Small Business
Enterprise

How to Pass a FIC Audit: A Step-by-Step Checklist for SA Businesses

July 27, 2026 by Sam Strand

For any South African Accountable Institution, a FIC audit is a moment of truth. It is where the Financial Intelligence Centre, or another supervisory body, examines whether your business is genuinely meeting its obligations under the Financial Intelligence Centre Amendment Act (FICA). With inspection activity at record levels and administrative penalties reaching millions of rand, passing a FIC audit is not a matter of luck. It is a matter of preparation.

The good news is that the requirements are clear and the most common failures are entirely avoidable. This guide provides a practical, step-by-step checklist to help your business prepare for and pass a FIC audit.

For an explanation of the consequences of getting this wrong, refer to our guide: What Happens if You Fail a FIC Audit?

What is a FIC Audit?

The term "FIC audit" is widely used, though the process is formally known as an inspection. Under section 45B of FICA, the Financial Intelligence Centre (FIC) and supervisory bodies including the Financial Sector Conduct Authority (FSCA) and the South African Reserve Bank (SARB) conduct inspections to assess whether an Accountable Institution is complying with its FICA obligations.

Inspection activity has increased sharply. The FSCA reported a 67% year-on-year increase in on-site inspections in the 2024/25 financial year, and even though South Africa exited the FATF greylist on 24 October 2025, this scrutiny has not eased. Inspections most commonly focus on an institution's Risk Management and Compliance Programme (RMCP) and its customer due diligence practices, which is exactly where preparation should be concentrated. For an explanation of which businesses are subject to inspection, refer to our guide: What is an Accountable Institution? FICA Obligations Unpacked.

Step 1: Confirm Your Registration with the FIC

The foundation of FICA compliance is registration. Confirm that your business is registered with the FIC as an Accountable Institution, that your registration details are current, and that you have registered under the correct Schedule 1 category. The December 2022 amendments expanded the list of Accountable Institutions to include categories such as crypto asset service providers, high-value goods dealers, and credit providers, so businesses in these newer categories should confirm that their registration reflects their obligations. An unregistered institution that should be registered is exposed from the outset.

Step 2: Develop and Maintain a Customised RMCP

The Risk Management and Compliance Programme is the single most important document in a FIC audit. Over one recent period, 87% of all FICA administrative sanctions resulted from failures to develop, document, maintain, and implement an RMCP. This makes the RMCP the first thing to get right.

The critical point is that a generic, copy-and-paste RMCP will not pass scrutiny. Your RMCP must be genuinely customised to your business, reflecting the specific products, services, customers, delivery channels, and geographic factors that shape your money laundering and terrorist financing risk. It must set out how your business identifies and verifies clients, conducts due diligence, applies Enhanced Due Diligence to higher-risk clients, monitors transactions, keeps records, and reports to the FIC. The FIC has explicitly urged businesses to focus on their actual risks rather than on generic paperwork, so your RMCP should read as a document written for your business and no other. It should also be reviewed and updated regularly, and the current guidance governing the RMCP is set out in the FIC's Guidance Note 7A, which took effect on 13 February 2025.

Step 3: Verify You Are Conducting Proper Customer Due Diligence

Customer due diligence failures are among the most common findings in FIC inspections. Confirm that your business verifies the identity of every client before establishing a business relationship, in line with FICA Section 21. This includes verifying identity against reliable, independent sources such as the Department of Home Affairs records, and verifying residential address and contact details. For detailed guidance, refer to our guides: What is Identity Verification (IDV) and Why Does it Matter? and How to Verify Physical Addresses and Contact Details in South Africa for KYC.

For business customers, confirm that you are verifying the entity and identifying its beneficial owners. South African regulation now requires beneficial ownership identification down to a 5% ownership threshold, following the FIC's Public Compliance Communication 59. For a full walkthrough, refer to our guide: How to Verify Businesses and Entities in South Africa for KYC.

Step 4: Confirm Your PEP, Sanctions, and Screening Processes

Confirm that your business screens clients against the relevant risk indicators. This includes checking whether a client is a Politically Exposed Person, whether they appear on the Targeted Financial Sanctions list derived from United Nations Security Council resolutions, and whether they feature in adverse media. Sanctions screening should take place not only at onboarding but whenever new sanctions measures are adopted, which can happen at any time. For a detailed explanation of these screening components, refer to our guide: What is AML Screening? PEP, Sanctions & Adverse Media Explained.

