Building the Fintech Dream
The Latest Content
High-risk customers do not announce themselves. They arrive via referrals, hidden behind corporate structures and ownership layers that take days to unwrap manually. By the time a traditional EDD review is complete, the risk picture has already shifted. The BNM AML/CFT Policy 2026 was written for exactly this reality, pushing Malaysian reporting institutions toward automated Enhanced Due Diligence (EDD) systems that work in real time rather than in review cycles. The question for compliance leaders in 2026 is no longer whether to automate, but how much longer they can afford not to.
What Is Automated EDD and Why Does It Matter in Malaysia?
Automated Enhanced Due Diligence (EDD) is the use of Artificial Intelligence (AI), Machine Learning (ML) and integrated data pipelines to conduct deep investigations on high-risk customers without manual handoffs or review bottlenecks.
In Malaysia's regulatory context, it means your compliance system can verify identity, screen ownership structures, assess source of wealth and flag suspicious behaviour continuously, producing a defensible audit trail at every step without an analyst having to stitch it all together by hand.
This matters because BNM AML/CFT Policy 2026 has fundamentally changed what regulators come looking for. Bank Negara Malaysia is no longer satisfied with well-written policies sitting in a compliance manual. It is now assessing outcomes, which means the speed, accuracy and explainability of your EDD decisions are under scrutiny in a way they simply were not before.
The Regulatory Framework Behind EDD in Malaysia
For years, compliance teams built their programmes around documentation: gather the right papers, hold the right reviews and file the right reports. That model worked when regulators measured inputs. It does not work anymore.
Bank Negara Malaysia's move to outcome-based effectiveness means the focus has shifted entirely to results.
Under AMLATFPUAA 2001 Section 14 (Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act), reporting institutions are legally required to apply enhanced measures to high-risk customers, and BNM's revised 2024 AML/CFT and TFS policy document tightened these obligations further, aligning them with FATF ( Financial Action Task Force) standards and introducing counter-proliferation financing requirements. What this means practically is that your enhanced due diligence processes must now go deeper for high-risk customers, move faster and produce documentation that holds up to regulatory scrutiny without gaps.
The enforcement numbers tell the story plainly. In May 2025, BNM imposed over RM 3.7 million in penalties on two financial institutions for weak beneficial ownership verification, inadequate customer due diligence and delayed sanctions screening. Both had compliance programmes. Neither could demonstrate outcomes that satisfied the regulator's scrutiny.
And the personal stakes are just as real. Non-compliance with AMLA obligations can result in fines of up to RM 3 million (~USD 675,000), imprisonment of up to five years, or both, with directors and compliance officers personally liable when institutional controls fall short.
What BNM Actually Requires for High-Risk EDD Review
Here is the practical checklist that every reporting institution in Malaysia needs to be able to demonstrate for each high-risk relationship:
- Senior Management Approval before establishing or continuing a high-risk business relationship
- Source of Wealth and Source of Funds verification, supported by independently verified documentation
- Enhanced ongoing monitoring, calibrated to the customer's live risk score rather than a fixed review calendar
- Full audit trails capturing every decision, escalation and document request throughout the customer lifecycle
- Explainable risk decisions, particularly where automated scoring is used to flag or clear a customer
That fifth point deserves its own moment. Explainable AI (XAI) has moved from a technical feature to a regulatory necessity. If an algorithm flagged a customer as high-risk, your compliance team must be able to articulate exactly why in terms a regulator can follow and verify. Black-box decisions are no longer defensible under BNM's outcome-based framework.
Who Qualifies as High-Risk Under BNM's Risk-Based Approach
Not every customer requires EDD, but the categories that do are broader than many institutions realise. Under BNM's regulatory compliance framework, the following customer types trigger enhanced obligations:
- Politically Exposed Persons (PEPs) and their relatives or close associates (RCAs)
- Customers linked to high-risk geographies or sectors, including those operating through shell companies or using bearer shares
- Corporate entities with layered or opaque ownership structures requiring UBO (Ultimate Beneficial Ownership) unwrapping.
- High-Net-Worth Individuals where Source of Wealth (SoW) cannot be established through standard documentation
- Customers with hits against the Sanctions List Malaysia or global sanctions registers
The challenge is that most of these categories are not static. A customer who passed a standard risk assessment at onboarding may become high-risk six months later due to a change in ownership, a new sanctions listing or a shift in transaction behaviour. Manual processes struggle to catch this in time. Automated ones are built for exactly this scenario.
The Real Difference Between Manual EDD and Automated EDD in 2026
Understanding the gap between where most institutions are and where they need to be helps clarify what automation actually solves.
Manual EDD typically looks like this:
- A risk alert is raised and lands in an analyst's queue
- The analyst manually cross-references sanctions databases and PEP checks
- Documents are requested from the customer via email with no tracking mechanism
- Beneficial ownership is mapped using publicly available sources, which may be outdated
- The completed case file is assembled manually and routed to a senior manager for approval
- The entire process takes days, sometimes weeks, with quality varying based on analyst experience and workload
Automated EDD changes this at every step:
- High-risk customer risk scoring triggers instantly at onboarding and updates continuously throughout the customer lifecycle
- KYC verification and screening against global watchlists happens in seconds rather than hours
- Document requests are issued digitally with automated follow-ups and real-time status tracking
- Beneficial ownership structures are verified against live registry data rather than customer-supplied documents
- Senior management approval workflows are built into the system, with case files assembled automatically
- Every action is logged, timestamped and audit-ready without manual effort
The difference in KYC workflows between these two approaches is not incremental. It is the difference between a compliance programme that satisfies BNM's outcome-based assessment and one that does not.
Find out which parts of your EDD process need automation first
Why Local Registry Integration Matters for EDD in Malaysia
Most compliance platforms screen well across global databases but lose precision when a Malaysian corporate structure needs local verification. SSM (Suruhanjaya Syarikat Malaysia) integration changes this entirely.
When your EDD platform connects directly to SSM, beneficial ownership is verified against official registry filings in real time rather than taken at the customer's word. For fintech onboarding teams handling large volumes of corporate customers, this removes one of the slowest manual steps in the process.
Beyond SSM, automated platforms built for the Malaysian market also connect to Securities Commission Malaysia records for capital market entities and Labuan FSA data for customers with offshore structures, giving compliance teams a complete local picture without having to check each registry separately.
How EDD Automation Actually Works: A Step-by-Step View
Step 1: Risk Scoring at Onboarding
The moment a customer begins an account opening journey, automated high-risk customer risk scoring kicks in. Identity documents are verified, sanctions screening and PEP checks run simultaneously and a risk profile is assigned instantly. If the customer crosses a high-risk threshold, they are automatically routed into the EDD pathway. No manual triage, no queue.
