‘Accountable institutions’ under FICA are learning their new obligations
Large numbers of businesses are having to gear themselves up to become ‘accountable institutions’ under last year’s amendments to the Financial Intelligence Centre Act (FICA).
These changes to our finance laws – including tighter regulation for estate agents, casinos and crypto – were nonetheless not sufficient for South Africa to avoid grey listing earlier this year by the Financial Action Task Force (FATF).
The amendments took effect on 19 December 2022 as part of efforts by the Treasury to amend five separate pieces of legislation.
As long ago as October 2021, the FATF - the global money laundering and terrorist financing watchdog which sets international standards and to which South Africa is a member – reported in an FATF Mutual Evaluation Report, that “South Africa has a solid legal framework to fight money laundering and terrorist financing but has significant shortcomings in implementing an effective system, including a failure to pursue serious cases.”
Grey listing means that a jurisdiction comes under increased monitoring but is actively working with the FATF to address strategic deficiencies. They typically have made a commitment to resolve deficiencies according to agreed timeframes.
Blacklisting is more serious: it has an official designated as a high-risk jurisdiction subject to a Call for Action. The listing identifies a nation as having weak anti-money laundering and counterterrorist funding regulatory frameworks and serves as a warning to the financial world of the significant money laundering and terrorist funding and danger that certain nations provide on the global scene.
According to the Financial Intelligence Centre (FIC), under the amendment Schedule 1 of the Act, more institutions are now being listed as ‘accountable institutions’ that will then be more harshly scrutinised, monitored and supervised, including any business that sells goods or services on credit.
The FIC put more compliance steps in place that need to be fulfilled before business transactions can conclude with day-to-day impacts on how businesses carry out their activities with the extra cost of compliance ultimately falling on the consumer.
A handful of the amendments to certain schedules widen the scope of activities of businesses to align the Act further with the FATF standards: trust and company service providers, credit providers, money transfer providers and others will now be required to fulfil FICA risk and compliance obligations.
The new rules involve a risk-based approach to combating money laundering and terrorist financing.
Under this risk-based approach, accountable institutions have seven pillars of compliance:
1. Registration: FIC has a registration and reporting system called goAML, and it is a legal obligation in terms of the FIC Act for accountable institutions to do so. It enables accountable and reporting institutions to comply with other FIC Act obligations, such as submitting a report. The consequence of failure to register or failure to provide information is regarded as a non-compliance and subject to an administrative sanction.
2. Training: The FIC Act states that employees need to be provided with ongoing training regarding FICA and the RMCP (risk management and. compliance programme). The required training ensures every employee understands the legislation and what is expected of them to be compliant. If an employee has not been trained, they are not allowed to deal with clients. It alerts employees to the risks of money laundering and terrorist financing and enables them to identify suspicious or unusual activities.
3. Governance: The accountable institution must have a compliance function to assist the board of directors or senior management in fulfilling their obligations, and must assign a person with sufficient competence and seniority to ensure the effectiveness of the compliance function.
4. RMCP: The institution’s risk management and. compliance programme needs to contain policy documents, and must detail all the processes, systems and controls used for customer due diligence (CDD), recordkeeping and reporting and how the risk-based approach is used in all of these measures. Employees may be tested regarding their understanding of the RMCP and how they have been trained.
5. CDD: This covers what the accountable institution knows about its client, what it understands about the business the client is conducting and the type of transactions the accountable institution can expect in the course of the business relationship.
6. Recordkeeping: CDD and transaction records must be maintained, whether that transaction is a single transaction, or one concluded in the course of a business relationship. These records may be kept electronically for five years.
7. Reporting: Reports must be submitted for any cash transactions for R50 000 or more; or in the event of a suspicious and unusual transaction; or for any property that may be held on behalf of someone who may have been involved in carrying out terrorist activities.
In the event of non-compliance with any of these seven pillars, there is a scale of administrative sanctions starting with a caution, and rising to a reprimand, directive to take remedial action, a restriction or suspension of certain specified business activities, and finally a financial penalty of up to R50 million for any legal person.