LetsComply
Compliance services

What the law asks of you, and what we’ll do about it.

Six compliance services for businesses across South Africa — from the first free consultation through to the training that makes it stick. Each one starts with what the Financial Intelligence Centre Act (FICA) and the Protection of Personal Information Act (POPIA) mean for your business, and what you already have in place.

01

Anti-Money Laundering

See more

Some businesses are legally required to know exactly who their clients are, keep an eye on what they do, and tell the Financial Intelligence Centre when something looks wrong. FICA calls them accountable institutions — law firms, estate agents, credit providers and about twenty other kinds of business. If that's you, we build the programme those duties ask for, and build it so your team can actually run it.

  • Knowing who your clients are
  • Sanctions & PEP screening
  • Watching for odd transactions
  • goAML registration & upkeep
Who it’s for

Law firms, estate agents, credit providers, crypto platforms, gambling operators and anyone who sets up companies or trusts for clients.

02

POPIA & PAIA Compliance

See more

Two Acts, one Regulator. POPIA governs the personal details you hold — clients, staff, the people who fill in your contact form — and in practice that is nearly every business. PAIA governs what happens when somebody asks to see your records, and it requires a written manual saying how they go about it. The Information Regulator oversees both. We work out what you are holding, whether you are entitled to hold it, what your privacy policies should actually say, and get the PAIA manual done properly.

  • What you hold, and where
  • The eight things POPIA asks
  • Privacy policies and notices
  • Your section 51 PAIA manual
Who it’s for

Every private body needs a PAIA manual. Add anyone with staff records, client files, copies of ID documents, a mailing list, a website contact form or files sitting in the cloud, and POPIA is in scope too.

03

RMCP & Custom Policies

See more

Every business FICA applies to needs a written plan for spotting dirty money: how you'd notice it, what you'd do next, and why your particular clients and products carry the risks they do. FICA calls it a Risk Management and Compliance Programme, or RMCP. It has to be specific to your business, and supervisors have said plainly that a template with a company name pasted on the front doesn't meet that.

  • Where your real risk sits
  • How criminals target your sector
  • Controls that match the risk
  • Sign-off that means something
Who it’s for

Every business FICA applies to — especially those whose plan came from a template, or who have an inspection on the horizon.

04

Gap Analysis

See more

A gap analysis — a compliance audit, if you prefer the formal name — tells you where you actually stand. We measure what you have against what the legislation asks for, then hand you a list of what to fix with the highest-risk items at the top. The point is to find the gaps while they're still cheap to fix.

  • Do the documents hold up
  • Does it happen in practice
  • Registrations & filings
  • A fix-it list, worst first
Who it’s for

Businesses that have never had an outside look, anyone who has had a query from a supervisor, and boards who want to know their reports match reality.

05

Staff Training

See more

FICA says your staff must be trained. POPIA says they must understand what's expected of them. A slide deck once a year doesn't really do either. We run sessions built around the decisions your people actually face — the client who won't hand over an ID, the payment that arrives from somewhere odd — and leave the records behind to show it happened.

  • Built for the room
  • Scenarios from your sector
  • Plain language
  • Records for your file
Who it’s for

Businesses meeting their yearly FICA training duty, new joiners in roles where it matters, and Information Officers and their Deputies.

06

Implementation Support

See more

Most compliance failures aren't drafting failures. The programme is sound; the gap is what happens at four on a Tuesday when a client file needs opening and everyone is busy. We work alongside your team to close that gap.

  • Workflows people can follow
  • Checklists & registers
  • Handover, properly
  • Ongoing support
Who it’s for

Businesses with a programme on paper but not yet in practice, teams with nobody in-house doing compliance, and anyone fresh out of a gap analysis.

Still not sure?

Does this apply to me?

Five questions about what your business does and whose details it keeps. You’ll get a plain answer on FICA and POPIA at the end of it, and nothing you tick leaves your browser.

Two people comparing printed documents across a desk
Whatever we build, you should be able to show your working.
How the work goes

Four steps, and then the first one again.

Whichever of the six you start with, the work has this shape — and you don’t have to start at the first step.

  1. 01

    Assess

    Measure what you already have against what the law actually asks of you.

  2. 02

    Build

    Write the plan, the policies and the registers around your real risks.

  3. 03

    Embed

    Turn all of it into steps your team can follow on a busy Tuesday.

  4. 04

    Review

    At least once a year, and again whenever the business changes.

Then round again. Compliance doesn’t have an end date, and a programme nobody revisits quietly goes out of date.

Let’s narrow it down to what you actually need.

Most people aren’t sure which of these applies to them. A free consultation sorts that out.

Free consultation