Financial Crime Risk Governance in 2026: Key Insights from FCRMC’s Q4 Newsletter

As 2026 draws to a close, one message has become increasingly clear across financial crime regulation, supervision and enforcement: having the right policies and frameworks is no longer enough.

Institutions are increasingly expected to demonstrate that their financial crime controls are current, appropriately designed, implemented and operating effectively in practice.

For senior management and Boards, this changes the question.

It is no longer simply:

“Do we have an RMCP?”

The more important question is:

“Can we demonstrate that our RMCP is current, approved, implemented, supported by appropriate data and operating as intended?”

That distinction between documentation and demonstrable effectiveness is likely to remain one of the defining financial crime risk themes as organisations move into 2027.

The risk-based approach is becoming more explicit

The publication of Guidance Note 7B in August 2026 reinforced the direction of South Africa’s risk-based financial crime framework.

Institutions need to demonstrate a clear relationship between the risks they identify and the controls they apply. This includes consideration of money laundering, terrorist financing and proliferation financing risks, as well as risks arising from new products, technologies, delivery mechanisms and changes to existing business practices.

The practical control chain should be clear:

Risk Factor → Risk Assessment → Risk Rating → Control → CDD / Monitoring → Review

Each stage should logically inform the next.

A customer classified as higher risk should, for example, experience a meaningfully different control environment from a lower-risk customer. This may affect the extent of due diligence performed, the level of approval required, the frequency of review, the intensity of monitoring and the nature of ongoing oversight.

Similarly, where simplified due diligence is applied, institutions should be able to demonstrate the basis on which the lower-risk classification was made.

The critical issue is defensibility.

If an institution cannot trace the relationship between its identified risks, customer ratings, controls and monitoring activities, it may struggle to demonstrate that its risk-based approach is operating effectively.

RMCPs are becoming more visible regulatory deliverables

Directive 12 represents another important development.

For specified Schedule 1 accountable institutions, submission of the approved Risk Management and Compliance Programme to the Financial Intelligence Centre is now an annual regulatory requirement.

The immediate 2026 submission dates include:

• 9 October 2026 for specified Schedule 1 items 1, 2, 9 and certain item 11 credit providers; and
• 31 October 2026 for specified institutions falling under items 3, 14, 20, 21 and 22.

Affected newly established institutions are required to submit within 90 days of commencing business, while subsequent approved RMCP updates may also need to be submitted within the prescribed period following approval.

This elevates the RMCP from an internal compliance document to a regulatory deliverable that institutions should expect to be scrutinised.

The practical implication is significant.

An RMCP should not merely contain technically correct wording. It should accurately reflect how the institution identifies risk, assigns responsibility, performs customer due diligence, monitors activity, manages sanctions exposure, reports suspicious activity and oversees the effectiveness of its controls.

A document that describes one process while the business follows another creates an immediate vulnerability.

Enforcement is testing what happens in practice

Recent supervisory and enforcement activity provides a useful indication of what regulators are looking for.

Administrative sanctions announced during Q3 2026 highlighted recurring themes around customer due diligence, enhanced due diligence, ongoing monitoring, risk methodology, reporting, sanctions controls, employee training and RMCP implementation.

The wider lesson is not limited to the institutions involved.

Regulatory testing is increasingly capable of tracing weaknesses from governance and methodology through to customer files and individual control outcomes.

A policy may state that enhanced due diligence is required for high-risk customers. The relevant question during an inspection may therefore become:

Can the institution produce a sample of high-risk customer files and demonstrate that enhanced due diligence was actually performed?

The RMCP may require ongoing due diligence.

Can the institution demonstrate that ongoing review took place throughout the customer relationship?

A methodology may describe customer risk factors and weightings.

Can management explain why those factors were selected, how they affect risk ratings and what changes when a particular risk threshold is reached?

The existence of a framework is increasingly only the starting point.

Evidence of implementation is what makes that framework defensible.

Beneficial ownership remains a critical control

Beneficial ownership also continues to attract regulatory attention.

Institutions should be able to identify the natural persons who ultimately own or control customers and understand the structures through which that ownership or control is exercised.

This becomes particularly important where structures involve multiple legal entities, trusts, nominees, offshore elements or arrangements that obscure the underlying parties.

A robust beneficial ownership process should therefore extend beyond simply collecting declarations.

Institutions should consider whether they:

• identify the natural persons who ultimately own or control the customer;
• understand intermediate entities and control arrangements;
• verify information through reliable and independent sources proportionate to risk;
• escalate material discrepancies or unnecessarily complex structures; and
• incorporate beneficial owners into PEP/PIP, sanctions, adverse-media and other relevant monitoring processes.

Beneficial ownership should ultimately operate as part of the broader customer risk framework rather than as a standalone onboarding exercise.

