Date: 21 August 2026
This week’s landscape highlights the intersection of regulatory enforcement, operational risk, and infrastructure liability. For general counsel, the focus must shift from reactive compliance audits to proactive risk mitigation strategies, particularly regarding procurement integrity and data security frameworks. We are observing a tightening of enforcement around conflict-of-interest protocols in public sector engagements and a significant rise in digital fraud exposure for financial intermediaries.
As reported by MyBroadband in 'Former Eskom employee convicted for R8.5 million in dodgy tenders to boyfriend and his uncle', the conviction of former Eskom buyer Nozipho Ntuli for fraud and money laundering serves as a stark reminder of the legal exposure inherent in flawed procurement processes. Ntuli abused her position to award tenders to entities linked to her romantic partner, Edward George Sekatane, and his uncle, resulting in R8.5 million in fraudulent awards.
While this case involves a state-owned enterprise, the legal implication for private sector businesses is profound under the Prevention and Combating of Corrupt Activities Act 12 of 2004 (PCCA). The PCCA imposes strict liability on employers for corrupt activities committed by employees in the course of their duties if the employer failed to implement adequate measures to prevent such conduct. For any business engaging with public entities or even in complex B2B tendering processes, this underscores the necessity of rigorous Conflict of Interest declarations. Boards must ensure that procurement policies explicitly mandate the disclosure of personal relationships between bidders and internal stakeholders. Failure to detect such conflicts can expose directors to criminal liability for gross negligence in preventing corruption.
As reported by MyBroadband in 'Major bank in South Africa takes R129-million cyber fraud hit', Absa disclosed a R129 million increase in operational risk losses in its interim results for the six months ended 30 June 2026, largely driven by sophisticated digital fraud. The bank attributed this to "increasingly sophisticated social engineering techniques and malicious applications targeting customer devices."
For businesses, particularly those in fintech or handling sensitive customer data, this highlights a critical gap between technical security measures and operational risk management under the Financial Sector Conduct Authority (FSCA) regulations and broader common law duties of care. While banks bear primary liability for transaction failures, corporate clients must assess their own exposure to social engineering attacks that compromise authorisation credentials. Under the Protection of Personal Information Act 4 of 2013 (POPIA), businesses must demonstrate that they have implemented reasonable technical and organisational measures to protect personal information. If a fraud incident stems from a third-party service provider’s vulnerability or a lapse in customer education on security protocols, the primary entity may still face regulatory scrutiny for inadequate due diligence.
As reported by Moneyweb in 'Shake-up of construction sector regulation coming', significant regulatory changes are anticipated in the South African construction industry. While specific legislative details remain to be finalised, this shake-up suggests a tightening of compliance standards around safety, licensing, and material sourcing. For businesses with supply chains dependent on construction services, this presents a contractual risk. Existing service agreements may not adequately address emerging regulatory obligations, leaving clients exposed to performance delays or non-compliant subcontractors.
The specific legislative instruments driving the construction sector shake-up are not yet defined in the source material. Legal counsel should monitor draft regulations from relevant SA government departments (e.g., Department of Public Works and Infrastructure) to assess potential impacts on contractual liabilities. Additionally, the scope of POPIA liability regarding third-party social engineering attacks should be validated against recent Information Regulator rulings to ensure accurate risk assessment for client data breaches.