FICA Risk Management & Compliance Programme (RMCP) in accordance with Sec 42 of the amended FINANCIAL INTELLIGENCE CENTRE ACT 38 of 2001
This document has been prepared solely for the private use of employees of Pinnacle Micro (Pty) Ltd. It may not be disclosed to any third party without prior written consent by Alviva Holdings (Pty) Ltd.
Company Confidential
Compliance
Risk Management & Compliance Programme (RMCP)
PROCESS OWNER
:
Mario Mynhardt – S43 Compliance Officer
APPROVED BY
:
Tim Humphreys-Davies – CEO/MD
APPROVAL DATE
:
23 October 2025
:
RMCP_V04_2025
DOCUMENT NAME. & VERSION NO.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 2 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
TABLE OF CONTENTS GLOSSARY OF TERMS
7
1.
Document Control
13
1.1.
Document Version Control
13
1.2.
Document Approval
13
2.
Purpose of FICA and this RMCP
14
2.1.
Seven Pillars of FICA Compliance
15
2.2.
Review of the RMCP
16
3.
About the AI as an HVGD
16
3.1.
Nature of the Business
16
3.2.
Philosophy
17
3.3.
Applicability & Availability of the RMCP
17
3.4.
Implementation of the RMCP
18
3.5.
Accounts Payable
18
3.6.
Accounts Receivable
18
4.
Governance of RMCP & FICA Requirements
19
4.1.
Prohibition and Offence
19
4.2.
Board of directors & senior management
19
4.3.
S43 Compliance Officer
19
4.4.
Money Laundering Reporting Officer
20
4.5.
All Employees
20
4.6.
Escalation of Non-Compliance with or Breach of RMCP/FICA
21
4.7.
High-level Remediation Processes
21
5.
Introduction to Risk and ML/TF/PF/PFA
22
5.1.
What is risk?
22
5.2.
What is Money Laundering (ML)?
22
5.3.
What is Terrorist Financing (TF)?
23
5.4.
What is Proliferation Financing (and Proliferation Financing Activities) (PF/PFA)?
23
5.5.
What risk does ML/TF/PF/PFA pose?
23
5.6.
What is ML/TF/PF/PFA risk management?
24
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 3 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
6.
Clients & Business Relationships
25
6.1.
Prospective Clients
25
6.2.
Timing of verification
25
6.3.
Established Business Relationships
26
6.4.
Anonymous or Fictitious Clients
26
6.5.
Business Relationship with a DPIP or FPPO
27
6.6.
Non-compliant Clients & Terminating Business Relationships
27
7.
Sources of Information
28
7.1.
Client information and documentation
29
7.2.
Doubts about the veracity of information
30
8.
Risk Management
30
8.1.
Process
30
8.2.
Mechanisms
31
9.
Risk-Based Approach
31
9.1.
Effect of a risk-based approach
31
9.2.
Risk Rating methodology
32
10.
ML/TF Risk Indicators
33
10.1.
Business-Level Risk Assessment
33
10.2.
Software-as-a-Service (SaaS)
33
10.3.
Products & Services Offered
34
10.4.
Client Risk-rating & Profiling
35
10.5.
Legal Entity/Juristic Person Types Contracted
36
10.6.
Natural Persons/Beneficial Owners
37
10.7.
Prominent Persons – DPIP and FPPO
38
10.8.
Geographic Locations
39
10.9.
Transaction Type – Business Relationship, Single Transactions
40
10.10. Payment Types
41
10.11. External Risk Elements
41
10.12. Frequency
41
11.
Risk Mitigation
42
12.
Customer Due Diligence
42
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 4 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
12.1.
Prohibited/Forbidden Clients
43
12.2.
Verification & Screening
43
12.3.
CDD – Natural Persons
44
12.4.
CDD – Juristic Persons/Legal Entities
45
12.5.
Additional Due Diligence (ADD)
49
12.6.
Enhanced Due Diligence (EDD)
50
12.7.
Targeted Financial Sanctions (TFS)
54
13.
Reporting Duties
55
13.1.
Cash Threshold Reporting (CTR)
58
13.2.
Terrorist Property Reporting (TPR)
59
13.3.
Suspicious and Unusual Activity / Transaction Reporting
61
13.4.
International Funds Transfer Reporting (IFTR)
64
13.5.
Reportable Information
64
14.
Risk Monitoring
65
14.1.
Account transaction or activity monitoring and Future Transactions
66
14.2.
On-going Due Diligence for Business Relationships
66
14.3.
Complex / Unusually Large Transactions
66
15.
Record Keeping
67
15.1.
GoAML Records
67
15.2.
Obligation to keep customer due diligence records
67
15.3.
Obligation to keep transaction records.
68
15.4.
Manner in which records must be kept
68
15.5.
Third Party Record Storage
68
15.6.
Period for which records must be kept
70
16.
Training
70
16.1.
Levels of Training
70
16.2.
Training Intervals/Frequency
71
17.
Adoption, Ownership & Approval of RMCP
72
Appendix 1: List of FATF Member States
73
Appendix 2: List of FATF High-Risk Jurisdictions
74
Appendix 3: List of FATF Very High-Risk Jurisdictions
75
Appendix 4: List of DPIP Positions
76
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 5 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 5: List of FPPO Positions
78
Appendix 6: Family Members & Close Associates of FPPO / DPIP
79
Appendix 7: High Risk Industries
80
Appendix 8: High Risk Occupations
81
Appendix 9: Sanctions Lists
82
Appendix 10: Source of Funds and Source of Wealth
84
Appendix 11: Acknowledgement to be signed by all Employees
86
Appendix 12: S43CO Appointment Letter
87
Appendix 13: MLRO Appointment Letter
91
Appendix 14: Summary of Offences and Penalties
95
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 6 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
GLOSSARY OF TERMS Terminology Terminology
Definition
Accountable Institution
any institution in accordance with the list published under Schedule 1 of the Financial Intelligence Centre Act, 2001, and in the context of this document refers to Pinnacle Micro (Pty) Ltd.
Alviva
Alviva Holdings Ltd, of which Pinnacle Micro (Pty) Ltd is a subsidiary.
Anonymous Client
Either a natural or juristic person who refuses to complete and/or provide information and supporting documentation required to verify their credentials, and/or who appears to desire or expresses a desire to transact with the Business anonymously.
Beneficial owner
in respect of a juristic/legal person, means a natural person who, independently or together with another person, directly or indirectly— (a)
owns the juristic/legal person; or
(b)
exercises effective control of the juristic person.
Branch
An office in a different city but still under the legal control of the Business.
Board
The governing body of Pinnacle Micro (Pty) Ltd.
Business Relationship
means an arrangement between a Client and the Business for the purposes of concluding transactions on a regular basis, whereby the Client has completed, accepted, and submitted either a COD Reseller Account Application form or Terms Reseller Account Application form, provided all the necessary documentation and subsequently been approved by Management and/or CGIC.
Business
Pinnacle Micro (Pty) Ltd
Cash
means— (a) coin and paper money of the Republic of SA or of any other country that is designated as legal tender and that circulates as, and is customarily used and accepted as a medium of exchange in the country of issue, (b) travellers’ cheques.
Cash does not include bearer negotiable instruments as defined in the FIC Act. It also does not include a transfer of funds by means of bank cheque, bank draft, electronic funds transfer, wire transfer or other written order that does not involve the physical transfer of cash. These methods of transferring funds are not regarded as cash and are therefore not reportable under section 28 of the FIC Act. Centre
the Financial Intelligence Centre established by section 2 of the FICA.
Client
in relation to an accountable institution, means a person who has entered into a business relationship or a single transaction with an accountable institution.
Credit Guarantee
A South African Financial Services company operating in the field of domestic and
Insurance Corporation of
international credit insurance.
Africa Limited
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 7 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Terminology
Definition
Customer Due Diligence
means ‘Know Your Client’ procedures in respect of identification and verification of identities of clients.
Declaration / Client
a formal document containing questions posed to, and declaration made by, a Client or
Declaration of
Prospective Client in fulfilment of the CDD obligations imposed by FICA and this RMCP.
Ownership and Control Structure Domestic Prominent
any person, or immediate family member or known close associate of a person, listed
Influential Person
under Appendix 4.
Employee
any person acting as such within the Business (whether as a director, shareholder, member, manager, employee, or contractor), or any other Client-facing staff member of the Business.
Executive Officer
in relation to a company, means a person who— (a) exercises general executive control over and management of the whole, or a significant portion, of the business and activities of a company; or (b) regularly participates to a material degree in the exercise of general executive control over and management of the whole, or a significant portion, of the business and activities of a company, irrespective of any particular title given by the company to an office held by the person in the company or a function performed by the person for the company.
Existing / established
A Client with whom the Business has an existing / established relationship, prior to the Implementation Date.
FATF Member State
any country listed under Appendix 1.
Financial Action Task
the independent intergovernmental body (of which South Africa is a member) established
Force
to develop and promote policies to protect the global financial system against money laundering, terrorist financing and financing of proliferation of weapons of mass destruction.
Foreign Prominent
a person, or immediate family member or known close associate of a person, who
Public Official
occupies, or within the past 12 (twelve) months occupied, any of the positions listed under Appendix 4, in a country other than South Africa.
goAML
The FIC’s registration and reporting system.
Governmental Authority
any public authority, and includes (without limitation): the South African Revenue Service; and the Commission for Intellectual Property and Companies; and any organ of state.
Identity Document
any document issued by a Governmental Authority that describes and identifies a natural person by his or her personal attributes, and which attributes must at least include his or her (i) forename and middle name (or initials), (ii) surname, (iii) unique identifying number, (iv) date of birth, and (vi) facial image. ID includes any of the following – green, bar-coded South African identity document, South African identity card, or foreign passport.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 8 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Terminology
Definition
Implementation Date
the date on which the amendment of Schedule 1 came into effect, 19 December 2022.
Inherent risk Legacy Client
This is an assessment of the pure risk taking into account the likelihood/probability and impact/severity levels, and assuming that no controls are in place. any person who had a business relationship with the Business before the Implementation Date, and in respect of whom the Business already has customer due diligence information as at the Implementation Date, albeit in terms of the Business’ own client verification methodology that applied prior to the Implementation Date and this RMCP becoming effective.
Legal arrangement
any other form of corporate arrangement or association.
Legal person / juristic
any person, other than a natural person, that establishes a business relationship or enters
person
into a single transaction, with an accountable institution and includes a person incorporated as a company, close corporation, foreign company or any other form of corporate arrangement or association, but excludes a trust, partnership or sole proprietor.
Management
the individual(s) responsible for the managerial and oversight functions within the business, whether owner, part owner, director, shareholder, trustee, member, partner or employee.
Money laundering /
an activity which has or is likely to have the effect of concealing or disguising the nature,
money laundering
source, location, disposition, or movement of the proceeds of unlawful activities or any
activity
interest which anyone has in such proceeds and includes any activity which constitutes an offence in terms of section 64 of the FIC Act or section 4, 5 or 6 of the Prevention of Organized Crime Act.
Money Laundering
a person, other than the S43CO (FIC Compliance Officer), with the responsibility and
Reporting Officer
authority to submit regulatory reports to the FIC on behalf of Business.
Non-compliance
any act or omission that constitutes a failure to comply with a provision of this Act or any order, determination, or directive made in terms of this Act, and which does not constitute an offence in terms of this Act, and ‘fails to comply’, ‘failure to comply’, ‘non-compliant’ and ‘not complying’ have the corresponding meaning.
Person/s
A natural person(s) and/or legal/juristic person(s).
Principal
for purposes of the Declaration, the party on behalf of whom a Client is authorised to complete the Declaration and deal with the Business
Proliferation
the rapid increase in the number, or the amount of something.
Property
has the meaning attributed to that term in section 1 of the Prevention of Organised Crime Act, namely, “money or any other movable, immovable, corporeal or incorporeal thing and includes any rights, privileges, claims and securities and any interest therein and all proceeds thereof.”
Prospective Client
a person who approaches the Business to enlist the Business' products and/ or services, but that person– is not yet likely, in the discretion of the S43CO, to transfer any Value to the Business; or has not yet firmly indicated that it would like or is ready to transfer Value to the Business, has not completed either a COD Reseller Account Application form or Terms Reseller Account Application form.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 9 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Terminology
Definition
Reporters
the person or entity making the report on goAML.
Representative
the person who is authorised deal with the Business on behalf of the Client.
Residual risk
This assessment provides an indication of the risk taking the likelihood/probability, impact/severity, as well as the existing/current controls effectiveness and existing deficiencies into account.
Risk appetite
the amount of risk (volatility of expected results) that the Business is willing to accept in pursuit of its desired financial performance.
Risk Management and
the programme contemplated in section 42(1) of the FIC Act.
Compliance Programme Risk tolerance
encompasses the broadest expression of risk the Business is willing to assume in executing its strategy. It is the level of risk the Business is willing to endure, and is expressed as either High, Medium or Low.
S43 Compliance Officer
As indicated in Section 43 of the FICA: - the person within the Business charged with overseeing compliance with FICA and this RMCP, or in their absence, - the Business' highest decision-making body (such as the Executive Committee (EXCO), all the members of which shall be jointly responsible and accountable for the Business' FICA and RMCP compliance. Note: if the Business has not appointed and MLRO, the S43CO is also responsible for submitting the prescribed FIC reports.
Sanction Lists
the following lists on appendix 9 on which appear persons and entities that are subject to sanctions measures imposed by the corresponding authority, and which lists are updated from time to time.
Single transaction
a transaction-(a) other than a transaction concluded in the course of a business relationship; and (b) where the value of the transaction is not less than the amount prescribed (i.e. R5000), except in the case of section 20A. This can be described as occasional or once-off business where there is no expectation on the part of the accountable institution or the client that the engagements would recur over a period of time.
Suspicious or unusual
relates to an activity which does not involve a transaction between two or more parties or
activity report
in respect of a transaction or a series of transactions about which enquiries are made, but which has not been concluded, respectively.
Suspicious or unusual
relates to a transaction or a series of transactions between two or more parties in respect
transaction report
of the proceeds of unlawful activities or money laundering.
Teams
Microsoft Collaboration and videoconferencing platform.
Terrorist Activities
any of the offences specified in POCDATARA, all of which relate to terrorism.
Terrorist financing
In respect of the financing of terrorism and related activities where the report relates to an
activity report
activity which does not involve a transaction between two or more parties or is in respect of a transaction or a series of transactions about which enquiries are made, but which has not been concluded, respectively.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 10 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Terminology
Definition
Terrorist financing
In relation to the financing of terrorism and related activities where the report relates to a
transaction report
transaction or series of transactions between two or more parties.
TFS List
Targeted financial sanctions list as published on the FIC’s website
Transaction
a transaction concluded by and between a representative of the AI and a client; a transaction between the Business and the Client under which Value will be transferred between the Business on one hand, and the Client.
