## 1zafea2021001 — South Africa (Detailed AML/CFT Assessment, onsite October 22–November 12, 2019)

## Source details

**Canonical URL:** [1zafea2021001 — South Africa (Detailed AML/CFT Assessment, onsite October 22–November 12, 2019)](https://www.imf.org/-/media/files/publications/cr/2021/english/1zafea2021001.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2021/english/1zafea2021001.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2021/english/1zafea2021001.pdf.json)

---

### EXECUTIVE SUMMARY — scope and purpose
- Summarizes the AML/CFT measures in place in the Republic of South Africa as at the date of the onsite visit (October 22 to November 12, 2019).
- Analyses compliance with the FATF 40 Recommendations and the level of effectiveness of South Africa’s AML/CFT system and provides recommendations to strengthen the system.

### Threats, risk understanding, and TF — key findings
- Main domestic ML crime threats are consistently understood by key authorities but understanding of relative scale, ML vulnerabilities, and threats from foreign predicates is limited.
- Understanding of terrorist financing (TF) risks is underdeveloped and uneven.
- Some ML risks are being mitigated but significant risks remain unaddressed.
- TF risks are not being adequately addressed.
- South Africa has a sustained period of “State capture” that generated substantial corruption proceeds and undermined key agencies; government initiatives from 2018/19 were starting to address this during the onsite.

### Financial Intelligence Centre (FIC) and Law Enforcement Agencies (LEAs)
- FIC effectively produces operational financial intelligence used by LEAs to investigate predicate crimes and trace criminal assets.
- LEAs lack skills and resources to proactively investigate ML or TF; SAPS:DPCI only had around 2,000 out of 5,000 positions in its special investigative units occupied as of the onsite.
- FIC receives on average approximately 300,000 STRs per year and more than five million CTRs and two million CTRAs annually.
- FIC disclosures are mostly reactive; ML or TF specific disclosures represent only eight percent of total disclosures.
- FIC average response time to LEA requests: around seven weeks; average working days to respond to domestic requests: 36 (five years to March 31, 2018).

### Investigations, prosecutions, convictions — findings and statistics
- South Africa convicted one person for TF since the last ME and had one ongoing TF prosecution as of the onsite.
- Prosecutions and convictions for ML:
  - Over the five-year period 2014–2018 SAPS/DPCI made 8,634 requests for information to FIC relating to ongoing cases; distribution: Fraud Related Crimes 2,338 (33%), Corruption 1,200 (17%), Drug Related Crimes 1,028 (15%), Tax Evasion 985 (14%), Robbery & Theft 588 (8%), Environmental Crimes 198 (3%), ML 469 (7%), TF 221 (3%), Total 7,027 (100%).
  - FIC made 2,216 proactive disclosures to LEAs (five years to March 31, 2018); distribution: Fraud Related Crimes 607 (27%), Tax Evasion 510 (23%), Corruption 98 (4%), Drug Related Crimes 92 (4%), Environmental Crimes 43 (2%), Robbery & Theft 16 (1%), ML 521 (24%), TF 329 (15%), Total 2,216 (100%).
- SAPS:DPCI predicate-offense investigation activity (Jan 1, 2014 to Dec 31, 2017):
  - Total Reported: 13,283; Investigated: 8,892; Referred for Prosecution: 2,554; Prosecuted for ML: 322; Percent of referred prosecuted for ML: 13%
  - Fraud: Reported 8,404; Investigated 5,350; Referred 740; Prosecuted for ML 240.
  - Corruption & bribery: Reported 1,663; Investigated 1,334; Referred 722; Prosecuted for ML 18.
- ML investigations, prosecutions and convictions — Five Years to March 31, 2019 (Table 3.10 / Box 3.1):
  - ML investigations by year: 2015: 358; 2016: 502; 2017: 457; 2018: 418; 2019: 271; Average: 401
  - ML prosecutions (cases) by year: 2015: 51; 2016: 43; 2017: 59; 2018: 67; 2019: 76; Average: 59
  - ML convictions (cases) by year: 2015: 51; 2016: 43; 2017: 59; 2018: 67; 2019: 76; Average: 59
  - Percentage of investigations leading to convictions (cases): 2015: 14%; 2016: 9%; 2017: 13%; 2018: 16%; 2019: 28%; Average: 15%
  - Number of persons convicted for ML by year: 2015: 69; 2016: 70; 2017: 93; 2018: 84; 2019: 114; Average: 86
  - For self-laundering (natural persons) — Average: 53 (63% of convicted persons)
  - For stand-alone ML — Average: 32 (37% of convicted persons)
  - Foreign predicates convictions — Average: 1
- Sanctions and sentencing for ML (March 2014 – October 2019):
  - Number of persons convicted of ML only: 154
  - Of which received suspended sentences: 119 (77%)
  - Of which received non-custodial sentence: 133 (86%)
  - Number receiving custodial sentences: 21
  - Average years of imprisonment: 7.6
  - Max years of imprisonment: 20
  - Custodial sentence bands: < 2 years: 2; 2 to < 5 years: 2; 5 to < 10 years: 11; 10 to < 20 years: 5; 20 to 30 years: 1
- NPA:AFU confiscation/forfeiture and recoveries (Five Years to March 31, 2019):
  - Provisional measures (restraints and preservations) — Number average: 409; Value (R millions) total: R 50,458.0? (per-year values listed; Average Value ($) per year shown)
  - Confiscations and forfeiture orders — Average number: 474; Value (R millions) average: R 1,233.1 (value across years listed)
  - Recoveries — Average number: 572; Value (R millions) average: R 1,142.7
  - NPA:AFU completed 5,607 confiscations and forfeitures to the value of R8.35 billion ($568 million) since 1999; completed 6,245 freezing orders to the value of R16.5 billion ($1.1 billion); recovered R6.74 billion ($458 million) (of which R5.68 billion ($386 million) returned to victims and R1.05 billion ($71.4 million) paid to CARA) as at September 30, 2019.
  - Analysis indicates on average authorities recover around 8 percent of the value of related proceeds in ML-related cases (recovery efforts continuing for some cases).

### Asset recovery, confiscation, and “State capture”
- South Africa proactively pursues confiscation and has good civil forfeiture results under POCA ch.6; less success recovering assets from “State capture” and proceeds moved abroad, although recent cases show early positive results.
- Case examples:
  - Company X — preservation order March 8, 2018 value R1.8 billion ($122.4 million); finalized April 26, 2018 and R1.9 billion ($129.2 million) paid to National Treasury.
  - Eskom/McKinsey — preservation order December 2017; preserved settled R902,274,123 ($61.4 million) on July 31, 2018 and paid back to Eskom.

### Cash and cross-border currency movement — findings and gaps
- Use of cash is prevalent and assessed as high risk for ML and TF; in 2016, 52 percent of the total value of all consumer transactions in South Africa were conducted in cash.
- Informal cross-border remittances substantial: up to 70 percent of cross-border remittances between South Africa and the SADC remittance market are informal.
- Reporting thresholds:
  - CTR must be filed when a cash transaction exceeds R24,999 ($1,700).
  - CTRA filed if aggregate cash transactions in a 24-hour period exceed R24,999 ($1,700).
- SARS:Customs border cash seizures — Five Years to March 31, 2019:
  - Total Seizures: 40; Total Value (R): R 215,047,192; Total Value ($): $16,029,670
  - Airports – Out accounted for 98% of value; 90% of outward seizures headed for United Arab Emirates; 4% Hong Kong.
- Gaps: FIC does not receive proactive reports from SARS on border cash declarations; written declaration requirement suspended in 2008; current expectation is oral declaration if carrying cash over R25,000 ($1,700) or foreign currency exceeding $10,000 or equivalent; system not well advertised.

### Terrorist financing (TF) and targeted financial sanctions (TFS) — findings
- TF prosecutions and investigations:
  - Only one TF conviction since last MER (Henry Okah, convicted March 2013; sentenced effective 24 years for bombings in Nigeria; maximum penalty for TF is 15 years).
  - Between April 1, 2013 and March 31, 2018, three TF investigative dockets opened and one advanced to prosecution.
  - Of 154 investigative inquiries over five years to March 31, 2018, 102 (72%) closed as unfounded/undetected/lack of information.
- TFS implementation:
  - No implementation of UNSCR 1267/1988/1989 designations since July 2017; last proclamation signed June 29, 2017 and published July 14, 2017.
  - Mechanism for UNSCR 1373 relies on High Court ex parte freezing orders focused on identified property rather than a general freezing order for designated persons — major shortcomings.
  - Since April 2019, TFS for proliferation financing (PF) implemented fairly well most of the time; between April 2019 and onsite, 1,822 users registered to FIC email alert (~5% of AIs and RIs).
  - As of the onsite and since April 2019, no PF-related assets had been frozen pursuant to UN designations.

### Preventive measures — private sector practices and coverage
- Larger banks: developed understanding of ML risks and implement mitigating measures commensurate with risks to some extent; generally better reporting and higher quality STRs.
- Smaller FIs and most DNFBPs: basic understanding, rule-based compliance focus rather than effective RBA implementation.
- CDD and BO:
  - Basic CDD applied by many accountable institutions (AIs) satisfactorily but beneficial ownership (BO) requirements only applied to some extent.
  - BO and PEP challenges: legal definition of PEP deficient (time limit), domestic PEP identification weak; AIs only apply BO requirements to some extent.
- VASPs and FinTech:
  - VASPs not subject to AML/CFT obligations other than general reporting; not supervised; 12 crypto-asset trading platforms identified as at 2019; largest three platforms control around 80–90 percent of market; hold AuM around R6.5 billion ($442 million).
- Reporting volume and quality:
  - Total reports (five years ending March 31, 2019): 977,485 (Grand Total)
  - Banks: 578,209 (59.15%); ADLAs: 360,655 (36.90%).
  - DNFBPs total (five years): 6,286 (0.64%); Casinos: 4,675 (0.46%); Estate agents: 99 (0.01%); Attorneys: 686 (0.07%).
  - Banks reported 175,580 s.29 reports in 2018/2019; ADLAs reported 96,748.
  - Best quality reports: larger banks; worst: attorneys and estate agents.
  - Trend: volume of reports decreased over last two years while quality improved per FIC.
- Transaction monitoring:
  - FIs improving automated systems but parameters often vendor defaults; Directive 5 of 2019 issued on use of automated transaction monitoring.

### Supervision — capacity, gaps, and effectiveness
- Risk-based AML/CFT supervision is relatively new; supervisory understanding of inherent ML/TF risk varies:
  - SARB:PA: relatively good understanding for banks; uses a risk matrix; 4 banks rated very high, 3 high, 27 medium as of onsite.
  - SARB:FinSurv: some understanding for ADLAs; inspections adequate but risk-based only to limited extent.
  - FSCA: developing understanding; sector-level SRAs conducted but entity-level risk ratings limited.
  - FIC: supervision skewed to MVDs and KRDs; limited coverage of TSPs and other DNFBPs.
- Inspection frequency and resources (selected figures):
  - SARB:PA — No. of AIs or RIs: 115; FTE staff for AML/CFT inspections: 19; Average Inspections Annually: 6; % of AIs inspected annually: 11%
  - FSCA — No. of AIs or RIs: 12,098; FTE staff for AML/CFT inspections: 74 general + 3 AML; % of AIs inspected annually: 2%
  - FIC — No. of AIs or RIs: 4,385; FTE staff for AML/CFT inspections: 9; Average Inspections Annually: 137; % of AIs inspected annually: 3%
  - LPC (attorneys) — No. of AIs or RIs: 19,119; FTE Staff for AML/CFT inspections: 0; % of AIs inspected annually: 0%
  - EAAB (estate agents) — No. of AIs or RIs: 27,568; FTE Staff for AML/CFT inspections: 4; Average Inspections Annually: 360; % of AIs inspected annually: 1%
- Supervisory shortcomings:
  - Market entry controls often rely on self-disclosure; fit and proper criteria frequently do not apply to beneficial owners.
  - Unlicensed cross-border MVTS not systematically identified or sanctioned.
  - Inspections often check presence of basic controls rather than soundness of AML/CFT programs.
  - Attorneys essentially no AML/CFT oversight at time of onsite.
  - Supervisors need major or fundamental improvements to conduct RBA supervision effectively.

### Legal persons, trusts, and beneficial ownership (BO) transparency
- Around 2,091,488 legal persons in South Africa (CIPC data as at June 14, 2019).
- Trusts: 180,159 trusts on electronic register at end of 2018 (registered since 2008); earlier trust records in paper form.
- Timeliness and access:
  - CIPC online information available only from 2016; companies registered before 2016 require manual search.
  - LEAs and prosecutors can access CIPC information within two days to two weeks depending on complexity.
  - Access to BO information is limited, often reliant on AIs; subpoenas take on average 7–10 days for response; complex structures can take about 30 days to access first-level legal ownership and longer for BO.
  - Master’s Office provides trustee identity on subpoena in about 10–15 days; does not collect information on other natural persons exercising ultimate control.
- Measures and gaps:
  - Measures to promote transparency address vulnerabilities only to a limited extent.
  - CIPC cannot impose administrative fines directly; two-year period to strike off delinquent companies considered too long.
  - Authorities could not demonstrate effective, proportionate, dissuasive sanctions for failure to comply with information requirements.
- IO.5 assessment: South Africa rated as having a low level of effectiveness for IO.5.

### International cooperation and mutual legal assistance (MLA)
- South Africa provides constructive MLA and extradition; assistance useful but sometimes slow; turnaround time averages over one year.
- Over 2015–2019: received 552 MLA requests; 41 ML/TF-related requests (40 ML, 1 TF); 29 executed or in process; 12 (30%) ML/TF requests not executed due to noncompliance with South African requirements.
- Outgoing MLA requests low: 50 outgoing MLA requests over 2015–2019 (32 in 2018); of these 50, 3 related to ML and 3 to terrorism; no outgoing MLA requests sought to freeze assets related to “State capture” cases.
- FIC international exchanges (five years ending March 31, 2018):
  - Outbound requests sent to other FIUs: 306 (Fraud 79 — 26%; Tax Crimes 75 — 25%; ML 40 — 13%; TF 28 — 9%).
  - Inbound requests received: 1,310 (Tax Crimes 403 — 31%; Fraud 346 — 26%; ML 332 — 25%; TF 99 — 8%); Requests Granted: 1,086 — 83%.
- IO.2 assessment: South Africa rated as having a moderate level of effectiveness for IO.2.

### Priority Actions (selected consolidated list)
- Develop policies to address higher ML/TF risks for:
  - (i) beneficial ownership (BO);
  - (ii) use of cash and its cross-border movement (physically and through illegal MVTS);
  - (iii) third-party ML;
  - (iv) foreign predicate crimes;
  - (v) TF. Ensure all FIs, DNFBPs and VASPs are subject to AML/CFT obligations unless they pose proven low risks.
- Analyze how to substantially improve availability of information on domestic PEPs; remove the time limit in the definition of PEP in the FIC Act.
- Provide SAPS:DPCI with more staff, especially financial investigators and forensic accountants, to better use financial intelligence and proactively identify/investigate ML cases, including “State capture”.
- Prioritize efforts to stem the flow and recover assets from “State capture”, including assets transferred abroad, and actively seek timely MLA for transnational ML, predicate offenses and TF.
- Make major enhancements to measures at borders to detect and seize illicit cash flows and identify/remove unlicensed cross-border MVTS.
- Greatly improve ability to proactively identify TF activity; reconsider policy of not pursuing domestic designations as a tool to counter terrorism or TF.
- Revise TFS legal framework to address major shortcomings in R.6 and create robust procedures for implementing UN listings without delay.
- Establish much better mechanisms to collect BO information about companies and trusts; train LEAs on complex structures and abuse for ML/TF.
- Ensure AIs adequately implement an RBA, including improved inherent risk assessment and dynamic RMCPs; authorities should provide better guidance on major ML/TF risks such as corruption.
- Supervisors should improve RBA AML/CFT supervision, prioritize supervisory activities by inherent risk, and ensure securities sector, attorneys, estate agents, TSPs, CSPs, DPMS and VASPs are supervised or monitored commensurate with risk.

### Overall effectiveness ratings (Immediate Outcomes selected)
- IO.1 - Risk, policy, and co-ordination: Moderate
- IO.2 - International cooperation: Moderate
- IO.3 - Supervision: Moderate
- IO.4 - Preventive measures: Moderate
- IO.5 - Legal persons and arrangements: Low
- IO.6 - Financial intelligence: Moderate
- IO.7 - ML investigation & prosecution: Moderate
- IO.8 - Confiscation: Moderate
- IO.9 - TF investigation & prosecution: Low
- IO.10 - TF preventive measures & financial sanctions: Low
- IO.11 - PF financial sanctions: Moderate

### Selected Technical Compliance ratings (summary)
- R.1 - assessing risk & applying risk-based approach: PC
- R.6 - targeted financial sanctions – terrorism & terrorist financing: NC
- R.10 – Customer due diligence: PC
- R.12 – Politically exposed persons: NC
- R.24 – Transparency & BO of legal persons: PC
- R.25 - Transparency & BO of legal arrangements: PC
- R.26 – Regulation and supervision of financial institutions: PC
- R.28 – Regulation and supervision of DNFBPs: PC
- R.40 – Other forms of international cooperation: LC

*Source: Detailed Assessment Report (onsite visit October 22 to November 12, 2019) — South Africa, INTERNATIONAL MONETARY FUND (extracted from content unit 1zafea2021001).*

### EXECUTIVE SUMMARY ________________________________________________________________________ 11

### EXECUTIVE SUMMARY

### Scope and purpose
- This report summarizes the AML/CFT measures in place in the Republic of South Africa (South Africa) as at the date of the onsite visit (October 22 to November 12, 2019).
- It analyses the level of compliance with the FATF 40 Recommendations and the level of effectiveness of South Africa’s AML/CFT system and provides recommendations on how the system could be strengthened.

### Key findings — threats, risk understanding, and TF
- The main domestic money laundering (ML) crime threats are consistently understood by the key authorities but the understanding of their relative scale, ML vulnerabilities, and the threats from foreign predicates is limited.
- Understanding of terrorist financing (TF) risks is underdeveloped and uneven.
- Some ML risks are being mitigated but some significant risks remain to be addressed.
- TF risks are not being adequately addressed.

### Key findings — State capture and institutional effects
- South Africa has suffered from a sustained period of “State capture”, which helped to generate substantial corruption proceeds and undermined key agencies with roles to combat such activity.
- Government initiatives from 2018/19 were starting to address the situation as of the onsite, including by replacing key staff and increasing resources at key law enforcement and judicial agencies.

### Key findings — Financial Intelligence Centre (FIC) and LEAs
- The Financial Intelligence Centre (FIC) effectively produces operational financial intelligence that Law Enforcement Agencies (LEAs) use to help investigate predicate crimes and trace criminal assets.
- The LEAs lack the skills and resources to proactively investigate ML or TF.

### Key findings — prosecutions, convictions, and enforcement gaps
- A reasonable number of ML convictions is being achieved but only partly consistent with South Africa’s risk profile.
- Cases largely concern self-laundering and few cases of third-party ML and foreign predicate offenses are prosecuted.
- The proactive identification and investigation of ML networks and professional enablers is not really occurring.
- Most ML convictions relate to fraud cases and there are fewer investigations and successful prosecutions relating to other high-risk crimes.
- ML cases relating to “State capture” have not been sufficiently pursued.

### Key findings — asset recovery and confiscation
- South Africa has achieved some good results proactively pursuing confiscation of criminal proceeds, particularly using civil forfeiture powers.
- The country has had less success recovering assets from “State capture” and proceeds which have been moved to other countries.
- Some recent cases suggest that this situation is improving.

### Key findings — cash and cross-border currency movement
- Use of cash is prevalent in South Africa and it has been assessed as high risk for ML and TF, including cross-border movement.
- Detecting and recovering cash proceeds of crime remains challenging and efforts to detect and confiscate falsely or undeclared cross-border movement of currency needs substantial improvement.

*Source: EXECUTIVE SUMMARY (Report as at onsite visit October 22 to November 12, 2019).*

### 7.      South Africa has convicted one person for TF since the last ME and was prosecuting

### 7.      South Africa has convicted one person for TF since the last ME and was prosecuting

### Summary of key findings
- South Africa has convicted one person for TF since the last ME and was prosecuting one case as of the onsite, which is inconsistent with its significant TF risks.
- A conservative approach to classifying politically motivated acts of violence as terrorism negatively impacts investigation and prosecution of potential terrorist financiers.
- Targeted Financial Sanctions (TFS) are not used to any great extent to fight terrorism; implementation of United Nations Security Council Resolutions (UNSCRs) for TF has not occurred since 2017.
- Law enforcement faces challenges to readily obtain accurate and updated beneficial ownership (BO) information about companies and trusts adequate to enable effective investigation of ML and TF.
- Larger banks are more developed at understanding their ML risks and implementing mitigating measures commensurate with those risks; most smaller Financial Institutions (FIs) and Designated Non-Financial Businesses and Professions (DNFBPs) focus on compliance, not on identifying and understanding risks.
- TF risk is understood by the private sector to some extent; overall, the risk-based approach (RBA) is inadequately implemented.
- Basic customer due diligence (CDD) is applied by many accountable institutions (AIs) satisfactorily but BO requirements only to some extent.
- Larger banks and Authorized Dealers with Limited Authority (ADLAs) meet suspicious reporting obligations to a large extent, but some high-risk sectors rarely report.
- Dealers in Precious Metals and Stone (DPMS) and Company Service Providers (CSPs) are not AML/CFT regulated (save for a general reporting obligation), as is also the case for Virtual Asset Service Providers (VASPs).
- Risk-based AML/CFT regulation and supervision is relatively new; most supervisory activities occur for banks and ADLAs but none of the supervision of FIs or DNFBPs uses a proper RBA.
- Inspections in other sectors are too infrequent and focus on the presence of basic controls not the soundness of AML/CFT programs.
- The Financial Intelligence Centre (FIC) is a key coordinator and provides a wide range of well-regarded guidance.
- Market entry controls to screen out criminality need fundamental improvements.
- South Africa provides constructive mutual legal assistance (MLA) which has helped to resolve some criminal cases in other countries, but it is sometimes slow and following up on requests needs major improvement.
- Since April 2019, South Africa has implemented TFS for proliferation financing (PF) fairly well most of the time without delay, but private sector understanding is uneven and supervision of PF-related obligations is new.

### Risk and general situation
- South Africa has a relatively high volume and intensity of crime; more than half of reported crimes fall into categories that generate proceeds.
- Main domestic proceeds-generating predicate crimes: tax crimes, corruption and bribery, fraud, trafficking in illicit drugs, and environmental type crimes.
- As a large economy and a regional financial hub for sub-Saharan Africa, South Africa has notable exposure to foreign proceeds of crime being laundered in or through the country.
- Exposed to TF risks associated with the financing of foreign terrorism, foreign terrorist fighters (FTFs), and potential domestic terrorism.
- Widespread use of cash and a large informal economy including informal cross-border remittances often involving physical cash movement.
- Insufficient BO transparency is an acute vulnerability; companies and trusts are often misused for ML or predicate crimes.
- Attorneys and trust and company service providers are inherently vulnerable to misuse; estate agents are also exposed with many known ML cases involving real estate.
- Public sector corruption represents a major weakness in the AML/CFT system, with key LEAs being the most impacted over the past decade.
- The RBA and many key preventive requirements were introduced in the legal framework only recently.

### Assessment of risk, coordination and policy setting
- Corruption, tax related crimes and fraud are understood as the main domestic ML threats by key AML/CFT authorities, but understanding of the relative scale and exploited vulnerabilities is less developed.
- Threats from proceeds of foreign predicates are understood only to a very limited extent.
- Authorities’ understanding of TF threats is underdeveloped and uneven; supervisors are the most unsensitized.
- Authorities identify TF risks as mainly stemming from international terrorism but lack due appreciation of domestic terrorism risks.
- South Africa has yet to conclude its first national ML and TF risk assessments (NRAs); a summary of preliminary findings of the ML NRA has been shared with some private sector representatives while those of the TF NRA have not.
- South Africa has yet to develop coordinated and holistic national AML/CFT policies informed by ML/TF risks.
- Significant ML risks remain largely unaddressed for beneficial owners of legal persons and trusts, cross-border movement of cash, and criminal justice efforts are not yet directed towards effectively combating higher risks such as ML related to corruption, narcotics, and tax offenses.
- TF is not properly integrated into the National Counter Terrorism Strategy (NCTS).
- Some financial sectors, DNFBPs, and VASPs are yet to be subject to most AML/CFT obligations and their exclusion is not justified based on risk.
- An Inter-Departmental Committee (IDC) on AML/CFT established in 2017 includes most stakeholders and coordinates NRAs but has not generated strategic AML/CFT policy initiatives; its agenda has been driven mainly by financial regulatory issues with little focus on law enforcement and judicial matters.
- Coordination among authorities on PF remains at its initial stages.

### Financial intelligence, ML investigations, prosecutions and confiscation
- The FIC obtains a large number of obligatory reports, possesses tools and access to additional information, and effectively produces operational financial intelligence.
- Significant gaps in financial intelligence exist due to: risks pertaining to cash (particularly cross border cash transactions), the FIC not routinely receiving reports on cash courier activity, and low reporting volume from high risk DNFBPs.
- SAPS, SARS and other authorities routinely use financial intelligence mainly to support investigations and activities related to predicate crimes, not proactively for ML and TF cases.
- LEAs require additional skills and resources to more effectively use generated information for financial investigations; SAPS:DCPI only had around 2,000 out of 5,000 positions in its special investigative units occupied as of the on-site.
- Authorities identify and investigate ML cases to some extent, with emphasis on investigating predicate offenses; Parallel financial investigations (PFIs) are undertaken in all cases of organized crime, serious commercial crime, and serious corruption.
- Authorities have not sufficiently demonstrated proactive identification and investigation of ML cases as a primary objective.
- ML cases relating to fraud form the bulk of cases investigated and prosecuted; fewer prosecutions relate to serious corruption, narcotics, and tax offenses.
- ML cases relating to “State capture” have not been sufficiently pursued; cases referred to the NPA by the Special Investigating Unit (SIU) have not been dealt with expeditiously.
- The NPA has suffered major resource and staffing constraints; establishment of the Investigative Directorate (NPA:ID) and increased budget allocation for hiring of prosecutors are addressing this.
- A reasonable number of convictions is being achieved, largely concerning self-laundering; standalone ML cases are prosecuted but few third-party ML and foreign predicate offense prosecutions occur.
- Sanctions against natural persons convicted of ML offenses are to some extent effective, proportionate, and dissuasive, but the majority of sentences involve non-custodial or suspended sentences for the ML offense.
- South Africa proactively pursues confiscation of criminal proceeds as a policy objective and has achieved some good results, with NPA:AFU emphasizing civil forfeiture under the Prevention of Organized Crime Act (POCA).
- Less emphasis is placed on criminal confiscation of property of equivalent value (dependent on a conviction).
- Recovery of proceeds from “State capture” and assets moved to other countries has been less successful to date; recent efforts show early positive results in some major cases.
- Recovering proceeds of criminal offenses outside South Africa is not being sufficiently targeted given South Africa’s role as a regional financial hub.
- South Africa has not positively demonstrated that confiscation of falsely declared or undeclared cross-border movement of currency is being addressed and applied effectively; use of cash is prevalent and assessed as high risk from an ML and TF perspective.

### Terrorist and proliferation financing (TF/PF)
- TF pursuit is coordinated through the Counter Terrorism Functional Committee (CTFC) comprising relevant security cluster stakeholders.
- Pursuing TF investigations is not well integrated with strategies to combat terrorism; authorities are failing to produce results reflective of the country’s identified TF risk.
- Low level of viable investigations and prosecutions into TF is inconsistent with South Africa’s TF risk profile as a country with FTFs and used by terrorist groups as a transit point and a base for planning and logistics.
- South Africa has failed to demonstrate that it is effectively identifying, investigating, or prosecuting terrorist financiers or addressing TF through alternative measures.
- Implementation of TFS against TF is not effective and suffers from deficiencies inherent to the applicable framework; terrorists are deprived of resources only to a negligible extent relative to TF risk.
- Measures for TFS and to combat abuse of non-profit organizations (NPOs) are not in line with South Africa’s TF risk profile.
- Authorities do not consider administrative TFS designations as a relevant tool in practice; they favor obtaining compelling evidence and testing in court through criminal proceedings before considering designations under UNSCR regimes for TFS.
- Alternative processes to deprive terrorists of assets have been used only to a limited extent relative to TF risk.
- Formation of an NPO Task Team (NPOTT) has begun identification of NPOs at risk of TF abuse, but authorities have not applied specific measures nor commenced monitoring or supervision of those organizations.
- Since April 2019, South Africa has implemented TFS for PF fairly well, but some major improvements are needed; implementation without delay occurs most of the time for existing UNSCRs but is unlikely to be without delay for new UNSCRs.
- Early detection of PF activities is to some extent ongoing, relying mostly on STRs and foreign intelligence; detection is challenged by limited access to BO information.
- Despite FIC outreach, private sector understanding of PF obligations remains uneven; only larger FIs with international exposure have more developed understanding and likely appropriate compliance; supervision and compliance monitoring of PF-related obligations is at an early stage.

### Preventive measures
- Larger banks (collectively, materially important) show a developed understanding of ML risks and implement mitigating measures commensurate with their risks.
- Most smaller FIs, including materially important financial services providers (FSPs) and collective investment scheme (CIS) managers, show a basic understanding of ML risk and are predominantly rule-based rather than risk-focused.
- DNFBPs’ understanding of ML risks and AML/CFT obligations is underdeveloped; mitigating measures are not risk-based, with casinos as a positive outlier.
- High-risk estate agents and attorneys have a poor understanding of risks and obligations.
- AIs understand and mitigate TF risk commensurate with their risks to some extent.
- Preventive measures are applied by larger banks in a risk-based manner to some extent, but the majority of other AIs (including FSPs and CIS managers, attorneys and estate agents) fail to adequately assess their ML/TF risks.
- Many AIs apply basic CDD satisfactorily, but all only apply BO requirements to some extent.
- Only the larger banks seem to apply a broader range of CDD measures including risk based ongoing due diligence and specific measures towards correspondent banking relationships (CBRs), new technologies, wire transfers, and high-risk jurisdictions.
- Politically exposed persons (PEPs) are in general insufficiently identified partially due to the deficient legal definition, but where PEP-status is determined AIs seem to take enhanced measures.
- AIs downplay risks of operating internationally and larger banks’ group controls may not be adequately applied in their foreign entities.
- Only larger banks and ADLAs are reporting sufficient STRs and Suspicious Activity Reports; other high-risk or materially important sectors underreport substantially (casino sector a positive outlier).
- Larger banks file the best quality reports; the worst are filed by attorneys and estate agents.
- Banks could improve reporting by providing better information to link both ends of reported transactions.
- The FIC Act was significantly amended in 2017 (enforced since April 2019) to provide for: a risk-based approach to CDD; institutional (or, business) risk assessments; and a full range of CDD measures.
- Several exemptions to the preventive measures regime were removed, but some sectors remain out of scope.
- Reporting obligations have been specifically applied to dealers in motor vehicles (MVDs) and Krugerrand dealers (KRDs), while CSPs, other DPMS and VASPs are subject to a general reporting requirement but are not classified as AIs under the FIC Act nor required to be registered with the FIC.

### Supervision
- Risk-based AML/CFT regulation and supervision is relatively new.
- Most supervisory activities occur for banks and ADLAs but none of the supervision of FIs or DNFBPs uses a proper RBA.
- Inspections in other sectors are too infrequent and focus on the presence of basic controls not the soundness of AML/CFT programs.
- Market entry controls to screen out criminality need fundamental improvements.

*Source: 1zafea2021001 - South Africa (IMF).*

### 36.      While fit and proper criteria are in place for many sectors, these often do not apply to

### 1zafea2021001 - 36.      While fit and proper criteria are in place for many sectors, these often do not apply to 

### Fit and proper criteria and beneficial ownership (BO)
- Fit and proper criteria are in place for many sectors, these often do not apply to beneficial owners.
- There was an isolated case where a bank application was rejected due to BO issues, but the authorities could not demonstrate that they implement adequate controls to prevent criminality from infiltrating FIs and DNFBPs.
- Most regulators rely to a large extent on self-disclosure, and there is little verification done by competent authorities on criminal record checks.
- Unlicensed cross-border MVTS are not being systematically identified, sanctioned, or removed from the market.

### Sector risk assessments (SRAs) and supervisors’ risk understanding
- As of the onsite, interim SRAs were completed for most sectors covered in the South African regime.
- Supervisors demonstrated varied levels of understanding of ML risks at the sector level:
  - The South African Reserve Bank’s (SARB) Prudential Authority (SARB:PA) has a relatively good understanding with respect to banks at the sector level.
  - Risks in potential high-risk DNFBP sectors (estate agents, attorneys and trust service providers (TSPs)) are understood by their supervisor to a limited or negligible extent.
  - The Financial Sector Conduct Authority’s (FSCA’s) and the Financial Surveillance Department’s (SARB:FinSurv’s) risk understanding is less developed.
- At the institutional level:
  - Banks and ADLA are the only AIs rated for ML/TF risks at the institutional level but with limited consideration of their inherent risks.
- Supervisors understand AML/CFT controls better than inherent and residual ML/TF risks.
- TF risk understanding across supervisors is very limited.

