Industry · Fintech

Fintech automation and data engineering for South African financial services

KYC that approves the clear cases and explains the rest, transaction-monitoring alerts an analyst can actually work, and a data platform that answers the FIC, the FSCA and the Prudential Authority by query. For banks, neo banks, payment providers, lenders and crypto asset service providers.

52%
of South African banks actively use AI, against 8% of lenders
Source: FSCA & PA, AI in the SA Financial Sector (2025)
570 000+
suspicious and unusual transaction reports received by the FIC in 2024/25
Source: Financial Intelligence Centre, 2024/25 annual report release
330
institutions told to take remedial action after the FIC's 556 inspections in 2024/25
Source: Financial Intelligence Centre, 2024/25 annual report release

Fintech architecture and engineering, built for the people who examine it

Most fintech automation in South Africa is not about inventing a product. It is about doing the regulated work underneath one: onboarding customers under the FIC Act, monitoring transactions, screening against sanctions lists, deciding on credit, and proving afterwards that each of those things happened the way your risk management and compliance programme says it does.

That proof is where programmes stall. The Financial Intelligence Centre received more than 570 000 suspicious and unusual transaction reports in 2024/25. After its 556 inspections that year, 330 institutions were told to fix things. South Africa has left the FATF grey list, but National Treasury was clear that regulated entities cannot afford to become complacent. Supervisors are now looking for evidence that controls work, not for a policy document that says they should.

So we build the evidence layer first. Event-driven pipelines capture every transaction and decision as it happens. Lineage runs from each regulatory figure back to its source event. Personal information is classified and masked before any model sees it. Every automated decision records which rule, model version and person made it. The AI sits on top: document intelligence for KYC, models that score transactions, and agents that turn a pile of alerts into a case summary an analyst can work.

We have built this shape before. For a South African neo bank we built a FICA compliance and fraud-scoring platform on Google Vertex AI. It automated 75% of KYC reviews, cut false-positive fraud alerts by 60% and scored transactions in under 50 milliseconds. For another neo bank we built the whole Google Cloud data estate, with under five minutes from transaction to analytical availability.

How it works

How a new customer moves through automated KYC onboarding

This is the shape of most onboarding automation we would build for a bank, payment provider or CASP. The AI reads and cross-checks; your risk-based approach, as written in your RMCP, decides what clears on its own; a compliance officer decides the rest.

  1. STEP 01

    Application arrives

    App, branch, partner API or a scanned pack. Every channel lands in one case file with a reference number, so nothing is onboarded from an inbox.

  2. STEP 02

    Documents read and cross-checked

    Document intelligence extracts the fields from ID documents, proof of address and company registration documents, then checks that they agree with each other and with what the applicant typed.

  3. STEP 03

    Screened against sanctions lists

    Names are checked against the targeted financial sanctions lists and your other watchlists. Near-matches are resolved with the evidence attached, not just flagged.

  4. STEP 04

    Risk-rated against your RMCP

    The customer is scored using the methodology your risk management and compliance programme documents, so the rating can be traced back to the programme your board approved.

Automated

Low risk, clean checks: onboarded

Consistent documents, no screening hit and a risk rating inside limits your compliance team set. The account opens without anyone touching it.

Human decides

Anything else: to a compliance officer

Any hit, inconsistency or higher-risk rating goes to a person with a structured risk summary and the exact reason. Declines are always made by a person.

Every decision evidenced

What was checked, which rule and model version decided and who approved it, all retrievable by query when the FIC, your supervisor or internal audit asks.

Guides

Fintech compliance automation, explained

These are the questions bank, payments and fintech leaders ask us, answered plainly. Each starts with a short answer you can take into a meeting, followed by the steps or reasons behind it.

01 · How to

How do you automate KYC and FICA onboarding in South Africa?

Short answer

Automate the reading, cross-checking and screening. Let the risk-based approach in your RMCP decide which low-risk applicants are onboarded without a person, and send everyone else to a compliance officer with a structured summary. The FIC expects your RMCP to cover the systems and controls you run, not only policy documents.

  1. 1

    Write down the risk-based approach first: which customer, product and channel factors raise or lower risk. The automation runs that methodology. It does not replace it.

  2. 2

    Bring every channel (app, branch, partner API, scanned packs) into one case file with a reference number.

