Risk management and compliance enforcement

Issue 3 2025 Security Services & Risk Management

Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA). More importantly, it has become the focal point of regulatory enforcement, with recent penalties confirming that the Financial Sector Conduct Authority (FSCA) will not hesitate to act when institutions fall short.

In April, the FSCA announced fines totalling R735 000 against three financial services providers (FSPs) that failed to implement proper RMCPs. One firm had no RMCP at all. Others submitted incomplete, generic documents or failed to link procedures to their actual business risks. These were not isolated oversights, each case demonstrates a growing intolerance for compliance frameworks that exist in theory, but not in practice.


Sameer-Kumandan.

The consequences of

non-compliance

One firm was fined R300 000 for not having an RMCP in place. Additional penalties were issued for failures in risk-rating clients, conducting customer due diligence, and screening against the Targeted Financial Sanctions (TFS) lists.

Beyond the financial penalties, the FSCA has made it clear that enforcement is not temporary; it is the new normal. Institutions must expect greater scrutiny going forward, especially as South Africa remains under international pressure to improve its anti-money laundering (AML) and counter-terrorism financing (CFT) frameworks in line with FATF standards.

What an RMCP is, and what it is not

An RMCP is more than a document. It is a strategic, risk-based approach that must be tailored to the institution’s size, business model, client profile, and sector risks. The board of directors or the most senior governing body is responsible for approving and maintaining it. This responsibility cannot be delegated.

At a minimum, an RMCP must demonstrate how the institution identifies and assesses risks associated with its clients, transactions, and services. It must explain the procedures used to mitigate those risks, how these are monitored, and how the institution will ensure that due diligence is conducted consistently. It must also outline how the institution will meet its reporting obligations under FICA and ensure that employees are trained to understand and carry out their compliance duties. Institutions are at risk if these measures are not implemented, regularly reviewed, and embedded in daily operations – even if an RMCP has been drafted.

A living document in a shifting environment

Guidance Note 7A, issued by the Financial Intelligence Centre, has raised the bar for RMCP expectations. It clarifies that institutions must maintain version control, ensure internal documents referenced in the RMCP are available during inspections, and link controls directly to their risk assessments. The FSCA has already acted against firms that failed to do this.

An RMCP that is copied from a template or not approved by the board is insufficient. Regulators want evidence that the document is understood, applied, and updated as risks evolve.

Supporting compliance with technology

With expectations rising and enforcement tightening, technology is becoming essential in ensuring that RMCPs are not just in place, but actually embedded into daily operations.

VOCA, powered by SearchWorks, enables institutions to implement their compliance framework. It automates customer due diligence, client risk profiling, ongoing monitoring, and regulatory reporting, ensuring that the day-to-day execution of your RMCP is aligned with FICA requirements. By embedding these processes into your operations, VOCA turns policy into practice.

For institutions needing to draft a new RMCP or update an existing one, Moonstone specialises in compliance and risk management. Their team provides expert guidance tailored to your business model and sector-specific risks, helping ensure that your RMCP meets both regulatory expectations and practical needs.

Together, VOCA and Moonstone provide an end-to-end compliance solution, from expert support in shaping your RMCP, to seamless implementation and operational enforcement. It is a practical, scalable approach to managing risk and staying audit-ready.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Nimbus remote fire alarm management
Technoswitch Fire Detection & Suppression Security Services & Risk Management Fire & Safety
Nimbus connects key stakeholders to their fire alarm systems, simplifying compliance with fire safety standards and greatly improving visibility into critical events, thereby augmenting first responder processes that save lives and protect assets.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.