Trust
a Trust defined in section 1 of the Trust Property Control Act, 1988 (Act 57 of 1988), other than a Trust established— (a) by virtue of a testamentary disposition, (b) by virtue of a court order, (c) in respect of persons under curatorship, or (d) by the trustees of a retirement fund in respect of benefits payable to the beneficiaries of that retirement fund, and includes a similar arrangement established outside the Republic.
Ultimate Beneficial
in respect of a juristic/legal person, means a natural person who, independently or
Owner
together with another person, directly or indirectly—
unlawful activity
(a)
owns the juristic/legal person; or
(b)
exercises effective control of the juristic person.
has the meaning attributed to that term in section 1 of the Prevention of Organised Crime Act.
Value
any form of economic benefit worth R5 000.00 (five thousand rand) or more.
Abbreviations Abbreviation
Definition
AI
Accountable Institution
AML
Anti-money laundering
BO
Beneficial Owner
CC
Close Corporation
CDD
Customer Due Diligence
CEO
Chief Executive Officer
CFO
Chief Financial Officer
CGIC
Credit Guarantee Insurance Corporation of Africa Limited
COD
Payment must be made and cleared before products and/or services are provided.
CTF
combating the financing of terrorism / counter terrorist financing
CTR
A cash threshold report submitted in terms of section 28 of the FIC Act.
DNFBP
Designated Non-Financial Businesses and Professions
DPIP
Domestic Prominent Influential Person
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 11 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Abbreviation
Definition
EFICA
The Business’ designated third-party software provider’s online web application which is designed to assist with the client identification, verification, screening, and risk rating requirements prescribed by the FICA and the Money Laundering and Terrorist Financing Control Regulations to FICA (the Regulations).
FATF
Financial Action Task Force
FIC
the Financial Intelligence Centre, a juristic person created under chapter 2 of FICA.
FICA
Financial Intelligence Centre Act, No 38 of 2001, as amended from time to time.
FPPO
Foreign Prominent Public Official
HVGD
High Value Goods Dealer
ID
Identity Document
KYC
Know Your Client
ML
Money laundering
ML/TF
Money laundering and the financing of terrorism, where "money laundering" refers to any practice through which the proceeds of crime are dealt with so as to obscure their illegal origins.
MLRO
Money Laundering Reporting Officer
NCCT
Non-Cooperative Countries or Territories as determined by FATF
PEP
Individuals who are or have been entrusted with, or are connected to those with, prominent public functions either domestically or by a foreign country.
PF
Proliferation financing
PFA
Proliferation financing activities
POCDATARA
The Protection of Constitutional Democracy Against Terrorism and Related Activities Act, No 33 of 2004, as amended from time to time.
POPIA
The Protection of Personal Information Act, No 4 of 2013, as amended from time to time.
RMCP
Risk Management and Compliance Programme
S43CO
S43 Compliance Officer
SACRRA
South African Credit and Risk Reporting Association
SAR
Suspicious or unusual activity report.
STR
Suspicious or unusual transaction report.
TF
Terrorist financing
TFAR
Terrorist financing activity report
TFTR
Terrorist financing transaction report
TFS
Targets Financial Sanctions
UBO
Ultimate Beneficial Owner
UNSC
United Nations Security Council
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 12 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
1. Document Control 1.1.
Document Version Control The revision history should contain details of all changes made to this document. No old entries may be amended in any way. Each updated version of the document must contain all history of all previous versions. Version Author
Title
Comment/ Summary of Updates
01.00
Group Risk & Compliance
Inception
M.da Fonseca
Date issued
Next revision due date
Manager 02.00
03.00
K Giltrow
K Giltrow
Pinnacle Head of Legal
Annual Review and
14 November 13 November
and Compliance
Cosmetic changes
2024
Pinnacle Head of Legal
Minor amendments/
28 May 2025
June 2026
and Compliance
additions as per ENS
Pinnacle Head of Legal
Minor amendments/ 23 October
June 2026
and Compliance
additions as per FIC
2025
feedback 04.00
K Giltrow
2025
feedback
1.2.
Document Approval All parties listed below acknowledge that they have read, understood and agree with all the information as specified in this document and that the document is accurate and complete. Version
Name
Title
Date
01.00
Tim Humphreys Davies
CEO/Managing Director
02.00
Tim Humphreys Davies
CEO/Managing Director
14 November 2024
03.00
Tim Humphreys Davies
CEO/Managing Director
28 May 2025
04.00
Tim Humphreys Davies
CEO/Managing Director
23 October 2025
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 13 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
2. Purpose of FICA and this RMCP The purpose of the Financial Intelligence Centre Act (FICA) is to root out money laundering and terrorist financing (ML/TF), which places in jeopardy the economy and constitutional order of any country. FICA seeks to fulfil this purpose by imposing certain obligations on Accountable Institutions (AI’s) which are recognised as potential vehicles for financial malfeasance. These obligations regulate the way Accountable Institutions handle money and property in the course of their business dealings with Clients and Prospective Clients. On 19 December 2022 amendments made to the FICA Schedule 1, Item 20 resulted in certain designated non-financial businesses and professions (DNFBP), being determined as new AI’s with an updated definition to High-Value Goods Dealers (HVGD’s). An HVGD is defined as “A person who carries on the business of dealing in high-value goods in respect of any transaction where such a business receives payment in any form to the value of R100 000,00 or more, whether the payment is made in a single operation or in more than one operation that appears to be linked, where “high-value goods” means any item that is valued in that business at R100 000,00 or more.” Consequently, Pinnacle Micro (Pty) Ltd (the Business) is required to adhere to the obligations imposed on them as an Accountable Institution, under the FICA and associated Money Laundering and Terrorist Financing Control Regulations (the Regulations). A key requirement of FICA is to develop, document, maintain and implement a Risk Management & Compliance Programme (RMCP) as a mechanism for the Business to identify, assess, mitigate, manage, and monitor ML/TF/PF/PFA risks. The RMCP will set out the procedures the Business will follow in order to identify, verify, screen and risk rate its clients and, where applicable, their related BO/UBO’s before entering into a business relationship or transaction with them in order to determine ML/TF risks the potential Client may present. The RMCP and, indeed, FICA itself, exist within the wider context of –
South Africa's status as a FATF Member State; and
the Business' own commitment to playing its part in protecting South Africa's financial system and constitutional democracy, by effectively identifying and managing the ML/TF risks to which the Business is exposed, and by co-operating with the relevant authorities whenever this is called for.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 14 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Procedures regarding:
collecting and verifying information about Clients,
keeping records of its Clients' Transactions, and
reporting information to the relevant authorities in certain circumstances, are crucial to FICA's efficacy, and will be outlined in the RMCP.
2.1.
Seven Pillars of FICA Compliance The seven (7) pillars of compliance to the FICA requirements are summarised as follows:
Registration with the FIC,
Appointment of the person responsible for governance and oversight of AML/CTF/FICA compliance,
Development and implementation of the Risk Management & Compliance Programme (RMCP),
Client identification and verification,
Reporting,
Training of employees, and
Record keeping.
Furthermore, this RMCP seeks to provide for all the requirements as set out in section 42 read with section 42A of the FIC Act and are discussed thematically as follows:
The RMCP governance,
ML/TF/PF risks assessment and risk-rating framework,
Customer due diligence controls,
Prominent influential person controls (also referred to as “Politically Exposed Persons” (PEP’s)),
Targeted financial sanctions controls aimed at terrorist financing,
Targeted financial sanctions controls aimed at proliferation financing (section 26A, 26B and 26C of the FIC Act),
Account monitoring,
Reporting controls, and
Record-keeping controls.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 15 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
2.2.
Review of the RMCP
The Business will review this RMCP annually to ensure that the programme remains relevant to the Business’ operations and the achievement of the requirements of the FICA.
Notwithstanding the annual review, if:
In the S43CO’s discretion, there is a change in the circumstances of the Business that warrants an interim review of the RMCP, such as material changes to the processes,
the S43CO may affect such amendments to the RMCP as are appropriate considering the changed circumstances; and
will do so within 30 days of this change being made.
There is a legislative change to relevant legislation,
then the S43CO will effect the necessary amendments to the RMCP, and
will do so within 30 days or within the prescribed legislated changes.
All reviews will be approved by the CEO and recorded in the Document Control section (paragraph 1) of this RMCP.
3. About the AI as an HVGD 3.1.
Nature of the Business
Pinnacle Micro (Pty) Ltd is a private company, as defined in the Companies Act, 2008 with CIPC Registration No. 1993/000917/07.
The head office is located at 269 16th Road, Randjespark, Midrand, Gauteng, South Africa, with operational, dependent branches located in Cape Town, Durban, Gqeberha, Bloemfontein, Nelspruit, which fall under the scope of this RMCP.
The Business sells computer hardware (physical goods), some of which may be valued at R100,000.00 or more, and as such it is deemed as a High Value Goods Dealer (HVGD) in terms of the FICA revision of Schedule 1, Item 20 and therefore classified as an Accountable Institution (AI).
The Business, it’s duly appointed FICA Compliance Officer (S43CO) and MLRO/MLRO’s have been registered with the FIC, who have provided organisation ID: 60175. Any changes in the Business details and/or appointments will be appropriately updated with the FIC within five (5) business days.
The Business is classified as a distributor/wholesaler.
Its clients are referred to as resellers/dealers/retailers, who in turn sell to end-users/consumers.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 16 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
All Clients are required to complete, accept the terms and conditions, and submit, either a COD Reseller Account Application form or Terms Reseller Account Application form, together with copies of all the necessary documentation, for subsequently approval by Management and/or CGIC.
3.2.
Philosophy
The Business mandates each of its business units, all employees, directors, and anyone who performs work on its behalf, to carry out their business and perform their duties: to the highest ethical standards; and in compliance with all relevant legal, contractual, and other requirements. We acknowledge and applaud everyone who upholds our ethical values.
The Board supports the adoption and implementation of adequate processes and mechanisms to identify, assess, mitigate, manage, and monitor the risks that may involve or facilitate ML/TF/PF/PFA, and, in all aspects of this RMCP.
3.3.
Applicability & Availability of the RMCP The RMCP applies to all employees and branches of the Business and is made available to employees via the following distribution channels: E-mail, Physical delivery to all staff who do not have dedicated workstations, Intranet, and Scubed (Company internal HR platform)
The Business does not have foreign branches. All foreign companies are separate legal/juristic persons.
The updated RMCP is uploaded onto the GoAML portal by either the MLRO or the S43 compliance officer.
A copy of the Risk Management and Compliance Programme and related information will be available upon request to: the Financial Intelligence Centre; or a supervisory body which performs regulatory or supervisory functions in respect of the Business.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 17 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
3.4.
Implementation of the RMCP
The RMCP will be implemented over 12 months by means of [training workshops, emails] based on the role and function of the employee.
The implementation of the RMCP will be done, via: Microsoft Teams and in-person workshops, Awareness emails, and Policy/Playbook
3.5.
Accounts Payable
3.6.
The Business does not make any payments in cash.
Accounts Receivable
The Business has an average of [2500] active Clients and onboards approximately [100] new Clients per month.
The Clients (local and foreign) may be classified as follows: Large & medium corporates SME/SMME SOE Trusts / Partnerships
The Debtors/Accounts Receivable department, located at the head office in Gauteng, is responsible for, inter alia, the following processes: Client verification and on-boarding, Client payment verification, receipts, and allocation.
The National Credit Manager has, therefore, been duly appointed as the S43 Compliance Officer.
Whilst the Business has branches in the following locations, Debtors/Accounts Receivable roles and functions are performed by each branch: Gauteng KwaZulu Natal Qheberha Cape Town
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 18 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Bloemfontein Nelspruit
4. Governance of RMCP & FICA Requirements 4.1.
Prohibition and Offence
Employees at all levels of the Business may not alert the Client (either prospective Client or established Client), whether directly or indirectly as to the fact that a report is about to or has been made to the S43CO or to the FIC (as the case may be), nor as to the content of the report.
Any person who knows, suspects or ought reasonably to have known or suspected— that information has been disclosed to the Centre; or that an investigation is being, or may be, conducted as a result of information that has been or is to be disclosed to the Centre, and who directly or indirectly alerts, or brings information to the attention of, another person which will or is likely to prejudice such an investigation, is guilty of an offence.
4.2.
Board of directors & senior management
The Board is ultimately accountable for the governance of compliance with the FICA obligations, in a way that supports the organisation being ethical and a good corporate citizen.
The Board is responsible for ensuring that the Business maintains an effective internal AML/CFT control structure through the RMCP and ensuring compliance by the Business and its employees with the provisions of FIC Act and this RMCP.
The Board and senior management (ExCo/Manco) exercise the highest-level decision-making body in the Business and, as such shall be jointly responsible for providing the necessary active and visible support to the S43CO in ensuring FICA and RMCP compliance across the Business.
The CEO/MD, Tim Humphreys Davies, and CFO, Coert Vorster, are responsible for the ownership, review, adoption, and approval of the RMCP.
4.3.
S43 Compliance Officer
Mario Mynhardt, as the National Credit Manager has been appointed as the FIC Compliance Officer, referred to as the S43 Compliance Officer, and holds the following qualifications and experience to
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 19 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
sufficiently demonstrate competence, seniority, and experience in assisting the Board in discharging their FICA obligations: BCOM Financial Management National Diploma: Cost and Management accounting Diploma in Management
As the appointed S43CO, he is responsible to: see to it that all Employees are properly sensitized, through appropriate training and instructional material, to their FICA duties in general, and to their duties under this RMCP in particular; and publish this RMCP in such a manner that all Employees are alerted as to its existence, and can access it freely and with ease; and ensure that all Employees sign an acknowledgement conforming to the format set out in Appendix 11; and screen all Prospective Clients against the sanctions lists as per Appendix 9 before they are onboarded, take action in the event a Prospective or Existing Client appears on any of the Sanctions Lists as noted above, and see to the Business' effective implementation of this RMCP.
4.4.
The detailed duties and responsibilities may be found in Appendix 12.
Money Laundering Reporting Officer
The appointed Money Laundering Reporting Officer (MLRO) is responsible for: submitting reports to the FIC on go AML, and/or assisting the S43CO per the detailed duties and responsibilities which may be found in Appendix 13.
The following person(s) is/are appointed as the MLRO for the Business: Edna de Klerk Jo- Ann Twigg
4.5.
All Employees
This RMCP is legally binding on all Employees, and any non-compliance therewith is regarded by the Business as serious misconduct.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 20 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Contravention may result in disciplinary action, including the termination of employment.
Certain breaches could also result in civil or criminal proceedings.
Furthermore, all employees are required to report all suspicious ML/TF/PF/PFA related behaviour, and all suspected or known non-compliance to Mario Mynhardt, the S43CO.
All employees are to undergo FICA check, which is conducted by Human Resources. Further all employees are to complete the Employee Due Diligence Survey.
4.6.
Escalation of Non-Compliance with or Breach of RMCP/FICA
All instances of non-compliance with or breach of, this RMCP and associated processes, and/or the FIC Act and associated Regulations must be escalated immediately upon becoming aware thereof, to Coert Vorster – CFO, and/or Mario Mynhardt – S43CO
The escalation may initially be done verbally, but must be substantiated in writing by email, and include as much information related thereto, such as: Description of the non-compliance Date and time Details of the parties involved in the non-compliance. Any other detail describing the non-compliance.
