Open navigation
Search

The Black Sheep of AML/CTF/CPF

09 Oct 2026 South Africa 8 min read

The Limelight Problem

Consider a mid-sized manufacturing company - call it Company X. It has no financial services licence, no trust account, no client onboarding process, and nothing resembling Schedule 1 status under the Financial Intelligence Centre Act, 2003 ("FICA"). It decides to sell the business as a going concern. During negotiations, a prospective purchaser's broker privately offers Company X's CEO a "success fee", paid outside the transaction documents, to push the deal through above its independently assessed valuation. The purchase price itself is proposed to be funded through a chain of offshore vehicles that Company X's own advisors cannot fully trace to a legitimate source of wealth - one of which operates out of a high-risk jurisdiction linked to regional security threats and militant extortion networks. 

Nothing about this fact pattern triggers FICA's accountable institution obligations - Company X is not a Schedule 1 entity. Company X's board is comfortable with the transaction. They are not a bank, an estate agent, or a law firm. They have never been told that they have anti-money laundering or anti-corruption obligations, because no one has ever had reason to tell them so. But is their comfort justified?

The increased focus on corporate accountability following the State Capture Commission has reinforced the importance of statutes beyond FICA. Government reporting in 2025 reflected significant growth in asset recovery efforts, with approximately R11 billion recovered and billions more subject to restraint and preservation orders. These developments illustrate that financial-crime enforcement is increasingly measured not only by compliance programmes and reporting metrics, but by successful investigations, prosecutions and asset recovery under statutes such as Prevention of Organised Crime Act, 1998 ("POCA") and Prevention and Combating of Corrupt Activities Act, 2004 ("PRECCA"). [1]

For years, FICA and subsequently the Financial Intelligence Centre Amendment Act, 2017 ("FICAA") have been the golden child of South African corporate compliance. They dominate boardroom agendas, dictate onboarding procedures, and provide a comfortable administrative checklist. But while companies obsess over FICA and FICAA, they routinely ignore the black sheep of the financial crime family which are POCA, PRECCA, and the Protection of Constitutional Democracy Against Terrorist and Related Activities Act, 2004 ("POCDATARA"). These overshadowed laws do not just ask for a risk management plan - they demand active whistleblowing, seize commercial assets, and impose severe criminal liability on those who look the other way. So why do FICA and FICAA receive all the attention?

Obligations Beyond FICA: The Triad of Black Sheep 

FICA's dominance comes from its design. It asks one core question, which is whether an entity is a Schedule 1 accountable institution? If the answer is yes, it tells you exactly what to do - client due diligence, risk management and compliance programmes, ongoing monitoring, record-keeping, and reporting to the Financial Intelligence Centre. 

POCA, PRECCA and POCDATARA ask no such question. They apply to natural and juristic persons alike, in business or out of it, whether or not Schedule 1 has ever crossed their desk. A company or individual can correctly conclude they fall outside FICA's regime and wrongly conclude that they therefore have no financial-crime obligations at all. They do - the obligations simply come from elsewhere.

POCA 

Sections 4 to 6 criminalise three things where the person knows or ought reasonably to have known that property is the proceeds of unlawful activity: 

  1. entering into an arrangement or performing any other act in connection with it that conceals or disguises it, or helps an offender avoid prosecution, remove or diminish the proceeds;
  2. facilitating another person's retention or control of their proceeds or using those proceeds to benefit them; and
  3. acquiring, using, or possessing another person's proceeds. 

Liability is not confined to cases where money laundering has been established or proven - it may arise once a person who deals with property ought reasonably to have known it was tainted. This standard applies irrespective of accountable-institution status - a landlord accepting rent in cash, a used-car dealer, or a private seller, each of which can commit these offences.

