Enterprise Risk Management

South Africa
Risk Playbook

Risk guidance written for SA's actual conditions — not imported from a London or New York template. Twin peaks regulation, grid instability, FATF greylisting, and a crime environment that makes standard BCP assumptions look naive.

9
Use case domains
3
Risk categories
SA
Jurisdiction
Q2
2025 edition
Governance & compliance

Regulatory alignment

SA's twin peaks model splits oversight between two regulators with different mandates and different temperaments. Building for one and hoping the other is satisfied is how enforcement actions happen.

SARB / PA / FSCA
Twin peaks framework
PA handles financial soundness; FSCA handles market conduct. They don't coordinate for you. Your risk appetite statement needs to speak to both, separately.
Information Regulator
POPIA data privacy
72-hour breach notification under Section 22. Cross-border transfer restrictions under Section 72. Most SA firms underestimate how many SaaS vendor contracts this touches.
FIC / FATF
FICA & AML controls
SA's 2023 FATF greylisting created real correspondent banking friction. Remediation is ongoing — beneficial ownership, DNFBP supervision, PEP screening. The CIPC register is live. KYC that ignores it is already out of date.

SARB / FSCA

  • Twin peaks in practice: PA and FSCA have different supervisory cultures. PA is capital-focused and process-driven. FSCA is outcomes-focused and increasingly assertive. Satisfy both — they will not reconcile differences on your behalf.
  • Operational resilience: SARB's 2023 guidance maps closely to DORA. If you've already done DORA work for EU-linked operations, you're most of the way there — but the SA version carries SA-specific BCP and third-party concentration expectations.
  • TCF: Treating Customers Fairly outcomes belong in the risk appetite statement, not buried in a compliance workplan. The FSCA will look for evidence it drives actual decisions.
  • Basel IV (banks only): Credit, market, and operational risk capital treatment under SARB Directive 11/2023. If your model predates 2023, revisit it.

POPIA

  • Information Officer: Registration with the Information Regulator is mandatory and enforceable. The IO needs to own POPIA risk in the second line — not sit in legal as a compliance formality.
  • Section 22 breach notification: 72 hours to the Information Regulator once a breach is confirmed. Most SA firms don't have a sub-plan for this. They have a POPIA policy and assume it's covered. It isn't.
  • Section 72 cross-border transfers: Every cloud-hosted SaaS tool used by SA staff potentially triggers this. Review vendor DPAs before signing, not after a breach.
  • PAIA overlap: POPIA and PAIA govern different things but share records management infrastructure. Running them as separate programmes creates gaps that are usually discovered during an incident, not before.

FICA / AML

  • FATF greylisting: SA was greylisted in 2023 — not as a technical failure but as a governance one. The remediation programme targets beneficial ownership transparency, supervision of DNFBPs, and PEP screening. Your AML controls need to show examiners you're operating at post-greylisting standards, not pre-2023 baselines.
  • FIC Act risk-based approach: Enhanced due diligence for high-risk clients is no longer optional. The expanded accountable institutions list caught several sectors that previously operated outside formal FICA scope.
  • CIPC beneficial ownership register: Live since 2023. KYC processes that don't reference it are already non-compliant in spirit.
  • Threats worth watching: Crypto asset fraud is growing fast. State capture recovery litigation has created a new category of sanctions and asset-tracing exposure. Syndicated fraud rings in the KZN logistics corridor remain active and technically sophisticated.
Try this: "Build a FICA AML risk framework for a SA financial services firm. Cover post-greylisting remediation, CIPC beneficial ownership, and the top three emerging fraud threats in the SA market."
Operational risk

Operational risk

Generic operational risk frameworks were built for stable electricity grids, manageable crime rates, and predictable labour relations. SA has none of those. Plan accordingly.

Eskom / grid
Load shedding & power risk
Stage 4+ should be treated as a declared incident by default. Most BI policies explicitly exclude it. Recalibrate RTOs assuming 4–12hr daily outages — the old targets are fiction.
SAPS / SABRIC
Crime & physical security
BEC fraud leads SA financial crime volumes per SABRIC data. July 2021 showed that looting scenarios aren't theoretical — BI cover and access controls both failed in real time.
LRA / CCMA
Labour & strike risk
The 48-hour LRA strike notice is your activation window. BCP that triggers at strike commencement is too late. Section 189 retrenchments need their own risk sub-plan — CCMA referral rates after botched processes are not small.

