FICA Requirements for Banks in South Africa: Reports, Directive 5, the Prudential Authority and Its Fines (2026)

What South African banks must do under the FIC Act: the four regulatory reports including IFTRs above R19,999.99, Directive 5's 48-hour and 15-day clocks, wire transfers, the RMCP and the board, what Prudential Authority inspections find, and every PA sanction on a bank from 2022 to 2026.

CS
Creodata Solutions Team
FICA Requirements for Banks in South Africa: Reports, Directive 5, the Prudential Authority and Its Fines (2026)

Short answer: Banks, mutual banks and co-operative banks are accountable institutions under the Financial Intelligence Centre Act, 2001 (FICA), and the Prudential Authority (PA) at the South African Reserve Bank supervises them. A bank registers with the Financial Intelligence Centre (FIC) on goAML and runs a board-approved Risk Management and Compliance Programme (RMCP). It files four regulatory reports: cash above R49,999.99 within 3 days, suspicious transactions within 15 days, terrorist property within 5 days, and international funds transfers above R19,999.99 within 3 days. If it uses automated monitoring, Directive 5 of 2019 gives it 48 hours to attend to each alert. From 2022 to 2026 the PA published 16 sanction decisions against banks, most of them for late reports and missed alert deadlines.

This guide is for money laundering reporting officers, compliance and financial crime teams, and boards at South African banks and their foreign branches and subsidiaries. It is a practical guide, not legal advice: the Act, the Money Laundering and Terrorist Financing Control Regulations, the FIC's directives and guidance, and the PA's instructions are the authoritative texts.


Which banks FICA covers

Schedule 1 itemInstitutionSupervisor
6A person carrying on "the business of a bank" under the Banks Act, 1990Prudential Authority
7A mutual bank under the Mutual Banks Act, 1993Prudential Authority
7AA co-operative bank under the Co-operative Banks Act, 2007 (added from 19 December 2022)Prudential Authority
14The South African PostbankThe FIC, as Schedule 2 names no supervisory body for it

Supervising compliance is "a core function" of every supervisory body (section 45). The PA describes itself as "responsible for the AML/CFT supervision of banks, mutual banks and life insurers", through an AML/CFT division set up in 2012, and its remit includes the cross-border operations of South African banks. At 31 March 2026, 37 institutions were registered with the FIC under item 6.

The PA's toolkit:

  • Risk returns. Banks file quarterly money laundering, terrorist financing and proliferation financing risk returns through its Umoja portal, under PA Directive D4/2022. They are mandatory.
  • Inspections. On-site AML/CFT inspections: 13 at local banks and 5 at banks' cross-border subsidiaries in 2025/26.
  • Remediation directives under section 43A, with quarterly progress reports.
  • Thematic reviews. In 2025/26 these covered wire-transfer information and the effectiveness of sanctions screening.

The reports a bank files

ReportSectionTriggerDeadline
Cash threshold report (CTR)28Cash above R49,999.99 paid to or received from a client3 days
Suspicious or unusual transaction or activity report (STR or SAR)29Knowledge or suspicion, any amountAs soon as possible, no later than 15 days
Terrorist property report (TPR)28AHolding property linked to terrorist activity, or a listed person's property5 days
International funds transfer report (IFTR)31A cross-border electronic transfer above R19,999.993 days

"Days" exclude Saturdays, Sundays and public holidays. All four go to the FIC through goAML. Since 1 July 2026 the Regulations require them in the FIC's format through its portal or another method it provides.

How the IFTR works (Guidance Note 9):

  • Who files. Only institutions authorised to move money across the border: authorised dealers (the banks), authorised dealers with limited authority, certain financial services providers, and the Postbank.
  • When. A transfer becomes reportable when the value reaches the beneficiary.
  • The amount. The test uses the amount that crosses the border, excluding fees, with no aggregation. Transfers within the Common Monetary Area count.
  • Format. Each direction is a separate report, and unrelated reports can be batched up to 500.
  • Rejections. A rejected report must be fixed within the same three days.
  • One transaction, three reports. The FIC's own example has one transaction producing an IFTR, a CTR and an STR.

The IFTR duty started on 1 February 2023, and the PA began checking it in inspections late that year.

Missed a report? FIC Directive 3A (31 March 2025) requires an institution that discovers it failed to file a CTR, TPR, STR or IFTR to tell the FIC in writing immediately. Doing so does not stop its supervisor from taking enforcement action.

See our guides to section 29 STRs, section 28 cash threshold reports and goAML registration with the FIC.


