Sept 30, 2026

Redrawing the Financial Crime Battlefield

nCino KYC Webinar-Redrawing the Financial Crime Battlefield
nCino KYC Africa hosted "Fact vs Fiction: Redrawing the Financial Crime Battlefield," a webinar hosted by Tertia Barrett, Area Vice President at nCino KYC Africa, and guest speaker Rianné Potgieter, CEO of the International Federation of Compliance Associations (IFCA). 

New technology as well as Artificial Intelligence (AI) are changing the financial crime landscape, creating new opportunities but also new risks for businesses to navigate. 

Fact Check: AI and Financial Crime 

With the ever-changing threats presented by technology, fighting financial crime is becoming increasingly complex. These forces are redrawing the financial crime battlefield for Accountable Institutions in South Africa. 

Still think it's fictional? 

The South African Reserve Bank had to publish a public warning that criminals were using AI to clone the voice and face of Governor Lesetja Kganyago to push South Africans into fake investment platforms. 

INTERPOL's African Cyberthreat Assessment Report 2026 links AI to more than 55 percent of cybercrime on the continent, and losses have gone from 192 million dollars to 484 million dollars in a single year. South Africa carries the heaviest load of any country in Africa. 

The digital ecosystem we work in is changing faster than any of us anticipated. The question is whether we, as a profession, are keeping up. 

Decide for Yourself: Fact or Fiction? 

  • An AI is generating identity documents convincing enough to onboard clients right now, undetected. 

  • Your Risk Management and Compliance Programme was written for the AI risks we face today. 

  • If my business does not touch crypto, then crypto risk is not my risk. 

  • Criminals are stealing encrypted data right now that nobody can read yet, and storing it, because they expect to be able to unlock it in about ten years. This might be closer than you think! Read more about how quantum computing shifts cyber security into a new era.  

These aren't hypothetical scenarios. They were the starting point for a wider conversation with Potgieter about where the real risks now sit. The conversation was framed around three main themes.

1. The financial crime battlefield has changed 

What can a criminal do this year that wasn't possible two or three years ago?

From an AML perspective, it's important to note that it's not just the person who can be imitated. A criminal can now manufacture the whole story.

AI, Potgieter explained, can now build an entire ecosystem around a false identity: "They can generate a whole ecosystem around that identity that says here are the transactions, here's the person, here's the address," all of it engineered to look coherent under a normal review. Institutions that used to chase clients for documents are now getting everything back almost instantly, which feels like progress until something else surfaces days later that doesn't add up.

That shifts what a red flag looks like. Traditional red flags remain relevant, but the new warning signs increasingly sit between separate pieces of information.

No single signal proves wrongdoing. Suspicion develops when several signals converge.

When the documents themselves are flawless, the tell moves elsewhere. Test the coherence of the whole story. Contradictions between where documents originate and where payments come from, unrelated parties transacting from different addresses that quietly funnel back to the same beneficiary, and a kind of unnatural polish, these are the new signals to watch.

As humans, we could probably not look across 1,000 transactions and see the patterns. But with AI doing it for you, you can spot that one beneficiary is receiving sub-transactions from multiple different addresses, and so on.

2. Are our frameworks fit for purpose?

The answer was measured rather than alarmist. Regulators, including the FIC, have largely moved toward principles-based, outcomes-focused regulation, and that holds up reasonably well because it asks institutions to understand their client relationships rather than tick a fixed list of boxes.

The vulnerability lies in implementation. An RMCP copied from a template, an annual risk assessment, visual inspection of client-supplied documents, or a checklist completed only at onboarding may no longer address the institution's actual exposure.

The framework may still be fit for purpose. Our assumptions, evidence and implementation may not be.

3. The role of the risk-based approach

The same logic applies to the risk-based approach. It was built on an assumption that risk holds still long enough to measure it, assess it periodically, report to the board, and move on. It doesn't hold still anymore. A customer can look low-risk on day one and shift entirely months later, well after the last scheduled review.

Sample testing runs into the same wall. It was built for a world where testing everything simply wasn't feasible. What institutions need now is something closer to a continuous engine, AI or otherwise, flagging risk as it happens rather than on a quarterly cycle. For smaller accountable institutions processing a handful of transactions a month, that doesn't mean building large-institution tooling; it means making sure every single transaction gets a properly done manual check.

The key line: You do not need bank-grade artificial intelligence. You need disciplined processes, reliable verification, and the courage to stop when the story no longer makes sense.

The compliance officer's own capability

Deep expertise in FICA, AML and the institution's sector remains necessary. The danger arises when that expertise becomes the only lens through which every problem is viewed. It now needs to sit alongside a horizontal awareness of what's happening in AI, cybersecurity, data and digital assets.

Potgieter said the ability to ask good questions, the kind of questions that will get you deeper into the detail, is what matters most. Her advice was blunt: don't be afraid to ask something obvious. "Be the idiot in the room," she said, "ask the questions until you understand." A meaningful human in the loop can see the evidence, challenge the machine's recommendation, identify missing information, override the conclusion, and remain accountable for the decision.

Her answer to the final question of the session, on the one thing everyone should remember, was simpler than any framework: "Be open-minded, and be open to learning. That's probably the biggest thing."

The takeaway

The world has changed, even if you cannot yet see the change in your immediate surroundings. Use the time before it reaches you wisely.

As technology evolves, staying ahead means knowing what to trust, where the risks lie, and when to question what you’re seeing. The right technology and processes can help you strengthen your compliance approach while preparing for what’s coming next. Want to see how nCino KYC can help? Reach out to our team. 

About the author:

nCino KYC

nCino KYC is Powering a new era in FICA compliance. Seamless KYC onboarding, real-time watchlist screening, and unlimited expert advice — built specifically for South African accountable institutions.