FICA Explained: What the Financial Intelligence Centre Act Requires of South African Accountable Institutions (2026)

A plain-English guide to South Africa's Financial Intelligence Centre Act, 2001 (FICA): who it covers, registration, customer due diligence and PEPs, records, targeted financial sanctions, the four reports, the RMCP, governance, supervision and penalties.

CS
Creodata Solutions Team
FICA Explained: What the Financial Intelligence Centre Act Requires of South African Accountable Institutions (2026)

Short answer: The Financial Intelligence Centre Act, 2001 (Act 38 of 2001, the FIC Act or FICA) is South Africa's core anti-money laundering and counter-terrorist financing law. It establishes the Financial Intelligence Centre (FIC), lists the accountable institutions it covers in Schedule 1, and requires them to register with the FIC, know their clients, keep records for five years, apply targeted financial sanctions, report cash above R49,999.99, suspicious and unusual transactions, terrorist property and international funds transfers, and run a documented Risk Management and Compliance Programme (RMCP). Its suspicious transaction duty applies to every business, not only accountable institutions.

This guide is for compliance officers, principals and board members at South African banks, insurers, financial services providers, estate agencies, legal practices, gambling operators, dealers, crypto asset service providers and other accountable institutions. It follows the Act's structure. It is a plain-English summary, not legal advice: the Act, its regulations and the FIC's guidance are the authoritative texts.


The Act at a glance

Part of the ActWhat it covers
Chapter 1The FIC: its establishment, objectives and functions
Chapter 3, Part 1 (sections 20A–21H)Customer due diligence, beneficial owners and politically exposed persons
Chapter 3, Part 2 (sections 22–26)Records and how long to keep them
Chapter 3, Part 2A (sections 26A–26C)Targeted financial sanctions under UN Security Council resolutions
Chapter 3, Part 3 (sections 27–41)Reporting: cash, terrorist property, suspicious transactions, cross-border cash and international transfers; the FIC's power to intervene
Chapter 3, Part 4 (sections 42–43B)The RMCP, governance, training, directives and registration
Chapter 3, Part 5 (sections 44–45)Referral of suspected offences, and supervision
Chapter 4 (sections 45A–71)Compliance and enforcement: inspections, administrative sanctions, offences and penalties
Chapter 5 (sections 72 onwards)Miscellaneous: amending the schedules, exemptions and regulations
Schedules 1, 2 and 3Accountable institutions, supervisory bodies and reporting institutions

Who FICA covers

Schedule 1 lists the accountable institutions, including legal practitioners, trust and company service providers, estate agents, authorised users of an exchange, collective investment scheme managers, banks, mutual and co-operative banks, life insurers, gambling operators, foreign exchange dealers, credit providers, investment financial services providers, money or value transfer providers, dealers in high-value goods (for payments of R100,000 or more), crypto asset service providers and clearing system participants. Schedule 3 lists reporting institutions. Section 29, the suspicious transaction duty, applies to anyone who carries on, manages or works for any business.

Registration (section 43B)

Every Schedule 1 accountable institution and Schedule 3 reporting institution registers with the FIC, free of charge, on its goAML portal; Schedule 1 institutions do so within 90 days of the business being established, and changes are notified within 90 days. See our FIC registration guide.

Customer due diligence and PEPs (sections 20A–21H)

Accountable institutions may not deal with anonymous clients or clients using false or fictitious names (section 20A). They identify and verify clients and those acting for them (section 21), understand the business relationship (section 21A), identify and take reasonable steps to verify the beneficial owners of legal persons, trusts and partnerships (section 21B), conduct ongoing due diligence (section 21C), act on doubts about information and on suspicions (section 21D), and do not proceed where due diligence cannot be done (section 21E). Foreign politically exposed persons (section 21F), domestic politically exposed persons and prominent influential persons (section 21G) and their family members and known close associates (section 21H) get the additional measures the Act prescribes. Our enhanced due diligence guide covers the practice.

Records (sections 22–25)

Due diligence and transaction records are kept for at least five years from the end of the business relationship, the conclusion of a single transaction, or the date a section 29 report was submitted (section 23). They may be kept electronically and by third parties (section 24).

