Sanctions & PEP Screening
LSEG World-Check One and On Demand, ComplyAdvantage (including ongoing monitoring with webhook-driven case creation and MLRO escalation ladders when risk profiles change), Dow Jones Risk & Compliance (Factiva AME and RiskCenter journalistic depth, not list-only matches), LexisNexis Bridger, and LexisNexis WorldCompliance Data as a standalone global risk data feed covering 180+ sanctions lists, PEPs, and 1,700+ enforcement sources across jurisdictions for due diligence programmes, for real-time screening, overnight full-book batch runs with exception queues, matching calibration and false-positive reduction (secondary identifiers, threshold tuning, known-FP suppression), structured hit-review case queues with escalation ladders and audit trails, embedded CRM sales-workflow screening with status sync-back, ongoing monitoring alerts when a client risk profile changes after onboarding, consolidated multi-list management that merges UN, EU, OFAC, UK Sanctions List, and FIC TFS into a single operational screening feed with source attribution and one audit trail, list-change detection across those feeds that triggers automatic full-book re-screening when new sanctioned parties are published, SA domestic PEP and DPEP databases covering Schedule 3A officials, SOE board members, municipal leaders, and associates alongside continuous global PEP database sync with scheduled full-book re-screens and same-day CRM alerts when a client becomes a PEP mid-relationship, adverse media and negative news monitoring for fraud, corruption, and reputational risk with ongoing alerts when new coverage appears, and pre-settlement payment and transaction sanctions screening with automatic holds and release/reject review queues.
KYC & KYB Onboarding
End-to-end digital onboarding for clear clients in minutes: paperless mobile document capture, ECTA-compliant electronic signatures, DHA/AVS identity verify, sanctions/PEP screen, CRM/core write-back, examiner-ready FICA Section 21 evidence packs, Section 21A enhanced EDD packs for foreign PEPs and high-risk clients with automated escalation, LSEG/Refinitiv Enhanced Due Diligence report ordering via API for narrative deep-dive packs covering PEP status, sanctions, and adverse media (distinct from World-Check list screening), a dedicated risk rating engine applying RMCP scoring models with low/medium/high classification, EDD/MLRO routing, and score explainability for examiners, CIPC and BizPortal company registration, director lookup, and trading-status confirmation for juristic persons, Moody's Grid and Orbis (formerly Bureau van Dijk) for global corporate entity data, ownership structures, financial risk indicators, and CRM write-back alongside local registry checks, beneficial ownership and UBO tree mapping through layered companies, trusts, and nominees with CIPC BO register cross-checks and opaque-structure flags, automated director and shareholder screening against sanctions, PEP, and adverse media, and risk-prioritised periodic KYC remediation queues with automated document chase and re-verification to clear review backlogs.
RMCP & Programme Governance
FICA section 42 Risk Management and Compliance Programme design and implementation: entity-wide risk assessments, control matrices, board reporting packs, section 43 staff training registers, and living programme evidence that survives FIC inspection instead of static Word documents.
AML Transaction Monitoring
Transaction-monitoring rule engines (threshold, velocity, and typology scenarios) with false-positive tuning and FIC Directive 5 48-hour evidence; ongoing AML customer risk scoring that combines behaviour, profile, and geography to drive EDD and monitoring intensity; FIC and FATF typology-aware detectors for structuring, layering, trade-based laundering, and mule networks; structured investigation case management (alert triage, assignment, evidence, decision capture); and automated STR/CTR filing to the FIC via goAML with disposition trails.
Credit Bureau Integration
TransUnion, Experian, XDS, Compuscan, and Datanamix API integration for automated credit enquiries with score, payment history, judgments, and defaults written back to CRM or loan systems, XDS Consumer Trace for skip recovery, Datanamix alternative and thin-file risk indicators beside traditional bureau pulls, multi-provider failover and best-match routing across bureaux, post-bureau credit score decisioning with configurable risk appetite, approve/decline/refer routing, and inspection-ready audit trails, POPIA consent evidence linked to each decision, and NCA affordability pack readiness.
Identity Verification
Home Affairs DHA NPR ID number validation with name/DOB match and alive/deceased status, HANIS fingerprint and facial photo matching for higher-assurance FICA onboarding, 1:1 selfie-to-ID facial recognition with examiner-ready match scores (distinct from HANIS photo matching), liveness and presentation attack detection (PAD) with passive or active challenges to ISO/IEC 30107 Levels 1–3 against deepfakes and injection attacks, OCR extraction for SA IDs and passports, proof-of-address authenticity and tamper checks, blur and glare rejection at capture, document authentication, AVS bank account verification, productised SA KYC APIs such as VerifyNow and Didit (document, biometric, AML/watchlist, optional DHA/SAFPS in one workflow), Onfido / Entrust document authentication and facial biometric KYC with CRM write-back, and global multi-jurisdiction IDV platforms such as Sumsub covering 220+ countries with risk-tier and jurisdiction routing for cross-border onboarding.
Privacy & GDPR
CRM consent ledgers, DSAR workflows, Art. 17 erasure, Art. 20 portability, and Art. 30 processing records for South African firms serving EU customers, alongside POPIA right-to-erasure and retention tooling so privacy policy promises are enforceable in the CRM. Also covers POPIA-compliant CRM and ERP migration events: consent carry-over into the new system, lawful-basis documentation, data minimisation before go-live, and Chapter 9 cross-border transfer assessments when the destination SaaS hosts data offshore, scheduled archive, anonymise, and delete automation with legal holds and disposition evidence packs across CRM, ERP, support, and storage (not only DSAR/erasure fields), full legacy-system archives that meet Companies Act accessible-form floors beyond CRM archive-vs-migrate, CRM access-control rebuild after migration (role mapping, permission sets, sharing rules, and least-privilege testing) so POPIA unauthorised-access risk is not introduced at cutover, archive-vs-migrate retention schedules that keep purpose limitation lawful, marketing-list and suppression continuity so opt-outs survive platform switch, and retiring orphaned CRM tenancies under POPIA once archival handoff is complete. Distinct from who-changed-what field-level audit trails used for dispute evidence, from immutable document access, edit, and share trails that support POPIA s23 third-party access evidence, and from independent CRM backup that supports POPIA security-safeguard continuity when personal information is lost or corrupted.
FSCA & FAIS Compliance
Financial sector regulatory reporting, FAIS Ombud submissions, adviser compliance tracking, and CRM change-history evidence packs that support five-year FAIS record retention and seven-day FSCA inspection readiness.
Insurance & Medical Aid
Discovery, Momentum, Sanlam, and Old Mutual broker feeds, claims processing, and policy management integration.
Securities & Trading
JSE, Strate, broker platforms, and wealth management system integration for portfolio and settlement workflows.