FICA Compliance and AML Software in South Africa: A Buyer's Guide for Accountable Institutions (2026)
How to choose FICA compliance and AML software in South Africa: FIC goAML reporting, the R49,999.99 cash threshold and 15-day STR rules, the RMCP, provider types, evaluation criteria, cost drivers and red flags.

Short answer: Good FICA compliance and anti-money laundering (AML) software for a South African accountable institution does five jobs well: it supports the customer due diligence and risk rating your Risk Management and Compliance Programme (RMCP) describes, screens customers against targeted financial sanctions lists and politically exposed person data, monitors transactions across every channel you run, turns alerts into documented cases inside the Financial Intelligence Centre's 15-day limit, and gets cash threshold, suspicious and terrorist property reports to the FIC through goAML. Choose on evidence from scripted demos on your own data, and compare three-year costs on the same basis.
This guide is for compliance officers, heads of risk and procurement teams at banks, insurers, financial services providers, money transfer providers, foreign exchange dealers, estate agents, gambling operators, crypto asset service providers and the other accountable institutions listed in Schedule 1 of the Financial Intelligence Centre Act, 2001 (FICA). Most already have a documented RMCP; the question is whether their systems can produce the evidence it promises.
Creodata offers FICA compliance and AML software in South Africa, so we say plainly where we fit near the end. The criteria before that are the ones we would use to choose any vendor. This is a practical guide, not legal advice: confirm requirements against the FIC Act, the Money Laundering and Terrorist Financing Control Regulations and the FIC's guidance.
What FICA compliance software does
AML software turns your customer and transaction data into the decisions FICA requires, and keeps the evidence of each one.
| Function | What it does | What matters in South Africa |
|---|---|---|
| Customer due diligence and risk rating | Scores each client's money-laundering and terrorist-financing risk from factors such as geography, product, channel and PEP status | A model that follows your RMCP, which compliance can change without code, with every override approved and recorded |
| Sanctions and PEP screening | Checks names against sanctions lists, PEP data and adverse media, at onboarding and whenever lists change | The targeted financial sanctions list and the UN 1267 list, FICA's PEP categories, and proof of which list version was used |
| Transaction monitoring | Runs rules and models over transactions to raise alerts on suspicious patterns | Cash, EFT, card and cross-border coverage, and detection of cash split to stay under R49,999.99 |
| Case management | Turns alerts into owned cases with deadlines, evidence and approvals | Working-day timers for the 15-day STR and 3-day CTR limits, and the reason for reporting and action taken recorded for each report |
| Regulatory reporting | Prepares cash threshold, suspicious and terrorist property reports | Files the FIC's goAML portal accepts, validated before submission |
| Audit trail | Records every action and decision | An append-only log and five-year records that stand up when the FIC or your supervisor inspects |
The complete AML platform guide explains each function in depth.
Who needs FICA compliance software
FICA's duties fall on the accountable institutions in Schedule 1. The list covers legal practitioners, trust and company service providers, estate agents, gambling operators, banks, mutual and co-operative banks, life insurers, foreign exchange dealers, credit providers, investment financial services providers, money or value transfer providers, dealers in high-value goods (payments of R100,000 or more), crypto asset service providers and clearing system participants, among others.
Schedule 2 of the Act names the supervisory bodies, and the FIC supervises accountable institutions that have none:
| Accountable institutions | Supervisor |
|---|---|
| Banks, mutual banks, co-operative banks, life insurers, money or value transfer providers and clearing system participants | Prudential Authority of the South African Reserve Bank |
| Foreign exchange dealers, issuers of travellers' cheques and money orders, and money or value transfer providers | Financial Surveillance Department of the South African Reserve Bank |
| Authorised users of an exchange, collective investment scheme managers and investment financial services providers | Financial Sector Conduct Authority |
| Estate agents, gambling operators, crypto asset service providers, dealers in high-value goods and other institutions with no supervisor in Schedule 2 | Financial Intelligence Centre |
Not every institution needs the same system. A bank needs real-time monitoring across many channels, while an estate agency or a small financial services provider usually needs dependable screening, risk rating and reporting first, at a cost that fits its size.
The FICA requirements that shape the choice
Most vendor demos look alike until you test them against the rules you actually work under. Section numbers below are those of the FIC Act; regulation numbers are those of the Money Laundering and Terrorist Financing Control Regulations.
- goAML for registration and every report. Registration with the FIC is compulsory, free and done only on its goAML portal, goweb.fic.gov.za; Schedule 1 institutions must register within 90 days of starting business (section 43B). The portal names four reporting streams, all filed on goAML: cash threshold reports, suspicious and unusual transaction reports, terrorist property reports and international funds transfer reports.
