12.1 FIC Act Requirements that Apply to FSPs

Key Takeaways

  • The FIC Act combats money laundering, terrorist financing and related financial crime through preventive controls and financial intelligence — a different primary lens from FAIS client-treatment duties
  • Many FSPs fall within accountable-institution (Schedule 1-type) themes and must apply a risk-based Risk Management and Compliance Programme (RMCP)
  • Core FSP duties include customer due diligence, ongoing due diligence, FIC record-keeping, and reporting of suspicious/unusual activity plus cash threshold reports as applicable
  • Suspicious reporting is based on grounds for suspicion (not a minimum cash amount); cash threshold reporting follows the published regulatory cash threshold reflected in the RMCP
  • FIC and FAIS/GCOC duties run in parallel — a complete advice file does not cure a missing FICA pack, and vice versa
Last updated: August 2026

12.1 FIC Act Requirements that Apply to FSPs

Quick Answer: The Financial Intelligence Centre Act (FIC Act) exists to combat money laundering, terrorist financing, and related financial crime by imposing duties on accountable institutions. Many authorised financial services providers (FSPs) fall within Schedule 1-type themes and must run a risk-based Risk Management and Compliance Programme (RMCP), perform customer due diligence (CDD), keep records, and report suspicious or unusual activity and cash threshold matters as the law and the firm’s programme require. FAIS duties and FIC duties run in parallel — one does not cancel the other.

Task 6 of RE5 (comply with the FIC Act and ML/TF control regulations as they apply to an FSP) expects representatives to understand the firm-level stack first, then apply it at the client interface (section 12.2). This section maps purpose, scope, core FSP duties, and how those duties sit next to FAIS.

Purpose of the FIC Act

Money laundering turns criminal proceeds into assets that look legitimate. Terrorist financing may use clean or dirty funds to support unlawful ends. Both exploit financial services channels — bank accounts, investment products, insurance premiums, trust structures, and intermediary platforms.

The FIC Act’s public-interest purpose is therefore practical, not academic:

  1. Detect and deter abuse of the financial system for ML/TF and related offences;
  2. Impose preventive controls on institutions that handle or facilitate client money or products;
  3. Generate intelligence through prescribed reports to the Financial Intelligence Centre (FIC);
  4. Support investigation and prosecution by ensuring identity, transaction, and report trails exist when needed.

For RE5, remember the purpose statement in exam language: FIC is about crime prevention and financial intelligence, while FAIS is primarily about fair treatment of clients in the rendering of financial services. Both protect the public, but through different lenses.

Accountable institutions and Schedule 1 themes

The Act does not treat every business the same. It designates accountable institutions (Schedule 1 themes and related instruments). In practice, many FSPs and financial service businesses fall in scope for some or all of their activities — especially where they establish business relationships, conclude single transactions above relevant thresholds, or deal with products and clients that present ML/TF risk.

Key study points:

ThemeRE5 takeaway
Schedule 1 scopeDo not assume “we only give advice, so FIC never applies.” Scope is determined by the Act’s lists and the firm’s business model, not by sales convenience.
Accountable institution dutiesOnce in scope, the institution (the FSP as legal person, not only the individual rep) must implement the full control stack.
Risk-based approachControls must be proportionate to risk — higher risk clients, products, delivery channels, and geographies demand stronger measures.
Firm ownershipThe licensed FSP owns the RMCP and systems; representatives execute CDD and escalation steps inside those systems.

A representative who says “FIC is only a bank thing” is wrong for RE5. Banks are classic accountable institutions, but FSPs commonly sit inside the same preventive architecture.

The Risk Management and Compliance Programme (RMCP)

Modern FIC compliance is organised around a documented Risk Management and Compliance Programme. Think of the RMCP as the firm’s living AML/CFT operating system. Typical themes (wording varies by firm, but exam concepts stay stable) include:

  • Risk assessment of clients, products, services, delivery channels, and geographic exposure;
  • CDD and ongoing monitoring procedures (standard, simplified where allowed, enhanced where required);
  • Record-keeping methods and retention aligned to FIC clocks (see Chapter 11 for the parallel FAIS/GCOC stack);
  • Reporting workflows for suspicious/unusual matters and cash threshold reports;
  • Roles — who is the Money Laundering Reporting Officer (or equivalent compliance function), who approves high-risk onboarding, who may refuse or exit a relationship;
  • Training so representatives know red flags and escalation paths;
  • Governance — board/KI oversight of effectiveness, not paper policies left in a drawer.

RE5 does not require you to draft an RMCP from scratch. It requires you to recognise that skipping RMCP steps to close a sale is non-compliant, and that the representative’s job is to follow the firm’s RMCP, not invent private shortcuts.

Core FSP-level duties (the control stack)

1. Customer due diligence (identify and verify)

Before establishing a business relationship or concluding certain single transactions, the accountable institution must identify the client and verify identity using reliable, independent source documents, data, or information — in line with the Act’s section 21 / 21A-type themes and the RMCP.

CDD is not a box-tick photocopy exercise. It answers: Who is this person or entity? Are they who they claim to be? Who owns/controls the entity? Is anyone a high-risk person (for example a prominent influential person theme)? Why are they seeking this product or service?