Directive 5: the 48-hour and 15-day clocks

Automated transaction monitoring is not mandatory: "It is not mandatory for a reporter to use an ATMS" (PCC 45). Every large bank uses one, though, and once it does, FIC Directive 5 of 2019 applies:

  • Attend to every alert within 48 hours of its generation, which PCC 45 counts as two business days.
  • The clock starts at the alert. "The reporter is deemed to have knowledge of the possible suspicious and unusual activity when an alert is generated by the ATMS".
  • File within 15 days of the alert. The 48 hours sit inside that period.
  • Board oversight. The board or senior management reviews and approves the system's effectiveness at least once a year.

This is where banks most often fail. The PA's December 2025 banking sector risk assessment reports these inspection findings:

  • deficient monitoring rules at 18 banks;
  • inadequate alert investigation at 14;
  • late STRs at 14;
  • missed 48-hour reviews at 10.

Directive 5 failures appear in the sanctions on Nedbank, Grindrod, African Bank, Bank of China, State Bank of India, HSBC, Capitec, Standard Bank, Absa and Discovery Bank.


Wire transfers, correspondents and cross-border operations

  • Wire-transfer data. The Reserve Bank's Directive 1 of 2022 sets the originator and beneficiary information that ordering, intermediary and beneficiary institutions must carry. Cross-border transfers under R10,000 carry a minimum data set that need not be verified unless there is a suspicion. Inward transfers under R10,000 from jurisdictions the FATF lists as high-risk or monitored must be verified. Each institution sends an annual compliance declaration by 31 March.
  • Correspondent banking. PA Guidance Note G7/2022 sets the due diligence expected for cross-border correspondent relationships.
  • Crypto asset service providers. PA Guidance Note G10/2022 tells banks to risk-assess them rather than terminate the relationships wholesale.
  • Foreign branches and subsidiaries. The RMCP must say how it is implemented in the bank's foreign branches and subsidiaries, and how group-wide programmes work (section 42(2)(q) and (qA)).

The RMCP and the board

Every accountable institution must have an RMCP (section 42), and the board must ensure compliance with the Act and the programme (section 42A). Guidance Note 7B (3 August 2026), issued with National Treasury, the Reserve Bank and the FSCA, uses a bank to make the point: "The board of directors of Bank K must approve the RMCP, the board cannot delegate its obligations in terms of the FIC Act." A committee can advise, but cannot approve. The PA does not approve RMCPs itself.

The PA's 2026 "flavour-of-the-year" topic for banks is the effectiveness of AML/CFT/CPF controls:

  • Who presents. A non-executive board member, in a presentation of about 45 minutes at the prudential meeting.
  • When. The deck goes to the PA at least three weeks before the meeting.
  • What it shows. Five years of evidence, covering transaction monitoring, correspondent banking, wire transfers, politically exposed persons, high-risk countries and cross-border subsidiaries.

What PA inspections find

The PA's Communication 1 of 2025 reported 53 findings at 9 banks in 2022/23 and 70 findings at 11 banks in 2023/24. Examples:

  • a sanctions-screening system that did not alert on deliberately altered names from the UN 1267 list;
  • cash threshold reports that did not match the goAML schema;
  • IFTR compliance reviewed in 8 of the 11 inspections in 2023/24.

The December 2025 banking sector risk assessment. It covers 2022 to 2024. Inherent money laundering risk is high for large, medium and small domestic banks, and residual risk is medium-high: the sector's residual risk "remains elevated". The control areas needing work:

  • governance;
  • business risk assessments;
  • customer due diligence;
  • beneficial ownership verification;
  • transaction monitoring;
  • training;
  • reporting.

Banks filed 76% of all STRs and about 89% of all CTRs, but 32% of CTR submissions failed, mostly for missing SWIFT codes, ID numbers or fund types.


