KYC, AML, Sanctions Screening and POPIA Explained
Behind every payment relationship in South Africa sits a set of compliance obligations. When a payment provider asks a new business for company documents, director IDs and proof of bank account, it is not bureaucracy for its own sake — it is the law. The two frameworks that matter most are FICA, which targets money laundering and terrorist financing, and POPIA, which protects personal information.
Understanding what each framework requires helps businesses prepare for onboarding, know what information they must protect, and recognise why certain checks and questions are non-negotiable.
What is KYC and why is it required?
KYC — Know Your Customer — is the process of verifying who a customer actually is before doing business with them. In South Africa it is required by the Financial Intelligence Centre Act (FICA), which obliges accountable institutions, including banks and payment providers, to perform customer due diligence. In practice that means:
- Verifying the identity of individuals (ID document, proof of address where required)
- Verifying businesses: registration documents, and identifying the directors and beneficial owners — the natural persons who ultimately own or control the entity
- Understanding the nature of the customer's business and the expected use of the account
- Applying enhanced due diligence to higher-risk customers, such as politically exposed persons
KYC is not once-off. Institutions must keep customer information current and re-verify when circumstances change.
What does AML involve beyond KYC?
Anti-money laundering (AML) is the broader programme that KYC feeds into. Under FICA, accountable institutions must also:
- Monitor transactions for patterns inconsistent with the customer's profile
- Report suspicious and unusual transactions to the Financial Intelligence Centre (FIC)
- Report cash transactions above the prescribed threshold
- Keep records of customer identities and transactions for the prescribed retention period, so that money flows can be reconstructed if investigated
- Maintain a risk management and compliance programme, with trained staff and an appointed compliance function
For businesses using a payment provider, this is why unusual activity — sudden volume spikes, transactions inconsistent with the stated business — can trigger questions or holds. The provider is legally obliged to ask.
What is sanctions screening?
Sanctions screening checks customers and transactions against lists of sanctioned persons, entities and countries — including the United Nations sanctions lists that South Africa applies through FICA's targeted financial sanctions provisions. Institutions must screen at onboarding and on an ongoing basis, and must not process transactions for sanctioned parties. Screening also flags politically exposed persons for enhanced due diligence rather than automatic refusal.
What does POPIA require?
The Protection of Personal Information Act (POPIA) governs how personal information — names, ID numbers, contact details, bank account numbers and more — is collected, used, stored and shared. It is enforced by the Information Regulator. Core requirements include:
- Collect personal information for a specific, lawful purpose and don't use it beyond that purpose
- Collect only what is needed, keep it accurate, and don't retain it longer than necessary
- Secure it with appropriate technical and organisational measures
- Notify the Information Regulator and affected people of security compromises involving personal information
- Respect data subjects' rights to access and correct their information
There is a natural tension with FICA: FICA compels institutions to collect and retain identity data, while POPIA demands minimalism. The resolution is that FICA processing is lawful under POPIA — but the data collected for compliance must still be protected, access-controlled and used only for its purpose. See logging, masking and audit trails for how this plays out in payment systems.
What does this mean for a business accepting payments?
- Expect KYC at onboarding and have documents ready: registration papers, director IDs, proof of banking details.
- Answer compliance questions honestly and promptly; delays usually mean missing information.
- Protect the personal information of your own customers — POPIA applies to you too, not only to banks.
- If you suspect your platform is being used to move criminal funds — for example, mule activity — raise it with your provider. See payment fraud.
Related topics
PCI DSS
What the PCI DSS standard requires, which merchants and providers must comply, and how hosted checkouts and tokenisation reduce your PCI scope.
Incident Response
A practical incident response approach for payment problems, from duplicate collections and data breaches to fraud attacks and processor outages.