PRECCA

Section 34A creates a 'failure to prevent corruption' offence for private-sector entities and incorporated state-owned entities. An entity may incur criminal liability where a person associated with it (anyone performing services for or on its behalf, in any capacity) offers, agrees to give, or gives prohibited gratification to obtain or retain business or a business advantage for the entity, unless the entity can demonstrate that it had adequate procedures in place to prevent such conduct. Section 3 mirrors this at the individual level, criminalising giving or accepting gratification, directly or indirectly, and whether for oneself or another. Section 34 obliges anyone in a position of authority (including directors, chief executives and senior public officials) who knows, or reasonably ought to have known, that another person has committed a specified corruption offence (involving R100 000 or more) to report it to the police official in the Directorate for Priority Crime Investigation. 

POCDATARA

Section 4 criminalises acquiring, collecting, or making available property or funds intending, or knowing, or ought reasonably to have known or suspected, that it will be used to commit or facilitate terrorist or terrorist related activity, with the Financial Intelligence Centre confirming that this applies to every person subject to South African law, not only accountable institutions.[2] Section 12 imposes reporting obligations where a person has reason to suspect that another person intends to commit, or has committed, certain terrorism-related offences.

FICA itself

Even FICA is not purely an accountable-institution regime. Section 29 requires any person who carries on, manages, or is employed by a business (regardless of Schedule 1 status) to report a suspicious or unusual transaction to the FIC. The "I'm not an accountable institution, so I have no AML obligations" assumption is wrong under POCA, PRECCA and POCDATARA, and wrong under FICA's own text.

Return to Company X

Nothing in the aforementioned scenario makes Company X a Schedule 1 accountable institution, yet by the close of the transaction, each of the obligations above has already attached. The "success fee" offered to the CEO is an offence under PRECCA's section 3 the moment it is offered, whether or not it is ever accepted; if offered to secure the deal for the purchaser, PRECCA's section 34A exposes the purchasing entity itself, and the CEO's own knowledge of it triggers a section 34 duty to report. The offshore funding chain, untraceable to a legitimate source of wealth, raises a live question under sections 4 to 6 of POCA - not whether Company X's board actually knew the funds were tainted, but whether, on the facts available to them, they ought reasonably to have known. The funding vehicle operating out of a jurisdiction linked to militant extortion networks is enough to find a reasonable suspicion under POCDATARA, engaging section 4's prohibition on receiving such funds and section 12's duty to report the suspicion once it arises. 

Why the Black Sheep Still Bite

The reason POCA, PRECCA and POCDATARA deserve more attention is not because they impose more paperwork than FICA. They are primarily criminal statutes aimed at money laundering and corruption, and can expose both organisations and individuals to criminal investigation, prosecution, asset forfeiture and imprisonment. By contrast, many FICA compliance failures are dealt with through administrative enforcement measures such as financial penalties, directives, remediation plans and adverse supervisory findings which may take years before finalisation. However, certain FICA breaches are themselves criminal offences and can result in prosecution, substantial fines and imprisonment. The triad of black sheep operate on an entirely different register. A POCA conviction under sections 4 to 6 carries a sentence of up to 30 years' imprisonment, and Chapter 6 of POCA permits civil forfeiture proceedings that may result in the forfeiture of property connected to unlawful activity even where no criminal conviction has been obtained. Section 34A of PRECCA exposes a company to criminal liability, not a fine schedule, the moment an employee offers a bribe on its behalf - and strict liability means the company's lack of knowledge is no defence at all. POCDATARA carries sentences running to life imprisonment for financing terrorism, with no threshold, no de minimis, and no accountable-institution gateway to hide behind.

This is the asymmetry FICA's dominance obscures. A business can be fully FICA-compliant (every client vetted, every risk register up to date) and still be one uninvestigated bribe, one unreported suspicion, or one unwittingly laundered payment away from a criminal charge under a statute it has never once thought about. FICA trains people to manage risk. POCA, PRECCA and POCDATARA are what happens when that risk crystallises into conduct - and crystallised conduct is prosecuted, not remediated.


 

[1] https://www.thepresidency.gov.za/significant-progress-made-implementing-state-capture-commission-recommendations . 

[2] https://www.fic.gov.za/wp-content/uploads/2024/02/2027.2-PCC-PCC-44A-Targeted-financial-sanctions.pdf

Back to top Back to top
Opens in new window