FIC compliance guide

FICA Compliance: how to get FIC compliant

A practical South African guide for businesses that need to move from concern to a working compliance file: FIC registration, RMCP, CDD, AML/PEP, sanctions, ongoing due diligence, reporting triggers and the VerifyNow reports that support each step.

FICA compliance South Africa

Build a FICA process your team can run every day.

Map customer due diligence, identity checks, AML screening, records and reporting into a practical South African compliance workflow.

  • CDD workflow
  • RMCP support
  • Verification reports
View service details+

Important distinction

VerifyNow gives you verification reports and audit evidence. Your RMCP, accountable-institution status, customer risk rating and reporting decisions determine whether your business is compliant.

See the Standard KYC Bundle
Step-by-step

What FICA compliance usually requires

Not every business is an accountable institution, and not every customer needs the same checks. Use the official FIC guidance and your RMCP to decide the final control set.

01

Confirm accountable-institution status

Check whether your business and workflow are listed in Schedule 1 of the FIC Act or otherwise regulated. If yes, you need a formal FICA programme, not only identity reports.

03

Document your RMCP

The RMCP sets out how your business identifies customers, verifies information, applies risk ratings, keeps records, screens risk and reports suspicious activity.

04

Run CDD and keep report evidence

Identify and verify natural persons, companies, directors or representatives before onboarding or transacting. Higher-risk customers need enhanced due diligence. After onboarding, FICA ongoing due diligence keeps the customer file current.

Report mapping

Which check supports which FICA step

Natural-person CDD

You need to identify and verify a South African individual.

Evidence it gives you

Verified identity fields, Home Affairs photo and transaction reference.

Stronger onboarding file

You want one report combining identity confirmation and supporting trace context.

VerifyNow check

Standard KYC Bundle

Evidence it gives you

Home Affairs ID + Photo with Consumer/Person Trace Lite fields where available.

Remote person assurance

A customer signs up remotely or you need to bind a person to the ID record.

VerifyNow check

Face Match

Evidence it gives you

Selfie-to-reference match result and confidence score.

Company or representative CDD

The customer is a company, supplier, agency, developer or business counterparty.

Evidence it gives you

Company registration status, details and director context.

Bank account control

Deposits, refunds, debit orders, payouts or settlements are part of the workflow.

Evidence it gives you

Account-found, account-open, ID/company match and account capability indicators.

AML, PEP and sanctions risk

Your RMCP, customer risk rating or transaction facts require screening or EDD.

Evidence it gives you

Sanctions, PEP, watchlist and adverse-risk matches for review.

Customer-book AML review

Your accountable-institution duties or RMCP require many customers or entities to be screened together.

VerifyNow check

Batch AML Screening

Evidence it gives you

Validated upload, batch history, consolidated CSV outcomes and detailed report links for potential matches.

Ongoing due diligence (ODD)

An identified customer stays in the relationship and your RMCP requires later AML, CDD and sanctions screens.

VerifyNow check

VerifyNow AML

Evidence it gives you

Licensed API enrolment, rescreens on your RMCP cadence, and withdrawal when the relationship ends.

Document evidence

A passport, ID document, licence or uploaded file is part of the customer file.

VerifyNow check

Document Verification

Evidence it gives you

Document authentication, OCR and tamper signals where supported.

Sample reports

See the reports that support your file

These are sample reports from the same report surfaces users see in the dashboard. They show the evidence a reviewer can attach to a CDD, KYB, bank-verification or AML/PEP review.

Loading sample report

By industry

Start with your sector

Industry pages translate the same FICA and fraud-prevention controls into the reports each team usually needs.

FAQ

FICA compliance questions

How do VerifyNow reports support FIC compliance?

VerifyNow reports provide evidence for the CDD, AML/PEP, bank-verification or KYB file. A complete FIC compliance programme also covers accountable-institution registration where applicable, the RMCP, risk ratings, record keeping, monitoring and reporting decisions.

When should I use the Standard KYC Bundle?

Use the Standard KYC Bundle when you need a stronger onboarding record in one result. It combines Home Affairs ID + Photo with Consumer/Person Trace Lite context where available, which is useful for CDD and fraud-prevention workflows.

Is AML/PEP screening always required?

Targeted financial sanctions and PEP-related obligations are part of FICA risk controls for accountable institutions. The exact timing and depth of screening should follow your RMCP, customer risk rating and current FIC guidance.

When should an accountable institution use Batch AML?

Use Batch AML when your RMCP or a risk-based review calls for many people or entities to be screened together. The service supports the screening record, while your institution remains responsible for review frequency, match decisions, monitoring and reporting.

How does ongoing due diligence fit after CDD?

FICA customer due diligence includes identifying the client, verifying identity, and conducting ongoing due diligence while the relationship continues. VerifyNow AML enrols identified customers through the licensed API, then rescreens them against refreshed sanctions and PEP lists on your RMCP cadence. One-shot AML/PEP and Batch AML remain available for onboarding and book reviews.

Where do I file suspicious transaction reports?

FIC reports are filed through goAML where a reporting duty is triggered. VerifyNow helps with verification evidence, but it does not file suspicious activity, cash threshold or other statutory reports on your behalf.

What is an RCR and what if we received a FIC notice?

RCR stands for Risk and Compliance Return. If your company received a FIC notice, check your goAML message board, confirm the affected Org ID and Schedule 1 item, then use the FIC notice and RCR deadline guide to gather RMCP, CDD, KYB and reporting evidence before responding through official FIC channels.

Build your first CDD file

Use the toolkit to define the workflow, then run the checks that match your customer, entity and risk profile.