Regulatory alignment
SA's twin peaks model splits oversight between two regulators with different mandates and different temperaments. Building for one and hoping the other is satisfied is how enforcement actions happen.
SARB / FSCA
- Twin peaks in practice: PA and FSCA have different supervisory cultures. PA is capital-focused and process-driven. FSCA is outcomes-focused and increasingly assertive. Satisfy both — they will not reconcile differences on your behalf.
- Operational resilience: SARB's 2023 guidance maps closely to DORA. If you've already done DORA work for EU-linked operations, you're most of the way there — but the SA version carries SA-specific BCP and third-party concentration expectations.
- TCF: Treating Customers Fairly outcomes belong in the risk appetite statement, not buried in a compliance workplan. The FSCA will look for evidence it drives actual decisions.
- Basel IV (banks only): Credit, market, and operational risk capital treatment under SARB Directive 11/2023. If your model predates 2023, revisit it.
POPIA
- Information Officer: Registration with the Information Regulator is mandatory and enforceable. The IO needs to own POPIA risk in the second line — not sit in legal as a compliance formality.
- Section 22 breach notification: 72 hours to the Information Regulator once a breach is confirmed. Most SA firms don't have a sub-plan for this. They have a POPIA policy and assume it's covered. It isn't.
- Section 72 cross-border transfers: Every cloud-hosted SaaS tool used by SA staff potentially triggers this. Review vendor DPAs before signing, not after a breach.
- PAIA overlap: POPIA and PAIA govern different things but share records management infrastructure. Running them as separate programmes creates gaps that are usually discovered during an incident, not before.
FICA / AML
- FATF greylisting: SA was greylisted in 2023 — not as a technical failure but as a governance one. The remediation programme targets beneficial ownership transparency, supervision of DNFBPs, and PEP screening. Your AML controls need to show examiners you're operating at post-greylisting standards, not pre-2023 baselines.
- FIC Act risk-based approach: Enhanced due diligence for high-risk clients is no longer optional. The expanded accountable institutions list caught several sectors that previously operated outside formal FICA scope.
- CIPC beneficial ownership register: Live since 2023. KYC processes that don't reference it are already non-compliant in spirit.
- Threats worth watching: Crypto asset fraud is growing fast. State capture recovery litigation has created a new category of sanctions and asset-tracing exposure. Syndicated fraud rings in the KZN logistics corridor remain active and technically sophisticated.
Operational risk
Generic operational risk frameworks were built for stable electricity grids, manageable crime rates, and predictable labour relations. SA has none of those. Plan accordingly.
Load shedding
- Stage triggers: Most SA firms have settled on Stage 4+ as their incident threshold. Below that, workarounds absorb the hit. Above it, the compounding effect — extended outages, generator fuel burn, staff availability — justifies formal activation.
- Power backup tiers: Map processes to tiers before you buy generators. Cold chain, payment processing, and data centres need seamless failover. Administration and back-office can tolerate a few hours. Don't spend Tier 1 budget on Tier 3 problems.
- RTO recalibration: RTOs written before 2019 assume grid availability that no longer exists. Treat 4–12hr daily disruption as the new baseline, not an exception scenario.
- Transnet compound effect: Durban port and Transnet rail disruptions often track Eskom events. Supply chain BCPs that model only one fail when both hit simultaneously, which they do.
- Insurance gap: Standard commercial BI and SASRIA policies name-exclude load shedding. Lloyd's-backed parametric products are entering the local market. If you haven't checked your exclusion clauses lately, check them now.
Crime & security
- SAPS crime data: Quarterly SAPS statistics are public and granular enough to risk-score individual premises and logistics routes by province. Most firms don't use them. They should.
- Cash-in-transit: Dual-control procedures and randomised route scheduling are non-negotiable minimums. Inside-job exposure is consistently underestimated — the risk sits inside the operation, not outside it.
- BEC fraud: Payment re-routing and supplier impersonation account for the bulk of reported losses in SABRIC's annual data. The attack is usually simple: a compromised email, a convincing domain, a payment run. Controls at the payment authorisation step stop most of it.
- Civil unrest: July 2021 cost the SA economy an estimated R50 billion. BI cover failed because policies excluded unrest. Access controls failed because they were designed for crime, not scale. Both need specific modelling — not a footnote in the main BCP.
Labour & strike risk
- LRA notice window: 48 hours is not much time. BCP activation at notice — not at strike commencement — gives you a real response window. Most firms do it the other way around and spend the first day scrambling.
- Section 189 retrenchments: The process is prescribed and the CCMA monitors compliance closely. Poorly run retrenchments generate referrals, bad press, and sometimes reinstatement orders. The reputational cost usually exceeds the legal cost.
- Essential services designation: Certain operations in health, security, and energy are legally required to maintain minimum service levels during industrial action. If you're in scope, it needs to be in your plan, not discovered mid-strike.
- Community unrest spillover: July 2021 began as a political protest and became a logistics shutdown. Labour disputes in resource-dependent regions carry the same escalation risk. Socioeconomic pressure indicators are worth monitoring as leading signals.
Strategic & macro risk
SA's macro risks don't arrive one at a time. Rand volatility, FATF friction, and GNU policy uncertainty often move together. Scenario planning that treats them as independent events will miss the actual stress cases.
Geopolitical
- Rand volatility: ZAR is one of the most traded EM currencies and one of the most volatile. Any business importing goods or servicing USD/EUR-denominated debt needs FX risk quantified in the financial risk register — not just noted.