4.7.
High-level Remediation Processes
The S43CO will maintain records of all reported and investigated non-compliance.
As noted below, the S43CO will provide written details of corrective measures to be taken, together with appropriate timeframes for resolution, and these must be effectively adhered to avoid noncompliance of the RMCP and FICA requirements, as well as disciplinary consequences.
The non-compliance matter will be reported back to the CEO/CFO as well as corrective actions.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 21 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
5. Introduction to Risk and ML/TF/PF/PFA 5.1.
What is risk? The concept of risk is often described as the effect of uncertainty on objectives, and that an effect is a positive or negative deviation from what is expected. This uncertainty is a function of three factors: threat, vulnerability, and consequence.
Threats refer to the potential to cause harm. In the context of ML/TF/PF this includes criminals, terrorist groups and their facilitators, their funds, as well as the past, present, and future money laundering or terrorist financing activities. These may also be considered as external factors.
Vulnerabilities comprise those things that can be exploited by the threat or that may support or facilitate its activities. Identifying vulnerabilities, as distinct from threats, means focusing on, for example, the factors that represent weaknesses or features that may be exploited in a given system, institution, product, service etc. These may also be considered as internal factors. The areas in which these vulnerabilities may arise are discussed in more detail in paragraph 10.
Consequences refers to the impact and likelihood materialising as a result of a combination of threats and vulnerabilities manifesting.
Ways in which to manage or deal with risks may include:
Treat - Changing the likelihood or impact of the risk,
Tolerate - Accepting / retaining the risk.
Terminate - Avoiding risk or removing the source of the risk, or
Transfer - Sharing the risk with another party/parties.
What are inherent and residual risks?
Inherent risk is the risk of an event or circumstance that exists before controls or mitigation measures are applied.
Residual risk is the level of risk that remains after controls and mitigation measures were implemented.
5.2.
What is Money Laundering (ML)?
Money laundering is the manipulation of money or property to disguise its true source.
Criminal activities, such as drug trafficking, human trafficking, racketeering, and corruption generate large amounts of profits for individuals or groups carrying out these activities. When criminals are
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 22 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
successful in generating returns from these criminal activities, they obtain illegal earnings that cannot be explained.
To avoid drawing the attention of the authorities and benefit from the proceeds of unlawful activity, criminals must conceal the origins of these funds.
This is the process of money laundering. The result of a successful money laundering scheme is that proceeds from an underlying unlawful activity are no longer associated with the activity. Unlawfully acquired proceeds therefore appear to be legitimate income.
5.3.
What is Terrorist Financing (TF)?
The financing of terrorism involves the solicitation, collection and the providing of funds and other assets, with the intention that it may be used to support terrorist acts, terrorist organisations or individual terrorists.
The funds and assets may stem from both legal and illicit sources. The primary goal of persons involved in the financing of terrorism is not to only conceal the sources of the funds and assets, as with money laundering, but to conceal both the financing and the nature of the activity being financed.
5.4.
What is Proliferation Financing (and Proliferation Financing Activities) (PF/PFA)?
Proliferation financing (and Proliferation financing activities) refers to the act of providing funds of financial services and or providing property, a financial service or economic support to a non-State actor which is used, in whole or in part, for the manufacture, acquisition, possession, development, export, trans-shipment, brokering, transport, transfer, stockpiling or use of nuclear, chemical or biological weapons and their means of delivery and related materials (including both technologies and dual use goods used for non-legitimate purposes), in contravention of national laws, or where applicable, international obligations.
https://www.un.org/securitycouncil/sanctions/information
http://www.fatf-gafi.org/media/fatf/documents/reports/Guidance-Countering-ProliferationFinancing.pdf
5.5.
What risk does ML/TF/PF/PFA pose?
Money laundering / terrorist financing / Proliferation financing and Proliferation financing activities (ML/TF/PF/PFA) risks are threats and vulnerabilities which put the Business at risk of being abused to facilitate ML/TF/PF/PFA activities.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 23 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
By using the Business’ products and services and abusing procedures and processes, a malicious Client can exploit the Business to promote money laundering or terrorist financing activities. This would result in the Business being regarded as part of the ML/TF process, resulting in the risk of prosecution or administrative sanctions, reputational risk, and financial loss.
When identifying and assessing these risks, various factors must be considered, such as the nature of our products and services, type of Clients and their ultimate beneficial owner (UBO’s), the geographic locations of the Clients and the Business’ operations, the delivery channels through which persons become clients or through which clients access its products and services, etc.
To have a robust ML/TF/PF/PFA risk management system, the Business must be able to demonstrate how it contextualises the concepts of “ML/TF/PF/PFA risk” as having an impact on its operational, line management and strategic objectives.
5.6.
What is ML/TF/PF/PFA risk management?
ML/TF/PF/PFA risk management is a process that includes the identification of ML/TF/PF/PFA risks, the assessment of these risks, and the development of methods, systems, and controls to manage and mitigate the identified risks.
The mechanisms included in its risk management systems and controls may include the application of customer due diligence measures, the monitoring of business relationships and transaction with clients, managing delivery channels for particular products and services, etc. The potential risk management mechanisms are discussed in more detail later in this guidance.
The concepts of “ML/TF/PF/PFA risk” and “ML/TF/PF/PFA risk management” must always be contextualised within the functions of the Business, and as having an impact on the operational, line management and strategic objectives.
The application of risk management systems and controls must be commensurate with the extent of assessed risks. This means that the extent to which particular risk management mechanisms are applied in individual cases must bear relevance to consequences of ML/TF/PF/PFA risk in particular scenarios in relation to the likelihood and impact of the risk.
The process to manage ML/TF/PF/PFA risk is a continuous cycle, and the Business should ensure that ML/FT/PF risk management systems and controls remain adequate in view of changing circumstances relating to emerging threats and vulnerabilities, product innovations, new target markets, changes in circumstances of individual clients or classes of clients, etc.
The Business should ensure that ML/FT/PF risk management systems and controls are adhered to within the organisation.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 24 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The reassessment ML/TF/PF/PFA risks, in particular residual risks, as well as the adequacy of the systems and controls should be done at regular intervals.
6. Clients & Business Relationships 6.1.
Prospective Clients When the Business engages with a prospective client to enter into a single transaction or to establish a business relationship, it must, in the course of concluding that single transaction or establishing that business relationship:
establish and verify the identity of the client,
if the client is acting on behalf of another person, establish and verifythe identity of that other person; and the client’s authority to establish the business relationship or to conclude the single transaction on behalf of that other person; and
if another person is acting on behalf of the client, establish and verifythe identity of that other person; and that other person’s authority to act on behalf of the client.
In addition, to reasonably determine whether future transactions that will be performed in the course of the business relationship concerned are consistent with the Business’ knowledge of that prospective client, the Business must obtain information describing: the nature of the business relationship concerned, the intended purpose of the business relationship concerned, and the source of the funds which that prospective client expects to use in concluding transactions in the course of the business relationship concerned.
6.2.
Timing of verification
The banking details of the Business must not be shared with a prospective Client until such time that the necessary customer due diligence, and where applicable, Management approval of the Client has been performed and successfully concluded.
Furthermore, the Client must be informed that accepting a mandate from a prospective client to establish a business relationship or take steps to conclude a single transaction or take any similar preparatory steps with a view of establishing a business relationship, before completing verification
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 25 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
of the identities of the prospective client and other relevant persons, does not constitute or give rise to a commitment from the Business until such time that the necessary customer due diligence, and where applicable, Management approval of the Client has been performed and successfully concluded.
These precautions are required to ensure the Business does not incur unmitigated ML/TF risks by, for example, receiving funds from a client which may have to be returned to the client due to their applications being declined, as this may constitute the Business being found guilty of moneylaundering.
6.3.
Established Business Relationships
In terms of the FICA, the Business may not conclude a transaction during that business relationship, unless the Business has taken the prescribed steps: to establish and verify the identity of the client, if another person acted on behalf of the client in establishing the business relationship, to establish and verifythe identity of that other person, and that other person’s authority to act on behalf of the client, if the client acted on behalf of another person in establishing the business relationship, to establish and verify— the identity of that other person; and the client’s authority to act on behalf of that other person; and to trace all accounts of the Business that are involved in transactions concluded in the course of that business relationship.
Fortunately, where the Business has an established business relationship with a client before this Act took effect, it has, as part of its standard operating requirements, taken certain measures to identify the Client as noted in paragraph 10.4 herein.
In the interest of business continuity all active clients will be risk assessed and prioritised for FICA evaluation accordingly. The Business plans to have all active clients evaluated within 12 months.
6.4.
Anonymous or Fictitious Clients
The Business is strictly prohibited from dealing with: anonymous persons, and persons who have fictitious names.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 26 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
By adhering to the provisions of this RMCP, the Business avoids the risk of: dealing with a person who refuses, appears to desire, or expresses a desire to transact with the Business without providing the accurate and necessary information and supporting documentation required to verify their legitimacy, dealing with a fictitiously named person by subjecting all Prospective Clients to the CDD procedures described in paragraph 12, which are aimed at ensuring, amongst other things, that the Business only deals with persons who exist.
6.5.
Business Relationship with a DPIP or FPPO
The Business must determine whether a Client and/or its BO/UBO is an FPPO or DPIP, by means of the Client providing this information in the Declaration and the Business verifying same using EFICA.
If the Client and/or its BO/UBO is an FPPO, or a high-risk DPIP is looking to establish a Business Relationship, then, in addition to the prescribed CDD procedures, the Business must: only on-board the Client with the approval of the CEO and/or CFO, establish and verify the Client's source of funds source of wealth; where: the source of funds is determined by considering the origin and the means of transfer for funds that are involved in the transaction (for example, occupation, business activities, proceeds of sale, corporate dividends), and the source of wealth is determined by considering the activities that have generated the total net worth of the client (that is, the activities that produced the client’s funds and property), and monitor the Business Relationship more closely than it would monitor any other Business Relationship.
6.6.
Non-compliant Clients & Terminating Business Relationships
If the Business is unable to: establish and verify the identity of a Client or other relevant person in accordance with section 21 or 21B, obtain the information contemplated in section 21A, conduct ongoing due diligence as contemplated in section 21C, or the Client and or UBO appears on the TFS List, the Business:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 27 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
may not establish a business relationship or conclude a single transaction with a Client, may not conclude a transaction in the course of a business relationship, or perform any act to give effect to a single transaction, or must terminate an existing business relationship with a client, as the case may be, and consider making a report under section 29 of this Act.
In the context of established Business Relationships, the Business will: request the Client to complete the Declaration and provide the necessary information and documentation within ten (10) business days. The Business will then allocate five (5) business days to review the information and request additional information, if necessary. Once reviewed the Business may find that some information is missing or additional information is required, the Client will then be given 5 days to submit the missing /additional information. In the event the Client is not forthcoming therewith, the National Credit Manager will contact the Client CEO or equivalent highest-ranking designation, to reiterate the requirements and request submission within five (5) business days. The national credit manager will escalate to CEO/CFO to assist where required If these are still not provided within five (5) business days, the Client account will be suspended, and no further transactions will be permitted. The S43CO will instruct the MLRO to submit a Suspicious Activity Report via go AML. The CFO and S43CO will contact the counterparts at the Alviva subsidiaries who are also designated AI’s and inform them hereof. These AI’s will also be required to suspend transactions with this Client until such time the non-compliance is addressed, if applicable.
7. Sources of Information
The Business will make use of copies of government issued documents received from the Client as the means of verification for basic identity attributes including, but not limited to, identity or company registration.
The Business uses EFICA to verify information provided by the Client including, but not limited to, identity, address, company name, registration number, directors’ information and contact details. EFICA uses third party suppliers to verify the ID information against Home Affairs and personal information against SACRRA.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 28 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Electronic or certified copies of ID documents are obtained depending on level of due diligence required.
All information shared on EFICA is done with the Client’s consent which is provided by the Client at the time of their completion of the Client Declaration and Ownership Structure document.
The Business will also make use of EFICA for adverse media screening.
The Business will use EFICA to screen against Sanctions or Global PEP Lists. EFICA uses third party data providers to screen against the Sanction and Global PEP Lists (as per Appendix 9).
7.1.
Client information and documentation
7.1.1.
Client Declaration The Business requires all its legacy Clients as well its prospective Clients to complete the Client Declaration and Ownership Structure document.
The document makes provision for the Client to: list the following to determine beneficial ownership (as noted in Point 10.7): all individuals who directly own 5%, or more, shares or members interest or voting rights at a general meeting of the Client, and all individuals who indirectly own 5%, or more, shares or members interest or voting rights at a general meeting of the Client (for example, through another entity or trust), or all individuals who control the Client through other means, or all individuals who exercise control over the management of the Client e.g., Senior Management. provide an indication of their source of funds. provide electronic or certified copies (depending on the level of due diligence required) of the following documents related to Natural Persons: ID/Passport, Proof of residence. provide electronic or certified copies (depending on level of due diligence required) of the following documents related to Juristic Persons: CIPC, Incorporation documents/ constitution/ founding documents/ partnership agreements confirming Name, address, registration number, etc. provide a company organogram of the ownership structure.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 29 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
7.2.
Doubts about the veracity of information Where an Employee has doubts about the accuracy and/or authenticity of information that it
previously obtained from an existing Client, they must take reasonable steps to verify the information's accuracy or otherwise, such as: request copies certified by a Commissioner of Oaths, organogram signed off by company secretary/accountants.
8. Risk Management 8.1.
Process The risk management process comprises the following phases:
RISK IDENTIFICATION & ANALYSIS • •
Identifying the regulatory obligations that apply to the Business. Identifying and determining the risk indicators / factors that would be appropriate to conduct a risk analysis. RISK ASSESSMENT
•
Prioritizing the regulatory obligations by rating each according to their potential impact and likelihood. RISK MANAGEMENT & MITIGATION
• • •
Developing internal control measures that will ensure compliance and facilitate the implementation thereof, including but not limited to the FICA CDD and reporting obligations. Evaluating the effectiveness of internal control measures. Applying appropriate risk management strategies. RISK MONITORING & REPORTING
• •
Monitoring the internal control measures that have been implemented to determine the level of compliance and whether the controls are effective. Providing reports and recommendations to the Board and senior management in respect of the effectiveness of the internal control procedures. The Business makes use of EFICA (as defined herein - an online/web application software-as-aservice (“Saas”) system) to: capture client information,
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 30 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
identify the client, verify the client’s information, screen the client against sanctions & PEP lists, screens the client for adverse media, and ultimately risk rates the client as low or high risk based on EFICA’s Risk Scoring Matrix which considers a range of metrics that are appropriate for the Business’ operations.
8.2.
Mechanisms
The mechanisms to address the obligations include: Adoption and implementation of this RMCP, Employee awareness and training, Client analysis (inter alia, Client Declaration of Ownership and Control Structure), Evaluation/Screening Tools (collection, verification of customer documents, EFICA online platform), Process to review and approve/decline higher risk transactions and relationships, Process to exit high-risk business relationships, Oversight of higher risk activities, Reporting and escalation channels.
