FICA

South Africa's AML statute: the RMCP, the CDD chain, and reporting into the FIC.

Market regime · Financial Intelligence Centre Act 38 of 2001 (South Africa)

Issued by

Republic of South Africa

Region

South Africa

Effective

2001; risk-based amendments 2017, scope expanded 2022

Oversight

Financial Intelligence Centre, with sector supervisors

Applies when

Accountable institutions under South Africa's AML regime

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

FICA is the backbone of South African financial-crime compliance: accountable institutions run a Risk Management and Compliance Programme, perform customer due diligence including beneficial ownership and prominent-person checks, keep records, and report cash, suspicious and terrorist-property events to the Financial Intelligence Centre.

The 2017 amendments made it explicitly risk-based, and the 2022 expansion swept in new sectors as South Africa worked its FATF action plan. Its shape mirrors the CBN's AML regime closely enough that one financial-crime control set carries both, which is exactly how the catalog maps it.

Where programmes are tested.

01

The RMCP

A board-approved Risk Management and Compliance Programme that actually governs how the institution identifies and manages its risk.

02

The section 21 CDD chain

Customer identification and verification, beneficial ownership, and enhanced scrutiny of prominent influential persons.

03

Reporting duties

Cash threshold, suspicious and terrorist-property reports filed with the FIC on statutory clocks.

04

Records, training, governance

Five-year record-keeping, workforce training, and named accountability the supervisor can test.

Curated once, evidenced continuously.

  • FICA rides the same Financial Crime controls as the CBN AML set, the live-evidence thesis applied continent-wide: screening, monitoring and reporting controls evidenced once, cited under either statute.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

FICA, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who is an accountable institution under FICA?

The entities listed in Schedule 1, banks, insurers, dealers, advisers, and since the 2022 amendments a wider set including crypto asset service providers and credit providers. If the schedule names your activity, the RMCP, CDD and reporting duties apply in full.

What is an RMCP?

The Risk Management and Compliance Programme: FICA's central artefact, a board-approved document setting out how the institution assesses risk, performs due diligence, monitors, reports and trains. Inspectors start with the RMCP and test whether practice matches it.

What must be reported to the FIC?

Cash transactions above the prescribed threshold, suspicious and unusual transactions, and property associated with terrorism, each on its own statutory clock through the FIC's goAML platform. The trail from alert to filed report is what an inspection samples.

How does FICA relate to South Africa's FATF grey-listing?

South Africa's 2023 grey-listing put FICA supervision under international scrutiny, and the remediation programme has meant more inspections and firmer enforcement. Demonstrable compliance, evidence rather than policy documents, is the practical difference supervisors now look for.

Where it connects.

The full catalog

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.