Legal & Risk: What Businesses Need to Watch
2026‑09‑23
In an era where headlines shift from cyber‑attacks to infrastructure gaps, the quiet legal risks that slip through daily operations can be far costlier. Below are three recent stories that illustrate hidden compliance traps many commercial leaders miss – and concrete actions a CLO or risk team should flag immediately.
---
1. Nedbank says the cash economy won’t die until digital ID arrives
Source: “Nedbank: the cash economy won't die until digital ID arrives” — TechCentral
The article highlights that South Africa still relies heavily on physical cash, partly because a universal digital identity framework has yet to be fully deployed. For fintechs, payment processors and even traditional banks, this translates into a dual‑risk profile:
- Data‑processing risk – Under the POPIA Act 4 of 2013, any personal data gathered through “digital ID” applications must have a lawful basis, purpose limitation and robust consent mechanisms. Businesses that build products around a digital ID service that is still in flux run the danger of non‑conformity with POPIA if they do not establish clear governance over the source, storage and sharing of that data.
- AML/KYC risk – Until a verified digital ID exists nationwide, cash will continue to be the default payment method. This exposes companies to increased money‑laundering (ML) exposure because cash transactions are harder to trace. Under the Financial Intelligence Centre Act (FICA), any entity handling cash or providing services that facilitate cash movement must maintain strict record‑keeping and transaction‑monitoring systems.
Compliance actions for your CLO
- Audit digital‑ID use – Map all customer touchpoints where a digital ID is captured, verify POPIA compliance (lawful basis, data minimisation) and document consent flows.
- Strengthen AML controls – Update transaction monitoring rules to flag large cash deposits/withdrawals, and ensure staff receive refresher training on FICA‑required red flags.
- Track regulatory developments – Set up a monitoring schedule for the Department of Home Affairs’ rollout timetable and any interim identity‑verification standards that may become mandatory.
---
2. Bank Zero breaks even as Mukuru migration swells its base
Source: “Bank Zero breaks even as Mukuru migration swells its base” — TechCentral
Bank Zero’s sudden profitability, driven by customers migrating from the remittance group Mukuru, underscores a key oversight for many payment‑service providers: remittance services are regulated under FICA and must meet stringent KYC and sanctions‑screening requirements. While Bank Zero is compliant as a licensed financial institution, other SMEs offering cross‑border money movement may not be.
Legal implications often missed
- Remittance operators are required to register with the Financial Intelligence Centre and maintain AML policies that mirror those of banks. Failure to do so can result in civil penalties or criminal prosecution.
- Cross‑border transfers involve sanctions compliance under both South African law and EU/UK regimes; any lapse can expose a company to reputational damage and potential fines.
Compliance actions for your CLO
- Confirm FICA registration – Ensure that every remittance partner, vendor or in‑house team handling cross‑border payments holds a valid FICA licence.
- Update KYC templates – Align customer due‑diligence procedures with the latest FICA guidelines, including enhanced verification for high‑risk jurisdictions.
- Implement sanctions screening – Deploy automated tools to screen every transaction against OFAC, EU and UK sanctions lists; conduct regular policy reviews to keep pace with new listings.
---
3. National Bargaining Council denies ownership of R2.6 billion in workers’ funds
Source: “The National Bargaining Council for Road Freight and Logistics denies ownership of R2.6 billion in workers' funds” — BusinessTech
This dispute raises serious concerns about the fiduciary duties that employers, payroll processors and benefit fund managers owe to employees. When a council’s audited financial statements raise questions about investment earnings and fund management, any business relying on that structure must reassess its contractual safeguards.
Key legal angles
- Under the Labour Relations Act 66 of 1995, an employer who operates or authorises a pension scheme must ensure it is administered in accordance with statutory provisions – including proper asset segregation and transparent reporting.
- The Companies Act 71 of 2008 imposes fiduciary duties on directors to act honestly and with due care; failure to monitor a third‑party fund can be construed as a breach.
Compliance actions for your CLO
- Audit benefit‑fund agreements – Verify that all contractual terms enforce segregation of assets, independent custodianship and annual independent audits.
- Obtain audited statements – Require third‑party verification of fund performance and ensure any investment strategy complies with the Pension Funds Act.
- Establish oversight mechanisms – Create a governance committee to review fund health quarterly and set clear escalation paths if discrepancies arise.
---
Bottom line
Whether it’s the lagging digital ID infrastructure, the rapid shift in remittance flows or a high‑profile workers’‑fund dispute, each scenario reminds us that compliance is not static. A CLO should treat every emerging business trend as an audit trigger, align statutory obligations with operational realities and proactively engage stakeholders before risk crystallises.
---
Sources