I was proud to represent GCI at the South African Anti‑Money Laundering & Financial Crime Conference last weekend, contributing to important discussions on strengthening compliance, supervision and financial crime resilience.
One of the central messages from the conference was that regulators and financial institutions are not opposing forces. They are on the same side, fighting the same enemy. The true adversary is financial crime, and the purpose of anti-money laundering legislation is not merely to create rules for institutions to follow, but to disrupt money laundering, terrorist financing, proliferation financing, fraud and the criminal networks that exploit the financial system.
1. Regulators and Financial Institutions are Partners in Disruption
A recurring theme was the need to move away from a defensive mindset in which regulation is seen as a burden imposed on financial institutions. Regulators emphasised that they and the private sector share a common objective: preventing the financial system from being abused by criminals. This requires institutions to see themselves not only as regulated entities, but as active disruptors of money laundering and financial crime.
The importance of reporting was repeatedly highlighted. Reporting is not an administrative exercise, it is one of the primary tools available to detect, investigate and prosecute criminals. The message was simple: all roads lead to reporting. Without timely, accurate and meaningful reports, law enforcement and regulators cannot build the intelligence picture needed to follow the money, connect criminal networks and recover the proceeds of crime.
2. FATF Next Mutual Evaluation of South Africa: Outcomes, Not Paper Compliance
South Africa’s next Financial Action Task Force mutual evaluation was one of the dominant topics. The next mutual evaluation is due in February next year, with the report of that evaluation due to be submitted to the FATF plenary in October 2027. The evaluation will not be satisfied by the existence of policies, rules and frameworks alone. South Africa will need to demonstrate that the controls in place are effective and that there has been a measurable change in compliance behaviour.
The country will need to show tangible outcomes and prove the ability to investigate and prosecute perpetrators of financial crime, and to recover the proceeds of crime.
3. Weaknesses Identified in Compliance Implementation
Regulators noted several common implementation weaknesses identified during investigations and supervisory engagements with FIs. Amongst others, beneficial ownership requirements are not always being fully implemented. Simplified due diligence and enhanced due diligence are sometimes not being properly distinguished based on client risk ratings. In the area of financial sanctions, regulators found instances where clients were not being screened, or where institutions could not produce evidence that screening had taken place.
The request by the Financial Intelligence Centre for financial institutions to submit their Risk Management and Compliance Programs (RMCP) reinforced the need for RMCPs to accurately reflect the institution’s actual risk profile. An RMCP must fit the company. A purchased or generic RMCP that nobody internally can explain is merely a document, not a control.
4. South Africa’s Evolving Financial Crime Landscape
Financial crime in South Africa is becoming more organised, more digital and more cross-border. It is no longer only a story of isolated corruption. Criminal networks are exploiting weaknesses created by fragmented responses across the public sector, private sector, regulatory agencies and law enforcement bodies. Collaboration is therefore non-negotiable. No government department, regulator or institution can fight financial crime on its own.
Several South African typologies received particular attention, including money mule accounts, shell companies, romance scams, online gambling and fraud through mobile applications. Mule accounts remain a significant risk, and many are linked to real individuals rather than synthetic identities.
The conference also highlighted the human impact of financial crime. The three biggest victims of financial crime in South Africa were identified as firstly the State purse, secondly the elderly and thirdly informal-sector traders. The State loses significant amounts of public money through corruption, fraud and other financial crimes, ultimately affecting taxpayers and public service delivery. Barriers to prosecution and recovery include victim cooperation challenges like emigration and victims who are unwilling or unable to testify.
Gambling was identified as a major and growing money laundering risk in South Africa. It can also be the cause of predicate crimes. Regulatory focus on casinos has had an impact, but online and informal gambling is expanding rapidly and presents significant fraud and money laundering vulnerabilities. Examples were given of corruption and fraud cases where the proceeds of crime were used to fund gambling habits, with large amounts of illicit gains ultimately lost through gambling activity in casinos.
Fraud was described as having reached the level of a national security concern. Organised crime hides behind legitimate vehicles and it operates within parts of the informal sector. Large criminal syndicates and extortion cartels create not only financial harm, but also personal safety risks for investigators, lawyers, prosecutors and others involved in disrupting these networks.
5. Geopolitical Risk, Sanctions and Horizon Scanning
Geopolitical risk was another important theme. Geopolitical risk is no longer only about who your neighbouring countries are, but also about the strategic ties a country has
Institutions need to consider how geopolitical risk is built into internal frameworks, including sanctions screening, customer due diligence, enhanced due diligence and transaction monitoring. Governance structures must be able to respond quickly, analyse emerging risks and make defensible decisions. They must also include horizon scanning. In this environment, managing uncertainty has become the status quo.