Step 2: UBO Discovery Through SSM Integration
For corporate customers, automated platforms verify ownership structures by pulling live data directly from SSM (Suruhanjaya Syarikat Malaysia) and where relevant, Securities Commission Malaysia and Labuan FSA records. This means compliance teams are working from official filings rather than customer-declared information, which is precisely what BNM looks for when assessing whether beneficial ownership checks are genuinely robust.
Step 3: Source of Wealth Verification
Rather than chasing documents over email, automated platforms issue digital requests, track submissions and verify received materials against independent sources. What previously took weeks now takes hours.
Step 4: Continuous Screening via Transaction Monitoring
Transaction Monitoring Systems (TMS) keep watching after onboarding is complete. If a customer's transaction behaviour shifts away from their declared profile, they surface automatically for re-review. Adverse media screening runs in the background continuously, picking up new hits as they emerge.
Step 5: Senior Management Routing and Audit Trail
Once the review is complete, the system routes the case file to the appropriate senior management level for approval. Every decision is logged and timestamped automatically, producing the audit-ready documentation that BNM AML/CFT Policy 2026 outcome-based assessments specifically look for.
Where EDD Technology Is Heading in 2026
The global Enhanced Due Diligence market is projected to reach USD 10.08 billion by 2034, growing at a CAGR of 11.2%, and the institutions driving that growth are not investing in better periodic reviews. They are investing in systems that never stop watching.
For Malaysian institutions, this shift has a local advantage built in. FIED, the Financial Intelligence and Enforcement Department, continuously analyses suspicious transaction data from reporting institutions across the country. The patterns it identifies feed into the risk rules that automated EDD platforms run on, making locally deployed systems progressively more accurate and harder for financial crime to outmanoeuvre.
2026 Belongs to Institutions That Automate
The compliance teams winning in Malaysia in 2026 are not the ones with the most detailed policy documents. They are the ones who can open any high-risk customer file and show a regulator, in real time, exactly how the risk was identified, assessed, escalated and resolved. That capability does not come from manual processes. It comes from building the right automated infrastructure now, before BNM asks for the proof.
FlexComply, FlexM’s award-winning RegTech platform, brings together every layer of this capability in a single platform: automated high-risk customer risk scoring, continuous PEP and sanctions screening, SSM-integrated UBO discovery, digital source of wealth collection, Explainable AI (XAI) powered risk decisions and full audit trail generation, all aligned with BNM AML/CFT Policy 2026 and broader FATF standards. For Malaysian reporting institutions ready to move from policy to proof, it is the clearest path forward available today.
See how far your current setup is from BNM's 2026 standard
.png)
How many customers left your checkout last month without you ever finding out?
If you run a remittance house in Canada, your customers rarely voice frustration before they leave. The ones who reach your payment screen, encounter a card-only option and quietly exit were never going to file a complaint or send a message explaining their decision, and that makes them the most expensive kind of customer to lose because the data never tells you clearly that they are gone until the pattern has already been building for months.
Remittance from Canada in 2026 is fiercely contested, and the operators pulling customers away from card-only platforms are not always winning on rates or corridor coverage. They are winning at checkout. The people funding international money transfer Canada transactions every week are digitally fluent, fee-sensitive, and quick to move to a platform that meets them where they already are financially. Card-only checkout is not just a mere inconvenience for them. For your business, it is a slow and largely invisible drain on the customer base you have spent years building.
Why Remittance from Canada Is More Competitive Than Ever
Running a remittance business in Canada used to mean competing on corridor coverage and a rate that did not embarrass you next to Western Union. That landscape has shifted considerably.
The corridors themselves have not changed. Billions still flow annually from Canada to the Philippines, India, Nigeria, Pakistan, Mexico, and more and for the communities behind those transfers, remittance from Canada is a fixed monthly financial commitment, not an occasional transaction.
What has changed is the customer. The people sending money home in 2026 look very different from five years ago:
- They compare rates across multiple platforms before placing a single transfer
- They understand the difference between a transparent fee and a padded exchange rate
- They have used enough platforms to recognise friction the moment they encounter it
- They switch without announcement and rarely come back to explain why
International money transfer Canada providers have largely converged on speed and corridor coverage. The gaps that actually move customers between platforms now live in the experience around the transfer, and increasingly, that means what happens at checkout.
How Canadians Actually Prefer to Pay?
Financial habits in Canada have shifted more decisively in the last decade than most markets care to acknowledge. The way people pay for things day to day, whether it is rent, groceries, a shared bill or a routine transfer between accounts, has quietly but firmly moved toward direct bank payments that feel immediate, low-cost and entirely within their control.
Interac sits at the centre of that shift. Built directly into Canadian banking infrastructure, it has become the default payment behaviour for millions of people who use it not because it is the only option but because it is the most natural one. In 2025, Canadians processed more than 8.7 billion Interac transactions across the country. This isn’t an occasional choice, it’s well ingrained payment habits.
So when the same customer who paid their landlord via e-Transfer this morning arrives at a Canadian remittance checkout and finds only a credit card field, the friction is real and immediately felt, not as a minor inconvenience but as a genuine mismatch between how they manage money and what your remittance platform Canada is asking them to do. That mismatch does not just cost you the transaction. It quietly tells the customer that the platform was not built around people like them, and that is a difficult impression to walk back.
The Real Money Transfer Fees Canada Remittance Businesses Are Absorbing
Remittance margins are thin, and every operator in this space has built their business knowing that. What makes card-only checkout a particular problem is that it applies a 2% to 3% processing fee on top of that already compressed margin, on every transaction, every month, without exception.
Beyond the processing rate, card-only checkout quietly generates overhead that builds with every transaction:
- Failed payments that trigger retries, each carrying their own processing cost
- Declined transactions that create support tickets and manual resolution work
- Chargeback exposure on transfers that have already been sent and cannot be recalled
- Reconciliation complexity that grows steadily as transaction volumes scale
And sitting underneath all of that is arguably the most damaging cost of all. When a customer gets hit with an unexpected bank charge on top of your processing fee, they rarely call to complain about it. They simply choose a different platform for their next transfer and do not look back. The credit card fees remittance Canada businesses pay are one part of the problem, but the customers quietly walking away because of fees they never anticipated are what makes money transfer fees Canada operators absorb genuinely expensive in the long run.
The Cash Advance Problem Most Remittance Businesses Don't See Coming
Here is something a significant number of remittance operators are genuinely unaware of, and it is costing them customer trust on a regular basis.
When a customer uses a credit card to fund a transfer on your platform, their bank does not always treat it as a standard purchase. Many Canadian banks classify that payment as a cash advance, which triggers a completely different fee structure, one the customer did not anticipate and that your platform had no hand in creating. The Financial Consumer Agency of Canada explicitly lists wire transfers and money transfers among transactions treated as cash-like by card issuers.