2. Ongoing due diligence

CDD is not “once at onboarding, then forever.” Ongoing due diligence themes require the institution to keep client information reasonably current, to scrutinise transactions for consistency with the client profile, and to refresh verification when risk or circumstances change (for example a sudden change in payment source, unusual product switching, or new controllers of a juristic client).

3. Record-keeping

FIC record themes (commonly taught with sections 22–24) require the institution to keep identity/verification records, transaction records, and records related to reports for the prescribed periods — typically framed as five years from relationship termination, transaction conclusion, or report submission, depending on the record type. Chapter 11 stressed that these clocks sit alongside FAIS five-year categories; do not collapse them into one casual purge rule.

4. Reporting — suspicious/unusual and cash threshold

Two reporting families dominate RE5 scenarios:

Report familyConcept
Suspicious or unusual transaction / activity reporting (STR themes)Report when there are grounds to suspect that a transaction or activity relates to proceeds of unlawful activity, money laundering, terrorist financing, or other reportable themes under the Act — regardless of amount. Suspicion is qualitative; there is no “minimum rand value before you may report.”
Cash threshold reporting (CTR themes)Report cash transactions that meet or exceed the published threshold set under the FIC framework (and any aggregation/structuring rules in the RMCP). Do not invent a number in the exam answer if the question does not give one — know that a regulated cash threshold exists, that the FSP must monitor for it, and that breaking one cash deal into smaller pieces to stay under the threshold (structuring) is itself a classic red flag.

Reports go through the institution’s approved channels to the Financial Intelligence Centre. Representatives usually escalate to the MLRO / compliance function; they do not freelance public accusations to clients or social media.

5. Controls on anonymous or inadequate relationships

Accountable institutions must not maintain relationships where prescribed CDD cannot be completed (subject to limited legal nuances taught in firm procedures). Practically: no verified client identity → no open-ended product relationship. That principle drives the sales-floor conflicts tested in 12.2.

Risk-based approach in plain language

A risk-based approach means:

  • Lower-risk profiles may allow streamlined measures where the law and RMCP permit (never “no measures”);
  • Higher-risk profiles require enhanced due diligence (EDD) — extra identity/source-of-funds/source-of-wealth checks, senior approval, closer ongoing monitoring;
  • Delivery channel risk matters (remote onboarding, third-party introducers, cash-heavy patterns);
  • Product risk matters (features that allow rapid movement, opacity, or third-party funding).

Exam trap: risk-based does not mean “skip CDD if the client is a friend of the manager.” Friendship is not a legal verification method.

Parallel duties: FIC + FAIS + GCOC

Representatives work under at least two statutory umbrellas:

FrameworkFocus
FAIS + GCOCAuthorisation, advice quality, disclosures, complaints, FAIS records
FIC ActWho the client is, ML/TF risk, reports, FIC records

A file can have a perfect record of advice and still fail FIC if the FICA pack is missing. A perfect FICA pack does not excuse unsuitable advice under FAIS. RE5 rewards candidates who keep both stacks visible.

Scenario: “Compliance will fix FICA after the sale”

Facts: A branch celebrates month-end numbers. Several new investment applications are submitted with incomplete identity verification. The manager says compliance can “clean FICA next week” after commission is secured.

Analysis: Onboarding incomplete CDD to lock a sale undermines the RMCP and accountable-institution duties. The FSP remains responsible; representatives who knowingly bypass systems participate in the failure. Correct sequencing is CDD complete (or lawfully staged per RMCP) → then service/product activation, not the reverse.

Governance roles representatives must recognise

  • Key individual / management: ensure the FSP’s AML/CFT controls are effective in practice;
  • Compliance function / MLRO themes: receive internal escalations, decide reportability, file reports, guide EDD;
  • Representative: collect prescribed information, refuse to skip controls, escalate red flags promptly, never tip off a client that a suspicious report is being considered (tipping-off themes are serious).

Exam traps for section 12.1

  1. “FIC replaces FAIS.” Parallel, not substitute.
  2. “Only banks are accountable institutions.” Many FSPs fall in Schedule 1-type scope.
  3. “STR needs a minimum cash amount.” Suspicion reporting is not a cash-threshold concept.
  4. “CTR is the same as STR.” Cash threshold is quantitative/cash-based; STR is suspicion-based.
  5. “RMCP is optional policy fluff.” It is the operational heart of FIC compliance for the FSP.

Master this section as the firm map: purpose → accountable institution → RMCP → CDD/ongoing DD → records → STR/CTR reporting → governance. Section 12.2 puts that map into the representative’s daily client conversations.

Test Your Knowledge

What is the primary public-interest purpose of the Financial Intelligence Centre Act as taught for RE5?

A
B
C
D
Test Your Knowledge

Which statement best describes how many FSPs relate to FIC Act accountable-institution themes?

A
B
C
D
Test Your Knowledge

How should a representative distinguish suspicious transaction reporting (STR themes) from cash threshold reporting (CTR themes)?

A
B
C
D
Test Your Knowledge

What is the best description of an FSP’s Risk Management and Compliance Programme (RMCP) for RE5 purposes?

A
B
C
D