Internal audit has traditionally played a vital role in reviewing completed activity, testing controls and confirming whether policies and procedures have been followed, but the risk environment facing...
Compliance is supposed to make transactions safer and more trustworthy. But in many organisations, it is creating the opposite effect. As verification requirements grow more complex, transactional processes...
From Compliance to Confidence: Updating your RMCP for 2025 and beyond. The essential webinar for compliance officers and risk managers. As the regulatory landscape continues to evolve, particularly...
Cyber security threats are on the rise, and organisations are on the back foot. This emerged at our latest LexisNexis webinar, which unpacked cyber security management strategies for more resilient organisations...
In a world rapidly transforming through technology, Governance, Risk, and Compliance (GRC) have emerged as pivotal concepts in Africa's evolving business landscape. GRC refers to the framework organisations...
Compliance is supposed to make transactions safer and more trustworthy. But in many organisations, it is creating the opposite effect. As verification requirements grow more complex, transactional processes become slower, more repetitive and more demanding for both businesses and clients. At the same time, the volume of personal and business information now being collected creates a larger exposure surface.
A controversial 2025 opinion piece in Business Day by economist Brian Benfield argues that, after decades of KYC and FICA expansion, the system has become costly, intrusive and operationally burdensome, with scant evidence of equivalent impact on illicit financial flows. Whether or not one agrees with his argument, the operational point is difficult to dismiss: more compliance administration does not automatically produce better outcomes.
That concern becomes more urgent when viewed alongside recent cyber incidents. On 7 April 2026, ITWeb reported that Standard Bank had notified business clients of a data breach involving unauthorised access to select records, including account numbers, account information, business names and ID or registration numbers. The bank said its transactional banking systems were not accessed and client funds were unaffected, but warned that the breach increased the risk of identity theft, fraud and phishing.
Taken together, these two stories point to a deeper challenge in transactional environments. The issue is not simply whether organisations are compliant, but whether their compliance model is well designed. When compliance becomes manual, duplicative and document-heavy, it creates friction for legitimate clients, pressure for internal teams and a growing stockpile of sensitive data that must be protected. In that model, organisations can end up carrying both the cost of compliance and the risk of data exposure.
For transactional teams, that has practical consequences. A process built on disconnected systems, repeated document requests and manual follow-ups makes it harder to see where risk sits, what has been verified, what is still outstanding and how decisions were made. The result is a workflow that feels more cumbersome than it should be, while still leaving room for inconsistency and exposure.
The answer is better workflow design: verification that is more proportionate, workflows that are better connected and information handling that is more disciplined from end to end. Benfield himself points toward risk-based models, better use of appropriate technology and more focused intelligence-led enforcement rather than blanket box-ticking. In a transactional setting, that means reducing unnecessary duplication, improving visibility and tightening control over sensitive information.
Transactional performance now depends on being able to verify quickly and confidently, while operating with less friction.