Capitec hit with R28 million in penalties over FIC Act breaches

Posted on September 15, 2026
by Yashmika Dukaran


Capitec Bank has been fined a total of R28 million by the Prudential Authority (PA) after an inspection identified several shortcomings in the bank’s compliance with South Africa’s anti-money-laundering and financial-crime laws.

The penalties follow a 2023 inspection conducted by the PA under the Financial Intelligence Centre Act (FIC Act), which requires banks and other accountable institutions to maintain measures to prevent money laundering, terrorist financing and other financial crimes.

The R28 million sanction consists of five separate penalties relating to different compliance failures.

The largest, R10 million, was imposed after the PA found that Capitec had not carried out adequate customer due diligence on a sample of client files, as required by the FIC Act.

Of this amount, R3 million has been conditionally suspended for 36 months from 13 October 2025.

The bank was also fined R5 million for failing to conduct adequate enhanced due diligence on certain sampled client files. Enhanced due diligence requires additional checks and monitoring for customers or transactions considered to pose higher financial-crime risks.

A further R1 million of this penalty has been conditionally suspended for 36 months.

Another R5 million penalty relates to inadequate ongoing due diligence. The PA found that Capitec had not sufficiently maintained and updated customer information and risk assessments on the sampled files.

R1 million of this penalty has also been suspended for 36 months.

The fourth penalty, amounting to R3 million, relates to employee training. The regulator found that Capitec had failed to provide ongoing training to some employees as required under the FIC Act.

The final R5 million penalty relates to weaknesses in the bank’s broader compliance framework.

The PA found that Capitec had not obtained management approval for its business banking anti-money-laundering name-screening and payment-screening investigation manuals before they were implemented.

The bank was also unable to provide evidence that it had documented and approved end-to-end processes for reporting terrorist property before it received notification of the PA's inspection.

The regulator further found that Capitec had not adequately developed, documented or incorporated policies, procedures, standards and controls relating to terrorist property reporting and financial sanctions into its Risk Management and Compliance Programme.

While the total value of the penalties is R28 million, R5.5 million has been conditionally suspended for 36 months.

This comprises R3 million from the customer due diligence penalty, R1 million from the enhanced due diligence penalty, R1 million from the ongoing due diligence penalty and R500,000 from the compliance framework penalty.

The sanctions also include five cautions requiring Capitec not to repeat the conduct that led to the respective compliance failures.

The PA says the penalties were imposed following its inspection and are intended to ensure that the bank complies with the requirements of the FIC Act.

Capitec cooperated with the regulator and has taken steps to address the deficiencies and weaknesses identified during the inspection.

The case highlights the obligations placed on banks to maintain effective systems for identifying customers, monitoring transactions and detecting potential money laundering, terrorist financing and breaches of financial sanctions.

The Prudential Authority is responsible for supervising compliance with these requirements within South Africa’s banking sector.