What that looks like for the customer in practice:
- An immediate cash advance fee of 3% to 5% of the transaction amount
- A cash advance interest rate of 22.99% to 27.99% at major Canadian banks, well above standard purchase rates
- No grace period, meaning interest begins accruing from the moment the transaction processes
The customer checks their statement, sees charges that do not match what your platform quoted them and draws the most logical conclusion available, which is that the remittance company is responsible. That misunderstanding is difficult to correct once it has formed, and most customers do not give platforms the opportunity to explain it.
What follows is predictable. A frustrated review citing unexpected fees, a support ticket that takes time and resources to resolve and in many cases a customer who decides the platform simply cannot be trusted with their next transfer. For a business where remittance from Canada runs on repeat usage and word of mouth referrals within close-knit communities, that kind of reputational damage travels further and faster than most operators account for.
International Money Transfer Canada: Credit Card vs Interac
The payment method most Canadian remittance customers are looking for at checkout is not a new one. Interac is woven into how Canadians handle money on a daily basis, from rent and utility bills to splitting costs and moving money between accounts, a payment behaviour so routine it barely registers as a decision anymore. The reason it matters for international money transfer Canada businesses is precisely that familiarity. Offering it at checkout is not introducing something unfamiliar, it is meeting customers at a behaviour they already trust completely.
The difference between card and Interac at a Canadian remittance checkout goes beyond the processing fee, and for any operator still running card-only, the full picture looks like this:
ModuleCredit CardInteracMerchant Processing Fee2% to 3% per transactionFlat $0.05 to $0.15 per transactionCustomer Fee Risk3% to 5% cash advance fee applied by their own bankNoneChargeback ExposureHigh - $4.52 lost per $1 of fraudNone - payments are irrevocableSettlementT+1 to T+3 daysNear immediateCustomer ExperienceCard details required, unexpected charges possibleDirect from bank account, familiar and frictionlessCustomer TrustEroding for large transfersDeeply embedded in Canadian daily banking behaviour
For a business running on thin margins where customer trust is genuinely foundational, that gap is difficult to justify keeping.
What a Better Checkout Looks Like for a Canadian Remittance Business?
A better checkout for a Canadian remittance business is not a complete rebuild of what already exists. It is an addition, one that sits alongside the card option your customers already have access to, giving them a choice rather than a constraint.
Adding bank-direct payment through Interac to your remittance platform Canada does three things at once, and that simultaneity is what makes it worth understanding properly:
- Processing fees drop significantly, from a percentage-based card fee on every transaction to a flat rate that does not scale with the transfer amount
- The unexpected bank charges quietly driving customers away without complaint are removed from the equation entirely
- The gap between how your customers want to pay and what your checkout was offering them closes
Operationally, what Interac at checkout means for a business looking to add a payment gateway for remittance in Canada is equally straightforward:
- The customer selects Interac at the payment step and authenticates directly through their own bank
- No card details to enter, no cash advance classification risk, no chargeback window on a transfer already in transit
- Integration happens through an API connection that adds Interac alongside existing card processing without replacing it, so customers who send money internationally from Canada through your platform retain full payment flexibility
For a remittance platform in Canada running on tight margins with a customer base that has real options and knows how to use them, that kind of checkout flexibility is increasingly less of a differentiator and more of a baseline expectation.
What Fixing Checkout Actually Unlocks?
A checkout that genuinely works for your customers does more than reduce friction at the payment screen. It removes the support tickets about unexpected fees, improves repeat transaction rates and generates the kind of word of mouth that travels quickly through close-knit communities, the same way the current frustration does, except in your favour.
Research shows that 43% of Canadians will abandon a transaction entirely if their preferred payment method is not available. For a remittance from Canada business where every completed transfer represents real trust placed in your platform, that number is not an abstraction.
The businesses that get checkout right do not just recover lost transactions. They build something more durable, a payment experience that gives customers a genuine reason to stay and an equally genuine reason to recommend. In a market as referral-driven as international money transfer Canada, that kind of trust is what separates platforms that scale from ones that stall.
FlexMerchant, built by FlexM, a leading global fintech conglomerate, gives Canadian remittance businesses a straightforward path to adding Interac at checkout through a simple API integration. For operators ready to stop losing customers at the one step that should never be the problem, the conversation starts here.
To learn more, visit flexm.com/flexmerchants

What happens if a gambling business misses the FICA RCR deadline?
Every gambling institution in South Africa was required to submit a Risk and Compliance Return to the Financial Intelligence Centre, a self-assessment covering how well the business understands its money laundering, terrorist financing, and proliferation financing risk, and whether its controls actually manage that risk. Casinos had until 30 June 2026 to file, while every other gambling institution, bookmakers, betting operators, bingo halls, and limited payout machine operators, had until 31 July 2026. Both dates have now passed.
For any gambling business that didn't submit, three specific things are unclear right now: whether the Financial Intelligence Centre has already flagged the file, what the actual penalty range looks like once a case is assessed, and whether there's still a legitimate path to resolve it without lasting damage to the business's standing with the regulator. Those are the concrete questions worth answering first, starting with what the FIC Act itself says happens next.
What the FIC Act Says Happens Next?
Missing the FICA RCR deadline puts a gambling institution into a formal process under section 45C of the FIC Act, not an informal review at the regulator's discretion. The FIC's supervision and enforcement framework sets a sanction, once decided, along one of these paths:
- A caution not to repeat the conduct that led to the non-compliance
- A formal reprimand
- A directive to take remedial action
- Restriction or suspension of certain business activities
- A financial penalty of up to R10 million for a natural person, or up to R50 million for a legal entity
Which of these applies, and how severely, depends on the nature, seriousness, and extent of the non-compliance, along with any mitigating factors the FIC takes into account. The same framework governs FICA non-compliance gambling cases regardless of licence type, since the gambling sector is supervised directly by the FIC as item 9 of Schedule 1, alongside sectors like legal practitioners and credit providers.
Once a sanction is imposed, the FIC or the relevant supervisory body must publicise it, unless compelling and substantial circumstances justify withholding that. Institutions that dispute a finding or penalty can appeal, through the appeal board established under section 45E.
A gambling operator dealing with a missed FICA deadline now has a clear picture of what follows: a formal process, a defined range of possible sanctions, and a public record once a decision is made.
Can You Still Submit a Late RCR?
Every gambling institution that missed the FICA RCR deadline this year is sitting with the same question. Can the return still be filed, and what actually happens once it is.
One accountable institution missed the 31 May 2023 deadline under Directive 6, the exercise that preceded this year's RCR. The FIC opened a formal sanction process against that institution, and as part of the sanction, directed it to file the outstanding return by a fixed date, more than a year after the original deadline had passed. A gambling operator dealing with a missed FICA deadline right now is looking at the same likely path. The FIC sets the terms of remediation once it steps in, and the institution files on the timeline it's given, not on its own schedule.
