Latest News

VAT Threshold Increase to R2.3 Million

What changed on 1 April 2026

On 25 February 2026, the Minister of Finance announced the most significant changes to South Africa’s small business tax landscape in 17 years. From 1 April 2026:

  • The compulsory VAT registration threshold increased from R1 million to R2.3 million
  • The voluntary VAT registration threshold increased from R50,000 to R120,000
  • The Turnover Tax threshold increased from R1 million to R2.3 million
  • The Turnover Tax tax-free threshold increased to R600,000

These changes affect every South African small business with annual turnover between R1 million and R2.3 million. If your business falls in this range, you have decisions to make about your tax registration status.

The three options

Option 1: Deregister from VAT

If your business was previously registered for VAT because its turnover exceeded R1 million, but your annual turnover is now below R2.3 million, you may apply to deregister for VAT.

When to consider this option:

  • Your annual taxable supplies are below R2.3 million
  • The administrative burden of VAT returns is disproportionate to your turnover
  • Your customers are mostly end consumers (not businesses that claim input VAT)
  • You want to reduce compliance costs

What deregistration means:

  • You stop submitting VAT returns every two months
  • You stop calculating output tax and input tax
  • You stop collecting VAT from customers on your invoices
  • You may need to adjust your pricing (removing 15% VAT from your prices)
  • You must apply to SARS for cancellation of your VAT registration using the prescribed process

What to watch out for:

  • If your turnover is approaching R2.3 million, you may need to re-register in the near future
  • Some customers may prefer dealing with VAT-registered suppliers
  • If you are in the construction industry or supply to government, VAT registration may be expected or required by contract

Option 2: Remain registered for VAT voluntarily

You may choose to remain VAT-registered even if your turnover falls below the compulsory threshold. This is called voluntary registration.

When to consider this option:

  • Your customers are mostly businesses that claim input VAT
  • You supply zero-rated goods or services
  • You make significant input VAT claims on business purchases
  • You want to maintain your VAT-registered status for commercial reasons

What voluntary registration means:

  • You continue to submit VAT returns and account for output and input VAT
  • You must still comply with all VAT administrative requirements
  • Your turnover must exceed R120,000 per year to remain voluntarily registered
  • If your turnover falls below R120,000, you will be required to deregister

Option 3: Register for Turnover Tax

Turnover Tax is a simplified tax system designed specifically for small businesses. It replaces Income Tax, Provisional Tax, Capital Gains Tax, and Dividends Tax with a single tax calculated on your annual turnover.

The Turnover Tax rates from 1 April 2026:

The maximum annual tax on R2.3 million turnover is R39,500.

Who qualifies:

  • Sole proprietors
  • Partnerships
  • Close corporations
  • Companies
  • Co-operatives
  • Annual turnover of R2.3 million or less

What Turnover Tax replaces:

  • Income Tax on business profits
  • Provisional Tax payments
  • Capital Gains Tax on business asset disposals
  • Dividends Tax
  • VAT (unless you elect to remain in the VAT system)

How to register:

SARS has integrated Turnover Tax registration into the SARS Online Query System (SOQS) from November 2025. You can register online.

How to decide which option is right for your business

The right choice depends on your specific circumstances. Consider these factors:

Your customer base

If your customers are mostly other businesses that need to claim input VAT, remaining VAT-registered may be important for your commercial relationships. If your customers are mostly end consumers, the VAT registration is less relevant to them.

Your input costs

If you make significant input VAT claims on purchases, equipment, or services, deregistering from VAT means you lose those deductions. Calculate whether the input tax you currently claim exceeds the administrative cost of VAT compliance.

Your growth trajectory

If your turnover is approaching R2.3 million, deregistering from VAT now may be short-lived. You may need to re-register within a year or two as your business grows.

Your administrative capacity

VAT returns require two-monthly submissions, accurate record-keeping of output and input tax, and reconciliation of your VAT account. Turnover Tax requires an annual return based on your total turnover. For small businesses with limited accounting resources, the simplicity of Turnover Tax can be significant.

Your pricing

If you deregister from VAT, you need to adjust your pricing. Your prices currently include 15% VAT. After deregistration, you charge your customers without VAT. This may mean your prices stay the same (increasing your net income) or you reduce your prices (maintaining your competitive position). Either way, the change affects your pricing strategy.

What businesses between R1 million and R2.3 million should do now

If your business falls in the R1 million to R2.3 million turnover range, here are the practical steps:

Step 1: Confirm your current turnover

Look at your actual turnover for the past 12 months. Not your projected turnover, not your best month, but your actual annual taxable supplies over the past 12 months.

Step 2: Check your VAT registration status

If you are currently registered for VAT and your turnover is below R2.3 million, you have the option to deregister. If you are not registered for VAT and your turnover is below R2.3 million, you are not required to register.

Step 3: Calculate your Turnover Tax liability

Use the Turnover Tax rates table to calculate what your tax would be under Turnover Tax. Compare this to your current Income Tax liability.

Step 4: Consider the transition

If you are switching from Income Tax to Turnover Tax, or from VAT to no VAT, there are transition issues to consider. You may need to account for output tax on existing stock when you deregister from VAT.

Step 5: Get professional advice

The right choice depends on your specific business circumstances. An accountant or auditor can help you model the financial impact of each option.

The bottom line

The 2026 threshold changes give South African small businesses more flexibility in how they manage their tax obligations. Whether you deregister from VAT, remain registered voluntarily, or switch to Turnover Tax, the key is to make an informed decision based on your actual business circumstances.

The worst thing you can do is nothing. If your turnover has changed, your tax obligations may have changed with it. Review your position, understand your options, and act before your next filing deadline.

SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support small businesses with tax planning, VAT compliance, Turnover Tax registration, and financial statement preparation. Contact SC Audit to discuss which option is right for your business.

Frequently Asked Questions

What is the new VAT registration threshold?

From 1 April 2026, the compulsory VAT registration threshold is R2.3 million in annual taxable supplies. The voluntary registration threshold is R120,000. If your annual turnover is below R2.3 million, you are not legally required to register for VAT.

Can I deregister from VAT if my turnover is below R2.3 million?

Yes. If you are currently registered for VAT and your annual taxable supplies fall below R2.3 million, you may apply to SARS for cancellation of your VAT registration. You must go through the prescribed deregistration process.

What is Turnover Tax?

Turnover Tax is a simplified tax system for small businesses with annual turnover of R2.3 million or less. It replaces Income Tax, Provisional Tax, Capital Gains Tax, and Dividends Tax with a single tax calculated on your annual turnover. The first R600,000 of turnover is tax-free.

Should I stay registered for VAT voluntarily?

If your customers are mostly businesses that claim input VAT, or if you make significant input VAT claims on purchases, remaining voluntarily registered may make sense. If your customers are mostly consumers and you do not claim significant input VAT, deregistration may reduce your compliance burden.

How do I register for Turnover Tax?

You can register for Turnover Tax through the SARS Online Query System (SOQS). The registration process has been digitalised since November 2025. You can also visit a SARS branch or use a tax practitioner to assist with registration.

Trust Account Audits in South Africa

Why trust account audits exist

Certain professions handle money on behalf of clients. Attorneys hold settlement funds, estate agents hold deposit money, and body corporates hold levy contributions. The law requires these professionals to keep that money separate from their own funds, in designated trust accounts, and to have those accounts audited annually.

Trust account audits protect the public. They verify that client money is accounted for, that trust balances match the records, and that the professional has complied with the applicable legislation. Failure to comply can result in disciplinary action, fines, or removal from the register of practitioners.

This article covers the trust account audit requirements for three categories of professionals: attorneys, estate agents, and body corporates.

Attorneys: Legal Practice Act trust account requirements

The legal framework

The Legal Practice Act 28 of 2014 governs the trust account obligations of legal practitioners in South Africa. Section 86 of the Act mandates the maintenance of trust accounts for client funds.

Every attorney who practises for their own account must hold a valid Fidelity Fund Certificate (FFC) under Section 84(1). The FFC is issued by the Legal Practice Council (LPC) and is a prerequisite for lawful practice.

What the audit covers

The trust account audit is conducted in terms of the LPC Rules and the IRBA Guide for Registered Auditors on Engagements on Attorneys Trust Accounts. The auditor examines:

  • Whether trust accounts were maintained in compliance with the Legal Practice Act and the LPC Rules
  • Whether trust money was deposited promptly into the trust banking account
  • Whether trust balances on the bank statements match the trust account records
  • Whether interest earned on trust investments was correctly calculated and paid to the Legal Practitioners Fidelity Fund (LPFF) as required by Section 86(5)
  • Whether transfers between trust and business accounts were properly authorised and documented
  • Whether trust money was used only for the purposes for which it was received

The auditor is also required to consider fraud and theft risks specific to trust accounts, as outlined in the IRBA Guide.

Key compliance requirements

Attorneys must:

  • Maintain trust accounts at a South African bank designated as a trust account
  • Keep trust money separate from personal or business funds
  • Deposit all trust money promptly into the trust banking account
  • Maintain accurate trust account records
  • Invest surplus trust money in interest-bearing accounts endorsed under Section 78(2A)
  • Pay trust interest to the LPFF as required by Section 86(5)
  • Submit the auditor’s report to the LPC within the prescribed timeframes

Consequences of non-compliance

The Legal Practice Council takes trust account breaches seriously. Court decisions from 2025 and 2026 illustrate the consequences:

  • In LPC v Phogojane (2026), the attorney was struck from the roll for systemic misuse of trust funds and failure to lodge audit reports
  • In Naude v LPC (2025), the court considered findings of trust account non-compliance including failure to invest trust monies in endorsed accounts and failure to deposit withdrawn funds promptly

Attorneys have a personal, non-delegable duty to account for all client funds. Ignorance of trust account obligations is not a defence.

Estate agents: Property Practitioners Act trust account requirements

The legal framework

The Property Practitioners Act 2019 (Act No. 22 of 2019) replaced the Estate Agency Affairs Act for estate agents. Section 54 of the Act requires annual trust account audits for business property practitioners who have not been granted an exemption by the Property Practitioners Regulatory Authority (PPRA).

Who must have a trust account audit

All business property practitioners (estate agents) who receive trust money from clients must maintain a trust account and have it audited annually. Exemption may be granted by the PPRA in certain circumstances, but the default position is that an audit is required.

What the audit covers

The auditor examines:

  • Whether trust accounts were maintained in compliance with the Property Practitioners Act and its regulations
  • Whether trust money was deposited into designated trust bank accounts
  • Whether trust balances match the accounting records
  • Whether transfers from trust to business accounts were properly authorised
  • Whether interest on trust investments was correctly handled

The auditor’s report must be submitted to the PPRA annually as required by the regulations.

Key compliance requirements

Estate agents must:

  • Maintain trust accounts designated as trust accounts at a South African bank
  • Keep all client money in trust accounts until the transaction is completed
  • Not mix trust money with personal or business funds
  • Submit the annual audit report to the PPRA within the prescribed timeframe

Body corporates: trust account requirements

The legal framework

Body corporates are established under the Sectional Titles Act 95 of 1986 and governed by the Sectional Titles Schemes Management Act 8 of 2011. The managing agent or trustee of a body corporate is responsible for managing the body corporate’s finances, including trust accounts for levy contributions and other funds.

Trust account obligations

Body corporates that collect levies and hold funds on behalf of owners must:

  • Maintain a trust account at a South African bank
  • Keep levy contributions and other trust money separate from the body corporate’s general funds
  • Maintain accurate records of all trust transactions
  • Have the financial statements audited annually as required by the Sectional Titles Schemes Management Act

The audit of a body corporate’s financial statements includes the trust account component. The auditor verifies that trust money was received, held, and spent in accordance with the body corporate’s rules and the applicable legislation.

What the audit covers

The auditor examines:

  • Whether levy contributions and other income were correctly recorded in the trust account
  • Whether trust money was used only for authorised body corporate expenses
  • Whether the trust account balance matches the accounting records
  • Whether payments from the trust account were properly authorised
  • Whether the body corporate’s financial statements present fairly the trust account transactions

Common themes across all three categories

Despite the different legislative frameworks, the trust account audit requirements share common principles:

Separation of funds. Client money must be kept separate from the professional’s own money. This is the fundamental obligation that underpins all trust account requirements.

Accurate records. Trust account records must accurately reflect all transactions. The auditor relies on these records to verify that trust money was properly handled.

Annual audit. All three categories require annual audit or examination of trust accounts. The audit is not optional, and failure to submit the audit report is itself a compliance breach.

Personal accountability. The professional who holds trust money has a personal duty to account for it. This duty cannot be delegated to staff or the managing agent.

Consequences of non-compliance. Trust account breaches can result in disciplinary action, fines, suspension, or removal from the register. The courts have shown willingness to impose severe penalties for trust account misconduct.

The bottom line

Trust account audits are a legal requirement for attorneys, estate agents, and body corporates in South Africa. They protect client money and verify that professionals comply with their fiduciary duties. The audit process is not a formality. Auditors examine trust account records, bank statements, and transactions to verify that client money was properly handled.

Professionals who maintain accurate trust account records and submit their audit reports on time avoid the disciplinary and legal consequences of non-compliance. Those who fail to comply face increasing scrutiny from regulators and courts.

SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support attorneys, estate agents, and body corporates with trust account audits, statutory audits, and compliance services. Contact SC Audit to discuss your trust account audit requirements.

Frequently Asked Questions

Do all attorneys need a trust account audit?

Yes. Every attorney who practises for their own account and holds client funds must maintain a trust account and have it audited annually in terms of the Legal Practice Act 28 of 2014 and the LPC Rules. The auditor’s report must be submitted to the Legal Practice Council within the prescribed timeframe.

Can an estate agent be exempted from a trust account audit?

The Property Practitioners Regulatory Authority may grant exemptions in certain circumstances. However, the default position is that all business property practitioners who receive trust money must have their trust accounts audited annually. Exemption is the exception, not the rule.

What happens if I do not submit my trust account audit report?

Failure to submit the audit report is a breach of the applicable legislation and rules. For attorneys, the LPC can recommend disciplinary action. Court decisions have shown that persistent non-compliance with trust account obligations can lead to suspension or removal from the roll of legal practitioners.

What is the difference between a trust account audit and a financial statement audit?

A trust account audit focuses specifically on whether client money was properly held, recorded, and used in accordance with the applicable legislation. A financial statement audit examines the overall financial position of the business. Both may be required, but they serve different purposes and follow different procedures.

Who can perform a trust account audit?

Trust account audits must be performed by a registered auditor registered with IRBA. The auditor must have the competence to perform engagements on trust accounts as outlined in the IRBA Guide for Registered Auditors.

New IRBA Auditing Standards 2026

Why these changes matter for trainees

The Independent Regulatory Board for Auditors has adopted a series of new and revised standards that take effect for audits of financial statements for periods beginning on or after 15 December 2026. These are not minor updates. They change how auditors assess going concern, how they respond to fraud risk, and how they report their findings.

If you are in a SAICA training contract, these standards will apply to the audits you participate in during your articles and beyond. Understanding them now gives you a head start when you begin performing audit procedures under the new framework.

This article explains the key changes, what they mean in practice, and how to prepare.

The three major standard changes

ISA 570 (Revised 2024): Going Concern

The revised going concern standard is the most significant change for audit practice. It strengthens the auditor’s responsibilities when management uses the going concern basis of accounting and introduces new reporting requirements.

What changes:

  • The auditor must evaluate whether management’s use of the going concern basis of accounting is appropriate in the preparation of the financial statements
  • The auditor must evaluate whether there is material uncertainty related to going concern events or conditions
  • New emphasis on the auditor’s responsibilities when management’s going concern evaluation is inconsistent with the auditor’s assessment
  • Updated reporting requirements: the auditor’s report must include a clear reference to the going concern section when material uncertainty exists
  • Introduction of an Emphasis of Matter paragraph or a Material Uncertainty Related to Going Concern section, depending on the circumstances

In practice, this means more structured documentation of going concern assessment procedures and clearer communication with those charged with governance about going concern conclusions.

ISA 240 (Revised): Fraud in an Audit of Financial Statements

The revised fraud standard responds to well-publicised audit failures and strengthens the auditor’s responsibility for detecting material misstatements due to fraud.

What changes:

  • Enhanced requirements for professional scepticism throughout the audit
  • Revised requirements for evaluating the risk of material misstatement due to fraud, including consideration of how fraud may be concealed
  • Updated requirements for responding to assessed fraud risks, including the design and implementation of further audit procedures
  • New requirements for communications with those charged with governance about fraud
  • Clarified requirements for evaluating misstatements to determine whether they may be indicative of fraud

The standard emphasises that audit procedures that are effective for detecting errors may not be effective for detecting fraud. Auditors must think about how fraud could be concealed, not just whether it has occurred.

Narrow-scope amendments to ISQMs, ISAs, and ISRE 2400

The IRBA also adopted narrow-scope amendments arising from the IESBA’s Using the Work of an External Expert project. These amendments affect:

  • International Standards on Quality Management (ISQMs): Updated requirements for firms when using the work of an external expert in quality management
  • ISAs: Clarified requirements for auditors when using the work of an expert in an audit engagement
  • ISRE 2400 (Revised): Updated requirements for independent reviews when using the work of an expert

These amendments are smaller in scope but important for audit firms that engage specialists, which is common in audits of companies with complex valuations, actuarial calculations, or IT systems.

The updated SAAPS 3: Illustrative Reports

The IRBA published an Exposure Draft of the proposed SAAPS 3 (Revised XXX 2026) in June 2026, with comments due by 7 August 2026. The final version is expected to be approved in November 2026.

SAAPS 3 provides practical guidance to registered auditors on the content and format of auditor’s reports in South Africa. The proposed revision contains 32 illustrative reports covering both audits and independent reviews.

