South Africa regulates anti-money laundering through the Financial Intelligence Centre Act 38 of 2001, supervised by the Financial Intelligence Centre, the Prudential Authority and the Financial Sector Conduct Authority. Accountable institutions must register, run a risk management and compliance programme, verify beneficial ownership and file cash, suspicious and terrorist property reports.
Key takeaways
- South Africa left the FATF list of jurisdictions under increased monitoring on 24 October 2025, having been listed in February 2023 and cleared all 22 action plan items.
- The cash threshold report trigger is R49 999.99, raised from R24 999.99 on 24 November 2022, and is due within three business days.
- Administrative penalties under the FIC Act reach R50 million for a legal person and R10 million for a natural person.
- Capitec Bank's R56.25 million penalty of 20 December 2024 is the largest recent bank sanction, ahead of Standard Bank's R13 million in January 2025.
- Crypto asset service providers and high-value goods dealers taking R100 000 or more have been accountable institutions since 19 December 2022.
Which laws and regulators define South Africa's AML regime?
Three statutes carry the weight. The FIC Act 38 of 2001 sets the preventive obligations and establishes the Financial Intelligence Centre as the national financial intelligence unit. The Prevention of Organised Crime Act 121 of 1998 criminalises money laundering and racketeering, and POCDATARA 33 of 2004 covers terrorist financing.
Supervision is split rather than centralised, which matters when you are working out who will inspect you. The FIC itself supervises the non-financial sectors, while prudentially regulated banks and insurers answer to the South African Reserve Bank's Prudential Authority, and market conduct entities to the Financial Sector Conduct Authority.
| Supervisory body | Sectors it supervises for FIC Act compliance |
|---|---|
| Financial Intelligence Centre | Legal practitioners, trust and company service providers, estate agents, gambling businesses, credit providers, high-value goods dealers, crypto asset service providers, Postbank, the SA Mint |
| Prudential Authority (SARB) | Banks, mutual banks, life insurers |
| Financial Sector Conduct Authority | Financial services providers, collective investment scheme managers, authorised users of an exchange |
Sector allocation and the sanction powers behind it are set out on the FIC's supervision and enforcement page.
Is South Africa still on the FATF grey list?
No. South Africa was removed from the FATF list of jurisdictions under increased monitoring on 24 October 2025, 32 months after being listed in February 2023. Nigeria left at the same plenary.
The exit followed completion of all 22 items in the action plan, with a follow-up on-site assessment in July 2025 confirming the reforms were sustainable. The South African Revenue Service's account of the delisting sets out the workstreams that closed the gaps: beneficial ownership access, risk-based supervision, outbound mutual legal assistance requests and law enforcement use of financial intelligence.
For screening teams the practical consequence is narrow. Delisting removes the country-level trigger that many institutions used to force enhanced due diligence on South African counterparties, but it does not reset customer or product risk. Our South Africa country coverage page tracks the current status, and FATF mutual evaluations explains the assessment mechanism behind listing decisions.
Who counts as an accountable institution in South Africa?
The answer changed materially on 19 December 2022, when amended Schedules 1, 2 and 3 to the FIC Act took effect and pulled several previously unregulated sectors into scope. Crypto asset service providers, credit providers, clearing system participants and high-value goods dealers all became accountable institutions on that date.
The high-value goods dealer category is the one most often missed. Item 20 of Schedule 1 captures any business dealing in goods valued at R100 000 or more that receives payment of R100 000 or more, in a single transaction or in linked transactions, as the FIC's high-value goods dealer guidance sets out. Payment form is irrelevant, so an electronic transfer counts.
Legal practitioners, estate agents, trust and company service providers, gambling operators and banks were already in scope. Schedule 3 covers a smaller set of reporting institutions, including motor vehicle dealers and Krugerrand dealers, whose duties are limited to reporting rather than the full obligation set.
Which reports must be filed with the FIC, and by when?
