Search legal guides

Search MJ Kotze Inc legal guides and articles

FICA Compliance

Risk Management and Compliance Programme

The Risk Management and Compliance Programme of MJ Kotze Inc., established in terms of section 42 of the Financial Intelligence Centre Act 38 of 2001.

Version 3.0 | Approved 2 July 2026 | Next review October 2026

1. The Firm’s Status and Registration

1.1 MJ Kotze Inc. (“the firm”) is an incorporated legal practice and a commercial juristic entity contemplated in section 34(7) of the Legal Practice Act 28 of 2014. The firm is an accountable institution under item 1(b) of Schedule 1 to the Financial Intelligence Centre Act 38 of 2001 (“the Act”). Where the firm forms or administers companies or trusts for clients, that work falls within item 2 of Schedule 1 (trust and company service providers), and the firm keeps its goAML registration aligned with the Schedule 1 items under which it practises.

1.2 The firm is registered with the Financial Intelligence Centre (“the FIC”) on the goAML platform in terms of section 43B of the Act (Org ID held on file). Changes to the firm’s registered particulars are updated on goAML within 90 days (s 43B(4)). goAML credentials are personal to the compliance officer and are not shared (FIC Directives 1, 2 and 4).

1.3 The firm is supervised and inspected by the FIC (section 4(g) of the Act, there being no Schedule 2 supervisory body for legal practitioners; inspections under sections 45A–45B; PCC 47A para 1.5).

1.4 This programme (“RMCP”) is developed, documented, maintained and implemented in terms of section 42(1) of the Act. No regulation prescribes the content of an RMCP; the firm has regard to the FIC’s Revised Guidance Note 7A (1 September 2025) and PCC 53 as authoritative guidance. In accordance with that guidance, this programme is commensurate with the size, complexity and nature of the firm’s business.

2. Governance and Approval

2.1 The firm is a legal person; sections 42A(1) and 42A(2) of the Act apply.

  • Highest authority (s 42A(1)): MJ Kotze, sole director, is responsible for the firm’s compliance with the Act and with this RMCP.
  • Compliance function (s 42A(2)): MJ Kotze is assigned to ensure the effectiveness of the compliance function, and is referred to in this RMCP as the compliance officer.
  • Approval (s 42(2B)): this RMCP is approved in writing by the sole director. Approval is not delegated.
  • Availability (s 42(3)): this RMCP is published on this page and provided to every employee or contractor involved in client take-on, trust-account transactions or other work to which the Act applies.
  • Production (s 42(4)): a copy is provided to the FIC on request.

Compliance officer: MJ Kotze (Director)

Email: martin@mjkinc.co.za

3. Business Risk Assessment

3.1 In terms of section 42(2)(a) the firm identifies, assesses, monitors, mitigates and manages the risk that its services may involve or facilitate money laundering, terrorist financing or proliferation financing. The assessment has regard to the FIC’s sector risk assessment for legal practitioners (March 2024) and is revisited at each review of this RMCP.

Service lineInherent riskPrincipal controls
Conveyancing and property transactionsHigherSource-of-funds enquiry on trust deposits (s 21A, section 11); cash triggers (sections 4 and 9).
Company and trust formation and administrationHigherBeneficial-ownership procedures (section 6) applied to every entity client.
Trust account (client money)HigherScrutiny of receipts; third-party and cash deposits treated as risk indicators (Annexure B).
Corporate and commercial advisory, drafting, litigationLowerFee-for-service work paid by EFT; limited movement of client funds.

3.2 Further factors considered:

  • Clients: predominantly South African individuals and owner-managed businesses; foreign clients are rated in terms of section 4.
  • Geography: South African practice; no foreign branches or subsidiaries.
  • Delivery channels: in-person and remote onboarding; remote onboarding is supported by the verification methods in section 5.
  • Cash: the firm does not accept payment in cash in the ordinary course; material cash is a high-risk trigger (section 4) and a reporting trigger (section 9).
  • Proliferation financing: the firm undertakes no trade-finance or dual-use-goods work; the risk is addressed through the sanctions screening in section 8.
  • New services: before a materially new service is offered, the compliance officer records an ML/TF/PF risk assessment of it and updates this RMCP where required.

