
South African Law Firms: FIC Act Risk Management Programme Requirements
Summary
- The Financial Intelligence Centre Act (FIC Act) requires all accountable institutions to develop a risk management and compliance programme (RMCP).
- The RMCP must address requirements outlined in section 42 of the FIC Act, including policy documents, customer due diligence, and employee training.
- Legal practitioners must report suspicious transactions or activities to the Financial Intelligence Centre (FIC) via the goAML platform within 15 days.
What Happened
The RMCP should be drafted and implemented based on the money laundering, terrorist financing, and proliferation financing risks specific to each institution.
The Financial Intelligence Centre Act (FIC Act) requires all accountable institutions, including legal practitioners, to develop and implement a risk management and compliance programme (RMCP). This RMCP must address the requirements outlined in section 42 of the FIC Act, which include policy documents, customer due diligence, record keeping, reporting, and employee training. The RMCP should be drafted and implemented based on the money laundering, terrorist financing, and proliferation financing risks specific to each institution. Legal practitioners must identify and report suspicious transactions or activities to the Financial Intelligence Centre (FIC) via the goAML platform within 15 days of becoming aware of potential money laundering or terrorist financing activities.
Legal Context
The FIC Act is a legislative requirement for all accountable institutions, including legal practitioners. The RMCP must capture the institution's understanding of its assessment and exposure to risks of money laundering, terrorist financing, and proliferation financing. The RMCP documentation must be updated on an ongoing basis, and the institution should conduct an entity-wide anti-money laundering, counter-terrorist financing, and counter-proliferation financing risk assessment prior to drafting their RMCP. There are three types of risk assessments: client-risk assessment matrix, business risk assessment, and geographic location risk assessment.
Why It Matters
The FIC Act requires legal practitioners to ensure that their risk management programme addresses all requirements, including policy documents, customer due diligence, and employee training. The RMCP must be submitted within 15 days of becoming aware of potential money laundering or terrorist financing activities. Failure to comply with the FIC Act can result in severe consequences, including asset forfeiture. Legal practitioners must take a risk-based approach to anti-money laundering, counter-terrorist financing, and counter-proliferation financing, and report suspicious transactions or activities to the FIC via the goAML platform.
Practical Implications
Law firms must ensure their risk management programme addresses all FIC Act requirements, including policy documents, customer due diligence, and employee training, and submit suspicious transaction reports (STRs) or activity reports (SARs) via the goAML platform within 15 days of becoming aware of potential money laundering or terrorist financing activities.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Wansom is AI and can make mistakes.