Targeted financial sanctions (sections 26A–26C)

The FIC gives notice of persons and entities identified by the UN Security Council, and the Act prohibits making property or financial services available to them, subject to permitted exceptions. When a notice is given, an institution scrutinises its client information for matches, and a match is reported to the FIC as a terrorist property report under section 28A.

The four reports (sections 28–31)

ReportSectionWhen
Cash threshold report (CTR)28Cash above R49,999.99 paid or received; within 3 days
Terrorist property report (TPR)28AProperty of listed persons or entities; within the prescribed period
Suspicious and unusual transaction report (STR, SAR, TFTR, TFAR)29As soon as possible and within 15 days of becoming aware of the facts
International funds transfer report (IFTR)31Electronic transfers into or out of South Africa above the prescribed amount

Day counts exclude Saturdays, Sundays and public holidays. All four are filed on goAML. An institution may continue with a reported transaction unless the FIC directs it not to proceed, for up to 10 days, under section 34. See our guides to cash threshold reports and section 29 reports.

The RMCP, governance and training (sections 42–43)

Every accountable institution develops, documents, maintains and implements a Risk Management and Compliance Programme (section 42). The board, or senior management where there is no board, must ensure compliance with the Act and the RMCP, and an institution that is a legal person has a compliance function led by a person "with sufficient competence and seniority" (section 42A). Employees are trained on the Act and the RMCP (section 43).

Supervision and administrative sanctions (sections 45–45F)

Supervisory bodies listed in Schedule 2, such as the Prudential Authority and the Financial Sector Conduct Authority, supervise the institutions they regulate, and the FIC supervises accountable institutions that have no supervisory body, such as estate agents. The FIC or a supervisory body may impose a caution, a reprimand, a directive, a restriction or suspension of business activities, or a financial penalty of up to R10 million for a natural person and R50 million for a legal person (section 45C).

Offences and penalties (sections 46–69)

Offences include failing to identify clients, to keep records, to report cash transactions, terrorist property or suspicious transactions, to register, and to maintain an RMCP; unauthorised disclosure; and conducting transactions to avoid a reporting duty. Most carry up to 15 years' imprisonment or a fine of up to R100 million (section 68). An employee charged with failing to report a suspicious transaction may rely on having followed the RMCP or reported internally (section 69).


What FICA means for your systems

DutyWhat a system has to do
Due diligence and PEPsHold identity and beneficial-owner data, rate risk under the RMCP, and flag PEPs, prominent influential persons and their associates
SanctionsScreen clients against the targeted financial sanctions list whenever the FIC gives notice, and route matches to a terrorist property report
Cash threshold reportsSeparate cash from EFTs, detect cash above R49,999.99 in each direction, and file within 3 working days
Suspicious transactionsTime-stamp the facts, not just the suspicion, so the 15-day clock is visible from the start
RecordsKeep records for at least five years and produce them for inspections

Our buyer's guide to FICA compliance software turns these duties into evaluation criteria, and our guide to FICA compliance for estate agents applies them to one sector.


Frequently asked questions

What is FICA?

The Financial Intelligence Centre Act, 2001 (Act 38 of 2001), South Africa's core law against money laundering and terrorist financing. It establishes the Financial Intelligence Centre and sets the duties of accountable and reporting institutions.

Who has to comply with FICA?

The accountable institutions in Schedule 1 (including banks, life insurers, estate agents, legal practitioners, gambling operators, credit providers, financial services providers, dealers in high-value goods and crypto asset service providers) and the reporting institutions in Schedule 3. The suspicious transaction duty in section 29 applies to every business.

What is an RMCP?

A Risk Management and Compliance Programme: the documented programme every accountable institution must develop, maintain and implement under section 42 to identify, assess and manage its money laundering and terrorist financing risk.

What reports does FICA require?

Cash threshold reports (section 28), terrorist property reports (section 28A), suspicious and unusual transaction reports (section 29) and international funds transfer reports (section 31), all filed on the FIC's goAML portal.

What are the penalties under FICA?

Administrative sanctions of up to R10 million for a natural person and R50 million for a legal person (section 45C), and for most criminal offences up to 15 years' imprisonment or a fine of up to R100 million (section 68).


See how Creodata's FICA compliance and AML software in South Africa supports your RMCP: book a demo.

See AML Compliance Software in action.