For any South African Accountable Institution, few prospects are as unsettling as failing a FIC audit. The Financial Intelligence Centre has significantly intensified its enforcement activity, and the financial penalties for non-compliance can reach millions of rand. Understanding exactly what happens when a business fails a FIC audit, and what the consequences are, is essential for anyone responsible for compliance.
This guide explains what a FIC audit involves, what happens if you fail one, the range of sanctions that can be imposed, and how businesses can avoid falling short.
What is a FIC Audit?
The term "FIC audit" is widely used, but the process is formally known as an inspection. Under section 45B of the Financial Intelligence Centre Amendment Act (FICA), the Financial Intelligence Centre (FIC) and other supervisory bodies, including the Financial Sector Conduct Authority (FSCA) and the South African Reserve Bank (SARB), conduct inspections to assess whether an Accountable Institution is complying with its obligations under FICA.
The scale of this activity has grown sharply. As part of South Africa's response to its FATF greylisting, the FSCA reported a 67% year-on-year increase in on-site inspections in the 2024/25 financial year, and its AML/CFT supervisory staff grew by 257% between 2022 and 2024. Even though South Africa was removed from the FATF greylist on 24 October 2025, this heightened level of scrutiny has not eased, and inspections remain frequent and rigorous. For an explanation of which businesses are subject to these obligations, refer to our guide: What is an Accountable Institution? FICA Obligations Unpacked.
What Does the FIC Inspection Process Look Like?
Understanding the inspection process helps clarify where and how a business can "fail." The process typically follows a structured sequence.
It begins with a notice of inspection sent to the Accountable Institution. The inspection is then conducted, either on-site or through a review of submitted documentation, focusing most commonly on the institution's Risk Management and Compliance Programme (RMCP) and its customer due diligence practices. The findings are set out in an inspection report, and the institution is given an opportunity to comment on the report and to remediate the deficiencies identified.
If the institution remains non-compliant, the supervisory body issues a notice of intention to sanction, setting out the findings and the proposed sanction. If the institution does not accept the sanction or the findings on which it is based, it may pursue the appeal process provided for in section 45D of FICA, with appeals adjudicated by an appeal board established under section 45E. "Failing" a FIC audit, in practical terms, means being found non-compliant to the point where the process advances to a sanction.
What Happens if You Fail: The Range of Sanctions
If an Accountable Institution is found to have contravened FICA, the FIC or supervisory body may impose an administrative sanction under section 45C. These sanctions are not limited to financial penalties, and they range in severity.
The available sanctions include a caution not to repeat the non-compliant conduct, a reprimand, a directive to take remedial action, a restriction or suspension of certain specified business activities, and a financial penalty. Financial penalties can reach up to R10 million for a natural person and up to R50 million for a legal person, such as a company.
In practice, the size of the penalty varies enormously with the seriousness of the non-compliance. Between April 2024 and April 2025, the FIC imposed financial penalties ranging from R20,000 to R7.8 million, primarily for failures identified during inspections. Larger institutions have faced substantially higher penalties. Standard Bank was fined R13 million by the SARB for failures including inadequate ongoing due diligence and late reporting, and Capitec Bank was fined R56.25 million in December 2024. These figures illustrate that the consequences of failing a FIC audit scale with the size of the institution and the extent of the non-compliance.
How Does the FIC Decide the Penalty?
The penalty imposed is not arbitrary. Section 45C(2) of FICA sets out the factors that must be weighed in determining an appropriate sanction, including the nature, duration, seriousness, and extent of the non-compliance, together with any aggravating and mitigating circumstances.
An important point that many businesses misunderstand is that fault is not a requirement for a sanction. As the FIC Appeal Board has confirmed, the transgression itself is the statutory jurisdictional fact, meaning that an institution can be sanctioned for non-compliance regardless of whether it intended to breach the law or was merely negligent. The FIC applies internal sanctioning guidelines to promote proportionality between the penalty and the extent of the non-compliance, and the courts have confirmed that these guidelines are designed to achieve exactly that proportionality.
Can You Avoid a Sanction by Fixing the Problem Afterwards?
One of the most common misconceptions is the belief that remediating a compliance failure after it has been identified will avoid a sanction. This is not the case. In the FIC Appeal Board matter of Capital Point Properties, it was established that the rectification of a transgression does not mean it was not a transgression, and it can still be subject to a sanction. Compliance professionals often summarise this principle bluntly: there is no such thing as retrospective compliance. If a business failed to verify a client's identity at onboarding, it cannot create that verification after the fact.
