Go back to Blog
Jennifer Edidiong
Marketing
9 min read
Share to
How South Africa's FICA Tightening in 2026 Affects Fintechs Expanding Into the Market

South Africa is one of the most developed fintech markets on the continent. It has established payment infrastructure, a mature regulatory environment and a growing consumer base for digital financial services. It is also one of the most demanding compliance environments a fintech can enter. FICA has always required more than a basic KYC check, andĀ the 2026 Amendment BillĀ adds obligations most expanding fintechs have not yet mapped.
South Africa was removed from the FATF grey list in October 2025, but that does not reduce the FICA burden. The country's next fullĀ FATF evaluation began in the first half of 2026 and concludes in October 2027, so the FIC is working in a high-scrutiny environment where enforcement is active. A fintech that treats FICA as a lighter version of Nigerian or Kenyan compliance will find out the difference during an examination, not before.
This guide covers what FICA actually requires, what the 2026 Amendment Bill changes, the most common gaps for fintechs expanding into South Africa, and how to build a compliant stack from day one.
What FICA Actually Requires

The Financial Intelligence Centre Act (Act 38 of 2001)Ā is South Africa's primary AML statute, administered by the Financial Intelligence Centre (FIC). It is not a single check at onboarding. It is a continuous compliance programme, and these seven obligations apply from the day you start operating:
- Register with the FIC within 90 days: Every accountable institution must register through the goAML portal atĀ fic.gov.zaĀ within 90 days of commencing operations. Failure to register carries fines of up to R10 million. This is the obligation expanding fintechs miss most often because they treat it as an admin step rather than a compliance deadline.
- Conduct risk-based customer due diligence: CDD must be applied before a business relationship starts. Most customers get standard due diligence, while higher-risk clients such as PEPs, customers tied to high-risk jurisdictions and complex ownership structures get enhanced due diligence.
- Verify beneficial ownership: For business customers, you must verify the ultimate beneficial owners, not just the entity. All South African companies must now file beneficial ownership information with CIPC, and accountable institutions must verify it as part of CDD.
- Screen against the FIC Financial Sanctions List: You must screen customers and transactions against theĀ FIC's sanctions listĀ as well as international lists. The local list is a separate, named requirement that international list screening does not cover.
- File suspicious transaction reports promptly: UnderĀ FICA section 29, STRs must be filed with the FIC as soon as reasonably possible after suspicion forms. Delay after suspicion is itself a compliance failure.
- File cash threshold reports: Cash transactions above ZAR 24,999.99 require a report under FICA section 28. This applies to any regulated fintech product that accepts or facilitates cash.
- Maintain records for at least five years: All CDD records, transaction records, and STR filings must be kept for a minimum of five years. TheĀ 2026 Amendment BillĀ extends this to seven, so design for seven now.
The 2026 Amendment Bill adds further obligations on top of this framework.
What the 2026 Amendment Bill Changes

TheĀ General Laws AML Amendment Bill 2026 does not replace FICA.Ā If you have mapped your FICA obligations against the original framework, that mapping needs updating.
Here are the four key changes:
- Record retention extended to seven years: The five-year requirement becomes seven. Building retention infrastructure for the seven-year standard now is cheaper than retrofitting it later.
- Lifestyle audits for high-risk customers: The Bill makes lifestyle audits a formal compliance tool for high-risk segments. You will need to assess whether a customer's financial activity is consistent with their declared income, assets, and profile. That goes well beyond document collection.
- Mandatory AML risk assessments for new technologies: Before deploying AI systems, new digital channels, or product innovations, fintechs must complete a formal AML risk assessment. A new feature that touches customer identity, transactions, or account access needs a documented assessment.
- Beneficial ownership discrepancy reporting: When what a customer declares differs from what is recorded in public registers, the institution must report the discrepancy. This turns beneficial ownership verification into an active monitoring obligation.
Together, these changes raise the baseline for what a compliant South African operation looks like in 2026 and beyond.
What This Means for Crypto and Fintech Platforms

