Resources

Compliance Glossary

A plain-language compliance glossary: the screening, due diligence and FICA terms South African compliance teams work with every day.

Legislation & Regulators

The rules and who enforces them

The legal framework South African compliance obligations flow from.

FICA Financial Intelligence Centre Act

South Africa's primary anti-money laundering law (Act 38 of 2001). FICA requires designated businesses, called accountable institutions, to identify and verify their clients, assess and manage money laundering risk, keep records, monitor business relationships and report suspicious activity to the Financial Intelligence Centre.

Check your FICA readiness →

FIC Financial Intelligence Centre

The national body that administers FICA. The FIC receives regulatory reports from accountable institutions, produces financial intelligence for investigators, issues guidance and directives, and can impose administrative sanctions on institutions that fail to comply.

AML / CFT

Anti-money laundering and countering the financing of terrorism: the umbrella term for the laws, controls and processes that stop criminal funds moving through the financial system. FICA is South Africa's AML/CFT framework; the FATF sets the international standard it follows.

FATF Financial Action Task Force

The intergovernmental body that sets global AML/CFT standards through its 40 Recommendations, and assesses countries against them in mutual evaluations. FATF guidance also shapes screening practice, including how adverse media should inform customer risk assessment.

FATF grey list

The FATF's list of jurisdictions under increased monitoring for weaknesses in their AML/CFT regimes. South Africa was placed on the list in February 2023 and removed in October 2025 after completing its action plan. Greylisting raises the cost and friction of cross-border business, which is why regulators inspect screening controls more closely during and after it.

POPIA Protection of Personal Information Act

South Africa's data protection law. Screening involves processing personal information, so POPIA governs how screening data is collected, stored, secured and retained. FICA compliance and POPIA compliance have to be designed together, not traded off against each other.

goAML

The FIC's online platform for registration and regulatory reporting. Accountable institutions register on goAML and use it to file the reports FICA requires, including suspicious and unusual transaction reports.

People & Entities

Who screening looks at

The categories of people and organisations that carry defined obligations or elevated risk.

Accountable institution

A business designated in Schedule 1 of FICA and therefore bound by its obligations. The schedule covers banks, financial services providers, credit providers, life insurers, legal practitioners, trust and company service providers, estate agents, high-value goods dealers and more.

Are you an accountable institution? →

PEP Politically Exposed Person

Someone who holds or has held a prominent public function, and who therefore carries a higher risk of involvement in bribery, corruption or the misuse of public funds. PEP status is not an accusation; it triggers enhanced due diligence, senior approval and closer monitoring rather than automatic rejection.

PEP screening and monitoring →

DPIP Domestic Prominent Influential Person

South Africa's domestic PEP category under FICA: senior figures in government, state-owned enterprises, political parties, the judiciary and large companies doing significant public-sector business. FICA sets out DPIPs and their foreign counterparts separately, but both call for enhanced scrutiny.

FPPO Foreign Prominent Public Official

The foreign counterpart to a DPIP: a person holding a prominent public function in another country, such as a head of state, senior politician, senior executive of a state-owned company, senior military officer or senior judicial official.

RCA Relatives and Close Associates

The family members and known close associates of a PEP, DPIP or FPPO. Risk and screening obligations extend to them, because illicit funds are commonly held or moved through people connected to the prominent person rather than by the person directly.

UBO Ultimate Beneficial Owner

The natural person who ultimately owns or controls a legal entity, traced through however many layers of shareholding, trusts or nominee arrangements sit in between. Identifying beneficial owners is a core FICA requirement for corporate clients, because entity structures are the standard way real ownership is hidden.

KYB and beneficial ownership →

Money laundering

Disguising the criminal origin of funds so they appear legitimate. It is classically described in three stages: placement, where cash enters the financial system; layering, where transactions obscure the trail; and integration, where the funds re-emerge as apparently clean assets.

Obligations & Processes

What accountable institutions must do

The duties FICA places on a business, and the processes that meet them.

RMCP Risk Management and Compliance Programme

The documented programme FICA requires every accountable institution to maintain. It sets out how the business identifies, assesses, monitors and mitigates its money laundering and terrorist financing risk, and it is usually the first document an inspection asks to see.

RMCP questions in the FAQ →

KYC Know Your Customer

The process of establishing and verifying who a customer is before and during a business relationship. KYC is the foundation the rest of compliance stands on: risk assessment, screening and monitoring all depend on knowing reliably who you are dealing with.

eKYC

KYC performed digitally: electronic identity verification, document collection and screening in one onboarding flow, rather than paper forms and manual checks. Done well, it verifies clients before onboarding completes and leaves an automatic evidence trail.