3.3 The firm’s overall ML/TF/PF risk is assessed as MEDIUM.

4. Client Risk Rating

4.1 Each client is rated low risk or high risk at take-on by the person opening the matter, confirmed by the compliance officer. A client is high risk if any of the following applies:

  1. the client or a beneficial owner is a foreign politically exposed person, or is a domestic politically exposed person or prominent influential person and the relationship otherwise carries elevated risk (section 7);
  2. the matter is expected to involve material cash (any single cash amount near or above the R49 999.99 reporting threshold, or apparent splitting of cash into smaller amounts);
  3. the client is a natural person who is neither a citizen nor a resident of South Africa, or an entity or trust with no operations or presence in South Africa;
  4. the client, a beneficial owner or the funds are connected to a jurisdiction on the FATF high-risk or increased-monitoring lists, or the client or a beneficial owner is the subject of credible adverse information;
  5. the ownership or funding structure is complex or opaque without a commercial explanation;
  6. a risk indicator in Annexure B is present; or
  7. the compliance officer, for recorded reasons, rates the client high risk.

4.2 All other clients are rated low risk.

4.3 Service-line risk (section 3) does not of itself change a client’s rating. The elevated risk in conveyancing, entity and trust formation, and trust-account work is addressed through the controls that apply to every matter: the section 21A source-of-funds enquiry, scrutiny of trust-account receipts (section 11), the beneficial-ownership procedures (section 6) and sanctions screening (section 8). This is the firm’s ground under section 42(2)(m) for permitting simplified due diligence for low-risk clients in those service lines.

4.4 The rating and its reason are recorded in the compliance register (Annexure C). If a rating changes during a matter, the due diligence in section 5 is supplemented accordingly.

5. Client Due Diligence

5.1 When due diligence is performed

  • on every engagement of the firm: a mandate expected to involve ongoing work or more than one transaction is a business relationship, and due diligence is performed at matter-opening regardless of value (s 21);
  • on a once-off transaction of R5 000 or more concluded outside a business relationship (s 1 read with regulation 1A);
  • again, to the extent necessary, where the firm doubts the veracity or adequacy of previously obtained information or files a report under section 29 (s 21D).

5.1.1 The firm does not establish a business relationship or conclude a transaction with an anonymous client or a client with an apparent false or fictitious name (s 20A), at any value.

5.1.2 For a once-off matter under R5 000 the firm records the person’s full name and identity number and screens the person against the targeted financial sanctions list (s 20A; section 8 of this RMCP). Verification is not required at that level.

5.2 Identification and verification

5.2.1 The firm determines the means of verification in terms of section 42(2)(d), using reliable and independent sources, scaled to the client’s risk rating:

Client typeEstablished (identification)Verification — low riskAdditional — high risk
Natural personFull names, identity or passport number, date of birthCopy or sight of ID document, ID card, passport or driver’s licence, or an electronic check against a reliable independent source (DHA-linked or credit-bureau data)Original or multi-source electronic corroboration; source of funds for the matter
Company / CCRegistered name and number; nature of business; ownership and control structure (s 21B(1))CIPC records (disclosure certificate or registry extract)Source of funds; corroboration of structure (share register, organogram)
TrustTrust name and Master’s reference; Master’s office; parties in section 6Letters of authority; trust deed where neededSource of funds; corroboration of parties against the deed
PartnershipPartnership name; parties in section 6Partnership agreement, or a letter signed by all partnersSource of funds
Person acting for a client, or person a client acts forIdentity of that person and the authority to act (s 21(1)(b)–(c))ID as above; resolution, power of attorney or mandateOriginal or corroborated authority

5.2.2 For every business relationship the firm records the nature and intended purpose of the relationship and the expected source of funds (s 21A), on the intake form (Annexure A).

5.3 Timing of verification

The firm may accept a mandate and perform preparatory work while verification is being completed. Verification is completed before the firm concludes a transaction, receives or applies client funds, or performs any act to give effect to the matter (Revised GN 7A, timing of verification).

5.4 Simplified and enhanced due diligence (s 42(2)(m))

  • Low risk — simplified due diligence: the low-risk column in 5.2.1; no address proof or source-of-funds documentation; information refreshed on the trigger events in section 11.
  • High risk — enhanced due diligence: the high-risk column in 5.2.1, written approval of the engagement by the director, and closer monitoring for the duration of the matter.
  • Simplified due diligence reduces the intensity of verification. It does not dispense with identification, the prohibition on anonymous clients, sanctions screening, reporting or record keeping.

