Grey list removal took compliance – staying off takes credibility

0
19

Bradley Elliott | CEO | RelyComply | mail me |


South Africa completed its Financial Action Task Force (FATF) action plan and left the grey list in October 2025. The more telling test now is whether the systems built under pressure remain effective when no deadline forces the issue.

For businesses, that makes compliance less of a regulatory exercise. Instead, it forms part of the infrastructure required to grow with confidence.

Background – what is FATF?

FATF is an international group created in 1989 by the G7. It sets global rules to stop money laundering, terrorist financing, and the funding of mass destruction weapons. More than 200 countries use its guidelines to protect the world’s money system.

Getting off the grey list was an important achievement for South Africa. It proved that a country facing serious weaknesses in its anti-money laundering and counter-terrorist financing framework could mobilise regulators, law enforcement agencies and the private sector around a common set of reforms.

However, drawing up an action plan and proving that a system works in the long term aren’t mutually assured. The FATF’s assessment process does not end when a jurisdiction leaves increased monitoring. South Africa’s next mutual evaluation is already imminent. It could include an on-site assessment in February 2027, followed by a plenary discussion later that year.

Even though policies and affiliated institutions exist, FATF also assesses whether mandated measures are in place and produce the outcomes they were designed to achieve. Those measures include customer due diligence, transaction monitoring and suspicious-transaction reporting. They also cover supervision, investigation, prosecution, asset recovery and cooperation between the institutions responsible for fighting financial crime.

For financial institutions and other accountable businesses, compliance has changed. It is no longer enough to demonstrate that an organisation has a policy, screening process or transaction-monitoring system. The real test is whether those controls work. It also involves whether leadership has a clear view of risk and whether the organisation can respond when the environment changes.

Compliance meets credibility

This is all happening in the shadow of the Madlanga Commission. The Commission is examining allegations of criminality, political interference and corruption within the criminal justice system. Its work remains ongoing, and its findings must be allowed to run their course. However, the public discourse has already put institutional credibility in the spotlight.

In July, the Minister of Justice and the National Director of Public Prosecutions publicly acknowledged that testimony before the Commission had raised serious credibility concerns around the Investigating Directorate Against Corruption. They also acknowledged that the testimony had affected public trust in its operations. The Commission’s final report is now due in November.

For the private sector, there is a useful principle here without attempting to prejudge any of the Commission’s findings. A framework is only as credible as its ability to operate as intended. Governance structures, policies and controls cannot be ignored. However, confidence ultimately rests on whether they can withstand scrutiny in practice.

The same is true of any anti-money laundering programme. A board may receive detailed compliance reports every quarter and still lack a consolidated view of the risks moving through the organisation. A business may have sophisticated technology and still struggle to explain why alerts are generated, how decisions are made or who takes responsibility when something goes wrong.

This supports the argument that compliance maturity has become a business issue rather than a compliance-team issue.

From remediation to strategy

Getting off the grey list forced many South African institutions to invest. Awareness increased, controls tightened, beneficial-ownership requirements underwent reevaluation, and financial-crime risk climbed higher up the executive agenda. The mistake now would be to regard those investments as the cost of passing a regulatory test that is safely behind us.

Commercially, removing a country-level risk label does not mean that banks, investors, partners and counterparties stop assessing the quality of an individual organisation’s controls. In fact, it makes the organisation’s own compliance maturity more visible.

A business that understands its customers can explain its risk exposure and has reliable information available when decisions need to be made. As a result, it is better equipped to onboard customers efficiently, enter new markets, satisfy potential partners and scale without accumulating compliance debt. Those are both regulatory and operating advantages.

Effective compliance infrastructure gives decision-makers better information. Better information allows them to assess risk properly. Moreover, when organisations design systems to grow with the business, expansion does not have to trigger an expensive scramble to rebuild controls. This avoids the problems that arise when controls were never designed for the new level of complexity.

The strongest organisations should stop asking how much compliance is enough to satisfy the regulator. The pertinent question is whether their financial-crime programme gives the business the visibility, resilience and confidence it needs to make good decisions.

Are we done yet?

There is no finish line for maintenance. South Africa’s greylisting jumpstarted urgency because the consequences were visible and the deadlines were finite. The next phase is more difficult precisely because it is less dramatic. Maintaining effectiveness requires continued investment when no crisis forces the conversation.

FATF’s next evaluation will provide one external measure of how well South Africa has sustained its progress. Meanwhile, the wider credibility debate playing out through the Madlanga Commission is the big yellow Post-it note. It reminds us that trust cannot be established through structures alone.

Compliance cannot be something we build for an inspection and hide in a cupboard. It must function every day and under changing conditions. Leadership also needs enough visibility to understand what is happening. At the same time, the organisation needs enough resilience to support where the business wants to go next.

Ultimately, getting off the grey list represents an important milestone, not the end of the compliance journey. Staying credible, competitive and ready for what comes next will require something more enduring.


 



LEAVE A REPLY

Please enter your comment!
Please enter your name here