Key changes in the illustrative reports:

  • Updated templates to reflect the new going concern reporting requirements under ISA 570 (Revised 2024)
  • Updated templates to reflect the revised fraud reporting under ISA 240 (Revised)
  • Introduction of Appendix 1(b) explaining the interaction between the IRBA’s Enhanced Auditor Reporting Rule and the going concern reporting requirements
  • An additional illustrative report for companies applying IFRS 19 (Subsidiaries without Public Accountability: Disclosures)
  • Editorial improvements updating references to the latest standards

For trainees, the illustrative reports are the practical bridge between the standards and the audit report you help prepare. Familiarising yourself with the new templates prepares you for what the final report should look like.

Sustainability assurance: ISSA 5000 and the IRBA Code

In February 2026, the IRBA adopted ethics standards for sustainability assurance, including independence standards, through Board Notice 911 of 2026. These standards introduce a new Part 5 to the IRBA Code of Professional Conduct, establishing a framework of ethics and independence requirements for sustainability assurance engagements.

The standards are designed to be equivalent to Part 4A of the IRBA Code (which applies to financial statement audits) and apply the same high ethical and independence principles.

ISSA 5000, General Requirements for Sustainability Assurance Engagements, has been adopted but is not yet effective. It is included in the 2025 Handbook Volume III. When it becomes effective, registered auditors in South Africa will be able to perform sustainability assurance engagements under a recognised framework.

For trainees, this is a career-shaping development. Sustainability assurance is a growing field, and the IRBA’s adoption of these standards means South African auditors will be at the forefront of this expanding area of practice.

The Enhanced Auditor Reporting Rule

The IRBA’s Enhanced Auditor Reporting Rule is already in effect for audits of Public Interest Entities. The rule requires enhanced content in the auditor’s report, including:

  • Key Audit Matters (KAMs): Disclosure of the matters that, in the auditor’s professional judgment, were of most significance in the audit
  • Enhanced description of the auditor’s responsibilities
  • Enhanced description of the scope and objective of the audit

The proposed SAAPS 3 (Revised) includes Appendix 1(b), which explains how the Enhanced Auditor Reporting Rule interacts with the new going concern reporting requirements. This is important for PIE audits where both the rule and the revised standard apply.

IAASB proposals on the horizon

The International Auditing and Assurance Standards Board has also issued for public consultation proposed revisions to three core ISAs: ISA 330, ISA 500, and ISA 520. These proposals aim to modernise the risk-based audit framework and address automated tools and technological advances.

Key elements of the proposed revisions:

  • Technology-neutral principles for deploying automated tools and data analytics
  • Clarified requirements for designing and executing tests of controls, substantive procedures, and substantive analytical procedures
  • Standardised concepts connecting risk assessment, risk response, and evaluation of audit evidence

These proposals are still at the exposure draft stage and have not yet been adopted by the IRBA. However, they signal the direction of audit standard-setting and the increasing role of technology in audit methodology.

What this means for SAICA training contract students

During your articles

The revised standards apply to audits for periods beginning on or after 15 December 2026. If your training office begins its audit season after that date, you will be working under the new framework from the start.

Focus areas during your articles:

  • Understand the revised going concern assessment procedures and documentation requirements
  • Learn the enhanced fraud risk assessment and response procedures
  • Familiarise yourself with the new illustrative report formats
  • Understand when and how to apply professional scepticism in the context of fraud detection

For your board exams

The SAICA board exams reflect current standards. The revised ISAs will feature in upcoming examination cycles. Key topics to master:

  • Going concern: assessment procedures, management’s responsibilities, auditor’s reporting obligations
  • Fraud: risk assessment, response to assessed risks, communication with those charged with governance
  • Audit evidence: sufficiency and appropriateness, use of experts, automated tools
  • Reporting: modified opinions, emphasis of matter, material uncertainty related to going concern

For your career

The audit profession is evolving. Sustainability assurance, technology-driven audit methodology, and enhanced reporting are reshaping what auditors do and how they do it. Understanding these trends early positions you for a career that keeps pace with the profession’s development.

The bottom line

The 2026 IRBA standards changes are the most significant updates to the auditing framework in recent years. They affect how auditors assess going concern, how they respond to fraud risk, how they use experts, and how they report their findings. For SAICA trainees, understanding these changes now is an investment in your professional development.

SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit is a SAICA-accredited training office. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support training contract students with practical experience across statutory audits, independent reviews, and assurance services. Contact SC Audit to learn more about the training programme.

Frequently Asked Questions

When do the new IRBA standards take effect?

The revised standards apply to audits of financial statements for periods beginning on or after 15 December 2026. Early adoption is permitted but requires full application of ISA 570 (Revised 2024), ISA 240 (Revised), and the narrow-scope amendments across the entire engagement.

What is the biggest change in the revised going concern standard?

ISA 570 (Revised 2024) strengthens the auditor’s responsibility for evaluating management’s use of the going concern basis of accounting and introduces new reporting requirements. When material uncertainty exists, the auditor must include a clear reference in the report, either as an Emphasis of Matter paragraph or a Material Uncertainty Related to Going Concern section.

How does the revised fraud standard affect audit procedures?

ISA 240 (Revised) enhances requirements for professional scepticism and requires auditors to consider how fraud could be concealed, not just whether it has occurred. Audit procedures effective for detecting errors may not be effective for detecting fraud, so auditors must design procedures that address fraud-specific risks.

What is sustainability assurance and why does it matter?

Sustainability assurance is the independent verification of sustainability reports and disclosures. The IRBA has adopted ISSA 5000 and ethics standards for sustainability assurance, which will allow South African auditors to perform these engagements. It is a growing field that expands the scope of audit practice.

What should SAICA trainees focus on first?

Start with the revised going concern and fraud standards, as these affect the most common audit procedures. Familiarise yourself with the new illustrative report formats in SAAPS 3. Understand the interaction between the Enhanced Auditor Reporting Rule and the new going concern requirements for PIE audits.

Independent Review vs Audit

How the Companies Act decides for you

The Companies Act of South Africa removed the one-size-fits-all audit requirement. Instead, it uses a scoring system to match your company’s assurance needs to its actual size and public impact. That score is called the Public Interest Score, and it determines three things: whether your financial statements must be audited, whether an independent review suffices, or whether a basic compilation is enough.

Most company directors know their annual turnover and asset base, but many do not know their Public Interest Score or what it means for their financial reporting obligations. This article explains the thresholds, the differences between an audit and an independent review, and how to determine which applies to your company.

Visit our page at Do I need an Audit for our PIS Calculator

What is the Public Interest Score?

The Public Interest Score is calculated at the end of each financial year in terms of Regulation 26 of the Companies Regulations, 2011. It is based on a combination of factors:

  • The number of employees
  • The value of third-party liabilities
  • The value of total assets at year-end
  • The average annual turnover for the past three years

Each factor contributes points, and the total determines which assurance level your company requires. The score is not optional. Every registered South African company must calculate it annually, and it drives your filing obligations with CIPC.

The three tiers: audit, independent review, and compilation

The Companies Act sets out three distinct assurance levels based on your Public Interest Score and how your financial statements were prepared.

Audit required

An audit is required if:

  • Your Public Interest Score is 350 or more, regardless of who prepared the financial statements
  • Your Public Interest Score is 100 or more but less than 350, and your financial statements were compiled internally (by your own staff rather than an external accountant)
  • Your Memorandum of Incorporation requires an audit
  • Your company is a public company, state-owned company, or body incorporated by the state

An audit provides reasonable assurance. A registered auditor performs in-depth procedures, testing transactions, balances, and internal controls. The auditor’s report expresses an opinion on whether the financial statements present fairly, in all material respects, the financial position of the company.

Independent review required

An independent review is required if:

  • Your Public Interest Score is 100 or more but less than 350, your financial statements are independently compiled, and your company is not owner-managed
  • Your Public Interest Score is less than 100, your financial statements are independently compiled, and your company is not owner-managed

An independent review provides limited assurance. The reviewer performs primarily inquiry and analytical procedures to determine whether anything has come to their attention that causes them to believe the financial statements are not prepared in accordance with the Companies Act. It is less extensive than an audit and typically costs less.

Compilation only

A compilation is sufficient if:

  • Your Public Interest Score is less than 100 and your company is owner-managed
  • Your Public Interest Score is less than 100 and your financial statements are independently compiled

A compilation involves preparing financial statements from information provided by management. It does not provide any assurance on the accuracy or completeness of the statements. The accountant compiles the statements and attaches a report stating that no audit or review was performed.

What an independent review actually involves

An independent review is not a lesser audit. It is a different engagement with a different objective.

Under ISRE 2400 (Revised), the reviewer performs primarily:

  • Inquiries of management and relevant employees
  • Analytical procedures applied to financial data
  • Evaluation of the sufficiency and appropriateness of evidence obtained

The reviewer does not verify balances through confirmation, inspect assets, or test internal controls in the way an auditor does. The objective is to obtain limited assurance that the financial statements are free from material misstatement.

The independent review report states whether anything has come to the reviewer’s attention that causes them to believe the financial statements do not comply with the Companies Act. This is a lower level of assurance than an audit, but it is still a professional engagement conducted under recognised standards.

Who can perform an independent review?

The Companies Regulations specify who may perform an independent review based on your company’s Public Interest Score.

PIS of 100 or more

The review must be performed by:

  • A registered auditor (registered with IRBA), or
  • A member in good standing of a professional body that has been accredited in terms of section 33 of the Auditing Profession Act (such as SAICA or ACCA)

PIS of less than 100

The review may be performed by:

  • A person in the categories above, or
  • A person qualified to be appointed as an accounting officer of a close corporation in terms of the Close Corporations Act

The key requirement is that the independent reviewer must not have been involved in the preparation of the financial statements. Independence is a prerequisite.

Owner-managed companies: the exemption

Section 30(2A) of the Companies Act provides an exemption from independent review for certain owner-managed companies. If all shareholders of the company are also directors, and the company’s Public Interest Score is below 100, the company is not required to have an independent review.

This exemption does not apply if:

  • The company voluntarily opts for an audit
  • The Memorandum of Incorporation requires an audit or review
  • The company is a public company or state-owned company

For owner-managed companies in this category, a compilation of financial statements is sufficient.

Why this matters for your business

The distinction between an audit and an independent review has practical consequences beyond compliance:

Cost. An audit is generally more expensive than an independent review because of the broader scope of procedures. For companies in the 100 to 349 PIS band, getting the compilation right (independently rather than internally) can mean the difference between an audit and a review.

Assurance level. Banks, investors, and potential buyers often prefer audited financial statements because of the higher level of assurance. An independent review provides a professional opinion, but it is limited assurance rather than reasonable assurance.

Time. An audit typically takes longer to complete than a review because of the additional procedures required. If your year-end is approaching, understanding your obligations early helps with planning.

Filing requirements. Companies with a PIS of 350 or more must submit financial statements in XBRL format to CIPC. Companies with a PIS of 500 or more must also establish a Social and Ethics Committee.

How to calculate your Public Interest Score

The Public Interest Score is calculated by adding four components:

  1. Employees: One point per employee on average during the financial year
  2. Third-party liabilities: One point per R1,000 (or equivalent) of third-party liabilities at year-end
  3. Total assets: One point per R1,000 (or equivalent) of total assets at year-end
  4. Average turnover: One point per R1,000 (or equivalent) of average annual turnover for the past three years

If your score is 350 or more, you must have an audit. If your score is between 100 and 349, whether you need an audit or review depends on who prepared your financial statements and whether your company is owner-managed. If your score is below 100, your obligations depend on ownership structure and compilation method.

The score should be calculated by your auditor, independent reviewer, or the accountant who compiles your financial statements. It is not a calculation you should attempt without professional guidance, because the definitions of assets, liabilities, and turnover for this purpose follow specific regulatory conventions.

The bottom line

The Companies Act gives every South African company a clear framework: your Public Interest Score determines your assurance requirements. An audit provides the highest level of assurance but costs more and takes longer. An independent review provides limited assurance at a lower cost. A compilation is sufficient for the smallest, owner-managed companies.

Knowing your score and understanding which tier applies to your company helps you plan your financial reporting, manage costs, and meet your filing obligations with CIPC. If you are unsure about your score or your obligations, a conversation with your auditor or accountant can resolve the question quickly.

SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support businesses across South Africa with statutory audits, independent reviews, compilations, and assurance services. Contact SC Audit to discuss which assurance level applies to your company.

Frequently Asked Questions

What is the difference between an audit and an independent review?

An audit provides reasonable assurance through in-depth testing of transactions, balances, and internal controls. An independent review provides limited assurance through primarily inquiry and analytical procedures. An audit is more extensive, takes longer, and costs more. Both are professional engagements conducted under recognised standards, but they have different objectives and produce different levels of assurance.

How do I calculate my company’s Public Interest Score?

The Public Interest Score is calculated by adding points for employees (one per employee), third-party liabilities (one per R1,000), total assets (one per R1,000), and average annual turnover for the past three years (one per R1,000). Your auditor or accountant should perform this calculation, as the regulatory definitions of each component follow specific conventions.

Can my company choose an audit even if it is not required?

Yes. A company may voluntarily elect to have its financial statements audited, even if the Public Interest Score would only require an independent review or compilation. Some companies choose this because banks, investors, or customers prefer audited statements, or because the Memorandum of Incorporation requires it.

What if my financial statements are compiled internally?

If your company compiles its financial statements internally (by your own staff) and your Public Interest Score is 100 or more, an audit is required regardless of ownership structure. Having an external accountant or firm compile your statements independently can reduce the assurance requirement to an independent review for companies in the 100 to 349 PIS band.

Who can perform an independent review on my company’s financial statements?

For companies with a PIS of 100 or more, the review must be performed by a registered auditor or a member of an accredited professional body such as SAICA or ACCA. For companies with a PIS below 100, the review may also be performed by a person qualified to be an accounting officer under the Close Corporations Act. The reviewer must not have been involved in preparing the financial statements.

POPIA Compliance for small businesses

Why POPIA compliance matters for small businesses

POPIA has been fully enforceable since 1 July 2021. Every South African business that processes personal information must comply, regardless of size. There is no small-business exemption.

The Information Regulator is now actively enforcing the Act. In the 2024/25 financial year, 2,374 data breaches were reported. By August 2025, a further 1,947 had been reported. The Regulator has imposed fines of R5 million on the Department of Basic Education, R500,000 on Blouberg Municipality, and R100,000 on Lancet Laboratories. Non-compliance with an Enforcement Notice carries a fine of up to R10 million or imprisonment of up to 10 years, or both.

Beyond fines, non-compliance creates practical business risks. Corporate procurement and ESD questionnaires now routinely ask for POPIA evidence. A missing privacy notice or Information Officer registration is an easy disqualifier for tenders and supply chain opportunities.

This checklist covers what every small business must do, in order of priority.

Step 1: Appoint and register an Information Officer

Every business must have an Information Officer. This is not optional.

Under Section 55 of POPIA, the Information Officer is responsible for encouraging compliance, dealing with data subject requests, working with the Regulator on investigations, and ensuring compliance with the Act.

If you do not appoint one, the CEO or head of the business becomes the Information Officer by default. You can authorise another person to fill the role, but the CEO remains ultimately accountable.

The Information Officer must be registered with the Information Regulator. The registration is free and can be completed online at inforegulator.org.za. You need to register before the Information Officer takes up their duties.

For small businesses, the practical minimum is one Information Officer and at least one Deputy Information Officer who can handle requests when the Information Officer is unavailable.

Step 2: Publish a privacy policy

The openness condition requires you to tell people what you do with their information. In practice, that means a privacy policy that states:

  • What personal information you collect
  • Why you collect it
  • Who you share it with
  • Whether it leaves South Africa
  • How long you keep it
  • How you secure it
  • How a person can access or correct what you hold
  • Your Information Officer’s contact details

A generic template copied from an overseas website usually fails this test. Most are written for GDPR, not POPIA. Your privacy policy must reflect your actual business practices.

The policy must be available at your principal place of business and on your website if you have one.

Step 3: Compile a PAIA manual

POPIA and PAIA share the same Information Officer. The Promotion of Access to Information Act requires every private body to maintain a manual describing the records it holds, how to access them, and the process for requesting information.

The PAIA manual must be available for public inspection during normal business hours at your principal place of business. If you have a website, it should be published there as well.

Many small businesses overlook this requirement. The Information Regulator has noted that PAIA compliance remains poor across both public and private bodies, and that many organisations still fail to publish PAIA manuals.

Step 4: Establish a lawful basis for processing

POPIA recognises several lawful bases for processing personal information. Consent is one, but not the only one. The lawful bases include:

  • Consent of the data subject
  • Performance of a contract with the data subject
  • Compliance with a legal obligation
  • Protection of a legitimate interest of the data subject
  • Performance of a task carried out in the public interest
  • Legitimate interests of the responsible party (subject to a balancing test)

You need to know which basis applies to each category of personal information you process. If you rely on consent, you must be able to prove you have it. Memory is not a record.

Direct marketing has its own stricter rules under Section 69. Marketing to someone who is not an existing customer by email, SMS, or automated call requires their consent first, and you may only ask for that consent once.

Step 5: Implement consent records and data collection notices

Section 18 of POPIA requires you to notify data subjects of specific information at or before the time you collect their personal information. This includes:

  • The purpose of the collection
  • Whether the collection is required or voluntary
  • The consequences of not providing the information
  • Who will receive the information
  • Whether the information will be transferred outside South Africa
  • The right to lodge a complaint to the Information Regulator

Where you rely on consent, the consent must be documented and can be withdrawn by the data subject at any time. You must be able to produce the consent record if challenged.

Step 6: Set up a process for data subject requests

People have the right to ask what personal information you hold about them, and to have it corrected or deleted. These requests generally must be answered within 30 days.

Your process needs:

  • A known way for people to submit a request (email, form, or in person)
  • A way to verify the requester’s identity before disclosing anything
  • A record showing each request was handled on time
  • A process for correcting or deleting information when requested

For a small business, the minimum is a documented process and a register of requests received and completed.

