Compliance Update July 2026: Grey-List Exit, RCR Deadlines and Recent Information Regulator Rulings
South Africa is off the FATF grey list, but the next Mutual Evaluation is already underway and supervisors now want evidence, not documents. Plus RCR deadlines, third-party record storage, new cash declaration rules and two recent Information Regulator findings.
Welcome to the first edition of our Anti-Money Laundering (AML) and data privacy compliance update, produced in partnership with DataCloud.
We break down what has changed in the South African anti-money laundering and data protection landscape, what it means for your business, and what practical steps you can take. The aim is clarity and jargon-free guidance, so your business can stay informed, manage risk and navigate an increasingly complex regulatory environment.
South Africa is off the grey list, but vigilance still matters
In February 2023, South Africa was placed on the Financial Action Task Force's (FATF) grey list, a sophisticated way of saying the country was flagged internationally for having gaps in its money laundering and terrorism financing controls. After three years of reform, in October 2025, South Africa was removed from that list.
This might sound like good news, but it is not a signal to relax just yet. FATF is already back at our doorstep. Their next full review of South Africa, called a Mutual Evaluation, began in the first half of 2026 and runs through to October 2027. This time they are not only checking whether you have the correct policies, they want to see how those policies operate in your day-to-day business. That means tighter controls, more inspections and more regulatory reviews.
It is important to note that the getting-ready phase is over. The Financial Intelligence Centre (FIC) will be looking for evidence of the practical implementation of your Risk Management and Compliance Programme (RMCP). A well-drafted RMCP on file will not be deemed sufficient. The moment you put your name on an RMCP template, it is not a template anymore, and you will be expected to evidence that you are doing what your RMCP says you are doing.
What you can do to firm up your implementation
- Check that your business is correctly registered on the FIC goAML system, including the correct business type. Make sure that your Compliance Officer, Money Laundering Reporting Officer and system administrators are up to date, especially after staff changes.
- Check your FIC message board regularly. Notices do not wait for you to log in.
- Keep your sanctions screening current. These lists change often, so make sure your client database is being checked against them consistently.
- Review and refresh your risk assessments, and check whether they are aligned to the relevant sectoral risk assessment. AML risk exposure is constantly evolving.
- Train staff at least once a year so they can identify warning signs and meet FICA requirements.
- Screen all new employees when they join the business and make this part of your recruitment process. Employee screening is not a once-off exercise.
- Review your RMCP at least annually.
- Ensure that you upload the latest version of your RMCP to your profile on the goAML system.
Understandably, these obligations may sound overwhelming when you also have a full-time business to run. This is where good anti-money laundering software can help. If your current process still feels like a juggling act, it is worth taking a closer look at what DataCloud can do for you.
Risk and Compliance Returns: who still needs to act
The FIC set the following deadlines for Risk and Compliance Return submissions by accountable institutions.
Due 30 June 2026:
- Trust and company service providers
- Casinos
- Credit providers, excluding banks, mutual banks and co-operative banks
- Crypto asset service providers
- South African Postbank
- South African Mint Company
Due 31 July 2026:
- Legal practitioners
- Estate agents
- Gambling institutions other than casinos
- High-value goods dealers, including dealers in precious metals and stones, Krugerrands, motor vehicles and art
If this applies to you and you have not yet filed, we encourage you to address it without delay.
Consequences of missing the deadline
Missing the deadline carries significant regulatory risk, and the consequences should not be underestimated. The FIC has consistently demonstrated its enforcement capacity, and non-compliance has resulted in hefty fines and penalties for accountable institutions.
One example is Tlholakae Attorneys Inc, a law firm that missed its 2023 return and was fined R50,000. The firm ultimately avoided paying the full amount because it submitted the return late and was able to negotiate a reduced R10,000 penalty as a result. Even then, the penalty had to be paid by a strict cut-off date.
The lesson is clear: a missed deadline should not be met with silence. Dealing with it now, even though it is late, will likely be far cheaper than ignoring it.
Should you require assistance with your RCR submission, the LetsComply team is ready to help.
Third-party record storage: an overlooked obligation
If someone else keeps FICA records on your behalf, whether a storage company, an outsourced provider or a cloud system, you are required to tell the FIC or your relevant supervisory body. This is not limited to boxes in a warehouse. It applies just as much to third-party digital record-keeping systems.
You will need to share details such as who the third party is, where the records are kept physically or digitally, who controls access to them, and who at your business manages that relationship.
While this is a relatively minor administrative requirement, it is frequently overlooked. We recommend taking a moment to assess whether it applies to your business, whether you have notified the FIC accordingly, and whether that notification has been saved as evidence.
Carrying cash across the border
If you or your clients travel with cash or foreign currency worth more than R100,000, there is a new rule to know about. From 1 July 2026, this must be declared through the Customs and Excise traveller management system when crossing South African air, land or sea borders. SARS will then share these declarations with the FIC.
Worth flagging to anyone in your business who travels internationally with cash on hand.
Recent Information Regulator cases and what they mean
Case 1: The "oops" email, Central Johannesburg TVET College
A staff member accidentally emailed a folder containing personal information, including sensitive background check results, to colleagues who were not entitled to see it. The email was recalled two days later with an apology and an explanation that it was an honest mistake.
The "we recalled it" explanation was not enough. The Information Regulator still found the college non-compliant with POPIA, and required it to update its Information Officer registration, apologise formally to affected staff, and review its data protection policies.
The key takeaways:
- Make sure your Information Officer and Deputies are registered on the Information Regulator's platform, and that registrations are kept up to date.
- Store personal information in restricted, access-controlled folders rather than on general shared drives.
- Build a control into your day-to-day processes to double-check before pressing send on anything containing personal information. One accidental email can count as a breach, even if it is caught quickly.
- Review your data protection safeguards on an ongoing basis to ensure your business is adequately protected against cyber attacks.
- Make sure your core policies, including privacy, PAIA, retention, business continuity and incident response, are reviewed, practically implemented, and that your staff are trained on them.
Case 2: When "confidential" is not a valid excuse, Sibanye-Stillwater
A research organisation asked a mining company for copies of its compliance reports under PAIA. The company refused, arguing the reports were commercially sensitive and could be misunderstood if released. The Information Regulator disagreed and ordered that the records be handed over.
This case highlights that where a business refuses to share a record, the responsibility is on that business to prove why the refusal is justified, not on the person asking. Being compliant with the law is not the same as holding a trade secret, and worrying that information might be taken out of context is not a valid reason to withhold it. Transparency generally wins over reputational discomfort.
The key takeaways:
- Take time to identify and classify the information your business holds. Understand and document what is freely available on request, and what would require a formal PAIA application.
- Have a clear process in place to handle these requests promptly and within the required timeframes.
- Before refusing any request, make sure you fully understand the legal grounds for refusal and when they genuinely apply. "We would rather not" and "it might look bad" simply will not hold up.
- Ensure that your staff and Information Officers are trained not only on POPIA but also on PAIA and your relevant policies.
Need help?
LetsComply is your compliance partner. If any of the above applies to your business and you are not sure where you stand, get in touch and we will walk through it with you.
This update is prepared for information purposes only and does not constitute legal advice.