Risk management requirements in South Africa arise from several directions: company law duties on directors, the King Code on corporate governance, sector-specific regulation, and statutory obligations such as those under health and safety and financial intelligence legislation.

There is no single risk management law. What applies to your organisation depends on what it is and what it does, and the practical question is which of these sources bind you rather than what best practice looks like in the abstract.

Business Requirements at a Glance

The main sources of risk management obligation are as follows.

Registration and Legal Requirements

Directors are required to act with reasonable care, skill and diligence, and failing to identify and manage foreseeable risks can found personal liability. This is the baseline obligation for any company.

The King Code is not legislation but is incorporated into the JSE listings requirements for listed companies, and is widely applied as the governance standard elsewhere.

Documents and Ownership Information Required

Where a documented programme is required, as under FICA and health and safety legislation, it must be in writing, approved, and actually implemented. A document that exists but is not applied does not discharge the obligation.

Records of risk assessments, decisions taken and reviews conducted are what demonstrate compliance when a regulator or a court examines it after an incident.

Tax, Licence and Compliance Requirements

POPIA requires appropriate technical and organisational measures to secure personal information, and breaches must be reported to the Information Regulator and to affected people.

Health and safety legislation requires hazard identification and risk assessment as an ongoing process rather than a one-off exercise.

Sector regulators impose their own requirements, and financial services in particular carry detailed obligations on governance, capital and operational risk.

Process, Deadlines and Ongoing Obligations

Establish which obligations actually bind your organisation before designing anything. Applying a listed-company governance framework to a small business wastes effort, and ignoring a binding sector obligation creates real exposure.

Review the assessment when circumstances change rather than annually by default. Most failures happen where something changed and the assessment did not.

This page is general information and not legal or tax advice. Confirm current requirements, fees and thresholds with the responsible authority, and take professional advice on your specific circumstances.

Frequently Asked Questions

Is there a risk management law in South Africa?

No single law. Obligations arise from company law, the King Code, sector regulation and statutes such as health and safety, FICA and POPIA.

Is the King Code compulsory?

It applies on an apply and explain basis, and is incorporated into the JSE listings requirements for listed companies.

Do directors carry personal liability?

Directors must act with reasonable care, skill and diligence, and failing to manage foreseeable risks can found personal liability.

Does a written policy discharge the obligation?

Only if it is actually implemented. A document that exists but is not applied does not discharge the obligation.

Establish which obligations bind your organisation and confirm them with the relevant regulator. This page is general information and not legal or tax advice. Confirm current requirements, fees and thresholds with the responsible authority, and take professional advice on your specific circumstances. Browse all business and compliance requirements.

Related Requirements