FICA applies to all accountable institutions, and that now explicitly includesĀ crypto asset service providersĀ and a broad range of fintech businesses. The expansion of FICA's scope under the 2017 amendment, and the later inclusion ofĀ CASPs in Schedule 1, means digital asset platforms, payment service providers and digital lenders sit in the same compliance framework as traditional banks.
Three implications matter most:
- Crypto platforms face full FICA obligations: The FSCA has declared crypto assets financial products under FAIS, and the FIC has included CASPs in Schedule 1. Exchanges and wallet providers therefore carry the same CDD, sanctions screening, STR filing, and record-keeping duties as banks. Operating without a FAIS licence and FIC registration is not a grey area. It is a regulatory violation.
- Payment platforms need localised sanctions screening: Most payment platforms entering South Africa screen against OFAC and UN lists. FICA also requires screening against theĀ FIC's own Financial Sanctions List, which it maintains locally. Platforms that screen only against international lists have a named compliance gap.
- The technology risk assessment affects product launches: Under the 2026 Amendment Bill, any new AI system, digital channel or fintech product that touches customer identity or transactions needs a formal AML risk assessment before deployment. Launching without one puts you in breach before the product goes live.
The most common gaps for fintechs expanding into South Africa come from treating FICA as equivalent to what they already run in their home market.
The Most Common FICA Compliance Gaps for Expanding Fintechs

Most fintechs expanding into South Africa already have a KYC stack. The gaps are about what the verification covers and whether it meets FICA's specific requirements.
These are the three gaps that come up most:
- Not registering with the FIC before going live: goAML registration is a precondition for operating as an accountable institution, not something to sort out after launch. A fintech that starts onboarding South African customers before registering is outside the regulatory framework from day one.
- Screening against international lists only: FICA names the FIC Financial Sanctions List as a distinct obligation. A platform that runs OFAC, UN and EU checks without it has a documented gap that an FIC examination will find.
- Treating beneficial ownership as a one-time onboarding check: With discrepancy reporting coming in under the 2026 Amendment Bill, you need to keep checking whether the ownership structure declared at onboarding still matches what is registered at CIPC, and report differences when they appear.
Building a compliant South African operation from day one takes infrastructure that covers all of these layers, not just the ones familiar from other markets.
How Dojah Supports FICA Compliance for Fintechs Expanding Into South Africa
FICA compliance requires identity verification that covers South African ID types, AML screening that includes the FIC Financial Sanctions List, beneficial ownership verification for business customers, and ongoing monitoring across the customer lifecycle. Dojah'sĀ identity verification andĀ AML Watchlist infrastructure covers these requirements from one integration.
- South African ID verification: Dojah supportsĀ South African ID verification directly, so expanding fintechs get the database connection they need for FICA-compliant CDD without building a separate local integration.
- AML screening including the FIC Financial Sanctions List: AML Watchlist screens against international sanctions lists, PEP databases, and adverse media alongside local lists. This closes the international-lists-only gap covered above.
- Beneficial ownership verification for business customers: Director identity verification and UBO identification run in the same flow as individual customer verification throughĀ EasyOnboard. That covers the beneficial ownership obligation under FICA without a separate vendor connection.
- Ongoing monitoring throughout the customer lifecycle: Dojah'sĀ Profiled Risk supports continuous risk assessment after onboarding, which meets FICA's requirement to assess risk throughout the relationship instead of treating onboarding as the end of the obligation.
For fintechs expanding into South Africa, Dojah covers the identity verification, AML screening and ongoing monitoring layers FICA requires from one integration, not a separate compliance stack for the South African market.
See how Dojah helps fintechs meet FICA compliance requirements in South Africa.
Ā
Frequently Asked Questions About FICA Compliance in South Africa for Fintechs
1. What is FICA and who must comply with it?
FICA is the Financial Intelligence Centre Act (Act 38 of 2001), South Africa's primary AML statute. It applies to all accountable institutions, which include banks, many fintech businesses, and crypto asset service providers listed in Schedule 1.
2. Do foreign fintechs need to register with the FIC?
Yes. Foreign fintechs expanding into South Africa must register with the FIC through goAML within 90 days of commencing operations. Failure to register carries fines of up to R10 million.
3. Does South Africa's removal from the FATF grey list reduce FICA obligations?
No. The removal in October 2025 does not lower FICA requirements. South Africa's next full FATF evaluation runs until October 2027, so the FIC is operating in a high-scrutiny environment.
4. What are the FICA KYC requirements for 2026?
Fintechs must apply risk-based CDD, verify beneficial ownership for business customers, screen against the FIC Financial Sanctions List, and file STRs and cash threshold reports. The 2026 Amendment Bill adds lifestyle audits, beneficial ownership discrepancy reporting, and mandatory AML risk assessments for new technologies.
5. How long must records be kept under FICA?
The current minimum is five years for CDD records, transaction records, and STR filings. The 2026 Amendment Bill extends this to seven years, so fintechs should build retention for seven.
6. Does FICA apply to crypto platforms?
Yes. Crypto asset service providers are included in FICA Schedule 1 and face the same AML obligations as banks, including CDD, sanctions screening, STR filing, and record-keeping.
Start using Dojah for all your business needs