Risk, compliance and operational policies · 03

FIC Act Risk Management and Compliance Programme

The programme every accountable institution must have, in the form the FIC Act prescribes.

What it does

The programme every accountable institution must have, in the form the FIC Act prescribes.

How it is drafted

Document the risk-based approach and the risk rating methodology; customer due diligence, including identification and verification, beneficial ownership and ongoing due diligence; enhanced measures for domestic and foreign prominent influential persons; sanctions and targeted financial sanctions screening; record-keeping; the reporting workflow for cash threshold, suspicious and terrorist property reports; the compliance officer’s appointment; training; and independent review.

What to look out for

A programme bought as a template and never operationalised is worse than none: it is documentary proof of what the institution said it would do and did not. The FIC’s inspections test the doing — the training register, the screening records, the reports actually filed — not the document.

The law it sits under

What governs this instrument.

Section 42 of the Financial Intelligence Centre Act 38 of 2001 requires an accountable institution to develop, document, maintain and implement a Risk Management and Compliance Programme reflecting its own risk. Section 29 imposes the duty to report suspicious and unusual transactions to the Financial Intelligence Centre. Schedule 1 was materially widened by the General Laws Amendment Act 22 of 2022.

Related pages, tools and documents

Where this instrument sits in the wider set, and the engagement that produces it.

Start here

Tell us the decision your organisation needs to make.

The first conversation is thirty minutes, confidential and free. You will leave it knowing which of our services you need and which you do not.