Issue 1 · September 2026
FSCA fines three FSPs up to R450 000 for FIC Act failures: what every FSP must check now
The FSCA has sanctioned three licensed FSPs for RMCP, customer due diligence, sanctions screening and FIC registration failures. Here is what was found, and the checks to run on your own file this week.
- FAIS
- FICA
On 9 September 2026 the Financial Sector Conduct Authority (FSCA) announced administrative sanctions against three licensed financial services providers for failing to comply with the Financial Intelligence Centre Act, No. 38 of 2001 (FIC Act). The fines range from R100 000 to R450 000.
None of the three were large institutions. All three are FAIS-licensed FSPs of the kind we work with every day, and every failure the FSCA listed is one we see in routine files. This issue sets out what the regulator found, why it matters to you, and the checks to run on your own business before the FSCA runs them for you.
Who was sanctioned, and for how much
- Sithembile Holdings (Pty) Ltd (FSP 50876): fined R100 000. Not yet paid.
- Mbuli Finance (Pty) Ltd (FSP 50831): fined R220 000. Paying under an arrangement with the FSCA.
- Mmela Financial Services (Pty) Ltd (FSP 20557): fined R450 000, of which R225 000 is conditionally suspended for three years. Paid.
Each institution was also directed to remediate the deficiencies found. The penalties were set with reference to the nature, size and complexity of each business, which is the FSCA's way of saying that being small is not a defence.
What the inspections found
The FSCA inspected all three entities under section 45B of the FIC Act. The contraventions fall into six areas.
1. No RMCP, or an RMCP that does not do the job (sections 42(1) and 42(2))
Every accountable institution must develop, document, maintain and implement a Risk Management and Compliance Programme (RMCP) covering money laundering, terrorist financing and proliferation financing. The FIC Act prescribes the minimum content.
Mbuli and Mmela both had an RMCP on file. The FSCA still found them non-compliant because the documents did not provide for one or more of the processes and procedures the Act requires. A template downloaded and renamed is not a programme.
2. Customer due diligence not done, or not recorded (sections 21A and 21C read with section 22)
Accountable institutions must identify and verify their clients, establish who acts on a client's behalf, understand the nature of the business relationship, and obtain beneficial ownership information. Records of all of this must be kept in the prescribed format.
Mmela failed to conduct the required due diligence on its clients and failed to keep the records in the required format.
3. Clients not screened against the sanctions lists (section 28A read with section 26B)
All current and prospective clients must be scrutinised against the United Nations Security Council Targeted Financial Sanctions (TFS) lists. A match must be reported to the Financial Intelligence Centre (FIC) and the client's accounts, assets and services frozen.
Mmela and Mbuli did not screen their clients against the TFS lists at all.
4. Employees not screened (Directive 8 of 2023 read with PCC 55)
Employees, prospective and current, must be screened for competence and integrity on a periodic, risk-based basis, and scrutinised against the TFS lists.
Mbuli had not screened a key employee who serves as both its Key Individual under the FAIS Act and its Money Laundering Control Officer under the FIC Act.
5. Not registered with the FIC (section 43B)
Every accountable institution must register with the FIC within the prescribed period. At the time of the inspection, Mbuli was not registered.
6. Directives to provide information ignored (section 43A(3))
The FSCA issued a Directive to Provide Information to all accountable institutions under its supervision on 27 May 2024. Mbuli did not respond within the prescribed period. On 27 February 2026 the FSCA directed Sithembile to submit information ahead of a planned onsite inspection. Sithembile did not comply.
"The above sanctions serve as clear reminders that the FSCA will not tolerate non-compliance with the FIC Act. Accountable institutions are urged to continually review and enhance their anti-money laundering and terrorist financing controls at the highest levels and to conduct thorough risk assessments on a regular basis. Failure to do so will result in firm regulatory action." — FSCA, 9 September 2026
Why this matters to your FSP
Three points stand out from this release.
Having a document is not the same as having a programme. Two of the three institutions had an RMCP. They were fined anyway, because the RMCP did not cover the processes the Act requires and, in practice, the business was not doing what the document said. Inspectors test the file against the programme, not the programme against itself.
Sanctions screening is not optional and it is not once-off. TFS screening of clients and staff is one of the cheapest controls to run and one of the most expensive to skip. Two of the three fines involved a complete absence of screening.
Silence towards the regulator is treated as a contravention in its own right. Failing to answer a Directive to Provide Information is listed alongside the substantive FIC Act failures and carried its own weight in the penalty.
Seven checks to run on your own file this week
- Confirm your FIC registration is current and that your registered details (MLCO, contact details, business activities) match reality.
- Open your RMCP and check it against the minimum content in section 42(2). If it was not written for your products, clients and delivery channels, it will not pass.
- Pull five recent client files at random. For each, confirm identity verification, beneficial ownership, the purpose of the relationship and the risk rating are on file in the required format.
- Confirm every client on your book has been screened against the TFS lists, and that new clients are screened before onboarding. Keep the evidence.
- Screen every employee, including your Key Individuals and your MLCO, against the TFS lists and record the competence and integrity screening required by Directive 8.
- Check whether your business responded to the FSCA's Directive to Provide Information of 27 May 2024. If you are not certain, find the submission.
- Diarise the next review of your RMCP and your business risk assessment. The FSCA expects both to be regular, and it will ask for the dates.
How RCC Compliance can help
RCC Compliance is an FSCA-authorised compliance practice (PN 7870). We implement FICA for FSPs and accountable institutions from the ground up, and we fix programmes that exist on paper but not in practice. That includes:
- Drafting or remediating your RMCP so it reflects your actual products, clients and channels and meets section 42.
- Setting up customer due diligence, beneficial ownership and record-keeping procedures your staff can follow.
- Client and employee screening against the TFS lists, with the evidence trail an inspector expects.
- FIC registration, goAML reporting and responses to FSCA directives and inspection requests.
- Ongoing monitoring so the programme stays current as your business and the regulations change.
If anything in this issue describes your business, get in touch before the FSCA does. Call us on 010 634 1800, email compliance@rccaudit.co.za, or book a consultation at rcccompliance.co.za/contact.
Source: FSCA press release, "FSCA imposes administrative sanctions on several Financial Services Providers", 9 September 2026. This newsletter is general guidance and not legal advice. Obligations differ by licence category and business model; speak to your compliance officer about your specific position.
Need help applying this?
Our consultants turn regulatory change into practical, auditable outcomes.
