The Financial Intelligence Centre Act (FICA) was introduced to fight related financial crime, such as money laundering, tax evasion, and terrorist related activities by making it more difficult for criminals to benefit from the proceeds of crime. The Financial Intelligence Centre Act (FICA) brings South Africa closer to international standards and best practices recommended by the Financial Action Task Force (FATF).
Accountable Institutions are required to register with the Financial Intelligence Centre (FIC) within 90 days of starting operations. Registration can take place on the FIC’s goAML online system which can be accessed via the FIC’s website.
The highest authority (e.g. Board) of an Accountable Institution need to formally appoint in writing a Compliance Officer to assist them with discharging their duties under FICA. The person appointed must have the competence, independence and seniority to ensure the effectiveness of the Accountable Institution’s compliance function.
Accountable Institutions are required to apply a risk-based approach when developing controls to measure, mitigate and manage their AML/CFT/PF related risks, and fulfil the FICA requirements. All the controls developed and implemented should be documented to form part of their risk management and compliance programme (RMCP). The RMCP should be reviewed at least annually and continuously updated (where necessary) to ensure that they are effective and sufficient.
An important part of mitigating risk to your business is performing customer due diligence. Customer due diligence refers to the process of verifying the identity of your client and analysing information about them to assess the potential risk they present.
This does not end at simply collecting and analysing documentation but it should also include:
• Verifying the identity of an individual or the registration of a legal person and their address or location through supporting documents and/or data
A client should be monitored throughout their relationship with you to ensure the information you have about them is up to date, so you can constantly monitor potential risk, and to assess whether any of their transactions or activity may be suspicious.
Accountable Institutions are obligated to report any suspicious behaviour or transactions, cash transactions above R49,999 and terrorist related property to the FIC.
To offer you further guidance we have put together a handy guide to identifying and reporting suspicious behaviours and transactions. In the guide, we unpack each of the above reporting duties set out in Part 3 of the FICAA.
FICA requires Accountable Institutions to keep records of not only the due diligence that was carried out, but also details of any transactions that took place - including any counter-parties to those transactions. This is to ensure that evidence is available should the FIC or the authorities require it for an investigation or a prosecution.
These must be kept for a minimum of five years from the later of either; when a client last transacts, when they cease being a client, when a report about them is submitted to the FIC or an active investigation is closed. The key here is to keep records for at least 5 years. It can be in paper or electronic form - it doesn’t matter as long as it is kept securely, safely, in confidence and is accessible by the FICA Compliance Officer.
According to section 43 of the FICA Accountable Institutions must provide training before an employee starts their role, and on an ongoing basis. The training should cover the AML/CFT/PF relevant to the employees with the purpose of complying with the provisions set out by FICAA and the processes within their internal RMCP. View our available FICA trainings here.
Directive 6,7 & 11: Serve to inform certain Accountable Institutions that they must submit information regarding their understanding of money laundering, terrorist financing and proliferation financing risks on their business as well as details of their clientbase through a risk and compliance return. Read more about this here.
Directive 8: Requires Accountable Institutions to screen prospective employees and current employees for competence and integrity, as well as to scrutinise employee information against the Targeted Financial Sanctions lists, in order to identify, assess, monitor, mitigate and manage the risk of money laundering, terrorist financing and proliferation financing from inside the business. Here is a summary of what is required for this directive. Here is a summary of what is required for Directive 8.
Directive 12: To annually submit the Company’s effective RMCP on the FIC’s GoAML platform. Read more here.
These are just a few of the key obligations, and as you can see there are several requirements that need to be met in order to be fully FICA compliant.
It is important to remember that all these requirements are set out for a reason and ultimately serve to minimise the risk of money laundering and reduce the risk of your business working with criminals.
Speak to us today and let us ease your FICA work load.
**The above are general obligations that apply to all most AIs, from time to time the FIC release Directives that are applicable to only some AI's and as such, may not be mentioned above. An example of this is Directive 9: Travel Rule Relating to Crypto Asset Transfers.