### AML/CFT supervision effectiveness and gaps
- All supervisors in South Africa need major or fundamental improvements to conduct AML/CFT risk-based supervision effectively.
- SARB:PA:
  - Supervision of the materially important banking sector checks compliance with AML/CFT requirements thoroughly but not yet using a proper RBA.
  - Has applied a range of remedial actions and sanctions against banks for AML/CFT breaches, but the sanctions are not always proportionate or dissuasive.
- SARB:FinSurv:
  - Inspections adequately cover ADLAs but are based on risks only to a limited extent.
- Other supervisors:
  - Inspections are too infrequent to be effective.
  - Attorneys are subject to essentially no AML/CFT oversight.
  - Except for SARB:PA, inspections primarily focus on existence of basic AML/CFT controls rather than soundness of the AML/CFT program.
- Effectiveness of supervision by the FSCA and the Estate Agency Affairs Board (EAAB - for estate agents) is hampered by a severe lack of resources.
- SARB:PA and the FSCA coordinate or share information with each other on AML/CFT but not yet on supervision of FIs that belong to the same group nor do they coordinate their inspections.
- Most other supervisors (except those for attorneys and casinos) apply remedial actions, but sanctions imposed are often too low and infrequent to be dissuasive or effective.
- Financial supervisors demonstrated some impact in improving FIs’ compliance with basic obligations.
- Enforcement of the amended FIC Act only started in April 2019 and supervisory impact that improves compliance with the new risk-based obligations was not demonstrated.

### Guidance, outreach, and information on risks
- The FIC provides a wide range of AML/CFT guidance and conducts outreach nationally, supplemented by other supervisors, to promote a consistent understanding of AML/CFT obligations in the FIC Act.
- Only limited information has been provided to help the private sector identify and understand ML/TF risks due in part to a lack of a completed NRA.

### Legal persons, trusts, and BO transparency
- Different types of legal persons can be created in South Africa; creation of trusts mostly relate to inter-vivos and testamentary trusts.
- Information on the creation of the different types of legal persons and trusts is publicly available.
- The majority of LEAs have a general understanding of the exposure of legal persons and arrangements to possible ML misuse, but this does not extend to identification and assessment of the specific ML/TF vulnerabilities.
- The legal framework prevents legal persons and arrangements from being misused for ML/TF to a limited extent only; measures are at different levels of implementation.
- Legal persons and arrangements remain vulnerable as they are frequently cited in ML schemes; limited information is known on misuse for TF.
- Some basic information on companies and trusts can be obtained as it is publicly available, but:
  - There is a challenge with the turnaround time for information about most companies registered before 2016 as the information has not been uploaded to the public system.
  - The Master’s Office maintains a register of trusts containing basic information that is publicly available.
  - Obtaining adequate, accurate and current BO information compared to basic, also varies but in the majority of cases it is not easily available and when available, it often takes a long time to obtain.
- The authorities could not demonstrate that they apply sanctions for failure to comply with information requirements.

### International cooperation and mutual legal assistance (MLA)
- South Africa provides constructive MLA and extradition in response to international requests.
- Assistance has resulted in resolution of some criminal cases in other jurisdictions but is sometimes slow; turnaround time averages over one year.
- There is an absence of an effective case management system and overall responsibility for the timely execution of the requests.
- Outgoing requests for MLA have only been made in a limited number of instances, which is inconsistent with South Africa’s risk profile.
- Authorities have not adequately demonstrated that seeking international cooperation in the investigation of ML, associated predicate offenses, and TF is a priority.
- Authorities need to use MLA more, especially for recovery of the proceeds of crime from “State capture” which have been moved abroad.
- Volume of ML/TF MLA requests has recently increased, but those requests often suffer from delays in getting responses, and follow-up on outgoing requests needs major improvement.
- Competent authorities exchange information informally with foreign counterparts more in keeping with South Africa’s risk profile.
- South African authorities can share some basic information on companies and trusts in a timely way because it is publicly available, but they have a limited ability to share BO information in a timely manner because this information is not readily available.

### Priority Actions (listed)
- Develop policies to address higher ML/TF risks for: (i) BO; (ii) use of cash and its cross-border movement (physically and through illegal MVTS); (iii) third-party ML; (iv) foreign predicate crimes; (v) and TF. Ensure that all FIs, DNFBPs and VASPs are subject to AML/CFT obligations unless they pose proven low risks.
- Analyze how to substantially improve the availability of information on domestic PEPs and then support AIs to identify such PEPs. Remove the time limit in the definition of PEP in the FIC Act.
- Provide the SAPS Directorate for Priority Crimes Investigations (SAPS:DPCI) with more staff, especially financial investigators and forensic accountants, so that it can better use financial intelligence and place more emphasis on proactively identifying and investigating ML cases, particularly high level and complex cases such as those related to “State capture” and others involving third party laundering, foreign predicates, ML networks, and professional enablers.
- Keep prioritizing efforts to stem the flow of and recover assets from “State capture”, including assets transferred to countries outside of South Africa, until satisfactory results are achieved.
- Actively seek formal and timely MLA for ML, associated predicate offenses and TF that have transnational aspects and follow-up on such requests, including proactively pursuing “State capture” requests through all available channels.
- Make major enhancements to the effectiveness of measures at borders to detect and seize illicit cash flows and to identify and address unlicensed cross-border MVTS.
- Greatly improve ability to proactively identify TF activity and reconsider the policy of not pursuing the domestic designations as a tool to counter terrorism or TF.
- Revise the TFS legal framework to address the major shortcomings identified in R.6 and create robust procedures for implementing UN listings without delay.
- Establish much better mechanisms to collect BO information about companies and trusts, and train relevant LEAs about complex structures and how they can be abused for ML/TF purposes.
- South Africa should ensure that AIs adequately implement an RBA, including through better assessing and understanding their inherent risks and refining and implementing their risk management and compliance programs (RMCPs) to mitigate their risks. The authorities should provide better guidance on these matters and on major ML/TF risks such as corruption.
- Supervisors should improve how they conduct risk-based AML/CFT supervision, including by improving their understanding of inherent ML/TF risks at sector and institutional levels and using that to prioritize their supervisory activities.
- Ensure the securities sector, attorneys, estate agents, TSPs, CSPs, and DPMS are supervised or monitored for AML/CFT commensurate with their risk profiles, by increasing supervisory resources and closing gaps in sector coverage.

### Effectiveness & Technical Compliance Ratings (summary)
- Table 1. South Africa: Effectiveness Ratings (IOs)
  - IO.1 - Risk, policy, and co-ordination: Moderate
  - IO.2 - International cooperation: Moderate
  - IO.3 - Supervision: Moderate
  - IO.4 - Preventive measures: Moderate
  - IO.5 - Legal persons and arrangements: Low
  - IO.6 - Financial intelligence: Moderate
  - IO.7 - ML investigation & prosecution: Moderate
  - IO.8 - Confiscation: Moderate
  - IO.9 - TF investigation & prosecution: Low
  - IO.10 - TF preventive measures & financial sanctions: Low
  - IO.11 - PF financial sanctions: Moderate
- Table 2. South Africa: Technical Compliance Ratings (selected)
  - R.1 - assessing risk & applying risk-based approach: PC
  - R.6 - targeted financial sanctions – terrorism & terrorist financing: LC
  - R.10 – Customer due diligence: PC
  - R.12 – Politically exposed persons: LC
  - R.24 – Transparency & BO of legal persons: PC
  - R.25 - Transparency & BO of legal arrangements: PC
  - R.26 – Regulation and supervision of financial institutions: PC
  - R.28 – Regulation and supervision of DNFBPs: PC
  - R.40 – Other forms of international cooperation: LC

*Source: Detailed Assessment Report (onsite visit October 22 to November 12, 2019) — South Africa, INTERNATIONAL MONETARY FUND*

### 51.      South Africa’s geographic and economic position potentially exposes it to the threat

### 1zafea2021001 - 51.      South Africa’s geographic and economic position potentially exposes it to the threat

### Exposure and primary threats
- Geographic and economic position exposes South Africa to foreign proceeds of crime from the region being laundered in or through South Africa, and to being used as a transit route for illicit goods and people smuggling.
- Foreign proceeds come predominantly from fraud, corruption and bribery, illicit drugs, and tax crimes.
- Proceeds are often in the form of cash and are being laundered using cash, banks, and legal persons, as well as virtual assets (VAs) and MVTS to a lesser extent.
- South Africa is potentially exposed to TF including financing to facilitate foreign terrorism for groups such as ISIL, and the presence of facilitation networks and cells. Most TF cases shared with the team have a transnational element. Funds for some attacks in Africa are suspected of originating from or transiting through South Africa.

### ML/TF vulnerabilities (findings)
- High volume and intensity of crime; more than half of reported crimes fall into categories that generate proceeds.
- South Africa is a large economy and a regional transport and financial hub for sub-Saharan Africa.
- Widespread use of cash and a large informal economy: cash use is assessed as high risk in the NRA, and a large proportion (up to 70 percent) of cross-border remittances between South Africa and the SADC remittance market are informal.
- Public sector corruption (often referred to as "State capture") represents a significant weakness in the AML/CFT framework.
- Insufficient resources dedicated to AML/CFT in some competent authorities relative to South Africa’s size and risk profile.
- Long porous borders with relatively poor controls at numerous land and sea entry points.
- Large migrant population from higher risk jurisdictions in Africa and South Asia and resulting remittance flows likely elevate TF risk.
- DNFBPs such as attorneys, other TCSPs, estate agents, and DPMS are inherently vulnerable to misuse.
- Insufficient corporate ownership transparency: no comprehensive framework for accessing accurate and up-to-date BO information.
- The RBA has only recently been incorporated in the AML/CFT legal framework; many preventive measures obligations are relatively new.

### Country Risk Assessment — ML NRA and TF NRA (findings & concerns)
- South Africa is concluding its first national assessment of ML risks (ML NRA); the approach is mainly qualitative, relying on experts’ judgement and internal and open-source information.
- Preliminary ML NRA high-risk threats: corruption and bribery, tax related offenses, cybercrimes, fraud and drug trafficking.
- Preliminary ML NRA medium-high threats: human trafficking, smuggling of illicit goods, and wildlife trafficking.
- Corruption and bribery are seen as high severe risks due to their role as “enablers” of other predicate offenses and ML.
- Use of cash is identified as a high risk.
- Preliminary ML NRA acknowledges South Africa's role as a financial hub and gateway for funds flowing from sub-Saharan countries to the rest of the world, including potential foreign proceeds of crime.
- Implementation challenges identified: coordination between private and public sectors, provision of resources, obtaining and accessing ultimate beneficial ownership information, and products/services from new technologies.
- TF NRA preliminary findings: South Africa not target of domestic terrorism but degree of risk from international terrorism; limited activities of the Islamic State involving South African citizens; potential sources of TF risks from Al-Qaeda in the Islamic Maghreb, Boko Haram, and Al Shabaab; potential threat of returning FTFs from ISIS held areas in Syria; vulnerabilities include lax border controls of travelers and cash and informal remittance systems at the regional level; VAs noted as susceptible to TF abuse.
- Assessors’ specific concerns with preliminary NRAs:
  - (i) proceeds from corruption significance may not be fully recognized;
  - (ii) no reference to high end sophisticated ML in preliminary ML NRA findings;
  - (iii) preliminary ML risk ratings for some FIs and DNFBPs seem incomparable or unreasonable across institutions (e.g., casinos rated higher-risk than banks) or inconsistent with known ML cases (e.g., attorneys and estate agents rated medium-risk despite regular association with ML cases);
  - (iv) potentially high-risk sectors outside current AML/CFT regime (e.g., DPMS, CSPs) were not assessed;
  - (v) threats from foreign predicates and associated vulnerabilities not well reflected;
  - (vi) TF NRA likely underestimates TF risks associated with funding domestic terrorist activities;
  - (vii) TF NRA preliminary findings lack specific conclusions on sector vulnerabilities.

### Scoping of higher-risk issues (areas explored)
- Risks beyond financial sector: informality (for ML/TF), abuse of real estate, companies, gate-keepers such as attorneys, and implications of AML/CFT regime not covering dealers in diamond and gold mining industries.
- Understanding of TF risks (TF-related risk information was only shareable during onsite).
- Banking and MVTS sectors' understanding of ML/TF risks, particularly for cash, cross-border, and PEP transactions.
- Efforts to combat ML/TF in the informal sector and management of risks in context of financial inclusion initiatives.
- Focus on customs and border controls due to frequent links between cash smuggling and ML/TF.
- Corruption ("State capture"): focus on how well authorities combat laundering of proceeds of corruption and effectiveness of measures targeted at foreign and domestic PEPs.
- South Africa’s role as a regional financial and economic hub and ML/TF risks from cross-border financial flows and smuggling, and cooperation with foreign counterparts.

### Sector risk ratings (from SRAs incorporated into preliminary ML NRA)
- Gambling Institutions: High
- Motor Vehicle Dealers (MVDs): High
- Krugerrand Dealers (KRDs): High
- Banks: Medium to High
- Lenders of money against the security of securities: Medium
- Authorized Users of a Securities Exchange: Medium
- Investment Managers: Medium
- Linked Investment Service Providers (LISP): Medium
- Estate Agents: Medium
- TSPs: Medium
- Attorneys: Medium
- CIS managers: Low
- Financial Advisers and Intermediaries: Low
- Note: SRAs of ADLAs and life insurers were completed shortly before the onsite and yet to be incorporated; ADLAs concluded to be of a very low to low risk while life insurers are of a medium risk.

### Materiality and financial sector scale (key statistics)
- Non-bank financial institutions in the securities sector hold about sixty percent of financial assets (R11,400 billion or $775.2 billion).
- The banking sector, comprising 34 banks, had around $385 billion in assets in the end of 2018.
- 2018 cross-border banking transactions equated to around $1 trillion (being $475 billion of outflows, $350 billion of inflows and $180 billion of correspondent flows).
- As of 2016, cross-border annual remittances amounted to around $1 billion in each direction.
- South Africa has the largest real estate market in sub-Saharan Africa, amounting to $50.2 billion in 2019.
- Total diamond sales in 2018 was R17 billion ($1.2 billion); precious metals are of a similar size.
- In 2016, 52 percent of the total value of all consumer transactions in South Africa were conducted in cash.
- Widely quoted but unsubstantiated claim: around 20 percent of GDP is lost to corruption. The NRA focuses on 20-25 percent of government procurement being lost annually; equivalent to about $6 billion.
- South Africa scores 56.7 in the World Bank Control of Corruption Index; below the FATF average (76.7) albeit better than other ESAAMLG members (39.5).

### Structural elements and institutions
- South Africa has a stable political system and has demonstrated commitment to implementing AML/CFT systems involving close cooperation and coordination between various government departments and agencies.
- The Inter-Departmental Committee (IDC), created in November 2018, coordinates AML/CFT matters at the national level; National Treasury (NT) is Chair and Secretariat.
- Ministries and responsibilities:
  - Ministry of Finance and National Treasury (NT): Finance Minister responsible for AML policy measures and issues; supported by the FIC (FIU) which reports directly to the Minister; NT receives FIC’s annual performance plans and recommends FIC’s budget allocations; Minister approves companies to act as ADLAs but delegated to SARB:FinSurv.
  - Minister of Police: responsible for the POCDATARA and CFT policy matters covered by that Act.
  - Department of Justice and Constitutional Development (DoJ&CD): responsible for the NPA and central authority for MLA and extradition matters.
  - Department of International Relations and Cooperation (DIRCO): participates in UN and global fora, facilitates MLA and international technical assistance; hosts Inter-Departmental Working Group on Counter Terrorism (IDWG-CT).
- Criminal justice and operational agencies:
  - Financial Intelligence Centre (FIC) is South Africa’s FIU; supports and guides supervisors on AML/CFT compliance, supervises some AIs and reporting institutions (RIs), and assists the Minister of Finance with advice on AML/CFT policy matters.

### Background, contextual factors, and strategy
- System is a work in progress following recent amendments to AML/CFT coordination and institutional structures.
- Since the last ME, South Africa experienced a prolonged period of corruption ("State capture") generating large amounts of corruption-related proceeds and undermining integrity and capacity of some key AML/CFT agencies.
- Financial exclusion: a large portion of population unbanked or with limited banking access; sizeable informal economy that uses cash. World Bank Global Findex suggests 67 percent of South Africans have an account at an FI, compared to 73 percent for upper middle-income countries. The FinScope survey uses 90 percent and estimates up to 45 percent use informal financial services.
- South Africa does not have a formal AML/CFT strategy. In 2017 NT and the FIC jointly issued a consultation paper that set policy priorities including:
  - strengthening AML/CFT through a more consultative approach based on partnerships between public and private sectors;
  - improving coordination and collaboration for more effective preventive measures and enforcement;
  - a more customer-friendly and less-costly approach to AML/CFT implementation;
  - supporting measures: increased CDD obligations (including for domestic PEPs), increased BO transparency, introducing UNSCR asset freezing, and improved information sharing and enforcement by supervisory bodies.

*Source: SOUTH AFRICA — INTERNATIONAL MONETARY FUND (1zafea2021001).*

### 82.      The South African Police Service (SAPS) is responsible for investigating ML cases and

### The South African Police Service (SAPS) is responsible for investigating ML cases and offenses pertaining to terrorism.

### Law enforcement structure and capacities
- SAPS houses the Directorate for Priority Crimes Investigations (SAPS:DPCI), also known as the Hawks, with overall responsibility for combating, investigating, and preventing national priority crimes such as serious organized crime, serious commercial crime, serious corruption, and related ML.
- SAPS:DPCI has a staff complement of approximately 2,500 members, although recent budget allocations by the NT have provided for a significant increase in staffing and resources going forward.
- SAPS:DPCI components:
  - Priority Crime Management Centre (SAPS:DPCI – PCMC): collects, monitors and analyzes information and intelligence on identified National Priority threats for the production of tactical and strategic analysis products, and research for threat assessments and forecasting.
  - Priority Crime Specialized Investigation (SAPS:DPCI – PCSI): provides specialized support to units that investigate predicate crime through specialized technology and assistance with cybercrime, ML, asset forfeiture, financial investigations and forensic investigation services.
  - Crimes Against the State (SAPS:DPCI – CATS): focuses on terrorism and TF.

### Other investigative and prosecutorial bodies
- Special Investigating Unit (SIU):
  - Deals with fraud, corruption, and serious maladministration in state institutions.
  - Conducts forensic investigations and institutes civil litigation to recover state assets or public money.
  - Refers some cases to the SAPS for criminal investigation.
- National Prosecuting Authority (NPA) and components:
  - National Prosecuting Services (NPA:NPS) institutes criminal proceedings on behalf of the State.
  - Specialized Commercial Crime Unit (NPA:SCCU): guides investigations into and prosecutes serious commercial and corruption cases, including ML.
  - Organized Crime Component, Head Office, NPS: manages, assists, and supports ML prosecutions in the regions; regional DPP offices prosecute ML cases arising from organized crime investigations.
  - Priority Crimes Litigation Unit (NPA:PCLU): manages and directs investigations into and prosecutes all offenses under the POCDATARA (including TF), non-proliferation offenses, and other serious crimes impacting State security.
  - Specialized Tax Unit: guides investigations into and prosecutes tax cases, including ML.
  - Asset Forfeiture Unit (NPA:AFU): implements freezing and forfeiture provisions in respect of the proceeds and instrumentalities of crime, and freezing obligations created under UNSCRs 1267 and 1373.
  - Investigative Directorate (NPA:ID): proclaimed by the President on April 4, 2019; has special investigative powers to address serious and complex economic crimes with a focus on crimes detected by the Commissions of Inquiry into State Capture (Zondo Commission), the Public Investment Corporation (PIC), and the SARS; mandated to investigate and prosecute statutory offenses including contraventions of, inter alia, the POCA and the FIC Act.

### Other state agencies relevant to AML/CFT
- South African Revenue Service (SARS):
  - Tax and customs authority; involved in controlling movement of people and goods across the border (along with SAPS and the National Immigration Branch of DHA).
  - Investigates tax offenses (tax evasion is a predicate offense to ML); related ML investigations must be investigated by the SAPS.
- State Security Agency (SSA):
  - Responsible for domestic and foreign intelligence and counter-intelligence security.
  - Coordinates all counterterrorism and TF investigations as chair of the CTFC.

### Financial sector competent authorities and oversight
- Monetary authority: South African Reserve Bank (SARB) and the MoF.
- SARB units relevant to AML/CFT:
  - Prudential Authority (SARB:PA): licenses and supervises banks and life insurers for compliance with the FIC Act.
  - Financial Surveillance Department (SARB:FinSurv): licenses and supervises ADLAs (including branches) for compliance with the FIC Act.
  - National Payment System Department (SARB:NPSD): responsible for supervising banks for compliance with rules for wire transfers; responsibilities delegated in practice to SARB:PA.
- Financial Sector Conduct Authority (FSCA): independent regulator supervising financial advisors and intermediaries, securities investment managers, CISs, and exchanges for compliance with the FIC Act.

### DNFBP, legal persons, and NPO competent authorities
- DNFBP/SRB oversight:
  - National Gambling Board (NGB): umbrella regulator for nine Provincial Licensing Authorities (PLAs).
  - Provincial Licensing Authorities (PLAs): issue gambling licenses, regulate casinos, ensure compliance with the FIC Act in provinces.
  - Estate Agency Affairs Board (EAAB): statutory regulator for estate agents; monitors compliance with the FIC Act.
  - Legal Practice Council (LPC): statutory body regulating attorneys; SRB overseeing compliance with the FIC Act.
  - Independent Regulatory Board for Auditors: registers auditors in public practice; SRB monitoring compliance with the FIC Act.
- Company and trust oversight:
  - Companies and Intellectual Property Commission (CIPC): registers companies, close corporations, and co-operatives.
  - Master of the High Court (Master): receives trust instruments, registers inter-vivos trust instruments, approves appointment of trustee(s) pursuant to the Trust Property Control Act (1988) (TPC Act).
- Non-profit organizations:
  - Department of Social Development (DSD): administers the Non-profit Organisations Act (1997) (NPO Act); NPO Directorate monitors compliance; registration is voluntary.

### Financial sector, market structure, and key statistics (as presented)
- Banking sector concentration and assets:
  - Five financial groups shaped around ABSA Bank, FirstRand Bank, Nedbank, Standard Bank, and Investec Ltd dominate the banking sector.
  - As at March 31, 2019, they held around 90 percent of total banking assets.
  - Some medium large banks have extensive reach; one caters to in excess of 10 million retail customers.
- Securities and asset management:
  - Securities sector market capitalization around 3.4 times banking assets.
  - AuM by FSPs: R9,100 billion ($618.8 million).
  - AuM by CIS managers: R2,300 billion ($156.4 million).
  - AuM by Authorized Users (AUs): R1,376 billion ($93.6 million).
- Life insurers:
  - Assets held by life insurers represent seven percent (R2.8 trillion or $190.4 billion) of South Africa’s financial assets.
- Public financial institutions of note:
  - Postbank (SAPO banking division) and Ithala SOC Limited (ISOC) operate under exemptions to provide banking services without a license.
- FinTech and VASP coverage:
  - More than 200 entities known as “Financial Technology (FinTech) companies”; not all fall within FATF definition of FIs; some licensed as FSPs and subject to AML/CFT obligations but many are not.
  - VASPs: legal and regulatory framework application remains to be clarified.

### Financial institutions and DNFBPs (selected figures from March 2019 data)
- Banks: 34 licensed; Total Assets 5,517.00 (R billion, end 2018); Total Assets ($ billion, end 2018) 385.55; AML/CFT supervisor SARB:PA.
- Mutual banks: 4 licensed; Total Assets 3.13 (R billion); Total Assets ($ billion) 0.22; AML/CFT supervisor SARB:PA.
- ISOC: 1 licensed; Total Assets 0.70 (R billion); Total Assets ($ billion) 0.05; AML/CFT supervisor FIC.
- Postbank: 1 licensed; Total Assets 3.50 (R billion); Total Assets ($ billion) 0.26; AML/CFT supervisor FIC.
- Development Bank of South Africa: 1 licensed; Total Assets 89.21 (R billion); Total Assets ($ billion) 5.85; AML/CFT supervisor FSCA/FIC.
- Land Bank South Africa: 1 licensed; Total Assets 50.42 (R billion); Total Assets ($ billion) 3.30; AML/CFT supervisor FSCA/FIC.
- ADLA: 19 licensed; Total Assets 0.67 (R billion); Total Assets ($ billion) 0.04; AML/CFT supervisor SARB:FinSurv.
- CIS managers: 55 licensed; Total Assets (AuM) 2,300.00 (R billion); Total Assets ($ billion) 159.00; AML/CFT supervisor FSCA.
- FSP Cat. II (Discretionary Investment Managers): 670 licensed; Total Assets (AuM) 9,100.00 (R billion); Total Assets ($ billion) 631.00; AML/CFT supervisor FSCA.
- Life insurance companies: 78 licensed; Total Assets 2 789.00 (R billion); Total Assets ($ billion) 193.84; AML/CFT supervisor SARB:PA.
- Casinos: 39 licensed; gross gambling revenue (GGR) around R18.6 billion ($1.3 billion); casinos account for 60 percent of GGR versus other gambling modes; provincial GGR shares: Gauteng 41 percent, KwaZulu-Natal 18 percent, Western Cape 17 percent.
- Estate agents: 44,874 licensed/registered.
- Attorneys (practicing only, including notaries): 19,119 licensed/registered.
- Accountants: 9,928 licensed/registered.
- Auditors: 4,152 licensed/registered.
- Trust Service Providers (TSPs): estimated 300; 74 registered with the FIC.

### Virtual Asset Service Providers (VASPs) and crypto market observations
- Scale and market concentration:
  - 12 crypto-asset trading platforms identified as at 2019.
  - Crypto-asset trading volumes about 1.4 percent of all trading on the Johannesburg Stock Exchange (JSE); alternative exchanges trading volume about 0.002 percent in 2018.
  - Largest three platforms control around 80-90 percent of the market; hold AuM of around R6.5 billion ($442 million, or around 0.05 percent of all AuM).
  - Largest platform controls around 65 percent of the market and trades for around R125 million ($8.5 million) per day.
- User base and trading patterns:
  - Most traders on domestic crypto-asset trading platforms are local citizens (about 86 percent in 2017).
  - Approximately 800,000 South African citizens registered with the three largest exchanges.
  - Foreign investor share of trades on domestic platforms increased from two percent in 2017 to 14 percent in 2018.
  - Four crypto-ATMs present but rarely used.
  - Bitcoin is dominant (80 percent of the market) among crypto-assets traded and stored on the three largest exchanges.
  - There are also providers of payment services in VA.
- Risk-based importance for AML/CFT supervision:
  - Assessment team assigned highest importance to banks, followed by attorneys and estate agents.
  - Medium importance: ADLAs, FSPs category II (asset managers), CIS managers, casinos, TSPs, and VASPs.
  - Less importance: life insurers and FSP category I (financial advisors).
  - Little to no weighting given to sectors outside FATF scope, including MVDs.

### Preventive measures, legal framework, and guidance
- FIC Act:
  - Provides legal basis for financial sector regulation and supervision and sets out basic AML/CFT obligations of AIs and RIs.
  - Significantly amended in 2017; amendments came into force in April 2019.
  - Amended Act provides for a RBA to CDD and a requirement for business risk assessments within the private sector.
  - Amendments include full range of CDD measures: understanding and obtaining information about the client, ongoing due diligence, PEPs, beneficial ownership, and record keeping.
  - Several previous exemptions from preventive measures regime were removed, though some FIs and DNFBPs remain outside the scope; these exemptions are not justified by risk assessments.
  - Based on identified risk, South Africa has applied reporting obligations on MVDs.
- FIC Guidance Note 7 (GN7):
  - Provides guidance to AIs on implementation of the FIC Act.
  - GN7 is an enforceable means under the FATF Recommendations; requires each AI to follow the guidance or demonstrate achieving an equal level of compliance.
  - Enforcement action may result from non-compliance where an AI has not followed GN7.
  - GN7 issued by the FIC in collaboration with the NT, the SARB and FSB (predecessor to the FSCA).
- Banking regulations:
  - Regulations relating to banks issued by the Minister of Finance in 2012 and are enforceable (Banks Act, s.90).
  - Regulation 36(17) is of importance regarding CBRs, covering all ‘banks and controlling companies in respect of a bank’, as defined by the Banks Act (s.1).

*Italic: Source — Excerpt from IMF country report content unit 1zafea2021001 (South Africa).*

### 105.      To implement a recommended action from the previous MER on R.16, the SARB issued

### 1zafea2021001 - 105.

### Legal Persons and Arrangements
- Companies Act of 2008: provides for the incorporation, registration, organization and management of companies and the capitalization of profit companies; repealed the Companies Act of 1973.
- CIPC: registers, monitors, supervises, and enforces compliance by legal persons with the Companies Act.
- Types of legal persons:
  - For-profit companies (five main types): (i) private companies; (ii) personal liability companies (also known as incorporated companies); (iii) State-owned companies; (iv) public companies; and (v) external for-profit companies.
  - Not for profit companies: (i) not for profit without members’ companies; (ii) not for profit with members’ companies; and (iii) external not for profit companies.
  - Close corporations: exist under the previous Companies Act (no new close corporations may be formed); do not have share capital; members have percentage interest; members can only be natural persons (a trustee of a trust may be a member in some circumstances); no directors.
  - Co-operatives: autonomous associations of persons (a minimum of five) organized and operated on co-operative principles.
  - Foreign companies on the register: companies created in other jurisdictions that choose to also register in South Africa.
- Quantities and registers:
  - Around 2.1 million legal persons in South Africa.
  - Around 400 thousand new companies are formed and roughly the same amount struck off the register each year.
  - Approximately 10 million directors with around 2.5 million of those being foreign directors.
- Company statistics (as at June 14, 2019; Source: CIPC, June 14, 2019):
  - Private companies: 1,509,814
  - Public companies: 1,986
  - Close Corporations: 355,073
  - Non-Profit organizations: 48,068
  - Personal liability companies: 14 660
  - Foreign companies with South African presence: 1,748
  - Primary co-operatives: 158,867
  - Secondary co-operatives: 1,188
  - Tertiary co-operatives: 84
  - Total: 2,091,488

- Trusts (Legal Arrangements):
  - Only legal arrangements recognized under South African law are trusts; regulated under the Trust Property Control Act, 1988.
  - Three types of trusts: inter-vivos trusts; testamentary trusts; community trusts.
  - Trusts are registered with, and trustees appointed by, the Master.
  - There were 180,159 trusts on the electronic register at the end of 2018 (representing those registered since 2008); records of trusts established before 2008 exist in paper form only.
  - Trust registrations declining due to limiting tax legislation: around 15 thousand registered per year over 2012 to 2019.
  - Trusts registered annually with Master of High Court, 2012–2019 (Source: Master of High Court):
    - 2012: 18,549
    - 2013: 16,374
    - 2014: 17,523
    - 2015: 17,442
    - 2016: 15,814
    - 2017: 12,850
    - 2018: 12,316
    - 2019: 11,558
    - Average: 15,303
  - Cross-border trust treatment:
    - A trust established by a person outside South Africa in respect of property located in South Africa will be subject to South African trust law.
    - A person outside South Africa appointed as trustee in respect of trust property in South Africa may be authorized as a trustee by the Master only in respect of that property.
    - The Master has no powers over trusts created outside South Africa nor may foreign trusts be registered.
    - Trusts created outside South Africa by South African citizens or residents with property in such countries are outside the scope of the Master.
    - The Master’s Office shares all information in its data base with the SARS for tax assessment and investigation of tax crime purposes.

### Supervisory Arrangements
- AML/CFT supervision: responsibility of various sector supervisory bodies, including SRBs in the DNFBP sectors; where there is no supervisor or SRB, the FIC; the FIC is responsible for national supervisory coordination.
- Twin peaks supervisory model (implemented in 2018):
  - SARB:PA: supervises deposit-taking institutions licensed under the Bank Act.
  - FSCA: supervises other financial sector institutions.
  - Supervision of the life insurance sector, including AML/CFT, was delegated by the FSCA to the SARB:PA via an MOU in 2018.
  - Supervision of banks’ compliance with wire transfer rules: conducted by the SARB:PA in consultation with the SARB:NPSD (responsible for overseeing the NPS including rules for wire transfers).
  - Cross-border MVTS activities: supervised by the SARB:FinSurv (also responsible for ensuring compliance with foreign exchange control regulations).
  - Postbank and ISOC: engage in deposit-taking activities under an exemption from being licensed as a bank and thus are not supervised for AML/CFT by the SARB:PA, but by the FIC. (As of the onsite, Postbank was in the process of applying for a banking license.)
  - The FIC and the SARB:NPSD jointly supervise SAPO’s compliance with wire transfer rules.
- DNFBP supervision:
  - Covered DNFBP sectors are supervised or monitored by their respective supervisors, except:
    - TSPs and KRDs are under the supervision of the FIC for their obligations as AIs and RIs respectively.
    - Accountants and auditors that are licensed as FSPs are supervised by the FSCA.
    - FIC supervises MVDs for their obligations as RIs.
- VASPs:
  - VASPs are not subject to AML/CFT obligations other than the reporting obligations that apply to all businesses and are not subject to AML/CFT supervision.
  - Some VASPs have voluntarily registered with the FIC.

### International Cooperation
- South Africa: regional and continental hub with large financial flows from other African jurisdictions as well as Europe and North America.
- Recent cases of “State capture” highlighted risks of proceeds of corruption and other financial crimes being laundered abroad.
- Most information exchange occurs with countries in Europe and Africa; major international cooperation countries include the United States, Botswana, and Germany.
- Feedback from 15 countries on international cooperation: generally positive but noted that provision of assistance can be slow on the part of the South African authorities (based on analysis of the latest available detailed data on MLA requests).
- Formal MLA requests may be directed via the DIRCO or the MoJ and NPA; informal cooperation achieved through these central channels as well as on an agency-to-agency basis.

