Compliance Update July 2026: Grey-List Exit, RCR Deadlines and Recent Information Regulator Rulings
South Africa is off the FATF grey list, but the next Mutual Evaluation is already underway and supervisors now want evidence, not documents. Plus RCR deadlines, third-party record storage, new cash declaration rules and two recent Information Regulator findings.
Welcome to the first edition of the Anti-money Laundering (AML) and Data Privacy compliance newsletter.
We will break down what has changed in the South African anti-money laundering and data protection landscape, what it means for your business and what practical steps you can take. The purpose of this breakdown is to provide clarity and jargon-free guidance to enable your business to stay informed, manage risks and navigate an increasingly complex regulatory environment. _________________________________________________________________________________
Anti-money Laundering (AML) – Financial Intelligence Centre Act
South Africa is officially off the grey-list however significant work and vigilance remains.
In February 2023, South Africa was placed on the Financial Action Task Force's (FATF) "grey-list", a sophisticated way of saying that South Africa was flagged, internationally, for having gaps in their money laundering and terrorism financing controls. After three years of reform, in October 2025, South Africa was removed from that list. This might sound like good news, but it is not a signal to relax just yet. FATF is already back at our doorstep. Their next full review of South Africa, called a Mutual Evaluation, began in the first half of 2026 and runs through to October 2027. This time, they are not only checking if you have the correct policies, but they want to see how those policies operate in your day-to-day business. This means tighter controls, more inspections, and regulatory reviews.
It is important to note that the "getting ready" phase is over. The Financial Intelligence Centre (FIC) will be looking evidence of the practical implementation of your Risk Management and Compliance Programme (RMCP). The fact that you may have a well drafted RMCP on file will not be deemed sufficient. The moment you put your name on an RMCP template, it is not a template anymore and you will be expected to evidence that you are doing what your RMCP says you are doing.
What can you do to firm up your implementation?
- Check that your business is correctly registered on the FIC goAML system, including the correct business type. Also make sure that your Compliance Officer, Money Laundering Reporting Officer and system administrators are up to date, especially after staff changes.
- Check your FIC message board regularly. Notices do not wait for you to log in.
- Keep your sanctions screening current. These lists change often, so make sure your client database is being checked against them consistently.
- Review and refresh your risk assessments and check whether it is aligned to the relevant sectorial risk assessment. Remember that AML risk exposure is constantly evolving.
- Train staff at least once a year so they can identify warning signs and meet FICA requirements.
- Screen all new employees when they join the business and make this part of your recruitment process. Employee screening is not a once off exercise.
- Review your RMCP at least annually.
- Ensure that you upload the latest version of your RMCP on your profile on the goAML system.
Understandably all these obligations may all sound overwhelming considering that you have a full-time business to run. This is where good anti-money laundering software could help. If your current process still feels like a juggling act, it is worth taking a closer look at what DataCloud can do for you.
Risk and Compliance Returns: who still needs to act?
See below the deadlines for the submissions of the returns to the FIC for the various Accountable Institutions.
| Sector | Deadline |
|---|---|
| Trust and Company Service Provider | 🔴 30 June 2026 |
| Casinos | 🔴 30 June 2026 |
| Credit Providers excl. banks, mutual banks and co-operative banks | 🔴 30 June 2026 |
| Crypto Asset Service Providers | 🔴 30 June 2026 |
| South African Post Bank | 🔴 30 June 2026 |
| South African Mint Company | 🔴 30 June 2026 |
| Legal Practitioner | 🟠 31 July 2026 |
| Estate Agents | 🟠 31 July 2026 |
| Gambling institutions (non-casinos) | 🟠 31 July 2026 |
| High-Value Goods dealers (dealers in precious metals, stones, Kruger rands Motor dealerships, Art dealers etc.) | 🟠 31 July 2026 |
If this applies to you and you have not yet filed, we encourage you to address it without delay.