Four filing duties do most of the operational work, and two of them run on hard clocks. Cash threshold reporting is mechanical and threshold-driven. Suspicious reporting is judgement-based, has no monetary floor, and applies to attempted as well as completed transactions.
| Obligation | FIC Act section | Trigger | Deadline |
|---|---|---|---|
| Registration on goAML | Section 43B | Commencing business as an accountable or reporting institution | Within 90 days of commencing operations |
| Cash threshold report (CTR/CTRA) | Section 28 | Cash received or paid out above R49 999.99, including linked transactions | Three business days |
| Suspicious or unusual transaction report (STR/SAR) | Section 29 | Suspicion of money laundering, terrorist financing or proceeds of unlawful activity | 15 days, excluding weekends and public holidays |
| Terrorist property report (TPR) | Section 28A | Property linked to a person or entity on a targeted financial sanctions list | As soon as possible after becoming aware |
The R49 999.99 figure is current: the FIC confirms the cash threshold report trigger rose from R24 999.99 with effect from 24 November 2022. The 15-day suspicious reporting clock comes from regulation 24(3) of the Money Laundering and Terrorist Financing Control Regulations, restated in the FIC's reporting period guidance.
What must a risk management and compliance programme cover?
Section 42 of the FIC Act requires every accountable institution to have a documented risk management and compliance programme. It is the institution's own rulebook, not a copy of the statute, and inspections test whether it is specific to the business and actually followed in practice.
The programme has to explain how the institution rates customer risk, what identification and verification it requires for each risk band, when it applies enhanced due diligence, how it establishes beneficial ownership, and how it detects and escalates reportable activity. Screening obligations for domestic prominent influential persons and foreign prominent public officials sit here too, as does ongoing due diligence.
Two failure modes recur in published sanctions. The first is a programme that reads well but was never operationalised in systems or training. The second is a programme that never catches up with a changed customer base. Definitions used across these obligations are collected in our glossary of AML terms.
How does South Africa's beneficial ownership regime work?
Beneficial ownership disclosure runs on two registers, and an accountable institution verifying a South African customer will use whichever fits the entity type. Companies file with the Companies and Intellectual Property Commission, while trusts file with the Master of the High Court under section 11A of the Trust Property Control Act.
The company threshold is lower than the FATF baseline. A beneficial owner of a South African company is an individual who ultimately owns or exercises effective control over 5% or more of the shares, per the CIPC beneficial ownership register, against the 25% used in several other regimes. Both regimes were introduced by the General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act 22 of 2022.
Filing is enforced through the annual return process, so a company that has not lodged current beneficial ownership information cannot complete its annual return. That gives institutions a reasonably reliable source, though registry data still needs independent ownership verification rather than being taken at face value.
What penalties has the Prudential Authority actually imposed?
The statutory ceiling is R50 million for a legal person and R10 million for a natural person, with cautions, reprimands, remedial directives and business restrictions available alongside. Published penalties routinely combine several of these, and part of the financial penalty is often conditionally suspended.
| Institution | Date | Financial penalty | Core failure |
|---|---|---|---|
| Capitec Bank | 20 December 2024 | R56.25 million, R10.5 million suspended | Customer due diligence, transaction monitoring and reporting failures found in 2021 and 2022 inspections |
| Standard Bank of South Africa | 24 January 2025 | R13 million | 17 259 suspicious reports and 1 466 cash reports filed late; no ongoing due diligence on two clients in 2018 and 2019 |
| Absa Bank | 25 April 2025 | R10 million | FIC Act non-compliance identified on inspection |
| HBZ Bank | June 2025 | R9 million | FIC Act non-compliance identified on a 2022 inspection |
| Nedbank | 12 August 2022 | R35 million, R15 million suspended | Cash threshold reporting failures found in a 2019 inspection |
Amounts and dates come from the Prudential Authority's administrative sanctions register, with the detail of the Standard Bank matter in its January 2025 media release and the Nedbank matter in the August 2022 release. Note the pattern: late filing at volume, not deliberate facilitation, produces most of the penalty value.
What changes now that grey-listing has ended?
Less than compliance officers hope. The supervisory cycle that produced the sanctions above was already running before delisting and is unaffected by it. Inspections continue to arrive two to three years after the period they examine, so conduct from 2023 and 2024 is still in the pipeline.
The scrutiny also shifts rather than stops. Having proved its framework works on paper, South Africa now has to show measurable effectiveness in investigations, prosecutions and asset recovery, which is what the next FATF assessment round will test. Supervisors under that pressure tend to be less tolerant of late reporting than they were mid-remediation.
Practically, three things are worth checking now: whether your customer risk model still applies a country-risk uplift that no longer has a factual basis, whether your goAML registration and reporting entity details are current, and whether your transaction monitoring rules produce alerts fast enough to meet a 15-day clock. MemberCheck customers screening South African portfolios should also confirm their sanctions and PEP screening covers domestic prominent influential persons, not only foreign officials. More jurisdiction analysis sits under jurisdictions and regulation.