5.5 Inability to complete due diligence (s 21E)

If the firm cannot establish and verify identity, obtain the section 21A information, or maintain ongoing due diligence, it does not establish the business relationship or conclude the transaction, and terminates an existing business relationship; in each case the firm considers filing a report under section 29. The client is ordinarily informed of what is outstanding and given a reasonable opportunity to provide it (Revised GN 7A), unless doing so would risk tipping the client off (section 11) or the risk requires immediate withdrawal. Termination and its reason are recorded, in writing where practically possible.

6. Beneficial Ownership

6.1 A beneficial owner is a natural person. For clients that are legal persons, trusts or partnerships the firm establishes, in addition to section 5, the following (s 21B):

  • Companies (s 21B(2)): the beneficial owner is established by elimination — (i) each natural person with a controlling ownership interest, for which the firm applies the 5% threshold recommended in PCC 59; failing which (ii) each natural person exercising control through other means; failing which (iii) each natural person exercising executive control, with the elimination reasoning recorded. Ownership through intermediate entities is traced through the chain; intermediate layers require structure information only.
  • Trusts (s 21B(4)): each founder, each trustee, each named beneficiary (or the particulars of how beneficiaries are determined, where they are not named), and each person authorised to act for the trust.
  • Partnerships (s 21B(3)): every partner (including silent partners and partners en commandite), the natural person exercising executive control, and each person authorised to act. No percentage threshold applies to partners.

6.2 The identity of each beneficial owner is verified by reasonable steps proportionate to risk (s 21B(2)(b)): an identity number corroborated against an independent source (CIPC records, credit-bureau data, or the entity’s own registers). A self-declaration without corroboration is not accepted (PCC 59). The CIPC and Master’s beneficial-ownership registers serve as corroborating sources and do not replace the firm’s own duty.

7. Politically Exposed Persons

7.1 A domestic politically exposed person (DPEP) holds or has held a prominent public function listed in Schedule 3A; a foreign politically exposed person (FPEP) holds or has held a function listed in Schedule 3B; a prominent influential person (PIP) holds, or held within the preceding 12 months, a senior position in a company providing significant goods or services to an organ of state (Schedule 3C, pending the Ministerial determination of the transaction-value threshold). For DPEPs and FPEPs, “has held” carries no time limit. These provisions extend to immediate family members and known close associates (s 21H).

7.2 Status is determined through a declaration on the intake form (Annexure A) and, where the matter or client profile suggests it, a check of public sources (s 42(2)(l)).

  • FPEP (s 21F): in every case — written approval of the engagement by the director, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring.
  • DPEP or PIP (s 21G): the same measures, where the business relationship is assessed as higher risk.

7.3 Senior management approval is given by the director in a written, dated approval recorded on the file.

8. Targeted Financial Sanctions

8.1 United Nations Security Council financial-sanctions resolutions have immediate effect on adoption (s 26A(1)). Section 26B prohibits dealing with the property of, or providing services to, designated persons. Screening applies to every client at every risk level (PCC 44A).

  • Screening: every client, every person acting for or acted for by a client, and every beneficial owner is screened against the FIC’s consolidated TFS list at take-on, when transacting where the parties have changed, and whenever the FIC publishes a list update. The screening date and result are recorded in the compliance register.
  • On a confirmed match: the firm does not deal with the property or proceed with the matter and does not inform the client of the match; it files a terrorist property report under section 28A via goAML within 5 business days (regulation 24(1)), reports further as directed (s 28A(2)), and considers a report under section 29 where a transaction relates to a contravention of section 26B.
  • Scrutiny notices: on a section 26A(3) notice by the FIC Director, the firm re-screens its client base (s 28A(3)).
  • Permitted dealings: dealings with affected property occur only under a written permission of the Minister of Finance in terms of section 26C.

9. Reporting to the FIC

9.1 Any member of staff who becomes aware of a reportable event or forms a suspicion reports it to the compliance officer on the same day. The compliance officer determines whether a report is required and files it on goAML. Decisions not to file after an internal escalation are recorded. The periods below are business days (regulation 24 read with regulation 1).

