The Financial Intelligence Centre (FIC) is set to include more sectors under its purview as accountable institutions while addressing gaps that may exist in the country’s anti-money laundering and counter-terrorist financing framework.
The expansion will be effected pending updates to the schedules to the Financial Intelligence Centre Act (FIC Act). The new categories of accountable institutions will include crypto asset service providers, high-value goods dealers, money value transfer service providers, payment clearing service operators, and credit providers.
The inclusion of these sectors as accountable institutions is a major milestone aligning South Africa’s anti-money laundering and counter-terrorist financing framework more closely with the Financial Action Task Force (FATF) standards. The FATF, of which South Africa is a member, is the international standard-setting body on measures to combat money laundering and the financing of terrorism and proliferation.
The impact of amending the schedules to the FIC Act will be far reaching for the sectors that fall under the new category of accountable institutions as they would have to meet additional compliance in terms of the FIC Act.
What does it mean to be an accountable institution?
In terms of the FIC Act, accountable institutions must meet certain regulatory obligations including:
Registration with the FIC
The entities that will fall under the new category of accountable institutions would have to register with the FIC via the online registration and reporting system called goAML. Refer to PCC 5C and the accountable and reporting institutions registration guideline for more information in this regard.
Account monitoring and reporting
Accountable institutions must monitor client transactions to identify suspicious and unusual transactions and activities.
There are three primary reporting streams for all accountable institutions:
- Cash threshold reports (CTRs) – on transactions (cash paid or received) exceeding R24,999.99. This must be reported as soon as possible but not later than two days from the transaction. See FIC guidance note 5B.
- Suspicious and unusual transaction reports (STRs/SARs) – transaction or activity that is unusual or arouses suspicion in terms of money laundering or terrorist activities. Must be reported without delay but no later than 15 days from becoming aware of the transaction or activity. These reports are filed regardless of the amount of money involved. See FIC guidance note 4B.
- Terrorist property reports (TPR) – where the accountable institutions have in their possession property of a person who is listed on a targeted financial sanctions list or is associated with terrorism, proliferation financing and related activities. This must be reported without delay and no later than five days from becoming aware. See FIC guidance note 6A.
The FIC uses regulatory reports it receives to conduct analysis to identify possible links to unlawful activities.
Applying a risk-based approach
Accountable institutions must follow a risk-based approach when dealing with different clients due to the differing levels of money laundering, terrorist financing and proliferation financing risks.
Where there are heightened risks, the accountable institution must apply more stringent controls to mitigate those risks. For example, where a client poses a higher risk, the accountable institution could request additional documents to further verify the information provided by the client.
Customer due diligence
Accountable institutions must know who their clients are. Accountable institutions must identify and verify the identity of clients, persons acting on behalf of the client, and the client’s beneficial owners.
Understanding who the client is and what business the client deals in enables the accountable institution to identify suspicious and unusual transactions or activities. Refer to FIC guidance note 7.
Scrutinising client information
Accountable institutions must scrutinise client information against targeted financial sanctions lists as no person may transact with a sanctioned person or entity or process transactions for such a person or entity. See FIC PCC 44.
In addition, accountable institutions must determine whether a client is a foreign prominent public official or high-risk domestic prominent influential person as there are additional obligations in terms of the FIC Act that apply when dealing with these persons. See FIC PCC 51.
Record-keeping
Accountable institutions must keep records of client identification and verification information, transactions and regulatory reports filed with the FIC.
These records must be kept for at least five years from the date on which:
- The business relationship was terminated
- A transaction was concluded
- A regulatory report was submitted to the FIC.
Risk management and compliance programme
Accountable institutions must develop, document, maintain and implement a risk management and compliance programme (RMCP). Section 42 of the FIC Act details what should be covered in an RMCP.
The FIC recently published draft PCC 114 and draft guidance note 7A which sets out guidance on the RMCP.
Training of employees
All employees of an accountable institution must be trained on both the FIC Act and their institution’s obligations as set out in their RMCP. Although the level of training may vary according to their risk exposure.
Appointing a compliance officer
The accountable institution should appoint a person with sufficient competence and seniority to ensure effective compliance by the institution, this person is referred to as a compliance officer. This person can be supported by the compliance function, however, the accountability for FIC Act compliance remains the obligation of the senior management and board of directors.
For more compliance information and guidance offered to accountable institutions, refer to the FIC website (www.fic.gov.za). For further information contact the FIC’s compliance contact centre on +27 12 641 6000 or log an online compliance query by clicking on: http://www.fic.gov.za/ContactUs/Pages/ComplianceQueries.aspx.




