The FIC provides an online compliance query channel for institutions to raise issues directly with the regulator, and when a sanction is assessed, it's weighed against the nature, seriousness, and extent of the non-compliance, along with any mitigating factors the institution can point to. Both give a gambling operator a real, available way to work toward FICA compliance South Africa recognises, rather than sitting on the problem and hoping it resolves on its own.
What Rebuilding FICA Compliance in South Africa Actually Requires?
A missed RCR usually means the business's compliance programme has a real gap, not just a missed form. Fixing that gap matters regardless of what the FIC's remediation process ultimately requires, because the moment resubmission is either requested by the FIC or made possible again, the business needs to be ready to act immediately, not scrambling to rebuild from scratch.
Section 42 of the FIC Act requires every accountable institution to maintain a documented Risk Management and Compliance Programme. Section 42(2C) requires that programme to be reviewed at regular intervals so it stays relevant to how the business actually operates. A missed deadline means one of two things happened: the review didn't happen recently enough, or it happened but missed this gap entirely.
Getting genuinely ready looks like four concrete steps, done in order:
- Review the RMCP against current operations, not the version drafted when the business first registered
- Identify exactly where the gap started, a lapsed registration, understaffed compliance function, or a misread requirement
- Document the gap and the corrective action taken, since the FIC's own guidance treats this record-keeping as part of an effective programme
- Confirm the FIC Org ID and registration details are current, so there's nothing left to fix at the moment resubmission becomes relevant
A business that works through these four steps now isn't just cleaning up after a missed deadline. It's positioned to respond the instant the FIC asks for a return, or the moment any future submission window opens, without losing time re-doing work that should have already been in place.
Why Ongoing FICA Compliance Can't Wait for the Next Deadline?
Treating the RCR as a once-off event is the exact pattern that leads back to a missed FICA deadline in a future reporting cycle. FICA doesn't structure compliance around a single annual filing. It structures it as a continuous obligation, and the RCR is simply the moment that obligation gets tested externally.
The FIC Act sets this out directly, across several distinct requirements:
- Section 21C requires ongoing due diligence throughout a business relationship, not just at onboarding, including continuous transaction monitoring and keeping client information current as circumstances change
- Section 43 requires ongoing employee training, not a single induction session completed once and forgotten
- The FIC's own Public Compliance Communication 53 recommends reviewing the RMCP annually, specifically because money laundering, terrorist financing, and proliferation financing risks change continuously, not on a fixed reporting schedule
Put together, these requirements describe a business that's expected to know its risk posture at any given moment, not one that reconstructs it under pressure once a return is due. Building genuine FICA compliance South Africa gambling operators can rely on year-round means the business can answer what its current exposure looks like on any random Tuesday, not just when the FIC comes asking.
That gap, between operators who maintain ongoing FICA compliance as a standing discipline and operators who treat it as a once-a-cycle scramble, is exactly what separates businesses that file cleanly from businesses that keep resurfacing in FICA non-compliance gambling cases. The work doesn't get lighter by waiting for the next deadline to force it.
The Compliance Stack Behind Year-Round FICA Readiness
Meeting ongoing FICA compliance obligations consistently requires more than a monitoring tool bolted onto onboarding. It requires a connected set of capabilities that together keep a gambling operator's risk picture current at all times, not just accurate on the day a return is due.
A genuinely complete stack for a gambling operator should cover ground like this:
- Identity verification at onboarding, with document checks across the international client base gambling operators increasingly serve, not just domestic clients
- Ongoing name screening against sanctions, watchlists, and politically exposed persons lists, refreshed continuously rather than checked once
- Risk assessment that updates a client's rating dynamically as behaviour changes, not a static score set at onboarding and left untouched
- Transaction monitoring built around gambling-specific red flags, given how fast cash moves through deposits and payouts in this sector
- Threshold monitoring calibrated to both regulatory minimums and the operator's own risk appetite
- Enhanced due diligence workflows for higher-risk clients, with a clear audit trail showing what additional checks were run and why
- Case and alert management that routes flagged activity to the right person, with a documented decision trail rather than an informal email thread
- Beneficial ownership discovery for corporate clients, a requirement set out directly under section 21B of the FIC Act
- Regulatory reporting tools that generate the records an RCR actually asks for, instead of assembling them manually under deadline pressure
None of these pieces work in isolation. A gambling operator with strong transaction monitoring but no beneficial ownership visibility, or solid onboarding but no ongoing screening, still has a real gap, and gaps like that are exactly what surface the next time a regulatory return comes due.
Legal obligation and operational discipline aren't the same thing, and a gambling business only stays audit-ready when both are running at once, not one propping up the other during a scramble.
Staying Compliant Going Forward
A gambling business only gets one real choice after this point: build compliance as infrastructure, or keep treating it as a recurring emergency. The first path costs effort now and pays back every cycle after. The second costs more each time, in penalties, in scrutiny, and in the hours spent reconstructing records that should have already existed.
FlexM has spent over a decade building compliance infrastructure for banks, MSBs, gambling operators and other regulated and non-regulated entities across the globe, including South Africa. FlexComply reflects that experience directly, bringing risk assessment, transaction monitoring, and regulatory reporting into one connected system, so the next FICA cycle draws on records that are already current rather than records assembled under deadline pressure.
The gambling operators who stop appearing in FIC enforcement notices aren't the ones who got lucky on timing. They're the ones who stopped running compliance as a once-a-year sprint.
No sales pitch, only a focused session cantered around your FICA obligations
Frequently Asked Questions
What happens if I miss the FICA RCR deadline?
The FIC opens a formal sanction process under section 45C of the FIC Act. Possible outcomes include a caution, a reprimand, a directive to take remedial action, restriction of business activities, or a financial penalty of up to R10 million for a natural person and R50 million for a legal entity.
How do I become FICA compliant after missing the deadline?
Review your Risk Management and Compliance Programme against current operations, confirm your FIC Org ID and goAML registration are active, and document the gap along with corrective steps taken. If the FIC has made contact, follow the timeline it sets.
Can I still submit my RCR late?
Only through the FIC's own process. In past cases, institutions that missed a deadline were later directed to file by a fixed date, but only after a sanction case had already opened.
How often do gambling operators need to review FICA compliance?
At least once a year for the RMCP itself. Due diligence, monitoring, and training aren't annual though, they're supposed to run continuously.
Who counts as an accountable institution under FICA in the gambling sector?
If you hold a provincial gambling licence, casino, bingo, betting, or LPM, you're covered under item 9 of Schedule 1.

Do you actually know if your business is on the FIC's radar this year?
