2026‑09‑01 – Legal & Risk: What Businesses Need to Watch
In a business world where headlines often focus on numbers or deals, the legal underpinnings are usually the silent drivers of risk. Three stories from this week—an environmental court ruling in KwaZulu‑Natal, a staggering loss in Eskom’s financials, and a fintech‑led mobile network launch—reveal compliance gaps that many companies overlook.
The High Court decision upheld the validity of several mining licences granted on the Wild Coast but clarified that certain environmental safeguards were insufficient. While the ruling did not halt exploration outright, it sharpened the focus on Mineral Resources Development Act (MRDA) compliance and the Environmental Management Act (EMA).
Legal angle missed: Many operators treat licence acquisition as a final hurdle, ignoring that post‑grant audits can trigger revocation or mandatory remedial action. The court’s emphasis on environmental assessment means that companies must now embed continuous environmental monitoring clauses in their exploration contracts, with defined penalties for non‑compliance.
Compliance actions:
Eskom’s latest audit revealed that unbilled electricity theft, coupled with under‑reported municipal revenue, accounted for an excess of R45 bn in the shortfall reported this year. This isn’t merely a bookkeeping error; it signals potential breaches of Public Finance Management Act (PFMA) provisions on accurate financial reporting and could expose Eskom to civil claims from municipalities reliant on its billing.
Legal angle missed: The focus often lands on the theft itself, but the ripple effect—loss of municipal trust, possible breach of contract under the Power Supply Act, and heightened scrutiny from the Public Service Regulatory Authority (PSRA)—has yet to be addressed by many utilities.
Compliance actions:
Weaver Fintech’s rollout of PayJustNow Mobile, a virtual network operator (MVNO) on Cell C’s spectrum, demonstrates the convergence of fintech and telecoms. While the press coverage celebrated market disruption, it glossed over two critical legal pillars: licensing under the Independent Communications Authority of South Africa (ICASA) and data protection under POPIA.
Legal angle missed: Fintech firms often rely on legacy data‑handling protocols that are ill‑suited to the strict privacy regimes governing telecom subscribers. Failure to secure an ICASA licence exposes the company to regulatory fines and potential shutdowns, while inadequate POPIA compliance can result in substantial penalties and reputational damage.
Compliance actions:
---
Key takeaway: In each scenario—resource extraction, public utilities, or fintech disruption—the common thread is a failure to translate regulatory changes into concrete contractual safeguards. CLOs should prioritize proactive contract reviews, licensing checks, and governance updates before headline‑making events expose their companies to costly litigation or regulatory action.
**
** The interpretation of regulatory requirements (e.g., EMA enforcement under the Wild Coast ruling, PFMA internal‑control thresholds for Eskom, and ICASA licensing categories for MVNOs) is based on publicly available summaries. Detailed statutory analysis and jurisdictional nuances should be confirmed with a qualified South African attorney before implementing any compliance measures.