South African Corporate Compliance Obligations by Department: A Comprehensive Guide

1. Introduction

For South African organisations, compliance is not merely a legal requirement—it is a strategic imperative. With legislation expanding across sectors and functions, businesses must proactively map and manage their compliance obligations by department. This ensures not only regulatory alignment, but also improved governance, risk reduction, and operational integrity.

At Crest Advisory Africa, we guide companies in building ISO-aligned Compliance Management Systems (CMS) based on ISO 37301 and other global frameworks.

Below is a department-by-department guide to the most relevant compliance laws, regulations, and codes in the South African corporate environment. This is a non-exhaustive list and it is the responsibility of each company to ensure compliance with their own requirements.

2. Human Resources (HR)

  • Basic Conditions of Employment Act (No. 75 of 1997)
  • Labour Relations Act (No. 66 of 1995)
  • Employment Equity Act (No. 55 of 1998)
  • Skills Development Act (No. 97 of 1998)
  • Unemployment Insurance Act (No. 63 of 2001)
  • Occupational Health and Safety Act (No. 85 of 1993)
  • Protection of Personal Information Act (No. 4 of 2013)

3. Supply Chain / Procurement

  • Broad-Based Black Economic Empowerment Act (No. 53 of 2003)
  • Preferential Procurement Policy Framework Act (No. 5 of 2000)
  • Consumer Protection Act (No. 68 of 2008)
  • Public Finance Management Act (No. 1 of 1999)
  • Protection of Personal Information Act (No. 4 of 2013)

4. Operations / Production

  • Occupational Health and Safety Act (No. 85 of 1993)
  • National Environmental Management Act (No. 107 of 1998)
  • Hazardous Substances Act (No. 15 of 1973)
  • Standards Act (No. 8 of 2008)

5. Maintenance / Engineering

  • Occupational Health and Safety Act (No. 85 of 1993)
  • Driven Machinery Regulations
  • Pressure Equipment Regulations
  • Electrical Installation Regulations

6. Information Technology (IT)

  • Protection of Personal Information Act (No. 4 of 2013)
  • Electronic Communications and Transactions Act (No. 25 of 2002)
  • Cybercrimes Act (No. 19 of 2020)
  • King IV Report on Corporate Governance

7. System Security / Cybersecurity

  • Cybercrimes Act (No. 19 of 2020)
  • Protection of Personal Information Act (No. 4 of 2013)
  • Electronic Communications Security Measures (relevant to state institutions and critical infrastructure)
  • ISO/IEC 27001: Information Security Management System (voluntary standard with best practices)

8. Safety, Health & Environment (SHE)

  • Occupational Health and Safety Act (No. 85 of 1993)
  • National Environmental Management Act (No. 107 of 1998)
  • Hazardous Chemical Substances Regulations
  • National Road Traffic Act (No. 93 of 1996)

9. Physical Security

  • Private Security Industry Regulation Act (No. 56 of 2001)
  • Firearms Control Act (No. 60 of 2000)
  • Occupational Health and Safety Act (No. 85 of 1993)

10. Finance / Treasury / Tax

  • Companies Act (No. 71 of 2008)
  • Income Tax Act (No. 58 of 1962)
  • Value-Added Tax Act (No. 89 of 1991)
  • Financial Intelligence Centre Act (No. 38 of 2001)
  • Public Finance Management Act (No. 1 of 1999)
  • Municipal Finance Management Act (No. 56 of 2003) where applicable

11. Legal / Governance

  • Companies Act (No. 71 of 2008)
  • Promotion of Access to Information Act (No. 2 of 2000)
  • Protection of Personal Information Act (No. 4 of 2013)
  • King IV Report on Corporate Governance
  • National Archives and Records Service Act (No. 43 of 1996)

12. Risk Management

  • King IV Report on Corporate Governance
  • ISO 31000: Risk Management Guidelines (non-binding, but internationally accepted)
  • Public Finance Management Act (PFMA) / MFMA
  • Protection of Personal Information Act (No. 4 of 2013)

13. Ethics and Compliance Office

  • ISO 37301: Compliance Management Systems (voluntary standard)
  • Prevention and Combating of Corrupt Activities Act (No. 12 of 2004)
  • Protected Disclosures Act (No. 26 of 2000)
  • Whistleblower protections under Companies Act and POPIA
  • GACP 2025 (Generally Accepted Compliance Practice framework)

14. Conclusion

Compliance is no longer the sole responsibility of the legal department. Every business unit has its own legal and regulatory duties that must be mapped, monitored, and continuously improved.

Crest Advisory Africa offers:

  • ISO training (37301, 37001, 31000, 27001)
  • Regulatory mapping workshops
  • GRC system implementation (via ISOLTX)
  • Compliance audits and advisory services

Let us help you turn regulatory complexity into strategic clarity.

www.crestadvisoryafrica.com
info@crestadvisoryafrica.com