Ignorance of the law is not a defense
Forensic investigation is all about finding the facts; digging, asking endless questions, and refusing to quit until we’ve exposed the truth. So it’s rare that you’ll find me leaning towards the dramatic, but this is one occasion when I feel a little drama is warranted:
Section 34 of The Prevention and Combatting of Corrupt Activities Act, Act12 of 2004 (PRECCA) might just be the most important law you’ve never heard of.
It forms part of the Judicial Matters Amendment Bill that was signed into law by President Cyril Ramaphosa on 3 April 2024, yet outside of legal and compliance circles, almost nobody realises it exists. Which, if you’re a CEO, CFO, or anyone who holds a position of authority, should be enough to wake you up in a cold sweat in the middle of the night.
Why?
Because it dictates how every single person in a leadership position is legally obligated to behave the moment financial red flags appear. So, please read on, because when it comes to corporate accountability, ignorance of the law is not a defence.
Fortunately, unlike many laws, the rule outlined in Section 34 is incredibly specific: If you hold a position of authority and you know – or even strongly suspect – that fraud, theft, or corruption involving R100,000 or more has occurred, you are legally required to report it directly to police.
Not the board. Not your internal audit department. The South African Police Service. Overlooking an incident, sitting on crucial information, or simply failing to act is a distinct criminal offence all on its own.
No one (except the bad guys) can deny this is a hugely positive step, but it does create a significant practical challenge when it comes to how fast a business needs to move.
It’s natural for corporates to pause, stay quiet, and let a thorough internal forensic investigation wrap up before sounding any broader alarms. But under Section 34, “he who hesitates is bust,” to paraphrase the well-known adaptation of English writer Joseph Addison’s quote.
On the surface, it’s a lot to process, and I know many leaders are unsure what the thresholds are, and how they should respond if something “looks wrong” or “feels off.” Hopefully you’ll find this breakdown useful.
The most important shift is the one from responsibility to accountability. Previously, you only had a duty to report incidents of fraud or corruption, (and cards on the table, nothing much would happen to you if you didn’t). Now however, you can now be found personally liable if it happened on your watch and you failed to do something about it.
Crucially, this liability isn’t only limited to fraudulent activity by company colleagues, it also includes third-party contractors. To me, this is possibly one of the strongest stipulations of the Act. We’re all far too aware – particularly during the worst years of State Capture – of how prominent a role third parties played in corruption. This was largely due to how easily public and private procurement processes could be abused, and it created wonderful opportunities for the bad guys to build a layer of bureaucracy between themselves and the people actually committing fraud.
It’s still a highly effective loophole today, creating an artificial buffer that makes corruption much harder to identify. Under Section 34A however, hiding behind a supplier or contractor is no longer a legal shield. Any dirty tricks they pull on your behalf are now squarely your responsibility.
Of course, if you’re not actually orchestrating the fraud yourself, it’s not always easy to know it’s going on, so how much due diligence by leaders is enough to satisfy the parameters of the law?
Section 34A talks about “reasonable measures” being put in place to prevent corruption in your organisation. The problem is, exactly what these “reasonable measures” look like is not yet clear under the law.
Until we have more clarity, what can we physically do to prove we’ve done everything possible to stop a colleague, employee or associated third party from crossing the line?
We could do worse than take inspiration from the UK’s Bribery Act. In fact, Section 34A is modelled directly on it.
The UK framework relies on six core principles to determine whether an organisation has “done enough:”
Proportionality: Defence measures must match the actual operational risks of your specific business size and sector.
Top-level commitment: Leadership must actively foster a culture where corruption is entirely unacceptable.
Risk assessment: Leaders must systematically evaluate and document internal and external exposure to fraud.
Due diligence: Thorough vetting must be deeply integrated into supply chain and vendor workflows.
Communication: Everyone representing your company needs to clearly understand your anti-corruption boundaries.
Monitoring and review: Compliance frameworks must be continuously audited and updated to be ready for evolving threats.
These principles currently form unofficial guidance for what “enough” looks like in a South African context. I’m confident our courts will provide further explicit clarity, but until that time, no one can afford to gamble by simply sitting around waiting for concrete legislation. We have to act proactively by establishing and leveraging systems that can spot problematic employees, compliance patterns, and third-party contractors well in advance.
Historically, companies and public organisations have been far more reactive than proactive, because the most up-to-date view of corruption we have is usually the mechanics of the last fraud scheme we managed to catch.
But prevention is always better than cure – proactive is better than reactive.
Of course, whistleblowers, as always, remain an invaluable asset, and we must continue to create and maintain safe, supportive environments that empower employees to report fraud as soon as they see it. But if we let them become our only line of defence, we’ll get stuck in reactive mode.
Getting ahead of the curve is the more reliable way to lessen leaders’ liability.
This is where data analytics can be a key ally, offering a new front to help tackle corruption before it takes place.
We must, for example, sift through and analyse current and historical data to identify previously missed patterns and operational red flags such as:
Invoices that are consistently processed on weekends or holidays when fewer people are online, leading to lower oversight.
An employee with high-level financial delegation who refuses to take a single day of leave over a three-to-four-year period.
Stopping corruption at the source means establishing digital parameters for continuous learning, regular testing, proactive reporting, and filtering out standard operational false positives from actual acts of corruption and fraud.
Realistically, we know many criminals are smart, tech savvy and endlessly creative, making it virtually impossible to stop 100% of bad intentions. Nevertheless, it remains our strict fiduciary responsibility to do everything in our power to meet and exceed the legal threshold of “enough,” not only to save our own skins, but to protect the future of the organisations that we work for.
In the UK, to improve safety on public transport, authorities have coined the slogan, “See it, say it, sorted.” This is exactly the behaviour senior South African leaders must adopt when faced with fraudulent activities at their organisation.
The era of pleading ignorance or hiding behind third-party buffers is officially over, and the age of personal accountability and liability is here.