Step 7: Prepare a data breach response plan

Section 22 of POPIA requires you to notify the Information Regulator, and in most cases the affected people, as soon as reasonably possible after personal information is compromised. The amended regulations set this at 72 hours.

A breach is the worst possible moment to figure out who does what. Your response plan should include:

  • Who identifies and reports the breach
  • Who assesses the scope and severity
  • Who notifies the Information Regulator (using the prescribed Form 2)
  • Who notifies affected data subjects
  • What corrective steps are taken
  • How the incident is documented

The Information Regulator has issued enforcement notices specifically for failures to notify after breaches. In May 2026, Central Johannesburg TVET College received an enforcement notice for failing to notify both the Regulator and affected individuals after personal information was unlawfully shared.

Step 8: Sign operator agreements

If a third party processes personal information on your behalf, you must have a written agreement in place. This applies to cloud providers, payroll processors, accountants, IT service providers, and anyone else who handles personal information for you.

The agreement must ensure the operator:

  • Processes personal information only on your instructions
  • Implements adequate security measures
  • Notifies you of any breaches
  • Returns or destroys personal information when the contract ends

You remain the Responsible Party and cannot outsource your accountability. If your operator has a breach, you are still responsible for notifying the Regulator and affected data subjects.

Step 9: Train your staff

POPIA compliance depends on the people who handle personal information every day. Regular training should cover:

  • What personal information is and why it matters
  • The business’s privacy policy and data handling procedures
  • How to recognise and report a data breach
  • How to handle data subject requests
  • The consequences of non-compliance

Training does not need to be expensive. A practical session covering your specific business processes, with documented attendance, is sufficient.

Step 10: Monitor and review

POPIA compliance is not a once-off exercise. Businesses should:

  • Review the privacy policy and PAIA manual annually
  • Update consent records when processes change
  • Check that operator agreements are current
  • Monitor breach reporting obligations
  • Stay informed about Regulator guidance and enforcement trends

The Information Regulator held a media briefing on 31 August 2026 outlining its enforcement priorities. Businesses that stay informed are better placed to avoid becoming the next enforcement notice.

What happens if you do not comply

The consequences are real and growing:

  • Administrative fines up to R10 million for non-compliance with enforcement notices
  • Imprisonment of up to 10 years for serious offences
  • Reputational damage from public enforcement notices
  • Loss of corporate tenders and procurement opportunities
  • Civil claims from data subjects who suffer harm

The Regulator is moving toward immediate fines upon a finding of non-compliance, rather than the current grace-period approach. This mirrors the GDPR model and signals that the enforcement environment will only tighten.

The bottom line

POPIA compliance is a legal requirement, not a recommendation. The 10 steps in this checklist are the practical minimum for any South African small business. Most of them cost nothing to implement beyond the time it takes to do them.

The businesses that complete these steps protect themselves from fines, maintain access to corporate procurement, and build trust with their customers. The businesses that ignore them face growing regulatory and commercial risk.

SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support businesses across South Africa with compliance frameworks, statutory audits, independent reviews, and assurance services. Contact SC Audit to discuss how POPIA compliance affects your business.

Frequently Asked Questions

Does POPIA apply to small businesses?

Yes. Any South African business that processes personal information is a responsible party under POPIA. There is no size threshold. The moment you collect customer names, contact details, employee information, or supplier records in the course of business, POPIA applies to you.

What is the minimum POPIA compliance for a small business?

The practical minimum is: register an Information Officer with the Information Regulator, publish a privacy notice, compile a PAIA manual, establish a lawful basis for the data you hold, and secure it appropriately. These five items represent the baseline the Regulator expects.

How long do I have to respond to a data subject access request?

The amended POPIA regulations set a 30-day deadline for responding to requests for access, correction, or deletion of personal information. You must verify the requester’s identity before disclosing anything.

What happens if I suffer a data breach?

You must notify the Information Regulator within 72 hours using the prescribed Form 2. In most cases, you must also notify the affected data subjects. Failure to notify is itself an offence under POPIA and has been the basis for enforcement notices against organisations that suffered breaches.

Do I need separate POPIA and PAIA compliance?

Both Acts apply to the same business and share the same Information Officer. POPIA protects personal information; PAIA enables access to records held by public and private bodies. You need compliance with both, and the Information Officer registered under POPIA also serves as the Information Officer under PAIA.

BBBEE Compliance for SMEs

Why these changes matter

The proposed amendments touch two core parts of the BBBEE scorecard. They introduce a new Transformation Fund as an alternative to enterprise and supplier development, and they reshape how preferential procurement is measured.

For SMEs, the key implications are:

  • Your current enterprise and supplier development programmes may need to change.
  • Your procurement targets will shift if you supply larger businesses.
  • The thresholds for EMEs and QSEs remain unchanged despite years of economic growth.

These changes are still proposals. The public comment period closed on 30 March 2026, and the Minister will consider submissions before publishing final amendments. Nothing is binding yet.

The proposed Transformation Fund

What it is

The Transformation Fund is a centralised vehicle into which businesses would contribute 3% of their Net Profit After Tax (NPAT). In return, the contributing business earns up to 20 scorecard points for the Enterprise and Supplier Development element.

The Fund would be managed by a Special Purpose Vehicle (SPV) whose board is appointed by the Minister of Trade, Industry and Competition. A website (sa-transformationfund.co.za) is already operational.

How it replaces current ED/SD

Under the current Codes, businesses earn points for spending on Enterprise Development (ED) and Supplier Development (SD):

  • ED: 1% of NPAT scores 5 points
  • SD: 2% of NPAT scores 10 points
  • Total available: up to 15 points

Under the proposed changes:

  • Contribution of 3% of NPAT to the Fund scores up to 20 points
  • Total available: up to 20 points

The extra 5 points are an incentive, but the trade-off is significant. You must choose between:

  1. Continuing with your own ED/SD programmes, or
  2. Contributing to the Transformation Fund

You cannot do both. If you choose the Fund, your existing ED/SD initiatives would end. The proposed Codes contain no transition period for winding down current programmes, which could have legal and commercial consequences for both your business and the beneficiaries you currently support.

What SMEs should consider

Before deciding, every business needs to evaluate:

  • Whether the additional 5 points would materially improve your BBBEE level
  • The tax treatment of contributions (the Fund’s website states contributions will be mostly tax-exempt under section 56(1)(h) of the Income Tax Act, with deductions available under section 18A)
  • The terms of the Participation Agreement you would sign with the Fund
  • What happens to existing beneficiary relationships

The Fund is intended to pool resources and drive impact for Black-owned enterprises, particularly EMEs and QSEs, rather than relying on individual business programmes.

Changes to preferential procurement

The shift to 100% Black-owned suppliers

The current scorecard rewards procurement from suppliers that are at least 51% Black owned. The proposed changes restructure this significantly:

Supplier category Current points Proposed points
100% Black-owned QSEs (R10m-R50m turnover) Included in general recognition 2 points (15% target)
100% Black-owned EMEs (below R10m turnover) Included in general recognition 2 points (15% target)
100% Black-owned suppliers Part of general scoring 7 points (25% target)
100% Black women-owned suppliers Part of general scoring 3 points (12% target)
51% Black-owned suppliers Highest weighting Reduced to approximately 3 points

The bonus points (2 points) now require 100% procurement from Designated Groups (unemployed Black people, Black youth, disabled Black people, Black people in rural areas, and Black military veterans), up from the current 2% target from 51%-owned suppliers.

What this means in practice

For businesses that supply larger companies, these changes affect your value as a BBBEE procurement partner:

  • If you are 100% Black owned, you become more attractive to procurement teams
  • If you are 51% Black owned but not 100%, your procurement recognition drops significantly
  • Only around 10,000 of the approximately 54,000 BBBEE-certified businesses in South Africa are 100% Black owned, and 90% of those have turnover below R50 million

For businesses that buy from suppliers, meeting the new targets may require restructuring your supply chain. The 25% target for 100% Black-owned suppliers is a substantial shift from current practices.

EME and QSE thresholds remain at 2013 levels

The proposed Codes maintain the existing definitions:

  • Exempted Micro-Enterprise (EME): annual turnover below R10 million
  • Qualifying Small Enterprise (QSE): annual turnover between R10 million and R50 million

These thresholds have not been updated since 2013. Given inflation and economic growth over the past 13 years, many businesses that would have been classified as EMEs or QSEs a decade ago now exceed these limits. Business Day and other commentators have noted that these thresholds are long overdue for an increase.

For SMEs, this means:

  • Your classification may not reflect your current business size
  • Businesses that have grown past R10 million in turnover move from EME to QSE status, with different verification requirements
  • QSEs that are not at least 51% Black owned must be verified by an accredited verification professional

Sector Codes are not affected (yet)

The proposed changes apply only to the Generic Codes of Good Practice. Sector-specific Codes remain in place for businesses operating in:

  • Agriculture
  • Chartered Accountancy
  • Construction
  • Financial Services
  • Information and Communication Technology (ICT)
  • Forestry
  • Property
  • Tourism
  • Transport

Businesses covered by Sector Codes will not score points from Transformation Fund contributions, and their procurement scores are not affected by the proposed changes, unless and until their Sector Codes are updated to align with the Generic Codes.

If your business falls under a Sector Code, check whether your sector’s Code is being amended separately.

What to do now

While the final Codes have not been published, there are practical steps every business can take.

1. Understand your current BBBEE position

Review your latest BBBEE verification or affidavit. Know your current level, your scorecard breakdown, and which elements contribute most to your rating.

2. Map your enterprise and supplier development spending

Identify where your ED and SD contributions go, who your beneficiaries are, and what relationships exist. If the Fund becomes mandatory or preferred, you need to know what you would be ending.

3. Review your procurement chain

Understand what percentage of your procurement currently goes to 51% Black-owned suppliers versus 100% Black-owned suppliers. If the proposed procurement targets are finalised, quantify the gap.

4. Monitor the public process

The Minister will consider comments received before deciding on final amendments. Stay informed through your industry body, your BEE verification agency, or your auditor.

5. Get professional advice

The proposed changes are complex and carry tax, legal, and commercial implications. SC Audit can help you understand how the changes affect your specific business and BBBEE level.

The bottom line

The proposed 2026 BBBEE Codes changes move enterprise development from scattered individual programmes toward a centralised fund, and shift procurement scoring from majority Black-owned suppliers toward 100% Black-owned suppliers. Whether these changes are finalised in their current form or modified through the comment process, they signal the direction of BBBEE policy.

SMEs that understand their current position and begin planning now will be better placed to respond when the final Codes are published.

SC Audit is an IRBA-registered audit firm based in Bellville, Cape Town. SC Audit’s partners Niel Schoeman, Simone Coetzee, and Hennie Meyer support businesses across South Africa with BBBEE compliance, statutory audits, independent reviews, and assurance services. Contact SC Audit to discuss how the proposed BBBEE changes affect your business.

Frequently Asked Questions

Are the proposed BBBEE Codes changes final?
No. The proposed amendments were published on 29 January 2026 for public comment. The comment period closed on 30 March 2026. The Minister will consider submissions before publishing final amendments. The current Codes remain in force until the final versions are gazetted.

What is the BBBEE Transformation Fund?
The Transformation Fund is a proposed centralised vehicle into which businesses would contribute 3% of their Net Profit After Tax (NPAT). In return, the business earns up to 20 scorecard points for Enterprise and Supplier Development. The Fund would be managed by a Special Purpose Vehicle appointed by the Minister of Trade, Industry and Competition.

Can I continue with my existing enterprise and supplier development programmes?
Under the proposed Codes, you must choose between contributing to the Transformation Fund or continuing with your own ED and Supplier Development (SD) programmes. You cannot do both. If you choose the Fund, your existing ED/SD initiatives would be terminated. The proposed Codes do not include a transition period for winding down current programmes.

How do the procurement changes affect my business as an SME supplier?
If your business is 100% Black owned, the proposed changes make you a more attractive procurement partner, with specific targets and points allocated to 100% Black-owned EMEs, QSEs, and general suppliers. If your business is 51% Black owned but not 100%, your procurement recognition under the scorecard would decrease significantly compared to the current Codes.

Do the proposed changes apply to Sector Codes?
No. The proposed changes apply only to the Generic Codes of Good Practice. Sector-specific Codes for Agriculture, Chartered Accountancy, Construction, Financial Services, ICT, Forestry, Property, Tourism, and Transport remain in place unless and until updated separately.

How Much Does an audit cost

Most businesses in South Africa ask the same question when they hear the word “audit”: “What is this actually going to cost us?” Audit fees are not one-size-fits-all. They depend on the size, complexity and risk profile of the engagement, as well as the work effort required to perform a quality audit.

This article explains the main factors that influence audit fees so you can understand how quotes are put together and what you can do to manage costs without compromising quality.

1. There is no single “standard audit fee”

An audit fee is the remuneration charged by auditors for the time and expertise needed to perform an audit in accordance with the applicable standards.

In practice:

  • Audit fees are usually based on the expected hours at different staff levels, multiplied by charge-out rates, and adjusted for complexity and risk.
  • Fees should be sufficient to allow auditors to perform the necessary work and maintain audit quality.
  • Reasonable fees support the auditor’s ability to obtain appropriate evidence and issue a reliable opinion.

This is why two entities of similar size can still receive different quotes: the underlying work effort is not identical.

2. Six factors that drive your audit fee

1) Size of your business and transaction volume

Client size is one of the most important determinants of audit fees.

In practical terms:

  • Larger entities tend to have more transactions, accounts and systems to audit.
  • Higher revenue, more assets and more staff usually translate into more work across areas such as revenue, inventory, receivables, payables and payroll.
  • Even within SMEs, fast-growing businesses often require more audit effort than very small, simple entities.

The fee usually moves in line with the audit hours required to cover all relevant areas at an appropriate level of depth.

2) Complexity of your structure and operations

Beyond sheer size, complexity is another major factor.

Complexity can come from:

  • Multiple entities or subsidiaries, group structures and consolidations.
  • Operations in more than one location or business line.
  • Significant estimates and judgments, for example impairment, provisions or fair value measurements.
  • Specialised industries with specific regulatory or reporting requirements.

Higher complexity typically requires more senior involvement, more planning and more procedures, which increases the overall effort.

3) Quality of your accounting records and reconciliations

The state of the client’s records and internal processes affects audit effort and, therefore, fees.

In practice:

  • Well-maintained records, timely reconciliations and clear audit trails make it easier for auditors to obtain evidence.
  • Missing documentation, late adjustments and unresolved differences can require additional work to resolve before the audit procedures can even start.
  • Frequent year-end “clean-up” work outside agreed scope may lead to discussions about additional fees.

This is one area where management can directly influence future fees by improving record-keeping and internal processes.

4) Strength of internal controls and risk profile

Assessed audit risk and the quality of internal controls are important determinants of audit fees.

From an audit planning perspective:

  • Strong, well-designed and implemented controls can allow auditors to place some reliance on those controls, potentially reducing the need for extensive detailed testing in certain areas.
  • Weak or poorly documented controls, significant fraud risk or a history of misstatements often mean more substantive work and more hours.
  • Entities operating in higher-risk environments or with complex IT systems may require specialist input.

The aim is not to “penalise” risk, but to ensure that the level of work matches the risk profile.

5) Reporting frameworks and regulatory environment

Different reporting frameworks and regulatory contexts can also have an impact.

Examples include:

  • Entities preparing financial statements under more complex frameworks may require additional technical work.
  • Regulated sectors may have additional reporting or compliance requirements.
  • Audits performed on behalf of certain public bodies are sometimes subject to specific fee guidelines or charge-out structures.

These factors influence both the amount and the nature of audit work.

6) Timing, deadlines and other practical considerations

Timing and practical constraints can also influence pricing.

In practice:

  • Very tight deadlines or audits scheduled in peak season may require increased staffing or overtime.
  • Requests for significant scope changes or additional reporting after the engagement has been planned can increase work effort.
  • In some cases, audits that involve extensive travel or work across many locations can have different cost profiles.

Clarifying timing and expectations upfront helps keep fees aligned with the initial quote.

3. How auditors typically build an audit fee

While each firm has its own approach, the process is broadly similar.

Step 1: Assess the engagement

  • Understand the entity’s size, complexity, risk profile, reporting framework and regulatory context.
  • Consider whether specialists or additional resources are required.

Step 2: Estimate hours by staff level

  • Plan expected hours for partners, managers and staff based on prior experience and the upcoming year’s circumstances.
  • Factor in planning, fieldwork, supervision, review and reporting.

Step 3: Apply charge-out rates

  • Use internal charge-out rates that reflect the cost of staff and partners, as well as overheads needed to maintain quality and compliance.

Step 4: Discuss scope and assumptions with the client

  • Explain what is included in the fee and what assumptions it is based on.
  • Agree how additional work, if needed, will be handled.

This process is intended to link the fee directly to the work needed to perform a quality audit.

4. How your business can help manage audit costs responsibly

Without undercutting quality, there are practical steps businesses can take to help keep audit fees under control:

  • Maintain good records throughout the year
    Keep invoices, contracts, bank statements and supporting documents organised, and perform reconciliations regularly.
  • Address known issues early
    Discuss unusual transactions, new funding structures or major changes with your auditor ahead of year-end so they can be planned properly.
  • Agree scope and timelines clearly
    Confirm what is included in the fee, when information will be ready and how long fieldwork will take, and avoid compressing timelines unnecessarily.
  • Use management letters constructively
    Work through prior-year recommendations on controls and processes to reduce risk and, over time, audit effort.

These steps also tend to improve the quality of internal information, which benefits management beyond the audit.

5. Why “too cheap” can be risky

Fees must be sufficient to support the work required to issue a quality audit report.

If a fee is significantly lower than what would be expected given your size, complexity and risk profile, it is important to:

  • Ask how the firm plans to cover all required areas within that budget.
  • Confirm that the work will still be performed in line with the applicable auditing standards.
  • Understand whether the quote is based on realistic assumptions about the state of your records and controls.

