You're viewing a live, simulated demo — nothing here is saved.

Get started free
All posts Guide

The Complete FICA Compliance Checklist for South African Estate Agencies

Lucere Team 29 July 2026 9 min read

Every estate agency in South Africa is, in the eyes of the law, a bank. Not literally, of course, but functionally: the Financial Intelligence Centre Act (FICA) places property practitioners in exactly the same regulatory category as banks, insurers, and forex dealers. You are what the Act calls an accountable institution, and that status comes with real, binding obligations, not a set of best-practice suggestions you can get to eventually.

For years, many agencies treated FICA as a box-ticking exercise: collect an ID copy and a proof of address, put them in a folder, move on. That approach no longer holds up. Fidelity Fund Certificate renewal is now conditioned on demonstrable FICA compliance, and the Financial Intelligence Centre can inspect a firm with short notice and expect to see a working programme, not a drawer of paperwork assembled the night before.

This checklist walks through what a genuinely compliant estate agency needs in place, section by section, so you can audit your own firm against it honestly.

In short

Eight things a real FICA programme needs: a living RMCP, a properly empowered compliance officer, thorough client due diligence, sanctions/PEP screening, retrievable records for five years, a working process for reporting suspicions, annual training, and the discipline to treat all of it as a precondition for your Fidelity Fund Certificate, not a separate concern. The full checklist is at the bottom if you want to skip straight there.

Why this is not optional anymore

Three things changed the risk calculus for property practitioners in South Africa:

  • The 2017 General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act rewrote large parts of FICA, replacing the old identity-verification checklist with a risk-based approach and introducing a formal Risk Management and Compliance Programme (RMCP) requirement.
  • The Property Practitioners Act of 2019 replaced the old Estate Agency Affairs Board with the Property Practitioners Regulatory Authority (PPRA), and tightened the link between a valid Fidelity Fund Certificate and demonstrable compliance, FICA included.
  • Real estate remains a recognised money laundering typology internationally. The Financial Action Task Force (FATF) has repeatedly flagged real estate transactions as a common vehicle for placing illicit funds, precisely because property deals are large, relatively infrequent for any one buyer, and historically under-scrutinised compared to banking transactions.

Put together: a lapsed or superficial FICA programme is now a direct threat to your ability to trade at all, not just a compliance footnote.

1A real Risk Management and Compliance Programme (RMCP)

Section 42 of FICA requires every accountable institution to have a documented RMCP, approved at senior management level, that sets out how the firm identifies, assesses, and manages money laundering and terrorist financing risk. An RMCP is not a generic template downloaded once and never revisited. Inspectors specifically look for evidence that it is a living document.

Your RMCP checklist:

  • Is it in writing, dated, and version-controlled, with a clear owner (usually your compliance officer)?
  • Does it name and describe your specific client base, transaction types, and geographic footprint, rather than reading like a generic industry template?
  • Does it set out your risk rating methodology: what makes a client low, medium, or high risk at your firm specifically?
  • Has it been reviewed and, where necessary, updated in the last 12 months?
  • Can you show board or senior management sign-off on the current version?
  • Does every person handling client onboarding actually know where to find it and what it says?

2A properly appointed compliance officer

FICA requires an accountable institution to appoint a person responsible for compliance, and the Financial Intelligence Centre expects that person to be genuinely equipped for the role, not simply the most senior name on the letterhead.

  • Is there a formally appointed compliance officer, documented in writing, with a clear reporting line?
  • Do they have the authority and time allocated to actually do the job, not just the title?
  • Have they completed FICA-specific training, and is that training refreshed periodically?
  • Is there a documented escalation path for when something looks wrong, a mismatched ID, a client who avoids questions, a payment from an unrelated third party?

3Client due diligence (CDD), done properly

This is the part most agencies already do in some form. The gap is usually in how thoroughly, and how consistently, it is done.

Natural persons

  • Full names and a valid South African ID number, or passport details for foreign nationals, verified against the source, not just visually inspected.
  • Proof of residential address, current, not an expired or borrowed utility bill.
  • Source of funds appropriate to the transaction size. A cash buyer for a multi-million rand property with no visible income history is exactly the profile FATF guidance flags as warranting closer attention.

Legal entities (companies, trusts, close corporations)

  • Full registration details verified against the CIPC company registry, not just a certificate the client hands over.
  • A complete picture of beneficial ownership: the natural persons who ultimately own or control the entity, not just the nominee director on record.
  • For trusts specifically: the trust deed, the trustees, and the beneficiaries, since trusts remain a favoured structure for obscuring true ownership.

