Internal Controls
Compliance Obligations Exposure
Exposure across statutory compliance obligations, scored on control coverage and breach history.
Why statutory exposure must be measured, not assumed
A public institution carries dozens of statutory obligations under the MFMA, PFMA, PRECCA, POPIA and sector-specific legislation, and a breach of any one can trigger an AGSA finding, fruitless expenditure or personal liability for the accounting officer. Treating compliance as a binary checklist hides the real picture: which obligations are weakly controlled and which have a track record of failure. AuditPro Core scores each obligation on control coverage and breach history so oversight can direct attention to genuine exposure rather than to obligations that are already well managed.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Obligations tracked
88
Fully controlled
67
76%
Partially controlled
15
Breaches YTD
9
▼ 3 vs prior
Obligations by regulatory area
Exposure by regulatory area
| Regulatory area | Obligations | Coverage % | Breaches |
|---|---|---|---|
| PFMA / MFMA | 26 | 85 | 3 |
| Tax | 16 | 88 | 1 |
| Labour | 14 | 79 | 2 |
| Data protection | 14 | 64 | 3 |
| Environmental | 12 | 92 | 0 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Obligation versus control
An obligation is the legal duty itself; a control is the mechanism that delivers it. An obligation can sit on the register fully named yet remain exposed because no reliable control actually enforces it.
Control coverage scoring
Coverage measures how completely an obligation is supported by designed and operating controls. Low coverage means the institution is relying on goodwill or manual diligence rather than embedded process.
Breach history as a leading signal
Past breaches are the strongest predictor of future ones. An obligation that has failed before, even if remediated, warrants a higher residual rating than its design alone would suggest.
Exposure as a composite
Exposure combines the consequence of non-compliance with the weakness of controls and the recurrence of breaches. It lets management rank obligations by risk rather than by alphabetical statute.
How AuditPro Core Bridges the Gap
- Obligation register: every statutory duty is captured with its legal source, responsible owner and the controls mapped against it for full traceability.
- Coverage scoring: the platform calculates control coverage automatically from linked control assessments, flagging obligations that lack adequate support.
- Breach workflow: recorded breaches feed an exception workflow that updates history and re-scores the obligation in real time.
- Audit-ready export: a defensible exposure schedule can be exported for the audit committee and AGSA, showing both the score and the evidence behind it.
Key Takeaways
- Compliance is not binary; weakly controlled obligations are exposed even when nominally met.
- Breach history materially raises residual exposure and should drive remediation priority.
- Direct assurance effort to high-exposure obligations rather than spreading it evenly.
- Maintain traceability from each obligation back to its enabling legislation and controls.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
