The Financial Intelligence Centre Act 38 of 2001 (FICA) is the cornerstone of South Africa's anti-money laundering (AML) and counter-terrorism financing (CTF) framework. For attorneys, FICA compliance is not optional — every firm that handles client money, transfers property, establishes companies or trusts, or manages client affairs is an "accountable institution" under FICA, with statutory obligations.
The 2022 amendments to FICA (which came into full effect in 2023) added significant new requirements — most notably the beneficial ownership disclosure obligation. Non-compliance carries severe penalties: administrative fines up to R10 million, criminal prosecution, and reputational damage that can end a firm. This guide walks through what every SA attorney must do, step by step.
Why attorneys are accountable institutions under FICA
The Financial Intelligence Centre (FIC) designates attorneys as accountable institutions because law firms are gateways to the financial system. Attorneys: receive client money into trust accounts (a potential money laundering channel); transfer property (a classic vehicle for laundering large sums); establish companies and trusts (which can obscure beneficial ownership); and provide legal opinions that legitimate questionable transactions. Every one of these activities is a money laundering risk, and FICA places the compliance burden on the attorney.
This means every SA law firm must: register with the FIC; appoint a Compliance Officer; conduct Customer Due Diligence (CDD) on every client; maintain records for 5 years; report suspicious transactions (STRs); report cash transactions above R24,999.99; and conduct ongoing staff training. The obligations are continuous — not a one-time registration.
Step 1: Register with the FIC
Every accountable institution must register with the Financial Intelligence Centre via the FIC online registration portal (goFIC). Registration requires: firm name and registration number, contact details, name of the Compliance Officer, and confirmation of the firm's activities as an accountable institution. Registration is free, but mandatory — failure to register carries an administrative sanction.
Step 2: Appoint a Compliance Officer
The Compliance Officer is responsible for: overseeing the firm's FICA compliance programme; receiving and reviewing suspicious transaction reports from staff; submitting STRs to the FIC; maintaining the firm's Risk Management and Compliance Programme (RMCP); and liaising with the FIC and inspectors. The Compliance Officer should be a senior person — typically a partner or the firm's compliance manager — with sufficient authority to enforce compliance across the firm.
Step 3: Develop a Risk Management and Compliance Programme (RMCP)
Section 42 of FICA (as amended) requires every accountable institution to develop, implement, and maintain a written RMCP. The RMCP must cover: (a) the firm's approach to identifying and assessing money laundering and terrorism financing risks; (b) the CDD measures the firm will apply; (c) the record-keeping regime; (d) the suspicious transaction reporting process; (e) ongoing staff training; and (f) the internal accountability structure.
The RMCP is not a template document — it must reflect the firm's actual practice areas, client base, and risk profile. A firm specialising in conveyancing has different risks from a firm specialising in litigation. The RMCP must be reviewed annually and updated as the firm's risk profile changes.
Step 4: Conduct Customer Due Diligence (CDD) on every client
CDD is the core of FICA compliance. Before establishing a business relationship or conducting a transaction, the firm must:
4.1 Identify the client
For natural persons: full name, ID number (or passport number for foreign nationals), date of birth, residential address, contact details. Identification must be verified against an original or certified copy of an ID document, passport, or driver's licence.
For legal persons (companies, trusts, partnerships): the entity's registration details (CIPC registration number for companies, Master's reference number for trusts), registered address, and the identities of all natural persons who ultimately own or control the entity (the beneficial owners — see Step 5 below).
4.2 Verify the client's identity
Verification requires original documents or certified copies, sighted in person or via reliable electronic verification. For SA citizens: SA ID book or smart card, or passport. For foreign nationals: passport plus proof of residence. For companies: CIPC disclosure, recent share certificate, or certified CoID 14.3 (now CoID 14.3 has been replaced by the CIPC online disclosure).
4.3 Screen for PEPs (Politically Exposed Persons)
Every client must be screened against the FIC's PEP list (and international PEP databases) to identify whether they are a domestic or foreign PEP, a family member of a PEP, or a close associate of a PEP. PEPs are not automatically refused service, but they trigger Enhanced Due Diligence (EDD) — see Step 6 below.
4.4 Verify source of funds
For transactions above a defined threshold (typically R50,000, but lower for high-risk matters), the firm must verify the source of the client's funds. For a conveyancing matter: bank statements showing the buildup of funds, sale of previous property proof, salary slips for bond qualification. For litigation: proof of the source of the retainer. "Source of funds" means where the money came from; "source of wealth" (broader) means how the client acquired their overall wealth.
Step 5: Identify beneficial owners (the 2022 amendment)
The 2022 FICA amendments added a specific beneficial ownership obligation. For every legal person client (company, trust, partnership), the firm must identify and verify the natural persons who ultimately own or control the entity. For companies: any natural person who directly or indirectly owns 25% or more of the shares or voting rights, or who otherwise exercises control over the company. For trusts: the trust founder, trustees, named beneficiaries, and any person who directly or indirectly owns 25% or more of the trust assets.
This is a significant new compliance burden. For complex corporate structures (holding companies, offshore shareholders, trust-owned companies), identifying the beneficial owners can take days of work. Failure to identify beneficial owners is now a stand-alone FICA offence — the firm cannot proceed with the matter without this information.
