicion in terms of money laundering or terrorist financing activities. Refer to Guidance Note 4B.
International funds transfer reports (IFTRs): Accountable institutions that may legally conduct cross-border transactions must report transactions above the threshold of R19 999.99. Refer to draft Guidance Note 104A.
The FIC issued Directive 11 on 31 March 2026, mandating specified accountable institutions to submit their 2026 risk and compliance returns (RCRs) to the Financial Intelligence Centre (FIC) on 30 June 2026 and on 31 July 2026. The first group of specified institutions, crypto asset service providers, company service providers, non-bank credit providers, trust service providers and casinos, were required to submit their 2026 RCRs to the FIC by close of business on 30 June 2026.
Extensive information detailing compliance matters may be found on the FIC website at https://www.fic.gov.za/Compliance/
Many specified institutions in the first group failed to submit the 2026 RCRs by the 30 June 2026 closing date. As a consequence, these specified institutions are in a state of non-compliance and should receive a financial administrative sanction from
the FIC. As of 30 June 2026, only 36.1 per cent of specified institutions submitted their 2026 RCRs.
What is an accountable institution? An accountable institution is defined as a person or an organisation referred to and listed in Schedule 1 of the FIC Act that carries on the business of any entity. Accountable institutions must fulfil certain obligations in terms of the FIC Act.
The accountable institutions identified in Schedule 1 of the FIC Act include:
Item 1: Legal practitioners
Item 2: Trust and company service providers
Item 3: Estate agents
Item 9: Gambling businesses
Item 11: Credit providers
Item 14 The South African Postbank
Item 20: Dealers in high-value goods where any transaction is equal to or more than R100 000 per item, whether the payment in any form is made in a single or in multiple operations that appear to be linked.
Item 21: The South African Mint Company
Item 22: Crypto asset service providers
Banks, mutual banks, co-operative banks
Authorised users of an exchange
Collective investment scheme managers
Life insurance businesses
Dealers in foreign exchange
Financial services providers
Issuers of travellers’ cheques and money orders
Clearing system participants
The Financial Intelligence Centre (FIC) issued Directive 10, which took effect on Friday, 31 July 2026. Directive 10 sets out the geographic location information that specified accountable institutions must provide when registering with the FIC or when updating their existing registration details.
This applies across the entire corporate structure and covers:
Head offices: Full particulars of the primary head office.
Local branches: Details for each branch operating in the Republic of South Africa.
Foreign branches: Details for each branch operating outside South Africa.
Local subsidiaries: Head office details for each subsidiary located in South Africa.
Foreign subsidiaries: Head office details for each subsidiary located outside South Africa.
Sub-branch operations: If a subsidiary has its own branches outside South Africa, details for each of these foreign branches must also be provided.
Note: Directive 10 applies to items 1, 2, 3, 9, 11, 14, 20, 21 and 22 of Schedule 1 to the FIC Act (refer to the above list). For item 11, banks, mutual banks and co-operative bank credit providers are excluded.
If your institution operates from more than one location, you must ensure the FIC has accurate information about each head office, branch or subsidiary from which your institution physically offers products and service to its clients. This includes locations in and outside South Africa.
This information will help the FIC understand your business structure and apply risk-based supervision more effectively.
What information must be provided?
- Name of the head office, branch, subsidiary or subsidiary branch
- Licence number, where applicable
- Registration number, where applicable
- Business address of each relevant location
- Name and contact details of the person responsible for the compliance function
Businesses are expected to keep your FIC registration information complete, correct and up to date. Existing registered institutions must update their details within 90 days after Directive 10 takes effect. Any later changes must also be updated within 90
days.
Arising from gazette 55337 dated 04 September 2026, a summary of actions for the submission of risk management and compliance programmes was published.
DIRECTIVE 12 IN TERMS OF SECTION 43A(1) OF THE FINANCIAL INTELLIGENCE CENTRE ACT ON THE SUBMISSION OF RISK MANAGEMENT AND COMPLIANCE PROGRAMMES
- This Directive is issued in terms of section 43A(1) of the Financial Intelligence Centre Act, 2001 (Act 38 of 2001) (FIC Act).
- The purpose of this Directive is to specify the manner and time frame within which specified accountable institutions are required to submit a copy of the documentation describing their risk management and compliance programme (RMCP) to the Financial Intelligence Centre (Centre) in accordance with section 42(4) of the FIC Act.
