Sanctions, FATF and POPIA: What Is Trending Today?
Featuring FATF blacklisted countries, sanctions list updates, Information Officer obligations and POPIA impact assessments.
In a fast-changing compliance environment, staying informed is essential. As spring arrives, September offers the perfect opportunity to refresh your compliance framework, review key obligations and reset priorities for the months ahead.
FICA, FATF and Sanctions: Are You Keeping Up?
What is new: FIC issues Guidance on risk-based compliance.
Missed last month's updates? We covered the Directive 10 deadline for FIC profile updates, the proposed RMCP upload requirements under Draft Directive 12, and the release of Guidance Note 7B, which provides further clarity on implementing a risk-based approach. Stay ahead by ensuring these developments are on your radar and if you have not updated your FIC profile with your geographical location, start immediately.
The FIC also released Guidance Note 7B, providing practical insight into the effective implementation of a risk-based approach.
| Key takeaways | Explanation |
|---|---|
| No simplified due diligence where suspicion exists. | A simplified due diligence may not be applied where there is any suspicion of money laundering, terrorist financing or proliferation financing. |
| Heightened focus on Proliferation financing. | Accountable Institutions must consider proliferation financing risks alongside money laundering and terrorist financing when assessing and mitigating financial crime risks. |
| Technology brings new risk. | The FIC expects institutions to assess and document risks arising from new technologies and business models, including AI, digital onboarding, automated monitoring systems, embedded finance and payment innovations. |
| Avoid assumptions about low-income clients. | Under-served or low-income clients should not automatically be considered lower risk. Risk ratings must be based on objective information and a proper risk assessment, not assumptions about a client's financial position. |
FATF Blacklisted Countries: A Red Flag for Enhanced Due Diligence
The Financial Action Task Force (FATF) blacklist currently contains three countries: Iran, North Korea and Myanmar. These countries are blacklisted due to serious systematic failures as well as their refusal to cooperate. FATF member countries are required to apply enhanced due diligence proportionate to the risk and, in the most serious cases, countermeasures, which can include restricting or prohibiting financial transactions entirely.
| Country | Key deficiencies | Countermeasures |
|---|---|---|
| Iran |
|
|
| North Korea |
|
|
| Myanmar |
|
|
A New Sanctions Update Has Landed. What's Your Next Move?
The Financial Intelligence Centre (FIC) regularly updates the domestic Targeted Financial Sanctions (TFS) list within 24 hours of any amendments made by the United Nations Security Council (UNSC).
When the list is updated:
- Accountable institutions must screen clients against the most current list at onboarding and continuously when the client transacts with the institution.
- If there’s a match, freeze assets under your control without delay, and file a Terrorist Property Report (TPR) with the FIC.
- Cease transacting with the client
Transacting with a listed entity/person or failing to adhere to TFS screening requirements constitutes a criminal offence.
Newsletter Tip: looking for a more automated solution to this requirement? Did you know that the DataCloud system can automatically screen your clients against the TFS updates with minimal involvement from you? Contact them to find out more.
Review, Refresh, Repeat: Why RMCP Updates and Annual Training Matter
An RMCP cannot be a static, "plug-and-play" template copied from the FIC Act and must reflect the actual ML/TF/PF risks of the business.
- Frequency: The Financial Intelligence Centre (FIC) expects an RMCP to be a "living document" reviewed at least annually.
- Trigger Events: Beyond annual reviews, you must update the document immediately if there are changes to legislation, financial sanctions lists, product offerings, delivery channels, or client risks.
- All updates to the RMCP require formal sign-off and approval from senior management or the board of directors.
Training employees on the RMCP is a mandatory legislative obligation.
- New employees must be trained on the RMCP before they deal with clients. Existing staff should undergo mandatory annual refresher courses or additional sessions whenever the RMCP changes.
- Regulators treat training as a primary compliance control, and failing to properly train staff often results in severe administrative fines. In a recent enforcement, the Prudential Authority imposed an administrative sanction on Discovery Bank as it was found that there was inadequate staff training, resulting in a R1 million fine. The bank failed to provide mandatory FICA training as outlined in its RMCP.
Information Officers: Are Your Appointments and Assessments Up to Date?
A Simple Question: Are Your Information Officer Records Still Correct?
Don't let outdated registrations become an avoidable risk. Keeping Information Officer and Deputy Information Officer details current is a small administrative task that supports strong POPIA governance and regulatory readiness. A practical approach is to build the review and update of these registrations into your HR onboarding, offboarding and employee movement processes, ensuring changes in personnel are reflected promptly and consistently.
Newsletter Tip: Knowledge is one of your strongest compliance controls. Information Officers are by law responsible for driving POPIA awareness across the organisation. Regular training helps keep compliance front of mind, reduces risk and strengthens your privacy culture.
Personal Information Impact Assessments: A POPIA Requirement, Not a Nice-to-Have
Did you know that the POPIA Regulations requires responsible parties to conduct a Personal Information Impact Assessment (PIIA)? Yet many organisations have never performed one or have not reviewed their assessment as their business operations have evolved.
A Personal Information Impact Assessment identifies how personal information is collected, used, stored, shared and protected. It is designed to assess whether processing activities comply with POPIA and to identify any privacy risks that may require additional controls or safeguards.
A PIIA is particularly important when introducing new products, systems, technologies, business processes or third-party service providers that involve the processing of personal information. It enables organisations to proactively identify and address privacy risks before they result in regulatory, operational or reputational issues.
The assessment should not be treated as a once-off exercise. As businesses grow and change, privacy risks evolve. Regular reviews can help ensure that your privacy programme remains aligned to your operational realities and POPIA requirements.
If you are unsure where to start or how to approach a PIIA, reach out to LetsComply.
The Information Regulator's Message is Clear: Compliance Can No Longer Be a Tick Box Exercise
The Information Regulator in its media briefing held on 31 August 2026 has signalled a clear shift towards more active enforcement of both POPIA and PAIA. Recent enforcement action against the South African Bureau of Standards (SABS), ongoing investigations into several organisations, increasing scrutiny of direct marketing practices, and proactive compliance monitoring all point to a regulator that is prepared to take action where compliance falls short.
With more than 8 000 security compromise notifications received since POPIA came into effect and proposals being considered to strengthen enforcement powers, organisations should expect greater scrutiny and a tougher regulatory environment in the future. The Regulator has also emphasised that compliance should be embedded into daily operations and not treated as a once-off exercise
Bottom line: The era of soft enforcement appears to be coming to an end. Organisations that wait until the Regulator comes knocking may find the cost of non-compliance far greater than the cost of getting it right today.
This newsletter is prepared for information purposes only and does not constitute legal advice. Questions or topics you would like to have covered? Reply to LetsComply with your suggestions
Need help? Get in touch with LetsComply or with DataCloud.