SMALL GAPS. BIG CONSEQUENCES.
In this edition, we explore sector risk assessments, key AML record-keeping obligations and the recent developments in direct marketing landscape.
As the regulatory landscape continues to evolve, businesses must ensure their compliance frameworks remain effective, up to date and aligned with regulatory expectations. In this edition, we explore sector risk assessments, key AML record-keeping obligations and the recent developments in direct marketing landscape.
We help you understand what your business actually needs to do, help you catch risks early, and give you a heads-up on what is coming next.
The Latest From the FIC.
FIC Directive 10: Review and Update Your Location Details Before 29 October 2026
The FIC published Directive 10 of 2026, on 31 July 2026 requiring accountable institutions (excluding banks, mutual banks, cooperative bank credit providers) to provide detailed information on their head offices, branches, subsidiaries, and subsidiary branches, both within and outside South Africa, as part of their FIC registration.
Institutions already registered with the FIC must update these details within 90 days of the Directive taking effect, which will be 29 October 2026, and any future changes must also be reported within 90 days. Failure to comply may result in administrative sanctions.
RMCPs Under the Spotlight: Annual FIC Submissions Proposed
The FIC has published Draft Directive 12, proposing the annual submission of Risk Management and Compliance Programmes (RMCPs) through the FIC reporting platform.
If implemented, impacted accountable institutions will be required to submit their RMCPs by either 30 September 2026 or 31 October 2026, depending on the Schedule 1 classification, with annual submissions thereafter. Newly established accountable institutions must submit their RMCP within 90 days of commencing business, and that any approved RMCP updates be submitted within 10 business days of approval.
Anti-money Laundering (AML): A fresh look at Sector Risk Assessments and record keeping
What is a Sector Risk Assessment and why is it important?
Put simply, a Sector Risk Assessment tells you what risks the FIC sees in your sector and whether those risks could apply to your business. Examples of some of these sector risk assessments include accounting profession, Legal Practitioners, Property Practitioners, Estate Agents, Trust and Company Service Providers. The FIC has already done the groundwork of identifying these risks, so it makes sense to use it. If you have not considered those risks in your own risk assessment and RMCP, you may be overlooking the very areas regulators expect you to address.
Newsletter Tip: An outdated RMCP can be as problematic as not having a RMCP at all. If it has been some time since your last review, LetsComply is available to assist with assessing and updating your RMCP to ensure it remains practical, effective, in line with the latest sector assessment and fit for purpose.
Legal Practitioners: The FIC has spoken.
The FIC has recently issued an updated draft Sector Risk Assessment for legal practitioners, highlighting the sector's continued vulnerability to money laundering and terrorist financing risks. Concerns haves been raised around services such as conveyancing, managing trust accounts, establishing legal entities and handling client funds, all of which may be exploited to conceal the movement or ownership of illicit funds. The draft assessment also notes concerns regarding low levels of regulatory reporting relative to the size and activity of the sector.
FIC Sends a clear message on RCR Compliance.
Last month we flagged the deadlines for submissions for the various accountable institutions. The FIC issued an updated media release on the latest rate of completion as at the 15 July 2026 for the returns which are listed below:
| Sector | Registrations 31/3/2026 | Submissions by 30/6/2026 | % Received as at 30/6/2026 | % Received as at 15/7/2026 | Deadline |
|---|---|---|---|---|---|
| Company Service Providers (Accountants) | 381 | 148 | 38.85% | 51.71% | 30 June 2026 |
| Trust Service Providers (Accountants) | 101 | 56 | 55.45% | 68.32% | 30 June 2026 |
| Company Service Providers | 1 291 | 373 | 28.89% | 39.27% | 30 June 2026 |
| Trust service Providers | 785 | 308 | 38.98% | 53.89% | 30 June 2026 |
| Casinos | 36 | 33 | 91.67% | 100% | 30 June 2026 |
| Credit Providers (non-banks) | 2 680 | 949 | 35.41% | 46.01% | 30 June 2026 |
| Crypto Asset Service Providers | 362 | 171 | 47.24% | 68.51% | 30 June 2026 |
| Total | 5 636 | 2 038 | 36.12% | 48.14% |
| Sector | Registrations 31/3/2026 | Submissions by 15/7/2026 | % Received as at 15/7/2026 | Deadline |
|---|---|---|---|---|
| Legal Practitioners | 21 022 | 2 037 | 9.69% | 31 July 2026 |
| Estate Agents | 9 678 | 1 141 | 11.79% | 31 July 2026 |
| Gambling institutions (non-casinos) | 4 563 | 589 | 12.91% | 31 July 2026 |
| High-Value Goods dealers (Motor Dealers) | 4 266 | 865 | 20.28% | 31 July 2026 |
| High-Value Goods dealers (Other) | 637 | 93 | 14.60% | 31 July 2026 |
| Dealers: Precious Metals | 176 | 25 | 14.20% | 31 July 2026 |
| Dealers: Precious Stones | 244 | 49 | 20.08% | 31 July 2026 |
| Dealers: Kruger Rands | 241 | 26 | 10.79% | 31 July 2026 |
| Total | 40 827 | 4 825 | 11.82% |
Consequences of missing the deadline.
