The Risk Management and Compliance Programme (RMCP)
The RMCP is the compliance document South African FSPs and CASPs are inspected against most heavily. This is a plain-English guide to what section 42 of the FIC Act requires it to contain, and how to keep it a living document rather than a template on a shelf.
What is an RMCP?
The Risk Management and Compliance Programme (RMCP) is the document required by section 42 of the Financial Intelligence Centre Act 38 of 2001 (FIC Act) that sets out how an accountable institution identifies, assesses, monitors and manages the risk of money laundering, terrorist financing and proliferation financing that arises through the services it provides.
Why is the RMCP required?
FIC Act section 42 requires every accountable institution — every FSP, every bank, every attorney holding client money, every casino, every CASP — to have an RMCP that is documented, approved by the board or senior management, and implemented in day-to-day operations. The RMCP is the operational bridge between the abstract risk of financial crime and the concrete controls a business puts in place.
What must an RMCP contain?
A compliant RMCP covers: the business-wide risk assessment (BWRA) methodology and its outputs; client due diligence (CDD) and enhanced due diligence (EDD) procedures; PEP and sanctions screening; ongoing monitoring; record-keeping obligations under section 22 (five-year retention); reporting duties (cash-threshold reports, suspicious-transaction reports, suspicious-activity reports); training and awareness; internal controls, roles and responsibilities; and the plan for reviewing the RMCP itself.
How often should an RMCP be reviewed?
Section 42 requires the RMCP to be reviewed regularly and updated when the business, its products, its client base or the regulatory environment changes materially. In practice, an annual documented review with interim updates for material changes (new products, new sub-categories, a new FIC directive such as Directive 9 of 2024 on the Travel Rule) is the working standard.
How is the RMCP inspected?
The RMCP is the first document the FSCA (as supervisory body for FSPs) and the Prudential Authority (for banks) ask for on inspection. Inspectors read it against how the business actually operates: they interview staff, sample client files, and test whether the CDD, EDD, screening and reporting described in the RMCP are the CDD, EDD, screening and reporting actually being done.
Where do I find the FIC Public Compliance Communications (PCC)?
The Financial Intelligence Centre publishes Public Compliance Communications (PCCs) on fic.gov.za. PCCs interpret FIC Act obligations in specific contexts (e.g. PEP screening, beneficial ownership, sanctions) and are treated as the FIC’s current position. Your RMCP should cite the PCCs relevant to your business.
What’s the difference between an RMCP and a compliance manual?
The RMCP is the FIC Act section 42 document that governs money-laundering, terrorist-financing and proliferation-financing risk. The compliance manual is the broader FSP document covering all FAIS, FICA, POPIA and internal-policy obligations. They cross-reference each other: the compliance manual points to the RMCP for AML/CFT; the RMCP points to the manual for governance, sanctions escalation, and disciplinary action.