A customer at a Capitec branch watches the teller process a new account application, unaware that the bank is under a regulator’s microscope.
According to news24.com, the Financial Intelligence Centre (FIC) imposed a R28m monetary penalty on Capitec after finding the bank fell short of its obligations under the Financial Intelligence Centre Act (FICA), the law that forces financial institutions to verify customers’ identity and monitor transactions for money-laundering risk.
What FICA means for banks
FICA requires banks to keep detailed records, report suspicious activity and maintain robust know-your-customer (KYC) procedures. Failure to meet these standards can trigger fines, sanctions or even licence restrictions.
For small and medium-sized enterprises that rely on quick account opening and credit facilities, tighter compliance can translate into longer waiting times and more documentation. While the cost of compliance is ultimately borne by the institution, banks may pass some of that expense onto business customers through higher fees or reduced service levels.
The regulator also announced a sanction against asset manager Ninety One for similar FICA shortcomings, but the statement did not disclose the size of the penalty or the exact remedial actions required.
These enforcement actions come as South African banks face growing pressure to strengthen anti-money-laundering controls. Recent years have seen several institutions fined for lapses, prompting industry-wide reviews of KYC processes and investment in compliance technology.
Capitec has said it will review its internal controls and work with the FIC to address the gaps identified. Ninety One, which manages a range of investment funds, issued a brief comment confirming it is cooperating with the regulator.
What FICA actually requires a bank to do
The Financial Intelligence Centre Act requires every accountable institution, banks foremost among them, to verify a customer’s identity before opening an account, keep records of that verification, and monitor transactions on an ongoing basis for patterns consistent with money laundering or the financing of terrorism, reporting anything suspicious to the Financial Intelligence Centre. The obligation does not end at account opening: a bank that verified a customer correctly five years ago can still be found non-compliant today if its ongoing monitoring processes have not kept pace with how that customer’s transaction patterns have changed.
A fine of this size against an institution the size of Capitec is a meaningful compliance finding rather than a business-threatening one, and the FIC’s own enforcement pattern in recent years has trended toward larger, more frequent penalties against major banks as part of a broader push to keep South Africa off international money-laundering grey lists. For related coverage of a different sector facing regulatory sanction the same week, see this site’s report on the greenwashing rulings against TotalEnergies, Shell and CNG Holdings.
Why FICA compliance costs have risen for every bank, not just the ones fined
South Africa’s inclusion on international grey lists for anti-money-laundering deficiencies in recent years pushed every accountable institution, fined or not, to spend considerably more on compliance staff, transaction-monitoring software and customer due diligence than a decade ago. That spending is a direct cost of doing business rather than a discretionary one, since a bank found persistently non-compliant risks correspondent banking relationships with international partners being restricted, which would be a far larger commercial problem than any single administrative fine.
For an SME banking with either institution, the practical effect of tighter FICA enforcement is usually felt as more paperwork at account opening and more frequent requests to re-verify documentation, rather than any change to day-to-day account use. That friction is the visible cost of a compliance regime working as intended: a bank that never asks its customers to update outdated verification documents is a bank that is not actually monitoring the risk FICA exists to manage.



