Capitec’s R28-million FICA penalty: compliance failures and the bank’s response
NEWS EXPLAINER · Reviewed 15 September 2026
Capitec Bank’s R28-million administrative penalty concerns weaknesses in the controls intended to detect and manage financial-crime risk. The Prudential Authority’s findings cover customer checks, staff training and parts of the bank’s risk management and compliance programme. Understanding those findings requires looking beyond the size of the fine to what the controls are supposed to accomplish. eNCA
What the regulator found
The sanctions followed inspections in 2023. According to EWN’s account of the findings, sampled customer files revealed shortcomings in customer due diligence, enhanced due diligence and ongoing due diligence. The regulator also identified inadequate continuing training for some employees and deficiencies involving terrorist-property reporting, financial sanctions and screening for prominent influential persons. EWN: the inspection findings
Of the R28 million, R5.5 million is conditionally suspended for 36 months. The arithmetic leaves R22.5 million outside the suspended portion. That is a description of the penalty’s structure, not evidence of when a payment was made. The combined R34-million headline in some coverage includes a separate R6-million sanction against Ninety-One Assurance; it is not Capitec’s individual fine. EWN
Why these controls matter
Customer due diligence, staff training and reporting processes form successive parts of a control system. The practical concern is what happens when information gathered about a customer does not lead to an appropriate response to risk, or when staff lack the training needed to apply the institution’s procedures. A compliance programme can exist on paper while its application remains inconsistent.
The regulator’s use of sampled files is also significant. Findings about a sample establish the weaknesses identified in that inspection; they do not provide a public count of every affected account. Nor can the size of an administrative fine be used to calculate a supposed amount of money laundered through the bank. Those are different questions requiring different evidence.
The sanctions announcement should therefore be read as a finding about compliance obligations under FICA. The reporting cited here does not establish that Capitec has been convicted of money laundering, or that a particular customer committed a crime. Screening for risk likewise must not be confused with proof of wrongdoing by the person being screened.
The bank’s response and the remaining accountability question
Capitec cooperated with the regulator and indicated that it had taken remedial steps, according to the reporting. eNCA describes the bank’s response as addressing the identified compliance gaps. That response is relevant, but a statement that improvements have been made is different from a published follow-up assessment confirming that every weakness has been resolved. eNCA: Capitec’s response
The inspection date and the announcement date also need to remain separate. The underlying inspection took place in 2023; the sanction became public in September 2026. It would be misleading either to present every inspected weakness as newly discovered this week or to assume that the passage of time proves successful remediation.
The useful next questions concern implementation: which controls changed, how their operation is checked, and whether the regulator is satisfied with the results. For readers assessing the headline, the firm conclusions are the administrative findings, the R28-million penalty and its suspended component. Claims about criminal conduct, current account safety or completed remediation require evidence beyond the fine itself.




Comments