ReportTriggerPeriod
Cash threshold report (s 28)Cash (notes, coins or traveller’s cheques; not EFT or card payments) exceeding R49 999.99, paid to or received from a client (reg 22B). Conducting transactions so as to avoid a reporting duty is an offence (s 64) and a section 29 trigger.3 business days (reg 24(4))
Suspicious or unusual transaction report (s 29)Knowledge or reasonable suspicion that the firm has received or is about to receive proceeds of unlawful activities; that a transaction has no apparent business or lawful purpose, is structured to avoid a reporting duty, may be relevant to tax evasion, relates to terrorist financing or to a contravention of section 26B; or that the firm is being used for money laundering. No monetary threshold; attempted and aborted transactions included (s 29(2)).15 business days (reg 24(3))
Terrorist property report (s 28A)Possession or control of property connected to terrorist activity or owned or controlled by or on behalf of a person designated under section 26A (section 8).5 business days (reg 24(1))

9.2 The following applies to all reports:

  • Confidentiality: no person discloses that a report has been or will be made, or its contents, except as permitted by section 29(3)–(4); unauthorised disclosure is an offence (s 53).
  • Privilege: section 37(1) overrides duties of confidentiality for reporting purposes; section 37(2) preserves attorney–client privilege for communications made for the purpose of legal advice or litigation. Client identity, verification records and trust-account transaction records are not privileged. Doubtful cases are resolved by the compliance officer before filing.
  • Protection: reports made in good faith attract the immunity in section 38.
  • Continuation: the firm may continue with a transaction after reporting unless the FIC directs otherwise (ss 33–34), subject to the section 26B prohibitions.
  • Not applicable to this firm: international funds transfer reports (s 31) — the firm does not itself send or receive cross-border electronic transfers on behalf of clients (FIC Guidance Note 9). Section 30 (cross-border cash conveyance) is not in force. Section 28 applies to physical cash only; there is no domestic EFT reporting duty. Recorded as part of the firm’s section 42(2)(o)–(p) reportability determination.

10. Record Keeping

  • Content (ss 22–22A): the due-diligence information obtained (including copies of, or references to, the verification material) and, for every transaction, records sufficient for it to be reconstructed: amount and currency, date, parties, nature, and the business correspondence.
  • Period (s 23): at least five years from termination of the business relationship, from conclusion of the transaction, and, for records underlying a section 29 report, from submission of the report.
  • Manner (s 24(4)): electronic, in the firm’s practice management system, reproducible in legible form, access-controlled and backed up.
  • Third parties (s 24(1)–(3)): the firm keeps its own records. If record keeping is outsourced to a third party, the firm remains liable and provides the FIC with the prescribed particulars of the third party without delay (regulation 20).

11. Monitoring and Ongoing Due Diligence

11.1 The director exercises direct oversight of every matter. Monitoring is conducted as follows:

  • Consistency (s 21C): transactions in a matter are checked against the client’s stated nature, purpose and source of funds. Trust-account receipts are scrutinised: unexpected sources, third-party payers or cash are queried before funds are applied.
  • Complex or unusually large transactions, and unusual patterns of transactions with no apparent business or lawful purpose (s 42(2)(h)): the background and purpose are examined and written findings are kept on the file. Patterns are identified through the scrutiny of trust-account receipts and the Annexure B indicators.
  • Keeping information current (s 21C(1)(b)): client information is refreshed on trigger events — doubt as to veracity (s 21D), a change in risk profile, or a materially new instruction after a substantial interval. High-risk clients are reviewed at least annually.
  • Suspicion during a relationship (ss 21D, 21C(2)): where suspicion arises, the steps in sections 21 and 21B are repeated to the extent necessary to confirm the information, unless doing so would disclose that a report will be made, in which case the firm may discontinue the due diligence and file the section 29 report.
  • Termination (s 21E): as set out in paragraph 5.5.

12. Training

12.1 The firm provides ongoing training on the Act and on this RMCP (s 43):

  • the director maintains his own currency through FIC guidance releases, FIC webinars and professional CPD, and assesses each new FIC instrument affecting legal practitioners against this programme;
  • every new employee or contractor involved in client take-on or trust-account transactions is trained on this RMCP before performing that work, with an annual refresher and further training when the law or this programme changes;
  • a dated training log (who, when, what) is kept in the compliance register and is available on inspection.

