A Be Relevant product

FSP compliance requirements in South Africa

Getting licensed is the start, not the finish. This is a question-led guide to the ongoing compliance a licensed FSP must maintain under the FAIS Act, the FIC Act and POPIA.

RegDesk automates the calendar, documents and registers behind these obligations. See RegDesk pricing →

What are an FSP's ongoing compliance obligations?

A licensed FSP must maintain, among others: an Annual Compliance Report submitted to the FSCA by 15 September for the reporting period ending 31 May; Continuing Professional Development (CPD) for Key Individuals and Representatives; annual financial statements within four months of financial year-end; a maintained Risk Management and Compliance Programme (RMCP) under the FIC Act; FIC cash-threshold and suspicious-transaction reporting; notification to the FSCA of material changes within 15 days; and POPIA obligations including data-breach handling. Records are generally kept for five years and must be retrievable for FSCA inspection.

What is an RMCP and why does it matter?

The Risk Management and Compliance Programme (RMCP) is the document required under section 42 of the FIC Act that sets out how an accountable institution identifies, assesses and manages money-laundering, terrorist-financing and proliferation-financing risk. It is the most inspection-scrutinised compliance document an FSP maintains, and it must be a living document that reflects how the business actually operates, not a template left on a shelf.

When is the FSP annual compliance report due?

The FSP Annual Compliance Report is submitted to the FSCA by 15 September each year, covering the reporting period that ends on 31 May. The Compliance Officer, or the accountable Key Individual where no external CO is appointed, is responsible for its completeness and submission.

What compliance documents must an FSP keep current?

An FSP maintains a core set of documents: the RMCP, compliance manual, Treating Customers Fairly (TCF) policy, conflict-of-interest policy, complaints management framework, business continuity plan, outsourcing policy, POPIA and PAIA policies, and the statutory registers (complaints, gifts and conflicts, training/CPD, and breaches/incidents). These must be kept current and be produced on request during an inspection.

How long must FSP records be kept?

FAIS and FICA records are generally retained for at least five years — for client and relationship records from the date the relationship ends, and for transaction records from the date of the transaction. Records must be retrievable within a short period (commonly cited as seven days) for FSCA inspection, whether kept electronically or physically.

How does RegDesk help an FSP meet these requirements?

RegDesk turns these obligations into a managed workflow: it tracks the compliance calendar and deadlines, generates and versions the required policies and registers, and keeps an audit-ready evidence trail linking each obligation to the document that satisfies it. The output supports your Compliance Officer; it is not legal or compliance advice.