nCino KYC Articles

RMCP Compliance: What Directive 10, 12 and GN 7B Require

Written by nCino KYC | Sep 14, 2026, 12:26:22 PM
The Financial Intelligence Centre (FIC) has long held that the Risk Management and Compliance Programme (RMCP) is where compliance with the FIC Act (FICA) begins and ends. “An adequate RMCP may safeguard accountable institutions from legal entities and natural persons seeking to criminally abuse the accountable institution,” said Christopher Malan, Executive Manager for Compliance and Prevention at the FIC, in a May 2025 reminder to industry.

The RMCP is also where most accountable institutions (AIs) fall short. Either there is no RMCP, or there is one that was bought off the shelf, never tailored to the business, and never updated. Three FIC publications in the space of five weeks (Aug to Sep 2026) have made that position considerably harder to sustain: Directive 10 on geographic particulars, Guidance Note 7B on implementing the FIC Act, and Directive 12, which makes RMCP submission an annual obligation.

Here is what an RMCP actually is, and what each of these three updates now requires of you.

What is an RMCP, and who needs one?

An RMCP is the document that records every procedure your business follows to comply with the FIC Act. It sets out how you identify, mitigate and manage your money laundering, terrorist financing and proliferation financing risks, and how you know those controls are working.

Every accountable institution listed in Schedule 1 of the FIC Act must develop, document, maintain and implement an RMCP. A document that exists but is not implemented is not an RMCP, and neither is a practice that is followed but never written down.

Where RMCPs Commonly Fall Short

The FIC's own inspection findings point to the same recurring failures:

  • Failing to develop or implement an RMCP at all — described by the FIC as a widespread failure noted through FIC Act inspections.
  • No prior completed and documented business risk assessment to inform the RMCP.
  • Not adopting a risk-based approach to customer due diligence.
  • No confirmation that clients were screened against the targeted financial sanctions list.
  • Failing to file suspicious and unusual transaction reports.
  • Ongoing difficulty determining beneficial ownership and identifying politically exposed persons.

These are not hypothetical risks, and the penalties for getting this wrong are hefty. Ninety One Assurance was recently hit with administrative fine actions for failing to comply with FICA. One of the charges related to its RMCP, with the Prudential Authority noting that they failed to create and maintain a risk management programme that would allow it to properly identify, evaluate, monitor, and reduce risks related to politically exposed (high-risk) persons or their businesses. The company said it had addressed the identified issues, strengthened its controls, and remained committed to working constructively with regulators. 

Regulatory Updates

1.) Directive 10 – Geographic Particulars

Directive 10 took effect on 31 July 2026. It requires various accountable institutions to disclose detailed geographic particulars of their business to the FIC on the goAML platform. The purpose is for the FIC to understand the location of an accountable institution’s head office, its branch offices, the head office of each subsidiary, and the branch offices of those subsidiaries, whether in or outside the Republic of South Africa.

The Directive applies to legal practitioners, trust and company service providers, estate agents, licensed gambling businesses, credit providers (excluding banks), the South African Postbank, high value goods dealers, the South African Mint and crypto asset service providers.

New accountable institutions must complete this information at the time of registering with the FIC. Institutions that are already registered have 90 days from publication of the Directive, which means 31 October 2026.

We would recommend that you update goAML with your geographic particulars and, in parallel, check that all other recorded information remains accurate. Bear in mind that the footprint you declare to the FIC should be consistent with the geographies covered in your business risk assessment and RMCP. A mismatch would be an obvious question during an inspection.

2.) Guidance Note 7B – Replaces Guidance Note 7A

Guidance Note 7B was published on 3 August 2026, officially replacing Revised Guidance Note 7A with immediate effect. It sets out the FIC’s expectations for accountable institutions to implement effective measures to manage money laundering, terrorist financing and proliferation financing risks in line with the FIC Act.

  • Proliferation financing runs throughout — your programme is now an AML, CTF and CPF programme.
  • New products, services, delivery channels and developing technologies must be risk-assessed before launch.
  • Low-income clients cannot automatically be treated as lower risk.
  • An entity-wide risk assessment must come before the RMCP controls are set.
  • RMCP approval cannot be delegated — a risk or audit committee may advise, but only the board can approve.
  • Directors and senior managers can be sanctioned personally under section 61.

Accountable institutions should revisit their RMCPs, business risk assessments and due diligence procedures to ensure they reflect the changes introduced.

3.) Directive 12 – Annual RMCP Submission

Directive 12 was published on 4 September 2026, following a consultation on the draft that closed on 21 August. It requires specified accountable institutions to submit a copy of the documentation describing their RMCP to the FIC via the goAML platform on an annual basis. This is a recurring obligation, not a once-off exercise.

Legal practitioners, trust and company service providers, licensed gambling businesses and credit providers (excluding bank, mutual bank and co-operative bank credit providers) must submit by 9 October each year. Estate agents, the South African Postbank, high value goods dealers, the South African Mint and crypto asset service providers must submit by 31 October each year.

Submission on its own is not compliance. Christopher Malan, Executive Manager for Compliance and Prevention at the FIC, has cautioned accountable institutions not to equate submission of the RMCP with meeting all the requirements of a fully compliant RMCP: “RMCPs will be tested against the legislative requirements through inspections and compliance monitoring.” Non-submission, equally, is itself a contravention of the FIC Act.

We would recommend ensuring that your RMCP is up to date, board-approved, signed and dated ahead of your submission date.

In summary, it is important that a RMCP detail the manner that the company complies with the requirements – it should not just regurgitate legislation. It should talk about the when, who, how and what of the business's compliance processes. 

Need Assistance with your RMCP? 

Regulatory changes move fast. Don't wait for an inspection to find out your RMCP, and FICA related processes are out of date. With nCino KYC, you're never alone on your FICA compliance journey. We combine expert service with powerful, purpose-built software. To learn more, reach out to our team.