Latest white paper on evolving regulations and emerging technologies

  • Industry perspective: The key forces driving AML reform in 2025 and beyond.

  • Operational insight: How automation is reshaping onboarding and accuracy.

  • Strategic value: Where collaboration is unlocking the next era of compliance.

Access White Paper
relycomply whitepaper

Get updates that matter

Stay connected with:

  • Industry insights - Reports on trends, threats, and regulatory shifts shaping the financial services world.

  • Customer highlights - See how businesses like yours are closing AML gaps and protecting their customers.

  • Feature releases - Discover the latest products and AI-powered capabilities in our platform.

relycomply whitepaper

Examining the increasing stakes for CDD at South African firms

The level of customer due diligence (CDD) expected today has taken it from a simplistic know your customer (KYC) check to an operational headache. CDD compliance is now a tiered exercise and a crucial step in the entire AML process – where poor or strong CDD has major implications for fincrime detection and investigative success down the line. 

Considering that the number of accountable institutions in South Africa has grown as much as its multiplying regulations, any traditional approaches to assessing customers’ intentions are not enough to satisfy stringent supervisors. 

Instead, learning how modern platforms can facilitate tricky CDD requirements can cement a business as a culturally compliant leader in good stead to increase its customer base, without the drawbacks of poor manual workflows, digital limitations, and the evolving threat of launderers. 

The purpose of customer due diligence

Simplistically, CDD is what it says on the tin: background checks on every new client that a financial institution onboards before they are able to use their services. However, the thoroughness of CDD relies wholly on the risks posed by certain customers (which may not be immediately obvious from their given information) and divides this mandatory KYC stage into three distinct levels of scrutiny:

  • Simplified due diligence (SDD) is a non-intrusive initial check for those where the threat of any illegal financial crime is very minimal. It involves verifying identities and getting them onboarded quickly.
  • CDD is a standardised procedure that warrants a level of protection for every customer (and the compliance integrity of the businesses). It applies a more holistic assessment into each customer’s risk profile: verifying their identity, but also their intentions and nature of business.
  • Enhanced due diligence (EDD) goes a step further to fully investigate high-risk customers, looking into their sources of funds, transaction history, beneficial ownership, negative press, and requires eventual sign-off from senior management.
The three tiers of CDD during onboarding

All three tiers are dedicated applications for any initial onboarding protocol within an entire AML framework. They act similarly to a door policy, allowing verified users into a business’s system.

South Africa’s CDD compliance nuances

Uncovering the backgrounds, identities, and beneficial ownership structures of every customer hinges on the data an institution has access to. Such intelligence is skyrocketing in importance; it is particularly useful when submitting any suspicious transaction reports (SARs) to the Financial Intelligence Centre (FIC). 

The FIC’s Financial Intelligence Centre Act (FICA) is the primary legislative framework underlining who is required to perform CDD, with the list of ‘accountable institutions’ growing outside of traditional financial service providers to encompass fintechs, insurance, real estate agents, and legal entities.

This is in light of South Africa only last year exiting FATF’s ‘greylist’ for once-insubstantial AML/CTF. The country’s ongoing reputation on the world compliance stage relies on the stringent enactment of its CDD and AML soundness across the ecosystem, aiming to improve prospects for foreign investment, greater customer trust in financial service providers, and avoid the reputational and fiscal damage of poor AML.

CDD falls under the mandate of the Financial Sector Conduct Authority (FSCA), set up as part of South Africa’s ‘Twin Peaks’ compliance reform model. The FSCA is responsible for assessing conduct risk, while the Prudential Authority was established to maintain the safety and stability of the financial systems. The Twin Peaks setup is evolving ever further, where the FSCA and Prudential Authority are attempting to unite all financial sector laws under one domineering Conduct of Financial Institutions (COFI) Bill. 

Diagram of South Africa's AML oversight structure showing the FIC, FSCA, Prudential Authority, and the COFI Bill under the Twin Peaks regulatory model.

Unravelling the customer due diligence process

While this standardised risk assessment framework is welcome to help businesses document their CDD process, regulators are aware that CDD must be proportionately attuned to the customer data volumes at any one accountable institution. 

