Recent, ongoing regulatory updates highlight a clear expectation that Anti-Money Laundering (AML) compliance needs to be robust and demonstrable. Enhanced record-keeping requirements mean that compliance must go beyond having policies in place. It’s crucial to show that systems and processes are effective in practice.
How the regulatory landscape is shifting
During Q1 & Q2 of 2026, the regulatory landscape has reflected a continued shift toward stronger enforcement, greater transparency, and more robust governance expectations across the financial sector. The release of the Draft General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Bill in January 2026 signals a clear intention by regulators to strengthen South Africa’s AML/CFT framework ahead of the upcoming FATF Mutual Evaluation, meant to commence mid-2026 to October 2027.
At the same time, significant Companies Act amendments came into effect in May 2026, introducing new governance and disclosure requirements, particularly in relation to remuneration and director accountability. In parallel, the Conduct of Financial Institutions (COFI) Bill has now been formally introduced to Parliament, marking a major step toward a unified, outcomes-based regulatory framework for financial institutions.
Deep dive into upcoming shifts
The proposed amendments to FICA introduce several enhancements that raise the bar for how we manage client information, monitor risk, and maintain records. One of the most notable developments is the requirement for enhanced client relationship record-keeping. If enacted, the Draft General Laws (AML/CFT) Amendment Bill will require institutions to capture more detailed information about client relationships, including when a relationship begins and when it ends. This information must not only be stored but must also be easily retrievable to support regulatory queries and investigations.
There is also a stronger emphasis on targeted financial sanctions. Institutions will need to actively identify whether clients or associated property are linked to sanctioned individuals or entities. Where such links are identified, there will be an obligation to freeze assets and report both confirmed and attempted transactions to the Financial Intelligence Centre (FIC). These provisions reinforce South Africa’s commitment to aligning with international sanctions frameworks and improving financial system integrity.
In addition, the authority of the FIC has been strengthened, particularly through expanded monitoring powers. The FIC Director will be able to issue monitoring directions that require institutions to scrutinise specified information and comply with enhanced oversight requirements. This reflects a broader move toward proactive supervision rather than reactive compliance.
The Draft Amendment Bill proposes extending the retention period from five years (as currently required under section 23 of FICA) to seven years. This change is not yet in force. This change ensures that regulators have access to a longer history of client and transaction data, which is particularly important for complex investigations and long-term financial crime detection. Alongside this, institutions will need to ensure their systems can efficiently retrieve data when requested, reinforcing the importance of structured data management practices. Under current FICA (sections 22 and 23), accountable institutions must keep records of client identification, transactions, and business relationships for at least five years from the date on which the business relationship is terminated or the transaction is concluded.
Companies Act amendments
Outside of AML-specific updates, the Companies Act saw major amendments come into effect on 22 May 2026. These changes introduce binding remuneration policies that must be approved by shareholders, as well as detailed annual remuneration reports that include disclosure of executive pay and pay gaps within organisations. The introduction of the “two-strike rule” further strengthens accountability by imposing consequences where remuneration reports are repeatedly rejected. These changes are part of a broader trend toward increased transparency and governance oversight at board level.
A risk-based approach to Customer Due Diligence
In line with FICA and supporting Public Compliance Communications (PCCs), accountable institutions must apply a risk-based approach to Customer Due Diligence (CDD), including:
- Identification and verification of clients and beneficial owners
- Understanding the nature and purpose of the business relationship
- Ongoing monitoring of transactions
- Enhanced due diligence for higher-risk clients
Recent regulatory focus has also emphasised beneficial ownership transparency, requiring institutions to take reasonable steps to identify natural persons who ultimately own or control clients, consistent with PCC guidance.
Unpacking the COFI Bill
Finally, the COFI Bill represents one of the most significant regulatory reforms in the financial sector in years. Although it is not yet law, it introduces a fundamental shift toward a single, unified conduct framework that will replace multiple existing laws such as FAIS and the Insurance Act. The Bill moves away from a rules-based approach to an outcomes-based model, where institutions will be expected to demonstrate that they are delivering fair outcomes for customers. It also introduces activity-based licensing, enhanced governance responsibilities for boards, and a broader scope that captures fintech and non-traditional financial services.
What this means for AML
From an AML perspective, these developments underscore the growing expectation that compliance must be both effective and clearly evidenced. Enhanced record-keeping requirements mean that our client data must be complete, accurate, and accessible at all times. This places increased importance on how we capture, store, and retrieve information across the client lifecycle. The strengthened focus on targeted financial sanctions will require heightened vigilance in client screening and ongoing monitoring.
The broader regulatory direction, including COFI, reinforces the shift toward accountability and outcomes. Governance is no longer a separate function but a core part of compliance, with increased expectations on how decisions are made, documented, and reviewed. Even where certain updates do not directly impact the AML function, such as the recent Companies Act amendments, they signal a wider regulatory trend toward transparency and accountability that applies across all areas of the business.
Regulatory dates and developments
The Draft General Laws Amendment Bill was published for public comment on 14 January 2026, with submissions having closed in February 2026. The Bill is expected to progress through the legislative process during 2026 as part of preparations for the FATF Mutual Evaluation scheduled for 2026–2027.
In addition, the Companies Act amendments became effective on 22 May 2026, meaning that affected entities should already be aligning their governance and reporting practices with the new requirements. The COFI Bill, introduced in April 2026, will follow a separate parliamentary process, with implementation likely to be phased over the coming years.
The regulatory environment continues to evolve toward greater scrutiny, stronger enforcement, and higher expectations of transparency and accountability. For us, this means staying proactive, maintaining high standards in how we manage client information, and ensuring that our day-to-day practices align with both current and emerging regulatory requirements.