South Africa’s financial crime compliance environment is entering a different phase.
Following the country’s removal from FATF increased monitoring, the immediate focus on grey-list remediation is giving way to a more demanding question: can institutions demonstrate that their financial crime controls actually work?
This distinction matters. A documented risk assessment, RMCP, customer due diligence framework or sanctions procedure may demonstrate that an institution has addressed a regulatory requirement on paper. Increasingly, however, regulators and supervisors are interested in whether those arrangements are proportionate to the institution’s actual risks, properly implemented and capable of producing effective outcomes.
For Boards, executive management and financial crime control functions, the challenge for the remainder of 2026 is therefore not simply maintaining compliance. It is demonstrating sustained effectiveness.
The risk-based approach is becoming more demanding
The risk-based approach remains at the centre of effective AML/CFT/CPF compliance, but institutions increasingly need to demonstrate how their assessment of risk translates into practical control decisions.
There should be a defensible connection between:
Risk Factor → Risk Assessment → Risk Rating → Control → CDD → Monitoring → Review
This means that customer categories or broad segmentation cannot substitute for a meaningful assessment of risk.
Where an institution applies simplified due diligence, for example, it should be able to demonstrate why the underlying risk assessment supports that decision. Similarly, higher-risk customers, products, jurisdictions or delivery channels should result in appropriately enhanced controls.
The important question is no longer simply whether a methodology exists. It is whether the institution can explain and evidence the logic behind the control outcome.
Proliferation financing is moving beyond sanctions screening
Proliferation financing is also becoming a more prominent part of the financial crime risk conversation.
Traditionally, many institutions have approached PF primarily through targeted financial sanctions and screening controls. While these controls remain critical, the emerging expectation is broader.
Institutions should consider whether proliferation financing is appropriately reflected within their overall ML/TF/PF risk assessment, including customer, geographic, product, transaction and delivery-channel risks.
For Boards and senior management, this raises several practical questions:
- Does the institutional risk assessment specifically address PF?
- Are beneficial owners and relevant related parties included within sanctions controls?
- Do sanctions-list updates result in timely rescreening?
- Are potential and confirmed matches subject to appropriate escalation?
- Is PF adequately incorporated into governance, training and reporting?
The direction of travel suggests that PF should increasingly be treated as an enterprise financial crime risk rather than a specialist sanctions issue.
Beneficial ownership remains fundamental
Beneficial ownership also remains a critical area of financial crime control.
Collecting the name of a beneficial owner is not, by itself, sufficient. Institutions need to understand who ultimately owns or controls a customer, how that conclusion was reached and whether the information can be adequately verified.
Complex corporate structures, trusts, nominees and layered ownership arrangements can all make this more difficult.
Institutions should therefore consider whether they can demonstrate:
- How ownership and control structures are identified;
- How controlling persons are determined;
- How beneficial ownership information is verified;
- How complex or unusual structures are escalated;
- When source-of-funds or source-of-wealth measures become appropriate;
- How beneficial owners are incorporated into sanctions screening and ongoing monitoring.
Where complexity lacks a credible economic or commercial rationale, it should remain an important financial crime risk indicator.
AI and deepfakes are changing the onboarding risk
Technology is also changing the nature of financial crime risk.
Generative AI, synthetic identities and deepfake technology increasingly challenge traditional approaches to customer identification and remote onboarding.
Institutions may now need to consider risks involving artificially generated identity documents, manipulated images, deepfake video or voice verification, automated impersonation and increasingly sophisticated social engineering.
This creates a growing need to view digital onboarding controls more holistically.
Identity verification + fraud risk + cyber risk + financial crime risk
These areas cannot always be managed effectively in isolation.
For institutions with significant digital or remote onboarding channels, testing whether existing controls remain appropriate in an AI-enabled environment should increasingly form part of the financial crime risk agenda.
Data is becoming a financial crime control
Another emerging theme is the role of data itself.
Customer due diligence, sanctions screening, transaction monitoring, beneficial ownership analysis and regulatory reporting all depend on complete and reliable information.
Poor-quality or fragmented data can therefore undermine several financial crime controls simultaneously.
As financial crime compliance becomes increasingly integrated and transaction-focused, institutions should consider whether their data environments allow them to understand customers, identify counterparties, monitor activity, investigate alerts and produce reliable regulatory reporting.
Data quality should consequently be viewed not simply as an operational issue, but as an important element of financial crime control effectiveness.
The question institutions should be asking
For the remainder of 2026, one question should sit behind many of these developments:
Could we demonstrate to a regulator that our financial crime framework is operating effectively, rather than simply demonstrate that it exists?
Answering that question requires institutions to look beyond individual policies and controls.
Governance, people, process, technology, data and risk need to operate as parts of the same financial crime control environment. Weaknesses frequently emerge not because an individual control is entirely absent, but because different components of the operating model do not work effectively together.
Read the Full FCRMC Q3 2026 Financial Crime & Regulatory Update
This article highlights only some of the issues covered in FCRMC’s Q3 2026 Financial Crime & Regulatory Update.
The full newsletter explores these developments in greater detail, including:
- The evolving risk-based approach and recent regulatory guidance;
- Proliferation financing and targeted financial sanctions;
- Crypto assets and transaction-level transparency;
- Beneficial ownership;
- Continuing DNFBP supervisory attention;
- AI, deepfakes and digital identity;
- Asset recovery and financial intelligence;
- FCRMC’s key compliance priorities for the remainder of 2026.
To receive the full Q3 2026 Financial Crime & Regulatory Update, contact us.