For a large number of gambling operators in South Africa, the honest answer is uncertain, and that uncertainty is the actual risk, not just an inconvenience. The FICA RCR deadline falling on 31 July isn't new territory for the Financial Intelligence Centre. The regulator ran this exact exercise before, under Directive 6, and institutions that ignored it or assumed it wasn't urgent ended up facing formal notices and sanctions once the FIC followed through.
That history matters because Directive 11 isn't asking for less this time. It's asking accountable institutions, gambling operators included, to prove they understand the money laundering and terrorist financing risk sitting inside their own business, not simply state that they do. If your business hasn't confirmed its FIC registration status, or isn't certain who internally is responsible for this submission, that gap needs closing well before the end of July, not during it.
FIC Directive 11 and the 2026 Risk and Compliance Return
FIC Directive 11 requires specified accountable institutions, gambling operators included, to submit a Risk and Compliance Return 2026 report to the Financial Intelligence Centre. This report asks businesses to self-assess two things: how well they understand their exposure to money laundering, terrorist financing, and proliferation financing, and how effective their actual controls are at managing that exposure.
A written policy sitting untouched in a compliance folder won't hold up here. The FIC isn't asking whether a programme exists on paper, it's asking whether the business can demonstrate that programme is actually working, and that gap between documented and demonstrated is exactly what the RCR is designed to expose.
Here's what the submission actually involves:
- To be submitted electronically through the FIC's goAML platform, not by email or hard copy
- To cover three years of activity, from 1 April 2023 to 31 March 2026, so historical data needs to be on hand, not just current records
- To be filed by 31 July 2026 for non-casino gambling institutions specifically
- Once filed, cannot be edited or withdrawn, which makes internal review before submission essential
Gambling Institutions FICA: Are You an Accountable Institution?
A lot of gambling businesses in South Africa don't realise they fall under FICA until a notice actually lands in their inbox, and by then the runway to prepare properly has already shortened considerably. Under Schedule 1 of the FIC Act, gambling institutions sit as Item 9, which places the entire sector under FICA obligations, covering all four legal forms of gambling recognised under the National Gambling Act, 2004. That means casinos, bingo, betting, and limited payout machines are all in scope, each one licensed by a Provincial Licensing Authority somewhere across South Africa's nine provinces.
The reasoning behind this classification comes down to how the industry actually operates. Cash moves quickly here, and stakes get placed and settled with very little friction between deposit and payout, which is precisely the kind of environment that makes gambling attractive for laundering illicit money. That's why the FIC applies the same level of seriousness to gambling operators as it does to legal practitioners and estate agents, rather than treating the sector as a lower priority.
Size doesn't change any of this either. A single-site bingo hall carries the same gambling institutions FICA status as a bookmaker with dozens of branches across the country. Whether the operation is small or large, the FICA compliance deadline South Africa businesses are racing against this July applies just the same.
Licensed and Compliant Are Not the Same Thing
Running a gambling operation in South Africa means satisfying two regulators with two entirely different mandates, and the complexity sits in managing both properly, not just knowing they exist.
The National Gambling Board handles licensing, through your Provincial Licensing Authority and its Verified Gambling Operators Web Portal. That confirms you're legally entitled to operate. It says nothing about money laundering risk.
The Financial Intelligence Centre asks a different question entirely. Not whether you're licensed, but whether you understand your money laundering, terrorist financing, and proliferation financing risk, and can prove your controls manage it, before the FICA RCR deadline arrives.
Both deserve equal attention. Your licence protects your right to operate, while your standing with the FIC protects you from sanction. That second obligation is exactly what the FICA compliance deadline South Africa has set for this July, and no approval from the NGB covers for it.
Preparing Your goAML RCR Submission
The FICA RCR deadline doesn't leave room for figuring things out as you go. A clean goAML RCR submission depends on groundwork most institutions underestimate until they're already behind on it.
Registration comes first, and it isn't optional:
- A valid FIC Org ID, issued through goAML, is required before the submission option is even available
- Outdated or incomplete registration needs correcting on its own timeline, well ahead of filing
Once registration is confirmed, preparation is what actually determines how smooth the submission goes:
- Review the FIC's sample questionnaire in advance, gambling institutions work from a sector-specific edition, not the generic composite version
- Pull together your Risk Management and Compliance Programme, customer due diligence records, and history of regulatory reports filed with the FIC
- Make sure this covers the full three year reporting period the RCR requires, not just the most recent year
A few rules govern the filing itself. Only a compliance officer, or someone with equivalent authority, can submit, third party providers are not permitted to file on an institution's behalf. And once submitted, the RCR is final, with no way to edit or withdraw it afterward.
What Missing the Deadline Actually Costs You?
Non-compliance under FICA carries formal, financial consequences, and gambling operators weighing whether this deadline is worth prioritising should know exactly what those consequences look like before deciding.
Section 45C of the FIC Act sets out what the FIC can actually do to a non-compliant institution:
- Financial penalties of up to R10 million for a natural person
- Financial penalties of up to R50 million for a legal entity
- Cautions and formal reprimands
- Remedial directives requiring specific corrective action
- Restrictions or suspension of business activities in serious cases
- Public disclosure of the sanction, unless compelling circumstances justify withholding it
Public disclosures are worth sitting with for a moment, because it changes what a sanction actually costs an operator. A financial penalty is a number that gets paid and eventually forgotten. A published sanction is different, it stays visible to banking partners, correspondent institutions, and other regulators long after the fine itself has been settled, and it shapes how those relationships treat the business going forward.
The numbers so far suggest a lot of institutions are still exposed to this risk.
Casinos, along with crypto platforms, trust companies, and credit providers, faced an earlier deadline of June 30th. But by mid-June 2026, the FIC reported a shockingly low compliance rate of just under 12%. As out of over 5,600 registered businesses across these sectors, a mere 655 had actually filed their returns.
Directive 6 already ran this exact process once. The FIC issued formal notices of intention to sanction against institutions that failed to submit, and that enforcement record is the clearest signal available for how seriously the current Directive 11 gambling deadline will be treated. Nothing here is speculative. It's a repeat of a process the regulator has already carried out, with documented consequences for the institutions that didn't take it seriously the first time.
Gambling operators carry a particular exposure here that other sectors don't share as sharply, since the industry already moves large volumes of cash through rapid transactions, exactly the profile the FIC treats as elevated risk. An operator that files late, or not at all, doesn't just sit outside the rules on paper. It gets flagged into precisely the risk category this entire system was designed to identify.
Meeting the FICA Compliance Deadline South Africa
The FICA compliance deadline South Africa has set for gambling operators this year rewards preparation. It penalises delay just as clearly. There's very little middle ground between the two.
Registration needs to be sorted well before July. Sector-specific documentation needs to be gathered. Risk Management and Compliance Programme records need to be in order, not assembled under pressure once the submission window is closing.