9. Risk-Based Approach The objective of the RMCP is to identify risk in terms of ML/TF/PF, assess the inherent ML/TF/PF risks faced by the Business and to ensure effective and appropriate controls are designed to mitigate the risk to an acceptable level. However, the FIC Act requires the Business to apply a risk-based approach when carrying out customer due diligence (CDD) measure.
9.1.
Effect of a risk-based approach
The Board understands that risk is inherent to any business and therefore also to its own business. The identification and management of risk, including risk relating to ML/TF, is central to delivering products and services that are consistently compliant with the FIC Act.
By applying a risk-based approach the Business can ensure that measures to prevent or mitigate money laundering and terrorist financing are commensurate with the risks identified. This will
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 31 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
ensure that resources are directed in accordance with priorities, so that the greatest risks receive the highest attention.
The risk-based approach also affords the Business the flexibility to use a range of mechanisms to establish and verify the identities of its clients.
This approach improves the efficacy of measures to combat money laundering and terrorist financing while promoting financial inclusion without undermining Anti-money Laundering, Counter Terrorist Financing and Counter Proliferation financing (and Proliferation financing activities), “AML/CFT/CPF” objectives.
The risk-based approach further allows the Business to simplify the due diligence measures applied where they assess ML/TF/PF/PFA risks to be lower.
9.2.
Risk Rating methodology
The Business has determined certain risk indicators in the assessment of its ML/TF risks. As the Business’ understanding and application of the FICA requirements matures, it will evaluate, and where necessary adjust, the relevance of particular risk factors and the appropriateness of previous risk-ratings over the next 12 months.
The risk scale has been defined as follows: High – where the definitions and/or components related to the indicators in paragraph 10 can be associated with or applied to either a natural or juristic person (the Client), they will be determined to be high risk. Low – by default, where the definitions and/or components related to the indicators in paragraph 10 cannot be associated with or applied to either a natural or juristic person (the Client), they will be determined to be low risk. Pinnacle considers medium risk in this category.
Risks rated as “high” require additional or enhanced due diligence and require more frequent or ongoing focus on monitoring.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 32 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
This process of risk identification is performed on the EFICA platform.
The Business performs fairly extensive standard customer due diligence, as noted in paragraph 12, on all its Clients by: Obtaining the duly completed Declaration, Copies of ID/Passport of all BO’s who have 5% or more ownership, Copies of CIPC documents, etc.
The information provided in the Declaration is then captured into the EFICA platform which in turn provides risk rating of the Client. The process determines different levels of risk i.e., low or high, which assists the Business with prioritizing the risk and the subsequent remediation in a manner which makes the best use of its resources.
10. ML/TF Risk Indicators The risk indicators listed below have been identified as impacting ML/TF/PF/PFA risk within the Business’ operations with an explanation of their rating methodology.
10.1. Business-Level Risk Assessment
The business-level risk assessment indicates ML/TF/PF risks faced by the Business. The FICA risk register should revised on a quarterly basis in order to ensure the business-level risks and planned actions to improve the controls are regularly monitored.
The summary of the assessment done on 22 August 2023 is summarised in the Pinnacle Micro (Pty) Ltd Risk Register which accompanies this RMCP.
10.2. Software-as-a-Service (SaaS)
The utilization of EFICA, an online/web application software-as-a-service (“Saas”) system, as a tool in the risk identification, assessment, rating, and management processes, provides the Business with the benefits of an interactive platform which is accessible to the Board, as well as its management and compliance teams in a live state.
EFICA simplifies the risk management process and facilitates effective control, monitoring, and reporting.
EFICA is used to: capture client information,
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 33 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
identify the client, verify the client’s information, screen the client against sanctions & PEP lists, screen the client for adverse media, and ultimately risk rate the Client as low or high risk.
EFICA uses the following criteria as set out in paragraph 10 and the applicable Appendix. Natural person or legal entity and complexity of the ownership structure of the legal entity, Geographical location of the natural person/entity, Occupation/Industry of the Natural person/entity, DPIP/FPPO status, Source of funding for transaction, Type of transaction/Product, If the client is known to the business or unknown, and Adverse media findings.
The decision to accept, reject, or require further approval from senior management is based on: A high-risk rating received from the EFICA platform Customer not providing the required information or consent, however, We have obtained necessary information to make an informed decision We have previously dealt with the customer per 10.4.1 below.
10.3. Products & Services Offered
The Business has considered the types of products it sells against the FIC’s Guidance Note 7 in respect of the evaluation of product risk in the assessment process. The range of products and related factors the Business offers to Clients, has resulted in several of the products being classified as high risk as noted below.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 34 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
10.4. Client Risk-rating & Profiling 10.4.1.
Legacy Clients The Business has been established for many years prior to the recent amendments to the FICA and, therefore, has a significant number of legacy clients who need to be assessed and verified as soon as possible.
Without having a severely negative impact on the longevity of the Business, it is impossible to discontinue trading with the legacy Clients until the FICA CDD requirements have been completed.
Fortunately, the Business has existing/legacy processes in place which required legacy Clients to complete account application forms and provide various documents to verify the data provided on the account application form, including shareholding certificates, copies of ID’s, CIPC documents.
However, the deficiencies in the legacy process are noted as follows: Documents were not assessed against external databases, and UBO’s were not necessarily determined.
It is, therefore, appreciated that it will require planned effort, resources, and reasonable timelines to obtain all the necessary documentation and perform the necessary FICA CDD assessments and verifications. The Business has therefore chosen to categorise and subsequently prioritise its legacy Client base in order to systematically work through the database of legacy clients.
The categorisations and prioritisation are based on the following elementary parameters for the purposes of prioritising and performing the FICA CDD requirements : Entity Name Reg. No. / Trust Ref No. Date A/C opened Priority 1 - after 19/12/22
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 35 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Priority 2 – between 01/01/22 and 19/12/22 Priority 3 – before 01/01/22 Annual Sales Turnover rating Priority 1 - Greater than R30m Priority 2 - Between R10m and R30 Priority 3 – Between R1m and R10m Priority 4 – Less than R1m Associations outside of SA Priority 1 – Yes Priority 2 - I don’t know Possible known DPIP / FPPO associations Priority 1 – Yes Priority 2 - I don’t know
The results of the above categorisations and prioritisation will be used to determine which clients will be targeted first to complete the assessment and verification process.
10.4.2.
Thereafter Clients will be assessed and risk-rated using the EFICA system and process.
New Clients All new Clients are required to complete the CDD process as noted herein prior to the Business transacting with the Client.
10.5. Legal Entity/Juristic Person Types Contracted
The entity type plays a role in the ML/TF/PF/PFA risk assessment process in respect of clients who are legal persons. The legal entity/juristic person have been risk rated as follows:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 36 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
In addition to the application of the Risk Scoring Matrix, as above a Client may be assessed as high risk should their conduct include (but not limited to): a reluctance or refusal to provide information; or deliberate evasiveness or vagueness when providing information; or being party to a complex or unusual pattern of transactions that have no apparent business or lawful purpose; or any other conduct or circumstances that, when viewed objectively, and when considered in light of all of the relevant factors taken as a whole, should be regarded with suspicion.
10.6. Natural Persons/Beneficial Owners
Natural persons or BO’s are the “warm bodies’ who ultimately own or control a legal entity/juristic person.
The Declaration requires the Client to provide the required details of the natural persons or BO/UBO as follows: all individuals who directly, own 5% or more of the shares or members interest or voting rights at a general meeting of the Client, and all individuals who indirectly own 5% or more (for example, through another entity or trust), or all individuals who control the Client through other means, or all individual(s) who exercise(s) control over the management of the Client e.g., Senior Management.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 37 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The initial risk assessment of juristic entities will inform the level of due diligence required on Beneficial Owners as follows: Where a juristic entity is assessed to be low risk, full due diligence procedures will be required on all natural persons who are Ultimate Beneficial Owners of more than 5% of the entity in question; or Where a juristic entity is assessed to be high risk, full due diligence procedures will be required on all natural persons who are Ultimate Beneficial Owners of more than 10% of the entity in question.
10.7. Prominent Persons – DPIP and FPPO
The list of DPIP’s and FPPO’s may be found in Appendix 4 and Appendix 5, respectively.
The immediate family members or known close associates of a person are included in the definition of a DPIP, and this list may be found in Appendix 6.
At the commencement of the business relationship a Client (or immediate family member or known close associate thereof) might meet the definition of a prominent person, or the Business may not be immediately aware thereof. If the Client’s status changes, or the Business becomes of the status after establishing a business relationship, the Business will perform the necessary enhanced due diligence to re-assess the risk and subsequently take the necessary actions as required in this RMCP.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 38 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
10.7.1.
DPIP’s
Business relationships with domestic prominent influential persons are not inherently high-risk.
The CFO and S43CO will consider each such relationship on its own merits in order to determine whether there is any reason to conclude that it brings higher risk of abuse for money laundering and terrorist financing purposes. If so, the Business must apply the same requirements as for foreign prominent public officials.
10.7.2.
These requirements also apply to immediate family members and know close associates of the DPIP.
FPPO’s
Business relationships with foreign prominent public officials are always be considered high-risk.
The CEO and CFO are required to approve the business relationships with a client who is an FPPO or who BO/UBO is a FPPO.
Furthermore, the Business will also take reasonable measures to establish the source of wealth and source of funds of the Client and conduct enhanced ongoing monitoring of the business relationship.
The Business is not required to verify the information about the Client’s source of wealth and source of funds but will include this information in its client profile on EFICA, which will be used as the basis for enhanced ongoing monitoring, whereby the Review date will be set for every three months instead of annually.
These requirements also apply to immediate family members and know close associates of the FPPO.
10.8. Geographic Locations The Business engages with prospective Clients and established business relationships who are natural or legal persons resident within the borders of South Africa as well as foreign countries. Each of these needs to identified and risk assessed appropriately.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 39 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
10.9. Transaction Type – Business Relationship, Single Transactions
The products and services offered by the Business grants it the capability of entering into either single transactions, or business relationships with Clients, regardless of the Value of the transaction(s).
However, each client is required to have their own dedicated trading account as no transactions are processed on a general, unnamed cash sale account.
Each client is therefore required to provide all relevant documentation in order to perform the necessary client verifications, prior to concluding any transaction.
The following activities are considered to be single transactions less than R5 000:
Customer regular buys same item below R5000
Customer is buying once off
The following activities are considered to be single transactions above the R5 000:
Customer buying an item which we displayed on promotion
Customer is buying once off
The following activities are considered to be business relationships:
Transacting on behalf of a subsidiary company as an intermediary where the subsidiary hold the information of the client
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 40 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
10.10. Payment Types
The Business does not pay any of its suppliers or vendors in cash, and all payments are made via EFT.
The Business does receive, cash payments at their premises.
Furthermore, Clients have been requested to not conclude cash deposits directly in the Business’ bank accounts.
However, there have been instances where Clients have not adhered to the request and bank statements are therefore analysed daily to identify cash deposits and submit the necessary FIC reporting requirements via goAML.
The following payment types from Clients are accommodated:
10.11. External Risk Elements Although the Business has formulated a calculated risk model, it does recognize that there may be other, not so obvious, risk factors that may need to be considered. The obvious ones have been listed and rated as follows:
10.12. Frequency
The intervals at which the Declaration form, submission of required documentation and EFICA review will be performed may be summarised as follows:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 41 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Prospective Clients - prior to concluding a single transaction or establishing a business relationship, either on a COD or Terms basis, and Once a business relationship is established reviews will be done annually, unless the entity is classified as no risk IE Blue Chip Company Clients whose BO/UBO’s are known FPPO’s and/or high risk DPIP’s, will be reviewed via EFICA every six (6) months.
11. Risk Mitigation
The Business requires all Clients to: complete and accept the Declaration form, provide the required documentation as stated herein, and undergo the EFICA review process.
If the EFICA review results in a high-risk rating additional or enhanced due diligence may be required as noted in paragraph 12.
Additional measures may also include: Increased review periods of client information. Senior management involvement in decisions to onboard clients.
12. Customer Due Diligence
In order to satisfy the standard CDD requirements of both prospective and established business relationships, the Business requires all new and existing clients to complete the Client Declaration document, which makes provision to obtain all the required information. The effectiveness of screening processes is highly dependent upon an efficient client identification and verification program. Should the AI detect complex, unusually large transactions or patterns of transactions, then:
Depending on the amount the Business refer to its Delegation of Authority to determine who has approval rights for the transaction amount.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 42 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
12.1. Prohibited/Forbidden Clients
Avoiding risk by refusing to onboard or transact with a client will be used as a measure of last resort where the Business has reached a conclusion that ML/TF risks relating to specific Clients cannot be mitigated adequately or effectively.
However, the Business will not establish or continue a business relationship with or conduct a single transaction in instances where: The Client or its BOs appear on any of the Sanctions Lists, The immediate family members or known close associates of a client or its BOs appear on the Sanctions List, The Client is anonymous, and/or acting under a false or fictitious name.
12.2. Verification & Screening The following documentation must be supplied by the client to verify the information:
Duly completed and signed Client Declaration of Ownership and Control Structure document.
A copy of the authorising letter or resolution empowering the Representative to deal with the Business on behalf of the entity.
Copies of Incorporation documents/constitution/Founding documents/CIPC reports/partnership agreements confirming Name, address, registration number and Id Number/ Passport number of directors/members/partners.
For Listed companies - proof that the company is listed, in the form of a letter, certificate or other appropriate document proving the listing status of the company for listed companies.
Proof of Ownership structure either in the form of an organogram, or a Share Certificate, letter from auditor confirming ownership, partnership agreement and/or organogram signed off by company secretary for unlisted companies, other legal entities, and partnerships.
Trust Deed and Amendments confirming Founder & Named Beneficiaries of Trust (excluding Testamentary Trust).
Last Will and Testament, and Death Certificate needed for a Testamentary Trust.
Letter of Authority confirming Trustees, Name and registration Number of Trust and address of Master of High Court for a Trust.
ID documents/passports for all Ultimate Beneficial Owners (Shareholders/ Partners/Members etc).
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 43 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
ID documents /passports for all authorised representatives to act on behalf of Listed Companies, Unlisted Companies, Partnerships, Close Corporations & Trusts.
12.3. CDD – Natural Persons
The following information must be obtained for all natural persons and uploaded on EFICA to be risk rated according to the relevant risk scoring matrix as described in paragraph 10 and applicable appendix. Full Name and Surname, Contact Information, ID or Passport Number, Physical Address, Occupation and Industry Employed in, Reason for Transaction/ Relationship, Type of Transaction, Source of Funds and Source of Wealth, Has the Client been met Face to Face or has another Accountable Institution complied with FICA verification of the client, FPPO/DPIP status.
