At the recent Fighting Financial Crime Conference, held in June 2026, one session had the whole room reaching for their notepads. Thilomi Govender, Financial Crime Compliance Manager at nCino KYC Africa, took to the stage for one of the conference's most anticipated sessions: a fireside chat with Adv. Pieter Smit, Executive Manager: Legal and Policy of the Financial Intelligence Centre (FIC).
Based on questions directly submitted by attendees, below is a look into some of the engaging and thoughtful conversation that took place.
For Adv. Smit, the answer came down to one sector. "The FIC's real focus is improving the level of compliance in the non-financial sector," he said. Compliance in this space remains a genuine problem, which is why the FIC's energy right now is going into understanding it better: where to concentrate resources, how to read the risks across different industries, and how to engage with those businesses as directly as possible.
Adv. Smit didn't mince words about what "good" looks like from a regulatory perspective. Compliance, he said, is a tool to control an outcome, not a paperwork exercise. You need to be able to identify when something is happening in your institution, be able to report it, and if you go back in your records, find the information about the customer that was collected over time.
What the FIC is not looking for is compliance where all the boxes are ticked, but nothing happens or gets reported.
"Compliance can look perfect. But if it doesn't actually mean something in terms of identifying, seeing when something suspicious is happening, being able to report it - the compliance itself doesn't achieve much," he said.
One misunderstanding that’s preferent in most institutions is that compliance is only the compliance officer’s problem. And that it’s good enough to just have a RMCP in place. Adv Smit highlighted that compliance needs to be part of the institutions' culture and as previously mentioned cannot just be a tick box exercise.
Unsurprisingly, Ultimate Beneficial Owners (UBO) also came up, and Adv. Smit noted that the reason for this is that very often this is hard work, and people try to cut corners and end up with poor information. Adv Smit highlighted that that where it is difficult to identify beneficial owners, you need to ask: "Why is my customer making it so difficult?”.
Adv. Pieter Smit emphasised that an inspection should be understood as a fact-finding exercise, not an attempt to catch institutions out. During the inspection itself, the inspector engages live with the institution's compliance and may offer comments and recommendations. These are useful, but not authoritative or final.
Once the inspection is complete, the inspector's report is reviewed by an independent team within the FIC, which assesses whether non-compliance occurred. This team then puts forward a recommendation to a third, equally independent body within the FIC, an adjudication panel. The panel considers whether it agrees with the facts, whether those facts constitute non-compliance, and how serious that non-compliance is in order to determine an appropriate penalty.
The factors weighed in this process are set out in the FIC Act itself, and include:
The circumstances that led to the non-compliance eg for instance, how long it persisted
What remedial steps the institution has taken
The broader impact the non-compliance has had on the system
For example, an institution might see a failure to identify a Beneficial Owner as minor, especially if everything else was done correctly. But viewed in the wider context, these kinds of gaps can significantly undermine the FIC's ability to generate the intelligence investigators rely on. That's precisely why something that looks like a small, technical oversight can have a disproportionately large impact.
Adv. Pieter Smit noted that the FIC is genuinely excited about this development. Looking ahead, face-to-face interactions in business are expected to become far less common, a shift enabled by advances in the digital space. The digital identification document opens up new, more secure ways for institutions to conduct business. Importantly, it's far harder to forge a digital identity than it is to forge a physical smart ID card, meaning this shift moves the industry into a considerably more secure environment.
Asked how the regulator is responding to AI-enabled crime, Adv. Smit was candid that the supervisory expectation hasn't changed, understand your risk, but the risk itself has changed.
In terms of international standards, we have to demonstrate that our understanding of new technologies keeps pace with the way things are rolled out. Understand what risks these bring and what the downstream effects will be on compliance functions within the institutions.
Some of the areas of concern, he said, isn't money laundering directly, the predicate offence environment is a major impact factor that AI has for massive fraud scams. “We see multinational fraud scams happening which are enabled and generated through AI agents," where a single scammer can effectively multiply themselves. That money goes into financial institutions, and that is the risk understanding that the FIC wants institutions to be aware of.
The only way to identify the victims is through reporting, often complicated by victims being too embarrassed to come forward and report it themselves.
A General Laws Amendment Bill currently before Parliament will introduce discrepancy reporting requirements tied to the Companies Act,which, as Adv. Smit explained, is something accountable institutions have been asking for: access to the beneficial ownership register itself. "That's the fundamental principle that I think we've now established and has generally been accepted," he said. It's not FIC-owned, and it's not fast but the legislative groundwork is being laid.
South Africa’s government policy is that we apply sanctions from multilateral bodies, in this case the United Nations Security Council. As a rule, we do not apply sanctions that emanate from other jurisdictions, in other words unilateral sanctions, because it's difficult to know what the political motive behind such a sanction may be in any given instance.
Adv Smit stated “That said, when another jurisdiction imposes sanctions on entities or individuals operating in South Africa, we still want to understand the reasoning and background behind that action. It could point to affiliations with organised crime syndicates, which is valuable risk information to have. This is why we maintain partnerships with institutions such as SAMLIT”
As if the questions answered above were not juicy enough, Thilomi then gave attendees at the conference to further ask any burning questions they had. The questions resulted in interesting discussion about banks and compliance culture within banks as well as the FICs view on the need for FICA still being carried out in complex situations such as betting at the Durban July.
Missed this discussion, be sure to join us next year where you will be able to actively get involved in compliance related conversations!
Our Fighting Financial Crime Conference was full of engaging and thoughtful conversations and discussions. Throughout the day we heard several experts discuss various topics relating to the financial crime landscape and it was great to hear straight from the regulator about what they see happening in the industry and why they are enforcing certain regulations.
Adv. Smit closed on the bigger picture: South Africa is in the FATF mutual evaluation process, and the private sector has a very big part to play in that process. "The proof of the eating is in the pudding," he said - meaning every accountable institution's compliance is, in effect, evidence for the system as a whole.
Missed FFC26? Explore more speaker sessions, highlights, and takeaways here.