Identity verification (IDV): A practical guide to staying FICA compliant
Onboarding new customers may feel like a simple business-as-usual task. Yet, it is one in which compliance officers face a great deal of responsibility and greater scrutiny. Before any new business can be conducted, strong identity verification (IDV) protocols have to be maintained at a growing range of accountable institutions under the Financial Intelligence Centre Act (FICA).
Launderers and fraudsters are riding high in an age of increased digitalisation to hide their identities and subsequent illicit activity. With that in mind, supervisory inspections are growing, where lax know your customer (KYC) checks will not be tolerated and actively punished.
When adopted as an instrumental first-stop in an anti-money laundering (AML) setup, however, IDV can provide both an effective safeguard and competitive advantage for businesses, and doing so from institution-to-institution relies on a guided framework followed by decisive strategic action, as we detail here.
Table of Contents
FICA’s aims
FICA has existed since 2001, and has been duly updated to reflect the obligations modern institutions need to take to detect and investigate financial crime. Money launderers and terrorist financiers are evolving in ingenuity and scope, and getting far more difficult to identify, where financial institutions exist on the frontline to report any potential high-risk activity.
This brings banks and fintechs into the fold with the Financial Intelligence Centre, the agency established to collect and analyse data indicative of financial crimes, to ultimately reduce such activity in South Africa. The very initial step for prevention involves KYC: measures to determine whether any new client or partner is who they say they are, according to stringent verification checks, before any business relationship or transaction can even begin.
What counts as an accountable institution?
The net of institutions facing supervisory action has expanded exponentially. This includes both financial and non-financial businesses under the FIC’s Schedule 1, including, but not restricted to: real estate companies; money exchanges; casinos; insurance firms; financial advisors; investment firms; payment service providers; and precious metal dealerships. They are supervised by the South Africa Reserve Bank’s Prudential Authority.
Risk-based IDV requirements
FICA’s detailed requirements for IDV come into play for each of these documented businesses. In practice, all of their relevant clients must be assessed and cleared through the collection of proven government-distributed documents, and ID numbers and other credentials being cross-referenced against national databases (including the Department of Home Affairs).
As made clear by the FIC’s guidance, institutions have to balance the accuracy of their IDV with a sustained, invested effort to obtain verification according to risk levels. Higher-risk clients warrant stricter checks, while lower-risk entities should see proportionate treatment. This establishes a tiered system that prioritises further due diligence where necessary, and allows fully legitimate clients and partners to start transacting without delay.
Although this recommended approach does promote a standardised level of regulatory expectation, it is not possible for a one-size-fits-all IDV approach to work across multiple institutions. Some may work in riskier jurisdictions, sectors, or incur material operational hurdles (if they are smaller institutions, say). Tailored approaches to IDV involve mapping out a comprehensive business-specific risk management strategy, with the help of regulatory technology (RegTech) providers.

