Onboarding a new customer might look like routine business, but for compliance officers it has become one of the most scrutinised moments in the client lifecycle.
According to RelyComply, under the Financial Intelligence Centre Act (FICA), a widening pool of accountable institutions must operate robust identity verification (IDV) protocols before any business relationship can evDiscover how FICA-accountable firms can master identity verification and avoid heavy penalties. Read the full guide now.en begin.
RelyComply, a South African RegTech firm, recently put together a practical guide to staying FICA compliant around identity verification.
Digitalisation has handed launderers and fraudsters new ways to disguise who they are and mask illicit activity. In response, supervisory inspections are intensifying, and weak know your customer (KYC) controls are being actively punished rather than quietly tolerated.
FICA has been in force since 2001 and has been repeatedly modernised to keep pace with increasingly sophisticated money launderers and terrorist financiers.
Financial institutions sit on the frontline, obligated to flag high-risk activity to the Financial Intelligence Centre (FIC), the agency created to gather and analyse data indicative of financial crime in South Africa. The first line of defence is KYC: rigorous checks confirming a new client or partner is genuinely who they claim to be before any transaction takes place.
The definition of an accountable institution has expanded dramatically. The FIC’s Schedule 1 now captures both financial and non-financial businesses, spanning real estate companies, money exchanges, casinos, insurance firms, financial advisors, investment firms, payment service providers and precious metal dealerships, all supervised by the South African Reserve Bank’s Prudential Authority.
FICA’s IDV requirements operate on a risk-based footing. Clients must be verified through government-issued documentation, with ID numbers cross-referenced against national databases such as the Department of Home Affairs (DHA). FIC guidance makes clear that higher-risk clients demand stricter checks, while lower-risk entities deserve proportionate treatment, creating a tiered system that focuses enhanced due diligence where it matters and lets legitimate clients transact without delay.
No one-size-fits-all model works across every institution, however; some operate in riskier jurisdictions or face operational constraints, making tailored risk strategies, often built with RegTech providers, essential.
The consequences of getting it wrong are severe. In 2024, South Africa’s Sasfin Bank was found historically non-compliant with FICA over sanctions, with an imposed R209m penalty reduced to a still-staggering R160m.
Beyond fines, firms face reputational damage, restricted access to global banking partners and licensing risk. The FIC can levy administrative penalties of up to R50m, while directors and compliance officers can be held personally liable and, in severe cases, imprisoned.
Manual, paper-based verification remains widespread but is fundamentally unscalable, generating human error, duplicated AML and fraud workflows, and none of the real-time audit trails FIC supervisors expect.
With 79% of South African banks already acknowledging rising fraud losses, AI-driven IDV, encompassing instant document checks, liveness detection and sanctions screening within a unified AML system, is fast becoming foundational rather than optional, particularly as instant payments demand real-time verification.
To meet FICA’s expectations, accountable institutions should embed five non-negotiables: customer IDV before any first transaction, with instant data collection; risk-based due diligence with automatic escalation to enhanced due diligence (EDD) where checks fail; digital IDV measures including DHA lookups and biometric liveness detection to catch synthetic identities; automated screening against politically exposed persons (PEPs) and sanctions lists, from domestic PIP lists to the Office of Foreign Assets Control, United Nations and EU registers; and beneficial ownership checks, covering anyone controlling more than 5% of a legal entity, via the Companies and Intellectual Property Commission’s (CIPC) register, effective since 2023.
A practical checklist includes defining compliance roles, registering with the FIC, maintaining a Risk Management and Compliance Programme, applying CDD and EDD thresholds, screening watchlists and adverse media, verifying beneficial ownership, retaining records electronically for five years, training staff, and running continuous transaction monitoring with automatic risk scoring. RegTech partnerships can bring this together in a centralised platform that raises anomalous alerts instantly.
With risk controls increasingly under the microscope, a well-built IDV process delivers strong, iterative, future-proofed KYC that goes beyond baseline compliance and becomes a genuine business advantage.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