The following information will be verified: The name, surname and ID number will be verified via EFICA ensuring the ID number and name is correct and by obtaining a copy of the ID document. Passport number will be verified by obtaining certified copy of said passport. The Physical Address of the Individual will be verified via EFICA and by obtaining a copy of the proof of residence. Personal Information such as email, telephone numbers, etc. will also be verified via EFICA.
All clients will be screened against: Sanctions Lists via EFICA, (Appendix 9) Global PEP Lists via EFICA, and All clients will undergo adverse media screening via eFICA.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 44 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Thereafter, EFICA will automatically evaluate the risk according to the risk matrix as per paragraph 10 and the Client will either be classified low or high risk.
If the client is identified as High Risk additional or enhanced CDD will be implemented as per paragraph 12.5and 12.6. Additional information may be needed and loaded on eFICA, as per risk rating/answers selected. A review date may be selected, if needed.
It remains the Business’ decision to accept or reject the Client based on the risk score and information provided. The Business must decide whether it accepts the residual risk remaining after all the mitigating factors have been addressed and reviewed.
A PDF report is generated by EFICA on the Client, capturing all risk rating questions and answers.
12.4. CDD – Juristic Persons/Legal Entities 12.4.1.
Concept of Beneficial Ownership A UBO is the Natural Person(s) who either own, exercise effective control over, or take advantage of capital or assets of an entity. It seeks to identify those persons who exert actual effective control over an entity.
The following natural persons will be classified as Beneficial Owners/Ultimate Beneficial Owners: Shareholders with shareholding of a private company, or If the ownership interests do not indicate a beneficial owner, or if there is doubt as to whether the person with the controlling ownership interest is the beneficial owner, it must establish who the natural person is that exercises control of the legal person through other means, for example, persons exercising control through voting rights attaching to different classes of shares or through shareholders agreements; or If no natural person can be identified who exercises control through other means, it must be determined who the natural person is that exercises control over the management of the legal person, including in the capacity of an executive officer, non-executive director, independent nonexecutive director, director, or manager, or All members of a CC, or All partners (including silent partners) of a partnership, or Trustees, founder and named beneficiaries of a Trust.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 45 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
12.4.2.
Unlisted Company For the purposes of this section, unlisted companies include the following companies registered in South Africa with the CIPC: Private companies – (Pty) Ltd. Public company not listed on an approved exchange – Ltd. Personal liability companies – Inc. State owned companies/enterprises – SOE Ltd.
The following information must be obtained, uploaded on EFICA and will be risk rated according to the relevant risk scoring matrix as described in paragraph 10 and applicable appendix: Trading name, address, and registration number, Resolution stating who is authorised to act on behalf of the business, Source of Funds, Source of Wealth, Nature of business, Industry classification, Reason for transaction/ Relationship, Type of transaction, Proof of Ownership either in the form of a Share Certificate, letter from auditor confirming shareholding or organogram signed off by company secretary, ID and residence of authorised person to Act on behalf of company, and ID and residence of all Ultimate Beneficial Owners who own 25 % for a low-risk company or 10% for a high-risk company.
12.4.3.
Close Corporation The following information must be obtained and uploaded on EFICA to be risk rated according to the relevant risk scoring matrix as described in paragraph 10and applicable appendix: Trading name, address, and registration number, Members Name, ID number and address, Source of Funds, Source of Wealth,
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 46 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Nature of business/ Industry Classification, Reason for transaction/ Relationship, Transaction Type, Resolution stating who is authorised to act on behalf of the business, and ID and residence of the authorised person.
12.4.4.
Trust (Including Testamentary Trusts) The following information must be obtained, uploaded on EFICA and will be risk rated according to the relevant risk scoring matrix as described in paragraph 10 and applicable appendix: Trust Name, Trust Registration Number, Address of the Master of the High Court, Nature of Business, Type of Transaction, Source of Funds, Source of Wealth, Full Names and Address of the Founder (UBO), Full Names and Address of all the Trustees (UBO), Full Names and Address of all the Named beneficiaries of the Trust (UBO), and IDs.
12.4.5.
Partnerships The following information must be obtained, uploaded on EFICA and will be risk rated according to the relevant risk scoring matrix as described in paragraph 10 and applicable appendix: Trading name and address, Resolution stating who is authorised to act on behalf of the partnership, Source of Funds, Source of Wealth, Nature of business,
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 47 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Industry classification, Reason for transaction/ Relationship, Type of transaction, Ownership structure, ID and residence of authorised person to Act on behalf of company, and ID and residence of all Ultimate Beneficial Owners.
12.4.6.
Listed Companies Listed companies operate in a highly regulated environment. As such, they pose relatively low ML/FT risk, warranting less rigorous CDD procedures.
The following information must be obtained, uploaded on EFICA and will be risk rated according to the relevant risk scoring matrix as described in paragraph 10 and applicable appendix: Trading name, address, and registration number, Resolution stating who is authorised to act on behalf of the business, Source of Funds, Source of Wealth, Nature of business, Industry classification, Reason for transaction/ Relationship, Type of transaction, and ID and residence of an authorised person.
12.4.7.
Estate Lates
The following is required to open an Account for an Estate Late:
Death Certificate with details of the deceased, Letter of Executorship, Letter of appointment if applicable, and ID of Executor.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 48 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
12.5. Additional Due Diligence (ADD)
The majority of the Clients of the Business are legal/juristic persons, and this requires the Business to perform additional due diligence. To ensure consistency in the CDD process all prospective and existing Clients will undergo the ADD process and in doing so, are required to provide, inter alia, the following information as contained in the Client Declaration document information: Registered and Trading names, Registration number/Trust Reference Number, the nature of the client’s business i.e., entity type (e.g.: close corporation, trust, partnership, etc.), the ownership and control structure of the client (organogram), the identity of beneficial owner(s) of the client by providing the identity details and copies of ID’s of: each natural person who, independently or together with another person, has a controlling ownership interest in the legal person, each natural person who exercises control of that legal person through other means, or each natural person who otherwise exercises control over the management of the legal person, including in his or her capacity as executive officer, non-executive director, independent nonexecutive director, director, or manager.
The veracity of this information will be verified using the EFICA online system.
After insertion of the Client information into the EFICA system, the eFICA system will automatically evaluate the risk according to the risk matrix as per paragraph 10 and Clients will be classified as either be low, Medium or high risk.
If the Client is identified as high risk additional or enhanced CDD will be implemented. Additional information may be needed and loaded on eFICA, as per risk rating/answers selected.
A review date to be selected if needed.
The following screening will be done including: All close corporations, private companies and public companies’ basic information will be verified by CIPC via EFICA, All close corporations, private companies & public companies will undergo sanction screening and adverse media screening via EFICA, EFICA will identify and verify all Listed Directors, Members & Authorised representatives Identification number and address details, All beneficial Owners identification and address information will be verified via EFICA,
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 49 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
All beneficial owners will be screened against various Sanctions lists and PEP lists via EFICA, and All beneficial owners will be screened for adverse media via EFICA.
12.6. Enhanced Due Diligence (EDD)
Enhanced due diligence is when the systems and controls make provision for: more information to be obtained about clients, more secure confirmation of clients’ information is applied, and closer scrutiny is conducted of the Clients’ transaction activities where the Business may assess the risk of abuse to be higher.
Enhanced due diligence (EDD) must be conducted for all high-risk single transactions or business relationships, where: the Client/BO/UBO is a high risk, the Client/BO/UBO is a DPIP that poses a high ML risk, the Client/BO/UBO is an FPPO, the family members or known close associates of the Client/BO/UBO are classified as a DPIP that poses a high ML risk, the family members or known close associates of the Client/BO/UBO are classified as a FPPO, or where there has been a deviation from the required, approved documentation or risk assessment.
Enhanced due diligence (EDD) requirements includes the following: Clear understanding of the client’s nature of business and the purpose of the account. Obtaining more information on the Client e.g., more information about the client’s nature of business and the purpose of the account, intended transactions, occupation / industry / etc). Senior management (CEO/CFO) must review and approve prior to on boarding the Client or continuing the business relationship. When considering whether to approve a business relationship with a prominent person, senior management should base their decision on the level of ML/TF risk the Business would be exposed to if it entered into that business relationship and how well equipped the institution is to manage that risk effectively. Documentary evidence of Source of funds and/or source of wealth must be obtained from client.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 50 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Conduct enhanced ongoing monitoring i.e., evaluation/screening to be done every three (3) months.
Senior Management and the S43CO must be comfortable with the risk of onboarding the Client otherwise the Business cannot onboard the Client.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 51 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The legal/juristic person information and documentary requirements may be summarised as follows:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 52 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The natural person/beneficial owner information and documentary requirements may be summarised as follows:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 53 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
12.7. Targeted Financial Sanctions (TFS)
South Africa has two targeted financial sanctions regimes based upon the country’s obligation as a member of the United Nations (UN), which originate from resolutions of the United Nations Security Council (UNSC) under Chapter VII of the Charter of the United Nations.
South Africa implements two distinct targeted financial sanctions regimes through the FIC Act and the POCDATARA Act, which form part of the AML/CFT regulatory framework.
The UNSC resolutions relate to the financing, prevention and suppression of terrorism and terrorist financing, as well as the prevention, suppression, and disruption of the proliferation of weapons of mass destruction and its financing.
Sanctions impose restrictions on activities that relate to particular countries, goods and services, or persons and entities.
TFS measures generally restrict sanctioned persons and entities from having access to funds and property under their control and from receiving financial services in relation to such funds and property.
The FIC Act therefore requires the Business to freeze property (including funds ) and may not proceed with any further transactions, pursuant to financial sanctions imposed in the UNSC Resolutions, and report this to the FIC within 5 business days.
12.7.1.
TFS Controls relating to terrorist financing and proliferation financing The Business makes use of EFICA to screen both natural and juristic persons against the United Nations Security Council 1267 resolutions list to ascertain whether any of its Clients may appear on the TFS List as a sanctioned person or entity.
This is done at the time of onboarding a prospective client as well as the determined intervals as noted in paragraph 10.12.
In the context of a prospective Client, the Business will not proceed with a business relationship and will submit a TFAR report with the FIC.
In the context of Clients in an established business relationship who, at a point after the establishment of the relationship, are found to be on the TFS List, the Client account will be immediately suspended, and no further transactions will be permitted. The required reporting as noted in paragraph 13 will be processed.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 54 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
13. Reporting Duties
Certain Sections of the FIC Act impose obligations on the Business to report certain transactions to the FIC.
The FIC utilises the transactional and other data received from businesses and accountable institutions to conduct analysis to create financial intelligence reports. Where necessary and upon request, this information is shared with local and international partners in the law enforcement environment and with the South African Revenue Service (SARS).
The FIC obtains financial intelligence and other data in the form of reports which are filed with it in accordance with the following sections of the FIC Act: Section 28 - Cash Threshold Reporting Section 28A - Terrorist Property Reporting Section 29 - Suspicious and Unusual Transaction Reporting Section 30 - Cash Conveyance Reporting (Commencement date of section 30: to be proclaimed) Section 31 – International Funds Transfer Reporting
All reports issued on goAML must be downloaded within 1 day.
Reporters are reminded to monitor the status of their submitted reports to ensure that the reports are successfully processed and that any failures or rejections are remediated accordingly
Reporters are reminded to download and save copies of all submitted reports for their internal record-keeping purposes.
Reporters should ensure that any information and communications technology related queries or incidents are logged with the Centre by means of the communicated channels and that they keep records thereof.
The MLRO together with the S43 compliance officer are responsible to report transactions pertaining to Section 27, Section 28, Section 29, Section 31 to the FIC.
Section 27 of the Act requires the accountable institution, reporting institution or person to provide information pertaining to the below to an authorised representative of the FIC:
whether a specified person is or has been a client of the accountable institution, reporting institution or person;
whether a specified person is acting or has acted on behalf of any client of the accountable institution, reporting institution or person;
whether a client of the accountable institution, reporting institution or person is acting or has acted for a specified person;
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 55 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
whether a number specified by the FIC was allocated by the accountable institution, reporting institution or person to a person with whom the accountable institution, reporting institution or person has or has had a business relationship;
on the type and status of a business relationship with a client of the accountable institution, reporting institution or person,
The FIC may contact the S43 compliance officer of the accountable institution to request information under Section 27, Section 32, Section 34 and Section 35. In the event of such a request, the S43 compliance officer must:
ensure the request comes formally through a written correspondence on the FIC’s letterhead
directly from The FIC itself
verify the authorised representative by way of either
telephonic or
a video call reference
inform the CEO/ CFO of the request from the FIC
update the FIC register with details furnished to the authorised representative.
Section 28 of the Act requires the accountable institution within the prescribed period to report to the FIC the prescribed particulars concerning a transaction concluded with a client if in terms of the transaction an amount of cash in excess of the prescribed amount:
is paid by the accountable institution or reporting institution to the client, or to a person acting on behalf of the client, or to a person on whose behalf the client is acting;
is received by the accountable institution or reporting institution from the client, or from a person acting on behalf of the client, or from a person on whose behalf the client is acting
Section 29 of the Act requires the accountable institution to report to the FIC any suspicious and unusual transactions that is about to or may have occurred.
Section 31 requires, that if an accountable institution through electronic transfer sends money in excess of a prescribed amount out of the Republic or receives money in excess of a prescribed amount from outside the Republic on behalf, or on the instruction, of another person, it must, within the prescribed period after the money was transferred, report the transfer, together with the prescribed particulars concerning the transfer, to the FIC
A clear instruction on tipping off and the non-disclosure of suspicious transaction reports (STRs) to other persons (see PCC 42).
A terrorist property report in terms of section 28A, must be filed where the accountable institution is in possession or control of property of:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 56 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Any entity which has committed or attempted to commit an offence as defined in POCDATARA Act Public compliance communication 53 guidance on the risk management and compliance programme in terms of Section 42 of the FIC Act Page 38 of 44
A specific entity identified in a UN 1267 sanctions list.
A person or entity identified in a TFS list as published on the FIC’s website.
The following process must be followed to identify reportable transactions under Section 28, Section 29 and Section 31:
the MLRO must check the bank statements daily to determine, whether cash transactions above the threshold per 13.1 have been paid or received, and
whether any suspicious and unusual transactions per 13.3 have taken place, and
whether any funds in excess of the prescribed amount which is R49 999 was received or paid by the accountable institution to or from outside the Republic respectively, on behalf, or on the instruction, of another person
where reportable transactions are identified, the following process must be applied:
MLRO to collate all information such as applications, bank statements, credit reports, AFS
communicate all the relevant information immediately to the S43 compliance officer in the prescribed manner
S43 compliance officer will perform an investigation, gathering information and evidence.
S43 compliance officer will update the FIC register with information, and either
report the activity to the FIC via the GoAml platform, or
keep details on file with the findings and reasons to not report
All reporting information is confidential, VH Fibre Optics must under no circumstances disclose the contents of a report or the fact that a report has been considered or filed to any other persons. Disclosure of this information is regarded as tipping off, which is an offence.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 57 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
There are four (4) main reporting obligations in terms of the FIC Act, as listed below:
13.1. Cash Threshold Reporting (CTR)
The obligation to report in terms of section 28 of the FIC Act arises when a transaction is concluded with a client by means of which cash of the prescribed amount, or more: is paid by the Business to the client, or to a person acting on behalf of the client, or to a person on whose behalf the client is acting; or is received by the accountable or reporting institution from the client, or from a person acting on behalf of the client, or from a person on whose behalf the client is acting. This includes the Business receiving cash in person, and cash deposited at a bank into the Business bank account, by, or on behalf of, the Client.
