A customer buys a car through a company. Someone else pays the deposit. The person who collects it has a valid South African ID.
Three checks come back clear. The relationship between those three people still needs explaining, and since December 2022 the law expects the dealership to explain it.
That is FICA compliance in practice: meeting the obligations the Financial Intelligence Centre Act places on "accountable institutions" to know who they deal with, assess the risk, keep the evidence and report what looks wrong. The Act now reaches motor dealers, credit providers, payment businesses and crypto platforms, and asks the same of them as it asks of a bank.
This guide covers what the Act requires, who counts as an accountable institution, how it lands for motor dealers, telcos, fintechs and life insurers, the beneficial ownership duty they all share, and what documents FICA actually requires.
What FICA actually requires
The Act asks accountable institutions to do five things.
Register. Every accountable institution must register with the FIC through goAML within 90 days of starting business. Registration is free.
Write and run a Risk Management and Compliance Programme. The RMCP explains how your business identifies, assesses and manages money laundering, terrorist financing and proliferation financing risk, approved by the board or senior management. A supervisor's first question in an inspection is not "did you verify this customer?" It is "show me the programme that told you how."
Verify who you are dealing with. Customer due diligence means establishing and verifying the client's identity and, where the client is a company, trust or partnership, identifying the natural persons who ultimately own or control it. It does not stop at onboarding: the Act requires ongoing due diligence, which means keeping the information current and monitoring transactions against what you know of the client. This is where KYC and e-KYC sit inside FICA, and where most of the customer friction occurs.
Keep the records. Identity and transaction records must be kept for at least five years, and the clock starts in three different places: when the relationship ends, when the transaction concludes, or when a suspicious transaction report is filed.
Report. Cash above R49,999.99 goes to the FIC within three business days. Suspicious or unusual transactions go within 15 business days, with no minimum value (Guidance Note 5C covers the cash rules). Matches against targeted financial sanctions lists must be reported and the property frozen. AML screening is how you find the matches before the regulator does.
Behind those five requirements sit the enabling duties: appoint a compliance officer, train staff, and submit a risk and compliance return when the FIC directs it. The 2026 return, under Directive 11 of 2026, applied to items 1, 2, 3, 9, 11, 14, 20, 21 and 22 of Schedule 1, with deadlines of 30 June and 31 July 2026 depending on sector. And from 7 September 2026, under Directive 12, the same categories must submit the RMCP itself to the FIC every year, with first deadlines of 9 and 31 October 2026.
Who is an accountable institution in 2026
Schedule 1 of the Act lists the accountable institutions. Until 2022 it was mostly financial services, plus a few other regulated businesses and professions.
The amendments of 19 December 2022 widened it in three ways. New categories: high-value goods dealers, crypto asset service providers, co-operative banks, company service providers, informal money remitters and payment clearing system participants. Existing categories were broadened, credit providers most of all. And Schedule 3, which listed motor vehicle dealers and Krugerrand dealers as lighter-touch "reporting institutions", was removed. Those dealing in goods at R100,000 or more moved into Schedule 1 with the full set of obligations.
The obligations applied from that date. The FIC ran an 18-month transitional approach, to June 2024, focused on implementation rather than financial penalties for the new sectors. By March 2025 more than 55,000 institutions were registered with the FIC, which conducted 556 inspections in the 2024/25 year.
Administrative sanctions run to R10 million for a natural person and R50 million for a legal person, alongside directives, restrictions on business activities and public reprimand. Serious contraventions can be prosecuted as crimes.
FICA compliance is not a form your customer fills in. It is the evidence that your business knew who it was dealing with, and can prove it.
Motor dealers: the newest accountable institutions
A dealership is an accountable institution when it receives payment of R100,000 or more for a single vehicle. Payment in any form counts: cash, EFT, card, finance or crypto. So does payment split across linked instalments (PCC 58 is the FIC's guidance for dealers).
The cash threshold report is a different rule. Cash above R49,999.99 triggers it, and an EFT is not cash for that purpose. So an EFT deal for R400,000 files no cash report, and still puts the dealership inside the Act.
What changes on the floor is the sequence. Under Schedule 3 a dealer filed cash threshold reports and, like any business, suspicious transaction reports. Now, for every qualifying sale, the dealer must verify the buyer before the deal concludes, identify the beneficial owner when a company is buying, screen against sanctions lists, keep records for five years and file suspicious transaction reports with no minimum value. For a dealer group with a hundred sites, that means one programme and one evidence trail, not a folder per showroom.