### National AML/CFT Policies and Coordination — Key Findings and Recommended Actions
Key Findings
- Corruption, tax related crimes and fraud, are understood as the main domestic ML threats consistently by the key AML/CFT authorities but the understanding of the relative scale of such threats as well as the vulnerabilities or channels exploited to launder the proceeds is limited.
- The threats arising from proceeds of foreign predicates is understood only to a very limited extent.
- The authorities’ understanding of TF risks is underdeveloped and uneven.
- South Africa is yet to develop coordinated and holistic national AML/CFT policies informed by ML/TF risks.
- Some ML risks are mitigated by existing policies or measures but significant risks remain largely unaddressed for beneficial owners of legal persons and trusts, cross-border movement of cash, and criminal justice efforts are not yet directed towards effectively combating higher risks such as ML related to corruption, narcotics, and tax offenses.
- Efforts at the policy level have been focused mainly on terrorism and are yet to target TF risks.
- Some sectors (including VASPs and potential high-risk DNFBPs) are not yet captured by the AML/CFT regime and their risks are not yet assessed.
- Simplified measures are often not justified by proven low risks.
- The extent to which the competent authorities’ priorities and objectives are aligned with national ML risks and policies is uneven, with the LEAs and the NPA focusing more on predicate crimes than on ML and supervisors at varying stages in applying an RBA to AML/CFT supervision.
- The IDC on AML/CFT, the policy coordinating body, plays a central role in coordinating the ML NRA and TF NRA but excludes some stakeholders and is yet to generate any AML/CFT policy initiatives at the strategic level.
- Coordination and cooperation at the operational level works well in general but the often-formal nature sometimes prolongs the process.

Recommended Actions
- Improve understanding of the major proceeds generating crimes, including those committed in a foreign country and channels and vulnerabilities exploited to launder these proceeds.
- Improve and harmonize understanding of TF risks including by completing the TF NRA to inform policies to prevent and combat TF.
- Develop national AML/CFT policies to address higher risks for:
  - (i) BO;
  - (ii) use of cash and its cross-border movement physically and through illegal MVTS;
  - (iii) third-party ML;
  - (iv) foreign predicate crimes; and
  - (v) TF, including by fully integrating it into the NCTS.
- Ensure all FIs, DNFBPs and VASPs (unless they are assessed as posing a proven low risk), in particular those with potentially higher risk such as DPMS and CSPs, are subject to AML/CFT obligations and supervision or monitoring.
- Ensure the key AML/CFT agencies’ priorities, objectives, and performance targets are aligned with ML/TF risks identified and national AML/CFT policies, particularly to ensure that LEAs focus on significant ML.
- Review the composition and structure of the IDC on AML/CFT to ensure it is:
  - (i) inclusive of all stakeholders including DNFBP supervisors; and
  - (ii) able to drive policy making in both the Financial Cluster and the JCPS cluster.
- Put in place mechanisms for cooperating and coordinating to combat the PF of weapons of mass destruction.
- Share the findings of the ML NRA and TF NRA, upon their conclusion, to all private sectors subject to AML/CFT obligations.

- The relevant Immediate Outcome considered and assessed in this chapter is IO.1. The Recommendations relevant for the assessment of effectiveness under this section are R.1, 2, 33 and 34, and elements of R.15.

### Immediate Outcome 1 (Risk, Policy and Coordination) — Country’s Understanding of its ML/TF risks
- ML NRA process:
  - South Africa is in the process of concluding its first coordinated assessment of ML/TF risks at the national level.
  - ML NRA exercise coordinated by an AML/CFT NRA Inter-Departmental Working Group (NRA IWG); involves major public sector stakeholders but excludes some stakeholders, notably regulators of DNFBPs (some were only invited to comment on a draft report late in the process).
  - Financial sectors’ inputs sought through supervisors and reflected in various SRAs, which fed into the NRA.
  - Some casinos, attorneys, and TSPs participated in SRAs conducted by the FIC by responding to surveys.
  - NRA takes a primarily qualitative approach and relies on experts’ judgement and SRAs, complemented by open source information.
  - Preliminary finding documents on ML and TF were completed in July and August 2019 respectively. They also intend to extend the NRA exercises to cover PF.
- Understanding of main domestic ML threats:
  - Main domestic ML threats consistently understood to include corruption, tax related crimes, and fraud.
  - Authorities’ understanding of the relative scale of such threats is questionable; basis for considering threats high-risk often centered on impact rather than scale of proceeds.
  - Corruption identified as a main concern for its role as an “enabler” of other predicate offenses and ML, including by undermining some key AML/CFT agencies, less so for the scale of proceeds generated (authorities indicated proceeds from corruption not as high as that of tax crimes or drug trafficking; the basis of this assertion is unclear).
  - VAT fraud highlighted as a main tax-related offense; evasion of income taxes also recognized as a concern.
- Knowledge of laundering channels and vulnerabilities:
  - Some vulnerabilities or channels exploited to launder proceeds of domestic predicates identified, in particular use of cash.
  - Authorities’ understanding of more sophisticated ML schemes is limited.
  - During the onsite, authorities indicated proceeds that stay within South Africa are mainly used to support luxurious lifestyles by purchasing real estate, motor vehicles etc., often through corporate structures or trusts.
  - Noted cross-border laundering methods: cash smuggling, trade-based schemes (e.g., mis-invoicing), wire transfers, and overseas cash withdrawal using bank cards.
  - Authorities lack a full appreciation of sector vulnerabilities (e.g., types of corporate structures most misused, role of enablers, geographic regions or corridors most exposed to cash smuggling or trade-based schemes, foreign jurisdictions where proceeds end up).
  - Dubai and China mentioned in a few recent cases.
  - Low number of cases for significant or sophisticated ML or main proceeds generating predicate offenses (such as corruption) hampers efforts to build understanding.
- Sectoral risk understanding:
  - Banks consistently considered most exposed to ML risks; banks are rated medium- to high-risk in the SRA.
  - Disconnect exists between authorities’ understanding of sector ML vulnerabilities in other sectors and known ML typologies.
  - SRAs produced risk ratings that do not appear aligned with known typologies (example: gambling entities rated high-risk though only one known ML case involves a casino).
  - Real estate, motor vehicles, and corporate structures often involved in known ML cases, but this knowledge does not seem to feed into SRAs.
  - Attorneys and estate agents rated medium risk.
  - Some DNFBP supervisors were not involved in analysis and do not agree with SRA ratings for sectors under their purview.
  - Potential ML/TF risk exposure of unregulated sectors not yet covered under AML/CFT regime is largely unknown (including DPMS, CSPs that are not attorneys, accountants for activities other than providing financial services, and VASPs).
- Foreign predicates and TF:
  - Authorities could not demonstrate an understanding of threats from foreign predicates or vulnerabilities exploited to launder the proceeds.
  - Preliminary ML NRA findings noted South Africa’s financial system (particularly banks) is a gateway for funds flowing from the rest of sub-Saharan Africa to the rest of the world, including potential foreign proceeds such as corruption.
  - None of the main AML/CFT agencies appear to recognize or prioritize foreign proceeds of crime; NRA IWG acknowledges understanding of such risks needs improvement at the national level.
  - TF understanding constrained by narrow approach: prior to TF NRA, TF issues viewed primarily through lens of terrorism that potentially targets South Africa (perceived low risk).
  - TF NRA preliminary findings identify potential threats associated with FTFs and foreign terrorist groups using South Africa as transit point and planning base, but authorities considered TF threats low based on lack of established evidence.
  - Authorities’ low-risk conclusion for TF is based on known intelligence that is incomplete and lacks in-depth understanding of vulnerabilities.
  - Authorities reluctant to classify politically motivated violent acts as terrorism, further narrowing evidence base for TF assessment.

*Source: 1zafea2021001 - 105.*

### 127.      Authorities have expressed concern about some high-level vulnerabilities that could

### 127.      Authorities have expressed concern about some high-level vulnerabilities that could

### High‑level vulnerabilities and authorities’ insights
- Authorities identified vulnerabilities that could be exploited for TF but were unable to determine if, or to what extent, such exploitation is occurring.
- Identified vulnerabilities include:
  - weak border controls for money and people
  - informal remittances from émigré communities to their home countries
  - NPOs
  - potential links between terrorist groups and organized crime
  - new financial technologies such as VAs and crowd funding
- Many vulnerabilities were identified on the basis of potential exploitation of the AML/CFT system by terrorist groups.
- Authorities did not share insights with assessors on how these vulnerabilities may be exploited to fund the agendas of international or domestic terrorists.

### Understanding of sector vulnerabilities and risk assessments
- Authorities’ understanding of sector vulnerabilities related to TF is poor.
- None of the SRAs differentiate between ML and TF vulnerabilities or address TF risks specifically; nor do they inform the TF NRA.
- Across all sectors, supervisors were not involved in the TF NRA and show a very limited understanding of TF risks, if any, largely seeing TF issues only in the context of ensuring compliance with TFS obligations.

### VASPs and virtual assets (VAs)
- South Africa recognizes the potential ML/TF risks of VASPs and has taken initial steps to identify them but is yet to develop a full-fledged understanding of such risks.
- SARB issued a Position Paper on Virtual Currencies in 2014 drawing from FATF and EU findings on ML/TF risks of VASPs.
- ML and TF NRAs reflected some VASP risks; VASPs are often considered high-risk customers by banks because they are not regulated.
- Inherent ML risks of VASPs are yet to be assessed; evidence suggests VASPs and VAs are exposed to abuse through some predicate crimes, in particular fraud.
- The TF NRA considers VASPs to be increasingly susceptible to TF based on a few known cases while specific vulnerabilities have not been identified.
- Inter-Governmental FinTech Working Group (IFWG) has taken steps to take stock of the VA market and issued a consultation paper recognizing generic risks of VA misuse for ML or TF.
- The authorities have prepared a legislative proposal to subject VASPs to AML/CFT obligations.

### Recognized weaknesses in the AML/CFT regime
- Broad consensus that a relatively low number of ML prosecutions and convictions represents the weakest aspect of the regime; LEAs were significantly affected in the past decade by “State capture”.
- Limited number of cases hampers understanding of risks.
- Authorities recognize gaps in sector coverage and lack of transparency of BO information as deficiencies.
- Generic challenges identified: domestic coordination, international cooperation, resources, and capacity constraints.

### National policies and measures (selected)
- South Africa amended the FIC Act in 2017 to close some gaps and provide for a RBA to preventive measures, but some higher-risk activities are yet to be covered.
- Measures to promote financial inclusion implemented; no specific policies to reduce cash use to mitigate ML risks (e.g., limiting use of cash in large-value transactions such as purchasing real estate).
- CTRs introduced in 2010: AIs and RIs must report cash transactions over R24,999.99 ($1,700). Over 150,000 CTRs have been used over the past six years in FIC disclosures to LEAs.
- MVDs were brought into the AML/CFT regime as RIs in 2001 and have been actively overseen by the FIC.

### Significant ML/TF risks remaining unaddressed
- Measures to combat corruption and other serious crimes are yet to address laundering of proceeds; SAPS:DPCI and ACTT efforts are not yet directed effectively towards ML related to serious crimes.
- Deficient legal definition of domestic PEPs undermines targeting of proceeds of corruption.
- Policies lacking to access accurate and up-to-date beneficial ownership information for legal persons and trusts; supervisory efforts not targeted towards company and trust service providers (e.g., attorneys and TSPs).
- Potentially high-risk sectors (CSPs which are not attorneys, and DPMS) remain out of the regime.
- Cross-border movement of cash risks largely unaddressed, especially between South Africa and other members of the CMA; controls focused mainly on airports and outflows; SARS:Customs lacks sufficient systems and staff to enforce controls.
- Identifying and sanctioning illegal MVTS is not pursued collaboratively as a policy objective; efforts limited and fragmented, focused on large-size outflows rather than smaller illegal networks.
- Proceeds of foreign predicate crimes not being proactively targeted by LEAs due to lack of understanding; supervisory activities for South African banks’ operations in SADC are not risk driven; other sectors like estate agents lack commensurate supervisory attention.
- Authorities were challenged to show proactive TF risk addressing: NCTS addresses TF only to the extent of recognizing the need to (i) regulate financial sector to mitigate risks from domestic extremism and international terrorism and (ii) make financial investigation integral to terrorism investigations. Implementation Plan assigns strengthening financial investigation capacity to the FIC rather than LEAs; progress not provided to assessors.
- NIE compiled by NICOC annually includes FIC inputs on TF risks, but assessors were not able to verify.

### Exemptions, enhanced, and simplified measures
- Sector coverage exclusions (not based on risks): CFIs, credit providers other than money lenders against securities, FinTech companies (offering financial services and not VASPs or FSPs), VASPs, DPMS, accountants (for activities other than providing financial services), and CSPs other than attorneys are not subject to AML/CFT obligations except the general requirement to file STRs and are not subject to supervision or monitoring.
- Since NRAs and SRAs are yet to be concluded, risk assessment results are not used to inform enhanced and simplified measures.
- GN7 suggests non-binding indicators to help AIs assess ML/TF risks but is fairly generic and only points to a few specific high-risk factors (e.g., domestic PEPs and cash use).
- Private sector has broad discretion to define high- and low-risk scenarios and measures; AIs can take simplified measures even when suspicion exists or when the AI does not adequately understand its ML/TF risks.
- Deficiencies in AIs’ risk assessments mean scenarios and measures are often not supported by proper risk assessments.

### Objectives and activities of competent authorities
- National policies are yet to direct setting of AML/CFT objectives and allocation of resources; objectives and activities of key agencies vary in alignment with ML/TF risks.
- NPA and LEAs focused mainly on predicate offenses rather than ML or TF; NPA’s Strategic Plan 2013-2018 recognized ML as an “emerging crime” but did not elaborate priority or significance.
- NPA:AFU performance measured by “value of completed forfeiture cases”; case evaluation criteria were not shared with assessors.
- SAPS:DPCI – FAFI identified improving financial and asset forfeiture investigations as a 2015–2019 priority, but SAPS:DPCI emphasis placed on predicate offense investigation rather than ML networks and professional enablers.
- NPA’s ML prosecutions focused mainly on self-laundering with no prosecutions of third-party ML; little attention to ML from foreign predicate offenses.
- Some KPIs may encourage undue focus on small/simple cases rather than complex/high-risk ML/TF activities (e.g., NPA target: convictions for more than 90 percent of prosecutions undertaken; SAPS:DPCI expected to deliver case ready files for 90 percent of ML investigations undertaken).
- CFTC coordinates SAPS and NPA TF investigations; very few TF cases investigated.
- FIC gives priority to transactions involving the state or SOEs, but disclosures related to corruption constitute 4 percent of total proactive disclosures; disclosures related to fraud and tax evasion constitute 27 percent and 23 percent respectively.
- Proactive disclosures labelled ML constitute 24 percent and TF 15 percent; underlying predicate crimes not specified.
- Supervisors vary in applying RBA: SARB:PA most advanced, followed by SARB:FinSurv; FSCA yet to apply an RBA to AML/CFT supervision specifically.
- FIC supervisory activities primarily driven by promoting registration and filing of CTRs, with little regard to other risk aspects.
- Thematic inspections by supervisors limited to SARB:PA and SARB:FinSurv on TFS.

### Targeting of high‑risk areas and operational gaps
- Authorities’ objectives and activities are not effectively oriented to target high ML risks posed by foreign proceeds entering/flowing through South Africa, cash and cross-border physical movement, or risks associated with illegal MVTS.
- Very little activity by key agencies directed towards risks from foreign proceeds of crime.
- SARB:FinSurv makes some efforts to uncover illegal cross-border MVTS but not as a high priority; SAPS did not follow up to sanction/shut down illegal operators.
- SARS focuses mainly on outwards cash movement at main airports.

### National coordination and cooperation
- IDC on AML/CFT (advisory committee) established November 2017 to understand and mitigate ML/TF risks but does not involve all stakeholders; notably excludes DNFBP supervisors.
- NPO Directorate part of IDC structure did not attend IDC meetings; NPOTT established 2018 to coordinate NPO risk assessment.
- CIPC invited to an IDC meeting only in May 2019.
- DNFBP supervisors, NPO Directorate, and CIPC were not involved in the ML NRA or TF NRA; some DNFBP supervisors disagreed with preliminary findings and expressed concern about proposal to shift supervisory responsibilities to the FIC.
- IDC coordinates the NRAs but has yet to generate AML/CFT policy initiatives at strategic level; IDC’s agenda driven mainly by financial regulatory issues and preparation for the assessment.
- IDC chaired by NT (Financial Cluster); law enforcement and judicial aspects fall under JCPS cluster but no discussions have taken place on their AML/CFT work.
- AML/CFT issues considered in policy development for some NT-led regulatory issues (e.g., IFWG Consultation Paper on Policy Proposals for Crypto Assets; consultation paper on financial inclusion), but TF covered only to a limited extent.
- Operational cooperation generally works well though some stakeholders are excluded and cooperation often relies on MOUs:
  - ML investigations/prosecutions: mechanisms (ACTT, IFFTT, SAMLIT) exist but not sufficiently used to pursue ML; SAMLIT aims to enable public-private collaboration between FIC, SARB:PA, and banks.
  - TF investigations/prosecutions/prevention: CFTC works effectively; every terrorism-related inquiry involves a TF component worked on by the FIC, but TF is not being proactively identified and pursued. IDWG-CT oversees UNSCR-related reporting and implementation but does not include regulators responsible for TFS oversight by FIs and DNFBPs.
  - Supervision: cooperation between FIC and supervisors appears strong (FIC provides inputs and supports onsite inspections), except LPC has not carried out AML/CFT oversight. Cooperation weaker in developing sector-specific guidance to help private sector implement RBA. SARB:PA and FSCA cooperate at licensing stage but no evidence of AML/CFT supervisory collaboration for banking, life insurance, and securities institutions within the same group.

*Source: 1zafea2021001 - 127.*

### 143.      Coordination on PF remains fragmented and takes place at different levels through

### Coordination on PF remains fragmented and takes place at different levels through

### Coordination and institutional framework
- Coordination on PF remains fragmented and takes place at different levels through IDCs which focus on proliferation rather than PF.
- The South Africa Council for the Non-Proliferation (NPC) of Weapons of Mass Destruction (WMD) is the main coordinating body focused on export controls of dual goods and nuclear items.
- Formal coordination among authorities on PF is still at its early stage and is lacking a more integrated and holistic approach.
- The authorities intend to extend the IDC’s mandate to PF.

### Private sector’s awareness of risks
- Authorities intend to publish sanitized versions of the ML NRA and TF NRA upon their conclusion.
- A high-level summary of the preliminary findings of ML NRA has been shared with representatives of some private sectors in a few workshops; preliminary findings of TF NRA have not been shared with the private sector.
- The SARB:PA and the FSCA have shared the SRAs or their high-level summaries with some entities and intend to publish the SRAs.
- SRAs of DNFBPs have not been shared with the private sector; preparation of some SRAs involved the private sector only to a limited extent.
- Sectors not yet covered have not been shared with any information of the NRAs.

### Overall conclusion on IO.1
- Authorities have demonstrated understanding of domestic ML threats, including those related to corruption, and associated vulnerabilities to some extent, while understanding of TF risks has been limited.
- Lack of understanding of ML risks arising from foreign proceeds is a concern given South Africa is a regional financial hub.
- The country is yet to develop and implement national policies to address its ML/TF risks, preventing AML/CFT agencies from setting objectives and aligning activities with national priorities.
- Operational AML/CFT cooperation and coordination works relatively well but the IDC, the policy coordinating mechanism, excludes some stakeholders and is yet to generate any AML/CFT policy initiatives at the strategic level.
- Concern exists regarding the IDC’s ability to drive or influence policy making within the JCPS cluster.
- South Africa is rated as having a moderate level of effectiveness for IO.1.

### Key findings — Immediate Outcomes 6–8 (selected)
- Immediate Outcome 6 (Financial intelligence ML/TF)
  - Authorities, particularly SAPS, routinely use financial intelligence to help investigate predicate crimes and trace criminal assets, primarily related to fraud and corruption; use for proactive ML/TF investigations is significantly lesser due to inadequate skills and resources.
  - Each year the FIC receives around 300,000 STRs and Suspicious Activity Reports mainly from banks and ADLAs (cross-border money remitters and bureau de change).
  - FIC also receives annually more than five million cash transaction reports (CTRs) and two million cash threshold aggregate reports (CTRAs).
  - FIC disclosures are mostly reactive; ML or TF specific disclosures represent only eight percent of the total disclosures.
  - FIC produces limited strategic products; the GIS Quarterly Report is not proactively disclosed to LEAs.
  - The FIC, the SAPS and the SARS cooperate effectively and form ‘Task Teams’ (TTs) for major investigations.

- Immediate Outcome 7 (Investigations and prosecutions)
  - Authorities identify and investigate ML cases to some extent; emphasis is placed on investigation of predicate offenses.
  - PFIs are undertaken in all cases of organized crime, serious commercial crime, and serious corruption.
  - SAPS:DPCI pursues ML offenses during investigation of predicate offenses, but proactive identification and investigation of ML cases as a primary objective is not sufficiently demonstrated.
  - Bulk of ML cases investigated and prosecuted relate to fraud; fewer ML prosecutions relate to serious corruption, narcotics, and tax offenses.
  - ML cases relating to “State capture” have not been sufficiently pursued in the past; corruption cases referred to the NPA by the SIU have not been dealt with expeditiously.
  - The NPA has suffered major resource and staffing constraints; this is being addressed by establishment of the NPA:ID and increased budget allocation for hiring prosecutors.
  - Prosecutions for ML are regularly undertaken and a reasonable number of convictions achieved, but only partly consistent with South Africa’s risk profile; many sentences are non-custodial or suspended despite a high head sentence of 30 years’ imprisonment and sentences of up to 25 years handed down in practice.
  - Sanctions have been applied against legal persons.

- Immediate Outcome 8 (Confiscation and asset recovery)
  - South Africa proactively pursues confiscation of criminal proceeds and instrumentalities as a policy objective and has achieved some good results.
  - NPA:AFU emphasizes civil forfeiture powers under POCA targeting tainted property; less emphasis on criminal confiscation of property of equivalent value.
  - Positive results achieved for recovery of proceeds in fraud and economic crime; recovery from “State capture” and proceeds moved abroad has been less successful but recent efforts show positive early results.
  - Recovered property is consistently returned to victims including state-owned enterprises (SOEs) or paid to the Criminal Assets Recovery Account (CARA).
  - Sharing of funds with foreign jurisdictions is sometimes pursued; recovery from foreign predicate offenses has been achieved in some cases.
  - Confiscation of falsely declared or undeclared cross-border movement of currency has not been positively demonstrated as effectively addressed; use of cash is prevalent and assessed as high risk for ML and TF, including cross-border movement.
  - Overall, confiscation partially reflects national ML/TF risk and policies; bulk of tainted property recovered stems from economic crime and fraud.

### Key statistics and operational data (preserve source figures exactly)
- Over the five-year period 2014–2018 South African competent authorities made 8,634 requests for information to FIC relating to ongoing cases; distribution by subject of requests: Fraud Related Crimes 2,338 (33%), Corruption 1,200 (17%), Drug Related Crimes 1,028 (15%), Tax Evasion 985 (14%), Robbery & Theft 588 (8%), Environmental Crimes 198 (3%), ML 469 (7%), TF 221 (3%), Total 7,027 (100%).
- The SAPS and the SARS are responsible for 75 percent of the requests made to FIC.
- The FIC made 2,216 proactive disclosures to South African LEAs (five years to March 31, 2018); distribution: Fraud Related Crimes 607 (27%), Tax Evasion 510 (23%), Corruption 98 (4%), Drug Related Crimes 92 (4%), Environmental Crimes 43 (2%), Robbery & Theft 16 (1%), ML 521 (24%), TF 329 (15%), Total 2,216 (100%).
- Section 205 subpoenas obtained by SAPS (2014–2018) by year and average: 2014: 331; 2015: 313; 2016: 390; 2017: 361; 2018: 470; Average: 373.
- Each year FIC receives on average approximately 300,000 STRs, Suspicious Activity Reports, TFTRs and TFARs. Six years to March 31, 2019 — Section.29 totals by year:
  - 2014 STR: 355,369
  - 2015 STR: 267,398
  - 2016 STR: 180,363
  - 2017 STR: 161,435 (plus STRB and other batch reports shown in source table)
  - 2018 STR: 169,203
  - 2019 STR: 144,730
  - Total Section.29 (six years to March 31, 2019): 1,780,615
  - Average Section.29: 296,769
  - Source note: The average total value of STRs filed in each of the last three years is around R300 billion ($20.4 billion).
- Over the five-year period 2014–2018, 92 percent of the 8,634 requests to FIC were for predicate crimes, with ML representing five percent and TF representing three percent (ML + TF = eight percent).

### Recommended actions (selected, organized by Immediate Outcome)
- Immediate Outcome 6
  - The SAPS should increase its requests from the FIC for ML and TF specific financial intelligence.
  - The SAPS and the SARS should increase their skills and resources to much better use financial intelligence in their investigations.
  - The FIC should receive information contained in the SARS cross border cash declaration system proactively.
  - Outreach should be made to DNFBPs that are under-reporting to increase volume and quality of STRs.
  - The FIC should be granted access to relevant SAPS databases to assist in identification and prioritization of relevant STRs.
  - FIC should proactively disclose its GIS Quarterly and Annual Reports to LEAs and develop in-depth strategic reports focused on typologies and trends relating to predicate crimes, ML and TF.

- Immediate Outcome 7
  - SAPS:DPCI should place much more emphasis on proactive identification and investigation of ML cases as a strategic priority, over and above investigation of serious predicate offenses.
  - Authorities should significantly enhance efforts to pursue ML cases from serious corruption (including “State capture”) and other high-risk areas such as narcotics and tax evasion, including expeditious handling of cases referred to the NPA by the SIU in terms of the MOU.
  - LEAs and the NPA should place much greater emphasis on investigating and prosecuting third-party ML and cases of foreign predicate offenses.
  - Prioritize efforts to pursue high level, complex and serious ML cases and to tackle ML networks and professional enablers.
  - Allocate sufficient resources, including attracting and retaining skilled staff and expertise.

- Immediate Outcome 8
  - Continue to prioritize efforts for recovery of assets from “State capture” and proceeds moved to other countries.
  - Enhance recovery from high risk areas (serious corruption, narcotics, tax evasion) by greater use of multidisciplinary or fusion teams from the FIC, the SAPS:DPCI, the SARS, the NPA, and the NPA:AFU at the operational case level.
  - Increase focus on recovery of proceeds from foreign predicate offenses, including seeking assistance from other jurisdictions and sharing or repatriation of funds where appropriate.
  - Undertake major efforts to enhance effectiveness of measures to detect and seize illicit cross-border cash flows at air, sea, and land border points; expedite review of the cash declaration system and implement a revised system effective in countering cash smuggling and introduce enhanced monitoring systems.
  - Allocate sufficient resources to achieve these actions.

*Source: Chapter content from the South Africa AML/CFT assessment (sections IO.1 and Immediate Outcomes 6–8) contained in the provided PDF content.*

### 156.      In addition, FIC receives more than five million CTRs and two million CTRAs annually.

### 1zafea2021001 - 156.

### Reports received and reporting thresholds
- FIC receives more than five million CTRs and two million CTRAs annually.
- Reporting thresholds:
  - A CTR must be filed when a cash transaction exceeds R24,999 ($1,700).
  - A CTRA must be filed if the aggregate total of cash transactions in a 24-hour period exceeds R24,999 ($1,700).
- Value of CTRs/CTRAs:
  - These reports are often included in cases disclosed to LEAs and, as prescribed reports, authorize FIC analysts to follow up with AIs and RIs to gather additional financial intelligence.

- Table 3.5: Section 28 Reports Received by the FIC from AIs and RIs (2014 to 2019)
  - CTR (million) by Year Ending March 31: 2014: 6.1; 2015: 6.7; 2016: 9.3; 2017: 2.6; 2018: 2.7; 2019: 2.6; Total: 30; Average: 5.0
  - CTRA (million) by Year Ending March 31: 2014: ; 2015: 2.1; 2016: 2.1; 2017: 2.6; 2018: 6.8; 2019: 2.3
  - Total Section 28 (million) by Year Ending March 31: 2014: 6.1; 2015: 6.7; 2016: 9.3; 2017: 4.7; 2018: 4.8; 2019: 5.2; Total: 36.8; Average: 6.1
  - Reports Disclosed by Year: 2014: 5,873; 2015: 6,188; 2016: 27,310; 2017: 4,577; 2018: 83,709; 2019: 21,707; Total: 149, 364; Average: 24, 894

### Gaps in reporting and coverage
- Notable gaps despite large volume of obligatory reports:
  - Some sectors including risky DNFBPs (such as most DPMS) fall outside the AML/CFT regulatory framework and have not been filing STRs with the FIC.
  - FIC does not receive, on a proactive basis, reports from the SARS regarding the cash declaration system at South Africa’s various border control points.
  - VASPs currently fall outside the AML/CFT framework; however, larger VA exchanges have provided STRs, TFARs, TFTRs, and voluntarily provided CTRs and CTRAs which have been included in FIC analysis and ongoing cases.

### FIC powers, information gathering, and use
- FIC actions to enhance analysis:
  - FIC requests additional information from AIs and RIs regarding submitted reports, including prescribed transactional information and supporting documentation.
  - In the last three years the FIC compelled AIs or RIs 96,995 times to advise if certain subjects have accounts with the AI or RI.
  - FIC gathered additional information from AIs or RIs 9,563 times on subjects which had been the subject of an obligatory report filed by the AI.
- Non-transactional information access:
  - FIC can, by written request, obtain information related to a subject’s criminal record or firearms registry information, but does not have direct access to basic police databases that would assist in prioritizing STRs.
- Operational needs supported by FIU analysis and dissemination:
  - Disclosures to LEAs are 77 percent reactive and 23 percent proactive over the past five years; FIC is working to increase proactive products.

### Requests from LEAs, response times, and task-team participation
- FIC response and interaction statistics:
  - The SAPS is the largest recipient of FIC’s proactive disclosures (46 percent); approximately five percent of proactive disclosures lead to new investigations.
  - FIC’s average response time for requests from LEAs is around seven weeks.
- Table 3.6: Intelligence Requests Made to the FIC by South African LEAs – Five Years to March 31, 2018
  - Number of domestic requests received by Year: 2014: 1,695; 2015: 1,626; 2016: 1,776; 2017: 1,904; 2018: 1,876; Average: 1,775
  - Number granted by Year: 2014: 1,695; 2015: 1,626; 2016: 1,776; 2017: 1,878; 2018: 1,840; Average: 1,763
  - Average working days to respond by Year: 2014: 40; 2015: 21; 2016: 35; 2017: 35; 2018: 47; Average: 36
- Operational collaboration:
  - Major investigations often involve task teams with FIC analysts embedded to provide ongoing financial intelligence; this real-time involvement supports operational needs.

### Case outcomes and monitoring orders
- Case study (Krejcir):
  - FIC analysis contributed to prosecutions and recovery of proceeds and property valued around R 288 million ($19.6 million).
- Section 35 monitoring orders (terrorism & TF inquiries) – Six Years to March 31, 2019 (Table 3.7):
  - Number of Orders Issued by Year Ending March 31: 2014: 4; 2015: 63; 2016: 16; 2017: 16; 2018: 10; 2019: 1; Total: 110; Average: 18
  - Number of Accounts Linked by Year: 2014: 27; 2015: 105; 2016: 46; 2017: 67; 2018: 20; 2019: 3; Total: 268; Average: 45
  - Number of Cases Linked by Year: 2014: 2; 2015: 8; 2016: 4; 2017: 5; 2018: 3; 2019: 1; Total: 23; Average: 4
- Forfeiture and restraint (Table 3.8: NPA:AFU Five Years – April 1, 2014 to March 31, 2019):
  - Cases by Year Ending March 31: 2015: 39; 2016: 48; 2017: 34; 2018: 16; 2019: 13; Total: 150
  - Amount Restrained or Frozen (R million) by Year: 2015: R 1,927; 2016: R 49.2; 2017: R 205; 2018: R 2,290; 2019: R 2,001; Total: R 6,472
  - Amount Restrained or Frozen ($ million) by Year: 2015: $ 131; 2016: $ 3.3; 2017: $ 13.9; 2018: $ 155.7; 2019: $ 136.1; Total: $ 440.1

### Reporting products and strategic outputs
- FIC reporting types:
  - Public/high-level typologies reports aimed at REs and the general public (limited depth).
  - Operational-focused reports:
    - NICOC Estimates: strategic inputs on ML and TF topics to NICOC’s National Intelligence Estimate.
    - Geographical Information System (GIS) Reports: quarterly and annual breakdowns of reactive and proactive reports, showing locations of requesting and receiving agencies. GIS reports are used internally with LEAs but are not proactively and routinely shared with LEAs.
- Assessment: many reports have value to FIC executives, but utility for competent authorities’ operational needs is less clear; GIS reports contain operational information but are not proactively shared.

### Cooperation, secure exchange, and international dissemination
- Domestic cooperation:
  - FIC and LEAs cooperate effectively; joint task teams and project committees address specific case types (examples listed: National Project Committee; Provincial Project Committees; ACTT; National Coordinating Strategic Management Team; Intelligence Working Group: Rhino Horn Smuggling; CTFC; IFFTT).
- Secure mechanisms for information exchange:
  - goAML encrypted email application
  - secure file transfer protocol (SFTP) solution
  - dedicated encrypted email mailbox using PKI
  - Accessed through authentication protocols; MOUs in place; Authorized Officers receive information; information is approved before dissemination.
- International dissemination:
  - FIC uses the Egmont Group secure web (ESW) to disseminate to Egmont-member FIUs; for non-Egmont members, goAML, SFTP, and encrypted email using PKI are used.