- Suspicious and unusual transaction reports within 15 days. Reports under section 29 go to the FIC as soon as possible and no later than 15 days, excluding Saturdays, Sundays and public holidays, after a person becomes aware of the facts that give rise to the suspicion (regulation 24(3)). Completed transactions are STRs and incomplete ones SARs. The FIC points out that the 15 days run from awareness of the facts, which is often before the suspicion is formed, so each case needs that date recorded.
- Cash threshold reports within three days. Cash above R49,999.99 paid to or received from a client must be reported no later than three days, excluding weekends and public holidays, after becoming aware of it (section 28; regulation 24(4)). Cash means coin, notes and travellers' cheques, not EFTs or bank cheques. Cash below the threshold is not added up into a CTR, but transactions split to avoid a report must be considered for an STR (section 29(1)(b)(iii)).
- Terrorist property reports. A match between a party to a transaction and the targeted financial sanctions list or the UN Security Council Resolution 1267 list is a factual report under section 28A, so screening has to run on current lists and record what was matched.
- Pre-validation. The FIC asks institutions to pre-validate reports so that accurate information reaches it on time, and reports must follow the reporting system's schema and business rules (Guidance Notes 5C and 4B).
- The RMCP. Every accountable institution must document, maintain and implement a Risk Management and Compliance Programme (section 42). The software should run the controls the RMCP describes and keep the evidence that it did.
- PEPs in FICA's terms. The Act distinguishes foreign politically exposed persons (section 21F), domestic politically exposed persons and prominent influential persons (section 21G), and their family members and known close associates (section 21H). Screening data and risk rules should use the same categories.
- Five-year records. Records of the business relationship, of single transactions and of anything reported under section 29 must be kept for at least five years (section 23).
The types of FICA compliance software provider
A search for FICA compliance software or AML software in South Africa returns very different kinds of supplier. Knowing which kind you are talking to tells you what to test.
| Provider type | Typical strengths | Watch for |
|---|---|---|
| Global AML suites | Depth, large-bank references, mature analytics | Cost, long implementations, and whether FIC goAML reporting and FICA's categories work out of the box or through partners |
| Local FICA and KYC platforms | Local presence, fast onboarding, identity and address checks | Whether they go beyond onboarding into transaction monitoring, case management and goAML reporting |
| AML modules from core banking vendors | Tight integration with the vendor's own core system | Screening and monitoring depth compared with specialist tools, and lock-in to one core platform |
| Consultancies | RMCP drafting, risk assessments, training | Whose software it is, and whether it is a system or a set of templates |
| Specialist AML vendors from other African markets | goAML reporting built in, and a full case-to-report workflow | Support arrangements in South Africa, references of similar size, security assurance, and the roadmap behind each module |
| Spreadsheets and in-house builds | Low starting cost, full control | Key-person risk, no audit trail, and the cost of keeping pace with FIC changes |
Evaluation criteria
Score every vendor against the same requirements, weighted before the first demo.
| Area | What to test |
|---|---|
| Regulatory fit | goAML files the FIC's portal accepts for CTRs, STRs, SARs and TPRs; working-day timers for the 3-day and 15-day limits; the R49,999.99 cash rule; pre-validation before submission |
| RMCP support | Controls, thresholds and workflows set to match your RMCP, with evidence exportable for an inspection |
| Risk rating | Compliance can change the model without code; overrides need four eyes; ratings explain themselves |
| Screening | The targeted financial sanctions list and UN lists; FICA's PEP categories; matching quality on your own sample of names; list freshness you can prove |
| Transaction monitoring | Cash, EFT, card and cross-border coverage; cash split below R49,999.99; back-testing before rules go live |
| Case management | The date of awareness on every case; reason for reporting and action taken; tipping-off controls; an append-only audit trail |
| Deployment and data | Where data is stored and processed; the same features in cloud and on-premises editions; security assurance |
| Commercials | Three-year cost; currency of the quote; implementation plan; references; exit terms; regulatory updates included |
How to run the evaluation
- Set priorities with compliance, risk, IT and procurement, using your RMCP as the requirements list.
- Long-list suppliers and drop those that fail your Must-have requirements.
- Issue an RFP with your questions and the evidence you expect. Our free AML vendor RFP checklist and scoring template was written for Kenya, but most requirements carry over once you swap in the FIC, FICA and your supervisor.
- Run scripted demos on your own data: a domestic prominent influential person at onboarding, a near-match against the targeted financial sanctions list, cash of R30,000 twice in a day at two branches, and an alert taken to a filed STR with the 15-day timer visible throughout.
- Call references of similar size and sector, and ask what went wrong.
- Score independently, then calibrate as a panel, and file the scoring sheet with the decision papers.
