COMPLIANCE

Updated: August 15, 2026
Reading Time: 13 min

Legal compliance in South Africa is the process of ensuring an organisation’s activities, contracts and internal policies conform to applicable statutes, regulations and industry codes — chiefly the Companies Act 71 of 2008, the Protection of Personal Information Act 4 of 2013 (POPIA), the Financial Intelligence Centre Act 38 of 2001 (FICA), the National Credit Act 34 of 2005, the Consumer Protection Act 68 of 2008, the labour-law cluster (LRA, BCEA, EEA), and the sector-specific financial-services, tax and competition statutes — administered by national regulators including the Financial Sector Conduct Authority (FSCA), the Information Regulator, the Companies and Intellectual Property Commission (CIPC), the South African Revenue Service (SARS), the Competition Commission and the CCMA. Compliance is enforced through a layered regime of licence conditions, supervisory inspections, administrative penalties and (in serious cases) criminal prosecution, and the practical compliance cycle involves identifying the statutes that apply to a specific business, mapping obligations against existing policies and contracts, building monitoring and reporting structures around the King IV governance framework, and correcting breaches before they attract enforcement action.

What Legal Compliance Means

Compliance is the act of bringing an organisation’s conduct into line with the laws, regulations and codes that govern its activities. Internal policies and ethics codes sit on top of the statutory floor, but never substitute for it. Where the law prescribes a minimum standard (for example, the conditions for lawful processing of personal information under POPIA, or the director duties under sections 76 to 78 of the Companies Act), a softer internal rule cannot displace it.

Compliance is distinct from — but overlaps with — two related disciplines:

  • Corporate governance — the system of direction and control: board composition, committee charters, reporting lines and the audit committee’s role under the Companies Act.
  • Ethics — standards of conduct that may go beyond legal minimums, including voluntary codes of conduct and stakeholder commitments.

The King IV Code of Governance for South Africa treats governance as the umbrella under which compliance management and ethics sit as standing programmes, each feeding into the board’s oversight responsibilities.

Non-compliance carries three escalating risks:

  1. Regulatory penalty — administrative fines, licence suspensions, conditions on authorisation, and removal from registers (for example, removal of an authorised financial-services provider by the FSCA).
  2. Civil liability — claims by counterparties, consumer class actions under section 20 of the Consumer Protection Act, and damages claims by data subjects whose personal information was unlawfully processed.
  3. Criminal exposure — for senior office-bearers in serious cases under statutes such as the Financial Markets Act, FICA, and section 89 of POPIA.

The South African Statutory Stack

The SA compliance framework is layered rather than housed in a single code. The statutes below are the most frequently encountered across commercial practice.

Statute Core compliance obligations Primary regulator
Companies Act 71 of 2008 Registration with CIPC, maintenance of company records, director duties (sections 76–78), financial reporting, annual returns and beneficial-ownership filings. CIPC
Protection of Personal Information Act 4 of 2013 (POPIA) Conditions for lawful processing of personal information, designation of an Information Officer, publication of a privacy policy, internal complaint mechanisms. Information Regulator
Financial Intelligence Centre Act 38 of 2001 (FICA) Customer due diligence, record-keeping, suspicious-transaction reporting, registration of accountable institutions with the FIC. Financial Intelligence Centre (FIC)
Financial Sector Regulation Act 9 of 2017 Twin Peaks architecture: FSCA (market conduct) and Prudential Authority (prudential soundness); licensing and supervisory baseline for financial-services firms. FSCA and Prudential Authority (SARB)
National Credit Act 34 of 2005 Credit-provider registration, conduct standards, affordability assessments. National Credit Regulator
Consumer Protection Act 68 of 2008 Consumer rights, supplier duties, marketing standards, fairness in consumer contracts. National Consumer Commission and Consumer Tribunal
Labour Relations Act 66 of 1995, Basic Conditions of Employment Act 75 of 1997, Employment Equity Act 55 of 1998 Collective bargaining, unfair dismissal, BCEA substantive protections, employment equity planning and reporting. CCMA, Labour Court, Department of Employment and Labour
Competition Act 89 of 1998 Prohibition of restrictive practices and abuse of dominance, mandatory merger notification above prescribed thresholds. Competition Commission, Competition Tribunal, Competition Appeal Court
Tax Administration Act 28 of 2011 SARS procedural framework for assessments, returns, audits, disputes and recovery; section 26 third-party reporting; section 46 information requests. SARS