The goal is not to suggest that higher fees always mean higher quality, but to recognise that quality audits require adequate time and resources.

6. Getting an audit quote that fits your situation

When you request an audit proposal, you can help the process by providing:

  • A brief description of your business and activities.
  • Recent financial statements or management accounts.
  • Information about group structures, locations and key systems.
  • Any regulatory or stakeholder requirements that may affect the engagement.

This allows the auditor to tailor the scope and fee to your circumstances and to explain how each of the factors above influences the quote in your case.

Frequently asked questions

Is there a typical audit fee range for small businesses?

There is no single standard fee because audit pricing depends on size, complexity, risk and work effort. Similar-sized entities can have different fees if their structures, records or risk profiles differ.

Do auditors charge by the hour or a fixed fee?

Many firms use a fixed fee based on estimated hours at different staff levels, while others may use hourly billing or a hybrid. In all cases, the fee should reflect the work needed to perform a quality audit.

Can our audit fee go down over time?

In some cases, fees may stabilise or decrease if the business becomes more efficient, records improve and prior-year issues are resolved. Major growth, complexity or new requirements can have the opposite effect.

Is it risky to choose the lowest audit quote?

A low fee is not necessarily a problem, but it is sensible to understand how the firm will carry out the required work within that budget. Quality audits require sufficient time and resources.

if SARS Selects Your Business for an Audit

Receiving a letter from SARS saying your return is “selected for verification” or “subject to audit” can feel intimidating, but it is a normal part of the tax system. Understanding the difference between verification and audit, the steps SARS follows, and your responsibilities can help you respond calmly and correctly.

1. Verification vs audit: what SARS means

Verification: face-value check of your return

SARS often starts with a verification, which is a face-value check of the information declared on your tax return or declaration.

In a verification:

  • SARS compares the amounts you declared with your supporting documents and/or third-party data, for example IRP5s, medical aid, retirement annuity and other reports.
  • You receive a verification letter listing the documents SARS wants and giving a deadline, often 21 business days.
  • SARS aims to finalise the verification within a set period after receiving all documents, depending on tax type and complexity.

A verification is focused on confirming that what is on your return matches your documents. If issues arise, SARS may adjust your assessment or decide that a more detailed audit is required.

Audit: deeper examination of your tax affairs

An audit is a more detailed examination of your financial and accounting records and supporting documents to determine whether you have correctly declared your tax position.

In an audit:

  • SARS can review multiple periods, income streams and tax types.
  • You receive a Notification of Audit letter and, usually, a separate request for further material.
  • SARS provides progress reports at intervals and the audit can take several months for more complex cases.

Both verification and audit fall under SARS’s powers in the Tax Administration Act to select taxpayers for inspection, verification or audit on a risk basis or even randomly.

2. How SARS communicates and what the letters mean

Notification and request for documents

For both verification and audit, SARS will communicate via official notices, typically:

  • A letter stating that your return or declaration has been selected for verification or for audit.
  • A list of “relevant material” (supporting documents and information) that you must submit, and the due date.

You may be asked to submit documents via:

  • eFiling (upload facility).
  • The SARS Online Query System.
  • A booked appointment and document submission at a SARS branch.

It is important to read the letter carefully to understand:

  • Which tax type and period the verification or audit relates to.
  • Exactly what documents SARS has requested.
  • The deadlines for submission and response.

Progress updates and outcome letters

Once you have submitted all requested material:

  • For verifications, SARS generally aims to finalise within a specified number of business days after receiving everything, although complex cases may take longer.
  • For audits, SARS may issue progress reports at defined intervals and ultimately a Finalisation of Audit letter setting out the outcome.

If SARS makes changes to your assessment, you will receive an adjusted assessment notice, and normal objection and appeal processes will apply if you disagree.

3. Common triggers for verification and audit

SARS can select any taxpayer, but certain patterns commonly lead to verification or audit:

  • Large or unusual deductions, for example travel, medical or business expenses.
  • Mismatches between your return and third-party data.
  • Significant VAT refunds or sudden changes in trading patterns.
  • Reporting business, rental or freelance income.
  • Claims for certain rebates or incentives.
  • A history of non-compliance or previous understatements.

There are also random selections as part of SARS’s broader compliance programme, so being selected does not automatically mean SARS believes you have done something wrong.

4. What to do immediately when you receive a SARS letter

Step 1: Read the letter carefully and stay within deadlines

When you receive a verification or audit notification:

  • Confirm which tax type and period are affected, for example income tax 2025 or VAT for specific months.
  • Note the due date for submitting documents or responding.
  • Check exactly what SARS is asking for, such as IRP5s, bank statements, invoices, contracts or tax computations.

Missing deadlines or providing incomplete information can lead to additional assessments and, in some cases, penalties.

Step 2: Gather and organise relevant material

Typical documents SARS may request include:

  • Financial statements and trial balances.
  • Bank statements for relevant periods.
  • Invoices, receipts, contracts and supporting documents for income and expenses.
  • PAYE and payroll records.
  • Supporting certificates such as IRP5s, IT3s, medical aid and retirement contributions.
  • Schedules for specific deductions or allowances.

Organise documents clearly, for example by month or by category, so SARS and any advisors can follow your explanations more easily.

Step 3: Consider involving your auditor or tax practitioner

Many businesses choose to involve a registered auditor or tax practitioner to:

  • Help interpret SARS’s request and check that all relevant material is included.
  • Ensure explanations and schedules are prepared clearly.
  • Assist in managing correspondence, especially if there are complex issues or potential adjustments.

This can be particularly useful if multiple periods are under review or if you have significant business, rental or international transactions.

5. During the audit: rights and responsibilities

Your responsibilities

During a verification or audit, SARS expects taxpayers to:

  • Keep and provide relevant records, typically for at least five years after the submission of the return.
  • Submit all requested documents and information within the specified timeframes.
  • Respond to follow-up requests and clarify items where SARS has questions.

Failure to provide requested material can result in SARS disallowing claims or issuing assessments based on the information available to them, which can be less favourable.

Your rights

At the same time, taxpayers have rights, including:

  • To be notified in writing before an audit starts.
  • To know which tax periods and tax types are under audit.
  • To receive reasons for adjustments and an opportunity to respond.
  • To object and appeal through the normal dispute resolution process if they disagree with the outcome.
  • To seek professional assistance, such as an auditor, tax consultant or legal advisor, at any stage.

Guidance for taxpayers and registered auditors also discusses how SARS should request access to audit files and working papers and how such access is managed within the framework of the Tax Administration Act.

6. After the audit: possible outcomes

A verification or audit can lead to several outcomes:

  • No changes – SARS is satisfied and issues a completion or finalisation letter.
  • Adjusted assessment – SARS changes your tax due or refund based on their findings.
  • Penalties and interest – For understatements or non-compliance, SARS may levy understatement penalties and interest, with levels depending on the nature of the error and the taxpayer’s behaviour.
  • Further investigation – In serious cases, matters may be referred for further investigation.

If you disagree with the outcome, you normally need to:

  • Request reasons, if needed.
  • Lodge an objection within the prescribed timeframes, supported by documents and explanations.
  • Follow with an appeal or alternative dispute resolution if required.

Professional assistance is often useful at this stage to ensure that your rights and obligations are properly balanced.

7. How to reduce stress next time

Even though no one can guarantee avoiding a SARS verification or audit, you can make the process smoother by:

  • Keeping your accounting records and supporting documents complete and well-organised for at least five years.
  • Reviewing your returns carefully before filing, or having a professional review them.
  • Ensuring that high-risk areas, such as VAT, PAYE, business expenses and allowances, have clear documentation.
  • Responding promptly and fully to any SARS letters.

For many businesses, working with a registered auditor or tax practitioner as part of a broader tax risk and compliance approach helps turn a SARS audit from a crisis into a manageable process.

Frequently asked questions

Is a SARS verification the same as a tax audit?

No. A verification is a face-value check of your return against supporting documents and third-party data, while an audit is a more detailed examination of your financial records and tax affairs that may cover multiple periods or tax types.

How long does a SARS audit or verification usually take?

Timeframes vary. Verifications are often finalised within a set number of business days after you have submitted all requested documents, while audits can take several months, especially for complex or multi-year cases.

Do I need a tax practitioner or auditor if SARS audits me?

You are not required to use a practitioner, but many businesses choose to do so. A registered tax practitioner or auditor can help interpret SARS’s requests, prepare responses and assist if you need to object or appeal.

Can SARS audit previous years that are already “done”?

Yes. SARS may audit previous years within the prescription periods allowed by law, and in some cases longer where there has been fraud, misrepresentation or non-disclosure of material facts.

NPO and NGO audits in SA

Non-profit organisations in South Africa live under two spotlights at once: local regulation (especially the Non-Profit Organisations Act and Companies Act) and the expectations of donors who want clear, reliable reporting. Getting the audit question right is a key part of staying compliant and fundable.

This guide gives boards and managers a practical view of when audits or reviews are required, how Public Interest Score (PIS) fits in, and what donors typically expect from your financial reporting.

1. Legal basics for NPOs and NGOs in South Africa

The NPO Act and registration with DSD

Registered NPOs fall under the Non-Profit Organisations Act, 71 of 1997. The Act and related guidance from the Department of Social Development (DSD) require that NPOs:

  • Register with the NPO Directorate and keep founding documents and office-bearer details up to date.
  • Keep proper financial records and prepare annual financial statements within six months of year-end.
  • Submit an annual narrative report and financial report, including an accounting officer’s report or alternatives where there are no formal financial statements yet.

Failure to submit these reports can lead to deregistration, and large numbers of NPOs have recently been reported as non-compliant or at risk, which directly affects their ability to access funding.

When audits or reviews are required by law

The legal requirement for an audit or independent review can arise from different places:

  • The Companies Act and Regulations, where the NPO is structured as a non-profit company and is subject to PIS-driven assurance rules, similar to profit companies.
  • The NPO Act, which focuses on proper financial statements and an accounting officer’s report, and is increasingly being discussed in terms of allowing or encouraging audits or reviews for higher-risk or higher-funded NPOs.
  • Other legislation or funding conditions, for example when an NPO holds assets in a fiduciary capacity or receives grants that contractually require audited financial statements.

Because structures differ (voluntary associations, trusts, non-profit companies), NPO boards are encouraged to obtain specific advice on which assurance level applies in their case.

2. Public Interest Score (PIS) and non-profit companies

How PIS applies to non-profit companies

Where an NPO is incorporated as a non-profit company under the Companies Act, it must calculate its Public Interest Score annually. PIS is based on:

  • Average number of employees.
  • Turnover in units of R1 million (or part thereof).
  • Third-party liabilities in units of R1 million (or part thereof).
  • Number of members or shareholders, depending on the type of entity.

Higher scores indicate higher public interest and can trigger mandatory audits or reviews, particularly where the entity holds assets in a fiduciary capacity or surpasses certain thresholds.

Broad relationship between PIS and assurance

Summaries of the Regulations and CIPC guidance explain, in broad terms, that:

  • Non-profit companies with high PIS are more likely to require statutory audits.
  • Those with moderate PIS may be eligible for independent reviews instead of audits, depending on how their financial statements are compiled and on other conditions.
  • At lower PIS levels, there may be no statutory requirement for an audit or review, although the entity may still choose assurance voluntarily or be required to do so by donors.

This sits alongside any specific obligations in the organisation’s founding documents or in grant agreements.

3. Donor expectations and “donor audits”

Why donors often ask for audited financial statements

Donors—whether local or international—use financial statements to assess whether funds have been applied as agreed and whether the organisation is managing resources responsibly. As a result:

  • Many grant agreements require audited annual financial statements for the whole organisation.
  • Specific large grants may require a separate “donor audit” or “grant audit”, focused on that funding stream.
  • Donors may also ask for assurance over restricted funds, project-specific tracking and compliance with grant conditions.

South African auditing guidance notes that reporting on donor funding may involve special purpose frameworks and specific reporting responsibilities beyond the general financial reporting framework.

Transparency and compliance as funding prerequisites

Recent commentary highlights that many NPOs lose opportunities not because funding is unavailable, but because reporting and compliance are not in order. Common challenges include:

  • Late or missing annual reports to the NPO Directorate or CIPC.
  • Financial statements not aligned with donor requirements.
  • Weak documentation and audit trails for restricted and project funds.

In this environment, NPOs that consistently produce timely, audited or reviewed financial statements and clear donor reports often find it easier to maintain and grow funding relationships.

4. Typical audit and review paths for NPOs and NGOs

Smaller, community-based NPOs

Smaller NPOs with limited turnover, few staff and simple funding streams often start with:

  • Annual financial statements prepared with an accounting officer’s report, as required by the NPO Act.
  • Voluntary audits or reviews only when a donor or founding document explicitly requires this.

Even at this level, maintaining good records (vouchers, receipts, bank statements) and submitting annual reports on time is critical to avoid deregistration and to demonstrate basic accountability.

Medium-sized NGOs with multiple donors

As organisations grow and begin to manage larger, multi-year funding:

  • Donors and governance bodies increasingly expect audited financial statements.
  • Complex fund accounting (restricted vs unrestricted) makes assurance engagements more valuable for both management and funders.
  • Some entities may use independent reviews where the risk profile and legal requirements allow, but still move to full audits as funding grows and expectations rise.

Large NGOs and non-profit companies with high public interest

For large NGOs and non-profit companies with significant staff, revenue and public visibility:

  • Statutory audits are commonly required under the Companies Act, the organisation’s own constitution, or specific legislation related to their sector or funding.
  • Donor audits and special purpose assurance engagements may be layered on top of the general audit to address specific grant or programme requirements.

In these cases, audit and assurance are a core part of the organisation’s accountability framework.

5. How to prepare your NPO for a smooth audit or review

Strengthen financial records and fund tracking

Whether you are preparing for an audit, review or accounting officer’s report, strong underlying records are essential:

  • Maintain complete and organised supporting documents (invoices, contracts, payroll records, bank statements).
  • Clearly separate restricted funds, earmarked for specific projects or purposes, from unrestricted funds in your accounting records.
  • Reconcile bank accounts, donor balances and key ledgers regularly during the year, not only at year-end.

This makes it easier for auditors and reviewers to follow the story of each grant and for management to answer donor questions confidently.

Align your reporting with NPO Act and donor requirements

NPOs are required to submit narrative and financial reports to the NPO Directorate, and failing to do so has led to many deregistrations and loss of funding. To align:

  • Map each donor’s reporting requirements, financial and narrative, to your internal chart of accounts and reporting formats.
  • Prepare a calendar of reporting deadlines, including annual reports to DSD, CIPC filings, donor reports and audit timelines.
  • Ensure your board or governing body formally approves the annual financial statements and reports before submission.

This helps build a consistent compliance habit and reduces last-minute rushes.

Engage early with your auditor or assurance provider

NPOs benefit from involving their audit or review practitioner early in the cycle, particularly when:

  • There are new or complex funding arrangements.
  • The organisation is changing legal form or governance structures.
  • There are known weaknesses in record keeping or internal controls.

Early engagement allows time to clarify expectations, agree on timelines and resolve potential issues before year-end.

6. Frequently asked questions

Do all NPOs in South Africa have to be audited?

No. All registered NPOs must keep proper financial records and submit annual reports, but whether an audit or independent review is required depends on the organisation’s legal form, PIS, founding documents and funding conditions. Smaller entities may rely on an accounting officer’s report, while larger or higher-risk entities are often required or expected to be audited.

What is the difference between an NPO’s annual audit and a “donor audit”?

The annual audit or review covers the organisation’s financial statements as a whole, whereas a donor or grant audit focuses on a specific funding stream or project and whether those funds were used in line with the agreement. Both are assurance engagements, but the scope and reporting are tailored to different audiences.

Can an NPO lose funding if it does not keep up with audits and reporting?

Yes. Many South African NPOs risk losing access to grants, subsidies and tax benefits due to non-compliance with basic reporting obligations and governance standards, including the submission of annual reports. Donors often consider timely, reliable audited or reviewed financial statements a condition for ongoing support.

Who decides whether our NPO should have an audit or an independent review?

The decision is guided by applicable laws, such as the Companies Act and NPO Act, the organisation’s founding documents, and the requirements set by major funders or regulators. Boards and governing bodies are encouraged to obtain advice from a registered auditor or suitably qualified professional to assess the appropriate level of assurance.

Compilation, Independent Review or Audit?

As your business in Cape Town grows, the question often shifts from “Do I have financials?” to “What level of assurance do we actually need on these financials?”. In South Africa, the Companies Act and its Regulations recognise three broad levels: compilation, independent review and audit, with requirements largely driven by your Public Interest Score (PIS) and who compiles your annual financial statements.

This article explains the differences in plain language so you can have informed discussions with your auditor and stakeholders.

The three levels: compilation, independent review and audit

Compilation (no assurance)

A compilation is when financial statements are prepared from the underlying accounting records, but no assurance is provided on those financial statements.

In practice, this means:

  • A professional may help you prepare the statements in line with a chosen framework.
  • They do not test or verify the information beyond what is needed to compile it.
  • There is no opinion or conclusion stating whether the financials are fairly presented.

Compilations can be sufficient for very small, owner-managed entities with low PIS and no external stakeholders requiring assurance.

Independent review (limited assurance)

An independent review provides limited assurance that nothing has come to the reviewer’s attention to indicate that the financial statements are not fairly presented in all material respects.

Key points:

  • Procedures are mainly inquiry and analytical procedures, rather than detailed substantive testing.
  • The reviewer issues a conclusion, not an audit opinion, and the level of assurance is lower than in an audit.
  • Independent reviews are performed in terms of standards such as ISRE 2400.

For many private companies below certain PIS thresholds, an independent review is permitted as an alternative to an audit, provided specific conditions are met.