There is, however, an important nuance that has been clarified by recent case law. In a Gauteng High Court judgment handed down on 25 March 2026, the court upheld an appeal by Len Dekker Attorneys Incorporated and found that remedial steps taken after a finding of non-compliance must be considered when determining an appropriate and proportionate penalty. The same judgment also limited the FIC's ability to calculate penalties for periods before it held lawful supervisory authority over the institution. The practical takeaway is that while remediation will not erase a transgression or guarantee escape from a sanction, it remains relevant and can reduce the size of the penalty. Fixing the problem still matters, but it is far better not to have the problem in the first place.
The Most Common Reasons Businesses Fail FIC Audits
The reasons businesses fail FIC audits are remarkably consistent, and understanding them is the key to avoiding the same fate.
By far the most common failure relates to the RMCP. Over one recent period, 87% of all FICA administrative sanctions resulted from failures to develop, document, maintain, and implement an RMCP. In many cases, either no RMCP existed at all, or the RMCP was a generic, copy-and-paste document that had not been customised to the institution's actual business operations. An RMCP cannot be filed and forgotten. It must be tailored to the business and reviewed regularly.
Customer due diligence failures are the second major category, including failures to properly identify and verify clients, to identify beneficial owners in line with FIC guidance, and to identify Politically Exposed Persons. For guidance on these obligations, refer to our guide: What is AML Screening? PEP, Sanctions & Adverse Media Explained. Inadequate ongoing due diligence is a related and frequent finding, where institutions verify clients at onboarding but fail to monitor them thereafter. For a practical approach to this obligation, refer to our guide: How to Ensure Re-screening Compliance with Bulk Services.
Training failures are another leading cause, featuring in a significant proportion of sanctions, as are failures to screen clients against the Targeted Financial Sanctions list and failures to report cash threshold and suspicious transactions to the FIC on time.
Beyond the Fine: The Wider Consequences
The financial penalty is often only part of the cost of failing a FIC audit. Administrative sanctions are generally publicised by the FIC or supervisory body, which means a sanction becomes a matter of public record. The resulting reputational damage can affect client relationships, banking partnerships, and commercial standing well beyond the value of the fine itself.
A sanction can also restrict or suspend certain business activities, directly affecting a business's ability to operate. In the most serious cases, FICA also provides for criminal liability, which is separate from the administrative sanctions regime and can carry far more severe penalties for the gravest offences.
It is also critical to understand that FICA accountability cannot be outsourced. Even where a business uses external compliance providers or verification technology, ultimate responsibility remains with the Accountable Institution, and specifically with its board, senior management, or highest authority. Using a compliance provider strengthens a business's position, but it does not transfer the legal responsibility away from the institution.
How to Avoid Failing a FIC Audit
The good news is that the most common causes of FIC audit failures are entirely preventable. The foundation is a properly customised RMCP that reflects the specific risks of your business, is genuinely implemented in practice, and is reviewed and updated regularly. Around this, a business should conduct thorough customer due diligence at onboarding, including identity verification, beneficial ownership identification, and PEP and sanctions screening, and should maintain ongoing monitoring throughout each relationship. For higher-risk clients, Enhanced Due Diligence should be applied. For a detailed guide, refer to our guide: How to Conduct Enhanced Due Diligence on High-Risk Clients in South Africa.
Staff training, thorough record-keeping, and timely reporting to the FIC complete the picture. Because these obligations apply continuously and at scale, automation is one of the most effective ways to ensure consistent compliance and to generate the complete audit trail that inspectors expect to see. For a comparison of the two approaches, refer to our guide: Manual vs Automated FICA Compliance: Which is Right for Your Business?
FICA Compliance Solutions for South African Businesses
As South Africa's leading provider of world-class identity verification, KYC, AML screening, and due diligence solutions, ThisIsMe gives Accountable Institutions the tools they need to meet their FICA obligations consistently and to maintain the audit-ready records that inspections demand. From identity verification and beneficial ownership identification to AML and sanctions screening, ongoing monitoring, and bulk re-screening, our solutions help businesses build compliance that stands up to FIC scrutiny. To experience our full suite of FICA compliance solutions and find out how we can serve your business, contact our team here.