  3. 3

    Extract fields from identity, address and company documents. Check them against each other and send low-confidence fields to a person instead of guessing.

  4. 4

    Screen against the targeted financial sanctions lists, and resolve near-matches with the evidence attached.

  5. 5

    Agree the straight-through limits with your compliance officer, start them conservatively and widen them as the data proves them. (Our experience, not an FIC requirement.)

  6. 6

    Log what was checked, which rule and model version decided, and who approved it.

Source: FIC Guidance Note 7A (Chapter 4, RMCP)
02 · How to

How do you reduce false positives in transaction monitoring without missing real cases?

Short answer

Keep your rules, and add a scoring and triage layer on top. Models rank alerts by learned risk and group related ones, and agents assemble the evidence. Analysts then work the highest-risk cases first. Nothing is closed without a person, and once suspicion forms the FIC's reporting clock is 15 working days.

  1. 1

    Measure today's baseline first: alerts per month, percentage closed as false positives, average handling time and the reporting backlog.

  2. 2

    Resolve customers, accounts and counterparties into single entities, so one person's activity is not split across ten alerts.

  3. 3

    Score alerts using behavioural, network and device features, and validate the model on cases your team has already closed.

  4. 4

    Have an agent draft the case narrative with the transactions that triggered it. The analyst edits and decides.

  5. 5

    Feed confirmed and cleared outcomes back in, and keep below-threshold samples under review so the model cannot hide what it misses. (Steps 2 to 5 are our practice, not regulatory text.)

  6. 6

    Remember the clock: under regulation 24(3), a suspicious-transaction report is due within 15 days, excluding weekends and public holidays, of becoming aware of the facts.

Source: FIC Guidance Note 4B on suspicious and unusual transaction reporting
03 · Why

Why does AML compliance still matter after South Africa left the FATF grey list?

Short answer

Leaving the grey list in October 2025 marked the start of a process, not the end of one. National Treasury said neither government agencies nor regulated entities can afford to become complacent, and the FATF expects countries that exit to keep showing measurable outcomes. The FIC's own inspections still find widespread gaps.

  • South Africa spent 32 months on the grey list and had to close 22 action items to exit.

  • The FATF requires countries that have exited to demonstrate continued commitment through measurable outcomes, including investigations, prosecutions and sanctions.

  • In 2024/25 the FIC ran 556 inspections, and 330 institutions were told to take remedial action.

  • Reporting volume keeps rising: more than 570 000 suspicious and unusual transaction reports in 2024/25, up from 414 984 in 2023/24.

  • Penalties apply to people as well as institutions: Guidance Note 7A notes that the board or senior management can be sanctioned under section 61 of the FIC Act.

Source: National Treasury: South Africa exits the FATF greylist (24 Oct 2025)
04 · Why

Why are South African banks so far ahead of lenders on AI?

Short answer

In the FSCA and Prudential Authority survey, 52% of banks and 50% of payment providers used AI, against 8% of lenders. Banks have the budget and the data: the report says more than half of bank respondents expected to invest over R20 million in AI in 2024. Most institutions planned under R1 million.

  • Budget: most institutions planned to spend less than R1 million on AI in 2024, while more than half of bank respondents expected to spend over R20 million.

  • Regulation: the survey found data privacy and protection laws were the most significant regulatory constraint on adoption.

  • Skills and explainability: insufficient talent, transparency and explainability were the main non-regulatory constraints.

  • Use case fit: fraud detection was the leading machine-learning use case, which suits a bank's transaction volumes better than a smaller lender's book.

  • Decision risk: a lender's model decides on credit worthiness, which POPIA section 71 singles out. Getting explainability right before going live slows the first deployment. (Our reading, not a survey finding.)

Source: FSCA & PA, AI in the SA Financial Sector (2025)
05 · How to

How should a crypto asset service provider implement the travel rule?

Short answer

Treat it as a data pipeline. Under FIC Directive 9, in effect since 30 April 2025, an originating CASP must send originator and beneficiary information securely, before or at the same time as the transfer. Every CASP in the chain keeps records that authorities can request, so the data has to be complete before anything moves.

  1. 1

    Map your role in each flow (ordering, intermediary or recipient), because Directive 9 sets different obligations for each stage.

  2. 2

    Collect originator and beneficiary data at the point of instruction, and validate it before the transfer is released.