Audit (reasonable assurance)

An audit provides reasonable assurance that the financial statements are free from material misstatement, whether due to fraud or error.

In an audit:

  • The auditor performs a broader range of risk assessment and substantive procedures, including tests of details and, where applicable, tests of controls.
  • The auditor issues an opinion stating whether the financial statements present fairly, in all material respects, in accordance with the applicable financial reporting framework.
  • The work is performed under International Standards on Auditing (ISAs), as adopted in South Africa.

Audits are mandatory for certain entities and voluntary for others that choose a higher level of assurance.

How Public Interest Score (PIS) influences what you need

What is PIS?

Public Interest Score is a calculation prescribed by the Companies Act Regulations and must be done at the end of every financial year.

The score is based on factors such as:

  • Average number of employees.
  • Turnover, measured in units of R1 million (or part thereof).
  • Third-party liabilities, also in units of R1 million (or part thereof).
  • Number of shareholders or members, depending on the type of entity.

The higher your PIS, the greater the public interest in your company, and the more likely it is that an audit will be required.

Simplified view of thresholds

While you should always confirm specifics for your situation, many summaries of the Companies Act and Regulations explain the effect of PIS in broad terms as follows:

  • PIS 350 or higher: An audit of the annual financial statements is generally required, subject to certain exemptions.
  • PIS between 100 and 349: If the annual financial statements are compiled internally, an audit is often required; if they are independently compiled and the company is owner-managed, an independent review may be sufficient.
  • PIS below 100: Owner-managed companies may in some cases be exempt from both audit and review, unless the Memorandum of Incorporation or another law requires assurance, although an independent review or audit may still be chosen voluntarily.

There are also automatic audit requirements for public companies, state-owned companies, certain non-profit companies and entities holding assets in a fiduciary capacity beyond specific thresholds.

Typical paths for growing Cape Town SMEs

While each entity needs advice based on its own facts, many SMEs in Cape Town follow a similar progression as they grow:

Early stage / micro entities

  • Low PIS, limited external stakeholders.
  • Often start with compilation only, while keeping records and reconciliations simple and up to date.

Growing SMEs with bank facilities or outside investors

  • PIS moves into the 100–349 range.
  • Banks, investors or group policies may require an independent review or audit, even where not yet strictly mandated.
  • Independent reviews are often used where the risk profile and complexity are moderate and limited assurance is sufficient.

Larger or more complex entities / groups

  • PIS at 350 or above, or other legislative triggers.
  • Statutory audits become mandatory, often combined with additional reporting, for example to group auditors or regulators.

The key is to understand both your legal requirements and your stakeholders’ expectations.

What you actually get from each service

Compilation: useful but no comfort

With a compilation, you get:

  • Financial statements prepared in line with the chosen framework.
  • No assurance regarding whether the underlying records are complete, accurate or free from material misstatement.

This can be acceptable for very small, owner-managed entities, but offers limited comfort to banks or external investors.

Independent review: limited assurance with focused procedures

With an independent review, you receive:

  • An independent assessment based primarily on inquiries and analytical procedures.
  • A written report expressing limited assurance that nothing has come to the reviewer’s attention to indicate that the financial statements are not fairly presented.
  • A level of comfort that is higher than a compilation but lower than an audit.

This is designed to be a more cost-effective, less onerous form of assurance for entities that do not require a full audit but still want independent scrutiny.

Audit: reasonable assurance and deeper insight

With an audit, you can expect:

  • A comprehensive risk-based approach that includes understanding the business, assessing internal controls and performing substantive tests of transactions and balances.
  • An audit opinion stating whether the financial statements present fairly, in all material respects.
  • Often, a separate report to management on internal control observations and process improvements identified during the engagement.

This level of assurance is generally expected by larger stakeholders, complex groups, regulated entities and companies with higher PIS.

How to decide what is appropriate for your SME

Start with legal and regulatory requirements

First, determine what the Companies Act and any sector-specific laws require for your entity, taking into account:

  • Your latest PIS.
  • Whether your annual financial statements are compiled internally or independently.
  • Any specific provisions in your Memorandum of Incorporation or shareholder agreements.
  • Whether you fall into categories, such as public or state-owned companies, that always require an audit.

A registered auditor or other suitably qualified professional can help you interpret these rules correctly.

Consider stakeholder expectations

Even where the Act does not mandate a particular level, stakeholders may have their own expectations:

  • Banks may require an independent review or audit as part of lending conditions.
  • Investors or shareholders may prefer a higher level of assurance.
  • Group reporting may require audited figures for consolidation.

It can be useful to discuss the options with those stakeholders before deciding.

Factor in your risk, complexity and growth plans

Finally, think about:

  • The complexity of your operations and financial reporting.
  • The scale and nature of your risks, for example cash-intensive operations, significant estimates or complex funding.
  • Where you expect the business to be in three to five years.

Some entities voluntarily move from compilation to review or from review to audit earlier than required because the additional discipline and insight support their growth and governance goals.

Frequently asked questions

Is an independent review “less professional” than an audit?

No. Both are conducted under recognised assurance standards and require appropriate expertise. The difference lies in the scope of work and the level of assurance: an audit provides reasonable assurance with more extensive procedures, while an independent review provides limited assurance based mainly on inquiries and analytical procedures.

Can we switch from an audit to an independent review if our PIS decreases?

In some cases this may be possible, provided you still meet the criteria for a review and there are no contractual or governance reasons to retain the audit. Any such change should be discussed carefully with your auditor, board and key stakeholders, considering both compliance and perceptions of transparency.

Who may perform an independent review?

For many companies, the reviewer must be a registered auditor or a member of a professional body accredited in terms of the Auditing Profession Act, who is not involved in compiling the same financial statements. Independence requirements apply even at the review level.

How often should we reassess our assurance level?

At minimum, your PIS and assurance requirements should be revisited annually when you finalise your financial statements. It is also sensible to reassess when there are major changes in ownership, financing, size, structure or regulatory environment.

auditors cape town choose the right firm

Appointing an auditor is a serious decision for any Cape Town business, because it directly affects the credibility of your financial information and the confidence of your stakeholders. In South Africa, audits are regulated by the Auditing Profession Act and overseen by the Independent Regulatory Board for Auditors (IRBA).

This guide is designed to help you think through the key questions when you choose an audit firm, in a practical, non-technical way.

Why your choice of auditor matters

Supporting trust and compliance

Your auditor provides independent assurance on your financial statements, which supports trust between you and parties such as shareholders, lenders, potential investors and tax authorities.

A well-planned, properly executed audit helps to:

  • Confirm that your financial statements are prepared in line with the applicable framework.
  • Provide stakeholders with confidence that material misstatements are less likely to go unnoticed.
  • Support smoother conversations with banks, prospective investors and other decision-makers.

Helping you understand your business better

In addition to the audit opinion, the process often highlights practical matters that management can act on, for example:

  • Areas where documentation and record keeping can be improved.
  • Control weaknesses that increase the risk of errors or fraud.
  • Opportunities to simplify processes and make year-end less disruptive.

When you appoint an auditor, you are not only appointing someone to sign a report; you are appointing a team that will work closely with your finance function and governance structures for a number of years.

Key requirements and non-negotiables

IRBA registration and independence

Only registered auditors may perform statutory audits in South Africa, and their conduct is regulated by the IRBA Code of Professional Conduct and related rules.

When you evaluate potential firms, it is sensible to confirm:

  • That the firm is registered with IRBA.
  • Who the engagement partner will be, and that this person is a registered auditor.
  • That there are no independence issues that would prevent the firm from accepting the engagement.

You can request IRBA registration details and verify them if you wish.

Relevant experience and understanding of your environment

Different entities face different risks and reporting challenges, depending on their industry, size and structure. It is therefore helpful to understand:

  • Whether the firm has experience with entities similar to yours (for example SMEs, NPOs, professional practices, property entities or groups).
  • Whether the team is familiar with the frameworks and regulations that apply to your circumstances.
  • How they approach engagements where there are resource constraints or legacy issues in the finance function.

Asking for examples, at a high level, of the types of entities they serve can give you a good sense of this.

Approach to quality and partner involvement

Audit firms are required to operate quality management systems in line with standards such as ISQM, which govern how engagements are planned, supervised and reviewed.

Useful questions to ask include:

  • How involved will the engagement partner be during planning, fieldwork and reporting?
  • How are technical questions and judgments handled within the firm?
  • How does the firm ensure that work is properly reviewed before an opinion is issued?

The aim is to understand how the firm maintains a consistent level of audit quality across its client base.

Practical questions to ask potential auditors

When you meet with potential auditors in Cape Town, the following questions can help you assess whether there is a good fit.

Scope, timing and interaction with your team

  • What is the proposed scope of the engagement?
  • How will you plan the timeline from pre-planning to signing the report?
  • Will the work be performed on-site, remotely or a combination of both?
  • What information and preparations do you expect from our team before fieldwork starts?

Clear answers here help both sides to plan properly and reduce year-end pressure.

Fees and underlying assumptions

Audit fees are influenced by factors such as the size and complexity of the entity, the state of the records, and the risk assessment performed by the auditor.

You may wish to clarify:

  • Whether the quote is fixed or time-based.
  • What assumptions the fee is based on (for example, reconciliations up to date, no significant prior adjustments).
  • Under what circumstances the fee might need to be revisited.

This helps to ensure that there is a shared understanding of expectations from the outset.

Communication of findings and recommendations

It is important to know how the firm will communicate with you during and after the audit:

  • How are issues raised with management during the engagement?
  • Will you receive a written report on internal control or process findings, in addition to the opinion?
  • Will the auditor attend board or audit committee meetings to discuss the results, if applicable?

Good communication promotes a constructive relationship and supports continuous improvement.

Points to consider when appointing or changing an audit firm

Understanding significantly different fee quotes

If one quote is substantially higher or lower than others, it may not necessarily be a problem, but it is useful to understand why. You can ask each firm to explain:

  • How many hours they expect to spend on the engagement.
  • The level of staff they will use.
  • The work they intend to perform in key risk areas.

Because audits must comply with professional standards, there is a minimum amount of work that needs to be done on any engagement, and the fee should realistically allow for that.

Accessibility and working style

For Cape Town entities, it can be beneficial to work with a firm that has a clear plan for understanding your operations, whether they are physically located in Cape Town or elsewhere.

Consider:

  • How easy it is to schedule discussions with the partner and team.
  • Whether meetings will be in person, online, or a mix of both.
  • Whether their proposed working style suits your organisation’s culture and the way your finance team operates.

Clarity of proposals and responsiveness

The way a firm responds during the proposal stage can provide insight into how the working relationship might feel later on. You can pay attention to:

  • How clearly the proposal describes scope, timelines and deliverables.
  • How promptly and clearly they respond to follow-up questions.
  • Whether they provide the information you need to brief your board or owners.

These are neutral indicators of fit, rather than judgments about quality.

How a Cape Town-based registered audit firm can support you

Many Cape Town audit practices with an SME focus aim to offer a combination of local understanding and robust audit methodology.

Typically, you can expect:

  • A registered audit partner who takes responsibility for the engagement.
  • A team that understands local operating conditions, regulatory requirements and banking practices.
  • A structured approach to planning, fieldwork and reporting that is designed to minimise disruption and add insight where possible.

When you evaluate options, you can ask each firm to explain how they deliver on these aspects in practice.

Frequently asked questions

Do all companies in South Africa need an audit?

Not all companies require a statutory audit; the requirement depends on factors such as the public interest score, the nature of the entity and regulatory or contractual obligations. Your auditor or another suitably qualified professional can help you determine what is required in your specific situation.

How long does an audit usually take?

The overall timeline depends on the size and complexity of the entity, the state of the accounting records and how early planning starts. Many firms encourage early engagement so that key risks and information needs can be identified before year-end.

Can we change auditors, and what is involved?

Companies can change auditors, subject to applicable legal and governance requirements. The process typically includes appointing the new auditor in line with your constitution or shareholder agreements, notifying the previous auditor, and complying with professional communication requirements between auditors.

Should we use a firm that is based in Cape Town?

There is no strict requirement to use a firm in your city, but many entities find it practical to work with a team that has a clear, workable plan to understand their operations, whether through local presence, site visits, or structured remote procedures.

Company Tax Submission Guide for South African Businesses

Running a business means juggling deadlines. Miss your tax submission date, and you’re looking at penalties that eat into your profit. Here’s what every company director needs to know about SARS deadlines.

The 12-Month Rule

Companies and Pty Ltd entities have 12 months from financial year-end to submit their ITR14. Year-end February 2026? Your return is due by February 2027.

​Year-end-February 2025? Your return is due NOW – February 2026

This sounds generous, but provisional tax creates pressure points throughout the year.

Provisional Tax: The Real Deadlines

You’ll submit IRP6 returns at three intervals:

  1. First payment – 6 months after year-end start
  2. Second payment – At year-end (critical deadline)
  3. Third payment – Optional top-up within 6 months

The second payment carries the highest risk. Under-estimate by more than 10-20%, and SARS applies a 20% penalty on the shortfall.

Penalty Structure

Late submissions trigger recurring monthly penalties ranging from R250 to R16,000, depending on taxable income. These accumulate for up to 35 months.

File more than 4 months late? SARS treats it as a nil return, triggering under-estimation penalties even if you owe tax.

What You Need

Before submitting your ITR14:

  • Completed annual financial statements
  • Reconciled provisional tax payments
  • Updated public officer details on eFiling
  • Supporting documentation for deductions

Take Action Now

Don’t wait until month 11. Engage your accountant early, ensure your books are current, and plan for provisional tax throughout the year.

Need help with your company tax returns?

Frequently Asked Questions

What is the deadline for corporate tax submissions in South Africa?
The South African corporate tax deadline depends on the company’s financial year end. Generally, annual returns and tax submissions must be filed within 12 months of the financial year end, though specific deadlines vary. Provisional tax payments are due twice a year, typically six months into the financial year and then shortly after year end.

What happens if I miss the tax submission deadline?
Missing the deadline can result in penalties, interest on unpaid taxes, and potential compliance reviews from SARS. SARS applies automatic penalties for late submission and late payment, which can accumulate quickly. It is important to engage with SARS proactively if you anticipate missing a deadline.

What documents do I need for company tax submission?
You will need your company’s annual financial statements, tax computation, details of provisional tax payments made, supporting schedules for deductions and allowances, and IRP6 provisional tax returns. Having organised records throughout the year makes the submission process significantly smoother.

Can I submit my company tax return myself or do I need an accountant?
While company directors can submit returns via eFiling themselves, most businesses engage a registered accountant or tax practitioner. A professional ensures the return is accurate, all allowable deductions are claimed, and compliance with current tax legislation is maintained, reducing the risk of queries or audits from SARS.

How can I reduce my company’s tax liability legitimately?
Legitimate tax planning includes timeous provisional tax payments, claiming all allowable business expenses and deductions, making retirement annuity contributions, and structuring capital expenditure correctly. Working with a tax professional year-round (not just at submission time) helps identify legitimate savings opportunities.

Contact SC Audit for Assistance.

Audit quality isn’t just a concern for regulators and audit firms — it directly impacts your business.
A high-quality audit protects your organisation from financial, operational, and reputational risks.
A poor-quality audit can do the opposite, exposing you to errors, missed risks, and compliance issues.

Here’s why audit quality matters, and how choosing the right audit partner helps your business stay secure.


1️⃣ Detecting Errors and Irregularities

A high-quality audit ensures that financial statements are:

  • Accurate
  • Complete
  • Free from material misstatement

This protects you from unnoticed:

  • Accounting mistakes
  • Fraud
  • Unreconciled balances
  • Misclassifications
  • Inaccurate valuations

These issues can create long-term financial damage if left unaddressed.


2️⃣ Protecting Your Reputation

Your financial statements are used by:

  • Banks
  • Investors
  • Donors
  • Regulators
  • Stakeholders

A reliable audit builds trust.
A low-quality one raises doubts, delays funding, and harms credibility — sometimes permanently.


3️⃣ Supporting Better Management Decisions

High-quality audits identify trends and insights management can use, such as:

  • Cash flow pressures
  • Expense inefficiencies
  • Revenue inconsistencies
  • Asset risks
  • Control weaknesses

These insights help leaders make informed decisions grounded in accurate data.


4️⃣ Ensuring Regulatory Compliance

In South Africa, IRBA holds firms to strict auditing standards.
A strong auditor ensures your business complies with:

  • Companies Act
  • IFRS / IFRS for SMEs
  • Governance requirements
  • Stakeholder expectations

Compliance isn’t optional — poor compliance risks legal exposure.


5️⃣ Strong Internal Controls Improve Performance

High-quality auditors evaluate your internal controls and highlight weaknesses such as:

  • Unauthorised approvals
  • Poor segregation of duties
  • Weak access controls
  • Inadequate documentation
  • Lack of oversight

Fixing these issues improves efficiency, reduces fraud risk, and strengthens financial health.


6️⃣ SC Audit’s Commitment to Quality

We prioritise:

  • Independence
  • Professional scepticism
  • Up-to-date audit methodologies
  • Continual staff training
  • Robust review processes
  • Clear, transparent communication

Quality isn’t just a checklist — it’s a commitment to protecting our clients.


Conclusion

Audit quality directly affects the health and future of your business.
Choosing a high-quality, ethical audit partner is one of the most important financial decisions you can make.

Contact SC Audit to learn more about our approach to exceptional audit service.

Frequently Asked Questions

What is audit quality and why does it matter?
Audit quality refers to how thoroughly and independently an audit is conducted in accordance with International Standards on Auditing (ISA). It matters because a quality audit gives stakeholders confidence that financial statements are accurate and free from material misstatement, protecting investors, creditors, and the broader public.

How can I tell if my audit firm is delivering quality work?
Signs of a quality audit include clear communication throughout the engagement, a demonstrated understanding of your business, professional scepticism in testing assumptions, timely reporting, and a willingness to explain findings in plain language. The firm should also have robust internal quality controls and be IRBA-registered.