6. Always-On Compliance and the Role of AI
A major theme was the mismatch between the always-on nature of financial services and the periodic nature of traditional compliance. Financial institutions are always on, clients are always on and criminals are always on, yet compliance often works through periodic reviews and static risk assessments. Customer risk should increasingly be viewed as a moving picture rather than a static snapshot.
Artificial intelligence was presented as a powerful tool for always-on compliance. AI can analyse large volumes of data, identify patterns and connect information faster than any human team. It can help reduce noise in alert management, automatically resolve low-risk false positives and allow human specialists to focus on the smaller number of unresolved alerts that require judgement. More than 90% of hits in transaction monitoring may be false positives, and existing AI tools can materially reduce alert noise.
However, AI must remain a tool, not a replacement for accountability. A human must remain in the loop because AI can be manipulated and cannot be trusted without oversight. Institutions do not necessarily need to start afresh with their systems when it comes to implementing AI, it can be bolted onto existing systems. Future systems are likely to support continuous customer risk rating along with daily customer profile and transaction screening.
7. Crypto Assets: Speed, Cross-Border Risk and Regulatory Complexity
Crypto assets present risks that are not merely traditional AML risks in a new format. They are quantitatively different and require different modes of attack. Crypto transactions are inherently cross-border, fast-moving and difficult to trace without specialised tools. Amongst others, VPNs, mule accounts, cold storage devices and self-hosted wallets can severely complicate tracing and recovery. Stablecoins were identified as one of the most commonly used methods for laundering value through crypto channels.
The travel rule remains one of the biggest regulatory challenges because it is not applied universally and different jurisdictions apply different thresholds and criteria. Blockchain analytics tools are critical and should not be regarded as optional. Enhanced transaction monitoring is essential.
The South African government has gazetted a draft crypto asset manual, and proposed legislation may treat transactions to and from self-hosted wallets as offshore transactions for exchange control purposes. Transfers to self-hosted wallets will be considered exports of capital, and transfers from such wallets to South African exchanges may be prohibited as they raise uncertainty about the source and origin of funds. Entities (corporates) may not transact with self-hosted wallets.
8. Terrorist Financing and the Need for Public-Private Cooperation
Terrorist financing was discussed as an area where the value of funds may be lower than in large-scale money laundering, but the impact is far greater because it can involve loss of life. Sub-Saharan Africa was described at high risk of terrorism financing. Terrorism is evolving, with the use of drones, kidnapping for ransom, gaming platforms, online gambling, casinos, youth radicalisation, technology, AI deepfakes and crypto channels all contributing to a more complex threat environment.
Non-profit organisations were also highlighted as presenting elevated risks where there is insufficient visibility over where funds ultimately end up. The need for stronger public-private cooperation in terrorist financing was emphasised. As with money laundering, the fight against terrorist financing requires coordination, intelligence sharing and a collective response across sectors.
9. Privacy, Information Sharing and Judgement
The tension between privacy laws, AI and AML transparency was also discussed. South African privacy protection laws not only apply to individuals but also apply to entities. It was discussed that financial institutions should share information where appropriate to combat financial crime, however privacy obligations may limit what can be shared and how. The value of building internal watchlists and internal data and also responsibly sharing that information between financial institutions was discussed as a tool in fighting AML. This requires careful judgement, clear governance and a defensible understanding of when information sharing is necessary, proportionate and lawful.
10. From Rules-Based Compliance to Effective Crime Prevention
The conference challenged compliance professionals to ask whether their policies help catch criminals or merely demonstrate that rules have been followed. A purely rules-based system sees only black and white, while financial crime often operates in the grey. Chasing alerts does not stop crime if most alerts are noise. Activity is not the same as effectiveness. Clearing alerts, completing reviews and maintaining files will not be enough if they do not contribute to disrupting criminal activity. If members of a due diligence team cannot explain the flow of funds from the documents on file, then what has been completed is a questionnaire rather than meaningful due diligence. The focus must therefore shift from activity to effectiveness, from process completion to disruption, and from collecting more data to identifying the right signals.
For compliance functions, this means developing governance structures, tools and escalation processes that can respond to fast-changing risks. It also means ensuring that documentation is clear, specific and understood by the people responsible for applying it. Clear documentation, strong investigation capability, meaningful reporting and practical collaboration are now central to demonstrating effectiveness.
Enforcement matters because enforcement changes behaviour
Conclusion: Your Work Matters
The conference ended with an important reminder for everyone working in AML: your work matters, your work makes a difference. It protects vulnerable people. It also safeguards public funds, supports the integrity of the financial system and helps disrupt criminal networks. The challenge for institutions is to move beyond proving that compliance activity has taken place, and to show that their controls, reporting, investigations and collaboration are making a real difference.
