South Africa has no single risk management law. Your risk management requirements depend on what your organisation is: the Companies Act sets a standard of care for directors, the Financial Intelligence Centre Act (FICA) requires a risk management and compliance programme from accountable institutions, POPIA requires security safeguards for personal information, and the Occupational Health and Safety Act (OHSA) requires employers to provide a safe working environment.
The practical question is which of these bind you. Establish that first, then document and apply the measures each one requires.
Business Requirements at a Glance
The legal sources, and who they apply to:
- Directors of companies: act in good faith and with the care, skill and diligence reasonably expected, under section 76 of the Companies Act, 2008.
- Accountable institutions: a documented risk management and compliance programme under section 42 of the FIC Act.
- Responsible parties handling personal information: security safeguards and breach notification under sections 19 and 22 of POPIA.
- Employers: a working environment that is safe and without risk to health, as far as reasonably practicable, under section 8 of the OHS Act.
- Regulated sectors: your sector regulator may add its own requirements.
Registration and Legal Requirements
Nothing here is a registration. The baseline for any company is the directors’ duty in section 76(3) of the Companies Act: act in good faith, for a proper purpose and in the company’s best interests, with the care, skill and diligence reasonably expected of a person with the same functions and with that director’s own knowledge, skill and experience.
Directors are jointly and severally liable for loss, damage or costs caused by breaching these duties. Proceedings generally may not start more than three years after the act or omission, although a court may extend that on good cause (section 77).
The King Code on corporate governance is issued by the Institute of Directors in South Africa. Whether it is mandatory for you depends on whether you are listed, so check the JSE Listings Requirements and the Institute if that applies to you.
Documents and Ownership Information Required
FICA applies only to accountable institutions. An accountable institution must develop, document, maintain and implement a programme for anti-money laundering, counter-terrorist financing and proliferation financing risk management and compliance. The programme must enable it to identify, assess, monitor, mitigate and manage the risk that its products and services are used for money laundering or terrorist financing. Check with the Financial Intelligence Centre whether you are an accountable institution.
Keep records of your assessments, decisions and reviews. A document that exists but is not applied does not show compliance.
Tax, Licence and Compliance Requirements
POPIA section 19 requires a responsible party to take appropriate, reasonable technical and organisational measures to prevent loss of, damage to and unauthorised access to personal information. That means identifying reasonably foreseeable internal and external risks, establishing and maintaining safeguards, verifying them regularly and keeping them updated.
Under section 22, where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, you must notify the Information Regulator and, subject to section 22(3), the affected person. Report breaches to the Information Regulator through its website.
Under OHSA section 8, every employer must provide and maintain, as far as reasonably practicable, a working environment that is safe and without risk to the health of employees. See the guide on health and safety requirements in the workplace.
Process, Deadlines and Ongoing Obligations
No single statutory risk management process applies to every organisation. Each source above describes its own steps, and they share a pattern: identify the risks, assess them, put safeguards in place, check that they work and update them. POPIA expressly requires regular verification and updating, and FICA requires the programme to identify, assess, monitor, mitigate and manage risk.
- Work out which obligations bind you: company, accountable institution, responsible party, employer, regulated sector.
- For each, identify the risks the law names and put written measures in place.
- Implement them and keep records.
- Review the measures regularly and when your circumstances change.
Public-sector bodies and regulated financial institutions have additional rules of their own. Ask your regulator or oversight body what applies.
Frequently Asked Questions
Is there a risk management law in South Africa?
No single one. Duties come from the Companies Act, FICA, POPIA, OHSA and sector regulation, and each applies only to the organisations it covers.
What is the risk management process in South Africa?
The law does not prescribe one process for everyone. POPIA section 19(2) requires you to identify foreseeable risks, establish safeguards, verify them regularly and keep them updated. FICA section 42(2) requires accountable institutions to identify, assess, monitor, mitigate and manage money-laundering and terrorist-financing risk.
Do directors carry personal liability?
Directors must meet the care, skill and diligence standard in section 76(3) of the Companies Act, and are jointly and severally liable for loss caused by breaching their duties (section 77). Take legal advice on a specific situation.
Does a written policy discharge the obligation?
No. FICA requires the programme to be implemented, not only documented, and POPIA requires safeguards to be established, maintained and regularly verified.
Confirm which obligations apply to you with the relevant regulator, such as the Financial Intelligence Centre or the Information Regulator. See company registration requirements for setting up the entity, and browse all business and compliance requirements.