Ongoing due diligence, not a one-time event

  • Documents carry an expiry or freshness window appropriate to their type. A proof of address from three years ago is not evidence of anything current.
  • Existing clients are re-screened periodically, not just onboarded once and left alone indefinitely.
  • A change in circumstances, a new director, a change in beneficial ownership, a sudden change in transaction pattern, triggers a fresh look, not a shrug.

4Sanctions and PEP screening

FICA requires screening against both sanctions lists and for politically exposed persons (PEPs), and this obligation does not stop at onboarding.

  • Every client is screened against sanctions lists (domestic and, where relevant, international) before the transaction proceeds.
  • PEP status is checked and, where a client is a PEP or closely associated with one, enhanced due diligence is applied and documented, not just noted in passing.
  • Screening is re-run periodically for existing clients, since a client's PEP or sanctions status can change after onboarding.
  • A positive match is escalated to your compliance officer with a documented decision, not silently ignored because the transaction was already in progress.

5A record-keeping regime that survives an inspection

FICA requires records to be kept for a minimum of five years from the date the business relationship ends, and inspectors do not accept "we can probably find that" as an answer. The bar is retrievability, not just retention.

  • Can you produce, for any client, every document collected, when it was collected, and who collected it, within minutes rather than days?
  • Is there an audit trail of every request sent, every document received, and every verification run, not just the final approved file?
  • Is consent to hold and share each document recorded as its own event, with a timestamp and the wording the client agreed to, rather than assumed?
  • If a client's relationship ends, does your five-year retention clock start correctly, and do you know when records can finally be destroyed?

6Reporting obligations

Accountable institutions must report certain transactions and suspicions directly to the Financial Intelligence Centre.

Don't guess at this one

Staff need to actually recognise a suspicious transaction to report it: structuring a purchase price to avoid a threshold, a third party paying on a buyer's behalf with no clear relationship, a transaction that makes no economic sense for the parties involved. If nobody on your team could name these patterns unprompted, that's the gap to close first in this section.

  • Staff know what a suspicious transaction actually looks like in a property context.
  • There is a clear, documented internal process for raising a suspicion, so it does not depend on one person remembering to act.
  • Reports that need to reach the FIC are filed on time, through the correct channel, and the fact of filing (never the content, which is legally protected) is recorded internally.

7Training that actually changes behaviour

A compliance programme that lives in a PDF nobody reads is not a compliance programme.

  • Every person who touches client onboarding, not just management, has received FICA training appropriate to their role.
  • Training is refreshed at least annually, and whenever the RMCP or the law itself changes.
  • New hires are trained before they handle a client file, not weeks or months after.
  • You can show a record of who was trained, when, and on what.

8The Fidelity Fund Certificate connection

Under the PPRA's current framework, FFC renewal is tied to your firm's compliance standing. A gap in your FICA programme is no longer just a theoretical enforcement risk, it can directly threaten your right to trade as a property practitioner at all. Treating FICA compliance as a prerequisite for your FFC, rather than a separate concern, is the correct mental model for 2026 and beyond.

The consolidated checklist

If you only have ten minutes, work through this list honestly:

  • Written, reviewed, senior-management-approved RMCP, updated in the last year.
  • Formally appointed, adequately trained compliance officer with real authority.
  • Verified identity documents for every client, natural person or entity, against the source, not just a photo.
  • Beneficial ownership established and documented for every company, CC, or trust client.
  • Source of funds considered and documented, proportionate to transaction size.
  • Sanctions and PEP screening run at onboarding and refreshed periodically.
  • A complete, retrievable audit trail: every request, every document, every consent, every check.
  • Five-year record retention that you can actually demonstrate, not just claim.
  • A documented internal process for raising and reporting suspicious transactions.
  • Annual FICA training for everyone who touches a client file, with records to prove it.
The firms that struggle at inspection are rarely the ones with no compliance programme at all. They are the ones whose programme exists on paper but cannot be evidenced, quickly, completely, and consistently, when someone actually asks.

Where this leaves most agencies

If you read through this list and found two or three gaps, you are in the same position as most of the industry. The honest next step is not panic, it is closing the gaps methodically: start with the RMCP, since almost everything else depends on it, then tighten document verification and freshness, then make sure your audit trail can actually answer "prove it" on demand.

This is precisely the workload Lucere was built to carry: client due diligence, real verification against Home Affairs and CIPC, sanctions and PEP screening, and an audit trail built from the first document request rather than reconstructed the night before an inspection. If you would rather your team spend its time selling houses than assembling folders, that is exactly the gap we close.

Sell houses. We'll handle the FICA.

See how Lucere runs client due diligence for South African estate agencies.

Get started