  3. 3

    Exchange the information securely with the counterparty CASP, and record what was sent, received and when.

  4. 4

    Decide what happens to transfers with missing or mismatched counterparty data, and log every exception. (Our design practice. The directive sets the obligation, not the workflow.)

  5. 5

    Keep the records retrievable, because they must be made available to appropriate authorities on request.

  6. 6

    Check cross-border transfers against exchange control regulations as well. The FIC flags that these still apply.

Source: FIC media release: Directive 9 (15 Nov 2024)
Challenges We Solve

The hard problems Fintech faces

Alert volumes that outrun analysts

Rule-based transaction monitoring tends to produce far more alerts than real cases, and every alert still has to be worked and documented. The cost shows up as analyst hours, backlogs and suspicious-transaction reports filed under time pressure.

A compliance programme that lives in a document

The FIC expects your RMCP to be more than policy documents: it also covers the procedures, systems and controls you actually run. If the risk-based approach on paper and the rules in production have drifted apart, an inspection will find it.

Real-time payments, real-time fraud

Instant rails like PayShap clear payments in real time. When money moves in seconds, fraud checks have to run inside the payment flow, not in an overnight batch. (Our experience, not a regulator finding.)

Explaining automated credit decisions

POPIA section 71 names credit worthiness specifically. If a decision about a person is based solely on automated profiling, they must be able to make representations and to understand the logic behind it. A model you cannot explain is a model you cannot deploy.

By line of business

Where automation fits, by type of institution

A tier-one bank, a payment provider and a crypto exchange share the FIC Act but not much else. The first thing worth automating is different for each.

First win: Financial-crime operations

Banks and neo banks

Banks lead South African AI adoption, and the regulators found they mainly plan to use machine learning for fraud detection and AML/CFT. The payoff is in onboarding throughput and alert triage, sitting on a data platform that can carry regulatory reporting too.

First win: Real-time risk

Payment providers and PSPs

Half of the payment providers surveyed already use AI. On instant rails the work is to score in the authorisation path, resolve merchants and counterparties into one view, and reconcile settlement data automatically rather than by spreadsheet.

First win: Explainable credit decisions

Lenders and credit providers

Only 8% of lenders surveyed use AI, the joint-lowest in the sector. That makes the first project cheaper to get right: affordability and document checks automated, reason codes on every outcome, and adverse decisions reviewed by a person, as POPIA section 71 expects.

First win: Travel rule and licensing

Crypto asset service providers

CASPs are accountable institutions under the FIC Act and, since crypto assets were declared financial products, FSCA licensees too. Directive 9 requires originator and beneficiary information to move with each transfer, which makes it a data-exchange problem as much as a compliance one.

Our Solutions

What we build for you

01

Event-driven data platform

Streaming architectures on Google Cloud, Azure or Snowflake that capture every transaction and decision as an event. A layered bronze, silver and gold model makes any reported number traceable to its source.

02

AI-assisted financial-crime operations

Document intelligence for KYC, machine-learning scoring for fraud and monitoring, and AI agents that assemble the case file. They triage and summarise; your analysts decide and file.

03

Governed, explainable decisioning

Model and rule versioning, feature lineage, reason codes on every automated outcome and a human gate on adverse decisions. You can explain a decision to a customer, a supervisor or the Information Regulator.

Regulatory context

The South African fintech rulebook, with dates

Fintech regulation in South Africa is spread across the FIC, the FSCA, the Prudential Authority and the Information Regulator. Here is what changed recently, with dates you can check. Where we could not confirm a detail from the regulator's own document, we say so.

  1. 24 October 2025

    South Africa exits the FATF grey list

    The FATF removed South Africa from its list of jurisdictions under increased monitoring after 32 months and a 22-item action plan. National Treasury called it the start of a broader process, not the end. The FATF expects countries that exit to keep showing measurable results, so supervision is not easing.

  2. Published February 2025

    FIC Guidance Note 7A on the RMCP

    This guidance replaces Guidance Note 7 on the risk management and compliance programme under section 42 of the FIC Act. Its examples include a bank whose RMCP did not describe its risk-based approach. Expect inspections to compare the programme on paper with the controls you actually run.