Load shedding

  • Stage triggers: Most SA firms have settled on Stage 4+ as their incident threshold. Below that, workarounds absorb the hit. Above it, the compounding effect — extended outages, generator fuel burn, staff availability — justifies formal activation.
  • Power backup tiers: Map processes to tiers before you buy generators. Cold chain, payment processing, and data centres need seamless failover. Administration and back-office can tolerate a few hours. Don't spend Tier 1 budget on Tier 3 problems.
  • RTO recalibration: RTOs written before 2019 assume grid availability that no longer exists. Treat 4–12hr daily disruption as the new baseline, not an exception scenario.
  • Transnet compound effect: Durban port and Transnet rail disruptions often track Eskom events. Supply chain BCPs that model only one fail when both hit simultaneously, which they do.
  • Insurance gap: Standard commercial BI and SASRIA policies name-exclude load shedding. Lloyd's-backed parametric products are entering the local market. If you haven't checked your exclusion clauses lately, check them now.

Crime & security

  • SAPS crime data: Quarterly SAPS statistics are public and granular enough to risk-score individual premises and logistics routes by province. Most firms don't use them. They should.
  • Cash-in-transit: Dual-control procedures and randomised route scheduling are non-negotiable minimums. Inside-job exposure is consistently underestimated — the risk sits inside the operation, not outside it.
  • BEC fraud: Payment re-routing and supplier impersonation account for the bulk of reported losses in SABRIC's annual data. The attack is usually simple: a compromised email, a convincing domain, a payment run. Controls at the payment authorisation step stop most of it.
  • Civil unrest: July 2021 cost the SA economy an estimated R50 billion. BI cover failed because policies excluded unrest. Access controls failed because they were designed for crime, not scale. Both need specific modelling — not a footnote in the main BCP.

Labour & strike risk

  • LRA notice window: 48 hours is not much time. BCP activation at notice — not at strike commencement — gives you a real response window. Most firms do it the other way around and spend the first day scrambling.
  • Section 189 retrenchments: The process is prescribed and the CCMA monitors compliance closely. Poorly run retrenchments generate referrals, bad press, and sometimes reinstatement orders. The reputational cost usually exceeds the legal cost.
  • Essential services designation: Certain operations in health, security, and energy are legally required to maintain minimum service levels during industrial action. If you're in scope, it needs to be in your plan, not discovered mid-strike.
  • Community unrest spillover: July 2021 began as a political protest and became a logistics shutdown. Labour disputes in resource-dependent regions carry the same escalation risk. Socioeconomic pressure indicators are worth monitoring as leading signals.
Try this: "Write a load shedding BCP for a SA logistics company with cold chain operations. Use Stage 4 as the activation threshold. Include generator tier mapping, Transnet compound risk, and the BI insurance gap."
Strategic & macro risk

Strategic & macro risk

SA's macro risks don't arrive one at a time. Rand volatility, FATF friction, and GNU policy uncertainty often move together. Scenario planning that treats them as independent events will miss the actual stress cases.

Geopolitical
SA macro & geopolitical risk
Sub-investment grade credit rating, FATF greylist, a coalition government with internal tensions on NHI and land reform, and regional operations exposed to Mozambique, DRC, and Zimbabwe. Model these together, not in isolation.
Reputational
Reputational risk in SA
Twitter/X SA punches well above its size. amaBhungane and Daily Maverick pursue stories that broadsheet media won't touch. B-BBEE fronting allegations travel fast and stick longer than most crises. Proactive is the only viable posture.
Insurance
SA insurance gaps
Load shedding is excluded. Cyber penetration is low. D&O policies often don't reflect Companies Act 71 liability exposure. SASRIA sub-limits were tested in 2021 and found wanting by many policyholders.

Geopolitical

  • Rand volatility: ZAR is one of the most traded EM currencies and one of the most volatile. Any business importing goods or servicing USD/EUR-denominated debt needs FX risk quantified in the financial risk register — not just noted.
  • FATF greylist + credit ratings: Moody's and S&P both rate SA below investment grade. The FATF greylisting adds correspondent banking friction on top. Some SA firms have already seen international payment delays. Model the scenario where this gets worse, not better.
  • GNU policy risk: The Government of National Unity is holding. For now. NHI, land reform, and energy sector policy are the three areas where coalition fracture would have direct business impact. These aren't fringe scenarios.
  • SADC exposure: Mozambique (LNG disruption, Cabo Delgado), DRC (minerals, logistics), Zimbabwe (currency, sanctions adjacency). Each carries different risk profiles. Map exposure by country and by dependency type — operations, supply, revenue, data.

Reputational risk

  • B-BBEE scrutiny: Fronting allegations don't need to be true to damage a brand — they need to trend. Proactive scorecard verification and public disclosure remove most of the attack surface. Waiting until an allegation surfaces is the wrong sequence.
  • Social media velocity: SA's Twitter/X user base is small by global standards but disproportionately influential with journalists, analysts, and policy audiences. A crisis that takes 48 hours to escalate in the UK can be at full boil in SA within six. Crisis timelines from the global playbook don't apply here.
  • Investigative media: Daily Maverick and amaBhungane publish work that would not make it into mainstream media. They're well-resourced, legally careful, and they finish what they start. If they're looking at something involving your organisation, assume the story will run. Engage legal and comms early.
  • ESG and just transition: International investors with SA exposure are asking harder questions about climate and labour practices than they were two years ago. Narrative control here is a risk management function. PR after the fact is expensive and usually ineffective.