- This Directive enables the Centre to monitor accountable institutions’ levels of compliance with the FIC Act, as envisioned in terms of section 4(c) of the FIC Act.
- This Directive applies to accountable institutions listed in items 1, 2, 3, 9, 11 (excluding banks, mutual banks, and co-operative bank credit providers), 14, 20, 21 and 22 of Schedule 1 of the Act.
- Every accountable institution subject to this Directive must make available a copy of the documentation describing their RMCP to the Centre on an annual basis, according to the time period as set out in Annexure A.
- Specified accountable institutions as listed in paragraph 4 above are subject to this Directive and must submit their RMCP using the Centre’s registration and reporting platform, in accordance with Annexure A, from the commencement date on Monday, 7 September 2026.
- The accountable institutions subject to this Directive must make a copy of the documentation describing their RMCP available to the Centre via the Centre’s registration and reporting platform within 90 days of commencing business.
- Where an accountable institution subject to this Directive updates and approves its RMCP in terms of section 42(2B) of the FIC Act, after the period set out in Annexure A, the accountable institution must submit the updated and approved RMCP via the Centre’s registration and reporting platform within ten (10) days of such approval.
- Accountable institutions subject to this Directive that fail to comply with any provision of this Directive are non-compliant and subject to an administrative sanction in accordance with section 42(4), read together with sections 61(c) and section 45C of the FIC Act.
List of accountable institutions and period of RMCP submission
Item 1 of Schedule 1 to the FIC Act 9 October 2026, and by 9 October annually thereafter
Item 2 of Schedule 1 to the FIC Act 9 October 2026, and by 9 October annually thereafter
Item 3 of Schedule 1 to the FIC Act 31 October 2026, and by 31 October annually thereafter
Item 9 of Schedule 1 to the FIC Act 9 October 2026, and by 9 October annually thereafter
Item 11 of Schedule 1 to the FIC Act (excluding banks, mutual banks, and co-operative bank credit providers) 9 October 2026, and by 9 October annually thereafter
Item 14 of Schedule 1 to the FIC Act 31 October 2026, and by 31 October annually thereafter
Item 20 of Schedule 1 to the FIC Act 31 October 2026, and by 31 October annually thereafter
Item 21 of Schedule 1 to the FIC Act 31 October 2026, and by 31 October annually thereafter
Item 22 of Schedule 1 to the FIC Act 31 October 2026, and by 31 October annually thereafter
In terms of section 61A of the FIC Act a failure to register is an offence and subject to a fine not exceeding R10 million or imprisonment for a period of up to five years. Alternatively, the FIC may also, in terms of section 45C (1) of the FIC Act, impose an administrative sanction for a failure to comply with any provision of the FIC Act, including a failure to register. Failure to submit an STR to the FIC could lead to imprisonment for a period not exceeding 15 years or to a fine not exceeding R100 million.
Sanctions issued by the FIC – 391 in total till 28 August 2026
Sanctions issued by supervisory bodies – 29 in total till 24 June 2026
Each and every sanction includes a financial penalty of varying value from tens of thousands to millions of Rands ranging from small businesses to major institutions such as national banks.
One such example is that of Standard Bank in January 2025. Prudential Authority imposes administrative sanctions on The Standard Bank of South Africa Limited. The Prudential Authority (PA) is mandated to supervise and enforce compliance by accountable institutions with the provisions of the Financial Intelligence Centre Act 38 of 2001 (FIC Act) or any order, determination or directive made in terms thereof. The PA has imposed administrative sanctions on The Standard Bank of South Africa Limited (SBSA) as a result of its non-compliance with certain provisions of the FIC Act, following an inspection conducted on SBSA in terms of section 45B of the FIC Act in 2022.
The administrative sanctions imposed on SBSA are due to its failure to comply with certain provisions of the FIC Act and consist of six cautions not to repeat the conduct which led to the non-compliance and a financial penalty totalling R13 million.
Details of these sanctions are available on the FIC website via these two links. https://www.fic.gov.za/compliance/supervision-and-enforcement/sanctions-issued-by-supervisory-bodies/ and https://www.fic.gov.za/compliance/supervision-and-enforcement/sanctions-issued-by-the-fic/