The current prescribed amount is R49 999,99 and may be amended from time to time.
The reportable transaction refers to unrelated transactions whereby each transaction on its own has exceeded the threshold and no aggregation is demonstrated.
Each transaction must be reported separately and refer to a unique transaction number to identify the specific transaction.
The bank statement(s) must be checked every day to determine, whether cash transactions above the threshold have been paid or received and whether any suspicious and unusual transactions have taken place.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 58 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Where a transaction is partly a cash transaction, only the cash portion exceeding the prescribed threshold must be reported.
All CTR’s must be reported via goAML as soon as possible but not later than three (3) days (excluding Saturdays, Sundays, and public holidays) after becoming aware of a fact of a cash transaction that has exceeded the prescribed limit.
In the event a Client is attempting to avoid the reporting requirement by making cash payments in amounts less than the prescribed amount (i.e., aggregation of cash amounts), the Business may be obliged to submit a cash threshold report (CTR) in terms of section 28 of the FIC Act and a suspicious or unusual transaction report (STR) in terms of section 29 of the FIC Act.
Whilst certain cash transactions may not be reportable in terms of section 28 of the FIC Act (i.e., the cash value is below the threshold amount), all cash transactions should be monitored and when it is deemed as suspicious, a suspicious or unusual transaction report should be submitted to the Centre in terms of section 29 of the FIC Act.
Where foreign currency forms part of a cash transaction that requires the completion of a CTR, the Business would have to refer to the exchange rate at the time of the transaction to calculate the amount in South Africa rand. The source of the exchange rate that is used may be determined at the discretion of the Business.
13.2. Terrorist Property Reporting (TPR)
As noted in paragraph 12.7, if the Business becomes aware that a Client in an established business relationship is on the TFS List, the following measures must be taken: The Client account(s) and pending transactions will be immediately suspended. The S43CO will contact the counterparts at the Alviva subsidiaries who are also designated AI’s and inform them hereof. These AI’s will also be required to suspend their account(s) and transactions with this Client until such a time the non-compliance is thoroughly investigated and confirmed. The S43CO will perform additional investigation and verification to determine that it is a match, and if confirmed, maintain the suspension on the trading account and cease to conduct any business with the entity in question, and update the Alviva subsidiaries of the outcome. All the Alviva subsidiary S43CO’s will then verify if the Business has in its possession any property e.g.: funds not allocated to transactions belonging to the Client, goods ordered but not delivered. The S43CO will create a record of the particulars related to the Client as well as a description and details of the property. The reporting, investigation of non-compliance and gathering of all supporting material must be completed within 2 business days.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 59 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Since the facts relating to this Client and their property would be confirmed i.e., it is no longer a suspicion, it can be said that the Business knows that it is in possession of, or has under its control property linked to a natural person or an entity as identified pursuant to a UN resolution. The Business is obligated to: file a report in terms of section 28A(1)(c) of the FIC Act, and freeze the Clients’ account(s), transaction(s) and good and/or services that were to be provided. Note: A report (see Guidance Note 4B) submitted in terms of section 29 of the FIC Act refers to a suspicion, whereas a report submitted in terms of section 28A of the FIC Act is factual. The S43CO will instruct the MLRO to submit “full particulars“, and “as much of the relevant “information as is readily available” as prescribed by the MLTFC Regulations (see GN6A), of the type of property concerned and a description of the property in relation to which the terrorist property report is made, by submitting a TPR report on the goAML portal. The report must be submitted as soon as possible but no later than five (5) days after the S43CO, the MLRO or any other Employee, had established that the Business has property associated with terrorist and related activities in its possession or under its control, unless the Centre has approved the report being sent after the expiry of this period.
The terrorist financing and terrorist property reporting obligations may be summarized as follows:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 60 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The differences between the Section 28A and Section 29 report type is shown as follows:
Section 28A
Section 29
(TPR)
(STR, SAR, TFTR & TFAR)
Applicable only to accountable
Applicable to all businesses including
institutions.
accountable institutions and any other persons connected to any business.
Report based on knowledge by the
Report suspicious or unusual activities or
accountable institution of property under
transactions or series of transactions related
its control – object test us used.
to the financing of terrorist and related activities – subjective test is used.
May not continue with transaction – it is
May elect to continue with transaction.
an offence. Valid defence to charges brought in terms of section 4 of the POCDATARA.
13.3. Suspicious and Unusual Activity / Transaction Reporting
These reports refer to suspicious or unusual transactions or activities related to the proceeds of unlawful activities and money laundering or terror financing, [and financial sanctions] offences as opposed to criminal activity in general. The FIC Act therefore does not require reports to be made on suspected crimes or unlawful conduct by a person (apart from money laundering, terror financing [and financial sanction] activities)
The term “proceeds of unlawful activity” refers to: any property or any service, advantage, benefit or reward; which was derived, received or retained; directly or indirectly; in South Africa or elsewhere; at any time before or after the commencement of the POC Act. In connection with or as a result of any unlawful activity carried on by any person.
The term “unlawful activity” means any conduct, which constitutes a crime or which contravenes any law whether such conduct occurred in the Republic or elsewhere.
The obligation to report in terms of section 29 of the FIC Act is applicable: to all businesses regardless of whether they are registered with the FIC or not,
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 61 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
to all employees at all levels of a business, and when a person, in relation to the proceeds of ML/FT/PF/PFA activities and/or transactions: knows of certain facts, or in circumstances in which a person ought reasonably to have known or suspected that certain facts exist, or becomes aware of something; or circumstances arise in which a person can reasonably be expected to be aware of something; or circumstances arise in which a person can reasonably be expected to suspect something.
The “something” noted above relates to: the proceeds of unlawful activity and unlawful activity; an offence relating to the financing of terrorist and related activities; [the contravention of a prohibition under section 26B of the FIC Act;] and any structuring of a transaction or activity which is conducted for the purpose of avoiding giving rise to a reporting duty under the FIC Act.
Both suspicious or unusual transactions, and suspicious or unusual activities must be reported. These may be differentiated as follows: Activity reports include: Suspicious activity report (SAR); and Terrorist financing activity report (TFAR). Transaction reports include: Suspicious and unusual transaction report (STR); and Terrorist financing transaction report (TFTR).
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 62 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
All instances of suspicious or unusual activities and/or transactions, in the context hereof, must be reported immediately upon becoming aware thereof, to: Mario Mynhardt – S43CO
The escalation must be done verbally, but must be substantiated in writing by email and include as much information related thereto, such as: Description of the non-compliance Date and time the non-compliance took place. Details of the parties involved in the non-compliance. Details as to whom the non-compliance was discussed with.
The S43CO will perform the necessary investigation and verification of the reported suspicious or unusual activities and/or transactions.
The S43CO or MLRO will submit the relevant report on go AML as soon as possible, but not longer than not be longer than 15 (fifteen) days, after a person became aware of the facts which give rise to a suspicion.
The S43CO will maintain records of all reports and supporting information and/or documentation.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 63 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
13.4. International Funds Transfer Reporting (IFTR)
The Business is not required to submit IFTR’s.
Section 31 of the FIC Act applies only to certain categories of accountable institutions that are authorised to conduct the business of cross-border electronic fund transfers. These are institutions that are authorised in terms of the Regulations under the Currency and Exchanges Act, 1933 (Act 9 of 1933) (the Exchange Control Regulations) to conduct authorised transactions under these Regulations.
Accountable institutions with this authorisation are: Authorised dealers (ADs); Authorised dealers with limited authority (ADLAs); A category of financial services providers (FSP) that have a direct reporting dispensation under the Exchange Control Regulations; and The Post Office.
13.5. Reportable Information
An Employee must immediately provide a written report to the S43CO if the Employee knows or reasonably suspects (including an unsuccessful attempt to do anything that, if done successfully, would have resulted in) any of the following – the Business received, or is about to receive the proceeds of crime, or property associated with the financing of Terrorist Activities; or the Business is party to one or more transactions that facilitated, or will likely facilitate, the transfer of the proceeds of crime, or property associated with the financing of Terrorist Activities; or are complex or involve abnormally large amounts of money, are not business-like, or do not appear to serve any legal purpose; or were effected so as not to trigger a reporting duty on the Business' part; or may pertain to an investigation into actual or attempted tax evasion; or are associated with the financing of Terrorist Activities; or the Business has been, or is about to be, used for ML/FT in any manner whatsoever. there has been a Transaction of the Business involving the payment of R50,000.00 (fifty thousand rand) or more in Cash, which payment is made to or received from a Client, or the Client's
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 64 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Representative or Principal. The sum of this money may be constituted by a single payment, or by a series of payments made within a period of 24 (twenty-four) hours that are R50,000.00 (fifty thousand rand) or more when aggregated.
An Employee must immediately provide the S43CO with a written report if the Employee knows (as opposed to merely suspects) that the Business is in possession or control of property associated with any person or entity listed on List 1267 (See Appendix 9), or any person or entity involved in Terrorist Activities.
The S43CO must ensure the FIC is informed, via goAML, within the following reporting deadlines: Reported to the FIC, via go
A report made by an Employee to the S43CO/MLRO -
AML within:
- about cash receipts of R50,000.00 (fifty thousand rand) or
within 3 (three) days.
more.
(including aggregation as noted herein)
- that the Business is in possession or control of property
within 5 (five) days.
associated with any person or entity listed on the Sanctions List
(subject to the further
1267, or any person or entity involved in Terrorist Activities.
provisions related to the freezing of assets.)
- suspicious activity as noted in paragraph 13.5
within 15 (fifteen) days.
NOTE: An Employee reporting to the S43CO, and the S43CO reporting to the FIC in terms of this paragraph 13 may not alert the subject of the report, whether directly or indirectly as to the fact that a report is about to or has been made to the S43CO or to the FIC (as the case may be), nor as to the content of the report.
14. Risk Monitoring A weekly report is compiled and overseen by the national credit manager, to ensure accounts remain within approved insurance limits. Comments are added to the report to keep written findings of the decisions in this regard. When establishing a business relationship, information on the source of funds, the nature of the client’s business, and the intended purposes of the business relationship must be obtained by the customer completing the application documents together with the declaration form. All clients and prospective clients must be profiled according to if they are an ICT reseller or minimum 70% of their business is ICT related
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 65 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
14.1. Account transaction or activity monitoring and Future Transactions
The following Client status changes will trigger additional or enhanced due diligence to be performed: COD Clients requesting their account to be amended to a Terms account, Terms Clients requesting their account to be amended to a COD account, All Clients whose average monthly sales increase by more than 10%, Change in ownership, e.g.: merger/acquisition Flagged by other subsidiaries in the Alviva Group CGIC limit withdrawals Once off big deals
14.2. On-going Due Diligence for Business Relationships
FPPO’s will be screened every 3 months.
High-Risk Clients will be screened every 6 months.
All other Clients will be screened every 2 years, particularly where their turnover is less than R1m p/a.
EFICA prompts the user to insert a selected review date and the system will therefore support ongoing CDD.
14.3. Complex / Unusually Large Transactions
The Business has assessed and provides for the manner in which to examine complex or unusually large transactions; and unusual patterns of transactions which have no apparent business or lawful purpose, and keeping of written findings relating thereto, as follows: Depending on the amount the Business will refer to its Delegation of Authority to determine who has approval rights for the transaction amount. Roll outs require an award letter, A small client getting a large deal requires written verification from the End User, an update to the verification of their beneficial ownership and an update to the EFICA verification.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 66 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
15. Record Keeping
FICA requires the Business to: retain all records concerning client due diligence and transaction activity, ensure that all relevant information is readily available, and that reporting under the FIC Act is not unduly delayed or impeded by a lack of available information.
Recordkeeping is an essential component of a successful system to combat money laundering and terrorist financing. Often the records of clients’ identities and their transaction activities would be the only evidentiary trail to assist law enforcement authorities in the detection, investigation, prosecution and confiscation of criminal funds where illicitly flows of funds are concerned.
Meeting the record-keeping requirements will ensure that adequate information is captured to enable the reconstruction of a trail of transactions with a view to assist investigators in determining flows of funds when performing their investigative functions.
The record-keeping requirement is fully applicable to the CDD, transaction and other information collected, regardless of the risk rating.
Keep records of decisions (and the reasons therefore) not to submit reports in terms of section 29 of FICA which were initially thought to be suspicious or unusual:
Should a decision be made not to report a transaction, which was initially thought to be suspicious or unusual transaction and in fact turns out to be a normal transaction, then:
The report stating that decision will be stored with the CO on a secure drive.
15.1. GoAML Records
The Business will maintain a register of all reports made to the Centre which will include the date on which the report was made, the person making the report and sufficient information and details regarding the transaction.
All reports issued on goAML must be downloaded in 1 day of submitting the report and kept on record.
15.2. Obligation to keep customer due diligence records
The Business must keep record of all information pertaining to a client obtained in the course of its processes to comply with sections 21 to 21H of the FIC Act. Such records must include copies of, or references to, information provided to or obtained by the accountable institution to verify the person’s identity.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 67 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
15.3. Obligation to keep transaction records.
The Business must keep records of every transaction which it has with a Client.
Transaction records must be sufficient to enable the transaction to be reconstructed and include the amount, currency, date of transaction, parties to the transaction, the nature of the transaction, pertinent or relevant business correspondence and also the identifying particulars of all accounts and account files related to the transaction if the accountable institution provides account facilities.
15.4. Manner in which records must be kept
The FIC Act is not prescriptive as to the way records must be kept. As such FICA required records will be kept in the same manner as other records are maintained as per the Retention of Records Policy.
However, the FIC requires that the following principles are met: The Business must have free and easy (in other words unencumbered) access to the relevant records, The records must be readily available to the Centre and the relevant supervisory body when required, The records must be capable of being reproduced in a legible format, and If the records are stored off-site the Centre and the relevant supervisory body must be provided with the details of the third party storing the records.
15.5. Third Party Record Storage
Pinnacle Micro stores the following records with a third party off-site (The document Warehouse).
The Business must advise the Centre in writing on a formal letterhead the information as per regulation 20 of the Money Laundering and Terrorist Financing Control regulations.
The CDD documents provided by the Client will be stored on the Business premises, either as physically or electronically, or both. Electronic documents can only be accessed by the Debtors Department. Physical documents are stored in a strong room, which is subject to access controls.
The CDD documents provided by the Client will be sent for archiving and stored at The document warehouse premises.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 68 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The CDD documents provided by the Client will also be stored electronically on the eFICA platform (i.e. document submission, sharing and verifying web application) Access to the platform is limited to the following people: Alviva Group Risk and Compliance Manager – Michelle da Fonseca S43CO – Mario Mynhardt MLRO – Jo- Ann Twigg; Edna de Klerk
The third party’s information is as follows: eFICA (Pty) Ltd (https://efica.co.za/) Third party’s registered name.
eFICA (Pty) Ltd
Third party’s registration number.
