NexBDM Blog
Client Onboarding Process: how to automate it and stop chasing the same documents
By NexBDM Team · 2026-08-10
Key takeaways
- An automated client onboarding process replaces the document chase with one structured request: one form, one upload of each file, and a system that chases what is missing on its own. What South African firms must collect under FICA and POPIA, what to automate, and what has to stay human.
An automated client onboarding process replaces the document chase with one structured request: one form, one upload of each file, and a system that chases what is missing on its own. What South African firms must collect under FICA and POPIA, what to automate, and what has to stay human.
An automated client onboarding process replaces the document chase with one structured request. The client fills a single form, uploads every file once, and the system stores each item against the record rather than in an inbox. Reminders fire on their own, and the next person to open the file finds everything already there.
That is the whole idea, and it is not a software problem. Most South African firms already own the tools that could do this. What they do not have is a decision about where the record lives, so every onboarding starts as a message and ends as a search.
Why the same documents get chased three times
Watch a normal onboarding closely and you will see the same failure repeat. Someone emails the client a list. The client replies with four of the seven items, two of them in the body of the message rather than as attachments. A second person picks the thread up a week later, cannot tell which items landed, and asks for all seven again. The client, who has now sent their company registration document twice, concludes that you are disorganised, and they are right.
The cause is structural, not personal. The request went out as a message, so the only record of what was asked is in one person's sent items. The answers came back as messages, so the only record of what arrived is in one person's inbox. Nothing in that loop knows what is outstanding, because nothing in that loop is a list of required items with a status against each one.
Every fix for this starts in the same place: the checklist has to stop being prose in an email and start being fields on a record. Once each required document is a field, three things become possible that were impossible before. The system can tell you what is missing without a human reading a thread. It can ask the client for exactly the missing items rather than the full list. And it can prove, later, what was collected and when.
What a South African client onboarding process actually has to collect
Before you automate the collection, be clear about what the law requires you to collect, because two statutes pull in opposite directions and most onboarding checklists only account for one of them.
The Financial Intelligence Centre Act pushes you to collect and keep. The Protection of Personal Information Act pushes you to collect less and keep it for less time. A good onboarding process satisfies both, and the way it does that is by being specific about purpose rather than collecting everything by default.
The correction most onboarding checklists get wrong
There is a persistent belief that FICA prescribes a fixed pack: certified identity document, proof of address, bank confirmation letter, for every client, every time. That has not been the position since the Financial Intelligence Centre Amendment Act 1 of 2017 moved customer due diligence from a rules-based model to a risk-based one.
Under the current regime an accountable institution applies due diligence proportionate to the risk it has assessed, and the standard it works to is its own Risk Management and Compliance Programme. Sections 21A to 21C, introduced by that Amendment Act, require you to understand the nature and intended purpose of the business relationship and the source of funds, and to keep client information current through ongoing due diligence. None of that is satisfied by a certified copy in a folder, and none of it is a single fixed list.
This matters for automation because a fixed list is easy to build and wrong, while a risk-tiered list is only slightly harder to build and correct. If your form asks every client for the same seven items, you are collecting more personal information than the purpose requires from your low risk clients, which is the exact thing section 10 of POPIA prohibits, and you are probably collecting too little from your high risk ones.
Two further points are worth knowing before you design the form.
First, the population of businesses this applies to grew. The schedules to FICA were amended with effect from 19 December 2022, published in Government Gazette 47596 on 29 November 2022, adding categories including credit providers as defined in the National Credit Act, high value goods dealers and company service providers to the list of accountable institutions. A number of firms became accountable institutions on that date without changing anything about what they do.