What happens if an audit is of poor quality?
Poor audit quality can lead to undetected errors or fraud in financial statements, regulatory penalties for both the auditor and the company, reputational damage, and loss of stakeholder trust. In serious cases, IRBA may investigate and impose sanctions on the audit firm.

Does a higher audit fee guarantee better audit quality?
Not necessarily. While adequate fees are needed to resource a proper audit, a higher fee does not automatically mean higher quality. What matters is how the firm allocates resources, the experience of the team, and the rigour of their methodology. Quality depends on people and process, not price alone.

How does SC Audit ensure audit quality?
SC Audit maintains quality through ongoing professional training for all staff, compliance with ISQM (International Standards on Quality Management), independent engagement reviews, and direct partner involvement on every audit. The firm is IRBA-registered and accredited as a SAICA training office, subject to regular external inspections.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Many businesses only think about their audit after the financial year ends — but that’s when problems surface.
Year-end planning is one of the most important steps to ensuring a smooth, efficient audit with minimal stress, lower fees, and fewer findings.

Here’s how proper planning can transform the entire audit experience and the key steps SMEs should follow long before the auditors arrive.


1️⃣ Why Year-End Planning Matters

Good planning helps organisations:

  • Avoid last-minute scrambling
  • Reduce audit adjustments
  • Improve accuracy of financial statements
  • Prevent delays
  • Lower audit costs
  • Build trust with auditors

It’s one of the simplest ways to improve audit quality.


2️⃣ Reconcile Early — Don’t Wait

Key balances should be up to date before year-end, including:

  • Bank reconciliations
  • Debtors and creditors
  • VAT accounts
  • Payroll
  • Inventory
  • Loan accounts

Leaving reconciliations to the last minute creates unnecessary risk and extra work.


3️⃣ Prepare Supporting Documentation

Auditors rely on clear, accessible evidence.
Make sure you have:

  • Signed contracts
  • Supplier invoices
  • Customer statements
  • Bank statements
  • Inventory sheets
  • Fixed asset registers
  • Board minutes
  • Payroll records

Organised documents speed up the entire audit.


4️⃣ Review Significant Judgements and Estimates

Management often needs to make estimates for:

  • Provisions
  • Bad debts
  • Depreciation
  • Fair values
  • Inventory write-downs

Documenting your reasoning in advance demonstrates good governance — and makes audit discussions easier.


5️⃣ Resolve Issues Before the Audit

If you’re aware of:

  • Accounting errors
  • System migration issues
  • Missing documentation
  • Unusual transactions

…it’s better to address them before the audit starts.
SC Audit offers pre-audit readiness checks to help clients identify risks early.


6️⃣ Communicate Changes

Auditors need to know about:

  • New systems
  • New management
  • Policy changes
  • Major transactions
  • Funding agreements
  • New entities or subsidiaries

The more information shared upfront, the fewer surprises later.


Conclusion

Year-end planning isn’t optional — it’s the foundation of an efficient audit process and quality financial reporting.
A few proactive steps can save time, reduce stress, and improve assurance.

SC Audit offers year-end planning and readiness sessions to help you prepare with confidence.

Frequently Asked Questions

When should I start preparing for my year-end audit?
Ideally, preparation should begin at least three to four months before your financial year end. This gives your team time to reconcile accounts, gather supporting documentation, and address any discrepancies before the auditors arrive. Early preparation reduces stress and helps avoid costly delays.

What documents should I prepare for the audit?
Key documents include trial balance, bank reconciliations, fixed asset registers, debtors and creditors age analysis, payroll records, VAT201 returns, tax computations, board minutes, and any contracts or agreements relevant to the financial period. A detailed request list from your auditor well in advance is standard practice.

How can I make the audit process faster and more efficient?
Ensure your accounting records are up to date, reconciliations are completed, and all supporting documents are organised before the audit starts. Assign a point person to coordinate with the audit team, and respond to queries promptly. A clean trial balance and well-prepared schedules save significant time.

What are the most common year-end mistakes businesses make?
Common mistakes include leaving reconciliations until the last minute, misclassifying expenses, overlooking intercompany transactions, failing to accrue for known liabilities, and incomplete fixed asset registers. Poor record-keeping throughout the year is the underlying cause of most year-end issues.

Can SC Audit help with year-end planning before the audit starts?
Yes. SC Audit offers pre-audit readiness sessions to help businesses prepare. The team reviews your financial position, identifies potential issues, and provides a tailored checklist so you enter the audit process organised and confident. Contact SC Audit to schedule a readiness session.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Internal controls aren’t just for big corporations.
Even the smallest businesses need strong controls to protect assets, prevent fraud, and ensure reliable financial reporting.
Without them, companies expose themselves to unnecessary risk — and often don’t realise the danger until it’s too late.

Here’s why internal controls matter and how SMEs can strengthen theirs quickly and cost-effectively.


1️⃣ What Are Internal Controls?

Internal controls are the policies, procedures, and systems that help ensure:

  • Accurate financial reporting
  • Protection of company assets
  • Prevention of fraud
  • Operational efficiency
  • Compliance with laws and regulations

They form the foundation of responsible governance.


2️⃣ Why Weak Internal Controls Are Dangerous

Poor controls lead to issues such as:

  • Cash theft
  • Duplicate or fake payments
  • Misstated financials
  • Unauthorised spending
  • Fraud by employees or suppliers
  • Difficulty during audits
  • Lost revenue from errors

Many fraud cases occur because “one person handled everything.”


3️⃣ Internal Control Essentials for SMEs

You don’t need a big finance team to have effective controls.
Start with these basics:

✔ Segregation of duties
Separate responsibilities for:

  • Approving payments
  • Capturing invoices
  • Releasing funds

✔ Regular reconciliations
Bank, VAT, debtors, and creditors should be reconciled monthly.

✔ Documented policies and procedures
Simple written guidelines help staff follow consistent processes.

✔ Authorisation limits
Set clear approval levels for purchases, payments, and contracts.

✔ Access controls
Restrict access to accounting systems based on roles.

✔ Physical asset protection
Track equipment, stock, and company assets using registers.


4️⃣ How Internal Controls Support Audit Readiness

Good controls reduce audit risks and improve the accuracy of your financials.
This leads to:

  • Faster audits
  • Lower costs
  • Fewer findings
  • Stronger confidence from stakeholders

Internal controls are the auditor’s first indicator of financial health.


5️⃣ SC Audit’s Approach to Internal Control Improvement

We don’t only identify control weaknesses — we help businesses strengthen them with:

  • Practical recommendations
  • Prioritised action plans
  • Templates for policies and procedures
  • Walkthroughs of key financial cycles
  • Mid-year control health checks

SMEs benefit from simple, affordable improvements that make a major difference.


Conclusion

Effective internal controls protect your business, improve reporting accuracy, and support healthy growth.
They’re not a luxury — they’re essential.

Want to strengthen your internal controls? Contact SC Audit to book an internal control assessment tailored to your business.

Frequently Asked Questions

What are internal controls and why do small businesses need them?
Internal controls are processes and procedures that safeguard assets, ensure accurate financial reporting, and promote operational efficiency. Small businesses need them just as much as large corporations because they prevent errors, deter fraud, and provide reliable information for decision-making.

What are examples of simple internal controls a small business can implement?
Examples include separating the roles of who authorises payments and who processes them, requiring dual approval for large transactions, regular bank reconciliations, maintaining a fixed asset register, using password-protected accounting software, and conducting periodic inventory counts.

How do internal controls affect my audit?
Strong internal controls make the audit process smoother and more cost-effective. Your auditor can rely on your controls, reducing the amount of detailed testing needed. Weak controls, on the other hand, require more extensive substantive testing, which can increase audit time and fees.

What is segregation of duties and why is it important?
Segregation of duties means dividing key financial tasks among different people so no single person has complete control over a transaction from start to finish. For example, the person who orders goods should not be the same person who approves payment. This reduces the risk of errors and fraud.

How can SC Audit help me improve my internal controls?
SC Audit offers internal control assessments tailored to businesses of all sizes. The team reviews your existing processes, identifies weaknesses, and provides practical recommendations to strengthen controls without adding unnecessary administrative burden.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Most companies view audits as a legal obligation — something to “get through” every year.
But an audit done well provides far more than a signed report.

In fact, audits offer some of the most valuable insights a business can receive, often uncovering opportunities for growth, risk reduction, and operational improvement.
Here’s how an audit can quietly strengthen your business behind the scenes.


Better Financial Controls and Fraud Prevention

Auditors examine internal controls — the policies and processes that safeguard your assets.
During this process, they often identify:

  • Weak segregation of duties
  • Unauthorised access to accounting systems
  • Duplicate or suspicious transactions
  • Gaps in oversight that expose the business to fraud

A strong control environment protects your business from financial loss and reputational damage.


Insights Into Operational Efficiency

Auditors frequently spot inefficiencies that management may overlook, such as:

  • Manual processes that could be automated
  • Inventory wastage
  • Delays in approvals
  • Poor workflow structures

These insights can streamline operations, reduce costs, and improve team accountability.


Improved Credibility With Stakeholders

An independent audit reassures:

  • Investors
  • Banks
  • Donors
  • Partners
  • Regulators

It confirms your financials are reliable and free from material misstatement.
This credibility can help secure funding, negotiate better supplier terms, or attract strategic partners.


Strategic Insights From Trend Analysis

Auditors analyse revenue patterns, cost movements, cash flow, and ratios year over year.
These trends can reveal:

  • Emerging risks
  • Profitability issues
  • Cost overruns
  • Liquidity pressure
  • Growth opportunities

Think of your audit as a snapshot of your business’s financial health.


A Roadmap for Future Improvements

SC Audit provides management letters that include:

  • Practical recommendations
  • Priority ranking of issues
  • Suggested process improvements
  • Guidance for next year’s audit readiness

This roadmap helps your business build stronger systems over time.


Conclusion

An audit is much more than compliance — it’s an investment in your organisation’s stability, performance, and long-term vision.
When done right, it becomes one of the most valuable annual exercises a business can undertake.

Book a consultation with SC Audit to discover the real value behind the numbers.

Frequently Asked Questions

What are the non-compliance benefits of having an audit?
Beyond meeting legal requirements, an audit provides valuable insights into business operations, identifies inefficiencies, strengthens internal controls, and enhances credibility with banks, investors, and suppliers. It gives business owners confidence that their financial information is reliable for strategic decision-making.

Can an audit help my business get funding?
Yes. Audited financial statements carry significantly more weight with banks, investors, and lenders. They provide independent assurance that your financial position is accurately presented, reducing the lender’s risk and often improving your chances of securing finance at favourable terms.

How does an audit improve internal processes?
During an audit, auditors review your internal controls and processes. Their recommendations often highlight areas where efficiencies can be gained, risks mitigated, and reporting improved. Many businesses implement audit recommendations and see measurable operational improvements as a result.

What is the difference between an audit and a review?
An audit provides the highest level of assurance, with detailed testing of balances, transactions, and controls. A review provides limited assurance through inquiry and analytical procedures only. An audit is required by law for certain entities, while a review is a lower-cost alternative for qualifying companies.

Is an audit worth the cost for a small business?
If your business needs an audit by law, the question is about getting value from it. A well-conducted audit provides actionable insights, improves credibility, and can reduce future compliance costs. The key is choosing an audit firm that treats the engagement as a value-add exercise, not just a compliance box-tick.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

For many South African businesses, poor record keeping isn’t just an inconvenience — it’s one of the biggest risks to financial stability, compliance, and audit readiness.
From missed tax deadlines to unreconciled accounts, small lapses compound into big problems.

Here’s what every SME needs to know about the consequences of weak record keeping — and how to fix it before it affects your bottom line.


It Increases Your Audit (and Accounting) Costs

When your books aren’t clean, auditors spend more time verifying transactions, correcting discrepancies, and chasing documents.
More time = more fees.

Common cost drivers:

  • Missing supplier invoices
  • Outdated or inconsistent ledgers
  • Manual journals with no explanations
  • Poor bank reconciliations

Clean records can reduce audit fees by up to 30% — simply because the audit becomes more efficient.


It Creates Tax Risks With SARS

SARS is increasing its use of data analytics to identify inconsistencies in VAT, payroll, and income tax filings.
Poor records can lead to:

  • SARS audits
  • Penalties and interest
  • Delayed refunds
  • Additional documentation demands

With proper record keeping, you’ll have the evidence to support every return.


It Prevents You From Making Smart Business Decisions

You can’t manage what you can’t measure.
Inaccurate or incomplete financials make it difficult to:

  • Track profitability
  • Forecast cash flow
  • Secure funding from banks
  • Manage debt, stock, or payroll obligations

Good records = better decisions = stronger business performance.


It Damages Trust With Investors and Stakeholders

Whether you’re dealing with lenders, shareholders, donors, or board members, financial transparency is everything.
Messy financials erode confidence and create doubt about leadership and governance.


How SMEs Can Fix Record-Keeping Problems Fast

  • Move to cloud accounting (Xero, Sage, QuickBooks)
  • Reconcile bank accounts monthly
  • Keep clean supporting documents (scanned or digital is fine)
  • Standardise naming conventions for files
  • Work with a professional accountant throughout the year
  • Request a mid-year mini-audit to identify issues early

Conclusion

Poor record keeping is expensive — but preventable.
Strengthen your systems today to avoid financial surprises tomorrow.

Need help cleaning up your records or preparing for audit? Contact SC Audit for a pre-audit readiness assessment.

Frequently Asked Questions

What are the most common record-keeping mistakes SMEs make?
Common mistakes include mixing personal and business transactions, failing to reconcile bank accounts regularly, losing receipts and invoices, inconsistent categorisation of expenses, and neglecting to back up accounting data. These errors compound over time and create significant problems during audit and tax season.

How long must I keep financial records in South Africa?
The Companies Act requires records to be kept for at least seven years from the date of the last entry. SARS also requires tax-related records to be retained for five years from the date of assessment. Certain documents, such as property transaction records, should be kept indefinitely.

Can poor record keeping trigger a SARS audit?
Yes. Inconsistent, incomplete, or contradictory financial records can raise red flags with SARS and trigger a verification or audit. SARS expects taxpayers to maintain accurate and complete records that support their tax returns. Poor records make it difficult to demonstrate compliance and may lead to additional taxes and penalties.

What digital tools can help with record keeping?
Cloud-based accounting software like QuickBooks, Xero, or Sage makes it easy to track transactions, automate reconciliations, and store receipts digitally. Document management systems, receipt scanning apps, and integrated payroll solutions also help maintain organised records throughout the year.

How can SC Audit help me get my records in order?
SC Audit offers record-keeping assessments and practical guidance to help SMEs establish efficient financial record systems. The team can review your current processes, recommend improvements, and help you prepare for a smoother audit or tax season.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

If you’ve ever wondered what auditors really do, how long audits take, or whether you even need one — you’re not alone.
Clients often come to us with similar questions, so we’ve compiled some of the most common ones, along with straightforward answers from our audit team.

“Do I really need an audit?”

That depends on your business structure and size.
In South Africa, audits are legally required for:

  • Public companies (Ltd).
  • Private companies that meet public interest score (PIS) thresholds.
  • Certain non-profits, schools, and organisations receiving public funds.

Even if not required, many SMEs choose audits voluntarily for credibility with investors, banks, or funders.

“How long does an audit take?”

It varies by size and complexity, but most audits take 2–6 weeks from planning to final report.
You can speed up the process by:

  • Having your reconciliations, supporting documents, and trial balance ready.
  • Responding promptly to auditor requests.
  • Keeping consistent communication throughout.

“What’s the difference between an audit and an independent review?”

An audit provides the highest level of assurance — auditors examine detailed evidence and test controls.
An independent review is limited assurance — the reviewer mainly performs analytical and inquiry procedures.
If stakeholders require confidence and compliance, an audit is usually the preferred option.

“What happens if the auditor finds mistakes?”

Small errors are corrected during the audit process.
If material misstatements exist, auditors will discuss them with management and allow adjustments before finalising the report.
The goal isn’t to “catch you out” — it’s to ensure financial statements are fair and reliable.

“How much does an audit cost?”

Fees depend on your company’s size, systems, and complexity.
However, efficient preparation can reduce time (and cost).
SC Audit offers transparent pricing and pre-audit planning sessions so clients know exactly what to expect.

“How can I make my next audit easier?”

  • Keep records up to date throughout the year.
  • Use cloud accounting tools like Xero or Sage for cleaner data.
  • Communicate changes (ownership, systems, policies) early.
  • Ask your auditor for a pre-year-end readiness review.

Conclusion

The best audits are collaborative — built on clear communication, preparation, and mutual understanding. At SC Audit, we believe informed clients make the strongest audit partners.

Still have questions? Contact the SC Audit team – we’re always happy to offer advice or schedule a free consultation.

Frequently Asked Questions

How do I know if my company needs a statutory audit or an independent review?
The requirement depends on your company’s Public Interest Score (PIS). A PIS of 350 or above requires a statutory audit. A PIS between 100 and 349 requires an independent review. Below 100 may allow internally compiled financial statements, depending on your company’s Memorandum of Incorporation.

How long does an audit typically take from start to finish?
Most SME audit engagements are completed within 4 to 8 weeks of receiving complete documentation. The timeline depends on business complexity, the quality of records provided, and the time of year. SC Audit provides a detailed timeline at the start of every engagement.

What does an auditor actually do during an audit?
The auditor plans the engagement, assesses risk, tests internal controls, verifies account balances and transactions, reviews supporting documentation, and forms an opinion on whether the financial statements are fairly presented. This involves both on-site work at your premises and off-site analysis.

Can I prepare my own financial statements or does the auditor do that?
Auditors cannot prepare the financial statements they audit, as this would compromise independence. Your company or a third-party accountant must prepare the financial statements. The auditor then audits those statements to form an independent opinion.

