Sameer Kumandan | Managing Director | SearchWorks | SW360 | mail me |
The latest regulatory action against a major financial institution resulted in a R28 million administrative penalty. The penalty followed shortcomings under the Financial Intelligence Centre Act (FICA). It is a timely reminder that compliance cannot become a once-off exercise.
What stands out to me is not the size of the penalty, or even the institution involved. Instead, it is the nature of the shortcomings identified. These included gaps in customer due diligence, enhanced and ongoing due diligence, employee training, screening, terrorist-property reporting and aspects of the organisation’s risk-management and compliance programme.
Compliance must remain ongoing
These are not isolated compliance activities. They are connected parts of an ongoing process. That process helps organisations understand who they are dealing with, assess the risks involved and respond when those risks change. That distinction is important.
Too often, organisations still view compliance as an onboarding event. They verify the customer, collect the documentation, complete the checks and move on. However, a customer’s risk profile does not remain static simply because the initial verification was completed successfully.
Ownership can change. A person can become a politically exposed person. Sanctions lists can change. A business can develop new activities or relationships. Transaction behaviour can shift. Information that was accurate when a relationship began may no longer reflect the situation months or years later. This is why ongoing due diligence matters.
These changing circumstances can create compliance gaps if organisations treat initial verification as the end of the process. Effective compliance requires organisations to revisit customer information and risk as circumstances change.
Technology can help close gaps
The other lesson is that compliance cannot depend solely on people remembering to perform manual checks at the right time. As organisations grow and customer volumes increase, relying on disconnected spreadsheets, manual processes, and periodic reviews creates opportunities for things to fall through the cracks.
Technology has an important role to play here. However, it should not replace human judgement. Instead, it should enable better and more consistent processes.
The right systems can help organisations verify information, identify changes, screen against relevant risk indicators, maintain records and create an electronic audit trail. They can also help bring different compliance activities into a more connected workflow. This makes it easier to identify where further investigation or enhanced due diligence may be required.
Technology can therefore help organisations identify and address compliance gaps earlier. However, organisations should not assume that technology alone will resolve every weakness.
People, policies and processes matter
Technology is only one part of the solution. Organisations also need clearly defined policies, appropriately trained employees, accountable management, and regular review of risk and processes that employees actually follow in practice.
A policy sitting in a compliance manual is of little value if employees do not understand it. It also has limited value if the organisation cannot demonstrate how employees apply it.
The encouraging point is that these risks are manageable. The objective should not be to create layers of bureaucracy that slow legitimate business down. Instead, organisations should build compliance into the way the business operates.
That means verification, screening, monitoring and risk assessment should happen as naturally as other critical business processes.
Prepare before regulators arrive
Recent enforcement actions should therefore be viewed as more than warnings about the potential financial consequences of non-compliance. They are reminders that effective compliance is ultimately about being prepared before the regulator arrives, rather than because the regulator has arrived.
For accountable institutions, the question worth asking now is simple: if our compliance processes were tested tomorrow, could we demonstrate not only that we have the right policies, but that they are working in practice?
If the answer is uncertain, that is not necessarily a reason for alarm. Instead, it is an opportunity to identify the compliance gaps, strengthen the processes and address them before they become a much more expensive problem.


