2011/140578/07
Name under which the third-party conducts business.
eFICA (Pty) Ltd
Third party’s registered address.
20 High Street, Hermanus, 7200
Full name and contact particulars of the individual who
Mario Mynhardt
exercises control over access to those records. Address where the records are kept
Electronic storage only
Address from where the third-party exercises control
20 High Street, Hermanus, 7200
over the records. Full name and contact particulars of the individual who
Mario Mynhardt
liaises with the third-party on behalf of the Business concerning the retention of the records.
The Document Warehouse Third party’s registered name.
The Document Warehouse (Pty) Ltd
Third party’s registration number.
1999/01656/07
Name under which the third-party conducts business.
The Document Warehouse (Pty) Ltd
Third party’s registered address.
5 Krag Street, Selby Johannesburg
Full name and contact particulars of the individual who
Neo Letswalo
exercises control over access to those records.
neol@tdw.co.za 012 681 0200
Address where the records are kept
5 Krag Street, Selby Johannesburg
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 69 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Address from where the third-party exercises control
5 Krag Street, Selby
over the records.
Johannesburg
Full name and contact particulars of the individual who
Edna de Klerk
liaises with the third-party on behalf of the Business
ednad@pinnacle.co.za
concerning the retention of the records.
011 265 3493
15.6. Period for which records must be kept
Records in relation to establishment of a business relationship referred to in section 22 of the FIC Act must be kept for at least five years from the date on which the business relationship is terminated.
Records of all transactions concluded referred to in section 22A must be kept for at least five years from the date on which that transaction is concluded.
Records of a transaction or activity which gave rise to a report contemplated in section 29 of the FIC Act must be kept for at least five years from the date on which the report was submitted to the Centre.
Records which, to the knowledge of the Business, relate to ongoing investigations must be kept until the relevant law enforcement agency has confirmed that the case has been closed, where possible. This may exceed five years.
16. Training
New employees, upon induction, as well as all current employees will receive appropriate training on money laundering and terrorist financing to ensure they are aware of, and understand, their legal and regulatory responsibilities and their role in handling criminal property and money laundering/terrorist financing risk management.
The Business will provide ongoing training relating to anti-money laundering and counter terrorist financing compliance to its employees to enable them to comply with the provisions of this Act and the Risk Management and Compliance Programme which are applicable to them.
The Business will also make documentation describing this RMCP, available to each of its employees involved in transactions to which this Act applies.
16.1. Levels of Training
Employees require training at an appropriate level that will educate employees on the compliance obligations and procedures related to:
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 70 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
The content of this RMCP, Duty to identify Clients, Duty to keep records, and identifying and reporting different reportable transactions.
The following anti-money laundering, counter terrorist financing and counter proliferation financing (AML/CTF/CPF) training will be provided to all employees of the Business: Intensive/Advanced training: Employees who are involved in areas of the Business that fall within the parameters of the FIC Act and/or who interact with clients are required to have intensive training on the provisions of the FIC Act. This includes Debtors/Accounts Receivable. Basic/Intermediate training: Employees that are not involved in the above activities may only require basic training. This will include basic training on the relevant legislation, the Business’ internal rules and procedures, and the more obvious warning signs in relation to money laundering. Starter training: Employees to be made aware of the act, but whose daily tasks are not affected by it.
16.2. Training Intervals/Frequency
Training is to be done on an on-going basis, based on the level and type of Client interaction an Employee has: Department
Title
Level of Training
Frequency
Facilitator
Accounts Receivable
Full Department
Group Standard
Bi-Yearly (2
MLRO’s will be
years)
responsible
Bi-Yearly (2
MLRO’s will be
years)
responsible
Bi-Yearly (2
MLRO’s will be
years)
responsible
Bi-Yearly (2
MLRO’s will be
years)
responsible
Bi-Yearly (2
MLRO’s will be
years)
responsible
/Debtors, Accounts Payable/Creditors Sales Brand Marketing, HR Logistics (Production,
Full Department Full Department Full Department Full Department
Group Standard Group Standard Group Standard Group Standard
Technical, Warehouse)
Employees will be subject to a knowledge assessment after training.
Evidence of the training will be retained and may include: Attendance Registers, Certificate of Completion
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 71 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
17. Adoption, Ownership & Approval of RMCP This FICA RMCP is hereby adopted and owned by Pinnacle Micro (Pty) Ltd (“the Business”), a duly authorized private company within the meaning of the Companies Act, 2008 (Act 71 of 2008), and an Accountable Institution within the meaning of item 20 of Schedule 1 of the Financial Intelligence Centre Act, 2001, referred to as the AI. As the Chief Executive Officer of Pinnacle Micro (Pty) Ltd, I hereby confirm approval and adoption of this RMCP on behalf of the governing body.
______________________________________________ Tim Humphreys-Davies
23/10/2025
_____________________________ Date
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 72 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 1: List of FATF Member States The following countries are FATF Member States as at 06 July 2023 as per http://www.fatfgafi.org/countries/#FATF. Argentina Australia Austria Belgium Brazil Canada China Denmark Finland France Germany Greece Hong Kong, China
Iceland India Ireland Israel Italy Japan Korea Luxembourg Malaysia Mexico Netherlands New Zealand
Norway Portugal Russian Federation * Saudi Arabia Singapore South Africa Spain Sweden Switzerland Türkiye United Kingdom United States
* membership suspended on 24 February 2023
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 73 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 2: List of FATF High-Risk Jurisdictions All Non-FATF countries, not listed in Appendix 3
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 74 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 3: List of FATF Very High-Risk Jurisdictions Afghanistan Algeria Angola Bangladesh Bolivia Burundi Central African Republic Cambodia Cameroon China Chad Comoros Congo Rep. Cuba Dem. Rep. Congo Djibouti Ecuador Egypt Eritrea Equatorial Guinea
Ethiopia Gambia Guinea Guinea-Bissau Haiti Honduras India Iran Iraq Kenya Laos Libya Madagascar Malawi Mali Mozambique Myanmar / Burma Nepal Nicaragua Niger
Nigeria North Korea Pakistan Palestine Philippines Russian Federation Rwanda Sierra Leone Somalia Sudan (North & South) Syria Tajikistan Turkmenistan Uganda Uzbekistan Venezuela Vietnam Yemen
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 75 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 4: List of DPIP Positions Schedule 3A to the FIC Act contains a list of positions that will be Domestic Prominent Influential Persons (DPIP) which includes: The President or Deputy President (http://www.gov.za/about-government/leaders) A government minister or deputy minister (http://www.gov.za/about-government/leaders) The Premier of a province; (http://www.gov.za/links/provincial-government) A member of the Executive Council of a province (http://www.gov.za/links/provincial-government) An executive mayor of a municipality elected in terms of the Local Government Municipal Structures Act, 1998 (http://www.salga.org.za/Municipalities%20MCD.html) A leader of a political party registered in terms of the Electoral Commission Act, 1996; (http://www.elections.org.za/content/Parties/Political-party-list/) Note: The leader of a political party is the person identified by the party to occupy the position of the highest level of authority in the party. Senior member a political party. A member of the royal family or senior traditional leader as defined in the Traditional Leadership and Governance Framework Act, 2003; http://www.cogta.gov.za/?p=938 Note: The description of a “senior” traditional leader, therefore, applies to such traditional leaders who exercise authority over a number of headmen or headwomen in accordance with customary law, or within whose area of jurisdiction a number of headmen or headwomen exercise authority. The head, accounting officer or chief financial officer of a national or provincial department or government component as defined in section 1 of the Public Service Act, 1994 (http://www.gcis.gov.za/gcis/pdf/government_28.pdf) The municipal manager of a municipality appointed in terms of section 54A of the Local Government: Municipal systems Act, 2000 or a chief financial officer designated in terms of section 80(2) of the Municipal Finance Management Act, 1999 (http://www.salga.org.za/Municipalities%20MCD.html) The chairperson of the controlling body, the chief executive officer, or a natural person who is the accounting authority, the chief financial officer or the chief investment officer of a public entity listed in Schedule 2 or 3 to the Public Finance Management Act, 1999 (http://www.gcis.gov.za/content/resourcecentre/contact-directory/government-structures-andparastatals) A constitutional court judge or any other judge as defined in section 1 of the Judges’ Remuneration and Conditions of Employment Act, 2001 (http://www.judiciary.org.za/index.html)
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 76 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
A constitutional court judge or any other judge as defined in section 1 of the Judges’ Remuneration and Conditions of Employment Act, 2001; (http://www.judiciary.org.za/index.html) An ambassador or high commissioner or other senior representative of a foreign government based in the Republic of South Africa; (http://www.dirco.gov.za/foreign/forrep/index.htm) Members of boards of central banks An officer of the South African National Defence Force above the rank of major-general (http://www.dod.mil.za/leaders/leaders.htm) Note: This will include persons holding the position of General and Lieutenant General in the South African National Defence Force. (Heads and other high-ranking Officers holding senior positions in the armed forces.) The position of—
Chairperson of the board of directors;
Chairperson of the audit committee;
Executive officer; or
Chief financial officer
of a company, as defined in the Companies Act, 2008 if the company provides goods or services to an organ of state and the annual transactional value of the goods or services or both exceeds an amount determined by the Minister of Finance by notice in the Gazette. Note: It is envisaged that the Minister of Finance will delay the operational date of this paragraph in the legislation, given that information about persons who may fall in this category is not publicly available currently. The National Treasury will explore ways to make such information readily available to enable easier compliance by accountable institutions. The position of head, or other executive directly accountable to that head, of an international organisation based in the Republic of South Africa. (Head of Supranational body e.g. UN,IMF, WB,etc) http://www.dirco.gov.za/foreign/forrep/intorg.htm
Note: The Client remains the most valuable source of information in order to determine whether he/she or any of their UBO’s occupies a prominent position.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 77 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 5: List of FPPO Positions The following positions in respect of countries other than South Africa are Foreign Prominent Public Officials (FPPO) positions: Head of state or head of a country or government Member of a foreign royal family Member of cabinet or similar structure Senior member or leader of a political party Senior judicial officer Senior executive of a state-owned entity High-ranking military officer. Note: The Client remains the most valuable source of information in order to determine whether he/she or any of their UBO’s occupies a prominent position.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 78 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 6: Family Members & Close Associates of FPPO / DPIP Immediate family members of Domestic Prominent Influential Persons and Foreign Prominent Public Officials include, but are not limited to: Spouse/s, civil partner/s and life partner/s Previous spouse/s, civil partner/s or life partner/s Children and stepchildren and their spouse/s, civil partner/s or life partner/s Parents Known sexual partners outside the family unit (e.g., girlfriends, boyfriends, mistresses) Prominent members of the same political party, civil organisation, labour, or employee union as the PEP Business partners or associates, especially those that share (beneficial) ownership of a Legal Person with the PEP, or who are otherwise connected (e.g., through joint membership of a company board). Any Individual who has sole beneficial ownership of a Legal Person or legal arrangement set up for the actual benefit of the PEP. Note: The Client remains the most valuable source of information in order to determine whether he/she or any of their UBO’s occupies a prominent position. Note: Close associates are individuals who are closely connected to a prominent person, either socially or professionally. The term "close associate" is not intended to capture every person who has been associated with a prominent person. Examples of known close associates extracted from guidance provided by the FATF.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 79 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 7: High Risk Industries Activities of religious, political, and extraterritorial organisations/bodies All security, safety, and defence activities (Private or Government) All trade (wholesale, retail etc.) in gold, metals, diamonds, pearls, and other precious/semi-precious stones Arms dealing Cryptocurrency Extraction of crude petroleum, natural gas Foreign Affairs and Representatives of foreign countries Gambling and betting activities Growing, Manufacture, Wholesale or Retail sale of tobacco and tobacco products Manufacture of basic chemicals, fertilisers, nitrogen compounds pesticides explosives and pyrotechnic products Manufacture of refined petroleum products Manufacture of weapons, ammunition, and military fighting vehicles Manufacture, trade in of articles of fur/leather Mining Public Administration at National, Provincial or Local Government Level Refining of precious metals, e.g., gold, silver, and platinum
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 80 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 8: High Risk Occupations Managing directors and chief executives of high-risk industries Legislators Senior government officials Senior officials of political party organisations Traditional chiefs and heads of village Religious associate professionals Customs and border inspectors Pawnbrokers and moneylenders Protective services workers n.e.c.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 81 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 9: Sanctions Lists
An up to date sanction lists issued pursuant to the United Nations Security Council Resolution (UNSCR) 1267 (1999) and its successor resolutions can be accessed via the United Nations website: https://www.un.org/sc/suborg/en/sanctions/1267/aq_sanctions_list 11.
The individuals and entities whose names appear on these listings are those whom the UNSC has identified as being associated with the Taliban, Al Qaida and the so-called Islamic State of Iraq and the Levant. These UNSC Resolutions are the only sanctions lists related to terrorist activities which are legally recognised within the Republic of South Africa and can be accessed on the United Nations website.
Australia, DFAT Consolidated list Australian Sanctions (AU) Bureau of Industry and Security - Entity List (US) Bureau of Industry and Security - Unverified List (US) Bureau of Industry and Security (US) Canada, Office of the Superintendent of Financial Institutions, OSFI Consolidated CIA Leader list Consolidated Canadian Autonomous Sanctions List Department of State, AECA Debarred List (US) Department of State, Non-proliferation Sanctions (US) EU Financial Sanctions (EU) European Union, Consolidated list of persons, groups and entities subject to EU financial sanctions Foreign Financial Institutions Subject to Part 561 (the Part 561 List) Foreign Sanctions Evaders List (FSE) INTERPOL Wanted List Non-SDN Iranian Sanctions Act List (NS-ISA) OFAC Consolidated Sanctions List Office of the Superintendent of Financial Institutions (Canada) Palestinian Legislative Council (PLC) List Sectoral Sanctions Identifications (SSI) List Specially Designated Nationals (OFAC) Specially Designated Nationals List (SDN) Switzerland Sanction List (SECO) U.S. Department of Commerce, Bureau of Industry and Security - Denied Persons List U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC)
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 82 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
UK Financial Sanctions (UK) UK, Consolidated Financial Sanctions list (HMT) United Nations Sanctions (UN) United Nations Security Council (UN), Consolidated Sanctions list US Consolidated Sanctions (US) US State Dept. WMD Non-Proliferation List FIC targeted financial sanction list Various Other Sanctions List Consolidated PEP list that is growing on a daily basis
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 83 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 10: Source of Funds and Source of Wealth 3rd party Debtors repayment (especially with Debtor financing)
Low
Allowance
Low
Asset sale cash flows
Low
Beneficiary of Trust
Higher Weighting
Bond
Low
Bursary
Low
Company Profits
Low
Company Sale or Sale of Interest in Company
Low
Court Order
Low
Cryptocurrency
High
Debt-financing cash flows
Low
Deceased Estates
Low
Director/Member of Company/CC
Low
Director/Owner of own Business
Low
Dividends
Low
Divorce Settlement
Low
Donation
Higher Weighting
Encasement Claim
Low
Equity-financing cash flows
Low
Gift
Higher Weighting
Government allocation
Higher Weighting
Group restructure
Low
Income from Employment
Low
Income from Previous Employment
Low
Inheritance
Low
Investment cash flows
Low
Loan
Higher Weighting
Lottery or Gambling Winnings
High
Maintenance
Low
Maturing Investments
Low
Member's Contribution
Higher Weighting
New Investments
Low
Operational Cash Flows
Low
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 84 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Other
Higher Weighting
Parental / Shareholder Support
Higher Weighting
Pension
Low
Private Capital Raise
Low
Public Capital Raise
Low
Revenue collection from the public
Higher Weighting
Sale of Asset/Property
Low
Sale of Assets
Low
Sale of Shares
Low
Savings
Low
Third Party Guarantee
Low
Treasury transfer
Low
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 85 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 11: Acknowledgement to be signed by all Employees I, ______________________________________________________ (FULL NAME), hereby declare the following:
I have read FICA and the contents of this RMCP, both of which have been distributed or otherwise made available to me, and I have also attended the necessary training workshops offered by the Business in this regard; and
I acknowledge that to the extent that I do not understand any of my duties under FICA or the RMCP, I have contacted the Risk Officer for clarifications; and
I undertake to observe strictly and diligently all my duties imposed by FICA and the RMCP, fully understanding that my failure to do so –
will potentially expose the Business to unacceptable ML/TF risk, as well as financial and reputational risk from the penalties that may be levied by the FIC against the Business for any instances of noncompliance with FICA and the RMCP; and
is a criminal offence in terms of FICA and constitutes serious misconduct in terms of the Business' disciplinary code.
