Capitec Bank has been hit with a R28 million regulatory penalty after South Africa’s Prudential Authority found several shortcomings in the lender’s compliance with anti-money-laundering and counter-terrorist-financing requirements.
The sanction follows an inspection conducted in 2023 under the Financial Intelligence Centre Act (FIC Act), with the regulator identifying weaknesses across customer checks, enhanced and ongoing due diligence, employee training and the bank’s broader risk-management and compliance framework.
Importantly, the penalty does not mean Capitec has been found to have facilitated money laundering or terrorist financing. The findings concern failures to meet regulatory requirements designed to prevent and detect such activity.
Why Capitec was fined R28 million
The Prudential Authority imposed five separate financial penalties covering different areas of non-compliance.
The largest, R10 million, relates to shortcomings in customer due diligence.
A further R5 million was imposed over inadequate enhanced due diligence, while another R5 million relates to weaknesses in ongoing due diligence.
The regulator imposed an additional R3 million over employee training failures.
The remaining R5 million relates to weaknesses in Capitec’s risk-management and compliance programme, including controls concerning financial sanctions and the reporting of property suspected of being connected to terrorist activity.
The total comes to R28 million.
Of that amount, R5.5 million has been conditionally suspended for 36 months. The PA also issued five cautions instructing the bank not to repeat the conduct that resulted in the regulatory findings.
Customer checks came under scrutiny
One of the regulator’s central concerns involved how Capitec conducted due diligence on customers.
Banks are required to establish who their customers are, understand relevant aspects of their financial activities and assess the risks associated with particular relationships.
For higher-risk customers, additional checks may be required, while ongoing due diligence requires institutions to continue monitoring relationships rather than treating customer verification as a once-off exercise.
The PA found that Capitec had not adequately carried out these processes on some of the client files examined during the inspection.
The regulator also identified shortcomings in the bank’s processes for enhanced and ongoing due diligence.
These controls are particularly important in South Africa’s broader effort to strengthen the financial system against money laundering, terrorist financing and other forms of illicit financial activity.
Employee training also flagged
The inspection found that some Capitec employees had not received adequate ongoing training relating to FIC Act compliance.
For banks, staff training is a critical component of financial-crime controls because employees are often responsible for identifying suspicious behaviour, applying customer verification procedures and escalating potential compliance risks.
The PA therefore imposed a R3 million penalty specifically relating to shortcomings in employee training.
Concerns over sanctions and terrorist-property controls
The regulator also highlighted weaknesses in Capitec’s broader risk-management and compliance programme.
These included shortcomings around sanctions screening, customer and payment screening and the reporting of property potentially linked to terrorist activity.
The PA said Capitec could not provide evidence that certain end-to-end procedures dealing with terrorist-property reporting had been properly documented and approved before the regulator’s inspection.
The findings also included issues around anti-money-laundering screening manuals and the approval of certain processes.
These requirements form part of the preventative architecture of South Africa’s financial system: banks are expected to have systems capable of identifying risks before they develop into larger financial-crime problems.
Capitec cooperated with the regulator
Despite the findings, the Prudential Authority said Capitec cooperated with the regulatory process and had taken steps to address the deficiencies and control weaknesses identified during the inspection.
Capitec has previously said that it is committed to strengthening its compliance framework and resolving matters identified by the PA. The bank also confirmed in its reporting that its financial-crime controls have been an area of heightened management focus.
The latest sanction therefore concerns regulatory compliance failures identified during an inspection rather than an allegation that the bank itself was involved in criminal financial activity.
This is Capitec’s second major FICA penalty
The R28 million sanction is particularly notable because it follows another substantial penalty against Capitec.
In December 2024, the Prudential Authority imposed R56.25 million in financial penalties on the bank following inspections conducted in 2021 and 2022.
That earlier case involved shortcomings including customer due diligence, transaction monitoring, reporting obligations and aspects of Capitec’s risk-management and compliance programme. Of the R56.25 million penalty, R10.5 million was conditionally suspended.
The latest R28 million sanction therefore brings renewed regulatory attention to Capitec’s financial-crime compliance systems.
It also highlights the continuing pressure on South Africa’s financial institutions to demonstrate that their anti-money-laundering controls work effectively in practice, rather than simply existing on paper.
What the Capitec penalty means
For customers, the latest sanction does not mean their Capitec accounts are implicated in money laundering or that the bank has been accused of knowingly facilitating criminal activity.
Instead, the PA’s findings concern whether the bank had sufficiently robust systems, procedures and training in place to comply with the country’s financial-intelligence laws.
That distinction is important.
The purpose of FICA compliance is to ensure financial institutions can identify customers properly, understand risk, monitor relationships and report relevant activity to the authorities.
The latest penalty shows that regulators continue to scrutinise those systems closely.
For Capitec, the immediate focus will be on maintaining the remedial measures it has already undertaken and avoiding a repeat of the compliance shortcomings identified by the Prudential Authority.