13. Returns and Non-Compliance

13.1 Risk and compliance returns. The firm submits risk and compliance returns to the FIC as directed. The firm submitted its return under Directive 6 of 2023 and submits the current-cycle return under Directive 11 of 2026 by 17:00 on 31 July 2026 via the FIC’s RCR portal. Each return cycle is diarised and submitted by the published deadline.

13.2 Internal escalation. Any person who becomes aware of a possible breach of this RMCP or of the Act reports it to the compliance officer immediately. No adverse consequences attach to internal reports made in good faith. The compliance officer records the event and its remediation in the compliance register, completes any outstanding compliance step, and treats recurring issues as a trigger for an early review of this RMCP.

14. Review, Version History and Approval

14.1 This RMCP is reviewed at regular intervals (s 42(2C)): annually in October, and earlier where the law changes, the FIC issues guidance materially affecting this programme, the firm’s services change materially, or a compliance event exposes a gap. Each review is recorded below.

VersionDateChanges
3.02 July 2026Realigned with the Act as amended by Act 1 of 2017 and the General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act 22 of 2022, and with current FIC guidance. Governance restated under section 42A; provisions derived from the withdrawn 2002 exemptions removed; supervision restated (FIC direct supervision); politically-exposed-person terminology updated to DPEP/FPEP/PIP, the 12-month lookback applying only to PIPs; cash threshold report stated per regulation 22B with the aggregation requirement’s removal reflected; beneficial-ownership procedures aligned with PCC 59; verification restated as risk-based with no prescribed documents; questionnaires consolidated into a single intake form; section 42(2) coverage table added.
2.020 October 2025Cash threshold updated to R49 999.99; CTR period updated; Legal Practice Act references; targeted financial sanctions procedures added; Directive 6 return noted.
1.0Initial programme.

Approval (s 42(2B)). This RMCP, version 3.0, is approved by MJ Kotze, sole director of MJ Kotze Inc., being the person exercising the highest level of authority in the firm, on 2 July 2026. A signed copy of this approval is kept in the firm’s compliance records.

15. Section 42(2) Coverage

The table below records where each requirement of section 42(2) is addressed in this RMCP, together with the firm’s statements under section 42(2A).

s 42(2)Requirement (summarised)Where in this RMCP
(a)Identify, assess, monitor, mitigate and manage ML/TF/PF risk, including for new products and services§3
(b)How the firm determines prospective-client and client status§5.1, Annexure A
(c)Compliance with s 20A (no anonymous clients)§5.1
(d)Manner and processes of identification and verification§5.2–5.3
(e)How the firm determines whether future transactions are consistent with its knowledge of the client§5.2.2, §11
(f)Additional due diligence for legal persons, trusts and partnerships§5.2, §6
(g)Ongoing due diligence and account monitoring§11
(h)Examining complex or unusually large transactions, and unusual patterns of transactions with no apparent business or lawful purpose, with written findings kept§11
(i)Confirming information on doubt, and when reporting (s 21D)§5.1, §11
(j)Performing CDD when suspicion arises during a relationship§11
(k)Terminating a business relationship (s 21E)§5.5
(l)Determining DPEP / FPEP / PIP status§7
(m)Enhanced due diligence for higher risk; when simplified due diligence is permitted§4, §5.4
(n)Manner and place of record keeping§10
(o)Determining when a transaction or activity is reportable§8, §9
(p)Processes for reporting to the Centre§9
(q)Implementation in foreign branches and subsidiariesNot applicable (s 42(2A)): the firm has no branches, subsidiaries or other operations, in foreign countries or elsewhere
(qA)Group-wide programmes for branches and majority-owned subsidiariesNot applicable (s 42(2A)): the firm has no branches or majority-owned subsidiaries, in the Republic or elsewhere — a single-office practice
(r)Processes for implementing the RMCP§2, §12, §13
(s)Any prescribed matterNone currently prescribed by regulation

Annexures

The following annexures form part of this RMCP.

Enquiries

Enquiries regarding this programme may be directed to the compliance officer.

Compliance officer: MJ Kotze

Email: martin@mjkinc.co.za