Name and Surname RSA Identity Number/ Foreign Passport No. Designation Date of Signature Signature
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 86 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 12: S43CO Appointment Letter Appointment as FIC S43 Compliance Officer Introduction The FIC (Financial Intelligence Centre) was established by the Financial Intelligence Centre Act, 2001 (Act 38 of 2001) and has the mandate to identify the proceeds of crime, combat money laundering and terror financing. The FIC Act introduces a regulatory framework of measures requiring certain categories of business to take steps regarding client identification, record-keeping, reporting of information and internal compliance structures. The Act obliges all businesses to report to the FIC various suspicious and certain other transactions. The FIC uses this financial data and available data to develop financial intelligence, which it is able to make available to the competent authorities and supervisory bodies for follow-up investigations or administrative action. All accountable and reporting institutions are required to register with the FIC. The FIC and supervisory bodies have the authority to inspect and impose administrative penalties on non-compliant businesses. More information on the FIC, may be found at www.fic.gov.za. Authorisation and appointment I, the undersigned, duly authorised to issue this certificate on behalf of Subsidiary (Pty) Ltd (the Company), as an Accountable Institution (“AI”) under the FIC Act, hereby certify that Full Name (ID 000000 0000 00 0), is hereby authorised by the AI to act as the FICA Section 43 Compliance Officer (“S43CO”) of the AI in terms of the Financial Intelligence Centre Act, 2001 (Act 38 of 2001).
Effective date This appointment is with effect from xx Month yyyy. It constitutes a variation of your existing contract of employment, as noted herein. Your duties and responsibilities as the S43CO The designated S43CO is responsible for ensuring that the accountable institution and employees of the accountable institution comply with the provisions of the FIC Act and the internal rules formulated for and applicable to the accountable institution. Please read them carefully and refer to them often.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 87 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Your duties and responsibilities are as follows: Duties •
The S43CO is responsible to ensure that the provisions of the FIC Act are adhered to by all employees and authorized representatives of the AI.
•
The S43CO has a thorough knowledge of the anti-money-laundering legislation and is able to train and provide guidance to employees and authorized representatives who have an obligation to carry out relevant duties in accordance with the FIC Act.
•
The S43CO is responsible for the maintenance, and if required updating, of the AI’s registration details on the FIC’s goAML online system.
•
The S43CO is responsible for the appointment of any Money Laundering Reporting Officer(s) (“MLRO”) within the AI, if considered necessary, for the purposes of compliance with the FIC Act.
Responsibilities Leadership You must provide leadership and oversight and communicate the vision for all our FIC compliance management activities that impact customers and employees. You must represent our FIC compliance management to relevant stakeholders and other officials responsible for the development, oversight, and enforcement of FIC legislation, to update or adopt FIC legislation, regulations, and standards. Policy, process, and procedure You must participate in and review the implementation of relevant policies, processes, and procedures to ensure the efficient management and resolution of all FIC compliance obligations required by the Company. Investigations and enforcement notices You are designated as the first and central point of contact and required to cooperate with the FIC in investigations and comply with any enforcement notices within the timeframes specified by the FIC. Please note that if you fail to comply with an enforcement notice you may be guilty of an offense that could have serious consequences.
Incident management and correction You must investigate and handle every incident of non-compliance and compliance exposure related to the FIC requirements to ensure it is dealt with correctly and appropriately. You are furthermore required to ensure the relevant information, processes and procedures are updated to prevent them from re-occurring.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 88 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Record-keeping and reporting You are required to correctly identify and report the different reportable transactions in accordance with the FIC Act and the Regulations. You must ensure employees correctly identify different types of clients in accordance with the FIC Act and the Regulations. You must ensure employees understand the duty to keep records correctly as per the accountable institution’s internal procedures. You must also keep a record of and monitor all incidents of compliance exposure and non-compliance related to the FIC requirements. A register and details of the these together with resolution measures taken must be communicated to your CEO and Compliance Officer on a quarterly basis. Remain informed You must keep abreast of: •
the status of all related laws.
•
all decisions of, and information from the FIC.
•
all related rules, codes, or standards (including leading and best practices and frameworks) and consider adhering to them, creating strategies to close gaps and follow them.
Training and awareness You must oversee and ensure the development, facilitation and promotion of ongoing corporate orientation, training, and awareness activities, communications for personnel at all levels and business partners regarding the FIC requirements. You must be able to demonstrate that the training took place and that it was sufficient to enable the employees to understand and comply with the FIC Act. Assessments Perform regular assessments of the adequacy and effectiveness of the implemented processes and procedures. Cost of compliance You should try to reduce our overall cost of compliance with FIC requirements and obligations as provided by the FIC. Delegation of duties Upon the written consent from the CEO, you may designate persons as AML (Anti-Money Laundering) Officers to help you to perform your duties or responsibilities, who will be required to attend the necessary training. They will be required to complete and accept an AML (Anti-Money Laundering) Compliance Officer appointment letter, which will also require signed approval from the CEO.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 89 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Once they are appointed and are under your continual supervision, you may designate some of your duties conferred or imposed on you, as allowed by the FIC. Please note that delegation of your responsibilities will not absolve you of your accountability to the Company and the FIC. Not a Prescribed Officer Being the S43 Compliance Officer does not make you a prescribed officer as defined in the Companies Act if you do not have general executive control. You are obviously deemed to be a prescribed officer if you have general executive control. Unless you have general executive control in your existing position, being appointed as a S43 Compliance Officer does not make you a prescribed officer as defined in the Companies Act. Kindly confirm your acceptance by signing below. Yours faithfully,
NAME OF CEO CHIEF EXECUTIVE OFFICER
Acceptance by person being appointed as the S43 Compliance Officer Name & Surname of Signatory Title of Signatory Email address Cellular No. Signature
Date of Signature By signing this letter, I accept my appointment as the S43 Compliance Officer of NAME OF COMPANY on the terms set out in this letter and those prescribed by the FIC, at any time. I acknowledge having read, understood, and accepted the terms of this letter, and declare that I am conversant with the relevant provisions of the FIC (Financial Intelligence Centre) and the Financial Intelligence Centre Act, 2001 (Act 38 of 2001).
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 90 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 13: MLRO Appointment Letter Appointment as FIC Money Laundering Reporting Officer Introduction The FIC (Financial Intelligence Centre) was established by the Financial Intelligence Centre Act, 2001 (Act 38 of 2001) and has the mandate to identify the proceeds of crime, combat money laundering and terror financing. The FIC Act introduces a regulatory framework of measures requiring certain categories of business to take steps regarding client identification, record-keeping, reporting of information and internal compliance structures. The Act obliges all businesses to report to the FIC various suspicious and certain other transactions. The FIC uses this financial data and available data to develop financial intelligence, which it is able to make available to the competent authorities and supervisory bodies for follow-up investigations or administrative action. All accountable and reporting institutions are required to register with the FIC. The FIC and supervisory bodies have the authority to inspect and impose administrative penalties on non-compliant businesses. More information on the FIC, may be found at www.fic.gov.za. An S43 Compliance Officer (S43CO) has been appointed as the designated first and central point of contact and required to cooperate with the FIC, and to provide leadership and oversight and communicate the vision for all our FIC compliance management activities that impact customers and employees. However, the FIC allows for the registration of further delegated users including a Money Laundering Reporting Officer (MLRO), who must understand the reporting requirements and be responsible for the submission of reports on the FIC platform. Authorisation and appointment I, the undersigned, duly authorised to issue this certificate on behalf of Subsidiary (Pty) Ltd (the Company), as an Accountable Institution (“AI”) under the FIC Act, hereby certify that Full Name (ID 000000 0000 00 0), is hereby authorised by the AI to act as a FICA Money Laundering Reporting Officer (“MLRO”) of the AI in terms of the Financial Intelligence Centre Act, 2001 (Act 38 of 2001). The MLRO role will be that of MLRO All (Money Laundering Reporting Officer - all reporting and message board). Effective date This appointment is with effect from xx Month yyyy. It constitutes a variation of your existing contract of employment, as noted herein.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 91 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Your duties and responsibilities as the MLRO The designated MLRO is responsible for working under the supervision of and assisting the S43 Compliance Officer (S43CO) in ensuring that the accountable institution and employees of the accountable institution comply with the provisions of the FIC Act and the internal rules formulated for and applicable to the accountable institution. Please read them carefully and refer to them often. Your duties and responsibilities are as follows: Duties •
The MLRO has a thorough knowledge of the anti-money-laundering legislation.
•
The MLRO assists the S43CO in training and providing guidance to employees and authorized representatives who have an obligation to carry out relevant duties in accordance with the FIC Act.
•
The MLRO has the responsibility and authority to submit intelligence reports to the Centre on behalf of the Company.
Responsibilities Record-keeping and reporting You are required to correctly identify and report the different reportable transactions in accordance with the FIC Act and the Regulations. You must assist the S43CO in ensuring employees correctly identify different types of clients in accordance with the FIC Act and the Regulations. You must assist the S43CO in ensuring employees understand the duty to keep records correctly as per the accountable institution’s internal procedures. You must also assist the S43CO to keep a record of and monitor all incidents of compliance exposure and non-compliance related to the FIC requirements. A register and details of the these together with resolution measures taken must be communicated to your CEO and Compliance Officer on a quarterly basis. Remain informed You must keep abreast of: •
the status of all related laws.
•
all decisions of, and information from the FIC.
•
all related rules, codes, or standards (including leading and best practices and frameworks) and consider adhering to them, creating strategies to close gaps and follow them.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 92 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Policy, process, and procedure You must participate in and review the implementation of relevant policies, processes, and procedures to ensure the efficient management and resolution of all FIC compliance obligations required by the Company. Investigations and enforcement notices You are required to assist the S43CO in their cooperation with the FIC in investigations and the required compliance with any enforcement notices within the timeframes specified by the FIC. Please note that failure to comply with an enforcement notice may have serious consequences to the S43CO as well as the Company. Incident management and correction You must assist the S43CO to investigate and handle every incident of non-compliance and compliance exposure related to the FIC requirements to ensure it is dealt with correctly and appropriately. You are furthermore required to assist the S43CO to ensure the relevant information, processes and procedures are updated to prevent them from re-occurring. Training and awareness You must assist the S43CO in the development, facilitation and promotion of ongoing corporate orientation, training, and awareness activities, communications for personnel at all levels and business partners regarding the FIC requirements. Delegation of duties Please note that delegation of any of the S43CO’s responsibilities to you will not absolve the S43CO of their accountability to the Company and the FIC. Not a Prescribed Officer Unless you have general executive control in your existing position, being appointed as a Money Laundering Reporting Officer (MLRO) does not make you a prescribed officer as defined in the Companies Act. Kindly confirm your acceptance by signing below. Yours faithfully,
NAME OF CEO/MD CHIEF EXECUTIVE OFFICER/MANAGING DIRECTOR
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 93 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Approval of the Money Laundering Reporting Officer (MLRO) by the Company’s designated S43 Compliance Officer (S43CO) Name & Surname of Signatory Title of Signatory Email address Cellular No. Signature
Date of Signature By signing this letter, I approve the appointment of Name of Money Laundering Reporting Officer as a Money Laundering Reporting Officer (MLRO) of NAME OF COMPANY on the terms set out in this letter and those prescribed by the FIC, at any time.
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 94 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Appendix 14: Summary of Offences and Penalties Section
Non-compliance / Offence
46
Failure to identify persons
46A
Failure to comply with duty in regard to customer due diligence in accordance with Sections 21A, 21B, 21C, 21D, 21E, 21F, 21G or 21H
47
Failure to keep records
48
Destroying or tampering with records
49
Failure to give assistance
49A
50
51
51A
52 53 54 55 56
Contravention of prohibitions relating to persons and entities identified by Security Council of the United Nations Failure to advise the FIC of client or Failure to advise within the prescribed period Failure to report cash transactions or Failure to report within prescribed period Failure to report property associated with terrorist & related activities or Failure to report within prescribed period, failure to comply with a direction, failure to scrutinise the info Failure to report suspicious or unusual transactions Unauthorised disclosure Failure to report conveyance of cash or bearer negotiable instrument into or out of S.A. Failure to send a report to the FIC Failure to report electronic transfers (future) or
Penalty Is non-compliant and subject to an administrative sanction Is non-compliant and subject to an administrative sanction Is non-compliant and subject to an administrative sanction Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Is non-compliant and subject to an administrative sanction Maximum period of 15 years imprisonment or a fine not exceeding R100m Is non-compliant and subject to an administrative sanction Maximum period of 15 years imprisonment or a fine not exceeding R100m Is non-compliant and subject to an administrative sanction Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 5 years or a fine not exceeding R10m Maximum period of 15 years imprisonment or a fine not exceeding R100m
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 95 of 96
Compliance
Risk Management & Compliance Programme (RMCP)
Section
57 58 59 60
Non-compliance / Offence Failure to report within prescribed period Failure to comply with a request Failure to comply with directives by the FIC Failure to comply with monitoring order Misuse of information
Penalty Is non-compliant and subject to an administrative sanction Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m Maximum period of 15 years imprisonment or a fine not exceeding R100m
Doc. Ref. & Version No:
Approval Date:
PIN FICA RR & V4.0
23 October 2025
Page 96 of 96