Back to Explore
⚠️

Internal Controls

Compliance Obligations Exposure

Exposure across statutory compliance obligations, scored on control coverage and breach history.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why statutory exposure must be measured, not assumed

A public institution carries dozens of statutory obligations under the MFMA, PFMA, PRECCA, POPIA and sector-specific legislation, and a breach of any one can trigger an AGSA finding, fruitless expenditure or personal liability for the accounting officer. Treating compliance as a binary checklist hides the real picture: which obligations are weakly controlled and which have a track record of failure. AuditPro Core scores each obligation on control coverage and breach history so oversight can direct attention to genuine exposure rather than to obligations that are already well managed.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Obligations tracked

88

Fully controlled

67

76%

Partially controlled

15

Breaches YTD

9

▼ 3 vs prior

Obligations by regulatory area

Exposure by regulatory area

Regulatory areaObligationsCoverage %Breaches
PFMA / MFMA26853
Tax16881
Labour14792
Data protection14643
Environmental12920

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Obligation versus control

An obligation is the legal duty itself; a control is the mechanism that delivers it. An obligation can sit on the register fully named yet remain exposed because no reliable control actually enforces it.

Control coverage scoring

Coverage measures how completely an obligation is supported by designed and operating controls. Low coverage means the institution is relying on goodwill or manual diligence rather than embedded process.

Breach history as a leading signal

Past breaches are the strongest predictor of future ones. An obligation that has failed before, even if remediated, warrants a higher residual rating than its design alone would suggest.

Exposure as a composite

Exposure combines the consequence of non-compliance with the weakness of controls and the recurrence of breaches. It lets management rank obligations by risk rather than by alphabetical statute.

How AuditPro Core Bridges the Gap

  • Obligation register: every statutory duty is captured with its legal source, responsible owner and the controls mapped against it for full traceability.
  • Coverage scoring: the platform calculates control coverage automatically from linked control assessments, flagging obligations that lack adequate support.
  • Breach workflow: recorded breaches feed an exception workflow that updates history and re-scores the obligation in real time.
  • Audit-ready export: a defensible exposure schedule can be exported for the audit committee and AGSA, showing both the score and the evidence behind it.

Key Takeaways

  • Compliance is not binary; weakly controlled obligations are exposed even when nominally met.
  • Breach history materially raises residual exposure and should drive remediation priority.
  • Direct assurance effort to high-exposure obligations rather than spreading it evenly.
  • Maintain traceability from each obligation back to its enabling legislation and controls.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.