### Overall conclusion on IO.6
- Strengths:
  - FIC obtains a large number of obligatory reports and possesses tools and access to additional information to analyze reports and produce operational financial intelligence.
- Significant gaps:
  - Identified risk pertaining to cash, especially cross-border transactions.
  - FIC not routinely receiving reports on cash courier activity.
  - Low volume of reporting from high-risk DNFBPs.
- LEA use:
  - SAPS, SARS, and other competent authorities routinely use financial intelligence mainly to support investigations related to predicate crimes, not proactively to identify ML and TF cases.
  - LEAs require additional skills and resources to more effectively use generated financial intelligence.
- Rating:
  - South Africa is rated as having a moderate level of effectiveness for IO.6.

### Immediate Outcome 7 (ML investigation and prosecution) — ML identification and investigation
- Overall practice:
  - Authorities identify and investigate ML cases to some extent, with emphasis on predicate offenses.
  - SAPS:DPCI is main agency responsible for ML investigations; PFIs are undertaken in all cases of serious organized crime, serious commercial crime, and serious corruption investigated by SAPS:DPCI.
  - ML cases largely identified and investigated based on evidence arising from specific predicate offenses rather than proactive identification of ML activities.
- SAPS:DPCI activity and case mix:
  - SAPS:DPCI – PCSI became fully operational in 2012; responsible for ML investigation, asset investigation, cybercrime investigation, and a newly formed forensic accounting investigation section (not yet operational).
  - SAPS:DPCI relies on FIC for tracing fund flows; FIC uses powers under FIC Act s.27, s.32, and s.34 to obtain account information and freeze accounts up to 10 working days.
  - SAPS:DPCI collects evidence under subpoena powers (CPA s.205) for court use.
- Table 3.9: SAPS:DPCI Predicate Offense Investigation Activity Resulting in ML Charge – Jan 1, 2014 to Dec 31, 2017
  - Fraud: Reported to SAPS:DPCI: 8,404; Investigated by SAPS:DPCI: 5,350; Percent of total: 60%; Referred for Prosecution: 740; Prosecuted for ML: 240; Percent of total: 23%; % of referred prosecuted for ML: 32%
  - Corruption & bribery: Reported: 1,663; Investigated: 1,334; Percent of total: 15%; Referred: 722; Prosecuted for ML: 18; Percent of total: 22%; % of referred prosecuted for ML: 2%
  - Theft: Reported: 836; Investigated: 589; Percent of total: 7%; Referred: 159; Prosecuted for ML: 39; Percent of total: 5%; % of referred prosecuted for ML: 25%
  - Counterfeiting & product piracy: Reported: 612; Investigated: 468; Percent of total: 5%; Referred: 280; Prosecuted for ML: 0; Percent of total: 9%; % of referred prosecuted for ML: 0%
  - Tax crimes: Reported: 607; Investigated: 229; Percent of total: 3%; Referred: 33; Prosecuted for ML: 8; Percent of total: 1%; % of referred prosecuted for ML: 24%
  - Drug Trafficking: Reported: 259; Investigated: 220; Percent of total: 2%; Referred: 182; Prosecuted for ML: 5; Percent of total: 6%; % of referred prosecuted for ML: 3%
  - Piracy (movies and music): Reported: 362; Investigated: 184; Percent of total: 2%; Referred: 114; Prosecuted for ML: 0; Percent of total: 4%; % of referred prosecuted for ML: 0%
  - Forgery: Reported: 97; Investigated: 81; Percent of total: 1%; Referred: 47; Prosecuted for ML: 4; Percent of total: 1%; % of referred prosecuted for ML: 9%
  - Environmental crime: Reported: 61; Investigated: 61; Percent of total: 1%; Referred: 74; Prosecuted for ML: 8; Percent of total: 2%; % of referred prosecuted for ML: 11%
  - Human Trafficking: Reported: 52; Investigated: 52; Percent of total: 1%; Referred: 30; Prosecuted for ML: 2; Percent of total: 1%; % of referred prosecuted for ML: 7%
  - All Others: Reported: 363; Investigated: 324; Percent of total: 4%; Referred: 173; Prosecuted for ML: 14; Percent of total: 7%; % of referred prosecuted for ML: 8%
  - Less Multiple Charges Laid: Reported: ; Investigated: 16
  - Total: Reported: 13,283; Investigated: 8,892; Percent of total: 100%; Referred for Prosecution: 2,554; Prosecuted for ML: 322; Percent of total: 100%; % of referred prosecuted for ML: 13%
  - Note: All but two prosecuted cases resulted in convictions.
- Capacity gaps:
  - SAPS:DPCI – PCSI has formed a forensic accounting investigation section but it is not yet operational; reliance on outside forensic accounting firms persists.
  - Lack of in-house forensic accounting expertise means focus is on collecting evidence to prove fund flows identified by FIC or other means.

*Source: IMF country report content unit 1zafea2021001 - 156.*

### Box 3.1. Case Example – Abalone

### Box 3.1. Case Example – Abalone

### Case summary and operational actions
- Abalone was seized during search and seizure operations and the accused arrested.
- Documents seized at another location indicated raw plastic had been purchased and was being exported to China.
- Further investigation revealed that more plastic had been purchased than was being exported.
- After consultations with the SARS:Customs and the shipping line concerned, a stop order was placed on two containers still en route to China and the containers were re-routed back to Cape Town.
- Dried abalone was found hidden inside the plastic bales.

### Prosecutions and sentencing outcomes
- As a result of investigations into the predicate offending, ML charges were developed and pursued.
- Five accused were convicted of ML including a legal entity.
- Sentences and penalties:
  - Three accused were sentenced to one year’s imprisonment.
  - Another accused was sentenced to 8 years imprisonment (with three years suspended).
  - The legal entity was fined R200,000 ($13,600) (suspended for five years).

### Assessors’ observations on ML investigative approach
- The authorities acknowledged that the potential cases of ML which are identified, and most ML investigations are directly linked to the investigation of the predicate offense.
- In the assessors’ view, less emphasis is placed by SAPS:DPCI on the proactive identification and investigation of ML cases, and the networks and professional enablers behind or linked to the predicate offense.
- This gap may be remedied in part when the forensics accounting investigation unit within SAPS:DPCI -PCSI, which has already been established, becomes operational and develops a capacity to:
  - focus proactively on ML cases; and
  - identify and investigate third-party ML, professional enablers and ML networks related to the predicate offense.
- It is noted that while SAPS:DPCI focused on around 250 serious drug trafficking or dealing cases over the period 2014–17; over the same period there were nearly 40,000 total such cases (out of more than 1 million drug crimes), indicating that investigating ML related to drug dealing is not receiving sufficient attention by the authorities overall although not all of these cases involve high level drug dealing generating significant proceeds.

### Nature of ML investigations and prosecutorial practice
- ML investigations conducted by SAPS:DPCI therefore appear to be largely reactive and form part and parcel of the investigation of the predicate offense.
- Most of the predicate offenses (including offenses against the person such as kidnapping) are major crime proceeds generating offenses which necessarily entail ML activity.
- Many of the ML cases charged are cases of self-laundering which are prosecuted in conjunction with the predicate offense.
- The ML aspect charged is frequently the immediate dealing in the proceeds of the predicate offense committed by the defendant or a close associate.
- The evidence developed by the PFI to prove the predicate offense and related confiscation or forfeiture applications is thus largely the same evidence used for the ML offense, and the ML charge necessarily follows the charge for the predicate offense.
- As a result of this narrow focus on predicate offenses, the authorities have not been effective in dealing with wider ML activities including third party ML.

### Key statistics from Table 3.10 (Number of ML Investigations, Prosecutions, and Convictions—Five Years to March 31, 2019)
- Number of ML investigations by year:
  - 2015: 358
  - 2016: 502
  - 2017: 457
  - 2018: 418
  - 2019: 271
  - Average: 401
- Number of ML Prosecutions (Cases) by year:
  - 2015: 51
  - 2016: 43
  - 2017: 59
  - 2018: 67
  - 2019: 76
  - Average: 59
- Number of ML Convictions (Cases) by year:
  - 2015: 51
  - 2016: 43
  - 2017: 59
  - 2018: 67
  - 2019: 76
  - Average: 59
- Percentage of investigations lead to convictions (Cases):
  - 2015: 14%
  - 2016: 9%
  - 2017: 13%
  - 2018: 16%
  - 2019: 28%
  - Average: 15%
- Number of Persons Convicted for ML, of which:
  - 2015: 71
  - 2016: 71
  - 2017: 96
  - 2018: 87
  - 2019: 116
  - Average: 88
- For Foreign Predicates by year:
  - 2015: 2
  - 2016: -
  - 2017: 2
  - 2018: 1
  - 2019: -
  - Average: 1
- For legal persons by year:
  - 2015: 2
  - 2016: 1
  - 2017: 3
  - 2018: 3
  - 2019: 2
  - Average: 2
- For self ML by year:
  - 2015: 47
  - 2016: 50
  - 2017: 46
  - 2018: 51
  - 2019: 73
  - Average: 53
- For stand-alone ML by year:
  - 2015: 22
  - 2016: 20
  - 2017: 45
  - 2018: 33
  - 2019: 41
  - Average: 32
- Source: The SAPS:DPCI – PCSI
- Notes included with the table:
  - 1: Annual data have been aligned throughout the report by matching all calendar year data to the March 31 year immediately following.
  - 2: Authorities shared 322 cases where ML charges were laid with a total of 516 natural and legal persons convicted. Some of the cases pre- and post-dated the data in this table.

### Roles of other enforcement agencies and referral patterns
- The SARS investigates tax and customs offenses. Once the criminal investigation is concluded, the case is referred to the SAPS and the NPA who may add charges such as ML.
- There have been some but not many ML cases investigated and prosecuted based on tax fraud or customs offenses.
- The SARS is obliged to report AML/CFT information it comes across during investigations to the FIC (FIC Act, s.36) or to share information with other relevant LEAs (POCA, ss. 71 and 73).
- A senior SARS official must authorize the laying of a criminal complaint with SAPS whether the offense constitutes a non-compliance offense or a serious tax offense and when an offense concerns a customs offense.
- The NPA decides if a prosecution should be instituted and for what offenses, which depending on the facts of the case may go beyond tax offenses. If elements of ML are identified, the NPA may work with SAPS:DPCI to prepare the ML case for court.
- SARS does not have a mandate to actively investigate ML cases.
  - In the years ending March 31, for 2017, 2018, and 2019, the SARS referred 660, 500, and 468 tax offenses to the NPA for prosecution respectively.
  - These offenses mainly involved failing to submit tax returns but also involved some tax fraud matters which generate proceeds.
- The SIU investigates serious malpractices or maladministration in the administration of the State and institutes civil proceedings to recover value of losses incurred; SIU does not investigate ML cases but passes findings of possible criminal offending including corruption and potential ML to the NPA to follow up in conjunction with the SAPS:DPCI.
  - SIU obtains information from FIC and financial institutions during financial investigations within its mandate.
  - SIU has a backlog of recovery cases pending in civil litigation; Special Tribunals have recently been made operational to help address the problem.
  - The NPA has been allocated with more resources in recent budget allocations to help address the issue of the past backlog of criminal referrals by SIU.

### Consistency with threats and national AML priorities
- South Africa has achieved a good level of prosecution for the ML offense in terms of the number of convictions; during the last five years the authorities have achieved over 300 convictions for the ML offense.
- The conviction rate for all crime prosecuted in South Africa is high, at over 90 percent of cases prosecuted; and nearly 100 percent for ML cases.
- Most ML cases investigated and prosecuted relate to the predicate offense of fraud, which is somewhat consistent with South Africa’s threat and risk profile.
- There have been fewer prosecutions relating to ML in other high-risk areas such as corruption and bribery, narcotics, and tax offenses.
- The time taken to litigate and resolve cases is lengthy in many cases.
- While the conviction rate is high for ML cases prosecuted, the number of ML cases prosecuted from the referrals made is relatively low averaging 15 percent.
- The data suggest that only the obvious cases of ML are being prosecuted.
- Authorities acknowledge that weakened institutional capacity through “State capture” seriously impacted their ability to investigate and prosecute serious corruption and ML and led to the loss of key personnel in LEAs and the freezing on hiring new staff.
- New heads of the NPA, the SAPS:DPCI, and the SARS have recently been appointed to address issues arising from “State capture” and to focus efforts on rebuilding institutional integrity and capacity in these agencies.
- The establishment of NPA:ID (Investigating Director of NPA:ID appointed in May 2019) is an indication of commitment to address major high-profile corruption cases; it is too early to assess effectiveness.

### Types of ML cases pursued and investigative gaps
- ML prosecutions mostly concern cases of self-laundering based on the predicate offending, which is often prosecuted at the same time.
- Stand-alone ML cases are prosecuted, but there are no third-party ML cases and only a few for ML arising from foreign predicates.
- This pattern appears to be a consequence of the focus on investigating predicate offenses rather than identifying and investigating ML networks and professional enablers.
- Table 3.11: ML Convictions—Number of Natural People Convicted – Five Years ending March 31, 2019
  - Total Convicted by year:
    - 2015: 69
    - 2016: 70
    - 2017: 93
    - 2018: 84
    - 2019: 114
    - Average: 86
  - For Self-laundering by year:
    - 2015: 47
    - 2016: 50
    - 2017: 46
    - 2018: 51
    - 2019: 73
    - Average: 53 (63%)
  - For Stand-alone by year:
    - 2015: 22
    - 2016: 20
    - 2017: 45
    - 2018: 33
    - 2019: 41
    - Average: 32 (37%)
  - Note: Totals for 2016/17 do not add due to a minor discrepancy in data provided.
- Authorities noted an attorney was involved in one case as a third-party launderer but claims to legal privilege proved a challenge during investigation and prosecution.
- Authorities struggle to investigate and prosecute cases of stand-alone and third-party ML due to lack of resources and expertise to proactively identify networks and ML syndicates that often have overseas links.
- Authorities provided some investigations taken for foreign requests for assistance involving proceeds of crime located in South Africa and the investigation of ML relating to foreign predicates but did not sufficiently demonstrate that ML relating to foreign predicate offenses is being proactively investigated and prosecuted as a policy objective.
- No ML cases relating to foreign corruption were provided.

### Effectiveness and proportionality of sanctions
- South Africa has a high head sentence of 30 years’ imprisonment for the ML offense and sentences of up to 25 years have been handed down in practice, which are dissuasive.
- There are no set guidelines or tariffs for the ML offense; sentence is fixed by the court taking account of circumstances.
- The most serious offenses result in direct imprisonment; in most cases the ML offense is linked to the predicate offense for sentencing purposes because the offenses are frequently prosecuted together.
- Sentences for the predicate offense and the ML offense may run fully or partly concurrent to each other.
- Non-custodial and suspended sentences and fines are imposed in a number of cases, reflecting proportionality for less serious offending.
- If the ML offense is self-laundering, the court may suspend the sentence for the ML offense and base imprisonment on the predicate offense.
- Time spent in custody pending conclusion of proceedings will be deducted from the sentence of imprisonment to be served.

*Source: Box 3.1. Case Example – Abalone, 1zafea2021001*

### 201.      Data provided by the authorities (see Table 3.12 below) evidence that suspended

### 1zafea2021001 - 201.

### Sanctions and Sentencing for Money Laundering (ML)

- Data provided by the authorities (see Table 3.12) indicate that suspended sentences are the prevalent sanction imposed for the ML offense and they outnumber cases where actual custodial sentences have been imposed.
- In about half the cases where the offender was convicted of both the predicate offense and the ML offense, the sentence for the ML offense was the same as the predicate offense (whether the sentence was suspended or not).
- The sentence for the ML offense only exceeded the sentence for the predicate offense in around six percent of cases.
- This pattern indicates penalties for the ML offense do not add much to the penalties imposed for the predicate offending in cases of self-laundering.
- Overall, sanctions for ML convictions may only be considered effective to some extent.

Key statistics from Table 3.12 (March 2014 – October 2019):
- Number of persons convicted of ML only: 154
- Of which received suspended sentences: 119
- % Suspended: 77%
- Of which received non-custodial sentence: 133
- % Non-custodial: 86%
- Number receiving custodial sentences: 21
- Average years of imprisonment: 7.6
- Max years of imprisonment: 20
- < 2 years: 2
- 2 to < 5 years: 2
- 5 to < 10 years: 11
- 10 to < 20 years: 5
- 20 to 30 years: 1

- Sanctions have been imposed against legal persons (e.g., if an attorney is prosecuted, their law firm may also be charged). During the period under assessment, 11 legal persons were sentenced for ML offenses.
- Case example — Corruption (AgriBEE fund): R100 million ($6.8 million) allocated; R6 million ($408,000) grant irregularly paid; sentences: former CEO of Land Bank – seven years imprisonment for fraud; Member of Parliament – 20 years imprisonment for fraud and ML; attorney – 24 years imprisonment for fraud and ML; attorney’s firm also convicted of ML; amount forfeited R3.2 million ($217,600) and paid to the Land Bank.

### Use of Alternative Measures and Asset Recovery Mechanisms

- South Africa employs alternative criminal justice measures in ML cases as a policy goal and has a range of options when it is not possible to secure a ML conviction.
- The NPA:AFU actively pursues asset recovery through civil forfeiture measures (POCA ch.5 and ch.6). SIU also pursues recovery of State losses through civil litigation.
- Asset recovery measures work in parallel with ML investigations and continue regardless of any criminal prosecution for the ML offense.
- Where ML cannot be pursued, the NPA may consider charging persons for other offenses (e.g., exchange control offenses in cash seizures at border points).

Operational and procedural features:
- The NPA:AFU can restrain and confiscate benefits following conviction (POCA, ch.5) and can pursue non-conviction-based forfeiture (POCA, ch.6).
- Ch.6 procedure is non-conviction based, targets criminal assets, and uses a lower civil standard of proof.
- The NPA:AFU has completed 5,607 confiscations and forfeitures to the value of R8.35 billion ($568 million) since 1999.
- The unit completed 6,245 freezing orders (restraints and preservations) to the value of R16.5 billion ($1.1 billion).
- The unit has recovered R6.74 billion ($458 million), of which R5.68 billion ($386 million) was paid back (or assets returned) to victims and R1.05 billion ($71.4 million) was paid to the CARA (as at September 30, 2019).

Referral and case management thresholds and processes:
- NPA:AFU standard form guideline factors for referral: all offenses for profit of more than R15,000 ($1,020); corruption involving more than R5,000 ($340); any investigation where SAPS or another investigating agency has seized cash of more than R15,000 ($1,020); all drug dealing cases; other cases with significant impact (e.g., syndicates); cases of unexplained wealth; and any other reason.
- NPA:AFU Case Intake and Allocation Committee evaluates cases, allocates cases to legal and investigative staff, and obtains and approves a case plan within 10 working days or longer if necessary.
- SAPS:DPCI – FAFI: mandated to trace proceeds, identify instrumentalities and property of equivalent value, and assess asset forfeiture potential before referral to asset investigators and/or NPA:AFU.
- The FIC may issue an order under the FIC Act, s.34 to prohibit a reporting entity from dealing in property for 10 days while NPA:AFU prepares an ex parte application for restraint or preservation orders.

Practical outcomes and judicial practice:
- NPA:AFU experience indicates most ch.6 forfeiture applications are not opposed; affected parties must demonstrate lawful origin of property.
- Restraints (POCA, ch.5) are optional and used when assets risk dissipation; preservations (POCA, ch.6) are required before forfeiture.
- NPA:AFU demonstrated ability to act expeditiously and successfully under POCA, ch.6, including in Virtual Asset (VA) cases and is beginning to focus on major “State capture” cases.

Case example — Virtual Assets:
- Fraud from Namibia: transfers of N$750,000 and N$500,000 to a fraudulent South African bank account; preservation order R343,000 ($23,300) on October 5, 2017; forfeiture order R954,356 ($64,900) on February 2, 2018; amount recovered and repatriated R961,654 ($65,400) on March 2, 2018.

### Confiscation Results, Scope, and Limitations

- South Africa adopts an “all offenses” approach to ML: all cases where NPA:AFU undertakes restraints and confiscations (ch.5 or ch.6) are regarded as predicate offenses even if ML may or may not have been involved.
- Ch.6 POCA powers are being used effectively and often preferred to ch.5 where a criminal conviction is required.

NPA:AFU POCA activity — Five Years ending March 31, 2019 (Table 3.13):

Provisional Measures – Restraints and preservations
- Number: 2015: 482; 2016: 464; 2017: 460; 2018: 355; 2019: 283; Average: 409
- Value (R millions): R 6,699.5; R 9,498.9; R10,292.9; R11,509.2; R15,889.4; R 10,777.9
- Value ($ millions): $ 525.1; $ 645.8; $ 771.9; $ 869.2; $ 1,034.6; $ 769.3
- Average Value ($): $ 1,089,377; $ 1,391,723; $ 1,678,141; $ 2,448,495; $ 3,655,868; $ 1,881,903

Confiscations and Forfeiture Orders
- Number: 2015: 459; 2016: 386; 2017: 459; 2018: 573; 2019: 493; Average: 474
- Value (R millions): R 1,941.5; R 342.5; R 420.9; R 368.4; R 3,092.1; R 1,233.1
- Value ($ millions): $ 152.2; $ 3.3; $ 31.6; $ 7.8; $ 201.3; $ 87.2
- Average Value ($): $ 331,528; $ 60,322; $ 8,783; $ 48,557; $ 408,387; $ 184,045

Recoveries – incl. victim payments
- Number: 2015: 571; 2016: 427; 2017: 568; 2018: 649; 2019: 645; Average: 572
- Value (R millions): R 1,705.6; R 446.6; R 221.1; R 293.4; R 3,046.7; R 1,142.7
- Value ($ millions): $133.7; $ 30.4; $ 6.6; $ 22.2; $ 198.4; $ 80.2
- Average Value ($): $ 234,118; $ 71,107; $ 29,192; $ 34,139; $ 307,571; $ 140,267

- Note: Large increase in recoveries in 2019 is from cases in Box 7 and 8.

NPA:AFU activity involving ML-related cases — Five Years to March 31, 2019 (Table 3.14):
- Average per provisional measure ($): $ 983,339; $ 471,038; $2,146,286; $9,483,407; $ 197,184; $2,656,251
- Average of Confiscation/Forfeiture Orders ($): $ 1,358,849; $ 914,444; $1,339,081; $193,476; $10,336,242; $2,828,419
- Average of recoveries ($): $ 459,202; $2,308,480; $ 499,809; $299,162; $4,541,152; $1,621,561
- Note: Analysis indicates that, on average, the authorities recover around 8 percent of the value of the related proceeds in ML related cases, noting that recovery efforts for some cases are continuing.

Case examples — "State Capture”
- Box 8.1: Company X — preservation order on March 8, 2018 to the value of R1.8 billion ($122.4 million); matter finalized April 26, 2018 and R1.9 billion ($129.2 million) paid to the NT.
- Box 9.1: Eskom/McKinsey — preservation order December 2017; preservation order settled for R902,274,123 ($61.4 million) on July 31, 2018 and monies paid back to Eskom.

### Assessment, Gaps, and Recommendations

Findings on effectiveness and gaps:
- ML activities, in particular major-proceeds generating offenses, are investigated and prosecuted to some extent but only partly consistent with South Africa’s risk profile.
- A reasonable number of convictions have been achieved; however, in most cases these flow directly from prosecution of the predicate offense and frequently involve self-laundering.
- ML activities arising from “State capture” have not been effectively addressed to date; wider ML activities by organized crime syndicates, including from outside South Africa, are not being sufficiently identified and targeted.
- Sanctions set by law are severe, but in practice non-custodial or suspended sentences are often imposed.
- The focus on self-laundering, absence of third-party ML cases, lack of concerted action against wider ML networks, and overall impact of “State capture” weigh heavily against the otherwise reasonably good number of successful prosecutions and convictions.
- South Africa is rated as having a moderate level of effectiveness for IO.7.

Recommendations and operational priorities implied by the assessment:
- Resolve difficulties in securing international cooperation for recovery of assets moved offshore and pursue recovery through all available channels.
- Ensure sufficient resources are made available to the relevant authorities to achieve satisfactory asset recovery outcomes.
- Pursue recovery of proceeds from foreign predicate offenses more proactively, consistent with South Africa’s risk profile as a regional financial hub.
- Continue and expand efforts to target ML activities linked to “State capture” and wider organized crime networks.

Recovered property management and international cooperation:
- Recovered property from proceeds of crime is well-managed by the NPA:AFU and routinely returned to victims (including SOEs) or paid to the asset recovery fund; bulk of recovered property is returned to victims.
- Sharing of funds with foreign jurisdictions has been pursued in some cases; reviewed data show some recovery of proceeds arising from foreign predicate offenses but not in a proactive manner.
- Authorities indicated evidence from overseas jurisdictions is not always available to support recovery action for foreign predicate offenses.

Table 3.15 — Cases Involving Funds Repatriated — Five Years to March 31, 2019:
- Number: 2015: - ; 2016: 3; 2017: 1; 2018: - ; 2019: 3; Average: 1.4
- Value (R millions): R 0; R 102.8; R 2.0; R 0; R 3.1; R 21.6
- Value ($ millions): $ 0; $ 6.9; $ 0.15; $ 0; $ 0.2; $ 1.5
- Average Value ($ millions): $ 0; $ 2.3; $ 0.15; $ 0; $ 0.07; $ 0.5
- Countries: Nigeria, Eswatini; USA; Germany, USA

- Authorities have encountered difficulties in securing adequate cooperation from foreign jurisdictions for recovery of “State capture” assets moved offshore; recent efforts are beginning to show positive results but remain at an early stage.

*International Monetary Fund — South Africa: Extracted content unit 1zafea2021001 - 201.*

### 221.      The SIU also pursues recovery of State losses through its civil litigation remedies.

### 1zafea2021001 - 221.      The SIU also pursues recovery of State losses through its civil litigation remedies.

### SIU civil recoveries and Table 3.16 (Six Years to March 31, 2019)
- SIU pursues recovery of State losses through civil litigation; link to criminal activity is not necessary but experience indicates most cases involve fraudulent, corrupt, or criminal activity.
- Table 3.16: South Africa: SIU Recoveries through Civil Litigation—Six Years to March 31, 2019
  - Year Ending March 31: 2014 | 2015 | 2016 | 2017 | 2018 | 2019 | Total
  - Acknowledgement of Debt (R millions): R 1.6 | R 164.9 | - | R 8.7 | R 5.4 | R 2.4 | R 183.1
  - Civil Litigation (R millions): R 23.7 | R 35.5 | R 43.5 | R 24.8 | R 97.9 | R 38.6 | R 225.5
  - NPA:AFU recoveries (R millions): R 119.8 | (blank) | (blank) | (blank) | (blank) | (blank) | R 119.8
  - Total Recovered (R millions): R 145.1 | R 52.0 | R 43.5 | R 33.5 | R103.4 | R 2.4 | R 379.9
  - Total Recovered ($ millions): $11.4 | $ 3.5 | $ 3.3 | $ 2.5 | $ 6.7 | $0.2 | $27.6

### Interdiction and recovery of cash proceeds of crime; cross-border movements
- Cash interdiction and recovery is challenging; offenders convert illicit proceeds to cash which becomes difficult to trace.
- Cash used to maintain lavish lifestyles and purchase luxury items including jewelry, high value motor vehicles, and property.
- Use of cash, including cross-border movement, is assessed as a high-risk area that requires priority action in the ML context.
- Confiscation of falsely or undeclared cross-border movement of currency/BNI:
  - Authorities have not positively demonstrated that confiscation of falsely or undeclared cross-border movement of currency is being addressed and applied as an effective, proportionate, and dissuasive sanction.
- Legal and enforcement framework:
  - SARS:Customs is first line of control; Enforcement Division combats fraud; Illicit Economy Unit operational since January 2019 focuses on serious non-compliance in industries such as tobacco, gold, clothes, and textiles imports.
  - Customs and Excise (C&E) Act, s.15 requires declaration of goods which includes cash; Exchange Control Regulations, 1961 (ECR) require declaration of South African banknotes and foreign currency in possession. ECRs do not restrict or control incoming BNIs payable in foreign currency.
  - Written declaration requirement for cash at border points suspended in 2008; current expectation is an oral declaration if carrying cash in excess of R25,000 ($1,700) or foreign currency exceeding $10,000 or equivalent. Requirement is not well-advertised to travelers.
  - SARS:Customs may search for and seize currency under the ECR when travelers have South African banknotes in excess of R25,000 ($1,700) unless specific exemptions apply.
  - Primary focus appears on outgoing movements of cash with less attention to incoming movements.

- Prevalence and patterns:
  - Undeclared cross-border movements of significant amounts of cash appears prevalent due to widespread cash use in South Africa’s informal economy, neighboring countries, and for foreign import/export of goods.
  - Largest movements of undeclared cash reported through airports, particularly OR Tambo International Airport in Johannesburg, with Dubai and Hong Kong as major destination points.
  - Statistics confirm most interceptions involved Dubai as destination.
  - A total of 40 cash seizures by SARS over five years from 2014 to 2019 does not match South Africa’s risk profile for cash smuggling.

- Handling and prosecutions:
  - Cash couriers intercepted upon departure are stopped, investigated in a secure room under camera, and a criminal investigation is opened; authorities have 48 hours to charge the person.
  - SARS:Customs informs NPA:AFU and FIC; NPA:AFU applies for a preservation order under the POCA followed by a forfeiture order, regardless of prosecution.
  - Authorities reported 14 prosecutions for cash smuggling during the last five years; this is not considered significant relative to the reported size of illicit activity.
  - Trends indicate cash smuggling now often occurs between passengers during airport transits, making intervention difficult.

- Assessment and recommended action:
  - It is not easy to assess what proportion of illicit cross-border movement of cash is linked to ML/TF; all illicit cash movements are liable to forfeiture as cash smuggling contrary to the ECR and evidence of ML/TF is not necessary.
  - Authorities should expedite a review of the cash declaration system and implement a revised system effective in countering widespread cash smuggling; actions should include enhanced monitoring systems and increased resources for staff and monitoring.

### SARS:Customs Border Cash Seizures — Table 3.17 (Five Years to March 31, 2019)
- Table 3.17: South Africa: SARS:Customs, Border Cash Seizures—Five Years to March 31, 2019
  - Year: 2015 | 2016 | 2017 | 2018 | 2019 | Total | Percent
  - Total Seizures: 4 | 9 | 8 | 14 | 5 | 40 | (blank)
  - Total Value (R):
    - R 89,292,379 | R 28,499,097 | R 19,053,371 | R 55,026,433 | R 23,175,912 | R 215,047,192
  - Total Value ($):
    - $6,998,422 | $1,937,447 | $ 1,428,955 | $ 4,155,789 | $ 1,509,057 | $16,029,670
  - Location breakdown (R):
    - Courier/Mail: R 242,379 | R 97,945 | R 2,400 | R 35,875 | R 212,931 | R 591,530 | 0%
    - Border Posts: - | R 35,000 | R 1,513,030 | R 1,508,505 | - | R 3,056,535 | 2%
    - Airports: R 242,379 | R 97,945 | R 2,400 | R 35,875 | R 212,931 | R 591,530 | 0%
    - Airports – In: - | R 50,760 | - | - | - | R 50,760 | (blank)
    - Airports – Out: R 89,050,000 | R 28,315,392 | R 17,537,941 | R 53,482,053 | R 22,962,981 | R 211,348,367 | 98%
  - Airports – Average (R): R 29,683,333 | R 5,673,230 | R 5,845,980 | R 5,942,450 | R5,740,745 | R 8,808,297
  - Airports – Average ($): $ 2,326,475 | $ 385,682 | $ 438,434 | $ 448,795 | $ 373,798 | $ 656,562
  - Notes:
    1. Two-thirds of the seized currency is USD, 28 percent ZAR, and five percent GBP.
    2. Ninety percent of outward seizures are headed for the United Arab Emirates, and four percent Hong Kong.

### Consistency of confiscation results with ML/TF risks and national policies
- Confiscation of proceeds of crime partially reflects South Africa’s ML/TF risk and national AML/CFT policies and priorities:
  - Most tainted property recovered stems from economic crime, fraud, and corruption — consistent with identified high-risk predicate offenses.
  - High volume and frequency of recoveries consistent with policy to deprive criminals of benefits under POCA through cooperation between FIC, LEAs and NPA:AFU.
  - Civil recovery regime under POCA, ch.6, is particularly effective and well-established; SIU has framework to pursue State losses and Special Tribunals expedite claims.
- Shortcomings:
  - Recovery from “State capture” and egregious public sector corruption cases has been less successful to date, as well as recoveries from proceeds of narcotics and tax evasion — not consistent with South Africa’s ML risk.
  - Authorities are aware and committed to recovering assets looted from State entities and moved offshore; international cooperation requests are pursued but sometimes difficult.
  - Interdiction and recovery of cash proceeds remain challenging and results are not consistent with ML/TF risks; seizures for cash smuggling do not adequately reflect volumes being smuggled.

### Overall conclusion on IO.8 (Confiscation)
- Criminals are being deprived of proceeds and instrumentalities of crime to some extent; South Africa has a well-developed civil forfeiture regime achieving good results.
- The regime has not been used effectively for the most serious crimes arising from “State capture”, including proceeds moved offshore.
- Recoveries from crimes occurring outside South Africa are not being sufficiently targeted given South Africa’s role as a regional financial hub.
- Criminal confiscation of proceeds of crime has been less effective overall.
- Cross-border movement of cash is prevalent and not being adequately addressed.
- The impact and non-recovery of bulk proceeds from “State capture” and prevalence of undetected cross-border cash movement weigh against otherwise good civil forfeiture results.
- South Africa is rated as having a moderate level of effectiveness for IO.8.