Who Enforces It: SA’s Regulator Landscape

Compliance obligations are not self-executing. Each statute is administered by a national regulator with the power to inspect, investigate, sanction and (in serious cases) refer matters for criminal prosecution.

  • CIPC — registers companies, records beneficial-ownership filings, processes director changes, receives annual returns, and monitors compliance with the Companies Act’s public-interest score reporting for large companies.
  • FSCA and the Prudential Authority — together constitute the Twin Peaks model. The FSCA supervises market conduct (financial-adviser licensing, collective investment scheme conduct, complaints against licensed entities). The Prudential Authority, a division of the South African Reserve Bank, supervises the financial soundness of banks, insurers and certain retirement funds under the Financial Sector Regulation Act 9 of 2017.
  • Information Regulator — receives POPIA complaints, adjudicates them, and may issue enforcement notices. Non-compliance penalties under section 89 of POPIA reach the higher of R10 million or 10% of annual turnover, with separate criminal exposure for obstruction offences.
  • Competition Commission and Competition Tribunal — investigate restrictive practices and abuse of dominance, and adjudicate merger notifications. The Competition Appeal Court hears appeals from the Tribunal.
  • SARS — administers tax compliance (income tax, VAT, PAYE, customs) and increasingly acts as the reporting counterparty for third-party data under section 26 of the Tax Administration Act.
  • CCMA and Labour Court — the CCMA is the conciliation and arbitration forum for most employment-relationship disputes, with the Labour Court adjudicating more serious matters and reviews.
  • National Credit Regulator and National Consumer Commission — supervise conduct under the NCA and enforce the CPA respectively, with the Consumer Tribunal imposing remedies under the CPA.
  • Financial Intelligence Centre (FIC) — receives suspicious-transaction reports and cash-threshold reports, and supervises FICA compliance by accountable institutions.

The Governance Frame Around Compliance

Compliance does not sit in isolation from the boardroom. The King IV Code of Governance for South Africa applies on an apply-and-explain basis to all entities (not only JSE-listed companies) and recognises compliance management as one of the standing governance disciplines reporting into the board, alongside risk management and ethics.

Board-level accountability cannot be delegated. Directors carry personal responsibility under section 76 of the Companies Act (duty of care, skill and diligence) and section 77 (indemnity and the business judgement defence) for the legal compliance of the company they govern. The board may delegate operational compliance tasks to management, but it cannot delegate ultimate accountability for the compliance programme.

Most regulated entities appoint a designated Compliance Officer. For FICA-accountable institutions, the appointment is statutory under section 42 of the Financial Intelligence Centre Act, with prescribed reporting duties to the Financial Intelligence Centre. For other entities, the appointment is a governance practice under King IV rather than a statutory mandate, although the trend in larger organisations is to combine the Compliance Officer role with the Company Secretary function.

The audit committee and external auditor interact with compliance through their financial-statement opinion under the Companies Act and the Auditing Profession Act — providing an independent check on whether the financial side of the compliance programme is operating effectively.

The Compliance Cycle in Practice

A working compliance programme follows a recurring six-step cycle. Each step produces a record that the next step builds on.