Namibia moves from remediation to sustainability

The financial crime risk environment is also evolving elsewhere in Southern Africa.

Namibia’s removal from FATF increased monitoring in June 2026 represented a significant milestone. However, removal from the grey list should not be interpreted as the end of the process.

The next challenge is sustainability.

The improvements introduced during the remediation period now need to become embedded within business-as-usual governance, controls, assurance and management oversight.

For Boards and executive teams, useful questions include:

• Are money laundering, terrorist financing, proliferation financing and sanctions risks reflected in the current institutional risk assessment?
• Do sanctions-list changes result in timely screening, escalation and reporting?
• Are beneficial ownership and high-risk customer controls operating consistently across the organisation?
• Are cross-border and correspondent-banking risks being appropriately managed?
• Are wider governance and fit-and-proper requirements being integrated with financial crime governance rather than treated as separate regulatory exercises?

A successful remediation programme is only valuable if its improvements continue once the immediate regulatory pressure has reduced.

Global financial crime standards continue to evolve

Developments at FATF level also indicate where financial crime programmes are likely to move over the coming years.

Payment transparency is becoming increasingly important. The strengthened international focus on originator and beneficiary information means payment data quality should increasingly be viewed as a financial crime control issue.

CDD information, payment-message data, transaction monitoring and sanctions screening cannot operate effectively as completely separate datasets.

Institutions need information that is complete, reliable, traceable and capable of being reconciled.

Professional money laundering and informal value-transfer systems also remain significant concerns, particularly where regulated and unregulated financial channels intersect.

For institutions operating in Southern Africa, this heightens the importance of understanding unusual third-party payments, unexplained cross-border settlements, trade-linked flows, informal remittance activity and networks capable of moving value outside traditional banking channels.

At the same time, fraud, cybercrime, artificial intelligence, synthetic identity and deepfake technologies are increasingly converging with traditional financial crime risks.

The organisational response will need to converge as well.

Financial crime, fraud, cyber, technology and customer-onboarding teams cannot address these risks effectively through isolated control environments.

What should Boards and executives prioritise for 2027?

The end of the year provides an opportunity to move beyond annual compliance planning and consider whether the institution’s financial crime programme is genuinely aligned to its risk environment.

Several priorities should form part of that discussion.

Link the 2027 plan to the actual risk assessment

The financial crime plan should respond to the institution’s current money laundering, terrorist financing, proliferation financing and sanctions risks rather than functioning as a generic annual compliance workplan.

Obtain assurance over implementation

Management should understand whether key controls are actually operating as intended across areas such as CDD, EDD, sanctions, transaction monitoring, regulatory reporting, high-risk customers and employee training.

Test whether risk ratings change control outcomes

Risk categorisation only has value where it affects the way the customer or activity is managed.

Boards should understand whether different risk ratings genuinely result in different review frequencies, approval requirements, monitoring intensity and due diligence measures.

Treat data quality as a control dependency

Customer information, beneficial ownership data, payment information, screening records and monitoring data should be complete, traceable and capable of being reconciled.

Weak data can undermine otherwise well-designed controls.

Strengthen new-product and technology governance

Material changes, new products, emerging technologies and AI-enabled processes should include documented financial crime risk assessment before implementation.

Make remediation accountable

Issues identified through compliance monitoring, internal audit, regulatory reviews or independent assessments should have clear ownership, deadlines and evidence-based closure criteria.

Closing an action should mean demonstrating that the underlying weakness has been addressed, not simply recording that an action has been completed.

A useful year-end Board question

Perhaps the most useful challenge a Board can put to management is a simple one:

“If a regulator selected a sample of our customers, alerts, reports and sanctions decisions tomorrow, could we demonstrate that our documented framework produced the intended control outcome in practice?”

The answer should be supported by evidence rather than assurance statements alone.

From technical compliance to demonstrable effectiveness

The defining lesson of 2026 is that financial crime compliance is increasingly becoming an operating-model discipline rather than a collection of isolated regulatory obligations.

Governance. People. Processes. Technology. Data. Risk.

Each component needs to reinforce the others.

Institutions that can demonstrate how these components work together will be better positioned to maintain regulatory confidence, respond to emerging threats and demonstrate the effectiveness of their financial crime controls.

As organisations prepare for 2027, the focus should therefore extend beyond asking whether the required framework exists.

The more important question is whether it works.

How FCRMC can assist

FCRMC supports organisations in moving from technical compliance towards demonstrable financial crime control effectiveness.

Our work includes financial crime risk assessments, RMCP development and enhancement, independent reviews, Board and executive training, sanctions and proliferation-financing frameworks, beneficial ownership, operating-model assessments, DNFBP compliance support and inspection readiness.

If your organisation is reviewing its financial crime framework, preparing its 2027 compliance priorities or assessing whether existing controls can be evidenced in practice, contact FCRMC to discuss how we can assist.