Start with scope
Build the file your team can work from
FICA places duties on accountable institutions listed in Schedule 1. The practical work begins with your business risk, then moves into client checks, ongoing monitoring, reporting and evidence.
This page was checked against current FIC material on 31 July 2026. Sector rules and supervisory directions may add detail, so your approved RMCP remains the working authority inside the business.
Scope and ownership
Confirm the category that brings the business into Schedule 1. Record who owns each control and keep the organisation’s goAML details current.
Institution setup
Accountability
Risk framework and RMCP
Section 42 requires an accountable institution to maintain an RMCP. Revised Guidance Note 7A describes a programme that starts with the risks faced by the institution and carries those risks through its controls and testing.
Business exposure
Assess the institution, its sector and the way its services could be abused.
Client risk
Set a method that considers customer type, ownership, geography and behaviour.
Control design
Connect each material risk to CDD, screening, monitoring, reporting and records.
Control testing
Review whether controls work in practice and update the programme when risks change.
RMCP file check
Client onboarding and due diligence
Client checks should follow the risk assigned under the RMCP. Capture why the relationship exists, who controls it and which evidence supports the decision.
Natural persons
Companies, trusts and partnerships
Screening and ongoing monitoring
Onboarding produces a starting view of the client. Monitoring keeps that view current as ownership, public roles, sanctions exposure and transaction behaviour change.
Screening controls
Ongoing monitoring
A screening result still needs a decision
Revised Guidance Note 7A places responsibility for the control with the accountable institution. Record the evidence reviewed, the match decision, the risk response and the name of the reviewer.
Open the FIC sanctions resourceEscalation and reporting
Staff need a route from an internal concern to a documented reporting decision. Regulatory reports are filed through goAML, using the stream and timing that applies to the event.
Internal case handling
goAML evidence
Records, review and staff training
Records need to show what the business knew, which control it applied and why it reached the decision. The FIC reference guide permits electronic records when they remain accessible, reproducible and available to the FIC or supervisor.
Record file
People and review
Conditional control
Directive 9 for crypto-asset transfers
Directive 9 took effect on 30 April 2025. It applies to accountable institutions that transfer or receive crypto assets for or on behalf of clients. The Travel Rule requires prescribed originator and beneficiary information to accompany covered transfers.
Confirm the transfer role
Record whether the institution sends, receives or intermediates the crypto-asset transfer.
Capture party information
Collect the prescribed originator and beneficiary information for the covered transfer.
Assess the counterparty
Apply the RMCP controls for the other service provider, hosted wallet or unhosted-wallet scenario.
Keep transfer evidence
Retain the transmitted information, screening results, exceptions and review trail.
Where VerifyNow fits
VerifyNow supplies verification and screening evidence that can sit inside the controls described in your RMCP. Your compliance team owns the client risk rating, approval decision, monitoring rules and regulatory reports.
Identity and photo checks
Verify South African identity details and retrieve the available Home Affairs photo result for the client file.
View identity verificationCompany and director checks
Use CIPC Company Match and Director Search results when checking legal-person details and related people.
View company verificationAML, PEP and sanctions screening
Screen people or entities and keep the returned result for review, escalation and ongoing-monitoring workflows.
View AML screeningBank account verification
Check account details where the RMCP uses bank ownership or account evidence in onboarding and payment controls.
View bank verificationOfficial sources
Use the source documents when writing or updating the business RMCP. The FIC publishes sector guidance and notices that may add controls for a specific accountable institution.
AML/CFT checklist questions
Who should use this AML/CFT checklist?
It is written for South African accountable institutions that fall within Schedule 1 of the FIC Act. Each institution should adapt the controls to its sector, clients, products, delivery channels and risk exposure.
Which version of Guidance Note 7A applies?
The Financial Intelligence Centre published Revised Guidance Note 7A on 1 September 2025. It replaced the February 2025 Guidance Note 7A and the earlier Guidance Note 7.
Who must follow Directive 9?
Directive 9 applies to accountable institutions that engage in crypto-asset transfers for or on behalf of clients. Its Travel Rule requirements took effect on 30 April 2025.
Where can VerifyNow support the process?
VerifyNow provides identity, company, director, bank-account, document, face-match and AML, PEP and sanctions checks. Your compliance team uses the returned evidence within its own RMCP, risk decisions, monitoring and goAML reporting process.