### Terrorist financing (TF) and proliferation financing (PF): Key findings (Immediate Outcomes 9–11)
- Immediate Outcome 9 (TF investigations and prosecutions) — Key findings:
  - Evidence of some investigative activity from intelligence gathering, but conservative classification of politically motivated acts as terrorism results in a low number of official terrorism and TF investigations and prosecutions; may be linked to technical deficiencies in the TF offense.
  - Limited experience prosecuting TF: prosecuting one TF case and investigating three other potential cases; no other prosecutions in past five years; one person convicted of TF in March 2013 for attacks in 2010.
  - Single person convicted on two counts of TF since the last ME is not consistent with TF risk profile; domestic terrorism risk assessed by authorities as low, but identified risks (international groups soliciting support, FTFs) suggest prosecutions should be higher.
  - Collaborative approach: CTFC meets regularly; LEAs follow up on FIC proactive disclosures and request TF-related financial intelligence; LEAs have not demonstrated adequate proactive identification of TF cases with majority derived from foreign agencies.
  - TF investigation not properly integrated into NCTS; NCTS does not identify pursuit of terrorist financiers as an operational mitigant nor designation as a tool to counter terrorism or TF.

- Immediate Outcome 10 (Targeted financial sanctions — TFS and listings) — Key findings:
  - Authorities have not implemented any designations adopted by the UNSC pursuant to resolutions 1267/1989 and 1988 since July 2017.
  - Authorities do not communicate effectively new designations or delistings to obliged entities.
  - Authorities have never used TFS under the UNSCR 1373 framework and would not be able to communicate such designations; rely on a freezing mechanism that does not amount to a proper designation.
  - CFTC could identify potential designation targets but authorities do not actively consider whether targets meet UNSCR criteria; policy of testing evidence in court before making designations impedes active use of TFS.
  - Larger FIs with international exposure understand and implement TFS obligations; other FIs and DNFBPs have limited understanding due to lack of communication mechanisms; implementation by smaller FIs and DNFBPs is not effective.
  - NPO sector: NPO Task Team initiated identification of at-risk NPOs but specific measures, monitoring, or supervision of at-risk organizations have not been applied.

- Immediate Outcome 11 (Proliferation financing — PF) — Key findings:
  - South Africa started to implement TFS for PF in April 2019; no assets have been frozen or identified since then.
  - Implementation is timely when updating existing UNSCR lists (in most cases within 24 hours) but can take days for a new UNSCR.
  - FIC real time alert notification is effective for subscribers but does not reach other entities; existing guidance lacks specific implementation detail for PF TFS.
  - Coordination on PF began recently and remains at initial stages but benefits from existing proliferation coordination mechanisms.
  - Early detection of PF activities relies mostly on STRs and foreign intelligence; lack of access to BO information hinders identification of PF-related assets.
  - Understanding of PF obligations uneven among FIs, DNFBPs, and VASPs; only large internationally exposed FIs understand new PF obligations.
  - Supervision and compliance monitoring for PF commenced in April 2019 with limited focus and scope; VASPs are not supervised at all.

### Recommended actions (selected, by Immediate Outcome)
- Immediate Outcome 9:
  - Substantially increase proactive identification of potential TF cases by broadening investigative perspective on acts that may be terrorism related.
  - Integrate TF investigations into the NCTS.
  - Reconsider policy of not pursuing domestic designation of terrorists, terrorist organizations, and support networks.
  - Ensure policies, procedures, and strategies to identify, investigate and prosecute all types of TF activity (collection, movement, use of funds or other assets).
  - Complete TF Risk Assessment, develop an Implementation Plan specific to TF investigations, and set detailed TF performance indicators for government departments.
  - Amend the POCDATARA to remove exceptions from the definition of terrorist activity inconsistent with the TF Convention.

- Immediate Outcome 10:
  - Address major shortcomings in R.6 by revising framework and strengthening procedures for implementing UN listings for UNSCR1267/1988/1989 and subsequent resolutions and for UNSCR 1373.
  - In the interim, resume immediately implementation of TFS for UNSCRs 1267, 1988, and 1989 and subsequent resolutions.
  - Improve mechanisms for communicating listings to the private sector for UNSCRs 1267, 1988, and 1989, and establish mechanisms for UNSCR 1373; consider a consolidated list for TFS.
  - Increase outreach to FIs, DNFBPs, and VASPs to improve understanding of TFS obligations.
  - Adopt a strategy to use TFS or alternative processes to deprive terrorists of assets; disseminate operational procedures to stakeholders (IDCs such as CFTC and IDWG-CT) to proactively consider targets for designation and use TFS where appropriate.
  - Train LEAs, intelligence, and prosecutors on procedures to promote proactive use of TFS and alternative tools to pre-emptively deprive terrorists of assets.
  - Implement an action plan to mitigate TF abuse of the NPO sector, designate a competent authority responsible for supervision or monitoring of NPOs, and integrate that authority within the AML/CFT security cluster.
  - Use NPO review work to identify types of NPOs at risk of TF abuse independently from other compliance risk assessments.

- Immediate Outcome 11:
  - Address moderate shortcomings in R.7 to ensure implementation of PF-related TFS is without delay in all cases, including new UNSCRs.
  - Increase reach of consolidated list communications to all AIs and RIs via FIC distribution list and supervisors notifying supervised entities.
  - Improve coordination among authorities on PF and involve appropriate supervisors to better and proactively identify assets and funds held by designated persons/entities.
  - Build upon FIC framework to receive, share, and act on private sector information to better identify assets/funds of designated persons/entities.
  - Provide more detailed, sector-tailored written guidance on implementation (such as freezing) and continue outreach to sectors with higher exposure to PF activity.
  - Ensure and demonstrate through monitoring and enforcement that FIs, DNFBPs, and VASPs comply with obligations.

*Source: 1zafea2021001 - 221. The SIU also pursues recovery of State losses through its civil litigation remedies.*

### 235.      South Africa has only convicted one person for TF since the last ME in 2009 (See Box

### 1zafea2021001 - 235. South Africa has only convicted one person for TF since the last ME in 2009 (See Box

### TF Convictions, Prosecutions, and Case Outcomes
- South Africa has only convicted one person for TF since the last ME in 2009.
- Conviction and sentencing:
  - Henry Okah was convicted in South Africa in March 2013 on six counts filed under the POCDATARA for each of the bombings in Nigeria; a TF charge was included for each attack.
  - Okah was sentenced to an effective 24 year imprisonment for all the offenses he committed in relation to the two bombings.
  - South Africa has a maximum penalty for a TF conviction of 15 years.
  - When compared to a maximum penalty of 30 years for ML, it is noted that it is not possible to conclude that the sanction for TF is proportionate.
- Ongoing prosecutions:
  - As of the onsite, there was only one ongoing TF prosecution (see Box 11.1 — the Thulsie twins matter is currently awaiting trial).
  - The Thulsie twins were indicted on 12 charges under the POCDATARA (including TF) and one of fraud; assistance has been provided by Syria, Iraq, Kenya, Lesotho, UK, USA, and France.

### TF Identification and Investigation: Volume and Sources
- Low investigative conversion:
  - Between April 1, 2013 and March 31, 2018, three TF investigative dockets had been opened and one advanced to prosecution.
  - Law enforcement conducted 154 inquiries into potential national security activities over the five years to March 31, 2018.
- Source breakdown of the 154 investigative inquiries (Table 4.1):
  - Foreign Police Agency: 93 (60%)
  - Internal Information: 20 (13%)
  - FIC: 16 (10%)
  - DIRCO: 6 (4%)
  - Media: 6 (4%)
  - SSA / SA Intelligence Service: 3 (2%)
  - Interpol: 3 (2%)
  - Other (crime scene etc.): 3 (2%)
  - Criminal Intelligence Head Office: 2 (1%)
  - DoJ&CD (MLA): 2 (1%)
  - Total: 154 (100%)
- Requests to the FIC for terrorism-related intelligence over six years to March 31, 2019 (Table 4.2):
  - SAPS:DPCI – CATS: 314 total (years: 4, 30, 101, 4, 18, 157); Average: 52
  - SAPS:DPCI – PCMC: 4 total (years: -, 1, -, -, 1, 2); Average: 1
  - SAPS CI: 104 total (years: -, 3, 5, 22, 22, 52); Average: 17
  - SSA: 20 total (years: 2, -, 6, -, 2, 10); Average: 3
  - NPA:AFU: 4 total (years: 1, 1, -, -, -, 2); Average: 1
  - Total requests: 446; Average: 74
- Case closures and reasons (Table 4.3) — five years to March 31, 2019:
  - Unfounded/Undetected/Lack of Information: 102 (72%)
  - Disruptive Operation – Non-TF: 7 (5%)
  - Responded to a Foreign Request: 6 (4%)
  - Referred to Other Investigative Units: 5 (4%)
  - MLAT request not met: 5 (4%)
  - Alternative Charges Laid Non-TF: 4 (3%)
  - TF Docket Registered: 3 (2%)
  - NPA Declined to Prosecute: 3 (2%)
  - Terrorism Docket Registered: 3 (2%)
  - Other: 3 (2%)
  - Totals: 141 (100%)

### Assessment of Investigative Capacity and Practices
- Structural capacity:
  - South Africa has a trained and resourced specialized police section to address terrorism and TF cases (SAPS:DPCI – CATS) and a specialized prosecution unit (NPA:PCLU).
  - Police powers include interception of communications, undercover operations, and, through the FIC, live monitoring of suspect accounts.
- Operational shortcomings:
  - Despite specialized units and investigative powers, assessors concluded TF is not being effectively identified nor investigated.
  - Of 154 inquiry files, 141 (91%) were closed for various reasons.
  - 71 percent of inquiry files are closed due to lack of information to advance them, inability to detect any crime, or false leads.
  - Only three inquiries led to TF investigative dockets being registered; only one advanced to prosecution as of the onsite.
- Classification approach:
  - Authorities take a conservative approach to classifying politically motivated violent acts as terrorism and prefer to pursue acts as simple acts of violence rather than terrorist acts in some circumstances.
  - This conservative classification limits the ability to pursue TF investigations because there is no offense for financing simple acts of violence.

### Integration with National Strategies and Use of Alternative Measures
- National Counter-Terrorism Strategy (NCTS):
  - Only a summary dated 2013 was shared; an Implementation Plan with specific Action Steps exists and is updated annually.
  - One action item example: “Assess and report on the capacity of government to conduct financial investigations into terror financing” assigned to FIC to be completed in the 3rd quarter of 2016; no such report was provided to the assessment team.
  - The Strategy’s pillars focus on investigating terrorism and terrorists, border controls, intelligence assessments, multi-agency approaches, prosecution rates, and forfeiture of terrorist assets; there is no reference to forfeiture of assets held by terrorist financiers.
- Targeted financial sanctions and domestic designations:
  - Authorities do not consider administrative TFS designations as a relevant tool to fight TF; they favor obtaining compelling evidence and testing it in court before considering a designation under UNSCRs for TFS.
  - South Africa does not pursue domestic designations as an alternative measure where a TF conviction is not possible.
- Alternative measures and disruption:
  - South Africa has not demonstrated effective use of alternative measures where TF convictions are not possible.
  - A handful of inquiries were referred to other LEAs or dealt with by disruptive operations, but authorities could not elaborate on whether these were TF cases or whether alternative measures successfully disrupted TF activities.

### Effectiveness Findings, Conclusions, and Rating
- Key findings:
  - Given the risks identified by the authorities, the conviction of one person and one other prosecution in the past several years is not consistent with the country’s TF risk profile.
  - TF is not being effectively identified nor investigated; authorities failed to demonstrate identification of specific roles played by terrorist financiers.
  - The conservative approach to classifying politically motivated violent acts as terrorism negatively affects TF case numbers and international cooperation.
  - The low number of TF investigations and policy not to use domestic UN sanctions designations hinder using these tools as part of a broader terrorism strategy.
- Overall conclusions on IO.9:
  - The pursuit of TF is coordinated through the CTFC but is not properly integrated in the NCTS and authorities are failing to produce results reflective of the country’s identified TF risk.
  - South Africa has failed to demonstrate that it is effectively identifying, investigating, or prosecuting terrorist financiers or addressing TF through alternative measures.
  - The low level of viable investigations and prosecutions into TF is not consistent with the country’s recognized TF risk profile as a country with FTFs and from which terrorist groups are soliciting support and using as a transit point and a base for planning and logistics.
- Final rating:
  - South Africa is rated as having a low level of effectiveness for IO.9.

*Source: IMF assessment text provided in content unit 1zafea2021001 - 235.*

### 260.      Authorities have not implemented any designations adopted by the UNSC pursuant to

### 1zafea2021001 - 260.

### Implementation of UNSC Designations and Targeted Financial Sanctions (TFS)
- Authorities have not implemented any designations adopted by the UNSC pursuant to resolutions 1267/1289 and 1988 since July 2017.
- The last proclamation was signed on June 29, 2017 and published in the Official Gazette on July 14, 2017.
- No proclamation has been published since then; no designations or de-listings decided since then have been implemented.
- Over the period under review, no assets have been frozen pursuant to UNSCRs 1267/1988 and 1989 and subsequent resolutions.
- There is no provision establishing a mechanism to identify targets for designations and authorities have not demonstrated active consideration of whether targets under CTFC scrutiny meet UNSCR criteria for designation.
- South Africa has not proposed on its own initiative, nor co-sponsored, any person for designation, but has supported all listing proposals submitted to the UNSC.

### Mechanism for UNSCR 1373 and Legal/Scope Deficiencies
- To implement UNSCR 1373, authorities rely on a mechanism enabling a Court to order an ex parte freezing obligation for an indefinite duration (High Court based on application by the NPA).
- When a foreign request to freeze is received, the NPA assesses and notifies relevant agencies (FIC, SAPS, security services) who advise on whether to submit a court application.
- Authorities report no received or made foreign requests and have not made any designation on their own motion; these provisions have not been used in the context of UNSCR 1373.
- Major deficiencies:
  - An order can only apply to identified property in South Africa at the time of the order rather than to any asset of a designated person.
  - No general freezing order prohibiting all dealing with any asset of a designated person.
  - Freezing cannot be issued if there is no property located in South Africa at the time of the request; assets entering South Africa after the request are not covered.
  - Communication of High Court decisions is limited to affected parties; the FIC would contact other FIs only to identify (and not freeze for indefinite duration) other potential assets.

### Financial Institutions (FIs), DNFBPs, and TFS Compliance
- Larger FIs with international exposure:
  - Show good understanding of TFS obligations for TF and implement them proactively.
  - Driven by global policies or correspondent bank requirements; use screening mechanisms against international lists at onboarding and when lists are updated.
  - Do not rely on authorities’ information nor wait for national designation to implement TFS.
- Other FIs and DNFBPs:
  - Have limited understanding of TFS obligations for TF, largely due to lack of appropriate communication mechanisms.
  - Publication of proclamations under UNSCR 1267/1988 and 1989 is not systematic, creating uncertainty whether UN list changes create legal obligations to freeze in South Africa.
  - No active communications to obliged entities about list changes.
  - The “TFS list” on the FIC website does not apply for TF TFS and does not incorporate or match the “Consolidated List of Individuals and Entities Subject to Measures Imposed by the United Nations Security Council” published on the SAPS website for TF, which is not updated.
  - Differing listing mechanisms create confusion and existing guidance is not helpful.
  - For UNSCR 1373, there is no communication mechanism and authorities have not demonstrated active outreach to FIs and DNFBPs on TF TFS obligations.
- Supervisory activity:
  - Supervisors for FIs incorporate TF TFS in supervisory activities at market entry and during ongoing monitoring.
  - Supervisors assessed screening mechanisms for banks in 2014 and 2017; the SARB:PA noticed improvements but concluded in 2017 work remained to be done.
  - Up to 2019, nearly all SARB:PA fines related to deficiencies in TFS reporting.
  - Supervisory activities for TFS in other sectors remain nascent; difficult to confirm compliance of other FIs and DNFBPs.
  - There is no supervision of VASPs.

### Non-Profit Organization (NPO) Sector: Oversight, Risks, and Targeted Approach
- NPO sector overview:
  - Over 220,000 known NPOs operating in the country.
  - No central registration database; registration with the NPO Directorate at the DSD is voluntary.
  - Instances of multiple registrations and registrations with other government bodies to the exclusion of the NPO Directorate:
    - 2,500 non-profit trusts registered with the Master’s Office.
    - 6,700 non-profit companies registered by the CIPC.
    - 21,250 Public Benefit Organizations (PBOs) registered with the SARS.
- NPOTT review (established December 2018):
  - Reviewed the sector to identify high risk NPOs (registered and unregistered) but review did not focus specifically on TF abuse; included ML, PF, financial integrity, good governance and general regulation compliance matters.
  - The review identified approximately 5,000 organizations believed to be most at risk, but risks identified were not specific to TF abuse and failed to identify the specific subset/types of NPOs at risk based on characteristics and activities.
- Recognized TF risks to NPOs:
  - Many NPOs provide relief in conflict areas with terrorist entities present and could be exploited for TF purposes.
  - Large donations through regulated financial channels are not matched by oversight across the full cycle of NPO funding activities.
  - Ultimate beneficiaries of NPO funding are unaccounted for; no oversight to ensure funds are not diverted to support terror groups abroad.
  - South African NPOs have been involved in ransom negotiations via large payments contrary to UNSCRs.
  - NPOs process large amounts of cash and regularly transmit funds between jurisdictions; operate in a less regulated environment with weak administrative and financial management.
  - No mandatory registration requirements for NPOs, representing a vulnerability for deceptive NPOs to mask ill intent.
  - Regulatory framework is fragmented and lacks sufficient oversight mechanisms.
  - Lack of sufficient proactive interaction between government stakeholders impedes proactive TF case identification.
  - The DSD, main NPO regulator, lacks monitoring and investigative capacity related to national security; it is not part of the security cluster and does not consider national security risks.
  - Oversight mechanisms have inadequate capacity and insufficiently trained personnel to guard against TF abuse.
  - The NPO sector is generally not sufficiently aware of TF risks.
- Consequences:
  - Lack of a designated department or mechanism responsible for safeguarding the NPO sector against TF abuse hinders effective risk addressing.
  - NPOTT has identified steps to address TF risk but has not applied measures to mitigate identified risks nor begun specific monitoring of organizations deemed vulnerable.

### Deprivation of TF Assets and Instrumentalities
- National Counter-Terrorism Strategy (NCTS) omissions:
  - NCTS does not identify pursuit of terrorist financiers as an operational mitigant.
  - Strategy does not identify designation of terrorists, terrorist organizations and terrorist support networks as a tool to counter terrorism or TF.
- No specific approach or strategy exists to use TFS or related mechanisms to deprive terrorists of assets.
- Authorities favor civil and criminal confiscation processes over administrative TFS designations for depriving assets and instrumentalities related to TF activities.
- Use of non-conviction-based forfeiture mechanism (POCA, ch.6):
  - Authorities have used POCA ch.6 to target instrumentalities and specific tainted property associated with terrorist and related activity.
  - In practice, use has been limited relative to South Africa’s TF exposure: seized or confiscated TF-related assets in three instances.
  - Over the period under review amounts frozen, seized, or confiscated amounted to around R6 million ($408,000):
    - R4.5 million ($306,000) confiscated.
    - R1.5 million ($102,000) frozen or seized.
  - Case examples:
    - One case: preservation order under POCA, ch.6 followed by post-conviction confiscation (Okah case).
    - Second: freeze of assets stolen from kidnapping victims to impede their use for TF.
    - Third (Thulsie Twins): seizing proceeds and instrumentalities during investigation phase.
- Assessment:
  - These cases do not demonstrate active use of freezing mechanisms to preemptively deprive terrorists of assets and prevent fundraising.
  - Limited number of cases and low amounts are not in line with South Africa’s TF exposure.

### Consistency with Overall TF Risk Profile and Effectiveness
- Measures implemented for TFS and to combat NPO abuse are not in line with the TF risk profile indicating exposure to TF.
- Authorities have investigated financing activities to facilitate foreign terrorism including links to organized groups such as ISIL and have acknowledged facilitation networks and cells.
- South Africa has dealt with FTFs, including observing some returnees, yet measures taken do not reflect these activities.
- Overall conclusions on IO.10:
  - Terrorists are identified and deprived of resources and means to finance/support activities only to a negligible extent considering TF risk and monitored activities.
  - Use of TFS is not proactive nor used as a tool to mitigate TF risk (including for FTFs).
  - Major shortcomings hinder implementation of TFS without delay for UNSCR 1267 and appropriate identification/proposal of targets for designation.
  - Last time UNSCR 1267/1988 and 1989 and subsequent resolutions entered into force in South Africa was July 2017; this fundamentally hinders system effectiveness.
  - Mechanism to implement UNSCR 1373 is inconsistent with UNSCR requirements as it does not provide for a general freezing order.
  - South Africa has not identified subset of NPOs at risk of TF abuse based on characteristics/activities; the responsible government authority has not had TF training, applied measures to address risk, nor begun monitoring vulnerable organizations.
  - South Africa is rated as having a low level of effectiveness for IO.10.

### Implementation of TFS Related to Proliferation Financing (PF)
- Freezing regime for PF came into force in April 2019.
  - This was six months prior to the onsite.
  - All PF designations adopted by the UNSC before April 2019 have only been implemented in South Africa since the freezing regime entered into force.
- Since April 2019, South Africa began implementing R.7 processes for publishing updated sanctions lists, triggering prohibition on dealing with funds/assets of designated persons/entities.
- The prohibition obligation applies to all persons in South Africa (including VASPs).
- Implementation performance since April 2019:
  - Implemented TFS for PF fairly well, but improvements needed in communication reach and implementation without delay in all circumstances.
  - FIC provides a free searchable consolidated list for PF designations and offers automated email alerts upon amendments.
  - Between April 2019 and the onsite, 1,822 users had registered to the email alert, representing nearly five percent of AIs and RIs.
  - The FIC user guide on TFS searches is publicly available.
  - Supervisors do not notify supervised entities, limiting communication reach.
  - For existing UNSCRs, FIC issues Director’s notifications mostly within 24 hours after list changes; process longer over weekends and in a few cases took up to three to five business days.
  - For new UNSCRs, requirement for publication in the Gazette would take a matter of days, which is not without delay.
  - Overall: process used to implement PF-related TFS is without delay most of the time for updates to UNSCR lists but not when a new UNSCR is adopted.

_Italic: International Monetary Fund — Excerpt from the source content provided._

### 292.      As of the onsite and since April 2019, no PF-related assets had been frozen pursuant to

### 1zafea2021001 - 292.      As of the onsite and since April 2019, no PF-related assets had been frozen pursuant to

### Proliferation Financing (PF) implementation and detection
- As of the onsite and since April 2019, no PF-related assets had been frozen pursuant to UN designations in South Africa.
- Identification of assets and funds held by designated persons and entities is hindered by limited access to accurate and up to date beneficial ownership information (see IO.5), affecting capacity to identify use of legal persons and arrangements to evade sanctions.
- Specific coordination on PF is recent and at an initial stage but benefits from existing proliferation coordination mechanisms supporting early identification of proliferation. Authorities use a multi-agency approach to mitigate operational risk.
- Inter-departmental coordination links DIRCO, SAPS:DPCI, NPA, FIC and SARS with three nonproliferation control bodies focusing on export controls, dual goods nuclear items, trade and export controls through mandatory registration, brokering, freight forwarding and shipping services, and PF.
- SARS:Customs uses a proactive RBA involving intelligence information including related to high risk jurisdictions.
- Control bodies conduct inspections, outreach, and refer potential regulatory non-compliance to SAPS:DPCI and the NPA to decide on administrative or criminal charges.
- NPA trains LEAs and SARS:Customs on investigations to promote detection and investigation of WMD offenses.
- Regulators overseeing implementation by AIs and RIs, except the FIC, are not part of these groups, which limits early detection of PF activities.
- Historical effectiveness: South Africa successfully convicted individuals in 2007 for role in the A.Q. Khan network and obtained significant forfeitures of assets inside the country and abroad.

### Use of STRs and intelligence in PF detection
- South Africa developed a framework allowing FIC and LEAs to receive, share, and act on information gathered from the private sector.
- Authorities extended STR obligations to activities relating to contravention of the prohibition regime for PF, going beyond FATF standards.
- STRs for PF have proven useful; FIC operates a daily screening of its STR database against UNSCRs lists to strengthen detection capacity.
- Early detection of PF-related activities relies mostly on STRs and foreign intelligence. LEAs (NPA, SAPS:DPCI, NPA:AFU), intelligence agencies (FIC) and export control bodies coordinate in investigations.
- Three shared investigative cases demonstrate reactive investigations based on STRs and foreign intelligence. STRs were sent before entry into force of the reporting obligation.
- FIC conducted analysis contributing to investigations and referred matters to SAPS:DPCI and SSA. In one case, a team comprising NPA, SAPS:DPCI, FIC, NPA:AFU asset tracking and control bodies was formed. Two investigations ongoing; one found no PF involvement.
- South Africa has never co-sponsored nor proposed a designation to the UN, as no activity within scope of the UNSCR regimes was detected to the knowledge of authorities nor reported by foreign jurisdictions.

### Private sector understanding and compliance with PF-related TFS
- Despite extensive FIC outreach, understanding of and compliance with obligations remains uneven among FIs, DNFBPs, and VASPs.
- Larger materially important FIs with international exposure:
  - Show more developed understanding and implement appropriate screening measures commensurate with exposures.
  - Apply on-boarding and real-time screening of client base (including back book) and transactions against PF-related TFS lists.
  - From a materiality perspective, the banking arms of these groups represent 85 percent of total banking assets and their FSPs and investment scheme managers control around 20 percent and 27 percent of assets under management.
- Other FIs, DNFBPs, and VASPs:
  - Understanding is limited largely to screening obligations and reporting to FIC in case of a match; many do not screen against PF-related lists in practice.
  - Handling of identified assets on matches cannot be assessed due to no matches or potential matches found yet; some regulatory engagement and public awareness sessions have provided guidance.
- Supervision and compliance monitoring of PF-related obligations commenced only in April 2019; no supervision occurred before because no legal obligation was in place.
  - Supervisors assessed other UNSCR screening mechanisms for banks in 2014 and 2017, noting a reduction of false positives/alerts but concluding many FIs required further improvements as of 2017.
  - Current level of compliance not possible to assess but likely reflects uneven private sector understanding.

### Outreach, guidance, and supervision
- In 2017, FIC incorporated public awareness sessions on PF, including TFS, into engagement with AIs and RIs (excluding VASPs). Sessions focused on revised legal framework obligations, case studies, and sanctions evasion techniques.
- March 2018 workshops with public and private stakeholders discussed PF challenges; Royal United Services Institute shared findings on PF risks and compliance programs. As of the onsite, lessons learned had not yet resulted in concrete developments; authorities planned a revised and more detailed GN on implementation of UNSCRs related to PF and intended to reflect those in a future NRA for PF.
- Supervision and compliance monitoring of PF-related obligations is at an early stage (commenced April 2019); no sanctions applied so far. Supervisors do not perform PF-related inspections; supervision limited to checking how some banks screen against TFS lists. Supervision of VASPs does not occur.

### Assessment and overall conclusion on IO.11
- South Africa has implemented fairly well PF-related TFS since April 2019, consistent with its exposure to PF.
- Implementation would occur without delay most of the time when updating existing UNSCRs’ lists, but is unlikely to be without delay for any new UNSCR.
- Detection and investigations of PF-related activities are to some extent ongoing, relying mostly on STRs and foreign intelligence.
- Authorities’ proactive ability to identify PF-related assets is challenged by uneven private sector understanding of PF obligations and limited access to accurate and up to date BO information.
- Overall level of compliance of FIs, DNFBPs, and VASPs cannot be demonstrated but likely reflects uneven private sector understanding; only larger FIs with international exposure have more developed understanding and likely appropriate compliance.
- Guidance documents lack sufficient detail to guide entities in implementing PF TFS. Supervision and compliance monitoring remain at an early stage; no sanctions for non-compliance with new PF obligations have been applied.
- Rating: South Africa is rated as having a moderate level of effectiveness for IO.11.

### Preventive measures — Key findings and recommended actions (IO.4 relevance)
Key Findings
- The larger banks show a developed understanding of ML risks and seem better at implementing mitigating measures commensurate with their risks than most smaller FIs, which are rule-based compliance focused rather than identifying and understanding risks.
- AIs understand and mitigate TF risk commensurate with their risks to some extent, primarily due to a lack of information from the authorities.
- Overall, DNFBPs’ understanding of ML risks and AML/CFT obligations is underdeveloped and mitigating measures are not risk-based, with casinos as a positive outlier.
- Basic CDD is satisfactorily applied by many AIs, but AIs only apply BO requirements to some extent, which is inadequate given the vulnerability of legal entities. Larger banks are better at applying such requirements but remain challenged at obtaining sufficient BO information. DNFBPs and FIs with an underdeveloped understanding conduct ongoing monitoring only to some extent.
- Limited implementation of the RBA by most AIs causes insufficient application of enhanced measures. Targeted measures to address high-risk scenarios, such as use of cash and corruption, are applied to some extent mainly by larger FIs. A deficient legal definition of PEPs limits effectiveness. AIs play down risks of operating internationally.
- Larger banks and ADLAs meet reporting obligations to a large extent; most other sectors fail to do so commensurate with their risk profiles. Some high-risk sectors rarely file STRs.
- FIs apply internal controls and procedures depending on their ability to apply an RBA, but concerns exist that larger banks’ group controls may not be adequately applied in their foreign entities.
- Some financial sectors and DNFBPs, including CSPs and DPMS, and VASPs are not covered under the AML/CFT regime, save for a general reporting obligation as a “business.”

Recommended Actions
- Ensure AIs conduct business risk assessments systematically while including a sufficient range of inherent risk factors (TF, corruption, geographical risks, use of cash) and make RMCPs dynamic exercises beyond rule-based compliance. Authorities should provide better guidance.
- Ensure AIs significantly improve application of all CDD obligations, especially ongoing due diligence and BO requirements, and provide better access to reliable BO information.
- Analyze ways to substantially improve information on domestic PEPs and support AIs in identifying PEPs across state, provincial, and municipal levels; rectify legal definition of PEP in line with R.12.
- Ensure AIs beyond larger banks and ADLAs, especially in high-risk sectors, file more STRs in line with risk profiles.
- Larger banks should effectively implement adequate AML/CFT group controls in the operations of their foreign entities.
- Include sectors currently out of scope—particularly CSPs, accountants, DPMS, and VASPs—under AML/CFT requirements.

### Preventive measures — Immediate Outcome 4 (summary points)
- Focus areas: larger banks (material and risk perspectives), securities sector (FSPs and CIS managers) (material perspective), high-risk sectors: estate agents and attorneys, and casinos.
- Some FIs and DNFBPs (including CSPs and DPMS) and VASPs are not subject to most AML/CFT obligations; active informal MVTS network is a concern.
- RBA to CDD, business risk assessments, and many preventive obligations are relatively new (October 2017) and enforced since April 2019. Larger banks began implementing measures prior to 2019 due to international exposure.
- Larger banks and large insurance companies show a developed understanding of ML risks; other FIs have a basic understanding and are predominantly rule-based.
- Larger banks’ business risk assessments:
  - Undertaken before legal obligation; part of global group initiatives.
  - Conducted predominantly from a client risk perspective; product/service and international operation risks not adequately understood.
  - Most assessments not systematically updated and do not sufficiently capture emerging risks; they are static and reactive.
- Other FIs:
  - Basic understanding; compliance-focused; RMCPs reflect client risk but consider other risk factors only to a limited degree.
- VASPs (CASPs) not regulated but three largest VASPs generally understand AML/CFT obligations and show proper understanding of ML risks (high volumes of deposits; sending/selling behavior in short intervals from rural areas logged from foreign jurisdictions such as China; funds not aligning with client profile). Top ML threats: darknet transactions, fraud, child abuse, pornography, illegal gambling.
- Among regulated DNFBPs, only casinos understand AML/CFT obligations to a large extent; estate agents and attorneys rely heavily on other partners in the AML chain and face challenges understanding amended FIC Act requirements and RMCP obligations.

*Source: 1zafea2021001 - 292. As of the onsite and since April 2019, no PF-related assets had been frozen pursuant to*

### 318.      DNFBPs’ have an undeveloped understanding of ML risks that varies significantly.

### DNFBPs’ have an undeveloped understanding of ML risks that varies significantly

### Understanding of ML and TF risks
- DNFBPs: casinos have better ML risk awareness; estate agents and attorneys have "basic to limited" knowledge of ML risks based on vulnerabilities such as the use of cash and failure of controls.
- ML threats (e.g., corruption, environmental crimes) are recognized to a much lesser extent by DNFBPs.
- DNFBPs do not perform ML risk assessments that include a sufficient range of inherent risk factors and seem limited to assessment of required controls.
- Casinos: better in assessing ML risk but need further steps to improve their RBA.
- Lack of adequate supervision compounds weaknesses for attorneys.
- Estate agents and attorneys do not appear to adequately identify ML risks associated with real estate.
- TF risk: only "to some extent" understood by AIs, mainly referring to typologies and obligations and often primarily based on TFS screening obligations.
- FIs may apply groupwide programs and refer to global/regional developments but do not adequately identify/understand TF risk in the context of South Africa.
- Limited attention to TF risk by the authorities contributes to weak understanding.

