A Risk Management and Compliance Programme (RMCP) is the documented programme that every Accountable Institution in South Africa is legally required to develop, document, maintain and implement under section 42 of the Financial Intelligence Centre Amendment Act (FICA). It records the money laundering, terrorist financing and proliferation financing risks that the institution faces, and sets out exactly how the institution identifies, assesses, monitors, mitigates and manages those risks.
In practical terms, the RMCP is the institution's own rulebook for compliance. FICA sets the outcomes that must be achieved. The RMCP sets the methods by which a particular business achieves them. This is why two Accountable Institutions in the same sector can lawfully apply different verification requirements to the same type of client: the Act does not prescribe a single universal process, and each institution's RMCP determines its own.
This guide explains what an RMCP must contain, who is responsible for approving it, why it sits at the foundation of every other FICA obligation, and what is changing for RMCPs in 2026.
For an explanation of which businesses are subject to these obligations, refer to our guide: What is an Accountable Institution? FICA Obligations Unpacked.
Why is the RMCP Foundational to FICA Compliance?
South Africa applies a risk-based approach to anti-money laundering regulation. Rather than imposing an identical checklist on every business, FICA requires each Accountable Institution to understand its own risk exposure and to build controls proportionate to that exposure. A small conveyancing practice and a large cross-border payments provider face very different risks, and the law expects their controls to differ accordingly.
The RMCP is the instrument through which the risk-based approach is applied. Without it, an institution has no defensible basis for deciding which clients require enhanced scrutiny, which transactions warrant investigation, or which documents are sufficient to verify an identity. Every other FICA obligation flows from it.
This is also why the RMCP is the first thing a supervisory body examines during an inspection. An inspector does not begin by asking whether a business verified a particular client. The inspector begins by asking what the RMCP says the institution will do, and then tests whether it actually did so. A business is measured against the standard it set for itself, which is why a generic programme is worse than useless: it commits the institution to a standard that does not match its business.
What Must an RMCP Contain?
Section 42 of the FIC Act sets out what the programme must address. An RMCP must contain the institutional risk assessment and policy documents, and must detail the processes, systems and controls used across the full range of FICA obligations.
Guidance Note 7A, which the FIC published on 13 February 2025 in replacement of Guidance Note 7, recommends that RMCP documentation be structured in three parts:
Part 1: Identification and assessment of risk. The institution must conduct an entity-wide risk assessment considering the nature, size, products, services, industry, client base, geographic exposure and complexity of the business. Guidance Note 7A draws a clear distinction between the business risk assessment and the client risk assessment, and makes the point that the former is broader than the latter. Assessing only client risk is not sufficient.
Part 2: Mitigation and management of identified risks. This covers the controls applied, including customer due diligence, targeted financial sanctions controls, reporting and record-keeping.
Part 3: Monitoring. The effectiveness of the controls must be continuously evaluated, updated and, where appropriate, audited.
Within those parts, the RMCP must document how the institution establishes and verifies client identity, determines beneficial ownership, identifies Politically Exposed Persons, conducts enhanced due diligence, examines unusual transactions, determines when a transaction is reportable, terminates a business relationship, keeps records, screens employees and trains staff. It must also address implementation across branches, subsidiaries and foreign operations.
Who Approves an RMCP, and How Often Must it be Reviewed?
There is a persistent misconception that an RMCP must be submitted to the Financial Intelligence Centre for approval. This is not correct, and the distinction matters.
Responsibility for approving the RMCP sits with the board of directors, or with senior management or the person holding the highest level of authority where there is no board. Guidance Note 7A is emphatic that these persons are solely responsible for the adequacy, suitability and effectiveness of the programme, and that they will be held accountable if it is found to be inadequate. This responsibility cannot be delegated.
Guidance Note 7A gives a practical example of how this fails in inspections. Where an institution updates its approved RMCP but does not obtain board approval for the revised version, that version control failure is itself a contravention by the board.
The RMCP must also be reviewed at regular intervals. Public Compliance Communication 53 recommends annual review, on the basis that money laundering, terrorist financing and proliferation financing risks change continuously.
Separately, the RMCP must be made available to the FIC or the relevant supervisory body on request, and it must be accessible to employees. In March 2025, the FIC exercised its power under section 42(4)(a) to issue a general request requiring Accountable Institutions to submit their RMCPs through the goAML platform. Availability on request is therefore not a theoretical obligation.
How Does an RMCP Connect to Everyday KYC?
An RMCP is only as good as the verification capability behind it. A programme that commits an institution to verifying identity against authoritative sources, screening every client for sanctions exposure and monitoring relationships continuously is unenforceable if the business has no practical means of doing so at the volume it operates at. This is where the RMCP stops being a policy document and becomes an operational reality.
Customer due diligence and identity verification: The RMCP must specify how identity will be established and verified. In practice this means verification against authoritative data such as the Department of Home Affairs HANIS database, rather than acceptance of a submitted document at face value. Refer to our guides: What is KYC (Know Your Customer)? and What is Identity Verification (IDV)?
Document validation: Where the RMCP relies on identity documents or passports, it should specify how authenticity is established. Machine Readable Zone validation and forensic tamper scoring detect forged and altered documents that visual inspection misses, and biometric comparison against the photograph held at Home Affairs confirms that the presenter is the document holder.
Address and contact verification: The RMCP must record the institution's standard for residential address information and the recency it requires. Refer to our guide: How to Verify Physical Addresses and Contact Details.