HLBNGA's eKYC platform →

KYB Know Your Business

Due diligence on corporate clients and counterparties: verifying that the entity exists, understanding its ownership and control structure, identifying its beneficial owners and directors, and screening all of them. KYB matters because a company's risk sits with the people behind it.

KYB screening →

CDD Customer Due Diligence

FICA's core requirement: identify the client, verify that identity against reliable sources, understand the purpose of the relationship, and keep that knowledge current. The depth of due diligence scales with risk, which is what the risk-based approach means in practice.

EDD Enhanced Due Diligence

The deeper level of due diligence applied to higher-risk clients such as PEPs, complex entity structures or high-risk jurisdictions. EDD typically adds source of funds and wealth checks, adverse media analysis, senior management approval and closer ongoing monitoring, with the reasoning documented.

AI-powered EDD with KYCopilot →

Risk-based approach

The principle, set by the FATF and built into FICA, that compliance effort should be proportionate to risk: stronger controls where risk is higher, simpler ones where it is lower. It replaces box-ticking with judgement, and it requires a documented risk assessment to stand on.

Ongoing monitoring

Re-screening and reviewing existing clients throughout the relationship, not only at onboarding. Client risk changes: people become PEPs, appear on sanctions lists or attract adverse media after they were accepted. Point-in-time checks cannot catch that; continuous or scheduled re-screening can.

Continuous monitoring with RiskSecure 360 →

Source of funds & source of wealth

Two related EDD questions. Source of funds asks where the money in this specific transaction or relationship comes from; source of wealth asks how the client accumulated their overall assets. Both are about testing whether the client's money is plausibly legitimate.

STR Suspicious Transaction Report

The report an accountable institution must file with the FIC when it knows or suspects that a transaction or activity involves the proceeds of crime or terrorist financing. Filed via goAML, and the client may not be tipped off that a report was made.

Audit trail

The retrievable record of what was checked, what was found, who decided and when. FICA requires records to be kept, and in an inspection the difference between a control that exists and a control that can be proven is the audit trail. A decision that cannot be evidenced is very hard to defend after the fact.

False positive

A screening alert on someone who is not actually the risk in question, most often a name match against a different person. High false-positive rates are the main operational cost of screening: every one consumes analyst time. Reducing them without missing true matches is the core quality measure of a screening system.

How HLBNGA reduces false positives →
Screening & Technology

The checks and the tools

The screening types FICA obligations translate into, and the technology behind them.

Sanctions screening

Checking clients and counterparties against targeted financial sanctions lists issued by bodies such as the UN Security Council. Sanctions obligations are strict rather than risk-based: they apply to every client regardless of risk rating, and a missed match is a reportable failure.

Sanctions screening and monitoring →

TFS Targeted Financial Sanctions

Sanctions aimed at specific listed persons and entities rather than whole countries: asset freezes and prohibitions on making funds available to them. Under FICA, accountable institutions must screen against the relevant lists and report matches without delay.

Watchlist

Any curated list used in screening: sanctions lists, PEP databases, law-enforcement wanted lists, regulatory enforcement lists or internal restricted lists. Watchlists are indispensable but always lag reality, which is why adverse media screening exists alongside them.

Adverse media screening

Screening news and other public sources for negative information about a client: fraud, corruption, sanctions evasion, organised crime and similar signals. Adverse media typically surfaces risk long before a person or company reaches any formal watchlist, which makes it an early-warning layer in due diligence.

Adverse media screening →

COMFORT™ Score

HLBNGA's patented AI scoring technology for adverse media. It reads at sentence level rather than matching keywords, weighs the frequency, severity and credibility of negative mentions, and produces a contextually accurate 0 to 100 risk score for a person or company, with every score source-cited and carrying a full audit trail.

How COMFORT™ works →

Third-party screening

Applying screening discipline to suppliers, agents, intermediaries and other business partners, not only to clients. Third parties carry the same sanctions, corruption and reputational exposure as customers, and are usually screened to a far lower standard, which is exactly why they are a common route for risk to enter a business.

Third-party screening →

Association mapping

Identifying the people, organisations and locations linked to a screened entity, so risk that sits one step away is visible: a clean company with a sanctioned director, or a customer whose close associate is a PEP. Network context is often where the real finding is.

Association mapping in I2G →
Put the terms to work

See where your obligations stand.

Run the free FICA self-assessment, or bring your questions to a compliance specialist.