AML compliance software for South Africa's reporting institutions.
Sanctions and PEP screening, transaction monitoring, customer risk rating, case management and reporting to the Financial Intelligence Centre through goAML, in one analyst workspace for accountable institutions under the Financial Intelligence Centre Act (FICA).
Built for FICA and the Financial Intelligence Centre.
The Financial Intelligence Centre Act, 2001 (FICA), the Money Laundering and Terrorist Financing Control Regulations and the FIC's guidance notes set out what an accountable institution has to do, starting with a documented Risk Management and Compliance Programme (RMCP). Each duty maps to a module, so the evidence sits where an examiner will look for it.
Identify customers and rate their risk
Six-factor customer risk rating across country, industry, product, channel, behaviour and PEP/sanctions exposure, with four-eyes overrides, plus a beneficial-owner graph for legal-entity customers.
Apply enhanced due diligence to PEPs and higher-risk customers
An EDD workflow inside case management, with periodic reviews scheduled automatically by risk band so a high-risk file does not go stale.
Screen customers against sanctions lists and PEP data
Multi-script, locale-aware matching against lists synced from providers such as Dow Jones and World-Check, plus manual upload for lists you maintain yourself, with versioned lists and freshness dashboards.
Monitor transactions for suspicious activity
A rule engine running in batch and streaming, with typology-aligned starter rules, back-testing and versioned promotion, fed by REST, SFTP, Kafka, CDC or ISO 20022 connectors.
Report suspicious and cash transactions to the FIC
A draft, review, approve and submit lifecycle with acknowledgement handling. The goAML XML is generated and validated by the Creodata goAML Reporting Platform, with a manual download if the portal is down.
Keep records and show supervisors the evidence
An append-only audit log behind every decision, evidence packs for inspections, a read-only regulator portal, and an obligation registry that turns new guidance and amendments into tracked tasks.
This maps software capability to obligations; it is not legal advice. For registration and filing mechanics, see the South Africa FIC goAML reporting guide.
For South Africa's reporting institutions, whichever regulator supervises them.
Schedule 2 of the Act names the supervisory bodies, and the FIC supervises accountable institutions that have none.
Supervised by the Prudential Authority of the South African Reserve Bank.
The Reserve Bank's Financial Surveillance Department; money or value transfer providers answer to the Prudential Authority as well.
Authorised users of an exchange, collective investment scheme managers and investment FSPs answer to the Financial Sector Conduct Authority.
Accountable institutions with no supervisory body in Schedule 2, such as estate agents, gambling operators, crypto asset service providers and dealers in high-value goods, are supervised by the FIC.
Frequently asked questions.
Does the software report to the FIC?
Yes, through goAML. Suspicious and threshold transaction reports move through a draft, review, approve and submit lifecycle in the AML software, with retry, reconciliation and acknowledgement handling. The Creodata goAML Reporting Platform then generates and validates the goAML file for the FIC's portal, and a manual download is available if the portal is down.
What are the FIC's reporting deadlines?
Suspicious and unusual transaction reports (STRs, and SARs for incomplete transactions) go to the FIC as soon as possible and no later than 15 days after becoming aware of the facts, and cash threshold reports for cash above R49,999.99 no later than 3 days after becoming aware of the transaction, in both cases excluding Saturdays, Sundays and public holidays (regulation 24 of the Money Laundering and Terrorist Financing Control Regulations). Terrorist property reports cover matches to the targeted financial sanctions list or the UN 1267 list. All of them are filed on the FIC's goAML portal.
Is this FICA compliance software?
It supports the FICA duties that need systems: customer due diligence and risk rating, screening for sanctions and politically exposed persons, transaction monitoring, record keeping and reporting to the FIC through goAML, with the evidence behind each decision kept for your Risk Management and Compliance Programme. The RMCP itself is your institution's document; the software supplies the controls and the audit trail it describes.
Can the software be hosted in South Africa?
Microsoft Azure has regions in South Africa (South Africa North in Johannesburg and South Africa West in Cape Town), and the software also runs on-premises on your own Kubernetes cluster with the same features as the Azure edition. Ask us which deployment fits your data-residency requirements.
How much does AML software cost in South Africa?
There is no public price list. Each capability is licensed separately and grouped into Starter, Growth and Enterprise tiers, so a quote depends on the modules you switch on and whether you deploy on Azure or on-premises. A demo is the quickest route to a quote scoped to your institution.
Can a smaller institution start small?
Yes. The Starter tier covers screening, customer risk rating and case basics in the cloud. Growth adds transaction monitoring, STR/CTR reporting and ingestion connectors, which a deposit-taking institution will need for its monitoring and reporting duties. Modules switch on per tenant, so moving up a tier adds capability without starting again.
How long does implementation take?
It depends on how many modules you start with and how your data arrives. Screening and risk rating need customer data; transaction monitoring also needs transaction feeds, which connect over REST, SFTP, Kafka, change data capture or ISO 20022 with replay and a dead-letter queue, so a failed load is visible rather than silent. After scoping, we propose a phased path to your first production go-live.
See the AML software run on a South Africa reporting profile.
Screening, monitoring, cases and FIC reporting on a realistic alert queue, in a live demo.