Screen, Freeze, Report: What Targeted Financial Sanctions Actually Require of Your Agency

An agent in Durban North closes an OTP on a R4.2 million cash sale. The buyer's ID was verified, proof of address checked, source of funds noted. By every measure the agent knows, the file is clean. Three months later, the FIC opens a routine inspection and asks a different question entirely: "Where is the record showing this client was screened against the targeted financial sanctions list, and when?"
There is no record. Not because the agent skipped a step deliberately, but because nobody told them that a sanctions and terrorism-financing check is a separate, standalone obligation from the identity verification they already do, with its own list, its own timing rules, and its own reporting deadline measured in days, not weeks.
This is not a hypothetical gap. It is the exact failure the FIC penalised an estate agency for in one of the clearest enforcement decisions on record for the sector, and it is a step that is easy to get wrong precisely because it looks, on the surface, like something an agency has already done.
Why this is the moment to get it right
In August 2025, the FIC published guidance addressed specifically to estate agents on their targeted financial sanctions obligations, a signal that the regulator sees this as a distinct weak point in the sector rather than something covered off by general FICA training. The guidance sits alongside Public Compliance Communication 44A (PCC 44A), the FIC's consolidated sanctions rulebook that replaced the older PCC 44 and PCC 54, and it has not stood still since. As recently as April 2026, the FIC issued a further update to the sanctions list itself, following changes made by the United Nations Security Council, a reminder that this is a live list an agency has to keep checking against, not a document you read once and file away.
WHAT PCC 44A ACTUALLY SAYS
PCC 44A sets out three obligations for every accountable institution, estate agencies included: scrutinise client information against the targeted financial sanctions list, freeze the assets of anyone who matches, and report the match to the FIC. The FIC's sanctions list itself is free to search at any time through its online portal, so there is no cost barrier to running the check.
Put plainly: verifying who your client is and checking whether your client appears on a UN sanctions list are two different obligations under two different sections of the FIC Act. An agency can do the first perfectly and still fail the second, and the FIC's own enforcement record shows exactly that happening.
1Understand what a sanctions screen actually is
Targeted financial sanctions are not the same thing as a politically exposed persons (PEP) check, and neither is the same as standard client due diligence. A PEP check flags clients who hold or held prominent public functions, because that status raises corruption risk. A sanctions screen checks a client's name, and where relevant a company or trust's beneficial owners, against the United Nations Security Council's list of individuals and entities designated in connection with terrorism and the financing of weapons of mass destruction proliferation. South Africa gives effect to these UN designations domestically, and the FIC Act, in sections 26A, 26B and 26C, places the screening, freezing and reporting duties directly on accountable institutions, estate agencies among them.
The list is maintained and published by the FIC and can be searched without charge. That matters for a small agency weighing up tooling decisions: the barrier to doing this correctly has never been cost, it has been process. A search that never happens, or happens once at onboarding and never again, fails the obligation just as surely as never searching at all.
2Screen every client, not just the ones that feel risky
It is tempting to reserve extra scrutiny for the transactions that already feel unusual: the buyer paying cash, the seller with an offshore address, the deal that closes unusually fast. Targeted financial sanctions screening does not work that way. The obligation applies to every client, on every transaction, regardless of how low-risk the deal otherwise looks, because a sanctions match is a binary fact about a person or entity, not a judgment call about transaction risk.
- Screen every natural person client, buyer and seller, individually by full name
- Screen every company or close corporation client and its registered directors
- Screen every trust client and its trustees, founders and identified beneficiaries
- Screen beneficial owners identified through your company and trust due diligence, not just the entity itself
This is where the beneficial ownership work an agency already does for FICA purposes pays a second dividend: the names surfaced when establishing who ultimately owns or controls a corporate or trust client are exactly the names that need to be run against the sanctions list, not just filed as part of the client due diligence pack.
3Screen again, not just once
The FIC is explicit that screening is not a single event completed at onboarding. Its own guidance describes the obligation as applying "during the client onboarding process, on an ongoing basis and when the UNSC adopts new TFS measures or expands existing ones." A client who cleared the list in January is not automatically clear in August. The UN Security Council adds and removes designations throughout the year, and a client onboarded before a listing was added will not be caught unless the agency re-runs the check.
For an agency with an active book of repeat clients, landlords, investors, developers, this is the part most likely to be missed in practice. A one-time check at first onboarding satisfies neither the letter nor the intent of the rule.
DON'T ASSUME "WE DID FICA" COVERS THIS
In August 2024, the FIC's Appeal Board upheld an administrative sanction of R266,000 against Capital Point Properties (Pty) Ltd, an estate agency found to have neither implemented a working risk management and compliance programme nor screened its clients against the targeted financial sanctions list. The agency had partially remedied the gaps after the FIC's enforcement process began. The Appeal Board held that remedial action taken after enforcement started did not undo the liability for the earlier non-compliance. The fines stood.
