FICA pressure turns CDD into a make-or-break test

CDD

Customer due diligence (CDD) in South Africa has grown from a basic know your customer (KYC) exercise into one of the most demanding parts of the anti-money laundering (AML) process.

According to RelyComply, the quality of CDD now shapes how well firms detect financial crime and how successful later investigations are. As regulations multiply and the number of accountable institutions expands, legacy approaches are struggling to satisfy increasingly demanding supervisors.

CDD usually works in three tiers. Simplified due diligence (SDD) is a light-touch check for low-risk customers, focused on quick identity verification and onboarding. Standard CDD goes further, assessing a customer’s identity, intentions and nature of business. Enhanced due diligence (EDD) is reserved for high-risk customers. It examines sources of funds, transaction history, beneficial ownership and adverse media, and it requires senior management sign-off.

The Financial Intelligence Centre Act (FICA), overseen by the Financial Intelligence Centre (FIC), sets out who must carry out CDD. Its list of accountable institutions now reaches beyond traditional financial services to include FinTechs, insurers, estate agents and legal entities.

The pressure has intensified since South Africa left the Financial Action Task Force (FATF) greylist last year. The country’s credibility, its appeal to foreign investors and public trust in its financial sector now depend on rigorous AML standards being applied consistently.

Oversight sits within the country’s Twin Peaks model. The Financial Sector Conduct Authority (FSCA) handles conduct risk, while the Prudential Authority protects financial stability. Both are working towards consolidating financial sector law under the Conduct of Financial Institutions (COFI) Bill.

Regulators accept that CDD must be proportionate to each institution’s scale, which places responsibility firmly on compliance teams. Core activities include biometric identity verification, identifying beneficial owners holding 5% or more of a company through the CIPC’s register, and assessing the purpose of each customer relationship using financial statements, PEP and sanctions screening, and adverse media checks.

CDD cannot stop at onboarding, either. It must continue throughout the customer lifecycle, with unusual transaction behaviour triggering refreshed checks or EDD.

This is where static, manual processes fail. Paper-based checks cannot keep up with large volumes of data, and a risk rating assigned at onboarding quickly becomes outdated. Criminals exploit fragmented customer journeys that are split across channels, products and siloed teams, while rules-based monitoring overwhelms analysts with false positives.

The FIC’s growing emphasis on real-time risk detection leaves slower institutions exposed to fines and remediation. RegTech platforms offer a path forward without requiring firms to replace existing systems.

They can layer AI-powered controls onto current infrastructure to improve watchlist screening, identify anomalies and reduce time spent on low-risk alerts. Strong data governance also supports the explainable AI the FSCA expects and gives firms the end-to-end auditability that supervisors increasingly demand.

Firms that treat CDD as a continuous discipline, rather than a one-off hurdle, stand to onboard customers faster and more safely. They will also be better placed to grow in a market where criminals are moving just as quickly into digital channels.

RelyComply’s full post can be read here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.