How to collect FICA and KYC documents from clients safely
Short answer: Collect FICA and KYC documents through a checklist derived from your institution's current risk management and compliance programme, not a universal internet list. Identify the client type, relationship, authority, beneficial owners and risk factors; request only the approved evidence; provide a secure submission route; track each item and verification result; restrict access; and retain records for the applicable period. Compliance staff must resolve exceptions and approve completion.

FICA collection is often described as asking every client for an ID and proof of address. That shorthand is operationally dangerous. South Africa's customer due-diligence framework is risk-based, and the information and verification needed depend on the accountable institution, client type, relationship, beneficial ownership, authority and assessed risk. A static document pack can therefore collect too much from one client and miss crucial evidence from another. This guide explains the administrative system around an institution's approved risk management and compliance programme: turning requirements into a live checklist, collecting evidence securely, preserving provenance, routing exceptions and retaining records. It does not replace the FIC Act, sector guidance, a compliance programme, legal advice or the accountable institution's compliance decision.
Why is there no universal FICA document checklist?
The FIC Act framework requires risk-based customer due diligence, so evidence must follow the institution's client and risk analysis. A familiar list is not a substitute for that reasoning.
The Financial Intelligence Centre's Revised Guidance Note 7A explains that accountable institutions have flexibility to choose information and verification means within a risk-based approach rather than follow the old rigid identification steps. The institution's compliance programme should translate that discretion into repeatable rules staff can apply.
A natural person, company, partnership and trust do not present the same ownership and authority questions. Higher-risk relationships may require enhanced steps. A checklist should therefore be generated from approved client-type and risk rules, with a version and effective date. It should never be invented afresh by an assistant from whatever the client happened to send.
What should the collection workflow establish?
The workflow should establish the client, relevant persons, authority, beneficial ownership and relationship information required by the compliance programme. Documents are evidence toward those facts, not the purpose by themselves.
The intake should first determine which approved pathway applies. For a person, that may involve identity and relevant address or relationship information. For a legal person, it may include registration, structure, authorised representatives and the natural persons who ultimately own or control it. Trusts and partnerships introduce their own relevant parties and authority.
The system should record each required fact, acceptable evidence types, verification method, result, reviewer and unresolved issue. It should also separate “received” from “verified” and “verified” from “CDD approved”. A clear status model prevents a complete-looking folder from being mistaken for a complete compliance process.
How should clients submit sensitive documents?
Give clients one approved, low-friction submission route and state exactly what remains outstanding. Security and completion both suffer when documents scatter across email, messaging apps and personal downloads.
A secure portal or controlled upload link may provide stronger access, request identity and audit than ordinary attachment exchange. If email is permitted, capture the message and attachment, then promote the authoritative copy into the restricted client record. Remove local downloads and duplicates under policy rather than allowing permanent shadow files.
Each request should name the item, person or entity, acceptable evidence, date or period where relevant, secure submission method and deadline. Avoid requesting broad packs “just in case”. The email-to-client-document workflow provides the filing spine, but the institution's compliance programme determines what belongs on the checklist.
How should received evidence be tracked and reviewed?
Track every item through requested, received, readable, matched, verified, accepted or exception states. “Uploaded” is only a transport result.
On receipt, preserve source, file identity and time. Associate the evidence with the correct client and checklist item. Extract visible names, numbers, dates and document type as review aids, then compare them with the claimed person or entity. Image quality, expiry, mismatch, suspected alteration and wrong-person evidence should create explicit exceptions.
Automated classification reduces manual sorting, but authenticity and verification need approved methods and data sources. Beneficial ownership, sanctions screening, politically exposed person treatment and higher-risk measures cannot be inferred safely from a folder of PDFs. Record the reviewer, decision, evidence used and any escalation.
How can automation help without making the compliance decision?
Automation can administer the approved process; it should not authorise itself to change the process or certify the result. The distinction protects both speed and accountability.
Useful automatic work includes creating the correct checklist, recognising document types, extracting visible fields, detecting missing items, identifying likely newer versions, drafting precise reminders and assembling the review packet. The automatic filing workflow can retain sender and source evidence while placing a document against the correct client.
Human or separately authorised controls should resolve ambiguous identity, ownership chains, authority, risk rating, suspicious indicators, sanctions matches, exceptions and final CDD approval. Inbound documents are evidence, never instructions to relax requirements, disclose another client's information or bypass review.