Business clients and beneficial ownership: Where clients are legal persons, trusts or partnerships, the RMCP must document how the ownership and control structure is established. Public Compliance Communication 59 strongly recommends identifying every natural person holding five percent or more of the ownership interest, a threshold considerably lower than the twenty-five percent standard many businesses once applied. Refer to our guides: What is KYB (Know Your Business)? and How to Verify Businesses and Entities.
Screening and risk rating: The RMCP must set out how clients are screened for Politically Exposed Person status, sanctions exposure, enforcement listings and adverse media, and how the results feed into a client risk rating. Refer to our guide: What is AML Screening?
Enhanced due diligence: The programme must define what triggers enhanced measures and what those measures involve. Refer to our guides: What is Enhanced Due Diligence (EDD)? and How to Conduct Enhanced Due Diligence on High-Risk Clients.
Ongoing due diligence: Risk status is not static. A client screened clean at onboarding may later become a Politically Exposed Person or appear on a sanctions list, and the RMCP must explain how the institution detects that. Refer to our guides: Once-Off AML Screening vs Continuous AML Monitoring: What's the Difference? and How to Ensure Re-screening Compliance with Bulk Services.
Employee screening: This obligation is frequently overlooked. Directive 8, issued on 31 March 2023 and supported by Public Compliance Communication 55, requires Accountable Institutions to screen prospective and current employees for competence and integrity and to scrutinise them against the targeted financial sanctions lists. The process must be risk-based, ongoing, and recorded in the RMCP, and the FIC recommends at least annual screening for higher-risk roles. Refer to our guide: How to Screen Employees for Criminal Records and Licences.
Record-keeping: The RMCP must document the record-keeping process. Records must currently be kept for at least five years, and crucially this covers the verification results themselves and not merely the documents a client submitted.
API Automation and Monitoring: For institutions operating at volume, automating this chain produces something a manual process cannot: a consistent, timestamped, auditable record demonstrating that the RMCP was applied to every client, every time. That evidence is precisely what an inspection tests. Refer to our guides: How to Automate KYC Compliance with an API and Manual vs Automated FICA Compliance: Which is Right for Your Business?
Why Do RMCPs Fail Inspections?
The FIC's own supervisory findings are consistent on this point. Most Accountable Institutions have an RMCP. The failures arise because the programme is a generic template rather than a customised assessment of the institution's actual risks, or because a perfectly adequate document is not implemented in practice.
Recent enforcement illustrates the pattern. In July 2026, the South African Reserve Bank imposed R600 000 in administrative sanctions on Southeast Exchange Company South Africa (Pty) Ltd, a foreign exchange dealer, following a FICA inspection. The largest single component, R200 000, was imposed in respect of section 42 alone, with further penalties for customer due diligence, ongoing due diligence, failure to appoint an anti-money laundering compliance officer and failure to train staff. The inspection found that weaknesses in the company's controls had inhibited its ability to conduct ongoing due diligence in accordance with its own RMCP and to apply the risk-based methodology set out in it.
The regulator was explicit that this was a finding of control failure, not a finding that the business had facilitated money laundering. An institution does not need to have been used for financial crime to be sanctioned. An inadequate or unimplemented RMCP is sufficient on its own.
Administrative penalties under FICA can reach R10 million for a natural person and R50 million for a legal person, and sanctions are published. Refer to our guides: What Happens if You Fail a FIC Audit? and How to Pass a FIC Audit: A Step-by-Step Checklist for SA Businesses.
What is Changing for RMCPs in 2026?
Two developments are worth tracking closely.
Draft Directive 12 would make RMCP submission an annual obligation. Published for comment on 31 July 2026, the draft directive proposes that specified Accountable Institutions submit their RMCPs to the FIC every year through its registration and reporting platform. The categories named are legal practitioners, certain trust and company service providers, estate agents, gambling institutions, credit providers other than banks and mutual banks, the South African Postbank, high-value goods dealers, the South African Mint and crypto asset service providers.
The proposed deadlines are 30 September each year for the first group and 31 October for the second. Two further requirements are significant: where an institution updates and approves its RMCP after its annual submission, the revised version would have to be submitted within ten business days of approval, and newly established Accountable Institutions would have to submit within ninety days of commencing business. Because the consultation is still open at the time of writing, affected institutions should confirm the final position before relying on these dates.
Record retention may extend from five to seven years. The Draft General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Bill, published in January 2026, proposes extending the minimum record retention period for Accountable Institutions from five years to seven. The Bill also proposes expanded FIC powers, including lifestyle audits, and strengthened RMCP obligations. It remains a draft, so the five-year rule continues to apply, but institutions designing retention infrastructure now should plan for the longer period.
Both developments point the same way. South Africa exited the Financial Action Task Force greylist on 24 October 2025, but its next mutual evaluation runs through to October 2027, and the FIC has made clear that supervisory intensity is increasing rather than easing. The RMCP is the document at the centre of that scrutiny.
RMCP and FICA Compliance Solutions for South African Businesses
As South Africa's leading provider of world-class identity verification, KYC, AML screening and due diligence solutions, ThisIsMe gives Accountable Institutions the operational capability their RMCPs depend on. With access to 45+ services, including real-time identity verification against the Department of Home Affairs HANIS database, document and passport authentication with tamper detection, biometric photo comparison, address and contact verification, company, director and trust searches for beneficial ownership, AML and sanctions screening powered by global risk intelligence, continuous AML monitoring, bulk re-screening, employee screening and bank account verification, ThisIsMe helps businesses turn a written programme into demonstrable, audit-ready compliance. To experience our full suite of FICA compliance solutions and find out how we can serve your business, contact our team here.