FlexM has spent over a decade building compliance infrastructure for regulated and non-regulated entities across the globe, including South Africa, which is what makes FlexComply relevant here. The platform brings risk assessment, transaction monitoring, and regulatory reporting into one system, so operators aren't piecing together evidence from scattered records when a deadline like this one arrives.
Meeting this deadline isn't just about avoiding a sanction. It's what keeps a gambling business operating with the full confidence of its regulator, its banking partners, and the market it serves.
Frequently Asked Questions
Is my gambling business an accountable institution?
Yes, if you hold a provincial gambling licence in South Africa. Item 9 of Schedule 1 to the FIC Act classifies all four legal forms of gambling, casinos, bingo, betting, and limited payout machines, as accountable institutions, regardless of business size.
What actually happens if I miss the FICA RCR deadline?
The FIC treats it as non-compliance, not a late submission you can quietly fix later. You're looking at cautions, remedial directives, and penalties that can run up to R10 million for an individual or R50 million for a legal entity, and these sanctions tend to get published rather than handled quietly.
When do bookmakers in South Africa need to submit their FICA RCR?
Bookmakers sit under the betting category of gambling institutions, classed as non-casino operators. Their deadline is 31 July 2026, and the return needs to cover activity going back to 1 April 2023.
What is the FICA deadline for bingo operators?
Bingo halls follow the same rules as other non-casino gambling institutions. Same deadline, 31 July 2026, and the same three year reporting period.
Do sports betting companies actually need to file an RCR?
Yes, sports betting falls under the betting category in Item 9 of Schedule 1, so the 31 July 2026 deadline applies just as much to a sportsbook as it does to a bookmaker or bingo hall.

Most Canadian marketplace operators know exactly how much work it takes to build a merchant network worth being part of. Years of onboarding, relationship management, traffic building and problem solving on both sides of the transaction, all of it stacked up to create something that genuinely works.
Then a customer reaches the payment screen and leaves because the option they were looking for simply was not there. The merchant never finds out why, the cart sits abandoned and neither of you can trace the problem back to a checkout that was not built around how Canadians actually prefer to pay.
Canadians tap on the go, move money directly from their bank account via Interac and increasingly expect to complete an online purchase without a card anywhere in the process. The Interac payment gateway they rely on for rent, bills and everyday spending is the same infrastructure they are looking for when they land on your merchants' checkout screens, and most Canadian marketplace platforms are simply not giving it to them.
Online payment processing Canada in 2026 is not a space where card-only checkout is a defensible position anymore, and the operators who have not addressed this are absorbing the cost through merchant churn they cannot quite put their finger on.
Why Canadian Marketplace Checkout Has Become a Competitive Differentiator?
The Canadian marketplace space is more crowded in 2026 than it has ever been. The Canadian e-commerce market is projected to grow at 9.6% annually, pulling more platforms, more operators and more merchants into an environment where the differences between platforms are getting harder to articulate on product alone. Commission structures, onboarding speed and category breadth were once enough to distinguish one marketplace from another. In 2026, the most decisive differentiator has moved somewhere most operators were not watching closely enough, which is, the merchant checkout Canada experience their platform delivers to end customers.
Merchants evaluate platforms with a sharper eye on what their customers will experience at the payment step, because their own revenue depends on it. A merchant losing sales to checkout abandonment on one platform is not going to stay quiet and hope next month improves. They look at what payment methods for Canadian merchants other competing platforms are offering, and they make decisions accordingly.
The Canada payment gateway market is currently valued at USD 2.68 billion and growing at 22.75% annually, which reflects just how much operator and merchant attention is now following the checkout conversation. For merchant acquiring businesses in Canada managing networks of sub-merchants, getting checkout right has stopped being a technical afterthought and started being the reason merchants choose one platform over another.
What Payment Methods for Canadian Merchants Actually Look Like in 2026?
Understanding what your merchants need at checkout starts with understanding what their customers are actually doing at the payment step, and the picture in Canada in 2026 is specific enough to act on.
Canadians have strong, established preferences around how they move money, and those preferences do not soften when they land on a marketplace checkout. 58% of Canadians trust Interac e-Transfer over PayPal, and 52% say they are as comfortable paying a small business via Interac. These are not marginal preferences. They represent the mainstream of how Canadian consumers think about digital payments, and they belong to the customers your merchants are trying to convert every day.
The payment methods for Canadian merchants that actually reflect this reality in 2026 go well beyond a standard card field. Canadians want options that feel familiar and low-friction, bank-direct payments via Interac, mobile wallets for on-the-go purchases and payment flows that do not require them to reach for a card they may not want to use for that particular transaction. The gap between that expectation and what most marketplace checkouts deliver is wide enough to be measurable in abandonment rates, with 43% of Canadians willing to abandon a cart entirely when their preferred method is not available.
For marketplace operators, this is not a consumer behaviour trend to monitor at a distance. It is the standard your merchants are being held to by their customers right now, and the platforms that help their merchants accept Interac payments Canada-wide are the ones giving those merchants a genuinely competitive checkout experience rather than a limitation they have to work around.
The Checkout Mistakes Canadian Marketplace Operators Keep Making
Most of these are not dramatic failures. They are quiet gaps that accumulate over time and become expensive to diagnose once they are embedded in how the platform operates.
Offering card-only checkout and calling it done
Cards cover a portion of Canadian customers but leave out a genuinely significant segment who prefer to pay directly from their bank. When those customers land on a merchant's page within your platform and find only a card field, the sale is over before the merchant knows it was ever in play.
No fallback when a payment method is unavailable
A checkout that offers one payment method and nothing else has no recovery path when that method does not work for a particular customer. The customer does not wait around to figure out an alternative, and the merchant absorbs a lost sale they will likely never trace back to the payment screen.
Assuming Interac means a separate integration per merchant
This is arguably the most common misconception among operators managing larger networks. The belief that enabling bank-direct payment options for merchants Canada-wide requires repeating a complex technical process for every sub-merchant is what keeps many platforms stuck on card-only long after they know it is costing them.
Inconsistent checkout experience across the merchant network
When different merchants on the same platform offer different payment options because the platform has no unified sub merchant payments Canada infrastructure, the customer experience becomes unpredictable. That unpredictability erodes the trust that a marketplace brand depends on across its entire network.
Not connecting checkout gaps to merchant churn
Merchants attribute slow months to product issues, pricing or traffic. The operators managing them often do the same. Checkout abandonment caused by limited payment methods for Canadian merchants rarely gets named as the source of the problem, which means it simply does not get fixed.
What Poor Checkout Costs Merchants on Your Platform?
There are costs here that go beyond the abandoned transaction, and they tend to surface in ways that are genuinely difficult for merchants to diagnose from inside their own data.