  1. Scope — identify the statutes that apply to the business, starting with the Companies Act baseline and layering on sectoral regimes (FSCA, NCA, FICA, CPA) where triggered by the entity’s activities.
  2. Map — translate each statutory obligation into a specific policy, control, contract clause or reporting task, with a named owner inside the organisation.
  3. Implement — embed the controls into day-to-day operations: training, system rules, screening checks, supplier due diligence, and customer onboarding under FICA.
  4. Monitor — internal audits, compliance reviews, key-risk and key-control indicators, and management reporting into the audit committee and board on a defined cadence.
  5. Report — file the required returns and notifications with each regulator on time (annual returns to CIPC, suspicious-transaction reports to the FIC, tax returns to SARS, the POPIA section 51 manual as required).
  6. React — manage regulator queries, investigations and complaints; respond to information notices and section 7 notices under FICA, and to information requests issued under SARS’s section 46 of the Tax Administration Act.

Common Failures and How They Show Up

Most compliance failures in practice are not exotic — they are recurring, predictable gaps. The table below pairs the gap with the statute it most often engages.

Failure mode Typical manifestation Statute most often engaged
Filing lapses Late annual returns; missing beneficial-ownership filings; outstanding FICA returns on trigger of a threshold client-event. Companies Act / FICA
Documentation gaps Supplier contracts missing POPIA processing clauses; employment contracts missing BCEA substantive protections; consumer-facing T&Cs missing CPA fairness disclosures. POPIA / BCEA / CPA
Training and record-keeping lapses FICA-accountable institutions failing to demonstrate ongoing employee training and a current risk-management compliance programme. FICA
Sector-licensing failures Acting as a credit provider, financial adviser or estate agent without the required NCA / FAIS / FIC registration. NCA / FAIS / FICA
Merger-notification lapses Implementing a transaction that exceeds the Competition Commission’s prescribed thresholds without prior notification. Competition Act 89 of 1998

When to Bring in a Compliance Attorney

Compliance work crosses statute lines, and the cost of a missed step is rarely reversible. Legal assistance tends to deliver the most value at the points below.

  • A regulator has issued a notice, information request or summons under any of the governing statutes.
  • A contract review is required to align a business’s standard terms with POPIA, the CPA, FICA’s accountable-institution obligations, or the National Credit Act’s conduct standards.
  • A company is structuring its governance and needs advice on King IV-aligned committee charters, the appointment of a Compliance Officer, or the FICA section 42 appointment.
  • A dispute is on the horizon — for example an alleged restrictive practice, a complaint to the Information Regulator, or class-action exposure under the CPA.
  • A transaction triggers merger notification to the Competition Commission or raises FICA / POPIA / exchange-control / sanctions questions.

This is precisely the cross-statute work Burger Huyser Attorneys’ commercial and contracts practice is set up to handle, supported by the firm’s general litigation team where a dispute has already crystallised.

The Gauteng Enforcement Geography

Most of the major SA regulators maintain operational headquarters in the Gauteng region: the FSCA and the Prudential Authority are both seated in Pretoria, CIPC operates its public-facing and case-handling operations out of its Pretoria and Johannesburg offices, and the Competition Commission’s case-handling teams work out of Pretoria with hearing support in Cape Town. Practically, that means Gauteng-based businesses face regulator queries, on-site inspections and enforcement-notice responses inside the same metropolitan footprint where their day-to-day operations sit — physical access to regulator offices for filing or for in-person hearings on investigations is a recurring compliance task rather than a once-off.

Burger Huyser Attorneys services Gauteng clients across this enforcement geography from its head office at 49 First Avenue, Linden, Randburg (011 888 0246) and its branches in Bedfordview, Sandton, Roodepoort, Centurion, Pretoria (Menlyn), Midrand, Alberton and the Randfontein-based Debt Collection Department. The firm’s commercial and contracts practice, supported by its general litigation team, is the natural intake point for compliance work that crosses statute lines — contract-aligned POPIA clauses, FICA-aligned onboarding documents, NCA-compliant credit agreements, and Companies Act governance reviews.

Frequently Asked Questions

Is legal compliance the same as corporate governance?

No. Corporate governance is the broader system of directing and controlling an entity — the board, committees and reporting lines, including the audit committee’s role under the Companies Act. Compliance is one of the standing programmes under that governance umbrella, alongside risk management and ethics. King IV recognises compliance management as a distinct discipline that feeds into governance rather than being identical to it.

