Having the right documents in place is not the same as being compliant. Many accountable institutions operate in the grey space of “almost compliant” when it comes to the Financial Intelligence Centre Act (FICA). Policies exist, but culture, consistency and accountability fall short. Here is why that gap matters – and how to close it.
When it comes to FICA, many accountable institutions believe they are compliant because the required documents, frameworks and policies are on file. The Risk Management and Compliance Programme (RMCP) is drafted. Policies are signed. Staff attended a FICA training session last year.
Yet when regulators assess effectiveness – not intent – those same institutions may find themselves exposed.
“Almost compliant” creates a false sense of security. Risks are underestimated, accountability becomes diluted and documentation is mistaken for implementation. The finish line may be visible – but unless it is deliberately crossed, exposure remains.
FICA compliance is built on a risk-based approach. Compliance is therefore not measured by the presence of documents, but by how effectively risks are identified, mitigated, monitored and evidenced in practice.
Common areas of “almost compliance”
In practice, “almost compliant” often looks polished on paper but weak in execution. Under FICA, supervisory inspections and published enforcement actions show that gaps often arise not because documents are absent, but because implementation is inconsistent or poorly evidenced.
In recent years, the Financial Sector Conduct Authority (FSCA), which supervises financial services providers (FSPs) for FICA compliance, has imposed multi-million-rand penalties for contraventions of the Act, particularly involving RMCP weaknesses, inadequate customer due diligence (CDD) and reporting failures.
The Financial Intelligence Centre (FIC), which supervises other accountable institutions under FICA, has in its recent Annual Reports and published inspection feedback similarly highlighted weaknesses in the practical implementation of RMCPs and CDD measures. The consistent message from both regulators is clear: having documents is not enough – they must be implemented, monitored and kept current.
Common “almost compliance” risks include:
- Generic or outdated RMCPs: Documents are outdated, overly generic or drafted for form rather than practical use. They exist but are not embedded in daily operations. Reviews are infrequent, and changes in products, services or client profiles are not reflected in the risk assessment.
- Inconsistent CDD measures: Beneficial ownership verification, client risk rating and sanctions screening are performed, but inconsistently or without proper evidence. High-risk clients are identified, yet enhanced due diligence is not meaningfully applied.
- Weak monitoring and reporting practices: Suspicious or unusual activity reporting frameworks exist, but escalation thresholds are unclear, reporting lines are blurred or documentation of decisions is incomplete.
- Once-off or superficial training: Section 43 of FICA requires accountable institutions to provide ongoing training to employees so they can comply with FICA and the RMCP. In other words, training is an ongoing obligation – not a once-off formality, and it goes beyond understanding the terminology. Staff must have the practical knowledge to apply it effectively in real client scenarios.
- Fragmented governance and accountability: Responsibility is delegated to the Compliance Officer, while operational teams disengage from anti-money laundering (AML), combating the financing of terrorism (CFT) and combating the financing of proliferation (CPF) oversight. Compliance becomes an isolated function rather than a shared responsibility.
A common thread runs through these areas: institutions assume that having documents with the correct headings equals compliance. Generic documents alone, however, do not protect an institution when scrutiny begins. Regulatory feedback reinforces this pattern – frameworks exist, but implementation and evidence fall short. These are rarely deliberate breaches; more often, institutions stop just short of full implementation, creating avoidable regulatory risk.
What are the consequences of being “almost” compliant?
Regulators don’t give points for effort – only for results.
Small gaps are rarely viewed as isolated issues. They signal broader weaknesses in governance, oversight and compliance culture. An institution that appears compliant but cannot demonstrate consistent application may be regarded as higher risk than one that is transparently addressing identified shortcomings.
The consequences are cumulative and material:
- Reputational risk: Credibility and stakeholder trust can be eroded quickly – and are difficult to restore.
- Financial impact: Administrative penalties of up to R10 million for natural persons and R50 million for legal entities – with maximums of up to R100 million for serious contraventions – as well as remediation costs and operational disruption.
- Regulatory and legal consequences: Administrative sanctions may include cautions, reprimands, directives, and the restriction or suspension of business activities. In serious cases, criminal prosecution can result in imprisonment of up to 15 years.
- Regulatory intensity: Increased supervisory attention, follow-up inspections and ongoing monitoring.
“Mostly compliant” offers little protection once regulatory scrutiny begins.
What steps can businesses take to move from “almost” to fully compliant?
Full compliance is less about perfection and more about consistency, ownership and discipline. Practical steps include:
- Embed FICA compliance into operations: FICA compliance should form part of client onboarding, changes to products or services, client risk assessment and reporting processes – not be treated as a separate exercise.
- Keep the RMCP genuinely risk-based: Review it at least annually, and whenever there are material changes to products, services, delivery channels or client risk profiles. Ensure that the controls described in the RMCP are implemented in practice.
- Strengthen shared accountability: Tasks can be delegated, but accountability cannot. First-line ownership should remain clear, with senior management actively engaged in oversight.
- Document decisions appropriately: Where judgement calls are made – for example, determining client risk ratings or whether to escalate a transaction – record the rationale clearly. Supporting evidence remains critical to protect both the institution and its people.
- Invest in meaningful, ongoing training: Move beyond theory. Provide continuous training aligned to the institution’s risk profile so staff understand how to identify, assess and escalate potential issues.
- Test controls periodically: Internal reviews or independent compliance monitoring can identify gaps before regulators do.
- Seek independent support where necessary: For some institutions, FICA compliance can feel complex or overwhelming. An external compliance provider can assist with reviewing existing controls, strengthening RMCP implementation, or delivering targeted training. Independent input can provide clarity, objectivity and practical guidance.
Why full compliance matters
FICA compliance is not merely a paperwork or box-ticking exercise – it is a legal obligation and a core component of responsible business practice. For accountable institutions, compliance is either operational and demonstrable, or it isn’t – there is no safe middle ground.
Being fully compliant means more than having documents in place. It means that controls are embedded, risks are properly assessed and mitigated, decisions are documented with supporting evidence, and responsibilities are clearly understood across the business. It means that when a regulator asks how a risk is identified and managed, the answer can be demonstrated and evidenced – not assumed.
“Almost compliant” may feel sufficient in day-to-day operations, but under regulatory scrutiny it quickly unravels. Full compliance provides clarity, defensibility and resilience. It protects the accountable institution, its clients and the integrity of the financial system.
FICA requires a risk-based approach that is applied consistently, supported by clear accountability and documented evidence. Institutions that move beyond form and focus on effective and practical implementation place themselves in a far stronger position – not only to withstand inspection and or regulatory scrutiny, but to operate with confidence and credibility.
