From CompliNEWS | Financial Services Intelligence Watch
The short answer is that every accountable institution should conduct and document a GN 7B gap assessment, but not every RMCP requires a complete rewrite. GN 7B is a targeted strengthening of the existing framework. An RMCP that already properly addresses proliferation financing, technology and product-change risk, evidence-based simplified due diligence and enhanced due diligence following suspicious transaction reporting may need only limited amendments. An outdated RMCP that remains focused mainly on money laundering and terrorist financing, however, will require substantial revision. The FIC describes its guidance as authoritative: accountable institutions must take it into account or be able to demonstrate that their alternative arrangements achieve an equivalent level of compliance. Waiting for the next annual RMCP review would therefore be difficult to defend where a material gap has already been identified.
What GN 7B actually changes
Although the document runs to 77 pages, most of it carries forward the existing guidance. The substantive additions are concentrated in four areas. First, proliferation financing is expressly integrated throughout the risk-based framework. RMCPs must therefore address PF across the risk assessment, controls, customer due diligence, monitoring and training, rather than mentioning it only in a sanctions paragraph.
Second, institutions must assess the ML, TF and PF risks associated with new products, services, business practices, delivery channels and technologies before implementation or launch, and again when material changes occur. Third, low-income or underserved clients may not automatically be classified as low risk; simplified due diligence must be supported by a documented, evidence-based risk assessment. Finally, where an institution files a section 29 report because it suspects ML, TF or PF, it must conduct enhanced due diligence on the relevant business relationship or single transaction without tipping off the client.
New products and technology
Financial inclusion and SDD
Section 29 reports and EDD
1. Proliferation financing must be integrated properly
GN 7B inserts a definition of proliferation financing and systematically changes the Chapter 1 risk-based framework from an ML/TF framework into an ML/TF/PF framework. PF must therefore be considered when identifying inherent and residual risk; evaluating clients, products, services, jurisdictions and delivery channels; assigning risk ratings; applying simplified or enhanced measures; monitoring activity; and designing controls.
This does not mean that PF first became relevant on 3 August 2026. Revised GN 7A’s RMCP chapter already required accountable institutions to develop an AML/CFT/CPF programme and conduct an entity-wide ML, TF and PF risk assessment. The FIC has also previously issued specific proliferation-financing guidance in PCC 54. A properly updated RMCP should therefore already contain much of this material. FIC guidance on drafting RMCPs, PCC 54
The practical problem is that many RMCPs mention PF only in the title, definitions or targeted financial sanctions section. That will no longer be enough. An institution should be able to demonstrate:
The FIC declined industry requests to expand paragraph 7A by expressly linking it to sections 26A and 26B and the wider targeted financial sanctions framework. Institutions should therefore retain the statutory definition used by GN 7B and address targeted financial sanctions separately and accurately rather than creating an overbroad internal definition.
2. New products, services and technology require a pre-launch risk assessment
Paragraph 37A is probably the most operationally significant change. Accountable institutions must identify and assess the ML, TF and PF risks associated with:
The assessment must take place before implementation or launch and must be reconsidered when material changes occur. It must also be reflected in the institution’s risk-assessment process and RMCP.
This is not simply an information-security or cybersecurity assessment. The question is whether the development could make the institution more vulnerable to money laundering, terrorist financing or proliferation financing. Relevant developments may include digital onboarding, biometric verification, automated screening, AI-assisted monitoring, client portals, application programming interfaces, outsourced KYC platforms, remote advice, new payment functionality, crypto services and non-face-to-face distribution models.
A compliant RMCP should set out:
This requirement must be applied proportionately. A small FSP with limited products does not need a bank-sized product governance committee, but it still needs a workable process. A short assessment and approval form may be sufficient if it genuinely considers the risks. An institution cannot simply state that technology risk is ‘not applicable’ when it uses digital onboarding, outsourced systems or other developing technologies.
Importantly, GN 7B does not clearly require institutions to perform a retrospective assessment of every mature system that has not changed. It does, however, justify reviewing the present technology inventory to establish whether new or developing technology is being used in existing offerings without an appropriate ML/TF/PF assessment.