### Application of risk-mitigating measures (RMCPs)
- Larger banks: apply mitigating measures commensurate with risks "to some extent".
- Majority of AIs: do not apply commensurate measures, failing to adequately assess ML/TF risks.
- RMCPs reviewed are predominantly rule-based policies/procedures manuals, not demonstrated to be founded on adequate entity risk assessments.
- Predominant focus on rule-based compliance rather than mitigation of ML/TF risk (example: exclusive focus on complying with FIC Act PEPs requirements rather than proactive monitoring of client relationships and transactions).
- Only some banks apply risk-based mitigating measures through monitoring or surveillance models aligned with jurisdiction-specific corruption threats.
- Cash risk: most AIs do not take focused mitigating measures for cash despite it being an important vulnerability; only banks take some measures.
  - One bank is limiting or exiting cash business; as a result, only "two percent" of the total value payment flow of this market participant is still in cash.
- Most AIs indicate they mitigate risks associated with the use of cash by filing CTRs.

### Client Risk Assessment and CDD implementation
- Many FIs assess client risk when developing RMCPs and perform different levels of CDD per client risk rating, but doubts exist about effective RBA implementation.
- AIs consider a limited set of risk factors; PEP status is often the only or one of few factors at onboarding.
- Very low share of clients categorized as high and very high risk at larger banks; enhanced measures may not be applied from onboarding onwards.
- Basic CDD and record-keeping measures are generally applied by many AIs to a large extent; larger FIs have enhanced systems for identifying/verifying clients and sources of funds/wealth. Digital ID initiatives at larger banks are positive.
- Beneficial Ownership (BO) requirements:
  - Banks undertake BO enquiries seriously but implement BO requirements "to some extent".
  - BO requirements became enforceable in 2019; SARB:PA and FIC observe BO recorded by FIs is not always a natural person.
  - Challenges stem from lack of transparency in corporates; banks use public information where available but note limitations and reliance on client self-declaration.
  - Some FIs request group structure, financial statements, voting rights, attestations from accountants/auditors; some obtain Master’s Office information for trusts (not always complete).
  - Only some FIs (including some banks) explicitly apply refusal to onboard when submitted BO information is insufficient.
  - The FIC Act does not address identification/verification of the natural person controlling an individual; assessors doubt adequate measures are taken.
- Methods to assess indirect influence: some banks rely on ongoing monitoring, network analysis, and financial flows; larger banks beginning to implement behavioral analytics.
- FSPs, CIS managers, attorneys, estate agents: do not yet adequately apply CDD measures since obligations fully enforced only since April 2019.
  - Prior exemptions (2017) allowed reliance on primary AIs; these secondary AIs now struggle to implement CDD and exercise judgment on sufficiency of information.
  - Estate agents are transaction-focused and often rely on others (banks, attorneys) to conduct CDD; they do not identify sellers who are not their customers.
- Ongoing monitoring:
  - Larger banks, insurers, and ADLAs (with developed risk understanding) are more effective in ongoing monitoring; transaction monitoring combined with network analysis is used.
  - Some banks’ systems generate a fair range of alerts leading to client risk profile adjustments and reporting.
  - Smaller FIs (including FSPs, CIS managers) and casinos: ongoing monitoring conducted to some extent but predominantly for compliance and CTR purposes.
  - Most FIs’ monitoring focuses on detecting transactions reaching the threshold of R25,000 for CTR reporting.
  - Ongoing monitoring by DNFBPs other than casinos is negligible due to underdeveloped risk understanding and obligations.

### Application of Enhanced Due Diligence (EDD) measures
- (a) PEPs
  - Systems/measures to determine PEP status are effective "to some extent"; most AIs take measures as prescribed by FIC Act.
  - Legal definition of PEP is deficient (only includes persons holding such position in the preceding 12 months).
  - Only FIs with developed risk understanding go beyond strict legal requirement and apply a broader approach.
  - Domestic PEPs at provincial/municipal level are not consistently identified because screening systems/databases may not include them.
  - Screening is predominantly ad hoc (e.g., FIC or Zondo Commission) rather than systematic at onboarding or ongoing basis — meaning unidentified PEPs may exist.
  - When a client is determined to be a PEP, AIs "seem to effectively take enhanced measures to a large extent" (establishing source of income/wealth, senior management approval, enhanced monitoring).
- (b) Correspondent Banking Relationships (CBRs)
  - Most banks apply enhanced measures to mitigate CBR risks "to some extent", often mirroring overseas partners rather than actively managing exposure.
  - De-risking is a concern; some larger banks have de-risked CBRs in the region, while others perform face-to-face onboarding and periodic review and treat such relationships as higher risk to perform EDD "to some extent".
- (c) New Technologies / VASPs and FinTech
  - Most banks do not take enhanced measures for VASPs and de-risk VASPs because VASPs are unregulated/unsupervised in South Africa.
  - As of the onsite, three banks accept VASPs as clients and identify them as high risk; other banks avoid exposure including refusing onboarding.
  - Enhanced measures are adequately taken to mitigate risk that bank clients might use accounts to trade in crypto assets.
  - Banks have incorporated FinTech products in line with RBAs to boost financial inclusion; product offerings are subject to conditions and transaction thresholds based on ML risk assessment; new product launches trigger business risk assessment refresh.
- (d) Wire Transfers
  - Banks apply specific measures regarding wire transfers "to a large extent", despite needed adjustments to CMA EFTs and deficiencies in capturing beneficiary information.
  - A deficiency concerning EFTs between South Africa and CMA countries (treated as domestic rather than cross-border) was identified and being addressed as of the onsite with additional systems and rules to treat them as cross-border EFTs; effectiveness cannot yet be established.
  - SARB confirms results need to be assessed through supervision. Some banks have de-risked CMA-related EFTs.
  - CMA transaction statistics (2018, excl. card transactions):
    - CMA inwards total: R 82.8 billion ($ 5.8 billion), 133,190 transactions, Average Transaction Value R 622,419 ($ 40,528).
      - Lesotho inwards: R 14 billion ($ 1 billion), 63,142 transactions, Average Transaction Value R 221,722 ($ 15,437).
      - Namibia inwards: R 45 billion ($ 3 billion), 21,039 transactions, Average Transaction Value R 2,138,885 ($ 139,370).
      - Eswatini inwards: R 23.8 billion ($ 1.7 billion), 49,009 transactions, Average Transaction Value R 485,625 ($ 31 621).
    - CMA outwards total: R 136 billion ($9.5 billion), 658,794 transactions, Average Transaction Value R 206,438 ($ 13,442).
      - Lesotho outwards: R 12 billion ($ 0.8 billion), 611,741 transactions, Average Transaction Value R 19,616 ($ 1,277).
      - Namibia outwards: R 107 billion ($ 7.4 billion), 37,054 transactions, Average Transaction Value R 2,887,677 ($ 188,026).
      - Eswatini outwards: R 16 billion ($ 1.1 billion), 9,999 transactions, Average Transaction Value R 1,600,160 ($ 104,191).
  - SARB:PA identified issues with capturing originator’s physical address on cross-border EFTs and uncertainty that required originator information in domestic (including CMA) EFTs can be provided within three days.
  - VASPs are not subject to EFT requirements and do not voluntarily apply relevant requirements.
- (e) TFS-TF (Targeted Financial Sanctions related to Terrorist Financing)
  - AIs indicate screening clients at onboarding and transactions, but there is limited proof of effective implementation.
  - AIs claim to apply screening and report hits to the FIC and to freeze funds until further notice, but no funds had been frozen up to the end of the onsite and no evidence (false positives, monitoring/audit reports) was shared with assessors.
  - SARB:PA found improvements in sanction screening since 2014 but many FIs required further improvements as of 2017.
  - Nearly all monetary sanctions issued to FIs by SARB:PA up to 2019 related to deficiencies in TFS controls.
  - No indications VASPs are adequately implementing TFS controls.
- (f) High-Risk Countries
  - Many AIs and DNFBPs apply EDD only regarding jurisdictions listed by FATF or communicated via the FIC website or jurisdictions related to TF sanctions.
  - Only a small number of FIs (larger banks and larger ADLAs) classify jurisdictions with strategic AML/CFT weaknesses as higher risk based on their own assessment.
  - AIs tend to underestimate risks of operating internationally (particularly in Africa) and therefore do not initiate EDD to mitigate these risks.

### Reporting obligations, tipping off, and reporting performance
- Larger banks and ADLAs meet ML reporting obligations to a large extent; other high-risk sectors fail to report commensurate with their risk profiles.
- s.29 reports in 2018/2019:
  - Banks reported 175,580 s.29 reports.
  - ADLAs reported 96,748 s.29 reports.
  - These represent 59 percent and 37 percent, respectively, or 96 percent of the total number of s.29 reports filed in this period.
  - This equates to an average of 5,164 s.29 reports per bank and 5,691 per ADLA.
  - Reporting patterns vary materially across banks:
    - One (top 10) bank files around 450 s.29 reports a year.
    - Another bank files around 40,000 s.29 reports a year.
  - From a risk perspective, these outcomes do not align with expectations that higher-risk banks should file more reports than lower-risk banks of similar size.
- Materiality perspective: FSPs and CIS managers are expected to file more reports than currently reported.
- DNFBP reporting:
  - Casinos are the best reporters among DNFBPs.
  - Estate agents, attorneys, and TSPs file a very low number of reports.
  - Underreporting may stem from underdeveloped understanding of ML/TF risks and obligations and absence of effective supervision.
- VASPs file STRs to some extent.

*Source: 1zafea2021001 - 318.      DNFBPs’ have an undeveloped understanding of ML risks that varies significantly.*

### 341.      FIs are improving their transaction monitoring systems to disclose suspicious

### 341.      FIs are improving their transaction monitoring systems to disclose suspicious

### Transaction monitoring systems and reporting behavior
- FIs are improving automated transaction monitoring systems to disclose suspicious transactions in a risk-sensitive manner.
- Failures identified: parameters often set to vendor settings and insufficiently adjusted to risk profiles of clients and transactions.
- Authorities issued Directive 5 of 2019 (FIC Directive 5 of 2019 on the usage of an automated transaction monitoring system...), and FIs were in the process of implementing such guidance as of the onsite.
- Observed compliance mindset: many FIs (and DNFBPs) indicated they consider themselves compliant once they file CTRs correctly, without paying sufficient attention to potential suspicions.
- Smaller FIs often use less efficient manual transaction monitoring systems.
- Reporting types referenced include STRs, SARS, TFTRs, TFARs, and batch reporting.

### Volumes and quality of reports (Table 5.3 highlights)
- Source: The FIC.
- Grand Total (five years ending March 31, 2019): 977,485 reports; 100.00% of total.
- Total Financial Institutions (five-year totals and share):
  - Bank: 578,209 (59.15%); Reports per AI/RI (average) 5,164.
  - ADLA: 360,655 (36.90%); Reports per AI/RI (average) 5,691.
  - Postbank: 506 (0.05%); Reports per AI/RI (average) 363.
  - Mutual Bank: 170 (0.02%); Reports per AI/RI (average) 23.3.
  - Authorized Exchange User: 269 (0.03%); Reports per AI/RI (average) 0.7.
  - CIS managers: 218 (0.02%); Reports per AI/RI (average) 0.5.
  - FSP: 5,868 (0.60%); Reports per AI/RI (average) 0.2.
  - Ithala: 2 (0.00%); Reports per AI/RI (average) 1.
  - Long-term insurers: 429 (0.04%); Reports per AI/RI (average) 2.6.
  - Money Lender Against Securities: 21 (0.00%); Reports per AI/RI (average) 0.1.
- DNFBPs totals and examples:
  - Total DNFBPs (five years): 6,286 (0.64%).
  - Casinos: 4,675 (0.46%); Reports per AI/RI (average) 46.97.
  - Gambling (excl. casinos): 655 (0.08%); Reports per AI/RI (average) 0.07.
  - Estate agents: 99 (0.01%); Reports per AI/RI (average) 0.002.
  - Attorneys: 686 (0.07%); Reports per AI/RI (average) 0.02.
- Other sectors:
  - MVDs: 24,663 (2.52%); Reports per AI/RI (average) 2.6.
  - Total Other Sectors: 24,852 (2.54%).
- Note: For 2015 and 2016 the STRs filed by casinos are included in the broad gambling category.

### Quality assessment of reporting
- According to the FIC:
  - Best quality reports: larger banks (but still need improvement).
  - Worst quality reports: attorneys and estate agents.
- Trend: volume of reports has decreased over the last two years, while quality has gone up (per the FIC).
- Areas for improvement:
  - Banking sector: provide better information to link both ends of the transaction.
  - ADLAs: include more context in reports.
  - Estate agents: disclose information on the person(s) buying property when the buyer is a corporation or complex structure.
  - Attorneys: improve disclosure on transactions going through their trust accounts.

### Tipping-off and information sharing issues
- No issue identified with regard to tipping off.
- Many FIs cite problems sharing client and transaction-related information with other FIs (even within the same financial group) based on a strict legal interpretation of the FIC Act tipping-off prohibition.
- Reported obstacle: the POPI Act does not allow adequate exchange of information for effective transaction monitoring unless considered processing to comply with obligations imposed by law; this creates legal uncertainty because essential AML/CFT obligations are imposed by secondary legislation (regulations and directives).
- Planned mitigation: the financial sector, in cooperation with regulators, intends to launch a public private financial information sharing partnership (SAMLIT).

### Internal controls, compliance functions, and group-wide application
- Internal controls and procedures are generally applied depending on ability to apply an RBA; where applicable, this is done at group level.
- Most AIs have compliance officers; DNFBPs (except large casinos and smaller nonbanking FIs) have problems establishing independent compliance functions due to size and limited knowledge.
- Some FSPs outsource compliance; others operate with no compliance function.
- Banks generally have implemented a Three Lines of Defense model attributing an independent monitoring function to compliance; most banks provide direct reporting lines from compliance to the board.
- Some larger banks’ multiple compliance committee layers may block effective reporting and hinder senior management engagement.
- Implementation weaknesses at smaller banks: understaffing, unsophisticated monitoring systems, and an inadequate RBA.
- All larger FIs and DNFBPs employ an independent audit function, most performing AML/CFT-related audits yearly; focus of third-line activities may be limited by a less developed RBA.
- Concerns about adequacy of controls at subsidiaries and branches abroad; assessors could not establish adequacy beyond self-declared strength of group-wide programs.
- Supervisors have performed a limited number of onsite inspections at subsidiaries and branches abroad; inspections were conducted as stand-alone rather than as part of consolidated group supervision.
- AML/CFT-related training is organized by AIs with a dedicated compliance function, but assessors doubt adequacy of training focused on ML/TF risks and RBA where RBA understanding is underdeveloped.

### Overall conclusions on IO.4
- FIs overall show an acceptable understanding of their AML/CFT obligations.
- Larger banks: developed understanding of ML risks and better implementation of mitigating measures commensurate with risks.
- Smaller FIs: basic understanding of ML risks, transitioning from a rule-based approach to an RBA.
- Estate agents and attorneys: underdeveloped understanding of risks and obligations, concerning given South African ML typologies.
- Some potentially high-risk sectors are not fully AML/CFT regulated and supervised.
- TF risk: understood to some extent.
- AIs apply basic CDD measures to a large extent; all challenged to implement BO requirements adequately.
- Larger banks and ADLAs meet reporting requirements to a large extent; other high-risk and materially important sectors underreport substantially.
- Concerns regarding determination of PEP status and BO identification due to a deficient legal definition.
- Assessors emphasize the need for larger banks to adequately apply group-wide AML/CFT programs and controls at subsidiaries and branches abroad.
- Rating: South Africa is rated as having a moderate level of effectiveness for IO.4.

### Supervision — Key findings
- Fit and proper criteria often do not apply to beneficial owners; most regulators do not conduct criminal checks or verify self-declarations.
- Unlicensed cross-border MVTS are not being systematically identified, sanctioned, or removed from the market.
- Supervisors’ understanding of ML risks varies:
  - SARB:PA has relatively good understanding of sector-level risks, followed by SARB:FinSurv.
  - Other supervisors have limited or negligible understanding of risks in high-risk DNFBP sectors.
  - Supervisors understand AML/CFT controls better than inherent and residual ML/TF risks; TF risk understanding is very limited.
- SARB:PA’s supervision of materially important banking sector checks AML/CFT compliance thoroughly but not yet using a proper RBA.
- SARB:FinSurv’s inspections adequately cover ADLAs but are based on risks only to a limited extent.
- For many supervisors, inspections are too infrequent or rare to be effective; attorneys are subject to essentially no AML/CFT oversight.
- Inspections focus on presence of basic controls rather than soundness/effectiveness of AML/CFT programs.
- FSCA and EAAB effectiveness hampered by severe lack of resources.
- SARB:PA and FSCA coordinate/share AML/CFT information but do not coordinate supervision of FIs in different sectors within the same group or their inspections.
- SARB:PA has imposed remedial actions and sanctions against banks, but penalties have not always been proportionate or dissuasive.
- Most other supervisors apply remedial actions; sanctions often too low and infrequent to be dissuasive or effective.
- Enforcement of the amended FIC Act only started in April 2019; supervisory impact demonstrating improved compliance with new risk-based obligations was not demonstrated.
- FIC provides a wide range of AML/CFT guidance and conducts national outreach; limited information provided to help private sector identify and understand ML/TF risks.
- Some financial sectors, DNFBPs including CSPs and DPMS, and VASPs are not subject to most AML/CFT obligations or supervision; their risks are not understood or mitigated.

### Supervision — Recommended actions
- Subject beneficial owners to fit and proper tests and verify directors, senior managers, beneficial owners or their associates are not criminals as part of market entry controls; apply upon renewal and on an ongoing basis.
- Proactively identify and address unlicensed cross-border MVTS through sanctioning, removal, or bringing them into the AML/CFT framework through licensing or registration; providers of domestic MVTS should be subject to licensing or registration.
- All supervisors should improve understanding of ML/TF risk, particularly inherent and residual risks for sectors and institutions, including through collecting and analyzing inherent risk information.
- SARB:PA and SARB:FinSurv should prioritize and scope onsite inspections on the basis of ML/TF risk informed by offsite monitoring and previous inspection findings; all supervisors should follow this approach.
- SARB:PA should ensure higher-risk FIs are inspected with more frequency consistent with their risks.
- During onsite inspections, supervisors should focus on effectiveness of controls, including obligations to obtain and hold accurate and up-to-date information on beneficial owners of companies and trusts.
- Financial supervisors should supervise financial groups for AML/CFT on a consolidated basis, including international operations, and coordinate supervision of FIs in different sectors that belong to the same group.
- Ensure oversight level of FSPs (Cat II), CIS managers, attorneys, estate agents, and TSPs is commensurate with ML/TF risk profiles, including substantially increasing supervisory resources and capacity of the FSCA, the EAAB, the Legal Practice Council (LPC), and the FIC.
- All supervisors should use a full suite of enforcement measures including monetary penalties to sanction AML/CFT breaches, dissuasive and proportionate to size of the entity and severity of breaches.
- Provide more sector-specific guidance (including typologies) to help the private sector identify and understand ML/TF risk.

### Licensing, registration, and market-entry controls (selected details)
- Market entry control robustness varies significantly by sector; fit and proper criteria often do not cover beneficial owners.
- Most regulators require a declaration of previous convictions, but no independent verification is done.
- SARB:PA market entry controls:
  - Significant shareholders (owning 15 percent or more) must be fit and proper (may not reach beneficial owner level); development of criteria was ongoing (jointly with the FSCA) as of the onsite.
  - For directors or executive officers subject to existing fit and proper criteria, SARB:PA relies on self-declarations of previous convictions without verifying with LEAs.
  - Until 2019, SARB:PA primarily used open source searches for negative media coverage for licensing assessments.
  - In 2019, SARB:PA began engaging with the FIC as part of licensing, screening for PEPs and TFS listings, and requesting information from international counterparts as necessary.
  - From 2014 to 2019, SARB:PA received 11 applications for new licenses or acquisition of banks: approved 5, rejected 2, and 4 pending.
  - SARB:PA conducted due diligence on a proposed new beneficial owner and rejected the application based on links to “State capture”.
  - SARB:PA rejected appointment of a senior person having a criminal record to a cooperative bank.
  - SARB:PA investigated 156 illegal deposit-taking schemes between 2014 and 2018 via its Illegal Deposit Taking Unit.
- Concerns remain about robustness of safeguards to prevent criminality from operating in the banking sector on an ongoing basis.

*Source: Chapter content from the IMF assessment provided in the supplied PDF content.*

### 354.      The SARB:FinSurv approves ADLA applications if the shareholders (that may not be

### 354. The SARB:FinSurv approves ADLA applications if the shareholders (that may not be natural persons) and directors are deemed to be fit and proper

### Fit-and-proper, licensing, and enforcement findings
- SARB:FinSurv approves ADLA applications if shareholders (that may not be natural persons) and directors are deemed to be fit and proper; these controls do not apply to beneficial owners or senior managers.
- SARB:FinSurv requires police criminal clearance certificates for applicants and conducts screening for TFS status.
- Out of the 24 applications for ADLA received between 2014 and 2018, 1 was declined in 2017 for fit and proper concerns in respect of 1 shareholder who had previously submitted fraudulent financial statements resulting in the withdrawal of the authorization of that ADLA.
- Reports of unlicensed cross-border MVTS activity are referred to SAPS but were not often actioned.
- Overall, the authorities could not demonstrate that unlicensed market participants are being effectively identified and sanctioned.

### Comparable weaknesses across supervisors and sectors
- FSCA market entry controls in the securities sector:
  - Requires a self-declaration of previous convictions by directors, members, partners, and trustees (“key individuals”); shareholders and beneficial owners are not subject to this disclosure.
  - In the FSP sector, the FSCA does not verify self-declarations.
  - In the CIS manager sector, self-declarations are supported by a police clearance certificate.
  - From 1 April 2014 to 31 March 2019 the FSCA authorized 6,918 key individuals in the FSP sector, of which 44 (0.64 percent) were later debarred for honesty and integrity issues.
  - To apply for authorization as an AU of the JSE, a criminal self-declaration from directors and shareholders with 10 percent ownership or higher must be provided, but this is not verified.
- Casinos licensing:
  - Licensing framework appears solid, but fit-and-proper checks (including on groups) are unclear and PLAs use inconsistent criteria.
  - Some PLAs validate self-declarations, but verification methods and consistency across PLAs are unclear.
  - Between 2016–2019, one license application was rejected as a result of a fraud conviction of a key individual.
  - PEP status is considered; PLAs and LEAs actively work together to shut down illegal gambling ventures including those online.
- Other DNFBP sectors:
  - Market entry controls are inadequate for preventing criminal elements in estate agents, TSPs, and attorneys.
  - Regulators generally rely on self-disclosure without verification; criteria used for attorneys and TSPs are unclear.

### Supervisors’ understanding and identification of ML/TF risks
- General:
  - Level of identification and understanding of ML/TF risks varies by supervisor; SARB:PA demonstrates the strongest understanding at sector and institution levels.
  - Interim SRAs were concluded by the SARB:PA, the SARB:FinSurv, the FSCA, and the FIC (on several DNFBP sectors) shortly before the onsite and fed into the NRA.
  - DNFBP supervisors were not involved in formulation of SRAs for their sectors.
- SARB:PA:
  - Relatively good understanding of ML risks for banks at the sector level; understanding of TF risks is underdeveloped.
  - Uses a risk matrix (since 2016) to risk-rate banks; matrix identifies high-risk customers, products and services, and delivery channels (including PEPs, corporates, non-residents, private banking, cross-border wire transfers, trade finance, online banking).
  - No geographic risks identified.
  - Matrix inputs primarily drawn from prudential returns rather than systematic information gathering on ML/TF inherent risks; matrix does not consider TF risks beyond controls that apply to both AML and CFT.
  - Matrix generated first set of risk ratings in 2016 and updated once in 2019.
  - As of the onsite: 4 banks rated very high for ML/TF risk (the “big four”), 3 banks rated high, and 27 rated medium. The three mutual banks were all rated medium.
  - The bank revealed to be involved in “State-capture” was risk-rated medium, even after concerns had come to light.
  - For life insurers: SRA concluded sector is at medium risk of being abused for ML/TF; SARB:PA had not yet risk-rated institutions as of the onsite.
- SARB:FinSurv:
  - Some understanding of ML risks in the ADLA sector; TF understanding limited to controls.
  - First ML/TF SRA of ADLAs completed in 2019, focused on compliance with legal obligations.
  - Since April 2019, SARB:FinSurv implemented a risk matrix to risk-rate ADLAs’ branches (not entities) for AML/CFT and exchange controls.
  - Matrix considers limited inherent ML risk factors: customers (PEPs, walk-in customers), products and services (transfer versus exchange), geographic locations (airports, border areas, etc.). No specific TF threat consideration.
  - Quality of controls assessed primarily based on findings of previous inspections; no inputs from offsite analysis.
- FSCA:
  - Developing understanding of ML/TF risk in securities sector at sector level; not at entity level.
  - Conducted first SRA considering ML risks from threats and vulnerability perspectives; methodology has shortcomings (e.g., relying primarily on reporting statistics).
  - Does not rate entities for ML/TF risks; assessments of FSPs’ conduct-related risks consider AML/CFT controls only to a limited extent (including AML/CFT controls with a negligible weight of three percent).
  - FSCA is taking steps to set up an integrated AML/CFT unit to conduct specific ML/TF risk assessment for all sectors.
  - JSE rates AUs for market and ML/TF risks with a 50 percent weight for each; ML/TF risks measured mainly by quality of controls learned in previous inspections.
- FIC:
  - Understanding of ML/TF risk in supervised FI and DNFBP sectors is driven by use of cash (including CTR reporting) and entities’ FIC registration status.
  - Interim SRAs completed in April 2019 on public FIs, money lenders against securities, TSPs and MVDs informed sector-level understanding.
  - MVDs and KRDs considered high risk due to cash-intensive nature and limited preventive obligations; TSPs rated medium risk.
  - FIC developed a risk matrix to assess risks of MVDs and KRDs at an institutional level, but only a portion are risk rated. Matrix includes some inherent risk factors (geographic and product risk) but simplistic; assessment of controls narrowly focused on CTRs and FIC registration status.
  - TSPs and other sectors supervised by the FIC are not risk rated nor is risk understood at an institutional level.
- DNFBPs:
  - Estate agents: EAAB views estate agents as high-risk; considers turnover, value of commissions, and complaints to identify higher-risk estate agents; no formal risk matrix.
  - Casinos and attorneys: supervisors understand risks to a much lesser or negligible extent.
  - No DNFBP supervisors demonstrated understanding of TF risk.

### Risk-based supervision, inspection frequency, and supervisory practices
- Supervisors generally are checking AML/CFT compliance but are not prioritizing or tailoring supervisory engagement on an ML/TF risk basis, partly due to weak institution-level risk understanding.
- Except for ADLAs, inspections are too infrequent across sectors to align with each sector’s size and risk.
- Supervisors do not systematically supplement onsite programs with offsite monitoring or scoping for targeted inspections.
- With the exception of SARB:PA, supervisors generally use a tick-box approach to test presence of controls rather than the soundness of AML/CFT programs.
- SARB:PA and FSCA started coordinating on AML/CFT and sharing high-level information in 2018; not yet sharing specific entity-level information or conducting joint inspections of group entities.
  - They started meeting regularly in 2018 to discuss AML/CFT matters; authorities intend to formalize this as the Financial Sector Regulators Forum on the FIC Act 38 of 2001, and draft Terms of Reference have been prepared.
- FIC support:
  - FIC supports other supervisors through joining inspections, outreach, and guidance to promote consistent interpretation of legislation.
  - From 2015 to 2019, the FIC participated in over 256 joint inspections conducted by other supervisors (SARB:FinSurv, PLAs, EAAB, and to a lesser extent FSCA and SARB:PA).
  - FIC conducts desk reviews (including providing registration and reporting data) to support planning of inspections even when not participating onsite.
- TFS supervision:
  - Compliance with TFS obligations is covered only by SARB:PA and SARB:FinSurv.
  - SARB:PA reviews banks’ TF-related TFS screening systems in regular inspections and during thematic reviews in 2014 and 2017, but inspections are narrowly focused on screening systems rather than related internal controls.
  - SARB:FinSurv covers TFS in its inspections and during a thematic review in 2017.
  - Other supervisors do not supervise for TFS.

### Supervisory resourcing and activity indicators (selected figures from Table 6.1 and related tables)
- SARB:PA:
  - No. of AIs or RIs: 115
  - NRA Risk Rating: Total M-H
  - FTE Staff for AML/CFT inspections: 19 (one position was vacant as of the onsite)
  - AIs per FTE: 2
  - Average Inspections Annually: 6
  - % of AIs inspected Annually: 11% (overall) / 20% (2016) / 14% (2018) / 11% (2019) — Inspection Rate (Domestic Banks) by year: 24% (2012), 24% (2013), 21% (2014), 23% (2015), 23% (2016), 20% (2017), 14% (2018), 11% (2019)
  - Average Inspection Duration: 9–16 days (overall); 16 days (banks), 9 days (life insurance)
  - As of onsite bank risk ratings: 4 banks very high, 3 banks high, 27 banks medium; Total Domestic Bank Inspections (annual totals): 8 (2012), 8 (2013), 7 (2014), 8 (2015), 8 (2016), 7 (2017), 5 (2018), 4 (2019); Total Domestic Bank Inspections average per annum: 6.9
  - Life insurers onsite inspections (2012–2019) average per annum: 3.8; Inspection Rate (Life Insurers) average: 5%
- FSCA:
  - No. of AIs or RIs: 12,098 (Total)
  - NRA Risk Rating: L-M (Total)
  - FTE Staff for AML/CFT inspections: 74 general + 3 AML
  - AIs per FTE: 163
  - Average Inspections Annually: 185
  - % of AIs inspected Annually: 2%
  - Average Inspection Duration: 3 days
  - FSPs: 12,028 (AIs); inspections: 158; % inspected annually: 1%
  - CIS managers: 70; FTE: 28; % of AIs inspected annually: 40%
- JSE:
  - No. of AIs or RIs: 100 AUs
  - NRA Risk Rating: M
  - FTE Staff for AML/CFT inspections: 10
  - AIs per FTE: 10
  - Average Inspections Annually: 24
  - % of AIs inspected Annually: 24%
  - Average Inspection Duration: 3 days
- SARB:FinSurv:
  - No. of AIs or RIs: 255 ADLA branches
  - NRA Risk Rating: L-M
  - FTE Staff for AML/CFT inspections: 17
  - AIs per FTE: 15
  - Average Inspections Annually: 72
  - % of AIs inspected Annually: 28%
  - Average Inspection Duration: 1–2 days
- FIC:
  - No. of AIs or RIs: 4,385 Total
  - NRA Risk Rating: M-H
  - FTE Staff for AML/CFT inspections: 9
  - AIs per FTE: 487
  - Average Inspections Annually: 137
  - % of AIs inspected Annually: 3%
  - Average Inspection Duration: 1 day
  - 223 KRDs: H risk; inspection rate: 7%
  - 189 TSPs: M risk; inspection rate: 4%
  - 6 Public FIs: H risk; inspection rate: 50%
  - 76 money lenders against securities: M risk; inspection rate: 5%
  - 3,891 MVDs (registered with FIC): H risk; inspection rate: 3%
  - 60,246 AIs in support role: L-H risk; FTE staff in support role: 6,694; % of AIs inspected annually: 0.1%
- LPC:
  - No. of AIs or RIs: 19,119 attorneys
  - NRA Risk Rating: M
  - FTE Staff for AML/CFT inspections: 0
  - Average Inspections Annually: N/A
  - % of AIs inspected Annually: 0%
- EAAB:
  - No. of AIs or RIs: 27,568 estate agents
  - NRA Risk Rating: M
  - FTE Staff for AML/CFT inspections: 4 (supported by nine private sector auditing firms)
  - AIs per FTE: 6,892
  - Average Inspections Annually: 360
  - % of AIs inspected Annually: 1%
  - Average Inspection Duration: 1 day

### Risk-based supervision specific observations for SARB:PA
- SARB:PA has a risk-based AML/CFT supervisory manual and uses a risk matrix to risk-rate banks since 2016, but the matrix does not capture risks in a comprehensive and dynamic manner.
- In practice, supervisory engagements are not fully prioritized on a risk basis; inspections of banks rated very high and high risk are too infrequent relative to their risk profiles.
- For very high-risk banks (the “big four”), more than five years on average passed between inspections.
- SARB:PA’s 2019 supervisory framework prescribes: very high-risk banks should be inspected every 12–18 months; high-risk banks every 24 months.
- Current rate of inspections means SARB:PA takes around five years to complete an inspection cycle for all banks and completes roughly a third of the number of inspections per year required under its stated risk-cycle.
- SARB:PA reduced numbers of bank inspections during 2018–2019 largely due to transition following the FIC Act amendments in 2017 and focus on life insurance supervision.

*Source: IMF staff summary of chapter content from the provided PDF excerpt.*

### 371.      The SARB:PA’s onsite inspections appear to be thorough but not tailored to target

### The SARB:PA’s onsite inspections appear to be thorough but not tailored to target

### SARB:PA — Onsite inspections and scoping
- Scoping exercise inputs: information on AML/CFT controls, recent feedback from the FIC on reporting, previously identified deficiencies and follow up of remedial actions, latest findings on controls with respect to business lines deemed inherently high risk across the sector, and actions by other authorities or media coverage.
- Limitation: lack of in-depth understanding of inherent risk at the entity level (see para. 360) leads to inspections that are not well tailored to individual banks’ residual risk exposure; selection of business lines or control aspects is informed only to a limited extent by the individual bank’s specific inherent exposure.
- Inspection approach: review of procedures, sample testing, and testing of IT systems.
- Staffing: the AML/CFT supervision team within the SARB:PA has 19 dedicated staff.

