Public Compliance Communication 23A (PCC 23A), issued by the Financial Intelligence Centre (FIC) on 30 March 2026, provides clear guidance on who falls within the category of a “credit provider” and what that means in practice.
PCC 23A clarifies the scope of credit providers as designated under Item 11 of Schedule 1 of the Financial Intelligence Centre Act (FIC Act). Any entity that falls under the definition of a credit provider, will be classified as an accountable institution and is subject to anti-money laundering (AML), counter-terrorist financing (CFT), and counter-proliferation financing (CPF) obligations.
Understanding who qualifies as a credit provider
The definition of a credit provider is broader than it might first appear. It includes not only those operating under the National Credit Act (NCA), but also entities providing credit under agreements that fall outside the NCA’s scope.
This results in a broad range of entities being included, such as traditional banks, microfinance institutions, credit card issuers, mortgage lenders, fintech lenders, and even those involved in ad hoc or once-off commercial lending arrangements. The document emphasises that the determination is not merely about labels or formal classifications, but about the substance and economic reality of the activity.
In practical terms, an entity is considered to be “carrying on the business” of a credit provider if it regularly extends credit, does so for profit, maintains systems to manage credit, or markets such services to others. No single factor is decisive; instead, the FIC adopts a holistic view, examining all relevant circumstances.
Two pathways into the definition
PCC 23A outlines two primary categories under which an entity may be classified as a credit provider.
The first category includes those explicitly defined under the NCA, such as lenders in instalment agreements, mortgage providers, and parties extending credit facilities. These entities are typically required to register with the National Credit Regulator (NCR).
The second category is more expansive and often more complex. It captures entities providing credit under agreements excluded from the NCA, including arrangements involving juristic persons that fall outside the Act’s scope. Even if interest is not charged, the act of deferring payment over time can still constitute credit provision.
This second category ensures that businesses cannot sidestep regulatory oversight simply by structuring agreements outside the NCA framework.
What falls outside the scope?
Not every instance of delayed payment triggers regulatory obligations. PCC 23A draws a clear line around incidental credit, such as late payment fees charged by a service provider. For example, a medical practitioner charging interest on overdue accounts would not typically be considered a credit provider, provided this is not part of a broader credit business.
However, the guidance warns against artificial structuring. Repeated or systematic use of incidental credit arrangements may signal that an entity is, in substance, operating as a credit provider.
The regulatory consequences
Once classified as a credit provider, an entity must comply with the FIC Act’s full suite of obligations. This includes conducting customer due diligence, monitoring transactions, and implementing a Risk Management and Compliance Programme (RMCP) tailored to its specific risk profile.
Importantly, credit agreements are treated as ongoing business relationships rather than isolated transactions. This reflects the enduring nature of lending arrangements, where interactions between lender and borrower unfold over time.
Risk indicators – reading the warning signs
Beyond definitions, PCC 23A also outlines potential financial crime risks associated with credit activities. It highlights several red flags that may indicate money laundering, terrorist financing, or proliferation financing.
For money laundering, warning signs include unusual repayment patterns, such as loans being settled far earlier than expected without a clear source of funds, or multiple cash repayments lacking plausible explanations. Similarly, clients who are reluctant to provide information or whose business activities defy economic logic may warrant closer scrutiny.
Terrorist financing risks often involve smaller, less conspicuous transactions. Examples include frequent early repayments of mortgage facilities, sudden large deposits into accounts, or credit cards being used across multiple foreign jurisdictions without a clear business rationale.
Proliferation financing risks, meanwhile, may surface in transactions involving dual-use goods, sanctioned jurisdictions, or complex trade arrangements with no obvious commercial purpose.
A broader regulatory philosophy
What emerges from PCC 23A is a regulatory philosophy grounded in practicality. The FIC is less concerned with how entities describe themselves and more focused on what they do.
By casting a wide net and emphasizing risk-based compliance, the guidance ensures that the financial system remains resilient against misuse. Credit, after all, is not just a tool for growth; in the wrong hands, it can become a conduit for illicit activity.
PCC 23A makes it clear that the definition of a credit provider is broad and rooted in the actual substance of lending activities. Entities that extend credit, whether within or outside the National Credit Act, may fall within the FIC Act’s scope and must meet strict compliance obligations. By focusing on real economic activity and highlighting key risk indicators, the guidance reinforces a proactive, risk-based approach to preventing financial crime in the credit sector.