Missed your sector's RCR deadline? Submit it as soon as possible anyway. A lower fine for a late submission is far better than a higher fine, and closer FIC scrutiny, for not submitting at all. These figures tell their own story. A sector that consistently lags can get risk rated as high by the FIC, meaning more scrutiny for everyone in it, even businesses that submitted on time.
New direct marketing rules you need to know about.
Direct marketing in South Africa is no longer just covered by one law anymore. There are now two you need to keep an eye on. The Protection of Information Act (POPIA) has been the main law governing directed marketing for years, policed by the Information Regulator. Since July 2026, there is a second layer: the National Consumer Commission's new Opt-Out Registry, introduced under the Consumer Protection Act Regulations.
"Direct marketing" is defined way more broadly than anyone expects. So, if you are a professional services firm such as an accountant, a law firm, in records management, or selling software to any of the above, chances are you are already doing "marketing" without knowing it.
Direct Marketing: What it actually means.
The Information Regulator's Guidance Note on Direct Marketing defines direct marketing as approaching someone, whether face-to-face, or by mail or electronic communication, for the purpose of promoting or offering to supply goods or services in the ordinary course of business. It doesn’t matter whether the approach is direct or indirect, where the content promotes goods or services, it is subject to the direct marketing regulations.
The law does not treat all direct marketing the same way. It comes down to how the message reaches the recipient. Here is the breakdown:
| Consideration | Non-electronic marketing | Electronic marketing |
|---|---|---|
| How it is sent | Post, hand-delivered mail, an in-person pitch, or a pamphlet in a letterbox | Email, SMS, WhatsApp, telephone calls, or direct messages on social media for example LinkedIn, Instagram or Facebook |
| May the business make first contact to a client without asking? | Generally, yes, provided there is a genuine, documented business reason for the contact (referred to in law as a “legitimate interest”) | Generally, no. The business needs either the person's prior consent, or an existing customer relationship involving similar goods or services |
| May the business post on social media without consent? | N/A | Yes, this does not count as direct marketing although it is electronic marketing |
| What the recipient can do about it | Object at any time; the business must then stop immediately | Must be given the option to decline both when their details are first collected and again on every message sent afterward |
Put simply: post and in-person direct marketing is the easier of the two. A business can go ahead if it has a genuine reason to, as long as the recipient can object at any time. Email, SMS and WhatsApp to a client is a different story. Consent or an existing customer relationship is needed before contact is made, and an opt out must always be provided for. Since most marketing today happens electronically, this is where businesses land up in hot water.
Assessment Checklist.
Some businesses are direct marketers without realising it. Here are a few examples:
| Your firm | A scenario that quietly counts as direct marketing |
|---|---|
| Accountants & auditors | Emailing existing clients about a new business solution which is not similar to the firm’s initial products and services. |
| Attorneys | An attorney sends a monthly email to former and prospective clients highlighting recent court judgments, legislative changes and legal tips. The newsletter concludes with: "Contact us today for a free consultation on your employment law or property law matter." |
| Record storage & archiving companies | Cold-calling or emailing prospective businesses to sell storage, scanning or destruction services. |
| Software & IT providers | A CRM software provider direct messages prospective clients on LinkedIn offering: "Start your free 30-day trial today and automate your customer management." The direct message contains a registration link and promotional material. |
| All of the above | Buying, scraping or importing a contact list and emailing or calling it. |
Ask yourself: does any of this apply to your business?