Second, the pressure is not going away because the country came off the grey list. The Financial Action Task Force removed South Africa from increased monitoring on 24 October 2025, at the end of the plenary held from 20 to 24 October 2025, thirty two months after the February 2023 listing. That removal was earned by addressing twenty two action items, and the domestic obligations that were strengthened to get there remain in force. Exiting the list changed the country's standing, not your file.
| Obligation | What it requires | What it means for the onboarding form |
|---|---|---|
| FICA sections 21 and 21A to 21C | Risk-based customer due diligence, understanding of the nature and purpose of the relationship and source of funds, ongoing due diligence | Tier the form. Ask risk questions first, then request only the documents that tier requires |
| FICA section 23 | Records of a business relationship kept for at least five years from the date the relationship is terminated, and of a transaction for five years from conclusion | The document has to live somewhere that will still exist in five years and be findable by client, not by date received |
| POPIA section 10 | Personal information must be adequate, relevant and not excessive for the purpose | Every field on the form needs a reason. If nobody can say why you collect it, delete the field |
| POPIA section 14 | Information may not be kept longer than necessary for the purpose, unless retention is authorised by law, required by contract or consented to | Record the retention basis at capture. FICA section 23 is that basis for the compliance pack, and it does not cover everything else you collected |
The practical consequence is that FICA and POPIA are not in conflict once you write the purpose down. POPIA section 14 expressly permits retention where the law authorises it, and FICA section 23 is that authorisation for the due diligence records. What POPIA does not permit is keeping the rest of the pack, the things you collected because the form asked for them and nobody could say why, for the same five years.
The five stages of an automated client onboarding process
Every workable version of this has the same five stages. The tooling varies. The stages do not.
| Stage | What happens | What must be true for it to be automatic |
|---|---|---|
| 1. Trigger | A deal is marked won, or a new client is created | One event, in one system, starts everything. Not a person remembering |
| 2. Request | The client receives one link to one form covering their risk tier | The required items exist as fields, not as sentences in an email |
| 3. Capture | Each upload is filed against the client record, tagged with what it is | Storage is keyed to the client, not to the message that carried the file |
| 4. Chase | Outstanding items only are re-requested, on a schedule, until complete | The system can compute what is missing without a human reading anything |
| 5. Handover | The complete file moves to the person doing the work, with a retention date set | Completeness is a state the record holds, not an opinion someone forms |
Stage four is where almost all of the recovered time sits, and it is the stage most firms skip when they automate. They build a nice form, send it once, and go back to chasing by hand the moment it comes back incomplete. It always comes back incomplete. The follow up is not the exception to the process, it is the process.
What to automate, and what must stay human
Automating the wrong half of onboarding produces a client experience that is worse than the manual version, because it is now impersonal and still slow. The split is not subtle once you look at it.
| Automate | Keep human |
|---|---|
| Sending the request and every follow up | The first conversation about what the client actually wants |
| Filing, naming and tagging what arrives | The risk decision that sets the tier |
| Computing what is still outstanding | Reading the documents and deciding whether they satisfy you |
| Setting the retention date at capture | Any conversation where the client is confused or unhappy |
| Notifying the delivery team when the file is complete | The welcome call |
Notice that everything in the left column is clerical and everything in the right column is judgement. That is the only test worth applying. If a competent person would reach the same answer every time without thinking about it, automate it. If two competent people could reasonably differ, a person decides.
How to build it without buying a new system
You almost certainly do not need new software. You need to move three things.
Move the checklist out of the email and onto the record. Whatever holds your client list, a CRM, a spreadsheet you have outgrown, the practice management system you already pay for, add one column per required document with three states: not requested, requested, received. This single change makes the status of every onboarding answerable in one glance, and it is the precondition for everything else. If you do not have a system that can hold this, a free CRM will do it on day one.
Move the request from a person to a form. One link, one form, tiered by the risk question you ask at the top of it. Uploads attach to the client record directly. The moment the client submits, the columns update themselves. What you have removed here is not typing, it is the interpretation step where a human decides which of the seven items actually arrived.
Move the chase from memory to a rule. A scheduled check runs against the columns, finds the records with anything still in the requested state, and sends that client a message naming only their outstanding items. Nobody reads a thread. Nobody remembers. The rule runs whether or not anyone is at their desk, which is why it also works over a long weekend.
Three specifics decide whether this holds up in practice. The document has to be captured once and reused everywhere it is needed, so the identity document collected at onboarding is the same object referenced later, not a second copy someone re-requested. Nothing gets re-keyed: if the client typed their registration number into the form, no person types it again into an invoice, a contract or a letter. And the reminder comes from the record's own state rather than from a diary entry, so it cannot drift out of sync with reality.