Cash flow delays that compound at volume
Card settlements run on a T+1 to T+3 cycle. For merchants doing meaningful volume, that gap between transaction and settlement is a consistent cash flow constraint they are carrying every single week. Bank-direct payment options resolve this at the source rather than at the accounting level.
Fee structures that quietly erode margins
Merchants on your platform are absorbing card processing fees on every transaction, and on already thin retail margins that percentage adds up faster than most merchants track it until they sit down and do the annual calculation. Within a merchant acquiring Canada network, sub-merchants often have limited ability to negotiate better rates independently, so the platform's payment infrastructure becomes their cost reality.
Chargebacks that cost far more than the original sale
A disputed card transaction costs the merchant the sale, the product if it has already shipped, a processor dispute fee and the internal time spent building a response. For merchants operating within a marketplace without strong merchant payment solutions Canada infrastructure behind them, managing that process efficiently is genuinely difficult. Bank-direct payments eliminate this category of loss entirely because those transactions are irrevocable.
A reputation problem they did not create
When checkout feels limited or unfamiliar, customers associate that friction with the merchant they were buying from rather than the platform behind the payment screen. A sub merchant payments Canada infrastructure problem at the platform level quietly becomes a review problem at the merchant level.
Conversion gaps they can see but cannot explain
Merchants who list on multiple platforms compare performance across them. When one platform consistently delivers weaker numbers at the payment step, merchants notice. The connection between limited payment options and lower conversion is rarely named explicitly, but it shapes how merchants think about where they put their effort.
What Strong Merchant Payment Solutions in Canada Look Like?
Getting this right in 2026 is less about adding every possible payment method and more about offering the ones that actually match how Canadian customers manage money, consistently, across every merchant on the platform.
For a Canadian marketplace, strong merchant payment solutions Canada means the checkout experience your merchants deliver is not dependent on what each individual merchant has been able to set up independently. It means the platform carries the payment infrastructure, and every merchant on it benefits from that without needing to negotiate their own processor relationships or manage separate integrations.
In practical terms, what that looks like is a checkout that includes bank-direct payment through a reliable Interac payment gateway alongside existing card options, accessible through a single API connection at the platform level. The ability to integrate Interac e-Transfer API at the platform level means operators are not repeating a complex technical process for every sub-merchant they bring on. One integration extends to the entire network, and every new merchant that joins inherits a checkout that already works for Canadian customers.
Here is how card-only checkout compares to a multi-method checkout built around what Canadian customers actually use:
A merchant payment gateway Canada that handles this at the platform level is not just a checkout upgrade. It is a structural advantage that compounds as the merchant network grows, because every new merchant joins a platform that already gives their customers what they are looking for at the payment step.
The Marketplace Platforms That Get Checkout Right Will Pull Ahead
Canadian marketplace operators who solve this now are not just fixing a current problem. They are building a payment experience that compounds in their favour as their merchant network grows, because every new merchant that joins inherits a checkout that already works for Canadian customers rather than one they have to compensate for.
The operators who wait tend to find that merchant churn and conversion gaps are considerably more expensive to reverse than they were to prevent. Merchant payment solutions Canada infrastructure built at the platform level scales with the network, and the gap between platforms that have it and those that do not will become harder to close as the market normalises around better checkout standards.
FlexMerchants, built by FlexM, a leading global fintech conglomerate, equips master merchants to add Interac to checkout across their entire network through a single API integration, giving every merchant on the platform a payment experience that matches how Canadian customers actually want to pay.
1:1 session to explore checkout options tailor-made for Canadian marketplaces.
Frequently Asked Questions
What is Interac e-Transfer and how does it work for online payments?
Interac e-Transfer lets Canadians send money directly from their bank account to a recipient, without a card or third-party wallet involved. For online checkout, it works the same way: the customer authorizes payment through their own bank, and the funds move directly between accounts.
Is Interac only available to businesses based in Canada?
Interac is built for the Canadian banking system, so it works for any business selling to Canadian customers, regardless of where the business itself is incorporated. What matters is that the customer's bank supports Interac, which nearly all major Canadian banks do.
How is paying with Interac different from paying with a credit or debit card?
A card payment runs through a card network and takes a few days to settle. An Interac payment moves directly between bank accounts and settles close to instantly, with no card network involved at any point in the transaction.
How long does it take to add Interac to an existing checkout?
This depends on the provider, but a single API integration at the platform level typically takes days to a few weeks. Once it's live, it applies across the entire merchant network rather than needing to be rebuilt for each new merchant.
Is Interac safe for businesses processing high volumes of transactions?
Yes. Interact payments are authorized directly through the customer's own bank, using the same authentication their bank already requires. Because the transaction is irrevocable once completed, it also removes an entire category of fraud risk that card payments carry.

How confident are you that your business could survive a POCAMLA audit, if the Financial Reporting Centre requested your records this week?
POCAMLA Kenya has governed how businesses handle customer identification, due diligence, and suspicious activity reporting since 2009, but the Act enforced today looks nothing like the one written back then. It has been amended multiple times since, most significantly through the 2025 Amendment Act, and each round has brought tighter obligations while pulling in businesses that were never covered before.
That evolution is exactly why so many compliance teams get caught off guard. A policy built around an older version of the law, or around what felt sufficient a few years ago, rarely matches what POCAMLA Kenya actually requires now. Most businesses still treat AML compliance Kenya as something they set up once and revisit only when a problem forces them to, and that habit is precisely what the current version of the Act was written to catch.
What Is POCAMLA?
POCAMLA Kenya, formally the Proceeds of Crime and Anti-Money Laundering Act, criminalises money laundering in Kenya and sets out what businesses must do to stop their services being used to move illicit money. It became law in 2009, but the version enforced today is far stricter than the one originally written, shaped by several rounds of amendment and most recently by the 2025 Amendment Act, which raised penalties sharply and brought many more businesses under its scope.
Beyond the Act itself, a set of detailed regulations spells out how it works in practice. These cover how customer identity gets verified, when a transaction needs to be reported, and how long records must be kept. Anyone still working off an older understanding of POCAMLA Act Kenya is likely missing changes that now shape what compliance actually looks like.
POCAMLA Requirements Kenya: Who Must Comply
POCAMLA organises reporting institutions into two categories, and neither carries lighter obligations than the other, regardless of how differently they operate day to day.
Financial institutions cover the businesses most people associate with AML law in the first place:
- Banks and microfinance institutions
- Insurance companies
- Capital markets firms and stockbrokers
- Money remittance and payment service providers
- SACCOs
Designated Non-Financial Businesses and Professions, or DNFBPs, is the second category, and it has long included:
- Lawyers and accountants
- Casinos, both land based and online
- Dealers in precious metals and stones
Real estate agencies are the newest addition to this list, formally brought under the DNFBP definition, with the Estate Agents Registration Board now empowered for AML oversight. Many agencies that never considered themselves part of a regulated sector now carry the same due diligence and reporting obligations as a bank.