We covered the operational side in our earlier piece on dealership compliance. The dealers who struggle bolted FICA onto the finance and insurance desk. The ones who cope built it into the sale, where verifying and screening a buyer takes less time than a test drive.
Telcos: outside FICA, until they are not
A mobile operator selling airtime and data is not an accountable institution. RICA governs SIM registration, and RICA has a different purpose and a different standard of identification.
But the big operators sell far more than airtime and data. Wallets, device finance, airtime advances and funeral cover are now part of the offer. Each one can land inside Schedule 1, depending on how it is structured and which entity provides it. Credit sits under item 11, money or value transfer under item 19, insurance advice or intermediation under item 12. Where a partner bank or insurer is the accountable institution, it pushes the obligation down the contract into the telco's onboarding flow.
So the same customer gets verified twice, to two standards, often by two systems inside one group.
The operators getting ahead of this treat identity as one verified asset that both regimes draw on. Verify once, to the stricter of the two standards, then reuse the result wherever the rules allow, rather than starting from nothing at each product.
Fintechs: regulated faster than they expected
Most fintechs did not plan to be accountable institutions. They planned to be software. But providing the technology and carrying on the regulated activity are not the same thing, and the Act only cares about the second. A lender registered under the National Credit Act is a credit provider under item 11. A business moving value between parties, including third-party payment providers, falls under item 19, which the FIC has been clarifying in draft guidance since 2025. Crypto asset service providers have their own item and travel-rule directive.
A fintech under a sponsor bank's licence takes on the bank's requirements by contract. The statutory accountability stays with the bank, which is exactly why the bank will audit the fintech's onboarding as if it were its own.
The commercial risk is different from the regulatory one. Fintechs live or die on conversion, and every extra verification step is a place applicants leave. The Act requires due diligence proportionate to assessed risk: simplified measures where risk is lower, enhanced measures where it is higher.
The useful question is how fast the full check can run. A well-built onboarding flow can verify an identity document in under 90 seconds, screen the applicant against sanctions and PEP lists in the same pass, and store the record in a form an inspector can read. At that speed, compliance is no longer the slowest step in the application.
Long-term insurers: the original accountable institutions with a new job
Life insurers have been accountable institutions since the Act was written, under item 8 of Schedule 1, and are supervised for FICA purposes today by the Prudential Authority. Short-term insurers are not, though the duty to report suspicious transactions under section 29 applies to any business, Schedule 1 or not.
What changed for life insurers is the beneficiary. The Prudential Authority's Directive ID1 of 2022 requires insurers to obtain a beneficiary's particulars as soon as the beneficiary is identified, designated or amended, and to complete the risk assessment and due diligence before proceeds are paid.
That is a data problem before it is a compliance problem. Most insurers captured beneficiaries as a name and a relationship on a form, years ago. Claim stage, with a grieving family and a regulator watching turnaround times, is the worst moment to discover the record is incomplete. Verify at nomination and re-verify at policy review, and far less of it reaches the claims desk.
Beneficial ownership: the obligation that cuts across every sector
Every sector above runs into the same obligation the moment the customer is a company or a trust.
Section 21B of the FIC Act requires an accountable institution dealing with a company, trust or partnership to establish who the beneficial owners are and take reasonable steps to verify them. A beneficial owner is a natural person who directly or indirectly ultimately owns or exercises effective control of the client. Not the company. Not the nominee director. The person.
The FIC's Public Compliance Communication 59 of August 2024 sets out the route for a company. First, identify every natural person holding 5% or more. That figure comes from the FIC's guidance rather than the Act itself, and mirrors the Companies Act beneficial ownership regulations. Control below 5% can still count. If that produces no clear controller, look for control by other means: voting agreements, powers of attorney, debt instruments, the right to appoint the board. Only if both fail do you fall back to senior management. For a trust, identify the founder, trustees, beneficiaries and anyone else exercising effective control.
Since 2023, companies must also file beneficial ownership information with the CIPC, and trusts with the Master. That register helps. It does not discharge the obligation. The accountable institution still has to establish the owners itself and verify the register against source documents.
