Onboarding new customers might appear a routine, business-as-usual exercise, but for compliance officers it carries mounting responsibility and ever-greater scrutiny.
According to RelyComply, under South Africa’s Financial Intelligence Centre Act (FICA), a growing range of accountable institutions must maintain robust identity verification (IDV) protocols before any new business can take place.
RelyComply, a South African RegTech firm, recently put together a practical guide to staying FICA compliant around identity verification.
Criminals are thriving in an era of accelerated digitalisation, using it to conceal their identities and illicit activity. As a result, supervisory inspections are intensifying, and lax know your customer (KYC) checks will not be tolerated – they will be actively punished.
FICA’s aims
FICA has been in force since 2001 and has been continually updated to reflect the obligations placed on modern institutions to detect and investigate financial crime. Money launderers and terrorist financiers are becoming more ingenious and harder to identify, leaving financial institutions on the frontline of reporting high-risk activity.
This draws banks and FinTechs into partnership with the Financial Intelligence Centre, the agency created to collect and analyse data indicative of financial crime and ultimately reduce it across South Africa. Prevention begins with KYC: stringent verification measures to confirm that any new client or partner is genuinely who they claim to be, before a business relationship or transaction can even commence.
What counts as an accountable institution?
The net of institutions facing supervisory action has widened dramatically. Under the FIC’s Schedule 1, it captures both financial and non-financial businesses, including real estate companies, money exchanges, casinos, insurance firms, financial advisors, investment firms, payment service providers and precious metal dealerships. These entities are supervised by the South African Reserve Bank’s Prudential Authority.
Risk-based IDV requirements
FICA’s detailed IDV requirements apply to each of these businesses. In practice, all relevant clients must be assessed and cleared through the collection of verified government-issued documents, with ID numbers and other credentials cross-referenced against national databases, including the Department of Home Affairs (DHA).
The FIC’s guidance makes clear that institutions must balance IDV accuracy with sustained effort proportionate to risk. Higher-risk clients warrant stricter checks, while lower-risk entities should receive proportionate treatment. This tiered system prioritises further due diligence where necessary while allowing legitimate clients to begin transacting without delay.
That said, a one-size-fits-all IDV approach cannot work across multiple institutions. Some operate in riskier jurisdictions or sectors, or face material operational hurdles, such as smaller firms with limited resources. Tailored IDV means mapping a comprehensive, business-specific risk management strategy, often with the support of regulatory technology (RegTech) providers.
Penalties for non-compliance
The industry is littered with cautionary tales of poorly handled AML, and drastic enforcement shows no sign of slowing when weak risk controls can enable organised crime. In 2024, South Africa’s Sasfin Bank was found to have historically breached FICA in relation to sanctions, with an imposed R209m penalty reduced to a still-staggering R160m.
That single fine is only one potential consequence, sitting alongside near-irredeemable reputational damage, restricted access to global banking partners and licensing risk – all traceable to negligent IDV. The FIC can impose administrative penalties of up to R50m, while directors or compliance officers can be held personally liable and, in severe cases, face imprisonment.
Unscalable manual verification
While a cultural shift is essential to improving IDV, it must run in parallel with growing automation to verify identities around the clock. The global rise of instant payment systems demands real-time verification; eKYC methods such as biometric recognition will soon underpin any credible IDV strategy, however distant that may feel for some firms today. Already, 79% of South African banks have acknowledged rising fraud losses – a threat that will exploit ongoing operational shortcomings.
Manual, paper-based verification – still widely practised – creates a stream of problems, from human error to duplicated work across AML and fraud workflows, and a lack of the tracked, real-time audit trails FIC supervisors require. AI-driven IDV, by contrast, moves beyond a box-ticking DHA obligation and becomes fundamental to curbing increasingly sophisticated fraud, provided it forms part of a unified system joining up typically fragmented AML functions such as authenticated instant document checks, liveness detection and sanctions screening.
Five FICA compliance non-negotiables
To meet FICA’s IDV expectations and move beyond periodic KYC checks, institutions should embed the following steps when onboarding clients, partners, vendors and third parties – all actionable within a frictionless, end-to-end AML system serving as a single source of truth for entity data.
- Customer IDV before first transaction – Initial KYC checks should be the first step of due diligence. Data collection must be instant, covering proof of identity, addresses and company documents where necessary, so digital IDV can proceed without holding up legitimate entities.
- Risk-based due diligence – Customer due diligence (CDD) should be standard, with risky activity flagged via user-controlled thresholds. Entities that fail or evade standard checks should be automatically escalated for enhanced due diligence (EDD), governed by documented policies covering enhanced source-of-wealth checks, senior management approval and ongoing monitoring.
- Digital IDV measures – Customers should undergo holistic authentication, including DHA lookups against official government records and biometric liveness checks capable of distinguishing synthetic identities from genuine ones via facial or fingerprint recognition.
- PEPs and sanctions screening – Constantly updated global watchlists for politically exposed persons (PEPs) and sanctioned individuals should be consulted automatically. Domestic South African “PIP lists” and sanctions lists, such as the Office of Foreign Assets Control, should be checked alongside global registers including the United Nations and the EU sanctions tracker.
- Beneficial ownership – Solutions must capture details of beneficial owners, defined as anyone owning or controlling more than 5% of a legal entity. The Companies and Intellectual Property Commission (CIPC) made its Beneficial Ownership Register effective in 2023, requiring registered businesses to submit their information.
A step-by-step FICA IDV checklist
To get ahead, all financial and non-financial businesses should take a modular approach – defining existing processes, identifying IDV gaps and making the changes FICA’s stricter gaze demands:
- Outline compliance team roles, including compliance officers and MLROs
- Register with the FIC
- Create and maintain a Risk Management and Compliance Programme (RMCP)
- Establish protocols for initial customer ID verification
- Apply risk-based CDD processes and EDD thresholds for high-risk clients
- Screen against PEPs, sanctions lists and trusted adverse media sources
- Check beneficial ownership information via the CIPC
- Retain records electronically for five years
- Deliver thorough staff AML training covering FICA rules, IDV methodologies and risk definitions
- Implement continuous transaction monitoring to detect behavioural changes
- Resolve entity profiles with automatic risk-scoring updates
For this formalised IDV stage to serve as the intrinsic first KYC step of a fully automated AML platform, FICA-accountable businesses should look to RegTech partnerships. A bespoke risk management system, spanning onboarding through to continuous monitoring and reporting, can be built around a business’s operational needs and limitations, assessing different risk classes in a centralised platform that instantly raises anomalous alerts.
Financial institutions’ risk controls will only come under greater scrutiny. A well-established IDV process supports strong, iterative and future-proofed KYC, moving beyond baseline compliance to become a genuine business advantage.
Copyright © 2026 FinTech Global



