Running the brokerage

FICA in a brokerage: are you an accountable institution, and what if you are not?

Schedule 1 of the FIC Act was rewritten in 2022. Work out whether your brokerage is an accountable institution, and the duties that bind you either way.

Published on 8 min readFCB.ai
Contents
  1. Start with the Schedule 1 wording, not with a checklist
  2. The duties that bind every business, accountable institution or not
  3. Where the WhatsApp inbox actually matters
  4. Putting it in the firm, not in a folder
  5. Frequently asked questions

Two brokerages, same suburb, same size. One has a compliance officer who registered the firm with the Financial Intelligence Centre years ago, files a risk and compliance return, and runs a full risk management and compliance programme. The other has never heard of an RMCP and assumes FICA is the insurer's problem. Both of them are probably wrong about something, because the question of who is an accountable institution under the Financial Intelligence Centre Act was quietly rewritten when Schedule 1 was amended with effect from 19 December 2022 — and because a second set of duties applies to every business in South Africa regardless of how that question is answered.

This is an organisational article rather than a legal one. The aim is to get you to the right answer for your own firm, in writing, and then to put the resulting work in someone's job description instead of leaving it floating.

Start with the Schedule 1 wording, not with a checklist

An accountable institution is not a type of company. It is a list. Schedule 1 of the FIC Act names the businesses that carry the full anti-money-laundering load — registration with the FIC, client due diligence, an RMCP, a compliance officer, cash threshold reporting, record keeping, training. If your activity is not on the list, none of that follows automatically.

The item that most brokerages ask about is the insurance one. The Financial Intelligence Centre states it as a person who carries on a life insurance business as defined in the Insurance Act, 2017, but excluding reinsurance business as defined in that Act. Read it carefully: the item is anchored to the Insurance Act licence, which is the insurer's licence. A firm whose business is advising on and servicing life policies under a FAIS licence is not, on the face of that wording, carrying on life insurance business. Short-term and commercial intermediaries have never sat in that item at all.

That is not a licence to stop reading, for three reasons.

  1. Schedule 1 has other items, and firms do more than one thing. If the group also provides credit, acts as a trust or company service provider, deals in high-value goods, or runs any form of money or value transfer, each of those items has to be tested on its own. Group structures are where firms get caught: the brokerage is clean, the sister company is not.
  2. Your contracts may impose the duties anyway. Binder and outsourcing agreements routinely push identification, verification and record-keeping obligations down to the intermediary, because the insurer carries the regulatory risk. Those obligations are then contractual and auditable, and an insurer audit is a far more likely event than an FIC inspection.
  3. Some duties do not depend on Schedule 1 at all. That is the next section, and it is the part most often missed.

Whatever conclusion you reach, write it down and date it. A one-page memo signed by the key individual, naming each Schedule 1 item considered and why it does or does not apply, is the artefact an inspector, an insurer or a professional indemnity underwriter will ask for. An opinion held in someone's head is not a control.

The duties that bind every business, accountable institution or not

Two obligations reach far beyond the Schedule 1 list, and a brokerage that has concluded it is not an accountable institution still has to run both.

The first is suspicious and unusual transaction reporting under section 29. The duty falls on persons who carry on a business, and on their employees and officers — not on a category of licensed firm. The report goes to the FIC as soon as possible and, per the Centre's own guidance, no later than 15 days excluding Saturdays, Sundays and public holidays after the person becomes aware of the facts. Two practical consequences follow: the clock starts when a staff member forms the suspicion, not when a manager gets around to it, and the client must not be told that a report is being considered or has been made.

The second is targeted financial sanctions. The FIC is explicit that the obligations in sections 26A, 26B and 26C are not confined to accountable institutions: no person may deal with property owned or controlled by a sanctioned person or entity, and property in your possession that belongs to one must be reported. For a brokerage, that means screening against the sanctions list is part of taking on a client, not an optional extra you buy when you grow.