What is the role of a Compliance Officer in South Africa?

A Compliance Officer identifies the statutes that apply to the business, translates them into policies and controls, monitors adherence, reports to the board (typically through the audit committee), and engages with regulators when questions arise. For FICA-accountable institutions, the appointment is statutory under section 42 of the Financial Intelligence Centre Act and carries prescribed reporting duties to the Financial Intelligence Centre. For other entities the appointment is a governance practice under King IV rather than a statutory mandate.

What is the difference between the FSCA and the Prudential Authority?

The Financial Sector Conduct Authority (FSCA) supervises how financial-services firms treat customers — market-conduct standards, financial-adviser licensing, collective investment scheme conduct, and complaints against licensed entities. The Prudential Authority, a division of the South African Reserve Bank, supervises the financial soundness of banks, insurers and certain retirement funds under the Financial Sector Regulation Act 9 of 2017. Together they form the Twin Peaks model introduced by that Act.

What are the penalties for non-compliance with POPIA?

The Information Regulator may issue enforcement notices, refer matters to the Enforcement Committee, and impose administrative fines up to the higher of R10 million or 10% of annual turnover under section 89 of POPIA, with separate criminal exposure for obstruction offences under section 103 of the Act. Practical exposure usually starts before the fine: a POPIA complaint that escalates can trigger a regulator audit, demand remediation steps and require the organisation to re-engineer some of its data-processing operations.

When does a business need to register as an accountable institution under FICA?

FICA schedules the accountable-institution category to include banks, life insurers, attorneys (under specific practice conditions), estate agents, gambling businesses, dealers in precious metals and stones, currency exchanges, money remitters, motor-vehicle dealers, trust companies and a range of other listed categories. A business that falls into one of those categories must register with the Financial Intelligence Centre, appoint a Compliance Officer under section 42, and run customer due diligence, record-keeping and suspicious-transaction reporting programmes as a standing compliance function rather than a once-off task.

When must the Competition Commission be notified of a merger?

Mandatory notification thresholds under the Competition Act are set by the Minister from time to time and are typically expressed in turnover or asset-value terms — at present an intermediate merger must be notified where combined turnover or assets reach R1 billion and the target firm reaches R200 million, and a large merger where combined turnover or assets reach R9.5 billion and the target firm reaches R280 million. Mergers that exceed the prescribed threshold must be notified before implementation, and failing to notify is itself a breach that may invalidate the transaction.

General Information Disclaimer: This article describes the general framework of legal compliance in South Africa as administered through the principal national statutes and regulators. It is general information, not legal advice for a specific business. Entities should confirm the application of each statute to their facts, check current filing deadlines with the relevant regulator, and consult a qualified attorney about any actual notice, complaint or proposed transaction before relying on the summary above.

Burger Huyser Attorneys’ commercial and contracts practice supports Gauteng-based businesses with POPIA-aligned contract clauses, FICA-compliant onboarding documents, NCA-aligned credit agreements, Companies Act governance reviews, and the response to regulator queries — supported by the firm’s general litigation practice where a dispute has already crystallised. The head office in Linden, Randburg (011 888 0246) is the first point of contact for cross-statute compliance work; specific sector questions can also be routed through the Pretoria (012 471 5700), Sandton (011 253 3080), Bedfordview (011 201 7190), Centurion (012 644 4990), Midrand (010 022 4082), Roodepoort (011 668 0030) and Alberton (011 439 3990) branches. The firm carries a 4.8/5 average across 250+ Google reviews (Trustindex verified “Top Rated Law Firm in South Africa”) and has been recognised as Commercial Law Firm of the Year 2025 (5 Star Lawyers Awards) and Best Multi-Sector Law Firm 2023 (Acquisition International).

NEED TOP LEGAL SUPPORT IN SOUTH AFRICA? CONTACT OUR LAWYERS TODAY.

Contact our team of experienced law attorneys at Burger Huyser Attorneys to assist you in all matters and procedures.

CONTACT DETAILS

DISCIPLINARY HEARINGS