If a client refuses to disclose beneficial ownership information, FICA requires the firm to: (a) not proceed with the business relationship or transaction; (b) consider filing a suspicious transaction report (STR) with the FIC; and (c) terminate any existing business relationship. You cannot "wait and see" — the obligation is immediate.
Step 6: Apply Enhanced Due Diligence (EDD) where required
EDD is required for higher-risk clients and transactions. EDD triggers include: PEPs (domestic or foreign), clients from high-risk jurisdictions (as listed by the FATF), complex or unusually large transactions, transactions with no apparent economic or lawful purpose, and any client where CDD has identified inconsistencies or red flags. EDD means: obtaining senior management approval to proceed, taking additional measures to verify identity and source of funds, and conducting enhanced ongoing monitoring of the relationship.
Step 7: Maintain records for 5 years
FICA Section 21 requires accountable institutions to keep all CDD records, transaction records, and internal compliance records for at least 5 years from the date of the transaction or the end of the business relationship. Records must be retrievable on demand — the FIC can request records at any time, and the firm has 7 days to produce them.
For law firms, this means: every client's FICA file (ID documents, verification evidence, PEP screening results, source of funds evidence, beneficial ownership disclosure) must be retained for 5 years after the matter closes. Paper records are acceptable but impractical at scale; electronic storage (with proper backup) is the standard.
Step 8: Report suspicious transactions (STRs)
Section 29 of FICA requires every accountable institution (and every employee of an accountable institution) to report any suspicious transaction or activity to the FIC. A "suspicious transaction" is broadly defined — any transaction where there is a suspicion of money laundering, terrorism financing, or other unlawful activity. The threshold is suspicion, not certainty. If you suspect, you report.
STRs are filed electronically via the FIC's online portal (goAML). The report must be filed "without delay" — typically interpreted as within 48 hours of forming the suspicion. Importantly, you may NOT disclose to the client that an STR has been filed (this is "tipping off" — a criminal offence under Section 40 of FICA, punishable by imprisonment of up to 5 years).
Step 9: Report cash transactions above R24,999.99
Section 28 of FICA requires accountable institutions to report any cash transaction above R24,999.99 to the FIC. "Cash" includes bank notes, coins, and traveller's cheques — but not EFTs, cheques, or credit card payments. The report is filed electronically via goAML within 2 business days of the transaction. For law firms, this is most commonly triggered when a client pays a retainer or trust deposit in cash.
Step 10: Ongoing staff training
Section 42 of FICA requires accountable institutions to provide ongoing training to all employees on FICA compliance. Training must cover: the firm's RMCP, CDD procedures, PEP screening, STR reporting, and any updates to FICA or the firm's policies. Training records must be maintained — the FIC can request evidence of training during inspections.
The cost of FICA non-compliance
FICA non-compliance penalties are escalating. The FIC has moved from "compliance assistance" to "compliance enforcement" mode in the past 3 years. Administrative fines for accountable institutions range from R50,000 to R10 million per offence. Criminal prosecution is reserved for serious or repeated non-compliance, with imprisonment of up to 15 years for individuals. Beyond statutory penalties, non-compliant firms face: loss of fidelity fund certificate (which means loss of right to practice), reputational damage, loss of banking relationships (banks will not maintain accounts for non-compliant firms), and increased professional indemnity premiums.
Software features required for FICA compliance
FICA compliance at scale requires software. The minimum features:
- •Client onboarding workflow that captures all CDD fields — natural persons and legal persons.
- •Document upload and verification tracking — ID documents, proof of address, source of funds evidence.
- •Beneficial ownership disclosure workflow — for legal person clients.
- •PEP screening integration — automatic screening against FIC and international PEP lists.
- •Risk rating automation — based on client type, jurisdiction, transaction value, and PEP status.
- •EDD workflow for high-risk clients — with senior approval capture.
- •5-year record retention with automated archival.
- •STR reporting workflow — internal capture, Compliance Officer review, FIC submission tracking.
- •Cash transaction reporting above R24,999.99.
- •Audit trail on every FICA action — who did what, when, and why.
LexPrime OS has a dedicated FICA / KYC module that handles every step: CDD capture, document verification, PEP screening, beneficial ownership disclosure, risk rating, EDD workflow, 5-year retention, and audit trail. Request demo access and we'll walk you through a sample FICA file from onboarding to ongoing monitoring.
Common FICA compliance failures
Based on FIC inspection reports, the top 5 FICA compliance failures for SA law firms are:
- 1No RMCP — the firm has never written down its compliance programme. This is the single most common finding.
- 2Incomplete CDD — client files missing ID verification, source of funds evidence, or PEP screening results.
- 3No beneficial ownership disclosure — the firm has not implemented the 2022 amendment for legal person clients.
- 4No STR reporting culture — staff do not know how to identify suspicious transactions or how to report them.
- 5Training gaps — staff cannot explain the firm's FICA procedures when asked during an inspection.
Every one of these failures is preventable with software and discipline. The firm that implements both passes any FIC inspection; the firm that does not is one inspection away from a fine and a damaged reputation.