
Risk management and opportunity identification form part of every discussion throughout the business, spanning from one-on-one performance management / feedback sessions to divisional meetings, management and executive committee meetings, and Board sub-committee meetings.
Significant risks are reported on and considered at every Audit and Risk Committee meeting and reported at every Board meeting. Internal audit and other appointed assurance providers are contracted to provide independent assurance to assist management and the Board in ensuring that the control environment improves and objectives are achieved.
There is clear accountability and ownership of risk through SAICA’s governance structures depicted below:

The SAICA Board sets the tone for risk management and assumes ultimate accountability, but delegates oversight of risk management to the Audit and Risk Committee and the day-to-day risk management activities to management. They ensure that assurance services and functions enable an effective control environment and support the integrity of information for internal decision-making and of the organisation’s external reports

Management is charged with the responsibility for taking appropriate risks within the risk appetite framework approved by the Board to create value. The Board receives quarterly reports on the status of existing as well as emerging risks and opportunities

Establishes the policies and procedures for managing risk, as well as promoting a culture of risk awareness and control The SAICA ERM policy and frameworks adopted by the Board govern ERM in the organisation and clearly define the roles and responsibilities of the Board, Board sub-committees, and various lines of assurance providers, promoting a sound risk culture. Risk is integrated with performance management and aligned to strategic objectives and performance goals

Risk owners are the staff who are directly accountable for ensuring that risks are managed effectively by implementing actions required to treat the risks

Internal audit and other appointed assurance providers are contracted to provide independent assurance to assist management and the Board in ensuring that the control environment improves and objectives are achieved

External auditors provide an additional line of assurance. Their role is to provide reasonable independent assurance on the integrity of financial statements, as well as the effectiveness of internal controls in mitigating risks
The Risk Appetite and Tolerance Framework provides guidance on developing and implementing risk appetite, risk tolerance levels and the risk-bearing capacity (which collectively form the risk thresholds of the SAICA Group), linked to and derived from the organisation’s strategic pillars and short-, medium- and long-term objectives. The realisation of SAICA’s strategy depends on the ability to take calculated risks in a manner that creates sustainable value for the SAICA Group. The framework provides guidelines for tracking and monitoring key risk indicators (KRIs) which provide an early warning signal of increasing risk exposures, enabling management to intervene in a timely manner through appropriate risk-mitigating responses.
The main drivers escalating the risk environment include the following emerging risks and events:
| Risk/Event | Mitigating actions | Related strategic risk/s |
Artificial intelligence (AI) and its impact on the accountancy profession An impact analysis on how AI technology and its generative capability are impacting the accountancy profession is currently being undertaken by the Standards division |
|
![]() |
AI IT security Although the introduction of AI software, applications and robotics presents many opportunities, there is a probability that it will also introduce threats or intensify the impact of current threats such as hacking, which could lead to more cyberattacks/breaches. It is important to investigate the impact of AI on IT networks and organisations’ IT infrastructure and systems |
|
![]() |
Power supply and maintenance Continued power outages are causing a disruption in business operations |
|
![]() |
SAICA’s evolving role as a regulator The proposed changes to the registered controlling body (RCB) criteria by SARS to monitor CPD compliance of tax practitioners will strain SAICA’s resources, as it could result in SAICA performing a dual role as member body and regulator |
|
![]() |
Disciplinary processes of tax practitioners From a compliance and potentially discipline perspective, the management and monitoring of tax practitioners by SAICA may become unduly burdensome |
|
![]() |
A decline in the number of transformation student passes at third-year and CTA levels |
|
![]() |