Customer due diligence (CDD) has grown from a simple know your customer (KYC) exercise into one of the most demanding parts of the anti-money laundering (AML) process in South Africa.
According to RelyComply, the quality of CDD at onboarding now shapes how well institutions detect financial crime and investigate it later. As both the number of accountable institutions and the volume of regulation keep growing, traditional ways of assessing customers are no longer enough to satisfy supervisors.
CDD works on three tiers. Simplified due diligence (SDD) is a light-touch identity check for low-risk customers, designed to onboard them quickly. Standard CDD goes further, assessing a customer’s identity, intentions and the nature of their business.
Enhanced due diligence (EDD) is reserved for high-risk customers and examines source of funds, transaction history, beneficial ownership and adverse media, with final sign-off required from senior management.
In South Africa, the Financial Intelligence Centre Act (FICA) sets out who must carry out CDD. The list of accountable institutions now extends well beyond traditional financial services to include FinTechs, insurers, estate agents and legal entities.
The pressure has intensified since the country exited the FATF greylist last year, as its standing on the global compliance stage now depends on consistently robust AML controls across the ecosystem.
Oversight sits within the country’s Twin Peaks model. The Financial Sector Conduct Authority (FSCA) handles conduct risk, while the Prudential Authority safeguards financial stability. Both are working towards consolidating financial sector legislation under the Conduct of Financial Institutions (COFI) Bill.
Effective CDD relies on several pillars: identity verification using FICA documentation and biometrics such as facial recognition and liveness checks, beneficial ownership checks identifying anyone controlling 5% or more of a company through the CIPC register, and a clear understanding of each business relationship through financial statements, source of funds and PEP and sanctions screening.
Crucially, CDD cannot be a one-off event. Static, manual processes fail to reflect changing customer circumstances, and criminals exploit the gaps created when a customer’s journey is split across channels, products and siloed teams. Rules-based monitoring also floods under-resourced compliance staff with false positives.
With the FIC expecting real-time risk detection, institutions relying on legacy systems face fines and remediation. Unified RegTech platforms can augment existing infrastructure with AI-powered screening and anomaly detection, triggering refreshed CDD when behaviour changes. Explainable AI and full auditability are also essential to meet FSCA expectations.
Treated as a continuous discipline rather than a point-in-time hurdle, CDD becomes a genuine business enabler, supporting fast, safe onboarding and helping South Africa stay ahead of increasingly digital financial crime.
RelyComply’s full post can be read here.
Copyright © 2026 FinTech Global