Penalties for non-compliance
The industry is filled with horror stories around how poor AML is addressed, and drastic action shows no sign of stopping when insubstantial risk controls can contribute to the success of nefarious organised crime groups. In 2024, South Africa’s Sasfin Bank was found to display historic non-compliance with FICA in regards to sanctions, and an imposed R209 million was reduced to a still-staggering R160 million.
That single penalty, while hefty enough, is only one potential repercussion alongside near-irredeemable reputational damage, restricted access to global banking partners, and licensing risk – all stemming from negligent attitudes to IDV. The FIC can impose up to R50 million in administrative penalties. Directors or compliance officers can be held personally liable, and even face imprisonment in severe cases.
Unscalable manual verification
As important as a cultural shift is required to improve IDV, this reform should be concurrent with the increasing use of automation for verifying identities around the clock. The increased global adoption of instant payment systems poses the need for real-time verification; eKYC methods such as biometric recognition will soon be foundational to a successfully demonstrated IDV strategy, no matter how far off that may feel today for some firms. Already 79% of South African banks have acknowledged rising fraud losses; an exploitative threat that will take advantage of ongoing operational shortcomings.
Manual paper-based verification (still very much practiced) creates a stream of problems, from human error to repeated work across AML and fraud workflows, and a lack of tracked, real-time audits that FIC supervisors require. Instead, AI-driven IDV goes beyond being a ticked-off compliance obligation with the DHA, and is fundamental to reducing ever-sophisticated fraudulent activity that can degrade business growth – so long as it is an integral part of a unified system that can join-up typically fragmented AML functions including authenticated instant document checks, liveness detection, and sanctions screening.
Five FICA compliance non-negotiables
In order to reach FICA’s expected IDV requirements and move away from periodic KYC checks, it is best to consider these essential steps whenever looking to onboard new clients, partners, vendors and third parties – and ensure they’re actionable within a frictionless end-to-end AML system that remains a single source of truth for all entity data.
- Customer IDV before first transaction
It should be a given that any customer faces initial KYC checks as the first step of due diligence. To let legitimate entities get onboarded as soon as possible, data collection must be instant (including proof of identity, addresses, and company documents if necessary), to obtain enough information to conduct the following digital IDV steps.
- Risk-based due diligence
Conducting customer due diligence (CDD) should be granted as a standard, with risky activity identified through user-controlled risk thresholds. If standard IDV checks are failed or evaded, triggered entities should then be automatically raised for enhanced due diligence (EDD). Compliance teams should then follow documented policies which explain the further measures required at the EDD stage, such as enhanced background checks for sources of wealth, senior management approval, and ongoing monitoring.
- Digital IDV measures
Customers should be subject to a thorough range of holistic authentication checks. This includes DHA lookup – regarding their official government-level information – and biometric liveness checks that are able to discern synthetic identities (often created from fraud or cyber-attacks) from real ones according to facial or fingerprint recognition technology.
- PEPs and sanctions screening
Worldwide watchlists for politically exposed persons (PEPs) or sanctioned individuals are constantly updated, and should be consulted to deem any suspicious background information considered high-risk. Domestic South Africa “PIP lists” and sanction lists, such as the Office of Foreign Assets Control, should be automatically checked in conjunction with global registers, namely the United Nations, and the EU sanctions tracker.
- Beneficial ownership
Accountable solutions must be able to collect details on beneficial owners, defined as someone who owns or controls more than 5% of a legal entity. The Companies and Intellectual Property Commission (CIPC) made its Beneficial Ownership Register effective in 2023, where registered businesses should submit their own information.

A step-by-step FICA IDV checklist
To get ahead, all financial and non-financial businesses should take a modular approach to define existing process, identify IDV gaps, and make necessary changes to adhere to FICA’s stricter gaze, as follows:
- Outline compliance team roles, including compliance officers, MLROs etc.
- Register with the FIC
- Create and house a Risk Management and Compliance Programme (RMCP): how a business assesses and mitigates risk
- Establish protocols for initial customer ID verification
- Apply risk-based CDD processes and EDD thresholds for high-risk clients
- Screen against PEPs and sanctions lists, and trusted adverse media sources
- Check beneficial ownership information via the CIPC
- Retain records electronically for five years
- Ensure thorough staff AML training to understand FICA rules, IDV methodologies, and definitions of low- and high-risk entities
- Implement continuous transaction monitoring to assess changes in user behaviours
- Resolve entity profiles with automatic risk scoring updates

For this formalised IDV stage to be the intrinsic first KYC step of a fully automated AML platform, FICA-accountable businesses should look to RegTech partnerships. Together, a bespoke risk management system (from onboarding to continuous monitoring and reporting) can be crafted according to a business’s operational needs and limitations. Ultimately, this enables different risk classes to be assessed accordingly, in line with the checklist above, in a centralised platform that instantly raises any anomalous alerts.
More and more, financial institutions’ risk controls will be under the microscope. Installing a well-established IDV process will assist the execution of strong, iterative and future-proofed KYC, going beyond baseline compliance levels and becoming a key business advantage.