3. Low-income clients may not automatically be treated as low risk
GN 7B preserves the ability to apply simplified due diligence. The FIC rejected concerns that its draft wording might effectively eliminate SDD and removed the proposed requirement for a ‘comprehensive’ risk assessment. SDD therefore remains available where it is justified by the institution’s risk-based approach.
However, paragraph 40A makes it clear that underserved or low-income clients cannot automatically be classified as lower risk simply because they fall within those categories. Financial inclusion is important, but low income is not, by itself, evidence of low ML, TF or PF risk.
RMCPs should therefore be checked for statements such as:
This does not mean every low-income client must undergo standard or enhanced due diligence. It means that the decision to apply SDD must be supported by a recorded risk assessment. Institutions may still classify particular low-value products or defined client groups as lower risk where the evidence supports that conclusion.
4. A section 29 report must now be followed by EDD
Paragraph 58A defines SDD as a basic level of identification and verification used where a business relationship or single transaction presents a low ML, TF and PF risk. It then introduces a significant requirement: where an institution has a suspicion of ML, TF or PF and files a report under section 29 of FICA, it must conduct EDD on the relevant relationship or single transaction.
The FIC’s consultation feedback provides important clarification on the sequence.
Not every automated or internal alert requires a section 29 report or EDD. The institution must first investigate the alert. If there is a reasonable explanation consistent with the client’s profile, the alert may be closed with reasons. Once the institution concludes that the matter is reportable and files the report, however, EDD becomes necessary.
The RMCP should describe what post-report EDD entails. Depending on the circumstances, it may include:
The process must be designed carefully to avoid tipping off the client. EDD does not invariably require immediately contacting the client and asking questions that reveal that a report has been filed. Institutions should first use information already held, reliable independent sources and ordinary review processes. Any client contact must be managed in accordance with the tipping-off prohibition.
GN 7B does not expressly require every historic STR or SAR to be reopened. A sensible response would be to review active relationships that were previously reported and determine whether appropriate EDD was completed. Closed historic relationships would generally require a documented risk-based decision rather than an indiscriminate back-book exercise.
So, must the entire RMCP be rewritten?
Not necessarily. The extent of the work depends on the present standard of the RMCP.
Limited update
A limited update may be sufficient where the RMCP already:
In that case, the institution should still update references from GN 7A to GN 7B, confirm the paragraph 37A and 58A processes expressly, document its gap assessment and obtain approval for the revised controlled version.
Targeted substantive revision
Most institutions will probably fall into this category. The RMCP, BRA and supporting procedures should be updated in the four affected areas, but the remainder of the programme can remain intact.
This will ordinarily require changes to:
Full redevelopment
A full redevelopment is warranted where the RMCP:
Approval and version-control implications
Any GN 7B amendments must be properly approved. Paragraph 190 states that RMCP reviews and amendments must be documented and approved. The board, senior management or person with the highest authority—depending on the institution’s structure—must approve the RMCP. This responsibility cannot be delegated to a compliance committee or the compliance officer.
GN 7B specifically gives the example of an FSP implementing an updated RMCP that has not been approved by its board. The FIC says this may constitute non-compliance. Institutions should therefore avoid circulating or implementing a supposedly final GN 7B version before formal approval.
Where procedures, templates or risk assessments sit outside the main RMCP, they must be clearly referenced. GN 7B states that documentation not referenced in the RMCP is not considered part of the RMCP.
Recommended implementation approach
Every accountable institution should now complete the following:
Overall conclusion
GN 7B does not justify automatically replacing every RMCP from the first page to the last. It does, however, require more than changing the document title or adding ‘PF’ next to ‘ML/TF’.
At a minimum, every institution needs a documented review and a properly approved GN 7B-aligned version. Where an existing RMCP was genuinely compliant with Revised GN 7A’s stronger Chapter 4 requirements, the amendments can be focused. Where the RMCP remains generic, checklist-driven or weak on PF, technology governance, SDD and post-report EDD, a substantial rewrite is necessary.
The most important new operational rule is straightforward: financial-crime risk must be considered before new products or technology are launched, and filing a section 29 report must now lead to documented EDD.
Website designed by WEBSITEDESIGN.co.za and hosted by WEBSITEHOSTING.co.za