What FICA compliance software costs
Vendors price AML software in very different ways, so ask every shortlisted vendor to itemise the same lines over three years:
- Licence: per module or tier, per client or account, per transaction, or a flat enterprise fee.
- List data: sanctions, PEP and adverse-media data is often a separate subscription.
- Implementation: data mapping, core-system integration, rule configuration and training.
- Hosting: cloud subscription and consumption, or servers and operations on-premises.
- Support, including whether changes to the FIC's goAML reporting are covered.
- Currency: rand or US dollars, and who carries the exchange-rate risk.
- Internal effort: your analysts' and IT team's time during and after implementation.
A lower licence fee can hide higher data, integration or change-request costs, so compare three-year totals, not first-year quotes.
Red flags
- The vendor cannot show a goAML file the FIC's portal accepts, or treats FIC reporting as a future feature.
- STR timers start when suspicion is confirmed rather than when the facts came to light, or count calendar days instead of working days.
- The cash rule treats EFTs as cash, or ignores cash paid out to clients.
- Screening has no path for terrorist property reports, or is demonstrated only on the vendor's sample names.
- The product "supports your RMCP" but cannot show which control produced which piece of evidence.
- An administrator can edit or delete audit entries.
- Must-have requirements are answered with roadmap dates.
Where Creodata fits
Creodata is a Nairobi software company, and our AML compliance software is a specialist vendor's answer to the criteria above. It covers sanctions, PEP and adverse-media screening with multi-script matching and a false-positive workflow; customer risk rating across country, industry, product, channel, behaviour and PEP or sanctions exposure, with four-eyes overrides; batch and streaming transaction monitoring with back-testing; case management with enhanced due diligence; and an append-only audit log. Reports move through a draft, review, approve and submit lifecycle, and our separate goAML reporting software for South Africa generates the file for the FIC's portal and validates it against the schema and business rules before submission, with a manual download if the portal is down.
The cloud edition runs on Microsoft Azure as an Azure Managed Application, and Azure has regions in South Africa (South Africa North in Johannesburg and South Africa West in Cape Town); the on-premises edition runs on your own Kubernetes cluster with the same features. Modules are licensed separately in Starter, Growth and Enterprise tiers, so an estate agency or financial services provider can start with screening, risk rating and case basics and a bank can run the full suite. See FICA compliance and AML software in South Africa for how each duty maps to a module and the AML product overview for every module, or book a demo and bring your own scenarios.
Frequently asked questions
What is FICA compliance software?
Software that runs the controls FICA requires and keeps the evidence: customer due diligence and risk rating, screening for sanctions and politically exposed persons, transaction monitoring, record keeping and reporting to the FIC through goAML. The RMCP is your institution's own document; the software supplies the controls and the audit trail it describes.
What are the FIC's reporting deadlines?
Suspicious and unusual transaction reports go to the FIC as soon as possible and no later than 15 days after becoming aware of the facts, and cash threshold reports for cash above R49,999.99 no later than 3 days after becoming aware of the transaction, in both cases excluding Saturdays, Sundays and public holidays (regulation 24 of the Money Laundering and Terrorist Financing Control Regulations). Terrorist property reports cover matches to the targeted financial sanctions list or the UN 1267 list.
How much does FICA compliance software cost?
It varies because vendors price differently: by module or tier, by client or account, by transaction volume, or as an enterprise licence, with list data, implementation and hosting often extra. Ask each shortlisted vendor to itemise licence, data, implementation, hosting and support costs over three years in the same currency, and compare the totals.
Does AML software file reports with the FIC?
Every regulatory report reaches the FIC through its goAML portal, so what matters is whether the software produces goAML files the portal accepts and tracks each report to acknowledgement. Ask for a validated sample file, and ask how the vendor handles changes to the FIC's reporting system. In Creodata's case, the AML software manages the report lifecycle and the separate Creodata goAML Reporting Platform generates and validates the file.
Do estate agents and other smaller institutions need FICA software?
Once volumes grow, usually. The duties do not shrink with size: registration on goAML, the RMCP, the 3-day and 15-day reporting limits and five-year records apply to every accountable institution, and the FIC supervises estate agents directly. A small institution can work manually for a while, but proving it met the reporting limits is hard without a system that timestamps each step.
Can AML software be hosted in South Africa?
Microsoft Azure has regions in South Africa, and on-premises deployment keeps data in your own data centre. Decide with your legal and risk teams where data should live, check what your supervisor expects of outsourcing, and ask each vendor where data is stored and processed and whether the cloud and on-premises options have the same features.
See how Creodata's FICA compliance and AML software in South Africa meets these criteria: book a demo and bring your own scenarios.


