Start with a risk-based AML programme that fits the business model, then apply customer due diligence at onboarding and throughout the relationship. Regulated entities should verify identities, screen for sanctions and adverse media, keep records, appoint a compliance officer, and train staff. The strongest programmes connect governance, monitoring, and reporting so compliance is routine rather than reactive.
What a Practical FICA Programme Has to Do
A workable FICA programme is not a policy binder, it is a business process that consistently identifies customers, verifies them to an appropriate standard, understands who ultimately owns or controls the relationship, and monitors activity for anomalies. The programme should be scaled to the institution’s products, delivery channels, customer types, and risk appetite, so the controls are proportionate rather than generic.
The practical test is whether the programme can be executed the same way by frontline teams, operations, and compliance without improvisation. That means clear onboarding rules, standard evidence requirements, escalation paths for exceptions, and documented review points when customer risk changes. It also means the organisation can prove what it did later, not just say it had a process.
For the control baseline, regulated businesses should anchor their internal standards to recognised information security and AML references, especially ISO/IEC 27001:2022 Information Security Management for governance discipline and FATF Recommendations, the AML and KYC framework for customer due diligence, beneficial ownership, and suspicious activity handling.
When the business model includes digital onboarding, delegated onboarding, or higher-volume customer intake, the verification standard must be explicit enough to resist weak manual judgment. A practical FICA programme defines which identities must be verified, which documents or electronic checks are acceptable, when enhanced due diligence is required, and what conditions stop onboarding until review is complete.
Regulated businesses should also treat recordkeeping as part of the control, not an admin afterthought. If the firm cannot show why a customer was accepted, what screening was run, what ownership information was collected, and when the file was reviewed, then the programme may look compliant on paper while remaining weak in practice.
Building the Operating Model Around Risk, Not Forms
The most effective programmes start with customer and product risk segmentation. Retail customers, corporate structures, intermediaries, cash-intensive businesses, cross-border activity, and politically exposed persons do not justify the same level of scrutiny, and a one-size-fits-all process usually creates either blind spots or unnecessary friction.
Risk-based design also helps resolve the common tension between compliance quality and customer experience. Low-risk relationships can often move through a streamlined path with standard checks, while higher-risk customers trigger enhanced due diligence, more frequent review, and stronger ownership verification. That keeps the programme defensible without forcing every case into the slowest workflow.
Independent governance matters as much as the checklists. Regulatory and audit perspectives on governance and audit trails are a useful reminder that strong programmes are measurable, reviewable, and owned, not scattered across inboxes and spreadsheets. Screening, approval, exception handling, and monitoring should each have a named owner and an auditable trail.
Where the programme is run through multiple systems or business lines, consistency becomes the real control issue. The firm needs the same risk logic, the same evidence thresholds, and the same escalation criteria across channels, otherwise weak treatment in one channel can undermine the whole control environment.
Monitoring, Reporting, and Practitioner Judgement
A practical FICA programme only works if customer due diligence continues after onboarding. Transaction monitoring, trigger events, periodic reviews, sanctions screening, and adverse media checks should all feed back into the customer file so risk ratings stay current and suspicious patterns are not treated as isolated anomalies.
Practitioners often underestimate the importance of timely remediation. A customer record that is outdated, an unresolved screening alert, or a missed beneficial ownership change can quickly become a governance problem because the business is then relying on stale assumptions about who it is dealing with and what level of risk it is carrying.
Monitoring and reporting should also be designed for decision quality. ISO/IEC 27002:2022 Information Security Controls supports the operational discipline behind access review, logging, and control implementation, while Cloud Compliance Pulse 2025 is a useful internal reference point for how access governance and auditability support repeatable compliance operations.
Practitioner takeaway: The strongest FICA programmes are built to make good decisions repeatable, because the real test is not whether the firm has controls, but whether it can consistently verify, monitor, escalate, and evidence them at scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | FICA programmes need controlled access to customer records, screening data, and approval workflows. |
| A.5.34 — Privacy and protection of PII | FICA processes collect sensitive identity and ownership data that requires protection and governance. | |
| A.5.24 — Information security incident management planning and preparation | Compliance programmes need escalation paths and evidence-preserving response when screening or review fails. | |
| Recommendation — Restrict access to customer due diligence records and approval functions to authorised staff. Protect identity evidence and customer files with strong handling rules and retention controls. Prepare escalation and evidence-preservation steps for failed checks, false positives, and exceptions. | ||
Related resources from NHI Mgmt Group
- How should crypto service providers in South Africa structure their AML and Travel Rule compliance programme?
- How should organisations operating in Quebec build a practical Law 25 compliance programme?
- How should financial institutions build a GLBA compliance program that actually reduces third-party risk?
- Why does an IGA-only model increase audit and compliance risk for regulated teams?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org