Consequences of missing the deadline
Missing the deadline carries significant regulatory risk, the consequences of which should not be underestimated. The FIC has consistently demonstrated its enforcement capacity, and non-compliance has resulted in hefty fines and penalties for accountable institutions. One such example is, Tlholakae Attorneys Inc, a law firm who missed its 2023 return and was fined R50,000. They ultimately avoided paying the full fine because they submitted the return late and were able to negotiate a reduced R10,000 penalty as a result thereof. However, even the penalty had to be paid by a strict cut-off date. The lesson here is clear: a missed deadline should not be met with silence. Dealing with it now, even though it is late, will likely be far cheaper than ignoring it.
Should you require assistance with your RCR submission, the LetsComply team are ready to help.
Third-Party Record Storage: An overlooked compliance obligation
If someone else, a storage company, an outsourced provider, even a cloud system, keeps FICA records on your behalf, you are required to tell the FIC or your relevant supervisory body. It is not limited to boxes in a warehouse, it applies just as much to third-party digital record-keeping systems.
You will need to share details such as who the third party is, where the records are physically or digitally kept, who controls access to them, and who at your business manages that relationship. While this may be a relatively minor administrative requirement, this step is frequently overlooked. We recommend taking a moment to assess whether this applies to your business, if you have notified the FIC accordingly and has the notification been saved as evidence.
Here is what you need to know if you carry cash across the border
If you or your clients travel with cash or foreign currency worth more than R100,000, there is a new rule to know about. From 1 July 2026, this must be declared through the Customs and Excise traveller management system when crossing South African air, land, or sea borders. SARS will then share these declarations with the FIC. Worth flagging to anyone in your business who travels internationally with cash on hand.
Data Privacy & Access to Information – Protection of Personal Information Act (POPIA) and Promotion of Access to Information Act (PAIA)
Recent Information Regulator Cases and their implications
Case 1: The "oops" email - Central Johannesburg TVET College (CJC)
A staff member accidentally emailed a folder, containing personal information which included sensitive background check results, to colleagues who were not entitled to the information. The email was recalled two days later with an apology and explanation that it was an honest mistake. Unfortunately, the "we recalled it" explanation was not enough. The Information Regulator still found CJC to be non-compliant with POPIA, and required it to update its Information Officer registration, apologise formally to affected staff, and review its data protection policies.
The key takeaways:
- Make sure your Information Officer and Deputies are registered on the Information Regulators platform and that registrations are kept up to date.
- Store personal information in restricted, access-controlled folders and not on general shared drives.
- Build in a control into your day-to-day business processes to double-check before you press send on anything containing personal information. One accidental email can count as a breach, even if it is caught quickly.
- Review your data protection safeguards on an ongoing basis to ensure that your business is adequately protected against cyber-attacks.
- Make sure your core policies which include privacy, PAIA, retention, business continuity and incident response are reviewed, practically implemented and your staff are trained on the policies.
Case 2: When "confidential" is not a valid excuse – Sibanye Still Water
A research organisation asked a mining company for copies of its compliance reports under PAIA. The company refused, arguing the reports were commercially sensitive and could be misunderstood if released. The Information Regulator disagreed and ordered that the records be handed over.
This case highlights that if a business is refusing to share a record, the responsibility is on that business to prove why it is justified, not on the person asking. Being compliant with the law is not the same as holding a trade secret and worrying that information might be taken out of context is not a valid reason to withhold it. Transparency generally wins over reputational discomfort.
The key takeaways:
- Take time to identify and classify the information your business holds. Understand and document what is freely available on request, and what would require a formal PAIA application.
- Have a clear process in place to handle these requests promptly and within the required timeframes.
- And before refusing any request, make sure you fully understand the legal grounds for refusal and when they genuinely apply as "we would rather not" or "it might look bad" simply won't hold up.
- Ensure that your staff and Information Officers are trained on not only POPIA but also PAIA and your relevant Policies.
This newsletter is prepared for information purposes only and does not constitute legal advice. Questions or topics you would like to have covered? Reply to LetsComply with your suggestions