Where screening identifies a higher-risk client, confirm that your business applies Enhanced Due Diligence, including establishing source of funds and source of wealth and obtaining senior management approval. For detailed guidance, refer to our guide: How to Conduct Enhanced Due Diligence on High-Risk Clients in South Africa.

Step 5: Confirm Ongoing Monitoring is in Place

FICA compliance does not end at onboarding. Confirm that your business conducts ongoing due diligence and monitoring throughout each business relationship, re-screening customers to detect changes such as a customer being sanctioned or becoming a PEP after onboarding. Confirm that the frequency of re-screening is calibrated to risk and documented in your RMCP. For a practical approach to re-screening at scale, refer to our guide: How to Ensure Re-screening Compliance with Bulk Services.

Step 6: Verify Your Reporting Obligations Are Being Met

Confirm that your business is meeting its reporting obligations to the FIC. This includes submitting Cash Threshold Reports for cash transactions exceeding R49,999, and Suspicious Transaction Reports where suspicious activity is identified. Reporting must be timely, and late or missed reporting is a common inspection finding. Confirm that your business has a clear, documented process for identifying and submitting reportable transactions, and that responsible staff understand it.

Step 7: Confirm Your Record-Keeping is Complete

FICA requires Accountable Institutions to retain customer due diligence records for at least five years from the end of a business relationship or the conclusion of a transaction. Confirm that your business retains not only the documents and data collected, but also the results of every verification and screening check, in a complete and retrievable format. A record that contains submitted documents but not the corresponding verification results is incomplete from an audit perspective. A complete, well-organised audit trail is one of the most effective ways to demonstrate compliance during an inspection.

Step 8: Confirm Your Compliance Officer and Staff Training

Confirm that your business has appointed a compliance officer responsible for FICA compliance, and that this appointment is documented. Confirm also that your staff receive regular training on their FICA obligations and your business's compliance procedures. Training failures feature in a significant proportion of FICA sanctions, so evidence of regular, documented training is important. Inspectors will expect to see that the people responsible for compliance understand their obligations and that training is an ongoing practice rather than a one-time event.

Step 9: Conduct an Internal Compliance Review Before the Audit

Before a FIC audit, conduct an internal review to test your own compliance against each of the steps above. Treat it as a mock inspection: examine a sample of customer files to confirm that identity verification, screening, and due diligence were properly conducted and documented, check that your RMCP is current and customised, confirm that reporting and record-keeping are complete, and verify that training records are up to date. Identifying and fixing gaps before an inspection is far preferable to having them identified by an inspector.

It is worth noting that remediating a gap after it has been identified by the FIC does not erase the underlying contravention, though recent case law confirms that remedial steps are considered when determining a proportionate penalty. This is a further reason to identify and close gaps proactively rather than waiting for an inspection to surface them.

Step 10: Consider Automating Your Compliance

Because FICA obligations apply continuously and across every customer, manual compliance is difficult to sustain consistently and is prone to the gaps that inspections uncover. Automating identity verification, screening, ongoing monitoring, and record-keeping delivers the consistency that manual processes struggle to achieve, and it generates the complete, timestamped audit trail that inspectors expect to see. For a comparison of the two approaches, refer to our guide: Manual vs Automated FICA Compliance: Which is Right for Your Business?

Your FIC Audit Preparation Checklist at a Glance

To prepare for a FIC audit, confirm that your business is registered with the FIC under the correct category, has a customised and current RMCP, conducts and documents proper customer due diligence including beneficial ownership identification, screens clients for PEP, sanctions, and adverse media risk, applies Enhanced Due Diligence where warranted, conducts ongoing monitoring, meets its reporting obligations, keeps complete records for at least five years, has an appointed compliance officer and a documented training programme, and has tested its own compliance through an internal review. A business that can answer yes to each of these is well positioned to pass a FIC audit.

FICA Compliance Solutions for South African Businesses

As South Africa's leading provider of world-class identity verification, KYC, AML screening, and due diligence solutions, ThisIsMe gives Accountable Institutions the tools they need to meet their FICA obligations consistently and to maintain the audit-ready records that inspections demand. From identity verification and beneficial ownership identification to AML and sanctions screening, ongoing monitoring, and bulk re-screening, our solutions help businesses build compliance that stands up to FIC scrutiny. To experience our full suite of FICA compliance solutions and find out how we can serve your business, contact our team here.