Back to resources
Compliance

Designing FICA-ready onboarding workflows

A practical guide to building FICA-ready onboarding around risk-based due diligence, verification, screening, and defensible recordkeeping.

12 min readJanuary 2025

What FICA-ready onboarding has to cover

The FIC Act requires accountable institutions to implement controls against money laundering, terrorist financing, and proliferation financing. That is not just a screening problem. It is an operating-model problem.

A workable onboarding flow has to join identity verification, sanctions and PEP screening, source-of-funds context, case handling, and long-term recordkeeping into one defensible process.

Start with risk management and customer due diligence

Every accountable institution needs a Risk Management and Compliance Programme that reflects its own business risk, client risk, and product risk. Onboarding should enforce that model rather than living outside it.

Customer due diligence then follows the client's risk profile: standard due diligence for routine cases, enhanced due diligence for higher-risk customers, PEPs, and relationships that need deeper source-of-wealth review.

Verification and screening need reliable data sources

Verification should corroborate client information against reliable third-party sources such as Home Affairs for individuals, CIPC for companies, and other trusted registries for ownership, address, and account checks.

The same flow should screen sanctions lists, PEP and RCA datasets, adverse media, and watchlists without forcing analysts to re-enter the same customer context across separate tools.

Recordkeeping is part of the workflow, not a later export

FICA obligations do not end at approval. Institutions need to preserve identity evidence, risk assessments, screening outcomes, transaction context, and remediation history for at least five years after the business relationship ends.

That is why the strongest onboarding platforms produce a digital audit trail as the work happens. Compliance teams should not need to reconstruct the customer story from inboxes, spreadsheets, and vendor consoles when a regulator asks for proof.

How technology improves compliance operations

Modern compliance teams move faster when verification, screening, risk scoring, and audit reporting are integrated into one operating layer. Real-time checks reduce manual delay, and structured evidence makes escalations easier to defend.

The practical goal is not to automate compliance theater. It is to give accountable institutions a risk-based onboarding surface that can stand up to regulatory review while still moving legitimate customers through quickly.

Need help applying this in a live workflow?

Use the contact route to discuss how these platform capabilities map to your onboarding, lending, compliance, document, AI, or municipal environment.

Talk to the Deis team