Risk Management and Compliance Programmes (RMCPs)
Every business FICA applies to needs a written plan for spotting dirty money: how you'd notice it, what you'd do next, and why your particular clients and products carry the risks they do. FICA calls it a Risk Management and Compliance Programme, or RMCP. It has to be specific to your business, and supervisors have said plainly that a template with a company name pasted on the front doesn't meet that.
What this covers
Where your risk actually sits
Your real exposure, across the clients you take on, what you sell them, how you deal with them, where they are and which branch handles them. Everything else rests on this, which is why a generic assessment can only produce a generic programme.
How criminals target your sector
South Africa publishes sectoral risk assessments for legal practitioners, estate agents, accountants and others — accounts of how money is actually laundered through each trade. Your programme is expected to reflect the one that covers you.
Rules your staff can follow
When to do extra checks and how far to take them, who to escalate to, what to write down and what to report — set out so somebody on the front desk can act on it without opening the Act.
Sign-off that means something
Senior management has to approve the programme. An approval given without understanding protects nobody, so we walk management through it until they can explain what they've signed.
A yearly look at it
The programme should be reviewed at least annually, with the current version uploaded to your goAML profile. A plan nobody has opened in three years isn't really a plan.
- Every business listed in Schedule 1 to the Financial Intelligence Centre Act
- Anyone whose current programme started life as a template
- Businesses with a supervisory inspection coming
- Businesses whose clients, products or way of working have changed since the plan was written
- A risk assessment written about your business, not your sector in general
- An RMCP built around those risks and the way you already work
- The registers, checklists and record formats that go with it
- A briefing for management, so the sign-off is an informed one
- A review rhythm, so the programme doesn't quietly go out of date
Questions we get a lot
A Risk Management and Compliance Programme is the document the Financial Intelligence Centre Act requires from every accountable institution, setting out how it identifies, assesses, monitors and manages money laundering, terrorist financing and proliferation financing risk. In plainer terms: your written plan for spotting dirty money and what you do when you see it. It has to be specific to your business and approved by senior management.
Supervisory bodies have been clear that a generic template with a company name inserted doesn't meet the requirement. There's also a catch worth knowing about: the moment your business adopts a document as its RMCP, it stops being a template. From then on you're expected to show your working — to prove you do what it says you do.
At least annually, and sooner if your business, products, clients or risk exposure change in any material way. Upload the current version to your institution's goAML profile while you're there.
Senior management. That's a legal requirement under FICA, and it isn't a signature exercise — management is expected to understand the programme it has approved.
Let’s take a look at where you stand.
A free consultation works out what applies to your business and what you already have in place — before you commit to anything else.