What happens if the auditor finds errors or issues during the audit?
The auditor will discuss findings with management as they arise, propose adjustments, and request corrections. Most issues are resolved before the audit is finalised. If material errors persist, the auditor may issue a qualified opinion or include an emphasis of matter in the audit report.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Auditing has come a long way from piles of paper and manual checklists. Today’s top firms use advanced data analytics, automation, and cloud collaboration tools to deliver faster, smarter, and more transparent audits.

At SC Audit, technology isn’t replacing people — it’s empowering our professionals to focus on insight, not admin. Here’s how digital transformation is reshaping the audit experience for South African businesses.

Automation That Reduces Errors and Saves Time

Modern audit software automates repetitive tasks like data extraction, sampling, and document matching. This means fewer manual errors, quicker turnarounds, and more reliable results.

Example: Instead of manually checking hundreds of invoices, our tools scan and reconcile them automatically — freeing our auditors to focus on deeper analysis.

Data Analytics for Smarter Insights

Advanced analytics allow us to review entire populations of transactions, not just samples.
This gives clients a clearer picture of:

  • Trends or anomalies in revenue and expenses.
  • Duplicate or unusual transactions.
  • Risk concentrations by supplier, region, or department.

📊 The result? A more data-driven audit that helps management make informed, evidence-based decisions.

Cloud Collaboration for Seamless Communication

Gone are the days of endless email chains and USB drives. With secure cloud portals, clients can upload documents, track audit progress, and respond to queries in real time — wherever they are.

This approach improves transparency, efficiency, and data security while cutting down audit timelines significantly.

Cybersecurity and Data Protection

With great tech comes great responsibility. SC Audit follows strict data-protection protocols aligned with POPIA (Protection of Personal Information Act) to keep client information safe.

We use encrypted communication, secure document storage, and robust access controls to protect sensitive data throughout the audit process.

The Human Touch Still Matters

While technology enhances accuracy, it’s still the experience, judgement, and integrity of auditors that make the difference. At SC Audit, we use digital tools to empower — not replace — the professional insight our clients rely on.

Conclusion

Technology is redefining what clients can expect from an audit: faster delivery, deeper insights, and greater transparency. But the real value lies in how these tools enable stronger partnerships and smarter business decisions.

Contact SC Audit to learn how our digital audit solutions can transform your next engagement.

Frequently Asked Questions

How is technology changing the audit profession?
Technology is transforming audits through data analytics, automation of routine testing, and AI-assisted anomaly detection. Auditors can now analyse entire datasets rather than samples, identify patterns and outliers faster, and focus more on risk assessment and professional judgement rather than manual tick-and-check procedures.

Do I need to provide digital data to my auditor?
Yes. Modern audits rely on extracting data directly from your accounting systems. Most firms provide secure portals or direct integrations to receive general ledger data, trial balances, and supporting schedules in digital format. This reduces errors from manual data entry and speeds up the audit process.

What is data analytics in auditing?
Data analytics involves using software to examine complete sets of financial data for trends, anomalies, and exceptions. Instead of testing a sample of transactions, auditors can review 100% of transactions in areas like revenue, payments, and journal entries, providing significantly deeper assurance.

Will AI replace auditors in the future?
AI will transform how auditors work, but is unlikely to replace professional judgement and scepticism. AI excels at processing large volumes of data and identifying patterns, but cannot replace the human ability to understand context, exercise judgement, and build trusted client relationships. The role evolves toward higher-value analysis.

Does SC Audit use technology in its audit process?
Yes. SC Audit leverages modern audit tools and data analytics to enhance audit quality and efficiency. The firm invests in technology that allows the team to focus on areas of higher risk and deliver more insightful findings, while maintaining the personal service and partner involvement that clients value.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Hearing that your audit has “deficiencies” can sound alarming — but it’s not always bad news. In fact, most deficiencies are opportunities to strengthen your processes and build credibility with stakeholders.

Let’s unpack what an audit deficiency really means, why it happens, and how SC Audit helps clients turn findings into value.

What Is an Audit Deficiency?

An audit deficiency occurs when the evidence or documentation supporting a transaction, control, or disclosure is incomplete, inconsistent, or missing.
Examples include:

  • Missing signed agreements or invoices.
  • Weak segregation of duties.
  • Unreconciled balances.
  • Outdated accounting policies or manual errors.
  • Deficiencies don’t always imply wrongdoing — often they reveal process or oversight gaps.

Common Causes for audit deficiencies

  • Rushed year-end closings that skip reconciliations.
  • Poor documentation culture (no signed minutes, incomplete audit trail).
  • High staff turnover, leading to knowledge loss.
  • System migrations where historical data isn’t properly validated.

Why You Shouldn’t Panic

A good audit identifies issues early — before they escalate into compliance breaches or financial losses.
Addressing findings promptly demonstrates management accountability and builds investor confidence.

🛠️ Remember: The goal of an audit is continuous improvement, not punishment.

How to Respond to Audit Findings

  1. Review each finding calmly and understand its root cause.
  2. Assign responsibility — who will correct or monitor the issue?
  3. Set a timeline for corrective action and follow up with your auditor.
  4. Update policies or controls to prevent recurrence.
  5. Communicate improvements to your board, funders, or stakeholders.

SC Audit’s Approach to Continuous Improvement

We see audit findings as value-creation moments.
Our reports include a practical Management Action Plan, helping clients prioritise fixes and measure progress before the next audit cycle. This proactive approach means fewer surprises, smoother audits, and stronger financial systems over time.

Want to turn audit findings into strategic advantage? Talk to SC Audit about our post-audit improvement program and risk health checks.

Frequently Asked Questions

What is an audit deficiency?
An audit deficiency is a finding where the audit evidence obtained does not adequately support the opinion, or where the audit was not performed in full compliance with applicable standards. Deficiencies can range from minor documentation gaps to significant failures in audit procedures.

How are audit deficiencies identified?
Deficiencies are identified through internal quality reviews within the audit firm, external inspections by IRBA, or peer reviews. They may also come to light when a company’s financial statements later prove to be misstated and the audit is reviewed retrospectively.

What happens when an audit deficiency is found?
The audit firm must investigate the root cause, implement corrective actions, and potentially re-perform affected audit areas. Deficiencies are reported to IRBA in some cases, and the firm may face regulatory follow-up. Firms use findings to improve their quality control systems.

How can I protect my business from the impact of audit deficiencies?
Choose an IRBA-registered firm with strong quality controls and a track record of clean inspections. Maintain clear communication with your auditor, ensure your records are complete, and ask questions about the audit approach. A proactive client-auditor relationship reduces risk for both parties.

Are audit deficiencies common in South Africa?
IRBA’s inspection reports show that while most audits meet acceptable standards, deficiencies are found in a minority of engagements each year. The profession is actively working to improve quality through enhanced standards like ISQM, better training, and more rigorous inspections.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Audit regulations in South Africa are becoming stricter, and not just for auditors. The Independent Regulatory Board for Auditors (IRBA) and the Companies Act place increasing responsibility on boards, directors, and management to ensure financial statements are accurate and transparent.

If you’re a business owner, board member, or finance manager, understanding your responsibilities can help avoid compliance risks — and build lasting trust with investors and regulators.

Management’s Key Responsibilities

  • Auditors don’t “own” the financial statements — management does.
    Your duties include:
  • Preparing and approving accurate financial statements that comply with IFRS or IFRS for SMEs.
  • Implementing effective internal controls to prevent misstatements or fraud.
  • Providing complete and truthful information to your auditors, including all relevant documents and explanations.
  • Assessing going concern — confirming your business can continue for the next 12 months.
  • Failing to meet these duties can delay your audit, increase costs, and in serious cases, expose directors to legal risk.

The Role of Boards and Audit Committees

Boards and audit committees serve as guardians of integrity in financial reporting.
Their responsibilities include:

  • Reviewing audit planning and scope with the auditors.
  • Overseeing management’s risk assessments and control systems.
  • Ensuring auditor independence — no conflicts of interest or undue influence.
  • Discussing findings and recommendations promptly and ensuring corrective action.

🧭 Tip: Regular board engagement with auditors (not just at year-end) leads to fewer surprises and stronger governance.

Why These Responsibilities Matter

  • Strong governance isn’t only about compliance. It builds:
  • Investor confidence: Reliable reporting attracts funding.
  • Operational discipline: Internal controls improve performance.
  • Long-term credibility: Stakeholders value transparency and accountability.

How SC Audit Supports Strong Governance

At SC Audit, we work with boards and management to clarify expectations early, helping clients establish clear audit timelines, documentation standards, and risk awareness.
We provide management letters that go beyond compliance — offering practical, actionable insights.

Are you confident your board and finance team understand their audit responsibilities? Book a governance and audit responsibility workshop
with SC Audit today.

Frequently Asked Questions

What are management’s main responsibilities in an audit?
Management is responsible for preparing and approving accurate financial statements that comply with IFRS or IFRS for SMEs, implementing effective internal controls, providing complete and truthful information to auditors, and assessing going concern. These duties cannot be delegated to the auditor.

What is the role of the board or audit committee during an audit?
Boards and audit committees review audit planning and scope, oversee management’s risk assessments and control systems, ensure auditor independence, and discuss findings and recommendations promptly. They serve as guardians of integrity in financial reporting.

How can boards prepare for rising audit standards in South Africa?
Boards can prepare by staying informed about IRBA regulatory updates, engaging with auditors regularly throughout the year (not just at year-end), reviewing internal controls proactively, and ensuring audit committees have the right expertise to challenge and support audit findings.

Can directors face personal liability for audit-related failures?
Yes. The Companies Act holds directors responsible for ensuring accurate financial records and statements. Failure to meet these duties can delay audits, increase costs, and in serious cases, expose directors to legal risk or regulatory action by CIPC or IRBA.

How does SC Audit help boards and management meet their responsibilities?
SC Audit works with boards and management to clarify expectations early, establish clear timelines and documentation standards, and provide management letters with practical, actionable insights. The firm also offers governance and audit responsibility workshops.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Audits can feel mysterious if you’ve never seen one up close. What are auditors actually looking for? How do they form an opinion? And what happens to all those documents you send?

To demystify the process, let’s go behind the scenes of a typical SC Audit engagement — showing how we work, step by step, and how each stage adds value to your business.

Step 1: Understanding Your Business

Before crunching numbers, we invest time in understanding your operations — your industry, business model, key risks, and internal processes.
This context ensures our audit plan focuses on what truly matters, not just generic checklists.

Step 2: Planning and Risk Assessment

Our audit team identifies where material misstatements could occur — whether due to error, system issues, or fraud.
We analyse prior-year results, perform analytical reviews, and meet management to discuss any big changes since the last audit.

🕵️ The goal: focus on high-risk areas and streamline low-risk sections to save time and cost.

Step 3: Fieldwork and Testing

This is where most of the action happens.
We gather and verify evidence — bank statements, supplier confirmations, inventory counts, and supporting documents.
Modern auditing tools allow us to test entire data sets, not just samples, giving better insight into potential irregularities.

Step 4: Review and Quality Control

Before signing off, engagement partners and reviewers (under ISQM 2) review the audit file for accuracy, documentation quality, and compliance with IRBA standards.
This step ensures audit quality and independence — the cornerstone of trust in financial reporting.

Step 5: Reporting and Feedback

Finally, we deliver the audit report and meet with management or the board to discuss findings.
Even if there are no misstatements, we provide management recommendations — ways to strengthen controls, streamline systems, and prepare better for next year.

What Clients Appreciate Most

  • Transparency: clear communication throughout the process.
  • Education: understanding what auditors look for (and why).
  • Partnership: practical insights, not just compliance.

Conclusion

An audit is not just a once-a-year obligation — it’s an opportunity to get an expert perspective on your financial health and business processes. At SC Audit, we see each engagement as a partnership built on trust, professionalism, and value.

Curious what an audit for your company would look like? Contact SC Audit to schedule an introductory consultation and learn more about our client-focused approach.

Frequently Asked Questions

What happens during the planning and risk assessment stage of an audit?
The audit team identifies where material misstatements could occur, analyses prior-year results, performs analytical reviews, and meets management to discuss significant changes. This stage ensures the audit plan focuses on what truly matters, saving time and cost in low-risk areas.

How does an auditor test transactions and balances during fieldwork?
Auditors gather and verify evidence including bank statements, supplier confirmations, inventory counts, and supporting documents. Modern auditing tools allow testing of entire data sets rather than just samples, giving deeper insight into potential irregularities.

What quality controls are applied before an audit is finalised?
Before signing off, engagement partners and reviewers check the audit file for accuracy, documentation quality, and compliance with IRBA standards under ISQM 2. This ensures audit quality and independence are maintained at the highest level.

What does SC Audit include in the management letter after an audit?
Even if no misstatements are found, SC Audit provides management recommendations to strengthen internal controls, streamline systems, and prepare for the next audit cycle. These practical insights add value beyond the statutory requirement.

How long does an audit engagement typically take from start to finish?
Most SME audit engagements are completed within 4 to 8 weeks of receiving complete documentation. The timeline depends on business complexity, the quality of records provided, and the time of year. Clear communication throughout ensures transparency.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

For many small and medium-sized businesses, audit season feels stressful — gathering documents, answering endless queries, and worrying about what the auditor will find.

The truth is, most audit challenges come down to preparation. With a bit of forward planning, you can save time, reduce fees, and get valuable insights from the process.

Here’s SC Audit’s simple Audit Readiness Checklist designed for South African SMEs.

Financial Records: Start with Accuracy

  • Ensure all reconciliations (bank, debtors, creditors, VAT) are up to date.
  • Verify that closing balances match your trial balance and supporting schedules.
  • Review asset registers — include purchase dates, depreciation, and disposals.
  • Double-check your inventory counts and valuation method (FIFO, weighted average, etc.).

📝 Pro Tip: Set a cut-off date at least 2–3 weeks before year-end to finalise reconciliations.

Governance & Documentation

  • Keep signed board minutes and resolutions for key decisions.
  • Retain copies of contracts, agreements, and leases — your auditors will request them.
  • Ensure policies and procedures are current (especially for revenue, payroll, and expenses).
  • If your company has external investors or lenders, ensure all loan agreements are available and signed.

Compliance Checks

  • Confirm CIPC annual returns are submitted and paid.
  • Ensure tax and VAT filings are up to date with SARS.
  • Review B-BBEE certificates, IRP5s, and PAYE reconciliations.
  • For non-profits: verify your NPO registration and donor-compliance documentation.

Communication & Planning

Appoint a single audit contact person to liaise with the audit team. Notify your auditors of any major changes (systems, ownership, restructuring, or new subsidiaries).

Provide early access to accounting systems if possible — this speeds up fieldwork.

Bonus: Year-End Readiness Timeline

Timeline – Key Action

  • 6–8 weeks before year-end – Begin reconciliations, clean up ledgers
  • 4 weeks before – Review trial balance, resolve anomalies
  • 2 weeks before – Submit pre-audit information list to auditors
  • During audit – Keep communication open; resolve queries daily
  • After audit – Review findings, plan improvements

Conclusion

Being audit-ready is not just about compliance — it’s about running a business with clarity, control, and confidence. A well-prepared audit helps management spot inefficiencies, identify risks, and attract investors or funding.

Need help preparing for your next audit? Book a pre-audit consultation with our team.

Frequently Asked Questions

What should SMEs prepare before an audit starts?
Ensure all reconciliations (bank, debtors, creditors, VAT) are up to date, closing balances match your trial balance, asset registers include purchases and disposals, and inventory counts are verified. Appoint a single audit contact person and provide early access to accounting systems if possible.

How far in advance should SMEs start preparing for an audit?
Start at least 6 to 8 weeks before year-end by beginning reconciliations and cleaning up ledgers. Four weeks before, review your trial balance and resolve anomalies. Two weeks before, submit the pre-audit information list to your auditors.

What documents do SMEs need to provide to their auditors?
Signed board minutes and resolutions, contracts and agreements, current policies and procedures, loan agreements, CIPC annual returns, SARS tax and VAT filings, B-BBEE certificates, IRP5s, and PAYE reconciliations. Having these organised saves significant time.

How can SMEs reduce audit costs through better preparation?
Better preparation reduces the time auditors spend gathering and verifying basic information. Keep clean records throughout the year, respond to queries promptly, provide digital data access, and address prior-year audit recommendations before the next engagement begins.

What common mistakes do SMEs make during audit season?
Common mistakes include incomplete reconciliations, missing supporting documents, unresolved prior-year queries, poor communication with auditors, and failing to notify the audit team of major changes like system upgrades, ownership changes, or restructuring.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Financial records hold some of the most sensitive personal data — employee details, supplier banking info, customer accounts. Yet many companies focus on POPIA compliance in marketing or HR, and forget that their audit trail may expose the biggest risks. Here’s how to ensure your audit and accounting processes stay compliant with South Africa’s Protection of Personal Information Act (POPIA).

Where POPIA Risks Hide During Audits

  • Auditors and clients exchange large volumes of information. Common weak points include:
  • Unsecured file transfers (emailing Excel sheets with IDs and salaries).
  • Shared drives without access control.
  • Unredacted supporting documents (bank statements, contracts).
  • Old audit files stored beyond legal retention periods.
  • Even a minor breach can trigger regulatory action or reputational harm.

The Auditor’s Responsibility

Auditors are independent operators, not just service providers — meaning both the audit firm and the client share responsibility for safeguarding information.
IRBA’s Code of Professional Conduct and ISQM standards require firms to:

  • Use secure communication tools.
  • Limit staff access to client data.
  • Destroy or archive files properly after retention deadlines.

What Businesses Should Do Before the Audit

  • Designate a POPIA Champion to liaise with your auditors.
  • Mask or anonymise personal data where full details aren’t required.
  • Use password-protected uploads or client portals for audit documents.
  • Update your consent and privacy notices to include audit-related processing.
  • Review your data-retention policy to match audit cycle timelines.

