Directive 11 is live. SARS is chasing R44 billion in unpaid taxes from companies still holding state contracts. A cabinet minister just lost her job over undisclosed benefits. The regulatory environment in South Africa has shifted – not gradually, but all at once. The question isn’t whether your organisation is compliant. The question is whether you can prove it.

Most AI KYC vendors are selling the first part. Far fewer can help you with the second, and that distinction matters more than most procurement teams realise.

Compliance has a documentation problem, not just a detection one.

For years, “we have a system” was good enough. You ran due diligence checks, you onboarded customers, and as long as suspicious transaction reports were filed without triggering further investigation or regulatory scrutiny – the audit was largely a box-ticking exercise. The system existed. The paperwork existed. Nobody looked too hard at either.

That era is over. Directive 11 of 2026, issued by the Financial Intelligence Centre, doesn’t just ask accountable institutions whether they have AML and CTF controls. It requires a detailed Risk and Compliance Return: documented evidence of how those controls function, how risks are assessed, and how the programme is managed over time.