PA sanctions on banks, 2022–2026

BankDatePenalty (suspended part)Main failings named by the PA
Nedbank12 Aug 2022R35m (R15m)Unreported cash transactions, Directive 5 and STR timing, RMCP, records
Grindrod Bank8 Dec 2023R10.73m (R5m)RMCP, due diligence, Directive 5 monitoring rules
African Bank8 Dec 2023R19.75m (R9.25m)CTRs, alerts closed late, late STRs, compliance officer's access to the board
Bank of China, Johannesburg7 Jun 2024R30.5m (R15.25m)Due diligence, late STRs, Directive 5
State Bank of India, South Africa2 Aug 2024R10m (R4.5m)Due diligence, CTRs, ineffective monitoring rules
HSBC, Johannesburg4 Oct 2024R9.5m (R4m)Beneficial ownership, 48-hour alerts
Bidvest Bank4 Oct 2024R5m (R2.5m)RMCP not applied to trade-based transactions
Capitec20 Dec 2024R56.25m (R10.5m)Due diligence, late CTRs and STRs, 48-hour alerts
Standard Bank24 Jan 2025R13m17,259 late STRs/SARs; 75,729 alerts not attended to within 48 hours
Absa25 Apr 2025R10mDue diligence on politically exposed persons, 8,559 alerts not attended to within 48 hours
Bank of Taiwan, South Africa20 Jun 2025Caution and reprimandRMCP, correspondent (vostro) due diligence
Citibank, South Africa20 Jun 2025R6m (fully suspended)RMCP not applied to advance payments
HBZ Bank20 Jun 2025R9m (R1.5m)Due diligence on medium- and high-risk files, trade finance
Discovery Bank7 Nov 2025R3m (R1m)Late STRs, new staff not trained within 30 days, 2,281 late alerts
Capitec11 Sep 2026R28m (R5.5m)Due diligence, training, terrorist property and sanctions procedures
Albaraka Bank11 Sep 2026R1.6m (R440,000)232 late CTRs, 144 late STRs, RMCP

By our count from the PA's releases, these 16 decisions imposed R247.33 million, of which R80.44 million was suspended. Several releases state that the bank was not found to have been involved in money laundering: the sanctions are for compliance failures. Penalties go to the National Revenue Fund, decisions must be published, and an institution can appeal to the FIC Act appeal board within 30 days. In July 2025 the appeal board set aside a separate R2 million due-diligence sanction on Albaraka's trade-finance files.

The Act allows financial penalties of up to R50 million for a legal person (section 45C), and part of a sanction can be suspended for up to five years.


After the grey list

The FATF put South Africa under increased monitoring on 24 February 2023 and removed it on 24 October 2025, after 22 action items, some of them on the PA's sanctioning and remediation. The next joint FATF and regional evaluation runs from June 2026 to October 2027.

The 2021 evaluation said the larger banks understood their risks and met reporting obligations "to a large extent". It also said the PA's penalties "have not always been proportionate or dissuasive". Expect examiners to test effectiveness, not paperwork: the same direction as the PA's 2026 board presentations. A draft General Laws Amendment Bill, 2026 had not been enacted at the time of the FIC's 2025/26 annual report.


Compliance checklist

  1. Confirm every Schedule 1 item your group needs to register under, and keep goAML registrations current.
  2. Tune monitoring rules to your products and keep evidence that every alert is attended to within 48 hours and closed or reported within 15 days.
  3. Reconcile cash and cross-border flows to CTRs and IFTRs, and fix rejected reports inside the 3-day window.
  4. Validate CTRs against the goAML schema before submission; the PA has found reports that did not match it.
  5. Test sanctions screening against altered names, and screen all cross-border payments before release.
  6. Apply the RMCP to trade finance, advance payments and correspondent relationships, and to foreign branches and subsidiaries.
  7. Have the board approve the RMCP and the monitoring system's effectiveness review, and prepare a non-executive director to present the evidence.
  8. File the PA's quarterly risk returns on time.

Frequently asked questions

What are the FICA requirements for banks in South Africa?

Register with the FIC, run a board-approved RMCP, identify and verify clients and their beneficial owners, screen for sanctions and politically exposed persons, and keep records for at least five years. Banks also file cash threshold reports above R49,999.99 within 3 days, STRs within 15 days, terrorist property reports within 5 days and international funds transfer reports above R19,999.99 within 3 days.

Who supervises banks for FICA compliance?

The Prudential Authority at the South African Reserve Bank, for banks, mutual banks and co-operative banks. The FIC supervises the Postbank.

What is FIC Directive 5 of 2019?

The FIC's directive for institutions that use automated transaction monitoring. Alerts must be attended to within 48 hours, the institution is treated as knowing of a possible suspicion from the moment the alert is generated, and the STR is due within 15 days of the alert.

What is the international funds transfer report threshold?

R19,999.99: cross-border electronic transfers above that amount are reported to the FIC within 3 days, by authorised dealers, authorised dealers with limited authority, certain financial services providers and the Postbank. The duty started on 1 February 2023.

What fines has the Prudential Authority imposed on banks?

From August 2022 to September 2026 the PA published 16 sanction decisions against banks. The largest were Capitec (R56.25 million in December 2024 and R28 million in September 2026), Nedbank (R35 million) and Bank of China's Johannesburg branch (R30.5 million).


See how Creodata's FICA compliance and AML software handles monitoring alerts, screening and FIC reporting for banks: book a demo.

More guides for South Africa

See AML Compliance Software in action.