This is where FICA compliance quietly becomes a business verification problem. A dealer selling a fleet, a telco onboarding a business account, a lender extending working capital, an insurer writing a key-person policy. Each answers the same question about the same kinds of entities. The businesses that answer it well have one business verification process that pulls the CIPC record, resolves the ownership chain, screens the people behind it and stores the evidence. The ones that answer it badly have a spreadsheet and a share register that was out of date the day it was certified.
What to do now
Confirm your status. Read Schedule 1 against every revenue line, not just the main one. Register anything that qualifies within the 90-day window.
Rebuild the RMCP around actual risk. A programme copied from a template will not describe your customers, channels or products, and an inspector will notice within minutes.
Make due diligence one process, not four. Identity verification, beneficial ownership, sanctions and PEP screening, and record keeping are one flow from the customer's side and should be one flow from yours, with one audit trail. Every seam between systems is a place evidence goes missing, and every seam is a question you will have to answer from four screens instead of one.
Test that you can prove it. Pick ten client files at random and time how long it takes to produce the full record for each: the identity verification result, the ownership chain for any company, the sanctions and PEP screening result, and who approved the relationship and when. If the answer is measured in days, or the four pieces live in four places, you have found your first remediation project.
Where FICA compliance goes from here
South Africa spent 32 months on the FATF grey list and came off it on 24 October 2025. The exit changed the country's reputation. It did not relax a single obligation. If anything the pace has picked up since: a new guidance note in August 2026 and a directive on RMCP submissions in September.
For any business at volume, the five requirements are the easy part. The hard part is running them across every customer, every channel, every day, and then explaining any single decision afterwards without a week of reconciliation. That is an infrastructure question, and it is the one we spend our days on at Contactable.
If you run compliance at that scale and want to see one audit trail across identity, ownership and screening working on real cases, book a walkthrough. If you want the detail on screening first, start with AML screening.
The question worth putting to your risk committee this quarter: if a regulator asked, eighteen months from now, why we approved one particular customer, could we answer completely, and in one place?
This guide is general information about the Financial Intelligence Centre Act and is not legal advice. Accountable institutions should confirm their obligations with their compliance officer and supervisory body.
Frequently asked questions
What is FICA compliance in South Africa?
FICA compliance means meeting the obligations of the Financial Intelligence Centre Act 38 of 2001. For an accountable institution that means registering with the FIC, running a Risk Management and Compliance Programme, verifying customers and their beneficial owners, keeping records for five years and reporting cash threshold and suspicious transactions.
Who must comply with FICA?
Any business listed in Schedule 1 of the Act as an accountable institution. Since 19 December 2022 that includes banks, long-term insurers, credit providers, high-value goods dealers such as motor dealers, money or value transfer providers, crypto asset service providers and several regulated professions. The duty to report suspicious transactions under section 29 applies to every business, whether or not it is an accountable institution.
What are the FICA requirements for motor dealers?
A dealer that receives R100,000 or more for a single vehicle, in any form of payment, is a high-value goods dealer under item 20 of Schedule 1. It must register with the FIC, adopt an RMCP, verify buyers and their beneficial owners, screen against sanctions lists, keep records for five years and report cash threshold and suspicious transactions. Taking payment by EFT does not change this: EFT only falls outside the separate cash threshold report. Register when you reasonably expect to sell vehicles at that value, not after the first one.
What documents are required for FICA?
There is no fixed FICA document list, and there has not been since the 2017 amendments. Each accountable institution sets out in its RMCP how it identifies and verifies customers, using reliable independent sources, which can be documents (smart ID card, green ID book, passport) or electronic sources such as government databases. Proof of address is not a universal legal requirement. Whether it is asked for depends on the institution's risk assessment. Companies add registration documents and beneficial ownership information.
What is the penalty for non-compliance with FICA?
The FIC and supervisory bodies can impose administrative sanctions including a caution, reprimand, directive, restriction of business activities and financial penalties of up to R10 million for a natural person or R50 million for a legal person. Certain contraventions are criminal offences and can be referred for prosecution.
What is a beneficial owner under FICA?
A natural person who directly or indirectly ultimately owns or exercises effective control over a client, or who exercises control over a client on whose behalf a transaction is conducted. The FIC's guidance uses a 5% ownership threshold as the starting point, then control by other means, then senior management.
Are telcos accountable institutions under FICA?
Not for selling airtime and data, which falls under RICA. But a telco, a subsidiary or a partner offering credit, mobile money, payments or insurance can fall within Schedule 1 for that activity, and a partner's registration does not automatically cover the telco's own obligations.