AML Compliance in South Africa: A 2026 Guide for Fintechs and Regulated Businesses

South Africa left the FATF grey list in October 2025 — here's what that does and doesn't change for AML compliance in 2026.

Share
AML Compliance in South Africa: A 2026 Guide for Fintechs and Regulated Businesses

South Africa's financial sector processes high transaction volumes across a cash-heavy economy, which keeps it a persistent target for money laundering and terrorist-financing risk. VOVE ID works with fintechs and crypto asset service providers (CASPs) to build AML compliance into onboarding and monitoring rather than treating it as a bolt-on.

This guide covers South Africa's AML reporting and screening obligations. For the underlying framework, see our AML requirements explained.

The Grey List Exit — and Why It's Not the End of the Story

The FATF grey-listed South Africa in February 2023 over gaps in beneficial-ownership transparency and enforcement. After 32 months of reform, South Africa exited the grey list on 24 October 2025. That's a real milestone, but supervisors have said plainly that delisting requires sustained results, not a one-time fix — South Africa's next FATF mutual evaluation is scheduled for the first half of 2026 through October 2027, and demonstrable investigations and prosecutions remain part of that ongoing scrutiny.

Regulatory Framework and Core Obligations

South Africa's AML/CFT regime is overseen by the Financial Intelligence Centre (FIC), the SARB Prudential Authority, and the Financial Sector Conduct Authority (FSCA), under a small set of core laws:

  • Financial Intelligence Centre Act (FICA), 2001 — customer due diligence, suspicious-transaction reporting, and risk-based compliance for accountable institutions, including banks, fintechs, CASPs, and estate agents.
  • Prevention of Organised Crime Act (POCA), 1998 — criminalizes money laundering, with penalties up to 30 years' imprisonment or R100 million in fines.
  • Protection of Constitutional Democracy Against Terrorist and Related Activities Act (POCDATARA), 2004 — counter-terrorism financing measures.

Key Compliance Requirements

Accountable institutions must:

  1. Register with the FIC via goAML within 90 days of commencing business as an accountable institution, and appoint a compliance officer.
  2. Maintain a Risk Management and Compliance Programme (RMCP) under FIC Guidance Note 7A — a living operational document, not a filed-and-forgotten policy.
  3. Conduct customer due diligence: verify identity (Smart ID, passport, proof of address), and apply the section 21B beneficial-ownership cascade — natural persons with controlling ownership first, then control through other means (PCC 59 recommends 5% ownership as an indicator worth checking, but it's not a safe harbor; the underlying test is control, not a fixed percentage) — plus enhanced due diligence for PEPs and higher-risk clients.
  4. Monitor transactions and file suspicious transaction reports (STRs) as soon as possible and no later than 15 business days after the suspicion arises, plus cash threshold reports (CTRs) for physical cash of R50,000 or more within three business days, and international funds transfer reports (IFTRs) for qualifying cross-border transfers of R20,000 or more within three business days, where the institution is in scope for IFTR reporting.
  5. Retain records for at least five years.

Supervisory Bodies

The FIC leads AML/CFT enforcement and intelligence-sharing; the SARB Prudential Authority regulates banks, insurers, and remittance services; the FSCA oversees non-bank entities including fintechs and CASPs.

Fintech and Crypto: The Travel Rule

FIC Directive 9 requires in-scope CASPs to implement the FATF Travel Rule for crypto asset transfers, effective 30 April 2025. Any transaction value above zero qualifies within a business relationship — the reduced-information treatment applies only to qualifying single transactions below R5,000, not an exemption from the rule altogether.

For a broader look at crypto and VASP obligations across the region, see our crypto and VASP regulation guide for Africa and the UAE.

KYC and eKYC for AML Programs

AML compliance depends on the identity layer underneath it. For individuals, that means Smart ID, passport, or driver's license plus proof of address; for corporates, entity documents, UBO details, and source-of-funds evidence. Higher-risk clients need enhanced due diligence, including PEP screening and periodic re-verification. Automated document authentication and biometric liveness checks reduce both fraud exposure and onboarding friction — the two problems tend to trade off against each other in manual processes.

Risks and Penalties

Non-compliance carries real consequences: FICA administrative sanctions can reach R10 million or 10% of annual turnover per violation, and POCA violations carry criminal penalties up to R100 million or 30 years' imprisonment. Failure to submit a required STR is a criminal offense in its own right. Beyond the direct penalty, weak AML controls limit access to correspondent banking relationships and international partnerships — a cost that shows up well before any enforcement action.

Compliance Checklist

Step Action
Register with the FIC Enroll via goAML; appoint a compliance officer
Build a working RMCP Document actual monitoring and escalation workflows, not aspirational ones, per FIC Guidance Note 7A
Implement KYC/eKYC Identity verification, biometric checks, and PEP/sanctions screening
Monitor transactions Calibrate detection to product type, not a single generic threshold
File reports on time STRs within 15 business days; CTRs for physical cash of R50,000 or more within 3 business days
Retain records At least 5 years
Reassess regularly Update the RMCP as products, risk exposure, and FIC guidance evolve

For the complete source-linked implementation checklist — all 7 control areas and 49 evidence prompts — see VOVE ID's South Africa compliance checklist.

Final Thoughts

AML compliance in South Africa is not a box to tick once and file away — it's a standing obligation that runs for the life of a customer relationship, and the post-grey-list environment has raised, not lowered, the operational bar.

VOVE ID helps fintechs and CASPs build identity verification, sanctions screening, and monitoring into one connected workflow.

Get in touch

This article is intended for general informational purposes only and does not constitute legal, financial, or regulatory advice. AML requirements may vary depending on jurisdiction, activity, and licensing status. For binding compliance obligations, consult the relevant regulator or a qualified professional.