### Supervision of foreign operations of South African banks
- SARB:PA supervises some foreign branches and conducts inspections typically triggered by: regulatory actions by host supervisors, adverse media coverage of the jurisdiction, or deficiencies found at headquarters.
- These foreign-branch inspections are not conducted as part of consolidated group supervision, are carried out jointly with the home regulator (sometimes with host FIU), and do not show evidence of systematic, risk-driven targeting based on institution- or jurisdiction-specific risk assessments.
- Inspections cover main aspects of controls, including CBRs; in a few cases special attention was given to PEPs due to public information on corruption.

### Offsite supervision by SARB:PA
- Primary offsite mechanism: AML/CFT meetings with large banks.
- Frequency: semiannual or triannual engagement with the largest or very high-risk banks.
- Focus of meetings: remediation of previously identified deficiencies, advances in control framework including risk management, and feedback on STR and CTR reporting.
- Weaknesses: unclear how SARB:PA verifies or follows up on information provided during meetings; much less frequent engagement with small and medium-sized banks; no systematic supervisory returns used to feed into risk matrix or supervision scoping exercise.

### Life insurers and amended FIC Act requirements
- SARB:PA began onsite inspections of life insurers in early 2019, starting with large institutions; early inspections were full scope to gain overview of businesses and AML/CFT controls.
- For these initial life-insurer inspections, except for FIC reporting data, no offsite data gathering was undertaken in advance.
- SARB:PA started covering new requirements in the amended FIC Act in inspections of banks and life insurers in early 2019. New legal requirements (introduced in 2017, enforceable in April 2019) include developing and implementing an RMCP, assessing ML/TF risks, and identifying beneficial owners.

### SARB:FinSurv — ADLA sector supervision
- General orientation: adequate supervisory coverage but focused on rules-based compliance with the FIC Act and ECR.
- Inspection frequency: each ADLA head office inspected annually alongside selected branches.
- Change since April 2019: branch selection has been informed by the risk matrix, but in practice selection emphasizes limited ML/TF risks and exchange control factors; branches in border posts, casinos, and airports inspected more frequently while other AML/CFT risk factors are not prioritized.
- Inspection volumes (Table 6.3 — Five Years ending Dec 31): Year 2014: 68; 2015: 86; 2016: 70; 2017: 83; 2018: 51; Average: 72.

### FSCA — securities sector supervision
- Character: not ML/TF risk sensitive; primarily concerned with presence rather than effectiveness of controls.
- Before 2017 FIC Act amendments, AML/CFT aspects were covered in conduct inspections; since then, more dedicated AML/CFT inspections have occurred.
- Offsite monitoring: except semi-annual returns by some FSPs and non-AML/CFT management meetings with large FSPs, there is no offsite monitoring.
- Resourcing: 43 inspectors (most with some AML/CFT training) for about 900 higher risk institutions for both AML/CFT and conduct supervision; supported by an AML Advisory Unit of three staff; FSCA aims to set up a dedicated AML/CFT supervision team.
- Onsite examinations that included AML/CFT (Table 6.4 — Five Years ending Dec 31, totals and averages):
  - FSPs: 2014: 227; 2015: 160; 2016: 250; 2017: 151; 2018: 0; Average: 158
  - CIS managers: 52, 21, 20, 24, 20; Average: 27
  - Hedge Fund CIS manager: n/a, n/a, n/a, 0, 3; Average: 2
  - AUs: 6, 12, 35, 32, 33; Average: 24
  - Total: 285, 193, 305, 207, 56; Average: 209
  - Note: The FSCA conducted 297 outreach visits to small FSPs to assist compliance with amended FIC Act; these were not examinations to assess effectiveness of AML/CFT programs.

### FIC supervision activity and coverage
- Focus and coverage skew: entities inspected by the FIC are mostly MVDs (78 percent), KRDs (12 percent), and only 5 percent are TSPs.
- TSP selection for inspection: primarily informed by non-registration with the FIC or randomly rather than ML/TF risk.
- Onsite inspections of TSPs: typically one day, focused on general AML/CFT controls.
- Overall emphasis: onsite inspections heavily focused on registration and reporting rather than effective mitigation of risks.
- Offsite monitoring: limited; 121 offsite exercises begun in 2018 focus mainly on MVDs rather than sectors covered under the FATF Standards; unclear content of these exercises.
- FIC — Number of onsite examinations (Table 6.5 — Four Years ending March 31):
  - TSPs: 2016: 8; 2017: 6; 2018: 7; 2019: 6; Total: 27; Average: 7; Percent: 5%
  - Money lenders against securities: 5, 4, 4, 4; Total: 17; Average: 4; Percent: 3%
  - FIs: 2, 2, 3, 4; Total: 11; Average: 3; Percent: 2%
  - KRDs: 16, 19, 18, 12; Total: 65; Average: 16; Percent: 12%
  - MVDs: 114, 101, 101, 112; Total: 428; Average: 107; Percent: 78%
  - Total: 145, 132, 133, 138; Total: 548; Average: 137; Percent: 100%

### DNFBP supervision — estate agents, attorneys, casinos
- Estate agents (EAAB):
  - Selection for inspection: based on size, FIC registration status, and complaints.
  - Inspections: typically one day, compliance-based, testing presence rather than effectiveness of controls.
  - Coverage: inadequate relative to sector risks and materiality.
  - Resourcing: EAAB has only four staff working on AML/CFT.
  - Inspection volumes (Table 6.6 — Five years ending March 31, 2019): 2015: 1,025; 2016: 474; 2017: 63; 2018: 108; 2019: 130; Total: 1,800; Average: 360.
  - Note: Prior to 2016, nine audit firms conducted the bulk of EAAB inspections; after a 2016 court challenge, those contracts were not extended.
- Attorneys:
  - Essentially no AML/CFT supervision; only 4 inspections in 2016 by the Free State Law Society with the FIC (referenced in the Panama Papers).
  - LPC entered an MOU with the FIC on November 5, 2019 for the FIC to conduct AML/CFT inspections going forward.
- Casinos and PLAs:
  - Supervision not risk-based: PLAs supervise for Gambling Act compliance and factor FIC Act compliance into inspections; no dedicated AML/CFT supervision.
  - Selection: based on size or random selection; coverage varies greatly across PLAs.
  - Inspections focus on compliance checklist (STR, SAR, CTR reporting) and existence rather than soundness of RMCPs; effectiveness is not assessed.
  - Gambling inspections (Table 6.7 — Five Years ending Dec 31):
    - Casino: 38, 47, 24, 29, 23; Total: 161; Average: 32; Percent: 8%
    - Bingo: 23, 27, 24, 27, 41; Total: 143; Average: 28; Percent: 7%
    - Bookmaker: 132, 132, 122, 135, 236; Total: 757; Average: 151; Percent: 39%
    - Limited Payout Machines: 110, 195, 124, 149, 314; Total: 892; Average: 178; Percent: 46%
    - Total: 303, 401, 294, 340, 614; Total: 1,952; Average: 390; Percent: 100%

### Remedial actions and sanctions — overall patterns and figures
- General pattern: majority of supervisors rely on remedial actions; several have applied only very limited monetary sanctions; all monetary penalties issued by financial supervisors are publicized.
- FSCA: only one small fine for non-compliance with the amended FIC Act; other sanctions related to previous FIC Act requirements.
- DNFBP supervisors: limited remedial actions and no monetary sanctions.
- Supervisory inspections and enforcement by sector (selected figures from Table 6.8 and related text):
  - SARB:PA — Total AIs or RIs: 115; Average Inspections Annually: 11; Average Breaches Identified Annually: 187; Average Remedial Actions Issued Annually: 172; Average Monetary Penalties Issued Annually: 3; Average Monetary Penalty Value per Institution across all years: R13,675,000 ($929,900).
  - SARB:FinSurv — 255 ADLA branches; Average Inspections Annually: 72; Average Breaches Identified Annually: 27; Average Remedial Actions Issued Annually: 182; Average Monetary Penalties Issued Annually: 1; Average Monetary Penalty Value per Institution: R326,667 ($24,100).
  - FIC — 4,385 Total; Average Inspections Annually: 137; Average Breaches Identified Annually: 87; Average Remedial Actions Issued Annually: 87; Average Monetary Penalties Issued Annually: 15; Average Monetary Penalty Value per Institution across all years: R220,054 ($15,000).
  - EAAB — 27,568 estate agents; Average Inspections Annually: 360; Average Breaches Identified Annually: 305; Average Remedial Actions Issued Annually: 305; Average Monetary Penalties Issued Annually: 0.
  - PLAs (Total) — 937 Total; Average Inspections Annually: 390; Average Breaches Identified Annually: 6; Average Remedial Actions Issued Annually: 6; Average Monetary Penalties Issued Annually: 0.
  - Notes: Table 6.8 includes additional sector-specific breakdowns and caveats (e.g., only sanctions payable included; until 2018 life insurers supervised by FSCA or predecessor; FSCA issued one financial penalty in five years on a CIS manager and revoked two FSP licenses).
- SARB:PA sanctions to banks (Table 6.9 — Year ending March 31):
  - Administrative sanctions imposed (R million): 2014: 125.0; 2015: 15.0; 2016: 35.0; 2017: 2.5; 2018: 62.5; 2019: 6.2; Average: 41.0
  - Administrative sanctions imposed ($ millions): 2014: 8.5; 2015: 1.0; 2016: 2.4; 2017: 0.2; 2018: 4.3; 2019: 0.4; Average: 2.8
  - Number of Banks Sanctioned (by year): 4, 2, 6, 1, 2, 3; Average: 3.0
  - Average Sanction per Bank (R million): 31.3, 7.5, 5.8, 2.5, 31.3, 2.1; Average: 13.4
  - Average Sanction per Bank ($ millions): 2.1, 0.5, 0.4, 0.2, 2.1, 0.1; Average: 0.9
- Observations on sanctions:
  - SARB:PA has used remedial actions and financial sanctions accompanied by reprimands, cautions, or directives to remediate.
  - Concerns about timeliness of remediation and whether penalties are consistently proportionate and dissuasive.
  - Example: in a recent case believed to be a systematic failure, a court reduced penalties from R11,000,000 to R400,000, creating potential legal challenges for SARB:PA sanctioning.
  - No sanctions issued to life insurers as SARB:PA only started supervising them in early 2019.
  - SARB:FinSurv has issued 909 AML/CFT related directives since 2014 (annual average 182) but only one financial sanction per year since 2014 (none in 2014 or 2015).
  - FSCA monetary penalties during 2015–2019: one AU R500,000 ($33,991) and one CIS manager R60,000 ($3,907); FSCA policy concerns about not applying monetary penalties against FSPs.
  - FIC monetary sanctions largely pertain to MVDs and KRDs for registration and reporting non-compliance; only one TSP referred for enforcement.

### Impact of supervisory actions on compliance
- Overall limitation: impacts in promoting compliance with new requirements in the amended FIC Act (e.g., RMCP, risk assessment, beneficial owners) cannot be demonstrated because these became enforceable only in April 2019 and most supervisors only recently began supervision in these areas.
- SARB:PA:
  - Some impact prior to 2017 amendments: evidence that supervisory actions led to increased compliance with CDD obligations between 2012 and 2014, and increased TFS compliance between thematic reviews in 2014 and 2017, though remediation items remain outstanding.
  - Unclear impact on application of risk-based controls.
  - External pressures (e.g., from CBRs and access to external markets such as the United States and United Kingdom) are important incentives for large banks to improve AML/CFT controls.
- SARB:FinSurv:
  - Inspections and remedial directives had some impact increasing ADLA compliance with basic AML/CFT obligations under the old FIC Act (more entities appointing compliance officers, improved training, more CTR reporting).
  - Impacts on identifying and effectively mitigating ML/TF risks under the amended FIC Act are yet to be seen.

*Source: 1zafea2021001 - 371. The SARB:PA’s onsite inspections appear to be thorough but not tailored to target (PDF chapter/section).*

### 392.      The supervisory actions of the FSCA and the JSE have led to limited improvements of

### 1zafea2021001 - 392.      The supervisory actions of the FSCA and the JSE have led to limited improvements of

### Supervisory actions and securities sector AML/CFT controls
- The supervisory actions of the FSCA and the JSE have led to limited improvements of AML/CFT controls in the securities sector.
- Since 2017, the FSCA has seen a decline in compliance levels across FSPs, CIS managers, and AUs as the entities were struggling to comply with the new obligations.
- As of the onsite, non-compliance remains high, including for basic rules-based obligations.
- There are some recent indications that the RBA is being adopted by a majority of FSPs in their policies.
- Overall, the securities sector is early in the process of moving away from the rule-based approach to an RBA.

### DNFBP supervision, guidance, and outreach
- DNFBP supervisors were unable to demonstrate that supervision impacted compliance.
- While FIC registration and reporting increased in some sectors, evidence of increased compliance with most preventive measures obligations was not available.
- The authorities, led by the FIC, provide guidance and undertake outreach and engagement with regulated FIs and DNFBPs to promote understanding of AML/CFT obligations, including after the FIC Act amendment, but only limited information has been provided on ML/TF risks.
- The private sector struggles in identifying and understanding ML/TF risks; representatives of all sectors indicated the need for more guidance on identifying and understanding ML/TF risks.
- FIC outputs and outreach:
  - The FIC produces GNs, PCCs, and other publications to promote awareness and consistent interpretation of the legal framework, including general and sector-specific guidance (the latter often developed in collaboration with supervisors).
  - The FIC conducts virtual and physical outreach (“road shows”) on a regular basis, invited to all registered entities, including voluntarily registered entities such as VASPs.
  - Most guidance provided is policy or compliance focused, with limited materials to help entities understand ML/TF risk.
- For all financial supervisors, the recent SRA exercises were their first engagement with the private sector on ML/TF risks.
- SARB:PA engagement:
  - Uses AML/CFT meetings to share national and international policy and regulatory developments with banks.
  - Held a one-day introductory workshop for life insurers recently brought under its purview to sensitize them to the amended FIC Act.
  - SARB:PA and FIC engage with private sector bodies on a quarterly basis to discuss guidance issues.
  - SAMLIT was established recently to facilitate public-private partnership in identifying ML/TF trends and typologies in the banking sector (see para. 142).
- FSCA and JSE outreach:
  - Following the FIC Act amendment, the FSCA hosted over a dozen sector-specific conferences across South Africa to outline changes to requirements after elimination of exemptions that previously applied to the securities sector.
  - AUs supervised by the JSE attended FIC roadshows only.
- DNFBP supervisors have conducted limited outreach, focused only on compliance.
  - The EAAB and four provincial law societies produced material to raise awareness of obligations in the amended FIC Act.
  - The EAAB conducts annual industry meetings that sometimes cover AML/CFT issues, provides materials to help estate agents develop an RMCP and a self-assessment of their AML/CFT controls.
- Guidance product counts cited:
  - FSPs—3 guidance products; Banks—3 guidance products; Estate Agents—2 guidance products; MVDs—1 guidance product; Gambling—3 guidance products; KRDs—1 guidance product; Securities—1 guidance product.

### Overall conclusion on Immediate Outcome 3 (IO.3)
- Assessors weighted banking sector supervision much higher than supervision in other sectors due to size and materiality.
- Market entry controls are deficient: fit and proper criteria often do not apply to beneficial owners; regulators do not conduct criminal checks or verify applicants’ declarations.
- Authorities could not demonstrate adequate controls to prevent criminality from infiltrating FIs and DNFBPs, despite an isolated bank application rejection linked to beneficial owners’ links to “State capture.”
- SARB:PA:
  - Understanding of banking sector ML risks is relatively good.
  - Onsite inspections of banks appear thorough.
- Other supervisors:
  - Understanding of inherent ML risks is insufficient and understanding of TF risks is nascent.
  - Focus on presence of basic controls rather than soundness of AML/CFT programs.
  - Supervisory prioritization or scoping is not driven by ML/TF risks, sometimes due to insufficient or poor risk understanding.
  - Limited or nonexistent supervision of high-risk DNFBPs (attorneys, estate agents, and TSPs) is a serious concern.
  - Not all supervisors apply remedial actions or monetary penalties; where applied, sanctions are often too low and infrequent to be effective or dissuasive.
  - Only financial supervisors demonstrated some impact in improving FIs’ compliance with basic obligations but not for the risk-based measures in the amended FIC Act.
- A fundamental issue: unlicensed cross-border MVTS are not being systematically identified and addressed.
- Conclusion: South Africa is rated as having a moderate level of effectiveness for IO.3.

### Legal Persons and Arrangements — Key findings
- A wide range of public information on the types of legal persons and arrangements which can be created in South Africa can be accessed through various means.
- Serious challenges exist in obtaining BO information on companies and trusts.
  - Authorities rely primarily on obtaining such information from AIs, but measures are not sufficient to ensure AIs can provide adequate, accurate, up-to-date, and verified BO information in a timely manner.
  - Where such information is available, it takes LEAs too long to obtain it.
- Measures to promote transparency and BO of legal persons and arrangements address only to a limited extent the main vulnerabilities that allow abuse of legal persons and trusts for ML/TF.
- Competent authorities have a general understanding that legal persons and trusts are exposed to ML/TF but have not properly identified or assessed specific ML or TF vulnerabilities.
- Companies are abused for ML and used regularly to facilitate corruption in awarding government tenders and laundering of proceeds thereof.
- CSPs that sell and transfer shell companies to new ownership are not subjected to AML/CFT measures; not all CSPs are AIs which limits BO availability.
- The Master’s Office maintains a register of trusts (positive feature) that holds only basic information publicly available and may not always be accurate as only trustees’ identity is verified.
- Authorities could not demonstrate effective, proportionate, and dissuasive sanctions for failure to comply with information requirements.

### Legal Persons and Arrangements — Recommended actions
- Revise and substantially improve mechanisms to ensure accurate, up-to-date, and verified BO information is timely available to competent authorities; consider appointing a competent authority responsible for obtaining and maintaining BO information.
- Thoroughly assess the ML/TF vulnerabilities of all types of legal persons, including vulnerabilities that facilitate corruption in government procurement.
- CIPC should verify information of all foreign officers and foreign shareholders of South African companies.
- Grant LEAs better powers to gain direct and timely access to ownership and control information for legal persons and trusts; further train LEA officers who investigate financial crimes about company and trust structures to enable quicker identification and obtaining of BO information.
- Expand the Trust Property Control Act to require trustees to hold and provide sufficient information to the Master’s Office to help identify any other natural person in ultimate control of the trust.
- Empower the CIPC to impose administrative penalties directly; then the CIPC should apply sanctions for failure to comply with information requirements.
- The Immediate Outcome considered is IO.5; relevant Recommendations: R.24-25, and elements of R.1, 10, 37, and 40.

### Immediate Outcome 5 — Public availability, risk understanding, and mitigating measures
- Public availability:
  - Good range of public information on types of legal persons and arrangements and how to create them is accessible via CIPC and Master’s Office.
  - CIPC means: website (most used), social media (Facebook, Instagram, and Twitter), walk-in self-service terminals, booklets and pamphlets, and requests at its offices.
  - CIPC website information is only from 2016; earlier information must be searched manually.
  - CIPC partnered with three major banks that provide information and a registration service for creating and registering a company.
  - Master’s Office provides trust creation information on its website and in a booklet.
- Identification, assessment, and understanding of ML/TF risks:
  - Most competent authorities have a general understanding that legal persons are often involved when ML occurs, but this is not grounded in proper efforts to identify and assess ML/TF vulnerabilities.
  - A comprehensive ML/TF vulnerability assessment of legal persons created in South Africa has not yet been undertaken.
  - South Africa carried out an NRA on transparency of BO of companies in May 2018; the assessment recognized problems but did not focus on ML/TF vulnerabilities nor on different types of legal persons and mostly centered on theoretical findings.
  - Understanding of the concept of BO varies across competent authorities, leading to different levels of understanding of ML/TF vulnerabilities.
  - SRAs by the FIC, SARB:PA, and FSCA acknowledged legal structures can be abused for ML but did not identify specific vulnerabilities linked to different company types.
  - LEAs and NPA appreciate companies can be abused for ML/TF but did not identify specific vulnerabilities or provide specific case examples.
  - CIPC aware of abuses through complaints (e.g., “company hijackings”) but showed limited understanding of how companies are abused for ML; did not assess ML/TF risks at registration and seemed unaware of specific ML abuse cases.
  - Authorities acknowledged CSP vulnerabilities (shelf companies resold/transferred without AML/CFT measures; nominee directors/shareholders) but did not know the extent of ML/TF abuse and had not assessed these vulnerabilities.
  - Overall understanding by authorities of ML/TF vulnerabilities affecting different company types is limited.
- Mitigating measures:
  - Measures implemented include company and trust registration; basic information made publicly available; requiring AIs to obtain BO information during CDD; background and validation checks on directors; and filing requirements.
  - All companies must be registered in South Africa, but registration does not result in BO information being obtained by the CIPC or companies themselves, creating a vulnerability for ML/TF.
  - Companies are not required to obtain information on foreign corporates that are shareholders.
  - Facilitation of company registration through three major banks could reduce some ML/TF risks depending on banks’ ability to obtain BO information during parallel CDD; however, banks indicated they still face challenges obtaining BO information (see paras. 325. and 326. under IO.4).
  - Trust registration is positive but does not result in full BO and control information being collected.
  - Basic public information may not always be accurate and reliable for trusts; only trustee identity is verified.
  - Requirements since 2017 for AIs to obtain BO information has improved availability of basic and BO information to authorities, but not all FIs, DNFBPs, and VASPs are subject to the requirements and compliance varies or cannot yet be demonstrated.
  - Access to information is not always timely, and information is not always accurate or comprehensive.
  - CIPC cross-checks proposed company directors with its register of delinquent directors and verifies particulars with the DHA database if they are South African; no verification occurs for foreign directors beyond obtaining a copy of their passports.
  - Companies must file annual returns and changes in directors and registered address, but filed information may not always be up to date and enforcement needs improvement (see para. 450).
  - Overall, measures leave companies and trusts open to ML/TF abuse due to incomplete coverage, lack of ML/TF-specific risk assessment, limitations described above, and LEAs’ inability (from finalized cases) to identify BO in complex structures or to address cases involving foreign corporations.
  - Public information and inquiries into “State capture” indicate companies are abused regularly to facilitate corruption in awarding government tenders and laundering proceeds.
  - The extent of TF abuse of companies and trusts and the effectiveness of measures to prevent such abuse is unknown.

### Timely access to adequate, accurate, and current BO information
- Basic information for legal persons is not always accurate as only information about South African directors is verified.
- For trusts, the Master’s Office is an office of record and does not verify information maintained in the register other than the identity of a trustee.
- Authorities primarily rely on AIs (in practice, large banks) to obtain both basic and BO information, and also access other sources such as credit databases.
- Discussions with the FIC and some LEAs indicated ownership information obtained often relates to legal not beneficial ownership.
- The timeline for accessing BO information varies (see details below).
- Access to basic information on companies is held by the CIPC.

*Source: Excerpt from the South Africa FATF-style assessment chapter.*

### 411.      LEAs and prosecutors (for free) can also access information directly from the CIPC

### 1zafea2021001 - 411.      LEAs and prosecutors (for free) can also access information directly from the CIPC

### Access to company information via CIPC and companies
- LEAs and prosecutors can access information directly from the CIPC through requests (rather than the CIPC website); the CIPC provides the information within two days to two weeks, depending on the request’s complexity.
- The SAPS, the FIC, the SARS, and the NPA have direct access to the CIPC’s database but do not use it often, preferring to get information directly from the CIPC for use as evidence.
- Information on the CIPC website is only available from 2016; information on companies registered before that must be searched for manually, posing challenges for timeliness and accuracy.
- Competent authorities can also obtain basic and shareholder information from the companies themselves to the extent the information is accurate and available; where LEAs find inaccuracies, they notify the CIPC.
- Legal persons are meant to keep information up to date by filing annual returns and notices of certain changes with the CIPC, but enforcement is limited.
- The law provides a period of two years for the CIPC to strike off a company after non-filing of returns, which is considered rather long and negatively affects the process.
- The only information held by the CIPC that is verified relates to the identity of local directors; shareholding information held by companies is not verified.
- Conclusion: Basic information obtained via the CIPC or companies might not always be reliable.

### Access to basic and beneficial ownership (BO) information using subpoenas (SAPS experience)
- SAPS obtains BO information on legal persons by applying for a subpoena (CPA, s. 205) served directly or through the FIC on the reporting entity (most often a bank).
- Subpoenas are often issued within half a day and state the timeline for providing BO information.
- Both LEAs and AIs indicated an average of 7–10 days for the information to be provided.
- For complex company structures, SAPS can take on average 30 days to access the first level of legal (shareholder) ownership information using various sources; often longer to reach actual BO information if sources lack it and further requests are required.
- These time periods can be too long for gathering evidence in criminal investigations, particularly those involving tracing assets that might be dissipated.
- A contributing factor is a lack of knowledge among many LEA officers about complex corporate structures and how they can be abused to facilitate crime.
- Result: Access to adequate, accurate, and current BO information by LEAs often does not occur in a timely manner.
- Assessors note consistency with AIs’ reports that it is difficult to identify BO and obtain required information through CDD processes and to verify the information’s accuracy.

### Accessing BO information from AIs through the FIC
- The FIC assists LEAs by requesting BO information from AIs and then providing LEAs the name of the FI, DNFBP, or VASP that the legal person or trust is a client of (see c.24.6).
- LEAs can then apply for a subpoena to obtain any BO information held by the specific institution (c.24.6).
- SAPS reported this process is extremely useful and made it easier to obtain ownership evidence.
- It takes the FIC about 7–10 days to receive the information from the requested AIs.

### Access to information on trusts via the Master’s Office
- The Master’s Office provides basic trust information on its website: trust name, trust file number, names of trustees, domicile address, and the office where the trust was registered.
- The Master’s Office can provide the trustee’s South African identity number to LEAs upon subpoena; it takes about 10–15 days to provide requested information.
- Basic information (other than trustee identity) is not verified and is not always up to date.
- The Master’s Office does not obtain information on other natural persons who might be exercising ultimate effective control of a trust, nor does it gather information on the trust’s purpose.
- The Master’s Office signed an MOU with the SARS in June 2018 to facilitate information exchange; it has been used once by the SARS to request a trust deed which was provided in about a month.
- There are no records kept on frequency of other authorities’ requests or timeliness of responses.

### Access to BO information on trusts from professional trustees and banks
- LEAs have requested BO information using subpoenas from professional trustees (AIs) and banks.
- Professional trustees provided information in less than 30 days when available but took more time where further information was requested on linked persons or accounts.
- Information from trustees is limited to the identity of their clients or persons giving instructions to create the trust, persons creating the trust, or appointed trustees; it does not include other natural persons exercising ultimate effective control, agents, or service providers as this is not required by law (see c.25.1).
- BO information was not always available from banks because banks have difficulties obtaining such information when establishing a business relationship with a trustee (see IO 4).

### Effectiveness, proportionality, and dissuasiveness of sanctions for noncompliance
- Authorities could not provide examples where requests for basic and BO information from AIs and other sources were not complied with and resulted in sanctions being applied.
- The obligation for AIs to identify BO and verify identity information became enforceable in April 2019; supervisors are yet to impose sanctions for breaches.
- Overall, effective, proportionate, and dissuasive sanctions have not been applied against persons who failed to comply with information requirements.
- The CIPC provided information about investigations into noncompliance with the Companies Act, but these do not identify cases related to noncompliance with information requirements.
- Where investigations resulted in CIPC issuing compliance notices and companies addressing violations, CIPC closed cases without imposing fines or other penalties.
- Where a company failed to file returns in two successive years, CIPC moved to strike it from the register as an administrative measure.
- The period of two years prescribed by law to strike off delinquent companies is considered rather too long to be dissuasive.
- The CIPC cannot impose administrative fines for Companies Act violations and must refer such cases to court, which is seen as a cumbersome process.

### Overall conclusion on Immediate Outcome 5 (IO.5)
- There is a good range of public information about types of legal persons and arrangements in South Africa and how to create them.
- Most competent authorities understand that legal persons created in South Africa are often abused for ML, but they have not properly identified and assessed ML or TF vulnerabilities of different types of legal persons.
- South Africa has implemented some measures to prevent misuse of legal persons and arrangements for ML/TF, but compliance varies; companies and trusts still feature prominently in ML schemes and the extent of their abuse for TF is unknown.
- Competent authorities can obtain adequate, accurate, and current basic information on legal persons and arrangements to some extent.
- Of great concern: they can access BO information only to a very limited extent or not at all, and access is not timely.
- There is no evidence that sanctions for failure to comply with information requirements have been imposed.
- Assessment: South Africa is rated as having a low level of effectiveness for IO.5.

### International cooperation — key findings and recommended actions (summary)
Key Findings
- South Africa provides constructive MLA and extradition in response to international requests; assistance provided is useful and has resulted in resolution of some criminal cases in other jurisdictions but is sometimes slow, and a significant proportion of requests are returned unexecuted for failure to comply with South African requirements.
- There is an absence of an effective case management system and overall responsibility for timely execution of requests.
- Requests for international legal assistance have only been made in a very limited number of instances, inconsistent with South Africa’s risk profile.
- Main competent authorities exchange information informally with foreign counterparts reasonably consistent with South Africa’s risk profile; most information is exchanged by the FIC.
- Some basic information on companies and trusts can be shared in a timely way as it is publicly available, but there are challenges with timeliness for companies registered before 2016 and with sharing BO information.

Recommended Actions
- Actively seek formal and timely MLA for all ML, associated predicate offenses, and TF in a much greater proportion of cases with transnational aspects and actively follow up on such requests in a timely manner.
- Proactively pursue requests made to foreign jurisdictions in “State capture” cases through all available channels, including direct contact with foreign agencies and travelling for case conferencing as appropriate.
- When requests fail to comply with South African requirements, provide proactive assistance and guidance to requesting countries about how those requests could be resubmitted or supplemented successfully.
- Develop an overall case management system within the DoJ&CD (the Central Authority) to streamline and monitor timely processing, prioritization, and execution of all incoming MLA and extradition requests by responsible agencies.
- Improve overall capacity and turnaround time to share BO information with foreign counterparts, primarily by implementing recommended actions for IO.5.
- Maintain adequate and accurate statistics on all international cooperation requests, especially turn-around time, to enhance monitoring of timely execution and internal review processes.

### Immediate Outcome 2 (International Cooperation) — practical observations and statistics
- The DoJ&CD is the central authority for MLA and extradition requests.
- Internal procedures are described as overly formal; each agency tends to work within a narrow focus, contributing to lack of overall responsibility and proactive case management (see c.37.2).
- South Africa receives and handles on average eight incoming ML/TF related MLA requests each year; about 30 percent are returned for not meeting South Africa’s legal requirements.
- Over the five-year period 2015 to 2019, South Africa received 552 MLA requests; of these incoming requests, 40 related to ML and one related to TF (total 41 ML/TF-related requests). Of these 41 requests, 29 were either executed or were still in the process of being executed.
- The shortest time taken to execute an MLA request was two months and the longest was two years and 1 month in a particularly complex case; on average, requests took at least one year to process.
- A total of 12 (or 30 percent) ML/TF-related requests were not executed due to noncompliance with South African requirements.
- South Africa received on average one ML/TF-related extradition request each year during the period under review.
- Over 2015 to 2019, 202 extradition requests were received and processed; only four related to ML and one related to TF. Three of these ML/TF-related extradition requests were returned for noncompliance with the legal basis for extradition requests (a return rate of 60 percent for ML/TF-related extradition requests).
- The TF-related extradition request was executed (the subject voluntarily agreed to return following arrest); one ML-related extradition request has been under processing for 13 years.
- The NPA:AFU has offered effective and timely assistance in recovery, restraint, and forfeiture of proceeds of crime in most cases; the Box 12 example describes recovery actions following a Danish request including preservation orders.
- Inward MLA requests related to ML/TF are mainly from North America and Europe and, to a lesser extent, neighboring African countries (e.g. Botswana and Eswatini). The authorities’ risk profile suggests a need for more cooperation within the African region.
- Over 2015–2019, authorities made 50 outgoing MLA requests (32 in 2018); prior to 2018, outgoing requests averaged less than five each year. Of the 50 requests, 3 related to ML and 3 to terrorism. No outgoing requests sought to freeze assets related to “State capture” cases. No outgoing ML or TF-related extradition requests were made during the period.

*Source: 1zafea2021001 - PDF chapter/section content provided.*

### 430.      The low volume of outgoing requests for MLA is not consistent with South Africa’s risk

### 1zafea2021001 - 430.      The low volume of outgoing requests for MLA is not consistent with South Africa’s risk profile

### Delays and low volume of outgoing MLA requests (State capture context)
- The low volume of outgoing requests for MLA is not consistent with South Africa’s risk profile.
- Delay in expeditiously investigating and pursuing recovery of proceeds of crime relating to “State capture” cases with transnational elements is a cause for concern.
- Authorities indicated they sent out 16 requests for MLA to 10 countries relating to “State capture” cases in 2018, but were still waiting for the responses as of the onsite, 14 months after the requests were made.
- Informal enquiries are often made through diplomatic channels prior to sending formal MLA requests; these informal enquiries are not tracked and often do not yield feedback.
- Case timeline example (sanitized): DPP submitted request to DoJ&CD on March 7, 2018; delivered to Country A on April 24, 2018; Country A acknowledged receipt in September 2018; no further feedback despite numerous diplomatic follow-ups from November 2018 onwards.
- Authorities received an initial response to 11 of 16 outgoing “State capture” MLA requests made to 10 different jurisdictions during the relevant period.
- In one case with concerted follow-up, assistance was provided to the authorities’ satisfaction.
- Where there has been no progress, authorities do not appear to have made regular concerted effort to pursue MLA requests after the initial response or lack thereof; authorities are urged to proactively pursue outstanding requests and keep a record of action taken.