Insurance gaps

  • Load shedding exclusion: This is explicit in most standard BI policies, not an ambiguity. The exclusion was tested in litigation post-2019 and held. Parametric products backed by Lloyd's syndicates are now available locally — they pay on grid event triggers rather than proven loss, which sidesteps the exclusion problem.
  • Cyber insurance: SA's cyber insurance penetration is low relative to the attack surface. The Experian breach (2020, 24 million records) and TransUnion breach (2022) set real cost benchmarks. If your cyber programme hasn't been sized against those incidents, it hasn't been sized.
  • D&O under Companies Act 71: Section 77 and 78 director liability is broader than most imported D&O policy templates account for. The SA-specific liability exposure — particularly around reckless trading and business rescue — needs explicit review of Side A, B, and C coverage limits.
  • SASRIA: State riot cover exists in SA specifically because private insurers won't write the risk. July 2021 showed both what SASRIA covers and where its sub-limits bite. Know your limits before the next event, not during it.
Try this: "Run a SA insurance gap analysis for a mid-size manufacturer with KZN operations. Cover load shedding BI exclusions, SASRIA sub-limits post-July 2021, cyber coverage versus actual attack surface, and D&O under Companies Act 71."
Reference

Risk scoring matrix

Standard 5×5 matrix. SA note: load shedding runs at likelihood 5 for most businesses. FATF-related correspondent banking disruption is likelihood 3–4. Civil unrest is likelihood 2 nationally but 4 in KZN and parts of Gauteng. Score for your actual geography.

Impact 1
Negligible
Impact 2
Low
Impact 3
Medium
Impact 4
High
Impact 5
Critical
Like. 5
Near certain
5
10
15
20
25
Like. 4
Likely
4
8
12
16
20
Like. 3
Possible
3
6
9
12
15
Like. 2
Unlikely
2
4
6
8
10
Like. 1
Remote
1
2
3
4
5
Low (1–4): Monitor Medium (5–9): Manage High (10–16): Treat Critical (17–25): Escalate immediately
Reference

Standards & regulatory map

International standards and SA-specific frameworks. Certification status matters: ISO 22301 and 27001 are auditable and defensible to regulators. King IV is apply-or-explain. COSO and NIST are reference frameworks — useful, but they don't create audit trails on their own.

Standard Domain Certifiable SA relevance
ISO 22301:2019 Business continuity (BCMS) Yes Directly mapped to SARB's 2023 operational resilience guidance. Certifying to 22301 is the most defensible way to demonstrate BCP maturity to the PA.
ISO 31000:2018 Enterprise risk management No (guidance) The standard SA ERM frameworks reference, but it's principles-only. You need a certifiable standard alongside it — 22301 or 27001 — to create actual audit evidence.
ISO 27001:2022 Information security (ISMS) Yes Provides structured, auditable evidence of information security controls — useful for POPIA compliance arguments, vendor due diligence, and cyber insurance underwriting.
POPIA Data privacy Regulatory Enforced by the Information Regulator. Section 22 breach notification and Section 72 cross-border transfer restrictions are the two most operationally demanding provisions for most businesses.
FICA / FIC Act AML / CFT Regulatory Post-greylisting obligations are tighter than many compliance programmes have caught up to. The 2023 FIC Act amendments expanded the accountable institutions list — check whether your sector is newly in scope.
Companies Act 71/2008 Director liability / governance Regulatory Section 77 and 78 personal liability for reckless trading and breach of fiduciary duty is broader than most imported D&O policy templates. SA-domiciled directors need SA-specific coverage review.
NIST CSF Cybersecurity No (framework) Widely used by SA financial services firms as an internal cyber risk reference. Useful for structuring security programmes, but produces no certification evidence. Pair it with ISO 27001 for regulatory credibility.
COSO ERM Enterprise risk No (framework) The framework JSE-listed boards most commonly cite in integrated reports. Strong on governance structure and risk culture; light on operational specifics. Used alongside ISO 31000, not instead of it.
King IV Corporate governance Apply or explain SA-specific and JSE-mandated on an apply-or-explain basis. Risk committee composition, integrated reporting, and stakeholder engagement obligations all flow from King IV. It is the governance layer everything else sits inside.
DORA (EU) Digital operational resilience Regulatory Only directly applicable to SA firms with EU-regulated operations or EU financial institution counterparties. That said, SARB's 2023 operational resilience guidance draws from it — firms that have done DORA gap analysis have a head start on the local equivalent.