RCR submissions: Are we answering honestly, or optimistically?

rcr

July 7, 2026


The 2026 Risk and Compliance Return is not just another regulatory questionnaire.

It may feel like one. It may look like one. It may sit on someone’s desk or inbox with the same quiet menace as every other compliance return that needs to be completed before a deadline. But accountable institutions should be careful not to treat the RCR as a “best case scenario” document.


The Financial Intelligence Centre has made it clear that the 2026 RCR is intended to gather information from specified accountable institutions about their understanding of money laundering, terrorist financing and proliferation financing risks, as well as the implementation of risk-based controls under the FIC Act. The FIC also states that it uses RCR data in a risk-rating tool to identify higher-risk accountable institutions for risk-based supervision consideration and possible inclusion in its supervisory plan.

That means the answers matter. Not in the abstract. Not only because “the regulator asked.” Not only because someone needs to tick the submission box and move on. They matter because the data submitted may influence how the institution is viewed, risk-rated and supervised. And this is where firms need to be brutally honest with themselves.


There is often a gap between the answer a business wants to give and the answer the evidence can actually support. Many compliance and regulatory questionnaires are completed from the perspective of what the policy says, what the RMCP intends, what management believes is happening, or what the firm hopes will be true once current clean-up work is finished. That is dangerous.

If the question asks whether a control is in place, the real test should not be: “Do we have a policy that says this happens?” The real test should be: “If we were inspected tomorrow, could we easily and consistently prove that this happens in the ordinary course of business?


There is a big difference between having a process and being able to evidence that the process is actually followed. There is also a big difference between being able to pull together evidence for an audit and being able to show that the business operates that way every day.

This is where “compliance theatre” creeps in. The business knows what the correct answer should be. The policy has the right wording. The RMCP looks respectable. The training register exists. The client due diligence procedure has been approved. The monitoring process is described neatly. But day to day, things are messier.

People bypass steps because the client is urgent. Reviews fall behind because the team is stretched. Risk ratings are not revisited when circumstances change. Beneficial ownership information is accepted because “we know the client.” Suspicious activity discussions happen informally but are not always properly documented. Escalations depend on one person remembering what to do. And when an audit or regulatory request lands, everyone runs to the same two or three internal heroes who know how to make the file look right. Those people may save the audit. They do not fix the control environment. In fact, they may unintentionally hide how fragile it really is.


The FIC’s own enforcement and supervision activity shows why this matters. In its 2024/25 reporting, the FIC said it follows a risk-based supervision approach, identifying accountable institutions at higher risk of being abused for money laundering and terrorist financing. It conducted 556 inspections in the year, mostly of medium and high-risk institutions. From those inspections, 330 institutions received reports requiring remedial action due to non-compliance. The FIC also issued 25 administrative sanctions during the financial year, with sanctions totalling R2.228 million.


So the issue is not theoretical. The FIC is not collecting RCR information so that it can admire everyone’s policy wording from a respectful distance. It is using data to understand risk. It is using data to inform supervision.

And if the data submitted does not reflect the reality of the business, the institution creates a problem for itself. This does not mean firms should understate their controls or answer defensively. It means they should answer accurately.

There is nothing wrong with saying: “We have implemented the control, but evidence is inconsistent.” There is nothing wrong with saying: “The RMCP provides for this, but the operational process is still being embedded.” There is nothing wrong with identifying gaps, provided the firm is honest about them and can show that it is actively addressing them.


What is risky is presenting a perfect-world version of the business when the underlying evidence tells a different story.

The FIC’s consultation feedback on Directive 11 is also worth noting. In response to concerns about the burden of completing the RCR, the FIC stated that the information requested in the questionnaire should be readily available to accountable institutions, although the initial gathering and collation of information over the relevant period may take preparation.

That is an important point. If the information is not readily available, that may itself tell the institution something about its control environment. If the business struggles to answer basic questions about its AML/CFT/CPF risk exposure, client base, control implementation, training, reporting, monitoring or governance, the problem is not the questionnaire. The questionnaire is revealing the problem.

The RCR should therefore be treated as more than a submission exercise. It should be treated as a mirror:

  • Can we support this answer with evidence?
  • Is this how the business actually operates, or is this how the policy says it should operate?
  • Are we answering based on normal day-to-day practice, or based on what our best people can reconstruct under pressure?
  • Are we relying on systems and controls, or on institutional memory and individual heroics?
  • If we were inspected tomorrow, would our files, registers, reports, meeting minutes, training records, client records and escalation logs tell the same story as our RCR answers?

South Africa’s removal from the FATF grey list in October 2025 was a positive development, but it should not create complacency. FATF confirmed that South Africa was no longer subject to increased monitoring, but the broader AML/CFT/CPF expectation remains one of effective implementation and ongoing risk-based supervision.


For accountable institutions, the message should be clear. Do not complete the RCR from the version of the business you wish existed. Complete it from the version of the business you can prove exists. Because if the questionnaire says one thing and the evidence says another, the issue is no longer only a compliance gap. It becomes a credibility problem.

Leave a Comment

Your email address will not be published. Required fields are marked *