What security and retention controls apply?
Restrict CDD evidence to authorised roles, preserve reproducible records and apply the retention authority recorded by the institution. These files contain concentrated identity and ownership information.
Use individual accounts, multifactor authentication, least privilege, encryption, access logging, controlled external sharing, tested recovery and documented incident handling. Separate client records where necessary and review access when staff roles change. The storage provider and any operator relationship should be evaluated against privacy and contractual duties.
FIC materials state that relevant CDD and transaction records may be electronic and set five-year periods for specified records, calculated from the applicable relationship termination or transaction date. The exact retention event, legal hold, sector overlay and backup lifecycle should be encoded from current advice. Prior evidence may need to remain retained even after a newer document becomes current.
What does a useful FICA collection dashboard show?
The dashboard should show compliance work and exceptions, not a comforting percentage stripped of meaning. A “90% complete” badge is useless if the missing item is beneficial ownership evidence.
For each client, show pathway and compliance-programme version, relationship, required facts, evidence status, last verification, exceptions, owner and next action. The portfolio view should surface overdue requests, unresolved mismatches, higher-risk reviews and stale information according to approved rules. Every status should open back to the evidence and decision history.
Do not expose sensitive identity numbers in broad list views or notifications. Use minimum necessary labels and role-based detail. A reminder can say which proof is missing without reproducing the private contents of documents already supplied.
Who it is not for
This article is not legal advice, a complete FICA checklist or a certification method. It is not for businesses outside the relevant obligations that are copying bank onboarding requests without a lawful purpose. Nor should an accountable institution adopt these examples without reconciling its current compliance programme, sector guidance, client base and risk assessment.
The workflow is also inappropriate if the repository lacks basic access control, incident handling, retention and deletion governance. Collecting more identity evidence into an insecure folder increases harm. Where the ownership structure, authenticity, sanctions result or client conduct raises concern, automated chasing should pause and the matter should follow the institution's compliance and reporting procedures.
Conclusion
Safe FICA and KYC collection begins with the institution's current compliance programme, not a universal attachment list. The approved client and risk pathway produces a checklist of facts and acceptable evidence. Clients receive one precise request and controlled submission route; every item retains source and moves through receipt, review, verification and exception states. Automation can classify, extract, file and draft reminders, but authorised people and systems decide authenticity, beneficial ownership, risk and completion. Access and retention apply across the full evidence lifecycle. Built this way, the collection process becomes faster and clearer without pretending that administrative completeness is the same as compliant customer due diligence.
Frequently asked questions
What documents are required for FICA in South Africa?
There is no single universal document list for every client and accountable institution. The institution applies its risk-based compliance programme to establish and verify the relevant identity, authority, beneficial ownership and relationship information. Requirements differ for natural persons, companies, partnerships, trusts and higher-risk cases. Use current FIC and sector guidance, not a generic checklist.
Can clients email their FICA documents?
Email may be an accepted intake route under an institution's approved controls, but sensitive documents should not remain unmanaged across inboxes and downloads. Provide the approved secure route where possible, preserve source, restrict access, verify receipt and file the authoritative copy. The compliance programme and privacy safeguards should govern the permitted channel and handling.
Can AI verify that a client is FICA compliant?
AI can classify submitted documents, extract visible fields, compare them with a checklist and identify missing or inconsistent information. It cannot itself determine that customer due diligence is legally complete. Authenticity, beneficial ownership, sanctions, risk, authority and exceptions require approved data sources, controls and accountable human oversight under the institution's compliance programme.
How long must FICA records be kept?
FIC guidance states that accountable institutions generally keep customer identification and verification records for five years after the business relationship ends, and transaction records for five years after the transaction. Apply the current FIC Act, sector requirements, legal holds and compliance programme to the specific record; do not use a generic timer without review.
What should happen when a FICA document expires?
Expiry does not automatically answer whether renewed evidence is legally required. The institution should apply ongoing due-diligence triggers and its compliance programme, identify the affected client and relationship, request the correct replacement where required, preserve prior evidence under retention rules, verify the new information and record who approved the updated due-diligence state.
Stop working for your inbox.
Hank turns the work arriving in your email into tasks, records, drafts and proposed actions, while you stay in command.
Start 14 days free — no card