
FICA: The Old and New Regulatory Regimes — From Legal Formality to Risk Intelligence
South Africa’s Financial Intelligence Centre Act (FIC Act or “FICA”) has long served as the foundation for combating money laundering, terrorist financing, and proliferation financing. Yet, the evolution from the old regulatory regime to the new risk-based framework represents a fundamental shift — away from procedural box-ticking and toward demonstrable, data-driven risk management.
The Old Regulatory Regime: Legalism and Compliance by Procedure
Under the old regime, compliance was primarily defined by legal interpretation and adherence to prescriptive rules. Institutions sought legal opinions to confirm compliance, produced voluminous policies, and relied on board sign-offs as evidence of adherence. The focus was often on satisfying auditors and supervisors rather than addressing the underlying risks that FICA was designed to mitigate.
While this rule-based environment created a degree of predictability, it also encouraged a compliance culture detached from operational reality. Control effectiveness was assumed rather than tested, and “compliance” too often meant paperwork, not protection. This misalignment contributed to weak due diligence, ineffective monitoring, and in some cases, the facilitation of illicit activity — not necessarily through intent, but through systems that were procedurally compliant yet substantively ineffective.
The New Regulatory Regime: Context, Judgment and Evidence
The new regulatory regime, established through the FICA amendments and expanded in Guidance Note 7A, replaces the one-size-fits-all model with a Risk-Based Approach (RBA). This approach empowers accountable institutions to design and implement a Risk Management and Compliance Programme (RMCP) under section 42 of the Act, which must be contextual to their business model, client base, delivery channels, and risk exposure.
In principle, the RBA allows flexibility — institutions can design controls suited to their operations — but in practice, it demands more skill, reasoning, and evidence. Institutions must now prove that their controls work. Risk assessment, customer due diligence (CDD), transaction monitoring, governance, and escalation processes must be interlinked and continuously evaluated. The FIC expects the RMCP to be both comprehensive and operationally effective — not merely approved on paper.
Distinct but Interrelated Risks: Compliance, ML, TF and PF
A key challenge under both regimes has been confusion between compliance risk and the substantive risks of money laundering (ML), terrorist financing (TF), and proliferation financing (PF). These are distinct yet interrelated domains:
Compliance risk arises from failing to meet legal and regulatory obligations — governance, registration, reporting, recordkeeping, or RMCP adequacy.
ML/TF/PF risk concerns the potential misuse of the institution’s products or services for illicit purposes.
Under the old regime, most regulatory action targeted compliance breaches, not criminal facilitation. Under the new regime, however, the expectation is that compliance controls must functionally mitigate ML/TF/PF risks. Institutions must now demonstrate that their controls are designed, implemented, and monitored to reduce real exposure, not just to satisfy procedural requirements.
The media’s focus on administrative fines illustrates this difference: most sanctions still relate to compliance failures — weaknesses in CDD, beneficial ownership, monitoring, or reporting — not necessarily proof of laundering. Yet this distinction cannot be used as an excuse. Institutions must accept that FICA’s purpose is preventative; their role is to enable effective law enforcement and to ensure their operations cannot be used as vehicles for financial crime.
Operationalising the Risk-Based Approach
Under the old regime, “risk appetite” was often cited as justification for tolerance — as though senior management approval for higher-risk clients absolved the institution of accountability. The new regime demands evidence that risk appetite is operationalised: that controls are measurable, applied consistently, and demonstrably effective.
This means embedding risk scoring, due diligence variation, transaction monitoring rules, and escalation procedures that align with defined risk thresholds. It also requires governance structures that ensure risk management outcomes are owned, reviewed, and improved — not left in compliance manuals. The regulator’s expectations are clear: risk must be identified, assessed, mitigated, monitored, and evidenced.
Data-Driven Assurance and Analytical Testing
Confidence in an institution’s ability to meet its FICA obligations must now be data-driven. Under the new regime, reliance on policy assertions or legal opinion is insufficient. Running analytical models and algorithms through transaction and due diligence datasets allows for empirical testing of whether controls are working.
By analysing patterns, anomalies, and behavioural data, institutions can test detection rules, validate customer risk ratings, and assess false-positive ratios in monitoring systems. This approach provides objective assurance that controls are effective — or identifies gaps where they are not. Ample Vista’s work in this space demonstrates how evidence-based testing supports continuous improvement and credible governance, providing institutions and regulators alike with substantiated confidence in control environments.
Enforcement and the Reputational Dimension
Despite the regulatory shift, many institutions continue to struggle. The pattern of repeated fines, supervisory findings, and South Africa’s greylisting demonstrates that too many have failed to internalise the RBA’s principles. Reputational risk — once the most feared consequence — has dulled in impact, largely because sanctions have become so common.
The real cost, however, is systemic: each compliance failure erodes trust in the financial system’s ability to protect itself from criminal exploitation. The regulator’s focus has therefore turned not merely to compliance documentation but to evidence of effectiveness. Institutions that cannot prove that their controls work in practice are now the ones most exposed to enforcement risk.
Ample Vista’s Approach — Turning Regulation into Measurable Outcomes
At Ample Vista, we help institutions bridge the gap between policy and practice. Our approach recognises the evolution from the old regime’s prescriptive compliance to the new regime’s performance-based risk management. We design RMCPs that integrate business context, customer profiles, and product-level risks into operational controls that are measurable and testable.
By applying data analytics to transaction and due diligence data, we substantively test whether the institution’s control environment functions as intended. This empirical assurance allows decision-makers to adjust frameworks, improve monitoring, and reinforce governance with evidence rather than opinion.
Our philosophy is simple: compliance should not be an administrative burden, but a mechanism that builds integrity and confidence. By helping institutions implement and prove effective risk management, we ensure they fulfil their regulatory obligations, support law enforcement outcomes, and protect both their reputation and the broader financial ecosystem.