- FATF greylist + credit ratings: Moody's and S&P both rate SA below investment grade. The FATF greylisting adds correspondent banking friction on top. Some SA firms have already seen international payment delays. Model the scenario where this gets worse, not better.
- GNU policy risk: The Government of National Unity is holding. For now. NHI, land reform, and energy sector policy are the three areas where coalition fracture would have direct business impact. These aren't fringe scenarios.
- SADC exposure: Mozambique (LNG disruption, Cabo Delgado), DRC (minerals, logistics), Zimbabwe (currency, sanctions adjacency). Each carries different risk profiles. Map exposure by country and by dependency type — operations, supply, revenue, data.
Reputational risk
- B-BBEE scrutiny: Fronting allegations don't need to be true to damage a brand — they need to trend. Proactive scorecard verification and public disclosure remove most of the attack surface. Waiting until an allegation surfaces is the wrong sequence.
- Social media velocity: SA's Twitter/X user base is small by global standards but disproportionately influential with journalists, analysts, and policy audiences. A crisis that takes 48 hours to escalate in the UK can be at full boil in SA within six. Crisis timelines from the global playbook don't apply here.
- Investigative media: Daily Maverick and amaBhungane publish work that would not make it into mainstream media. They're well-resourced, legally careful, and they finish what they start. If they're looking at something involving your organisation, assume the story will run. Engage legal and comms early.
- ESG and just transition: International investors with SA exposure are asking harder questions about climate and labour practices than they were two years ago. Narrative control here is a risk management function. PR after the fact is expensive and usually ineffective.
Insurance gaps
- Load shedding exclusion: This is explicit in most standard BI policies, not an ambiguity. The exclusion was tested in litigation post-2019 and held. Parametric products backed by Lloyd's syndicates are now available locally — they pay on grid event triggers rather than proven loss, which sidesteps the exclusion problem.
- Cyber insurance: SA's cyber insurance penetration is low relative to the attack surface. The Experian breach (2020, 24 million records) and TransUnion breach (2022) set real cost benchmarks. If your cyber programme hasn't been sized against those incidents, it hasn't been sized.
- D&O under Companies Act 71: Section 77 and 78 director liability is broader than most imported D&O policy templates account for. The SA-specific liability exposure — particularly around reckless trading and business rescue — needs explicit review of Side A, B, and C coverage limits.
- SASRIA: State riot cover exists in SA specifically because private insurers won't write the risk. July 2021 showed both what SASRIA covers and where its sub-limits bite. Know your limits before the next event, not during it.
Risk scoring matrix
Standard 5×5 matrix. SA note: load shedding runs at likelihood 5 for most businesses. FATF-related correspondent banking disruption is likelihood 3–4. Civil unrest is likelihood 2 nationally but 4 in KZN and parts of Gauteng. Score for your actual geography.
Negligible
Low
Medium
High
Critical
Near certain
Likely
Possible
Unlikely
Remote
Standards & regulatory map
International standards and SA-specific frameworks. Certification status matters: ISO 22301 and 27001 are auditable and defensible to regulators. King IV is apply-or-explain. COSO and NIST are reference frameworks — useful, but they don't create audit trails on their own.
| Standard | Domain | Certifiable | SA relevance |
|---|---|---|---|
| ISO 22301:2019 | Business continuity (BCMS) | Yes | Directly mapped to SARB's 2023 operational resilience guidance. Certifying to 22301 is the most defensible way to demonstrate BCP maturity to the PA. |
| ISO 31000:2018 | Enterprise risk management | No (guidance) | The standard SA ERM frameworks reference, but it's principles-only. You need a certifiable standard alongside it — 22301 or 27001 — to create actual audit evidence. |
| ISO 27001:2022 | Information security (ISMS) | Yes | Provides structured, auditable evidence of information security controls — useful for POPIA compliance arguments, vendor due diligence, and cyber insurance underwriting. |
| POPIA | Data privacy | Regulatory | Enforced by the Information Regulator. Section 22 breach notification and Section 72 cross-border transfer restrictions are the two most operationally demanding provisions for most businesses. |
| FICA / FIC Act | AML / CFT | Regulatory | Post-greylisting obligations are tighter than many compliance programmes have caught up to. The 2023 FIC Act amendments expanded the accountable institutions list — check whether your sector is newly in scope. |
| Companies Act 71/2008 | Director liability / governance | Regulatory | Section 77 and 78 personal liability for reckless trading and breach of fiduciary duty is broader than most imported D&O policy templates. SA-domiciled directors need SA-specific coverage review. |
| NIST CSF | Cybersecurity | No (framework) | Widely used by SA financial services firms as an internal cyber risk reference. Useful for structuring security programmes, but produces no certification evidence. Pair it with ISO 27001 for regulatory credibility. |
| COSO ERM | Enterprise risk | No (framework) | The framework JSE-listed boards most commonly cite in integrated reports. Strong on governance structure and risk culture; light on operational specifics. Used alongside ISO 31000, not instead of it. |
| King IV | Corporate governance | Apply or explain | SA-specific and JSE-mandated on an apply-or-explain basis. Risk committee composition, integrated reporting, and stakeholder engagement obligations all flow from King IV. It is the governance layer everything else sits inside. |
| DORA (EU) | Digital operational resilience | Regulatory | Only directly applicable to SA firms with EU-regulated operations or EU financial institution counterparties. That said, SARB's 2023 operational resilience guidance draws from it — firms that have done DORA gap analysis have a head start on the local equivalent. |