DutyWho it bindsWhat it looks like in practice
Registration with the FIC, RMCP, compliance officer, trainingAccountable institutions onlyRegistration, a written programme, a named officer, an annual training record
Client identification and verification to FICA standardAccountable institutions; often intermediaries by contractDocuments collected and retained at onboarding, refreshed on a risk basis
Cash threshold reportingAccountable and reporting institutionsAutomated reporting of cash above the prescribed threshold
Suspicious and unusual transaction reports (section 29)Any person carrying on a business, and their staffAn internal escalation route and a report filed within 15 working days
Targeted financial sanctions (sections 26A to 26C)Any personScreening at onboarding and on list updates; freeze and report on a match

Where the WhatsApp inbox actually matters

The typical brokerage suspicion does not arrive as a transaction. It arrives as a sentence in a chat thread, usually from a client who is being helpful. The patterns worth training staff to notice are boring and repetitive:

  • A request to pay a premium in cash, or to split one premium across several payers.
  • A third party offering to pay for a policy on a life or an asset they have no obvious connection to.
  • An overpayment followed by a request to refund the difference to a different account.
  • A single-premium or large lump-sum product taken out and cancelled early, with the refund routed elsewhere.
  • A client who resists giving any information about the source of funds, or whose explanation changes between messages.

Three things make this workable in a firm where consultants handle dozens of threads a day. The conversation has to be retrievable months later, which is the same discipline as FAIS record-keeping on WhatsApp and should not be a second system. The identity and address documents clients send as photographs have to land somewhere structured rather than in a phone gallery — the document collection workflow is the place to fix that. And the escalation route has to be a single named person, reachable the same day, because the section 29 clock starts at the moment of suspicion.

Tooling helps only if it keeps the trail. In ORIS, client conversations sit against the customer record in a shared inbox rather than on a consultant's handset, flags and notes stay attached to the client, and audit logs record who did what. The export is CSV; there is no native feed into a screening vendor or a broker management system, so the screening step remains a human process you have to schedule. Be clear-eyed about that when you write the procedure: automate the retrieval, not the judgement.

Putting it in the firm, not in a folder

A workable arrangement in a firm of five to fifty people has four moving parts and no committee.

  1. A status memo, signed and dated by the key individual, recording the Schedule 1 analysis and the date it should be revisited — at minimum when the firm adds a licence category, buys a book or restructures.
  2. One named escalation point for suspicions, with a deputy, and an instruction that consultants escalate rather than investigate. Investigating tips clients off.
  3. A screening step inside onboarding, so that no policy is submitted to an insurer before the sanctions check has been done and recorded against the client record.
  4. An annual refresher of twenty minutes for every client-facing person, built around the five message patterns above rather than around the statute. Keep the attendance register; it is the only evidence that the training happened.

None of this is expensive. What it costs is a decision, taken once, about what your firm actually is — and the discipline of writing the answer down. If you want to see how a shared, auditable client thread changes the mechanics of that, book a walkthrough and bring your onboarding checklist with you. The South African context for the rest of it, from the FSCA to POPIA, is summarised on our South Africa country page.

Frequently asked questions

Is a short-term insurance brokerage an accountable institution?

On the Schedule 1 list as the FIC publishes it, the insurance item is framed around life insurance business as defined in the Insurance Act, 2017, which is the insurer's licensed business. A short-term or commercial intermediary does not fall into it on that wording. You should still test every other Schedule 1 item against what your firm and any related companies actually do, and have your compliance officer confirm the conclusion in writing.

We registered with the FIC years ago. Should we deregister?

Do not act on an article. Registration status, past filings and any group activities all bear on the answer, and deregistering in error is worse than an unnecessary registration. Take the status memo to your compliance officer or attorney, and if the conclusion is that registration is not required, ask them to handle the deregistration and to keep the reasoning on file.

If we are not an accountable institution, do we still have to report suspicious transactions?

Yes. Section 29 applies to persons who carry on a business and to their employees and officers, which includes every brokerage in the country. The report must reach the FIC as soon as possible and no later than 15 days excluding weekends and public holidays after you become aware of the facts, and the client must not be told.

Does sanctions screening apply to a five-person brokerage?

The FIC's position is that the targeted financial sanctions obligations in sections 26A to 26C apply to any person, not only to accountable institutions. The practical minimum for a small firm is a screening step at onboarding, a repeat check when the sanctions list is updated, and a recorded outcome against the client file.

Can our AI-assisted inbox flag suspicious messages for us?

It can surface and route; it cannot decide. Classification and sentiment analysis help a supervisor see which threads need a human eye, and drafts speed up the reply. The suspicion itself, the decision to report and the wording of the report remain the firm's, and the escalation route must work even when the software does not.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo