VerifyNow compliance guide

South African AML/CFT Compliance Checklist

Work through the controls that sit behind a South African AML/CFT programme. The checklist covers FICA and Revised Guidance Note 7A, with a focused section for businesses that fall within Directive 9.
Updated 31 July 2026Based on official FIC sources

Start with scope

Build the file your team can work from

FICA places duties on accountable institutions listed in Schedule 1. The practical work begins with your business risk, then moves into client checks, ongoing monitoring, reporting and evidence.

This page was checked against current FIC material on 31 July 2026. Sector rules and supervisory directions may add detail, so your approved RMCP remains the working authority inside the business.

Scope and ownership

Confirm the category that brings the business into Schedule 1. Record who owns each control and keep the organisation’s goAML details current.

Institution setup

Accountability

FIC overview of accountable-institution duties

Risk framework and RMCP

Section 42 requires an accountable institution to maintain an RMCP. Revised Guidance Note 7A describes a programme that starts with the risks faced by the institution and carries those risks through its controls and testing.

01

Business exposure

Assess the institution, its sector and the way its services could be abused.

02

Client risk

Set a method that considers customer type, ownership, geography and behaviour.

03

Control design

Connect each material risk to CDD, screening, monitoring, reporting and records.

04

Control testing

Review whether controls work in practice and update the programme when risks change.

RMCP file check

Client onboarding and due diligence

Client checks should follow the risk assigned under the RMCP. Capture why the relationship exists, who controls it and which evidence supports the decision.

Natural persons

Companies, trusts and partnerships

Screening and ongoing monitoring

Onboarding produces a starting view of the client. Monitoring keeps that view current as ownership, public roles, sanctions exposure and transaction behaviour change.

Screening controls

Ongoing monitoring

A screening result still needs a decision

Revised Guidance Note 7A places responsibility for the control with the accountable institution. Record the evidence reviewed, the match decision, the risk response and the name of the reviewer.

Open the FIC sanctions resource

Escalation and reporting

Staff need a route from an internal concern to a documented reporting decision. Regulatory reports are filed through goAML, using the stream and timing that applies to the event.

ReportTriggerTiming
STR or SARA transaction or activity gives rise to knowledge or suspicion under section 29.As soon as possible, within 15 days excluding Saturdays, Sundays and public holidays.
TPRThe institution holds or controls property connected to terrorism, terrorist activity or a person or entity named in targeted financial sanctions.Without delay and within five days of becoming aware.
CTRQualifying cash received or paid exceeds R49 999.99.As soon as possible and within three business days of becoming aware.
IFTRA qualifying cross-border electronic funds transfer exceeds R19 999.99.For covered institutions, within three business days of the value being given.

Internal case handling

goAML evidence

Records, review and staff training

Records need to show what the business knew, which control it applied and why it reached the decision. The FIC reference guide permits electronic records when they remain accessible, reproducible and available to the FIC or supervisor.

Record file

People and review

Conditional control

Directive 9 for crypto-asset transfers

Directive 9 took effect on 30 April 2025. It applies to accountable institutions that transfer or receive crypto assets for or on behalf of clients. The Travel Rule requires prescribed originator and beneficiary information to accompany covered transfers.

Confirm the transfer role

Record whether the institution sends, receives or intermediates the crypto-asset transfer.

Capture party information

Collect the prescribed originator and beneficiary information for the covered transfer.

Assess the counterparty

Apply the RMCP controls for the other service provider, hosted wallet or unhosted-wallet scenario.

Keep transfer evidence

Retain the transmitted information, screening results, exceptions and review trail.

Read Directive 9

Where VerifyNow fits

VerifyNow supplies verification and screening evidence that can sit inside the controls described in your RMCP. Your compliance team owns the client risk rating, approval decision, monitoring rules and regulatory reports.

Identity and photo checks

Verify South African identity details and retrieve the available Home Affairs photo result for the client file.

View identity verification

Company and director checks

Use CIPC Company Match and Director Search results when checking legal-person details and related people.

View company verification

AML, PEP and sanctions screening

Screen people or entities and keep the returned result for review, escalation and ongoing-monitoring workflows.

View AML screening

Bank account verification

Check account details where the RMCP uses bank ownership or account evidence in onboarding and payment controls.

View bank verification

Official sources

Use the source documents when writing or updating the business RMCP. The FIC publishes sector guidance and notices that may add controls for a specific accountable institution.

AML/CFT checklist questions

Who should use this AML/CFT checklist?

It is written for South African accountable institutions that fall within Schedule 1 of the FIC Act. Each institution should adapt the controls to its sector, clients, products, delivery channels and risk exposure.

Which version of Guidance Note 7A applies?

The Financial Intelligence Centre published Revised Guidance Note 7A on 1 September 2025. It replaced the February 2025 Guidance Note 7A and the earlier Guidance Note 7.

Who must follow Directive 9?

Directive 9 applies to accountable institutions that engage in crypto-asset transfers for or on behalf of clients. Its Travel Rule requirements took effect on 30 April 2025.

Where can VerifyNow support the process?

VerifyNow provides identity, company, director, bank-account, document, face-match and AML, PEP and sanctions checks. Your compliance team uses the returned evidence within its own RMCP, risk decisions, monitoring and goAML reporting process.