  3. Issued 15 November 2024, in effect 30 April 2025

    Directive 9: the travel rule for crypto transfers

    CASPs must send originator and beneficiary information securely with each crypto transfer, before or at the same time as the transfer itself, and keep records that authorities can request. Non-compliance carries administrative sanctions under section 45C of the FIC Act.

  4. Declared 19 October 2022; licensing from 1 June 2023

    Crypto assets regulated as financial products

    The FSCA declared crypto assets financial products under the FAIS Act. CASPs have had to register with the FIC as accountable institutions since 19 December 2022.

  5. Set to commence 1 June 2025

    Joint Standard 2 of 2024: cybersecurity and cyber resilience

    The FSCA and the Prudential Authority said the standard was envisaged to commence on 1 June 2025. It sets requirements for sound cybersecurity and cyber-resilience practices across financial institutions. Reports indicate a 12-month window from commencement to comply in full, which would mean June 2026. Confirm your own obligations against the standard.

  6. Published 24 November 2025

    Joint FSCA and Prudential Authority report on AI

    The regulators' survey found 52% of banks and 50% of payment providers using AI, and that banks mainly intend to use machine learning for fraud detection and for profiling clients and transactions. It encourages explainability methods such as SHAP and LIME, and clear disclosure when AI is used in decisions such as credit assessments.

  7. Published 3 July 2020; phased in during 2021

    Conduct Standard for Banks

    The FSCA's conduct standard builds the Treating Customers Fairly principles into banks' obligations. For automation, that means fair outcomes and complaint handling have to be evidenced in the data, not stated in a policy.

Where we start

Engagements we run in Fintech

01

KYC and FICA onboarding

Document intelligence that reads and cross-checks identity, address and company documents, screens against sanctions lists and approves low-risk applicants within limits you set. Everyone else goes to a compliance officer with a structured risk summary.

02

Transaction-monitoring alert triage

Models and AI agents that group related alerts, pull the customer's history and draft a case narrative, so analysts spend their time on judgement rather than gathering data. The decision to report stays with them.

03

Real-time fraud scoring

Low-latency scoring endpoints in the authorisation path. They use behavioural, device and network features, and retrain on newly labelled cases so the model learns your book.

04

Travel-rule data exchange for CASPs

Pipelines that collect, validate and send originator and beneficiary information with each crypto transfer, and keep a record the FIC can request. Transfers with missing counterparty data are flagged before they go.

05

Regulatory reporting that traces to source

Lineage-tracked platforms where regulatory returns and FIC reports are generated from tested tables. Any figure can be traced back to the transaction events behind it.

06

Employee screening under Directive 8

Automated checks of current and prospective employees against the targeted financial sanctions lists whenever the FIC issues a notice. Each result is logged in the form your RMCP says it will be.

Key terms

Fintech terms, in plain language

Accountable institution
A business listed in Schedule 1 of the FIC Act, such as a bank, CASP or financial services provider. It must register with the FIC, know its customers, keep records and report to the FIC.
RMCP (risk management and compliance programme)
The programme section 42 of the FIC Act requires every accountable institution to develop, document, maintain and implement for anti-money laundering, counter-terrorist financing and counter-proliferation financing.
Risk-based approach
Applying stronger controls where money-laundering and terrorist-financing risk is higher and simpler ones where it is lower. Each institution's RMCP sets out how it does this.
STR (suspicious and unusual transaction report)
A report to the FIC under section 29 of the FIC Act. It is due as soon as possible, and no later than 15 days (excluding weekends and public holidays) after becoming aware of the facts behind the suspicion.
Targeted financial sanctions (TFS)
Sanctions against named people and entities. Accountable institutions screen customers, and under Directive 8 employees, against the lists the FIC notifies.
CASP (crypto asset service provider)
A business that provides crypto asset services. In South Africa CASPs register with the FIC as accountable institutions and are licensed by the FSCA under the FAIS Act.
Travel rule
The FATF Recommendation 16 requirement for wire transfers, applied to crypto transfers. In South Africa it is implemented by FIC Directive 9.
PayShap
South Africa's low-value, real-time rapid payment platform, launched on 13 March 2023. It lets people pay using an alias such as a cellphone number instead of an account number.
FAQ

Fintech questions

Ready to transform your Fintech data strategy?

Let's discuss the specific challenges your business faces and design a solution that delivers real impact.