4Treat a list update as an action item, not background noise
Because the FIC updates its targeted financial sanctions list periodically, most recently in April 2026, following changes made by the UN Security Council, an agency's existing client book needs to be checked again every time the list changes, not just when a new client walks in. This is the step manual processes tend to quietly drop: nobody is watching the FIC's list update notices on a Tuesday afternoon, so existing files simply never get re-checked until an inspector asks for proof that they were.
A workable answer does not require anyone to monitor the FIC's website by hand. It requires a system that re-runs the existing client book against the list automatically whenever the list changes, and keeps a timestamped record that it did.
5Freeze first, ask questions never
If a client, director, trustee or beneficial owner does return a match, the obligation is immediate and absolute. The FIC's own guidance states it in stark terms: "Any person or entity is strictly prohibited from dealing with property that is associated with acts of terrorism, with persons or organisations that carry out acts of terrorism or with sanctioned persons." There is no waiting period, no discretion to complete the deal first and sort out the paperwork afterward. Once a positive match is identified, the property involved must be frozen and all business dealings with that client must cease immediately.
This is a materially higher bar than a normal risk-based decision. Client due diligence generally allows an agency to weigh risk and apply proportionate measures. A confirmed TFS match removes that discretion entirely.
6File the correct report, in the correct window
A confirmed match and a mere suspicion trigger two different reports, with two different deadlines, both filed through the FIC's goAML platform.
- Terrorist Property Report (section 28A): filed when a client, or property connected to a client, is a confirmed match against the sanctions list. Per FIC Guidance Note 6A, this must be filed without delay and no later than five days from becoming aware of the relevant property.
- Suspicious or Unusual Transaction Report (section 29): filed when facts give rise to a reasonable suspicion, without a confirmed sanctions match. Under section 29 the report must reach the FIC as soon as possible, and no later than 15 days, excluding Saturdays, Sundays and public holidays, from when the suspicion arose.
Confusing the two, or defaulting to the longer 15-day window when a five-day one applies, is itself a compliance failure. Knowing which report a given fact pattern calls for is as much a part of the obligation as knowing that a report is needed at all.
WHAT NON-COMPLIANCE CAN COST
Under section 45C(3) of the FIC Act, the maximum administrative sanction the FIC can impose is a financial penalty of up to R10 million for a natural person and up to R50 million for a legal person, alongside cautions, reprimands, directives for remedial action, or restrictions on business activities. The Capital Point Properties case shows sanctions well below that ceiling still run into hundreds of thousands of rand for a single small agency.
7Keep a record that proves it happened
Every one of the obligations above shares a common failure mode: doing the work but being unable to prove, months or years later, that it was done, when it was done, and against which version of the list. Capital Point Properties did not fail because sanctions screening is conceptually hard. It failed an inspection because the FIC could not see evidence that screening had happened in practice, as distinct from a policy document that said it should.
An audit-ready record for this obligation needs to show, for every client, the date each screen was run, which list version it was run against, the result, and, where a re-screen was triggered by a list update, the date of that update. A paper file with a signed checklist rarely survives this level of scrutiny intact.
8Make sure the person doing the screening knows the rules
In most agencies, the person capturing a new client's details is not the principal, and often is not the person who attended the last FICA refresher. Sanctions screening obligations only hold up in practice if whoever is onboarding a client, junior agent, admin support, or the principal themselves, understands that this step exists, runs it every time, and knows what to do if a name comes back flagged. A risk management and compliance programme that lives in a folder nobody has read since it was signed off is, in the FIC's own words in the Capital Point Properties matter, a programme that exists on paper and not in practice.
The FIC does not ask whether an agency meant to screen its client. It asks whether the screen happened, when it happened, and whether the agency can prove it within days of being asked, not weeks.
The five-minute version
If the detail above gets lost in a busy week, here is what actually has to happen, every time, for every client.
Sanctions screening, at a minimum
- Screen every buyer, seller, director, trustee and beneficial owner against the FIC's targeted financial sanctions list at onboarding
- Re-screen existing clients whenever the sanctions list is updated, not only when a new client is onboarded
- On a confirmed match, freeze the property and cease all dealings with that client immediately
- File a Terrorist Property Report within five days of a confirmed match, or a Suspicious or Unusual Transaction Report within 15 business days of a reasonable suspicion
- Keep a timestamped record of every screen run, its result, and the list version checked
None of this replaces the identity verification, beneficial ownership, and document-freshness work an agency already does under FICA. It sits alongside it, as a separate obligation with its own list, its own timing, and, as Capital Point Properties found out, its own enforcement risk if it exists only as a line item in a policy nobody actually runs.
Lucere screens every client, director, trustee and beneficial owner against Home Affairs and global sanctions and PEP watchlists automatically, re-checks them whenever those lists change, and timestamps every result into an immutable consent ledger, so the record an inspector asks for is already there, not something to reconstruct after the fact. You can see it running on a live file, with your own name and company, at the Lucere demo, no signup required, or look up any term above in the Lucere glossary.
Sell houses. We'll handle the FICA.
See how Lucere runs client due diligence for South African estate agencies, or look up a term in the compliance glossary.
Get started