### Examples of effective international cooperation (selected cases)
- Bobroff matter:
  - Incoming and outgoing MLA requests; predicate offenses: fraud, theft, and tax evasion.
  - MLA process including asset forfeiture took almost two years.
  - Final Forfeiture Order obtained on August 21, 2019: R103,648,756.66 ($7 million).
  - The criminal trial for predicate offenses and ML is still pending in South Africa.
- Another case: forfeiture of R63 million ($4.3 million) from a Ponzi scheme over a six-year period from 2009 till 2015 using POCA, ch.6; case involved over 10 countries and R13 billion ($884 million) in proceeds; suspects extradited from Australia, Switzerland, and the United Kingdom.
- John Gregory Stouch (incoming request):
  - MLA request received August 16, 2016, for bank statements and company records including BO information.
  - Information obtained from CIPC and a bank; delivered to requesting state during February 2018 (18 months after the request was made).

### Other forms of international cooperation and information exchange
- FIC outbound activity (five years ending March 31, 2018):
  - Total requests sent to other FIUs: 306.
  - Crime breakdown (Totals and Percent):
    - Fraud: 79 — 26%
    - Tax Crimes: 75 — 25%
    - ML: 40 — 13%
    - Corruption: 31 — 10%
    - TF: 28 — 9%
    - Narcotics: 9 — 3%
    - Rhino Horn Smuggling: 5 — 2%
    - Illicit Flow of Funds: 5 — 2%
    - All Other: 34 — 11%
  - Requests Granted (total): 16
  - Average Response Time (Months): 3-9 (for each year 2014–2018)
- FIC inbound activity (five years ending March 31, 2018):
  - TOTAL requests received: 1,310
  - Crime breakdown (Totals and Percentage):
    - Tax Crimes: 403 — 31%
    - Fraud: 346 — 26%
    - ML: 332 — 25%
    - TF: 99 — 8%
    - Corruption: 49 — 4%
    - Narcotics Related: 29 — 2%
    - All Other: 52 — 4%
  - Requests Granted: 1,086 — 83%
  - Requests Refused: 0 — 0%
  - Requests Pending: 224 — 17%
  - Average Response Time (Days): 1-10 (2014–2016), 1-15 (2017–2018)
- FIC spontaneous disclosures to other FIUs (five years ending March 31, 2018):
  - TOTAL: 101 — 100%
  - ML: 26 — 26%
  - Fraud: 23 — 23%
  - Tax Crimes: 22 — 22%
  - Illicit Flow of Funds: 12 — 12%
  - Narcotics: 9 — 9%
  - TF: 4 — 4%
  - Corruption: 4 — 4%
  - Theft: 1 — 1%
  - Fifty-one percent of disclosures related to crimes considered highest risk in South Africa.
- SARS:
  - Sent 84 requests for assistance during the period under review.
  - 70 percent were granted; 2 percent were turned down.
  - Average turnaround time estimated by the authorities to be 34 days per request.
  - Received 98 requests during the period under review covering various trade and enforcement matters.
- FSCA:
  - Cooperated in a timely manner; between 2016 and 2018 received and processed 137 requests from other jurisdictions.
  - Average turnaround time: 25 days.
  - Case example (Mamepe Capital): investigation led to withdrawal of FSP license, debarment of key individual, and direction to repay R10 million ($680,000); Financial Services Tribunal later found Mamepe’s actions were probably ML.
- SARB:PA:
  - Handled 184 outgoing correspondence relating to fit and proper inquiries, AML/CFT inspections, licensing, and cross-border banking issues during the period under consideration.
  - Foreign information requests received by SARB:PA (2014–2018):
    - Requests received by year: 10, 15, 13, 8, 15 (Average: 12)
    - Requests granted by year: 10, 15, 13, 8, 15 (Average: 12)
    - Average Response Time (days) by year: >25.6, >22.0, >18.5, >30.9, >27.7 (Average: >24.4)
- NPA:AFU:
  - Dealt with 41 requests from foreign regional and international AFUs in the relevant period.
  - As a member of ARINSA, cooperates effectively with other members and can obtain helpful information pending formal MLA processes.
- LEAs and intelligence organizations are active in informal information exchange and joint investigations; examples include arrest of two intending FTFs and successful investigation of a kidnapping linked to TF.

### Challenges in exchanging beneficial ownership (BO) and basic legal person information
- CIPC provides basic information online from 2016; information on companies registered before 2016 must be searched manually; information is not always up to date.
- Capacity to exchange BO information in a timely manner is limited:
  - Authorities receive requests for BO information but cases did not clearly demonstrate routine ability to obtain and provide BO information.
  - CIPC does not always hold BO information; authorities rely on AIs, but AI-held BO information may not be accurate as AIs cannot verify it with CIPC.
  - Banks will only release BO information if served with a subpoena; serving a subpoena can take 7 to 10 days each time, and complex corporate structures can take SAPS a number of weeks to access first-level legal ownership and longer to access BO information; repeated subpoenas may be required.
- Trusts:
  - Master’s Office holds and maintains basic information (except names of trustees online) and can provide details about trustees within 15 days when subpoenaed.
  - Master’s Office does not provide information on other persons who control or benefit from the trust without a subpoena; competent authorities cannot provide foreign jurisdictions with full BO information for trusts when requested.
- Example where BO information was obtained: Gregory case — CIPC records and bank records produced and delivered after 18 months.

### Assessment and recommendations (implicit from findings)
- South Africa should be seeking other forms of international cooperation at a higher level to effectively deal with ML/TF given its risk profile.
- Authorities are urged to:
  - Proactively pursue all outstanding MLA requests and keep a record of action taken.
  - Improve tracking of informal diplomatic enquiries and their outcomes.
  - Enhance capacity and processes to obtain and provide BO information in a timely and routine manner, including reducing delays related to subpoenas and improving the completeness and accuracy of BO records.
  - Increase early and concerted follow-up on MLA requests, particularly those relating to “State capture” cases, to avoid missed opportunities to obtain evidence and assistance and to prevent dissipation of proceeds.

*Source: 1zafea2021001 - 430.      The low volume of outgoing requests for MLA is not consistent with South Africa’s risk profile.*

### 454.      The authorities demonstrated that they provide MLA and extradition to other

### 454.      The authorities demonstrated that they provide MLA and extradition to other 

### Findings on MLA and extradition provision
- The authorities demonstrated that they provide MLA and extradition to other jurisdictions to some extent but seek it to a much lesser extent.
- South Africa provides some basic information for companies and trusts in a timely manner.
- Most authorities are reasonably good at exchanging information with their foreign counterparts on an informal basis consistent with the risk profile.
- The authorities have increased the volume of ML/TF MLA requests that they make in recent times.

### Timeliness and execution challenges
- The turnaround time for assistance requested averages over one year.
- A significant proportion of requests are returned unexecuted due to a failure to comply with South African requirements.
- Authorities do not give proactive assistance on how returned requests could be resubmitted or supplemented successfully.
- Requests often suffer from delays in getting responses, especially relating to “State capture”, and need major improvements to how they follow up such requests.
- The main challenge to providing BO information in a timely manner is that this information is not readily available.

### Information obtained (excerpt)
- The information obtained includes trust name, file number, names of the trustees and their South African identification number, and the office where the trust was registered.

### Assessment
- South Africa is rated as having a moderate level of effectiveness for IO.2.

*Source: 1zafea2021001 - 454. The authorities demonstrated that they provide MLA and extradition to other (IMF PDF chapter).*

### Annex I. Technical Compliance Annex

### 1zafea2021001 - Annex I. Technical Compliance Annex

### Overview
- The Annex provides a detailed analysis of technical compliance with the FATF 40 Recommendations in numerical order, limited to technical criteria for each Recommendation and to be read in conjunction with the MER.
- Where FATF requirements and national laws/regulations remain the same, analysis from the previous ME in 2009 is referenced.
- The report repeatedly notes scope deficiencies: several financial activities and DNFBPs required under the FATF standard are not fully regulated or supervised in South Africa (see recurring reference “Scope deficiency” and c.1.6).

### High-level findings and overall conclusions
- South Africa has begun national ML/TF risk identification and assessment but had not concluded the NRA process at the time of the assessment; approaches are predominantly qualitative and rely on experts’ judgement (c.1.1).
- Risk-based approaches (RBA) have been adopted in some supervisory areas (e.g., SARB:PA for banks since 2017) but most AML/CFT authorities have not fully implemented RBA (Weighting and Conclusion of R.1).
- Many FATF criteria are “mostly met” or “partly met” with frequent scope deficiencies where FIC Act does not cover all FIs and DNFBPs (notably: CFIs including stokvels, credit providers other than money lenders against securities, FinTech companies that are not VASPs or FSPs, DPMS not KRDs, accountants for non-financial services, and CSPs other than attorneys — c.1.6).

### Selected Recommendation-by-Recommendation technical conclusions (key points and ratings)
- Recommendation 1 (Assessing Risks and Applying a Risk-Based Approach)
  - Overall rating: partially compliant.
  - Key points:
    - Criterion 1.1 – Partly met: first coordinated NRA in progress; approach predominantly qualitative.
    - Criterion 1.6 – Not met: several sectors are not AIs subject to AML/CFT obligations or supervision (scope deficiency).
    - Criterion 1.10 & 1.11 – Mostly met: AIs must develop RMCPs (FIC Act s.42(1)); Scope deficiency applies to some FIs/DNFBPs.
- Recommendation 2 (National Cooperation and Coordination)
  - Overall rating: partially compliant.
  - Key points:
    - IDC established to coordinate policy (c.2.2); IDC excludes supervisors of DNFBPs and the CIPC.
    - No mechanisms for cooperation/coordination to combat financing of proliferation (c.2.4 – Not Met).
- Recommendation 3 (Money Laundering Offense)
  - Rating: largely compliant.
  - Key point: Minor shortfall for self-laundering (POCA, s.5 and s.6 do not fully extend to perpetrator of the predicate offense) (c.3.7).
- Recommendation 4 (Confiscation and Provisional Measures)
  - Rating: largely compliant.
  - Key point: Minor gap for confiscation of instrumentalities intended for use in ML/predicate/TF offenses (c.4.1b,c).
- Recommendation 5 (Terrorist Financing Offense)
  - Rating: partially compliant.
  - Key points:
    - POCDATARA contains TF offenses but excludes certain acts committed during an armed struggle (c.5.1 – major exemption narrowing scope).
    - Sanctions: maximum fine R100 million ($6.8 million) or imprisonment not exceeding 15 years; concern on proportionality relative to ML (30 years) and terrorism (life) (c.5.6).
- Recommendation 6 (Targeted Financial Sanctions Related to Terrorism and Terrorist Financing)
  - Rating: non-compliant.
  - Key findings:
    - No domestic process for identifying targets or procedures to make designation proposals (c.6.1 – Not met).
    - UNSCR 1373 implementation relies on in rem freezing order (POCDATARA, s.23) that focuses on identified property rather than general freezing of assets of designated persons (c.6.2 – Partly met / Not met), causing major shortcomings.
- Recommendation 7 (Targeted Financial Sanctions Related to Proliferation)
  - Rating: partially compliant.
  - Key points:
    - FIC Act s.26A–26C introduced PF-related TFS (April 2019); publication in Gazette and FIC notices used; some delays up to 3-5 days in a few cases (c.7.1).
    - Shortcoming: s.26B(2) does not extend to funds/assets of persons acting on behalf of, or at the direction of, a designated person (c.7.2(b)(iv) – Not Met).
    - No publicly known procedure enabling listed persons to petition delisting at UNSCR 1730 Focal point (c.7.4(a) – Not met).
- Recommendation 8 (Non-Profit Organizations)
  - Rating: non-compliant.
  - Key findings:
    - No assessment identifying subset of NPOs at risk of TF abuse (c.8.1 – Not Met).
    - Registration is voluntary; monitoring, supervision, sanctioning and capacity to detect/investigate TF abuse in NPO sector are inadequate (c.8.3–c.8.6).
- Recommendation 9 (Financial Institution Secrecy Laws)
  - Rating: largely compliant.
  - Key point: POPI Act may form a legal obstacle for FIs sharing information required by R.13, 16 or 17 when the AML/CFT obligation derives from secondary legislation (c.9.1).
- Recommendations 10–12 (Preventive measures: CDD, Record-keeping, PEPs)
  - R.10 (Customer Due Diligence): partially compliant.
    - Key shortcomings: scope deficiency (all R.10 criteria have scope deficiency due to incomplete FIC Act coverage); definition of “beneficial owner” not covering situation where a natural person exercises effective control of a natural person client; absence of specific CDD measures for beneficiaries of life and investment-related insurance; no explicit provision permitting an AI to suspend CDD and instead file a suspicious report where CDD may tip off the client (c.10.20 – Not Met).
  - R.11 (Record-Keeping): largely compliant.
    - All necessary transaction records must be retained for at least five years (FIC Act ss.22A and 23) but scope deficiency applies (c.11.1–11.4).
  - R.12 (Politically Exposed Persons): non-compliant.
    - Major shortcomings: PEP definitions limited in time (preceding 12 months or acting positions exceeding six months) and limited to international organizations based in South Africa; no requirement to identify existing customers who become PEPs and obtain senior management approval on continuation (c.12.1–12.4).
- Recommendations 13–18 (Correspondent banking, MVTS, New technologies, Wire transfers, Reliance on third parties, Internal controls)
  - R.13 (Correspondent Banking): largely compliant with scope limitations (c.13.1–13.3).
  - R.14 (MVTS): partially compliant — domestic MVTS providers not required to be licensed/registered; enforcement/sanctions for unauthorized MVTS not demonstrated; informal MVTS networks recognized (c.14.1–14.5).
  - R.15 (New Technologies and VAs/VASPs): non-compliant (major deficiencies).
    - No identification and assessment of ML/TF risks from VAs/VASPs; VASPs not required to be licensed/registered or supervised; VASPs subject only to general reporting obligations (c.15.3–15.11).
  - R.16 (Wire Transfers): largely compliant.
    - SARB EFT Directive 1 and IN set requirements; some shortcomings on batched transfers verification and certain record-keeping obligations (c.16.1–16.18).
  - R.17 (Reliance on Third Parties): non-compliant.
    - No explicit requirements for the relying AI to immediately obtain outsourced CDD information, ensure availability of copies without delay, or satisfy itself that the third party is regulated/supervised (c.17.1–17.3).
  - R.18 (Internal Controls; foreign branches/subsidiaries): partially compliant.
    - Compliance functions and training required; screening hiring procedures not required; no requirement for group-wide AML/CFT programs; non-core FIs not required to have independent audit (c.18.1–18.3).
- Recommendations 19–23 (Higher-risk countries; Reporting; Tipping-off; DNFBP CDD and other measures)
  - R.19 (Higher-Risk Countries): largely compliant — powers exist to issue directives and publish advisories; scope deficiency (c.19.1–19.3).
  - R.20 (Reporting Suspicious Transactions): largely compliant.
    - Broad reporting obligation to a very wide category of persons; prescribed period “as soon as possible but not later than fifteen days” may create ambiguity (c.20.1–20.2).
  - R.21 (Tipping-Off & Confidentiality): compliant (FIC Act protection and tipping-off prohibitions) (c.21.1–21.2).
  - R.22/R.23 (DNFBPs Customer Due Diligence / Other Measures): partially compliant.
    - Some DNFBPs are covered (casinos, real estate agents, attorneys, TSPs, KRDs, certain accountants for financial services) but DPMS (other than KRDs), accountants (for non-financial activities), and CSPs other than attorneys are not covered (c.22.1–22.5; c.23.1–23.4). PEPs, new technologies, third-party reliance shortcomings apply to covered DNFBPs per R.10, R.15, R.17.
- Recommendations 24–25 (Transparency and Beneficial Ownership of legal persons and arrangements)
  - R.24 (Legal persons) – partially compliant.
    - Companies must register with CIPC; basic information publicly available. However: no comprehensive ML/TF risk assessment for types of legal persons (c.24.2 – Not met); BO information not systematically or timely available in all cases; AIs’ BO obligations limited by scope of FIC Act (c.24.6–24.15).
  - R.25 (Legal arrangements / Trusts) – partially compliant.
    - Professional trustees (TSPs) are AIs and must obtain/verify certain trust-related information; other trustees often not required to collect BO information; timely access to trust BO information by LEAs not always guaranteed (c.25.1–25.8).
- Recommendations 26–28 (Regulation and supervision of FIs and DNFBPs; Powers of supervisors)
  - R.26 (Regulation & Supervision of FIs): partially compliant.
    - Supervisory responsibilities designated across FSCA, SARB:PA, SARB:FinSurv, SARB:NPSD and the FIC; gaps remain—CFIs, certain credit providers, FinTechs not covered; market entry controls and fit & proper rules inconsistent and often do not extend to beneficial owners; consolidated/group-level AML/CFT supervision not in place (c.26.1–26.6).
  - R.27 (Powers of Supervisors): partially compliant.
    - Supervisors and the FIC have inspection and information powers and may impose administrative sanctions, but gaps remain in suspension/withdrawal of licenses and some sectors not subject to oversight (c.27.1–27.4).
  - R.28 (Regulation & Supervision of DNFBPs): partially compliant.
    - Supervisors designated for casinos, estate agents, attorneys, TSPs, KRDs; supervision uneven and not consistently risk-based; DPMS not KRDs, accountants for non-financial services, CSPs not attorneys largely outside monitoring (c.28.1–28.5).
- Recommendations 29–31 (FIU; LEAs responsibilities and powers)
  - R.29 (FIU): largely compliant.
    - FIC established as FIU with broad powers to receive/analyze/disseminate STRs; strong safeguards and IT security; strategic analysis products exist but not always tailored to identifying ML/TF trends; gaps in FIU intelligence holdings due to DNFBP coverage gaps (c.29.1–29.8).
  - R.30 (LEAs responsibilities): compliant.
    - SAPS:DPCI mandated for ML/TF investigations; SARS handles tax/customs offenses; NPA:AFU and SIU have asset tracing and confiscation capabilities (c.30.1–30.5).
  - R.31 (Powers of LEAs): compliant.
    - Extensive powers to subpoena, search and seize, obtain witness statements, use undercover techniques, interception subject to law, controlled deliveries, and to compel production of records (c.31.1–31.4).
- Recommendation 32 (Cash couriers)
  - Rating: partially compliant.
  - Key findings:
    - Declaration systems exist for travelers above R25,000 or equivalent (Reg 3(1)), but incoming BNIs payable in foreign currency are not covered; SARB:FinSurv does not provide declarations of physical cash movements to the FIC; national coordination at all ports not consistent (c.32.1–32.11).
- Recommendation 33 (Statistics)
  - Rating: largely compliant.
  - Key point: Authorities maintain statistics on STRs, ML/TF investigations, prosecutions, convictions, and property frozen/seized/confiscated; some gaps in coverage across agencies (c.33.1).
- Recommendation 34 (Guidance and Feedback)
  - Rating: largely compliant.
  - Key point: FIC issues GN7 and other guidance (some enforceable); guidance tends to be general and may lack sector-specific detail; most supervisors provide feedback and outreach except the LPC (c.34.1).
- Recommendation 35 (Sanctions)
  - Rating: largely compliant.
  - Key points:
    - Range of administrative, civil and criminal sanctions exist (administrative financial penalties up to R50 million ($3.4 million) for legal persons; criminal fines up to R100 million ($6.8 million) or imprisonment up to 15 years for failure to file an STR — c.35.1).
    - Sanctions for directors/senior management exist but are not applicable to sectors outside FIC Act scope (c.35.2).
- Recommendation 36 (International instruments)
  - Rating: largely compliant.
  - Key point: South Africa has acceded/ratified key international instruments (Vienna, Palermo, Merida, TF Convention) but POCA s.6 does not cover the perpetrator of the predicate offense (c.36.2 – minor deficiency).
- Recommendations 37–40 (Mutual legal assistance, extradition, other international cooperation)
  - R.37 (Mutual Legal Assistance): largely compliant.
    - ICCMA provides legal basis for MLA; DoJ&CD central authority; target decision turnaround 25 days for whether to execute request but overall execution times and case management systems limited (c.37.1–37.8).
  - R.38 (MLA: Freezing and Confiscation): largely compliant.
    - ICCMA permits registration/enforcement of foreign restraint/confiscation orders; restraint orders may be set aside if subject to appeal/review — a minor deficiency (c.38.1–38.4).
  - R.39 (Extradition): largely compliant.
    - Extradition available for ML and TF (noting TF definition narrowing for acts during armed struggle); cases prioritized on request but case management not systematic (c.39.1–39.4).
  - R.40 (Other Forms of International Cooperation): largely compliant.
    - Main AML/CFT authorities can provide a wide range of international cooperation; some minor deficiencies in demonstrated rapidity, prioritization mechanisms, and universal feedback across all competent authorities (c.40.1–40.20).

### Policy implications and recommended priorities (as reflected in the Annex)
- Address scope deficiencies: extend AML/CFT obligations and supervision to uncovered FIs and DNFBPs (c.1.6 repeatedly referenced).
- Finalize and operationalize national ML/TF risk assessments (NRA) and ensure mechanisms to (i) share results across all relevant supervisors and DNFBPs, and (ii) allocate resources based on risk (c.1.1–1.5).
- Strengthen TF criminalization to remove the exemption for acts committed during an “armed struggle” to align with the TF Convention (c.5.1).
- Establish domestic processes and competent authority responsibilities for designations and TFS under UNSCRs (R.6), and ensure that UNSCR 1373 designations are implemented in a manner consistent with TFS obligations (c.6.1–6.6).
- Regulate, license/register and supervise VASPs and address VA-related ML/TF risks; issue VASP-specific guidance and ensure licensing/registration and supervisory frameworks are in place (R.15, c.15.3–15.6).
- Introduce explicit requirements for reliance on third parties that require immediate access to outsourced CDD information and verification of third-party AML/CFT adequacy (R.17, c.17.1).
- Improve PEP definitions and impose obligations to identify existing customers who become PEPs and require senior management approval for continuation of such relationships (R.12, c.12.1–12.3).
- Strengthen mechanisms for beneficial ownership information: assess ML/TF risks of all types of legal persons; ensure timely access to BO information; consider mechanisms for BO registers or enhanced CIPC/registry processes (R.24, c.24.2, c.24.6–24.15).
- Enhance DNFBP supervision and sanctioning capabilities, including for DPMS (non-KRDs), accountants outside financial services, and CSPs that are not attorneys (R.22–R.28).
- Strengthen targeted financial sanctions implementation speed and coverage (R.6 and R.7) and provide clearer delisting/review procedures (c.6.6, c.7.4).
- Improve cross-border cash reporting/coverage for incoming BNIs payable in foreign currency and ensure Passenger Processing System (PPS) captures and shares relevant declarations/suspicious incidents with FIC/LEAs (R.32, c.32.1–32.9).
- Strengthen supervisory application of a risk-based approach and develop consolidated/group-level AML/CFT supervision where applicable (R.26, c.26.4–26.6).
- Improve case management and timeliness for MLA and extradition processes (R.37–R.39, c.37.1–37.3; c.39.1).

*Source: Annex I. Technical Compliance Annex, 1zafea2021001*

### Annex II. Summary of Technical Compliance – Key Deficiencies

### Annex II. Summary of Technical Compliance – Key Deficiencies

### 1. Assessing risks & applying a risk-based approach
- Rating: PC
- Factor(s) underlying the rating:
  - South Africa is yet to conclude its first NRA exercise.
  - Most authorities that have AML/CFT responsibilities are yet to apply an RBA.
  - The exclusion of CFIs, credit providers other than money lenders against securities, FinTech companies offering financial services that are not FSPs, DPMS that are not KRDs, accountants (for activities other than providing financial services), and CSPs other than attorneys from most AML/CFT obligations and supervision or monitoring is not based on proven low ML/TF risks.

### 2. National cooperation and coordination
- Rating: PC
- Factor(s) underlying the rating:
  - South Africa is yet to develop coordinated and holistic national policies on AML/CFT informed by risks identified.
  - Mechanisms to enable inter-agency cooperation at both policy and operational levels exclude DNFBP supervisors and the CIPC (company registry).
  - No mechanisms to allow cooperation and coordination to combat the financing of proliferation of weapons of mass destruction.
  - No evidence of cooperation and coordination between relevant authorities to ensure the compatibility of AML/CFT requirements with Data Protection and Privacy rules and other similar provisions.

### 3. Money laundering offenses
- Rating: LC
- Factor(s) underlying the rating:
  - A minor shortfall exists for self-laundering (acquisition, possession or use of proceeds does not extend to the perpetrator of the predicate offense)

### 4. Confiscation and provisional measures
- Rating: LC
- Factor(s) underlying the rating:
  - There is a minor gap for confiscation of instrumentalities intended for use in ML, predicate, and TF offenses.

### 5. Terrorist financing offense
- Rating: PC
- Factor(s) underlying the rating:
  - Criminalization of TF is significantly narrower than the scope of the TF Convention.
  - Concern about the proportionality of TF sanctions.

### 6. Targeted financial sanctions related to terrorism & TF
- Rating: NC
- Factor(s) underlying the rating:
  - Delays in implementing for UNSCRs 1267, 1989, and 1998.
  - No domestic process for identify or proposing targets for those UNSCRs
  - UNSCR 1373 mechanism focuses on identified property not all property of designees.

### 7. Targeted financial sanctions related to proliferation
- Rating: PC
- Factor(s) underlying the rating:
  - Some delays in implementing TFS.
  - Prohibition does not extend to funds and other assets of persons acting on behalf of, or at the direction of a designated person or entity.
  - Weaknesses in processes for de-listing.

### 8. Non-profit organizations
- Rating: NC
- Factor(s) underlying the rating:
  - No assessment to identify those NPOs at risk of TF abuse.
  - No capacity to monitor or investigate NPOs identified to be at risk of TF abuse.

### 9. Financial institution secrecy laws
- Rating: LC
- Factor(s) underlying the rating:
  - Legal obstacle to information sharing between FIs where required under R.13. 15. or 17.

### 10. Customer due diligence
- Rating: PC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.
  - “Beneficial owner” does not extend to a natural person exercising control of a customer who is a natural person;
  - No requirement to ensure that any other natural person exercising ultimate effective control over a trust must be identified and their identity verified;
  - No CDD requirements for the beneficiary of life insurance and other investment related insurance policies;
  - Requirement to apply enhanced measures does not entail higher risk (occasional) transactions, and the application of simplified measures when there is a suspicion of ML/TF or specific higher risk scenarios apply, is not explicitly excluded;
  - AIs not explicitly permitted not to pursue CDD, when it reasonably believes that performing the CDD process will tip-off the client

### 11. Record keeping
- Rating: LC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.

### 12. Politically exposed persons
- Rating: NC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies;
  - The definition of a PEP is limited in time;
  - International organizations PEPs limited to organizations based in South Africa;
  - Identified limitations apply to family members and close associates of all types of PEPs;
  - No clear requirements for AIs to put in place risk management systems to determine whether an existing customer or the beneficial owner becomes a PEP, and to subsequently obtain senior approval for continuing the relationship with such customers.

### 13. Correspondent banking
- Rating: LC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.

### 14. Money or value transfer services
- Rating: PC
- Factor(s) underlying the rating:
  - Domestic MVTS are not subject to licensing or registration.
  - Insufficient action being taken against unlicensed MVTS
  - Limited circumstances where agents are registered
  - MVTS need not include agents in their AML/CFT program

### 15. New technologies
- Rating: NC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.
  - ML/TF risks relating to new technologies are identified only to a limited extent
  - AIs not required to undertake ML/TF risk assessments for new products, business practices and technologies nor to take measures to manage and mitigate the risks;
  - VAs and VASPs risks not adequately identified, assessed, and understood yet, and no risk-based measures taken
  - VASPs not required to take AML/CFT measures beyond a general reporting obligation.
  - VASPs not subject to licensing or registration, nor supervised.

### 16. Wire transfers
- Rating: LC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.
  - Minor shortcomings for: verifying originator information with regard to batched transfers, record keeping, and screening wire transfers to comply with international sanctions.

### 17. Reliance on third parties
- Rating: NC
- Factor(s) underlying the rating:
  - No requirements for AIs to obtain immediately information about outsourced CDD; ensure that copies of data will be available upon request; or to be satisfied that the third party is regulated, supervised, and complies with CDD and record keeping requirements.
  - No determination about in which countries the third party can be based.

### 18. Internal controls and foreign branches and subsidiaries
- Rating: PC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.
  - No requirement for financial groups to implement group-wide programs;
  - Procedures to screen staff are not required;
  - Non-core FIs are not required to have an independent audit function;
  - Mitigation where host country does not permit proper implementation not required.

### 19. Higher-risk countries
- Rating: LC
- Factor(s) underlying the rating:
  - No obligations for CFIs, credit providers other than money lenders against securities, and some fintech companies.

### 20. Reporting of suspicious transaction
- Rating: LC
- Factor(s) underlying the rating:
  - Outer limit of 15 days allowed to report after forming suspicion creates an ambiguity that could undermine the requirement to report as soon as possible when a suspicion is formed.

### 21. Tipping-off and confidentiality
- Rating: C

### 22. DNFBPs: Customer due diligence
- Rating: PC
- Factor(s) underlying the rating:
  - No obligations for CSPs that are not attorneys; accountants (for activities beyond provision of financial services), and DPMS;
  - Same shortcomings already identified for R.10, R.11, R.12, R.15, and R.17.

### 23. DNFBPs: Other measures
- Rating: PC
- Factor(s) underlying the rating:
  - No obligations for CSPs that are not attorneys; accountants (for activities beyond provision of financial services), and DPMS that are not KRDs as RIs;
  - Same shortcomings already identified for R.18 and R.20

### 24. Transparency and beneficial ownership of legal persons
- Rating: PC
- Factor(s) underlying the rating:
  - ML/TF risks of legal persons created in South Africa not fully assessed and identified.
  - BO information is not always available to competent authorities in a timely manner.
  - There is limited access to BO information as not all DNFBPs and VASPS are AIs.

### 25. Transparency and beneficial ownership of legal arrangements
- Rating: PC
- Factor(s) underlying the rating:
  - Professional trustees not required to obtain full information on BO when creating trusts.
  - AIs not required to obtain BO information for other natural persons controlling a trust.
  - There is a limited range of sanctions applicable to non-professional trustees.

### 26. Regulation and supervision of financial institutions
- Rating: PC
- Factor(s) underlying the rating:
  - A few sectors are only subject to reporting requirements and are not monitored for AML/CFT preventive measures
  - Gaps exist for market entry of certain non-core sectors.
  - Fit and proper requirements are inconsistent and often not extended to beneficial owners
  - RB AML/CFT supervision is either at an early stage or does not exist.

### 27. Powers of supervisors
- Rating: PC
- Factor(s) underlying the rating:
  - Not all supervisors can suspend or withdraw licenses
  - CFIs, credit providers other than money lenders against securities, and some fintech companies are not subject to most AML/CFT obligations or oversight for compliance

### 28. Regulation and supervision of DNFBPs
- Rating: PC
- Factor(s) underlying the rating:
  - For all sectors and professions, it cannot be established that adequate controls are in place to prevent criminality from operating.
  - Supervision for the most part is not risk sensitive
  - Attorneys not supervised
  - DPMS, accountants (for activities other than provision of financial services), and CSPs other than attorneys not subject to most AML/CFT obligations and not supervised.

### 29. Financial intelligence units
- Rating: LC
- Factor(s) underlying the rating:
  - Operational analysis adversely affected by gaps in intelligence holdings due to some DNFBPs not being covered under the AML/CFT framework
  - Strategic analysis is not specific to identifying ML and TF related trends and patterns.

### 30. Responsibilities of law enforcement and investigative authorities
- Rating: C

### 31. Powers of law enforcement and investigative authorities
- Rating: C

### 32. Cash couriers
- Rating: PC
- Factor(s) underlying the rating:
  - Gaps in the regime pertaining to BNIs.
  - Documentation not comprehensive nor routinely made available to the FIC or LEAs.

### 33. Statistics
- Rating: LC
- Factor(s) underlying the rating:
  - Not all AML/CFT agencies maintain statistics on international cooperation requests.

### 34. Guidance and feedback
- Rating: LC
- Factor(s) underlying the rating:
  - Some guidance may not provide enough sector specific detail

### 35. Sanctions
- Rating: LC
- Factor(s) underlying the rating:
  - No coverage for CFIs, credit providers other than money lenders against securities, some fintech companies, DPMS, accountants (for activities beyond providing financial services), and CSPs that are not attorneys

### 36. International instruments
- Rating: LC
- Factor(s) underlying the rating:
  - A minor deficiency relating to self-laundering (acquisition, possession or use of proceeds of crime does not extend to the perpetrator of the predicate offense).

### 37. Mutual legal assistance
- Rating: LC
- Factor(s) underlying the rating:
  - Minor shortcomings relating to confidentiality, the absence of a case management system and timely provision of MLA

### 38. Mutual legal assistance: freezing and confiscation
- Rating: LC
- Factor(s) underlying the rating:
  - Restraint orders can only be enforced if they are not subject to appeal or review
  - No specific provision for confiscation of instrumentalities intended for use in criminal activities

### 39. Extradition
- Rating: LC
- Factor(s) underlying the rating:
  - The authorities have not demonstrated they are able to execute extradition requests without undue delay and there is no case management system in place

### 40. Other forms of international cooperation
- Rating: LC
- Factor(s) underlying the rating:
  - It is not clear that all authorities can cooperate or that all information can be provided rapidly
  - South Africa did not establish that it exchanges information or assistance when there is an inquiry, investigation or proceeding underway
  - The only competent authority which gives feedback is the FIC

*Source: Annex II. Summary of Technical Compliance – Key Deficiencies*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2021/english/1zafea2021001.pdf_
