Tag: compliance
Africa’s white-collar crime – the cross-border risks?
White-collar crime in Africa is no longer a predominantly domestic concern. It has expanded onto an international stage, and so has the corporate exposure that comes with it. As capital crosses borders, data moves at the speed of light, and corporate structures become more complex, economic crime has kept pace. It has become more sophisticated, more multinational and increasingly difficult to investigate and prosecute within the confines of a single legal system.
CPA amendments – is your prospecting still compliant?
The recent amendments to the Consumer Protection Act 68 of 2008 (CPA) Regulations introduced a formal compliance framework for direct marketing in South Africa. The CPA Amendments took effect on 15 April 2026. For property practitioners who rely on cold-calling or other direct marketing methods, the rules have changed. These methods include SMS campaigns, neighbourhood canvassing, and outsourced lead-generation services.
Government procurement – is price still the deciding factor?
The Public Procurement Act 28 of 2024 is signed but not yet in force. However, the Constitutional Court is yet to rule on a challenge by the Western Cape Government, the City of Cape Town and amaBhungane. They argue that Parliament failed to facilitate reasonable public participation on material amendments, as required by section 59(1)(a) of the Constitution. That judgment is still pending.
Cybersecurity compliance demands faster patching
Regulatory compliance in cybersecurity is no longer an administrative chore that organisations can treat as an afterthought. As digital ecosystems expand, threat actors are leveraging automation, Artificial Intelligence (AI)-driven reconnaissance and supply-chain attack vectors. Consequently, governments are moving from advisory guidelines to enforceable directives.
SME cybersecurity – turning David’s compliance to a Goliath advantage
The enterprise Goliath is worried about its suppliers. These Small and Medium-sized Enterprises (SMEs) are underprepared. They are also disproportionately targeted. In fact, 43% of cyber-attacks target their digital front door. In addition, the Protection of Personal Information Act (POPIA) holds large organisations legally responsible when a supplier is breached.
Bad partnerships can break good businesses
South African businesses do not need to look far for a cautionary tale. The fallout from the Steinhoff scandal continues to reveal how weak governance, inadequate scrutiny of business relationships and unchecked transactions can destroy billions in shareholder value. What began as aggressive growth ultimately became one of the country’s most expensive lessons on the cost of insufficient oversight.
The 2026 National Water Amendment Bill – water rights explained
South Africa’s growing water insecurity has moved from an environmental concern to a central economic and regulatory challenge. Deteriorating infrastructure continues to worsen the situation. Recurring supply disruptions also place strain on national systems. In addition, unlawful water use increases pressure on already limited strategic water resources. These factors together strain the country’s water governance framework.
Skills development planning now impacts B-BBEE compliance
Skills development planning is no longer viewed as an administrative compliance exercise under South Africa's Broad-Based Black Economic Empowerment (B-BBEE) framework. Companies must now demonstrate clear alignment between training initiatives and measurable transformation outcomes. Skills development remains a priority element of the B-BBEE scorecard.
Boards are underestimating the AI agent risk
Artificial Intelligence (AI) is rapidly moving from experimentation to execution within South African organisations. Organisations increasingly embed AI agents across business functions, including finance, customer service, IT and operations. However, a significant governance concern is emerging.
Sustainability disclosure – why cybersecurity metrics also matter
Environmental, Social and Governance (ESG) discussions in South African boards generally default to carbon, community impact and governance process. While those remain essential, they do not tell the full story of organisational sustainability. A business may define sustainability narrowly. However, it still fails if it cannot protect data and recover quickly from cyber disruption in a digital economy.































