Let’s do the compliance. You do the business.
Two laws cause most of the headaches. FICA is about keeping dirty money out of your business. POPIA is about looking after the personal details you hold on people. Between us we’ve got thirty years of both behind us, and we turn that into something your business can actually run. We stay until your team can run it without us.
What we do
Anti-Money Laundering
If FICA applies to your business, this is the work it asks for. Knowing who your clients really are. Checking them against sanctions lists. Watching transactions, and reporting anything that looks wrong.
02POPIA & PAIA Compliance
Privacy policies, the PAIA manual the law says you must publish, registering your Information Officer, and a check of where you stand against POPIA. One regulator runs both laws, and between them they reach almost every business.
03RMCP & Custom Policies
Your written plan for spotting dirty money, built around your risks and your industry's. An RMCP is what the law calls it. What it is not is a template with your name on it.
04Gap Analysis
An outside look at where your compliance falls short of what regulators expect, while the gaps are still cheap to fix.
05Staff Training
Compliance training in plain language, built around the decisions your staff actually make. We record it too, so you can show it happened.
06Implementation Support
Hands-on help turning the plan into something your team actually does. Checklists, registers, simple routines, and support while it settles in.
The best compliance programme is the one your team actually uses.
Programmes almost never fail because of the writing. They fail on a Tuesday afternoon, when a new client needs signing up and nobody’s sure whose job the checks are.
They fail again when an inspector asks you to show what you have been doing all along. A policy in a folder won’t answer that. What answers it is a dated record: who did the check, when, and what they found.
Built around your business, not businesses in general
We start with how criminals actually go after businesses like yours. The regulator publishes this for every industry. Then we look at where your own weak spots are.
A to-do list, worst problem first
We rank the gaps by how much risk they carry, not alphabetically. So the time you can spare goes where it matters most.
Ready if someone asks
The people who signed it off can tell you what’s in it. The annual review actually happens. And the current version is where an inspector would look for it.
It lives in the business, not on a shelf
We hand each job to the person who’ll actually be doing it, then stay close for the first few months. That’s when a new routine is easiest to drop.
The four problems we see most
None of these is a missing document. They’re all the same problem: your programme says one thing, and you can’t show it actually happened. All four are quick to fix.
You did the checks. Can you prove it?
The work gets done. What goes missing is the record of it. And the record is the only part anyone else can see.
You screened them once, on day one.
Sanctions lists change. A client who was clean when they signed up might not be a year later. One check at the start doesn’t cover that.
You trained the team. Nobody wrote it down.
An inspector will ask who came, what was covered and when. If nobody wrote it down, it looks the same as training that never happened.
Someone left. The paperwork still has their name on it.
Two records have to name a real person: your registration with the Financial Intelligence Centre, and whoever you registered as responsible for personal data. When someone resigns, both quietly go out of date. Both take a supervisor a minute to check.
Where things stand right now
Read insights →South Africa came off the grey list. That’s the international watchlist for countries with weak controls on dirty money. It changed the country’s reputation, not what’s asked of your business.
International inspectors are reviewing South Africa again, until October 2027. This time they look at how checks work day to day, not at what the policy says.
R50m
The largest fine a business can be given for serious FICA failures.
R10m
For ignoring an official order to fix a data problem. It can also mean a prison sentence.
In our clients’ words
Attorneys, estate agents, accountants, healthcare practices and more. From one-person practices to groups with branches.
“LetsComply’s expertise and proactive guidance gave us confidence from day one. They helped us close key gaps and ensure full compliance with privacy laws.”
“Knowledgeable, approachable, and always willing to go the extra mile. Thanks to LetsComply, we now have a strong framework to manage privacy risks.”
“Professional, practical, and precise. Their training was clear, relevant, and easy to follow. Our team left with confidence in our responsibilities.”
“A clear needs analysis that highlighted our compliance gaps and delivered fit-for-purpose training. Our team is now far better equipped to manage compliance.”
Let’s start with a free consultation.
We work out which rules actually apply to you, and where you stand today. Nothing else has to follow from it. And it’s much better to find a gap yourself than to have an inspector find it for you.