☐ We send emails, SMSs, WhatsApp messages or make calls that promote what we do
☐ We contact people who have not asked to hear from us, including cold prospects
☐ Our newsletters, alerts or bulletins carry any promotional message, however subtle
☐ We use a purchased, scraped or third-party contact list
Where any of the above applies, your business is likely to a direct marketer for the purposes of POPIA and CPA, and the obligations below will apply accordingly. ________________________________________________________________________________
The one message Rule: How POPIA governs marketing
Not all marketing messages are equal under POPIA. It comes down to how you contact someone, and whether they already know you.
If you are marketing electronically (email, SMS, calls, WhatsApp) and the person is not yet your customer:
- Your first message can only ask for permission to market. You cannot sell and ask for consent at the same time.
- You only get one shot at this and not if they have already refused.
- You need to ask using the Regulators Form 4, or something very close to it, and it is on you to prove consent was actually given.
- Got consent over the phone? The call and their response need to be recorded.
If the person is already your customer:
- You can market similar products or services to existing customers without asking again, but only if you got their details through an actual sale or service you provided.
- You must give them an opportunity to opt out, free of charge when you first collect their details, and again on every marketing message after that.
Say stop once and it better stop.
- Every marketing message must say who it is from and give people a way to say stop.
- If someone objects or withdraws consent, you must stop contacting them immediately, and you need to keep an updated list of everyone who has opted out or withheld consent, so you do not slip up and contact them again. The Regulator will ask this on inspection.
- For post, in-person approaches or letterbox drops, a person can object at any time using the Regulator's Form 1. Once they do, processing their information for marketing must stop.
Now add the CPA Layer: The Opt-Out Registry
From July 2026, the amended CPA Regulations added a second layer on top of POPIA.
Direct marketers must:
- Register with the NCC as a direct marketer on the Opt-Out Registry before contacting any consumer for marketing purposes.
- Renew that registration annually.
- Cleanse their marketing database against the Registry every month and remove anyone who has registered a pre-emptive block.
- Never contact a consumer who has registered a pre-emptive block, even if they gave you consent before they registered it as the later block overrides the earlier consent.
Newsletter tip: It is tempting to assume that if someone has not registered a pre-emptive block on the CPA registry, you are free to contact them electronically. The Information Regulator's guidance is explicit that this is not the case. The CPA registry is an additional layer, not a substitute for the POPIA consent. Not being on the registry is not, on its own, permission to market to someone.
The table below sets out the practical cost side of the CPA registration regime, based on the 2026 fee schedule.
| Obligation | Frequency | Indicative 2026 fee |
|---|---|---|
| Register as a direct marketer with the NCC | Once-off, then annual renewal | From R2 574 (registration) |
| Renew registration | Annually | From R1 930.50 (renewal) |
| Cleanse your marketing database against the Registry | Monthly, once registered | Scales with database size |
Consequences of non-compliance
There are no fines, yet under the new regime. Registration only opened in July 2026, so the Commission has not had a chance to issue fines. This does not mean the risk is low.
R200,000 Later: What FT Rams Consulting (FT Rams) Got Wrong Under POPIA.
A training institution, FT Rams, kept emailing a person who had asked, more than once, to be taken off its mailing list. The Information Regulator stepped in, finding TF Rams had never actually got consent to market to them in the first place. Having an opt-out button did not fix the lack of consent.
The Regulator ordered FT Rams to stop, fix its process, and prove it within 90 days. It did not. The result: a R200,000 fine, which it also did not pay. FT Rams has now been charged criminally. Ignoring an Enforcement Notice is its own separate offence under POPIA and it carries a fine up to R10 million in fines, or up to ten years in prison.
How LetsComply can Help
If you've ticked a box above and are not yet sure what that means for your day-to-day business communications, we can help you work through it by getting your customer consent right under POPIA, registering with the NCC, building a simple internal direct marketing policy, and setting up a practical monthly cleansing routine that does not become a burden on your team. Reach out and let us help get you compliant.
This newsletter is prepared for information purposes only and does not constitute legal advice. Questions or topics you would like to have covered? Reply to LetsComply with your suggestions