An R28m administrative penalty for shortcomings under the Financial Intelligence Centre Act (FICA), is a timely reminder that compliance cannot be treated as a once-off exercise.

Sameer Kumandan, managing director, SW360 says the recent enforcement actions need to be seen as opportunities, not just warnings (Image supplied)
What stands out to me in this latest regulatory action against a major financial institution is not the size of the penalty, or even the institution involved, but the nature of the shortcomings identified.
These included gaps in customer due diligence, enhanced and ongoing due diligence, employee training, screening, terrorist property reporting and aspects of the organisation’s risk-management and compliance programme.
An important distinction
These are not isolated compliance activities.
They are connected parts of an ongoing process designed to help organisations understand who they are dealing with, assess the risks involved and respond when those risks change.
That distinction is important.
Ongoing due diligence matters
Too often, compliance is still viewed as an onboarding event: verify the customer, collect the documentation, complete the checks and move on.
But a customer's risk profile does not remain static simply because the initial verification was completed successfully.
Ownership can change.
A person can become a politically exposed person. Sanctions lists can change.
A business can develop new activities or relationships. Transaction behaviour can shift.
Information that was accurate when a relationship began may no longer provide an accurate picture months or years later.
This is why ongoing due diligence matters.
Sameer Kumandan 4 Dec 2024 The right systems
The other lesson is that compliance cannot depend solely on people remembering to perform manual checks at the right time.
As organisations become larger and customer volumes increase, relying on disconnected spreadsheets, manual processes and periodic reviews creates opportunities for things to fall through the cracks.
Technology has an important role to play here, not as a replacement for human judgement, but as an enabler of better, more consistent processes.
The right systems can help organisations verify information, identify changes, screen against relevant risk indicators, maintain records and create an electronic audit trail.
They can also help bring different compliance activities into a more connected workflow, making it easier to identify where further investigation or enhanced due diligence may be required.
Technology only one part
But technology is only one part of the solution.
Organisations also need clearly defined policies, appropriately trained employees, accountable management, regular review of risk and processes that are actually followed in practice.
A policy sitting in a compliance manual is of little value if employees do not understand it or if the organisation cannot demonstrate how it is being applied.
Manageable risks
The encouraging point is that these risks are manageable.
The objective should not be to create layers of bureaucracy that slow legitimate business down.
It should be to build compliance into the way the business operates, so that verification, screening, monitoring and risk assessment happen as naturally as other critical business processes.
An opportunity more than a warning
Recent enforcement actions should therefore be viewed as more than warnings about the potential financial consequences of non-compliance.
They are reminders that effective compliance is ultimately about being prepared before the regulator arrives, rather than because the regulator has arrived.
For accountable institutions, the question worth asking now is simple: if our compliance processes were tested tomorrow, could we demonstrate not only that we have the right policies, but that they are working in practice?
If the answer is uncertain, that is not necessarily a reason for alarm.
It is an opportunity to identify the gaps, strengthen the processes and address them before they become a much more expensive problem.