SC Audit’s Approach to Data Security

  • At SC Audit, we follow a “privacy-by-design” philosophy:
  • Secure file-transfer platforms for all clients.
  • Minimal-data principle — we only collect what’s essential.
  • Staff POPIA training and confidentiality undertakings.
  • Encryption and regular system audits.

This ensures your information stays protected throughout the audit process.

Need help aligning your financial and audit data with POPIA? Get in touch for a privacy-compliance checklist or consultation.

Frequently Asked Questions

Where do POPIA risks commonly hide during an audit?
Common weak points include unsecured file transfers such as emailing spreadsheets with personal information, shared drives without access control, unredacted supporting documents like full bank statements, and old audit files stored beyond legal retention periods.

Who is responsible for data protection during an audit — the auditor or the client?
Both the audit firm and the client share responsibility. IRBA’s Code of Professional Conduct and ISQM standards require auditors to use secure tools and limit staff access, while clients must implement safeguards when sharing information with their auditors.

What should businesses do before an audit to ensure POPIA compliance?
Designate a POPIA champion, mask personal data where full details are not required, use secure uploads or client portals for documents, update privacy notices to include audit-related processing, and review data retention policies to match audit cycle timelines.

How does SC Audit protect client data during the audit process?
SC Audit follows a privacy-by-design approach with secure file-transfer platforms, a minimal-data principle collecting only what is essential, staff POPIA training and confidentiality undertakings, encryption, and regular system audits.

What are the consequences of a POPIA breach during an audit?
Even a minor breach can trigger regulatory action by the Information Regulator, reputational harm, and potential financial penalties. For auditors specifically, breaches may also result in disciplinary action by IRBA for failing to meet professional conduct standards.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Accounting standards evolve to reflect how businesses operate — and 2025 brings two key updates that every South African organisation should note:

  • GRAP 104: Financial Instruments, effective 1 April 2025, reshapes how public-sector entities classify, measure, and disclose financial instruments.
  • ISA 570 (Revised): Going Concern, refines auditors’ responsibilities when assessing whether an organisation can continue operating for the foreseeable future.

Even if you’re not in the public sector, these changes influence how auditors evaluate risk and what information management must provide.

GRAP 104: Clarity and Consistency in Financial Instruments

  • GRAP 104 aligns closer to IFRS 9, demanding clearer classification and measurement. Key shifts:
  • Three measurement categories – amortised cost, fair value through profit or loss, and fair value through other comprehensive income.
  • Expected Credit Loss (ECL) model replaces incurred-loss, making impairment more forward-looking.

More detailed disclosures on credit risk, liquidity risk, and market risk.

Who it affects: municipalities, government departments, public entities, and NGOs that report under GRAP.
Why it matters: finance teams must review their policies now to ensure assets and liabilities are classified correctly before audits begin.

ISA 570 (Revised): Strengthened Going-Concern Assessments

  • ISA 570 requires auditors to challenge management’s going-concern assessment more rigorously.
    Expect:
  • Enhanced documentation of management’s cash-flow forecasts and risk analysis.
  • Explicit reporting in audit opinions when material uncertainty exists.
  • Board accountability for identifying mitigating actions (funding, restructuring, cost control).

For clients: this means early conversations with your auditor are vital — especially if you’ve faced liquidity strain, delayed payments, or funding changes.

What SC Audit Recommends

✅ Review accounting policies for financial instruments by December 2025.
✅ Prepare forward-looking cash-flow models with assumptions and scenarios.
✅ Educate finance staff and audit committees on these changes.
✅ Use a pre-audit consultation to test compliance before year-end.

Want a smooth transition to GRAP 104 or need help reviewing your going-concern processes? Contact SC Audit to book a technical update session with our partners.

Frequently Asked Questions

What is GRAP 104 and who does it affect?
GRAP 104: Financial Instruments is a new accounting standard effective 1 April 2025 that reshapes how public-sector entities classify, measure, and disclose financial instruments. It affects municipalities, government departments, public entities, and NGOs that report under GRAP.

What are the key changes under GRAP 104?
The standard introduces three measurement categories — amortised cost, fair value through profit or loss, and fair value through other comprehensive income. It replaces the incurred-loss model with an Expected Credit Loss (ECL) model and requires more detailed disclosures on credit, liquidity, and market risk.

How does the revised ISA 570 change going-concern assessments?
ISA 570 (Revised) requires auditors to challenge management’s going-concern assessment more rigorously. Expect enhanced documentation of cash-flow forecasts and risk analysis, explicit reporting when material uncertainty exists, and stronger board accountability for identifying mitigating actions.

What should private sector companies know about these changes?
Even if you are not in the public sector, the enhanced scrutiny in going-concern assessments under ISA 570 affects all entities. Auditors will ask more probing questions about cash-flow forecasts, and management should prepare detailed forward-looking models with clear assumptions.

How can organisations prepare for these 2025 accounting standard changes?
Review accounting policies for financial instruments, prepare forward-looking cash-flow models with assumptions and scenarios, educate finance staff and audit committees on the changes, and schedule a pre-audit consultation to test compliance before year-end reporting begins.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Enhanced-Auditor-Reporting

Starting for reporting periods ending 15 December 2024, South African auditors of Public Interest Entities (PIEs) must follow the new Enhanced Auditor Reporting (EAR) Rule. If your company is classified as a PIE — or if you’re a board member or audit committee member — this change directly affects the audit report attached to your annual financial statements.

What Is the EAR Rule?

  • The EAR Rule requires auditors to include:
  • Key Audit Matters (KAMs): Areas of significant risk and how they were addressed.
  • Transparency on responsibilities: Clearer explanations of auditor and management roles.
  • Additional disclosures: Why certain judgments were material, and how audit evidence was assessed.

Who Is Affected by the EAR Rule?

  • Listed companies.
  • Entities with a significant number of stakeholders (banks, insurers, retirement funds).
  • Certain large nonprofits and public-sector entities.
  • Even SMEs that grow into PIE status should prepare — transparency expectations are rising across the board.

Why the EAR Rule Matters to Businesses

  • Investors & funders will see more detail: They’ll know exactly what issues auditors flagged.
  • Audit committees must be proactive: Boards can’t leave risk management to year-end; they’ll need to engage auditors throughout.
  • Public accountability rises: A “clean” audit now also shows that significant risks were managed properly.

How to Prepare for EAR

  • Engage your auditors early: Discuss potential KAMs and how management will address them.
  • Strengthen documentation: Board minutes, policies, and management estimates must be well-supported.
  • Educate stakeholders: Ensure your board and finance teams understand what EAR entails.

SC Audit’s Approach

We’re already guiding clients through EAR implementation, providing workshops and pre-audit assessments so finance teams aren’t surprised by new disclosure requirements.

Not sure if your entity qualifies as a PIE, or how EAR will change your audit report? Contact SC Audit to schedule an EAR readiness session with our partners.

Frequently Asked Questions

What is the Enhanced Auditor Reporting (EAR) Rule?
The EAR Rule requires auditors of Public Interest Entities (PIEs) to include Key Audit Matters (KAMs), clearer explanations of auditor and management responsibilities, and additional disclosures about why certain judgments were material. It applies to reporting periods ending on or after 15 December 2024.

Which entities are affected by the EAR Rule?
PIEs including listed companies, entities with significant stakeholder numbers such as banks, insurers and retirement funds, certain large nonprofits, and public-sector entities. SMEs that grow into PIE status should prepare early as transparency expectations are rising across the board.

How does the EAR Rule affect audit committees and boards?
Audit committees must be more proactive throughout the year rather than leaving risk management to year-end. Boards will see more detail in audit reports about what issues auditors flagged, requiring deeper engagement with auditors on potential KAMs during the planning phase.

What are Key Audit Matters (KAMs) in the EAR context?
KAMs are the areas of significant risk in an audit that required the most auditor attention. Under EAR, auditors must explain what made each matter significant and how it was addressed during the audit, giving stakeholders a clearer picture of the entity’s key risk areas.

How can companies prepare for EAR implementation?
Engage auditors early to discuss potential KAMs, strengthen documentation including board minutes and management estimates, educate stakeholders about what EAR entails, and consider a pre-audit EAR readiness assessment to avoid surprises in the audit report.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Quality Auditing

Audit quality isn’t just about the team on site — it begins with how an audit firm is managed. That’s the idea behind International Standards on Quality Management (ISQM 1 & 2), which South Africa adopted through the IRBA. From December 2022, every registered firm must maintain a comprehensive system of quality management. Here’s what that means for businesses choosing an auditor.

https://open.spotify.com/episode/6oI0M18qzU8IkJb0glJvld?si=20VMQAW8Q4aABdRcaXQN0Q

What Is ISQM?

  • A framework requiring audit practices to identify and assess quality risks across leadership, ethics, client acceptance, resources, and monitoring.
  • Firms must design controls, evaluate them regularly, and document results.
  • ISQM 2 adds detailed rules for engagement quality reviews (EQRs) on higher-risk audits

Why It Benefits Clients

When your auditor runs on ISQM principles, you gain:

  • Consistency: policies make sure every file is handled to the same high bar.
  • Better staffing: firms must assign suitably skilled, independent staff.
  • Early warning: internal monitoring spots issues before they affect your report.
  • Confidence for boards and funders: quality oversight reduces the chance of surprises.

Questions to Ask Your Auditor

  • How has your firm embedded ISQM into day-to-day work?
  • Do you perform annual risk assessments on all clients?
  • Who performs engagement quality reviews on my audit?
  • What training do your teams undergo to maintain quality?

SC Audit’s Commitment

SC Audit has implemented ISQM across leadership, human resources, technology and monitoring. For you, that means a boutique-sized team with big-firm quality controls — ensuring your financial statements are scrutinised with independence, rigour and efficiency.

Discover how our quality-first approach can make your next audit seamless. Schedule a consultation with our partners today.

Frequently Asked Questions

What is ISQM and why does it matter to clients?
ISQM (International Standard on Quality Management) is a new framework requiring audit firms to design, implement, and operate a system of quality management. For clients, this means higher and more consistent audit quality, better risk identification, and greater confidence in the audit opinion.

How is ISQM different from previous quality control standards?
ISQM is more proactive and risk-based than prior standards. Instead of checking compliance retrospectively, firms must now identify quality risks, design responses to mitigate them, and monitor the system continuously. The focus shifts from quality control to quality management.

Does ISQM affect the cost or duration of my audit?
ISQM primarily changes how audit firms manage quality internally. While there may be some initial investment as firms implement new systems, the standard is designed to improve efficiency over time by reducing errors and rework. Clients should expect consistent quality, not necessarily higher fees.

How does SC Audit ensure compliance with ISQM standards?
SC Audit has implemented a comprehensive quality management system aligned with ISQM requirements, including regular risk assessments, engagement quality reviews, independence checks, and ongoing staff training. These processes are embedded in every engagement from planning to sign-off.

What should clients look for in an audit firm’s quality management?
Clients should ask about the firm’s quality control policies, how they handle independence and conflicts, their approach to engagement reviews, and their track record with IRBA inspections. A firm that invests in quality management demonstrates commitment to reliable, professional audits.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

SARS Filing Season 2025

SARS has officially released the 2025 Filing Season dates – make sure these are in your diary to avoid last-minute stress or penalties:

  • 21 July – 20 October 2025 -> Non-provisional taxpayers (manual filing)
  • 21 July 2025 – 19 January 2026 -> Provisional taxpayers
  • Trusts -> Filing also closes 19 January 2026

A few quick tips:

  • If you’re auto-assessed and everything looks correct, no action is needed.
  • If you need to make changes or prefer manual submission, file before the deadlines.
  • Double-check that your eFiling profile is updated (especially banking details and contact info).

The earlier you file, the less stressful tax season will be. 

We’re here to guide you through the process, answer your questions, and help ensure that you remain fully compliant. 

This of us as a partner in making the tax season simple and stress-free.

Frequently Asked Questions

When does SARS Filing Season 2025 run?
For non-provisional taxpayers filing manually, the filing season runs from 21 July to 20 October 2025. Provisional taxpayers and trusts have until 19 January 2026 to submit their returns.

What should I do if I receive an auto-assessment from SARS?
If everything in your auto-assessment is correct and matches your records, no action is needed. If you need to make changes or prefer to submit manually, you can still file a return before the relevant deadline for your taxpayer type.

How can I prepare for filing season to avoid delays?
Update your eFiling profile with current banking details and contact information, gather all necessary documents including IRP5s and medical aid certificates, and start early to avoid last-minute stress. Ensure your tax returns align with your financial records.

What happens if I miss the filing deadline?
Missing the deadline may result in penalties and interest charges from SARS. Non-compliance can also trigger a SARS audit or verification. If you anticipate missing the deadline, contact your tax practitioner or SARS directly to discuss options.

How can SC Audit help with my tax filing?
SC Audit and the broader Schoemans Group can guide you through the filing process, answer your questions, review your return before submission, and help ensure full compliance. Their team serves as a partner in making tax season simple and stress-free.

SARS has warned that it will intensify and deepen its existing administrative efforts to drive taxpayer compliance, deploying more data science and AI, and imposing significant legal and administrative costs on non-compliant taxpayers.

This means that in 2025, maintaining full tax compliance will be more crucial than ever. Your best shot at ensuring all the compliance requirement boxes are ticked continuously and efficiently is to rely on our friendly and professional expertise.

“Being tax compliant and ‘paying your fair share’ is not just good for you, but also contributes to the positive growth of our country’s economy which in turn benefits all South Africans.” (SARS)

Being tax-compliant is a legal requirement for all South Africans.

SARS says it will be unrelenting in driving voluntary compliance in pursuing the 2024/25 tax revenue target of R1,840.8 billion.

To expand the tax base, detect dishonest taxpayers, deal with tax avoidance, expand debt collection, and improve service levels, SARS will:

  • Deploy more data science and artificial intelligence (AI)
  • Broaden the tax base via third-party data sources (banks, medical schemes, fund administrators etc.
  • Use predictive modelling to ensure all taxpayers and traders are registered, filing returns and paying dues
  • Build detection capability using machine learning models and AI
  • Enforce Customs and Excise trade laws against the illicit economy
  • Focus on dispute prevention and resolution.

Importantly, SARS is ready to act against those who willfully and defiantly ignore their legal obligations by misrepresenting their true economic status. SARS will impose significant legal and administrative costs on taxpayers and traders who deliberately fail to meet their obligations.

What does tax compliance look like?

Your company needs to:

  • Be registered with SARS for all the tax types applicable to your company
  • Have either merged or declared all registered tax reference numbers on eFiling
  • Timeously submit all tax returns and other documentation requested
  • Keep all registered particulars updated
  • Pay all tax debt on time, or timeously secure a payment arrangement or suspension of payment
  • Deregister the business if it is liquidated or closed.

Remember that your tax compliance status is not static: it changes according to your continued compliance with tax requirements month after month. Also remember that SARS can impose both monetary and criminal sanctions to enforce compliance. This is a significant business risk, because the burden of proof, should a taxpayer disagree with a decision taken by SARS, lies with the taxpayer. In the event that the taxpayer fails to argue their case successfully, they may find themselves in a position where penalties are suffered even if the error was unintentional or administrative in nature.

Benefit from the advantages of tax compliance

When you comply with your tax obligations, you give your business some compelling advantages.

  • Eliminate the costs of non-compliance, like penalties, interest, and additional accounting and admin fees.
  • Avoid the risk of criminal offences, which may result in a fine, imprisonment or both. Common offences include not registering for a tax type, or simply not submitting tax returns.
  • Proof of tax compliance is considered an indicator of good company management and legal good standing.
  • Good standing tax clearance certificates are often required for tender applications, bidding processes or prequalification as a supplier. They can also be needed to receive payment, or for foreign investment allowances.
  • Compliance enables companies to gain the confidence of clients, stakeholders and investors; take advantage of business opportunities; and prevent reputational damage.

Help is at hand

Now more than ever before, professional assistance is the best way to consistently meet all the tax compliance requirements across all the relevant tax types over the tax year, and in an always-changing tax landscape.

SARS itself recommends “employing an accountant, tax practitioner, or other tax professional to complete returns, or from whom to obtain advice before completing a return with entries that are not understood or adopting a position with tax implications” to ensure you have taken “reasonable care” when it comes to your tax affairs.

We are well-versed in the requirements and deadlines of the various tax types and we’re also on top of the latest rules and processes. In a nutshell: we have the tax expertise to ensure you remain tax compliant all through 2025.

Frequently Asked Questions

What types of tax compliance help does SC Audit offer?
SC Audit and the Schoemans Group offer guidance on company tax returns, provisional tax, VAT, PAYE, and tax planning. The team helps businesses understand their tax obligations, prepare accurate returns, and stay compliant with SARS requirements throughout the year.

What is provisional tax and who needs to pay it?
Provisional tax is a system where taxpayers pay tax in two installments during the year of assessment rather than a lump sum after year-end. It applies to taxpayers earning income not covered by PAYE, including business owners, freelancers, and companies with taxable income above the threshold.

How can businesses avoid common tax compliance mistakes?
Common mistakes include incorrect VAT classifications, missed filing deadlines, under-declared income, and inadequate record keeping. Working with a tax professional, maintaining organised records, and staying informed about legislative changes helps businesses avoid costly errors.

What tax deadlines should South African businesses track in 2025?
Key deadlines include monthly VAT returns, PAYE submissions, the upcoming filing season for annual returns, and provisional tax payment dates. The specific dates depend on your business structure, turnover, and registration type. SC Audit can provide a personalised deadline calendar.

How can SC Audit help my business stay tax compliant?
SC Audit offers practical tax compliance support including return preparation and review, deadline management, SARS correspondence assistance, and proactive tax planning. The team helps businesses navigate South Africa’s complex tax landscape with confidence and peace of mind.

SC Audit is part of the Schoemans Group that includes Schoemans – Chartered Accountants in Cape Town and Acrede – Quality Auditing and Tax Consulting.

Newsletter Sign Up