FIC issues Directive 12: your RMCP must now be sent to the FIC every year

This article will count 0.25 units (15 minutes) of unverifiable CPD. Remember to log these units under your membership profile.


The Financial Intelligence Centre (FIC) has gazetted the final web-notice alerting accountable institutions to the new Directive 12 under section 43A of the Financial Intelligence Centre Act 38 of 2001 (FIC Act). It was issued on 4 September 2026, along with a web notice and a consultation feedback note.

The change is simple. If you are an accountable institution in one of the listed categories, you must now send a copy of your risk management and compliance programme (RMCP) to the FIC once a year, through goAML.

Having an RMCP is not new. Section 42 of the FIC Act has always required you to develop, document and implement one. What is new is that you must now submit it.

Does this apply to you?

Directive 12 applies to accountable institutions registered under items 1, 2, 3, 9, 11, 14, 20, 21 and 22 of Schedule 1 to the FIC Act. In plain terms, that covers:

  • legal practitioners (item 1)

  • trust and company service providers (item 2)

  • estate agents (item 3)

  • gambling institutions (item 9)

  • credit providers (item 11), but not those that form part of a bank, mutual bank or co-operative bank group

  • the South African Postbank (item 14)

  • high-value goods dealers (item 20)

  • the South African Mint (item 21)

  • crypto asset service providers (item 22)

If your accounting practice is registered with the FIC as a trust and company service provider, you are in scope.

If you are not on this list, for example authorised dealers and other financial institutions, you do not submit yet. The FIC says it is in talks with other regulators and that further directives may extend the same requirement to everyone else.

Your deadline

There are two dates, depending on your item number.

  • Due by 9 October each year: items 1, 2, 9 and 11.

  • Due by 31 October each year: items 3, 14, 20, 21 and 22.

Commentators asked for a three to six month transition period before the first submission. The FIC said no. Its reasoning is that having an RMCP was already a requirement, so the dates in the directive stand.

How many RMCPs do you submit?

  1. You need to have an RMCP per accountable institution.

  2. If you have branches that are not accountable institutions in their own right, you submit once for the whole network. Branches that are separate accountable institutions must submit their own RMCPs.

  3. If you hold more than one item registration with the FIC, you must submit an RMCP for each registration.

If you change your RMCP during the year

Once your board, senior management or the person with the highest authority approves an amendment, you have 10 days to submit the amended RMCP.

Industry asked for 90 business days and for interim submissions to be limited to material changes only. The FIC kept 10 days, saying it is reasonable because the amendment has already been approved. The FIC also said it will not advise on what counts as a material or non-material change, so treat approved amendments as submittable.

Uploading it does not mean the FIC has approved it

A successful upload on goAML only confirms that your document went through in the right format and with the right naming convention. It says nothing about the quality of your RMCP.

You remain responsible for complying with section 42 and the rest of the FIC Act. The FIC and other supervisory bodies will pull submitted RMCPs from time to time for guidance, monitoring, inspections and enforcement.

What is an RMCP, and how is it different from a risk and compliance return?

Your RMCP is your own written rulebook for complying with the FIC Act. It sets out how your business identifies, assesses, monitors and manages money laundering, terrorist financing and proliferation financing risk. In practice it explains how you rate the risk of a client, how you identify and verify clients and their beneficial owners, how you deal with politically exposed persons, how you screen against sanctions lists, how you keep records, when and how you report to the FIC, how you train your staff, and who is responsible for each of those steps. Guidance Note 7B deals with the RMCP in more detail.

A risk and compliance return is something different. It is a questionnaire, or self-assessment, that the FIC uses to gather information about your level of risk awareness and compliance. It is not your rulebook, it is a report about you. Both exist, and they run on different systems:

  • risk and compliance returns under Directives 6 and 7, submitted on a Microsoft form link

  • the risk and compliance return under Directive 11, submitted on the risk and compliance return system

  • the RMCP under Directive 12, submitted on goAML

The FIC has warned that submitting these incorrectly can attract administrative penalties. Before you start, be clear about which obligation you are dealing with and which system it belongs on.

If you work under a group RMCP

Requests to exclude institutions in banking groups were turned down. High-value goods dealers, crypto asset service providers and trust and company service providers within a banking group must still submit.

If you operate under a group-wide RMCP, submit extracts of that group RMCP as annexures to your own submission.

What exactly do you upload?

The RMCP documentation as approved by your board, senior management or the person with the highest authority. The FIC will publish a user guide setting out the practical upload steps, the accepted format and the naming convention.

Your checklist

  1. Confirm which Schedule 1 item or items you are registered under.

  2. Check whether you have more than one registration, as each one needs its own RMCP.

  3. Make sure your RMCP has been formally approved at the right level.

  4. Diarise 9 October or 31 October, depending on your item.

  5. Check that your goAML login still works.

  6. Watch for the FIC user guide before you upload.

Queries can go to the FIC compliance contact centre on 012 641 6000, option 1, or through the online query form at https://www.fic.gov.za/compliance-queries-2/.


Are you a CIBA member? Find your RMCP template under your member profile, or complete our FIC Compliance for Accountable Institutions short course and learn more about how to set up an RMCP.



 


Next
Next

Directive 10: The FIC Now Wants Every Office Address