Industry labels have little bearing on whether POCAMLA requirements Kenya apply to a given business. What matters is exposure. Any entity handling client funds, facilitating high value transactions, or operating close to how wealth changes hands sits within scope, whether it has historically thought of itself as regulated or not.
Financial Reporting Centre Kenya (FRC): Registration and Supervision
Every reporting institution's relationship with POCAMLA runs through one body, the Financial Reporting Centre Kenya, which functions as the country's financial intelligence unit. Registration with the FRC isn't optional or informal. It happens through a dedicated online portal called goAML, and it's the first real signal to the regulator that a business understands it falls within scope and is prepared to operate accordingly.
Once registered, the relationship doesn't end there. The FRC expects reporting institutions to submit an annual compliance report by the 31st of January each year, detailing how the business has met its obligations under POCAMLA and the supporting regulations over the preceding twelve months.
Supervision itself is sector based, meaning the FRC works alongside regulators specific to each industry, the Central Bank of Kenya for banks, the Capital Markets Authority for capital markets firms, and the Gambling Regulatory Authority for casinos, while retaining overall authority to request records, investigate gaps, and take action where something doesn't add up. For a business that treats registration as a one time formality rather than an ongoing relationship, that's usually where the trouble starts.
Core POCAMLA Compliance Obligations
POCAMLA compliance in Kenya is not a single task completed during onboarding. It is a chain of obligations that runs for as long as a customer relationship exists, and each link in that chain sets up the next.
Customer due diligence and enhanced due diligence
Every reporting institution in Kenya has to verify who its customers are and assess the risk they carry. Standard due diligence covers most customers, but enhanced due diligence Kenya rules apply where the risk is higher, including:
- Politically exposed persons and their close associates
- Customers linked to high risk or FATF grey listed jurisdictions
- High value transactions
- Customers with complex or unclear ownership structures
Suspicious and cash transaction reporting
Once a business identifies risk, Kenyan law requires that risk to be escalated formally.
- A suspicious transaction report Kenya (STR) must reach the Financial Reporting Centre once suspicious activity is flagged, and under the 2025 Amendment Act, delaying that report is treated as non-compliance in its own right.
- Cash transactions carry a separate reporting duty. A cash transaction report Kenya (CTR) is required for any cash transaction equivalent to or exceeding USD 15,000, filed through goAML, regardless of whether the transaction itself appears suspicious.
Ultimate beneficial ownership
Reporting institutions in Kenya are also required to look past the individual in front of them and identify who ultimately owns, controls, or benefits from that customer, particularly where a company or legal structure is involved. Beneficial ownership Kenya POCAMLA requirements have tightened considerably in recent years, closing what used to be a common gap in corporate onboarding.
Record keeping
None of the above holds up without documented proof it happened. POCAMLA record keeping obligations, set out under Regulation 37 of the Proceeds of Crime and Anti-Money Laundering Regulations, require customer identification records, due diligence notes, and transaction records to stay accurate, complete, and retrievable, with a minimum retention period of seven years.
Each obligation looks procedural on its own. Lined up together, they form the exact sequence an FRC inspection tests, and the gaps that surface are usually the ones where one step in that chain was treated as optional.
POCAMLA Penalties for Non-Compliance
The financial risk of getting POCAMLA wrong is steeper than most businesses expect, and it isn't a single flat number. Under the Proceeds of Crime and Anti-Money Laundering Act, POCAMLA penalties scale with both the offence and the entity involved.
- Up to 14 years imprisonment for an individual convicted of money laundering, alongside a fine of up to KES 5 million or the value of the property involved, whichever is higher
- Up to KES 25 million, or the value of the property involved, whichever is higher, for a company convicted of the same offence
- Up to 50 percent of the amount involved as a separate penalty for failing to declare monetary instruments crossing Kenya's borders
- An additional KES 10,000 per day for continued non-compliance, capped at 180 days
A business that assumes one number covers every scenario is usually underestimating what it's actually exposed to, especially once cross-border transactions enter the picture.
Kenya's FATF Grey List Status in 2026
Kenya was placed on the FATF grey list in February 2024, and it remains there as of the June 2026 plenary. Algeria and Namibia both exited that same review cycle after demonstrating sustained reform, a contrast that makes Kenya's continued listing harder to treat as a formality still working itself out in the background.
The practical consequences are already visible across how Kenyan institutions do business internationally:
- Correspondent banks apply heavier scrutiny to cross-border payments routed through Kenyan institutions
- International partners lean more heavily on enhanced due diligence before entering new relationships
- Investors factor grey list exposure directly into risk pricing before committing capital
- Approvals that once moved quickly now come with additional documentation requests, or in some cases, don't come through at all
This exposure attaches to the jurisdiction, not to any single institution's individual track record. Every business operating under Kenya FATF grey list 2026 conditions absorbs a share of that scrutiny by default, regardless of how disciplined its own compliance programme happens to be.
POCAMLA Compliance Checklist
Understanding the obligations is one thing. Proving them in practice, on demand, is what actually holds up during an FRC inspection. Most gaps trace back to one of the following being treated as settled once and never revisited since.
- Registered with the Financial Reporting Centre through the goAML portal
- Documented AML/CFT policy in place, covering onboarding, CDD, and escalation procedures
- Risk-based customer due diligence process applied consistently across all customers
- Enhanced due diligence triggers clearly defined for PEPs, high-risk jurisdictions, and complex ownership structures
- Beneficial ownership identification built into onboarding for corporate and legal entity customers
- Suspicious transaction reporting process that can move quickly once risk is flagged
- Cash transaction reporting process in place for transactions at or above the USD 15,000 threshold
- Records retained for a minimum of seven years, in a format that's accurate, complete, and retrievable on request
- Staff trained on AML obligations relevant to their role, rather than a generic annual refresher
- Annual compliance report submitted to the FRC by the 31st of January deadline
The businesses that hold up under scrutiny aren't the ones with the most polished policy document. They're the ones that can produce evidence against every line above without needing a week to prepare for it.
Staying Ahead of POCAMLA Compliance
POCAMLA keeps moving in one direction. More sectors get pulled in, penalties get heavier, and the bar for what counts as compliant keeps climbing. That trend shows no sign of slowing down, which means the rules businesses are working with today will likely look outdated again before long.
FlexComply, an award-winning, end-to-end compliance solution by FlexM, the leading global fintech conglomerate, gives Kenyan businesses everything they need to stay compliant, from identity verification and due diligence to transaction monitoring and regulatory reporting, so they can stay ahead of POCAMLA compliance rather than scramble to catch up every time it changes.

.gif)



%20(1)%201.png)


.png)