The same discipline is what makes invoicing automation work, and for the same reason. Both are cases of capturing a fact once and refusing to let anyone type it a second time.
What this looks like in a firm that has to hold a compliance pack
Take an agency or a professional services firm that has to hold due diligence records on every client. Before: the file opens, someone emails a list, the pack comes back in pieces across two weeks and three threads, and the certified copy that arrived on day one is in an inbox rather than a folder. Six months later a compliance question arrives and somebody spends an afternoon reconstructing what was collected.
After: the deal is marked won, the tiered form goes out inside the minute, uploads land against the client record as they arrive, the outstanding items chase themselves, and the file is marked complete by the system rather than by a person's judgement. The compliance question six months later is answered by opening the record. The reconstruction afternoon does not happen, because nothing was ever unstructured enough to need reconstructing.
Firms in regulated categories have a further reason to care about the last part. If you are subject to FICA obligations as an estate agency, the difference between a record you can produce and a thread you can search is the difference between a short conversation with a supervisory body and a long one.
Frequently Asked Questions
How long should a client onboarding process take?
Measure it from the day the client agrees to the day the file is complete, not from when you sent the form. Most of the elapsed time in a manual process is waiting for a follow up that nobody sent, which is precisely the part automation removes.
Do I need a CRM to automate client onboarding?
No, but you need something that can hold a status per document per client. A CRM is the natural home because it already holds the client record. A spreadsheet with a column per item works until the chase step, which is where a real system starts paying for itself.
What documents can I ask a South African client for at onboarding?
Ask for what the purpose requires. If you are an accountable institution under FICA, your Risk Management and Compliance Programme sets the standard and the requirement is risk-based rather than a fixed list. POPIA section 10 independently prohibits collecting more than is adequate and relevant for the purpose.
How long must onboarding documents be kept?
FICA section 23 requires records relating to a business relationship to be kept for at least five years from the date the relationship is terminated, and records of a transaction for five years from conclusion. POPIA section 14 permits that retention because it is authorised by law, but it does not extend the same permission to material you collected without a stated purpose.
Does exiting the FATF grey list reduce our onboarding obligations?
No. South Africa was removed from increased monitoring on 24 October 2025, but the removal reflected domestic reforms being implemented rather than repealed. The customer due diligence and record keeping duties in FICA are unchanged by it.
Sources
- Financial Intelligence Centre Act 38 of 2001, sections 21, 21A to 21C, 23 and 42, as amended.
- Financial Intelligence Centre Amendment Act 1 of 2017, introducing the risk-based customer due diligence regime and sections 21A to 21C.
- General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act 22 of 2022, and the amended FICA schedules published in Government Gazette 47596 of 29 November 2022, in force 19 December 2022.
- Protection of Personal Information Act 4 of 2013, section 10 (minimality) and section 14 (retention and restriction of records).
- Financial Intelligence Centre media release, South Africa exits the grey list, 24 October 2025, and National Treasury media statement of the same date, recording the FATF plenary of 20 to 24 October 2025 and the February 2023 listing.
This is a general guide to published legislation, not legal advice. Whether you are an accountable institution, and what your due diligence obligations are if you are, depends on your sector and your own risk assessment. Check your position against the Act and your supervisory body's guidance, or take advice, before acting on it.
Where this fits
Onboarding is where most of a client's data enters your business, which makes it the cheapest place to get the rest right. The identity and registration details captured here are the same ones your POPIA compliance checklist asks you to account for, the same ones that end up on a valid tax invoice, and the same ones a five year retention rule will still be holding long after the relationship ends. Collect them once and every downstream obligation gets easier. Collect them in an inbox and every one of them gets harder. The wider picture, in dependency order, sits in our South African small business compliance checklist, and the cost of leaving it manual is set out in the real cost of manual admin.
If nobody in your business can say, right now, which clients have an incomplete file, that is not an onboarding problem. It is an operations problem that onboarding happens to expose first. A business autopsy maps where your client data actually lives and what it would take to stop collecting it twice. You can also book a discovery call and talk it through first.