top of page

Why Compliance Frameworks Are Failing Against Modern Financial Crime in South Africa

  • Jul 25
  • 4 min read

Updated: Jul 27

SprintHive launched its "See the Fraud" podcast with a sit-down interview featuring Lebogang Thobokgale, KPMG's Associate Director and Anti-Money Laundering Compliance Officer, and Co-Chair of the Africa Chapter on Trade-Based Money Laundering for the Global Coalition to Fight Financial Crime.


To open our discussion, Thobokgale highlighted that there was a time when financial crime was called white collar crime, and detecting it was a methodical process. Auditors would vouch for an invoice against a copy, and anomalies were visible to a trained eye.


What replaced this instantly visible era are economic crime schemes that don't operate in isolation. Money laundering requires predicate offenses: fraud, corruption, and cybercrime. One crime generates the proceeds, another hides them, while the other moves them. By the time laundered money surfaces in the legitimate economy, it's been through enough layers to be considered “clean”.


According to a NASDAQ financial intelligence report, 3.1trillion dollars is the estimated value of illicit financial flows in the global economy. The Financial Action Task Force estimates financial crime contributes between 2 and 5 percent of global GDP, and that money doesn't sit outside the economy in some criminal parallel universe. "Perpetrators don't have their own economy," Thobakgale says. "They get back and integrate it back into the same economy."


Early this year, the World Economic Forum's risk report ranked corruption and financial crime as a top-tier global risk for the next two to ten years. This is not a problem approaching resolution, it’s a scary risk indicator we are projected to be living with, at scale, for the foreseeable future.


On South Africa's Corruption Perception Index, the country sits at approximately 45 percent, in the median between very corrupt and very clean. On AML risk indexes, we've moved from high to medium risk. Is that progress? Yes, but significant room for improvement is still required in both. So, when you ask how serious financial crime actually is? "Catastrophic," Thobakgale says. "We just don't see it."


The sectors most associated with money laundering get most of the regulatory attention, but organised syndicates have moved well beyond financial services, and the vehicles they're using now are far less obvious.


Property agents are implicated. Cash from property transactions, received without adequate source-of-funds verification, can be used to clean criminal proceeds. Add an offshore account, and the beneficial owner becomes nearly impossible to trace without significant investigative effort.


Non-profit organizations are another laundering vehicle, this tends to surprise people. NPOs rely on donations, which means money flows in with relatively limited scrutiny. Association with a legitimate cause provides cover. Criminals need to clean money and get it back into circulation, and a credible NPO affiliation helps them do exactly that. The General Laws Amendment Bill placed NPOs under significantly more regulatory scrutiny for precisely this reason.


Accountants and tax practitioners are at risk too. A client asking how to structure offshore holdings may not necessarily be asking a tax question, they could potentially be asking a financial crime question. The professional who can't tell the difference becomes an unwilling participant in economic crime.


Deepfakes have now entered the market and are part of the toolkit. The FIC has documented cases involving convincingly manipulated video footage of senior public figures promoting fraudulent investment platforms. One such case involved approximately R90 million in losses. 


The overall takeaway from the conversation with Lebogang, financial crime is no longer contained to financial services, it follows money wherever money moves. If your sector touches capital, it touches this problem.


Compliance officers and auditors are aware that there is a version of compliance that exists purely to satisfy regulators, known as compliance theater. A compliance officer is appointed, reports are filed, and boxes are ticked. The board takes the pack without scrutiny or understanding and sadly moves on. But as you can imagine, this version of compliance is expensive, ineffective, and increasingly dangerous.


The regulatory shift from rules-based to risk-based compliance was a direct challenge to this posture. Thobakgale clarifies that, under a risk-based approach, institutions are expected to genuinely understand their own business activities, map their financial crime exposure, and implement controls proportionate to their actual risk profile. Not a template, or a checklist, but conducting a real assessment of where the risks live and what to do about them.


When boards lack the credential knowledge to understand what financial crime actually looks like in their business, two things happen. 1. Compliance functions become isolated from strategy, and 2. Compliance becomes a cost center, not a risk management mechanism.


"If you don't have the core understanding of your business," Thobakgale says, "you won't be able to do what we call a business risk assessment."


The fix is not more compliance resources, it's better board-level understanding about what financial crime looks like, how it moves through different business activities, and why the compliance function exists to protect against something real, not to satisfy an abstract regulatory obligation. Once boards understand the threat, the conversation shifts from "what does this cost?" to "what is this protecting us from?"


It’s without a doubt that South Africa's regulatory framework is, by international standards, above standard. Our legislation is strong, the FIC Act has been refined progressively. The twin peaks model, adapted from UK practice, separates prudential and market conduct regulation in a way most peer regulators respect. The problem is not the quality of the rules, it's the coordination between the people applying them.


However, what's still missing is the systematic inclusion of the private sector in that coordination. Banks, investment firms, and other accountable institutions hold intelligence about how financial crime actually moves through business activity. Leaving them outside the coordination framework means leaving significant detection capacity on the table.


Financial crime is not abstract, it is the economy we all share, and whether your institution is onboarding customers, processing transactions, or advising on structures, the question is no longer whether this affects you. It's whether your frameworks are ready for what's coming next.


-

SprintHive builds AI-powered identity verification and income assessment infrastructure for financial institutions across Sub-Saharan Africa. See the fraud is an Executive Fraud Roundtable SprintHive original series. Each episode brings together senior voices in compliance, risk, and financial crime to unpack the realities of emerging fraud threats, systemic vulnerabilities, and the strategies institutions must adopt to stay ahead in banking, insurance, and lending in fintech Africa.


Book a demo with one of our experts to see how our Identity Verification, Income and Affordability Verification, and Fraud Prevention solutions can protect your digital customer onboarding sales@sprinthive.com or visit www.sprinthive.com

bottom of page