Not being able to apply a one-size-fits-all solution puts the onus on the business’ compliance arm, and their proactivity in maintaining a continuous CDD methodology, largely through the following means:

  • Identity verification (IDV): customer identities being assessed via the collection of FICA-required documentation, and biometric scanning. Advanced biometric IDV includes digital facial recognition, fingerprint matching, and liveness checks.
  • Beneficial ownership (BO) information: particularly relevant to know your business (KYB) checks, it’s important to discover who owns or controls at least 5% in a company. South Africa’s BO Register requires all businesses to declare such persons through the CIPC.
  • Understanding purpose and nature of business relationships: reviews of financial statements, source of funds, employment histories, adverse media, and PEP or sanctions databases and watchlists can showcase ‘normal’ activity for why customers choose a financial service, and be indicative of their risk level for CDD (or indeed EDD in more complex or high-risk cases.)

Of course, passing CDD does not grant one-time exclusive access to a service. Due diligence must be a continuous system that tracks any changing risk behaviours across a customer’s lifecycle.  With continuous CDD in place, any anomalous occurrences in transaction behaviours can be a trigger for refreshed CDD or necessary EDD in future. 

The perils of traditional static CDD

This highlights today’s need for automated and risk-based KYC/AML according to the regions in which a business operates, and who it works with.

This was not always so pivotal, however, with CDD only performed out of sheer obligation. Cumbersome manual processes once used to onboard customers have become so ingrained that a digital overhaul has become a costly and worrisome process for many institutions. But paper-based document checks are impossible to maintain when bouts of financial and customer intelligence are so high in volume. Applying risk ratings at the very first KYC check alone cannot keep up with changing customer circumstances, nor their shifting transactional patterns.

Criminals can exploit such static systems and mask activity more easily when a single customer’s journey is divided between channels, financial products, and the dominions of legal risk, AML compliance and fraud teams. It’s easy to overwhelm under-resourced and siloed compliance teams blighted by false positives that result from rules-based CDD and monitoring.

Hallmarks of quality modern CDD

Where once demonstrable CDD was used to pass an audit every now and then, the FIC’s stronger expectations for spotting real-time risk puts many ‘behind the times’ institutions at risk of fines and remediation. Consistent CDD that uses single-source-of-truth data mitigates that possibility, aligning KYC to the highest scrutiny of FICA and, for that matter, the global watch of FATF.

In which case, legacy systems that are inflexible to risk-based decisioning are already outdated. AML platforms must be unified front-to-back, where repeatable CDD can be triggered by suspicious transactions further into the monitoring process – which is dynamic, and not periodic in the case of manual workflows. That does not mean that existing customer data and infrastructures must be dismantled. Often RegTech platforms allow for existing systems to be augmented with AI-powered risk controls, able to more accurately screen data against trusted global watchlists, spot anomalies in historical transactions and reduce inefficient investigations into low-risk alerts.

Likewise, supportive and strategic RegTech partnerships can instill greater data governance that leads to explainable AI required by FSCA – models that are transparent and able to verify their rationale for coming to a conclusion – while auditability involves human analysts being able to prove how effective their end-to-end AML is in identifying high-risk behaviours and tracking that intelligence through to reporting.

When CDD helps compliance teams focus less on the noise and more on true risk, it becomes an integral part of the arsenal in appeasing regulators and signalling trust to customers, correspondent services, and third-party vendors.

CDD: The business enabler

CDD, being a point-in-time hurdle, is an outdated mindset. The nation’s delisting was a positive step for national risk assessment and compliance culture, and the regulators’ heightened gaze on highly auditable CDD reflects the need for accountable businesses to treat CDD as an effective discipline: using sound risk data to support quality investigations at every institution, through to the FIC and law enforcement. 

With a continuously-running AML setup, more attention can be paid to the existing and new customers that matter, and the growth opportunities that banks and fintechs seek – away from the risk of poor CDD conduct that can inflict a thousand blows to AML progress.

Automated CDD is a facilitator of fast and safe onboarding, and paramount to South Africa’s ecosystem operating under FICA guidelines, so that criminals are not the ones gaining all the momentum in fincrime’s digital evolution. To learn more about how integrated CDD works within an end-to-end AML platform, contact the RelyComply team today.