Most businesses don't fall out of compliance on purpose. A policy gets written once and never reviewed, a registration lapses when someone leaves, a new contractor starts on-site before anyone checks their paperwork. Each gap looks small on its own. Together they add up to legal, financial and safety risk that tends to surface at the worst possible moment: after an incident, during an inspection, or in the middle of a dispute.
This checklist gives you a quick, honest read on where you stand. It covers the four areas we see tripping up South African businesses most often: health and safety, data privacy and risk, people and employment, and governance, finance and legal.
How to use this check
Answer each question with a simple Yes or No. Only answer Yes if you could hand over the document, register or proof today if someone asked for it. "We sort of do that" counts as a No. Your score updates as you go, and the rubric at the bottom tells you what it means.
Prefer paper? Download the one-page version to print, share with your team or fill in at your next management meeting.
Download PDF ↓Health & Safety
Items 1 to 10Do you have a written, legally compliant Occupational Health and Safety (OHS) Policy in place?
Has a formal hazard identification and risk assessment (HIRA) been documented for your workplace?
Are all employees and contractors appropriately trained and inducted on health and safety procedures?
Is your first aid arrangement adequate, stocked, and managed by trained statutory first aiders?
Are emergency arrangements, fire equipment inspections, and evacuation procedures documented and tested?
Do you have a documented process for reporting, recording, and investigating workplace incidents and near-misses?
Are external contractors vetted, inducted, and monitored for compliance before starting work on-site?
Is required Personal Protective Equipment (PPE) identified, issued, maintained, and enforced?
Is a comprehensive emergency response and business continuity plan documented and accessible?
Can you produce valid evidence of compliance, inspection registers, and maintenance logs upon request?
Data, Privacy & Risk
Items 11 to 14Do you understand your privacy obligations, have an Information Officer registered, and maintain a PAIA manual?
Have your operational and financial risks been comprehensively reviewed with your insurer or broker?
Do you have explicit privacy notices, consent mechanisms, and clear rules for handling client/employee data?
Are basic data security measures (backups, access controls) and a data breach response process in place?
People & Employment
Items 15 to 18Does every employee have a written contract aligned with applicable labour legislation and sector standards?
Are workplace codes of conduct, disciplinary procedures, and grievance policies documented and communicated?
Are you registered and up to date with UIF, COIDA / Compensation Fund, and relevant bargaining councils?
Do working hours, overtime practices, leave administration, and remuneration meet statutory minimums?
Governance, Finance & Legal
Items 19 to 25Are CIPC / company registration documents, annual returns, and statutory registers current and maintained?
Are all statutory tax obligations (PAYE, VAT, Corporate Income Tax) filed and paid up to date?
Are proper accounting records kept, and annual financial statements compiled or audited as required?
Do you hold and display all required municipal, trade, and industry-specific operating licences?
Are client service agreements, supplier contracts, and standard terms of trade legally reviewed and active?
Are key company trademarks, domain names, and intellectual property registered and protected?
Is there a regular schedule for management reviews and annual internal compliance audits?
What your score means
Generally Organised
Core compliance frameworks are active and documented. Maintain regular reviews and keep evidence files updated.
Potential Gaps Requiring Attention
Key operational areas are compliant, but notable legal or safety gaps exist. Prioritise remediation within 30 to 60 days.
Significant Areas Requiring Professional Review
Critical missing policies or statutory non-compliance expose the business to severe legal, financial, or operational risks. Immediate professional review required.
Where to start if you have gaps
Don't try to fix everything at once. Start with the items that carry immediate legal or safety consequences: your OHS policy and risk assessment, incident reporting, COIDA and UIF registrations, and POPIA obligations. These are the areas inspectors, insurers and the courts look at first.
Then work outward to the items that protect the business over time, such as contracts, licences, intellectual property and a regular audit schedule. A compliance framework only works if it is maintained, so item 25 matters more than it looks: a yearly internal audit is what keeps a Green score Green.
A self-check is a starting point
This checklist is a general guide and doesn't replace a formal audit or legal advice. Requirements vary by sector, size and location. If you scored Amber or Red, or you weren't sure how to answer some questions, a professional review will give you a clear, prioritised plan.
Take the checklist with you
A printable one-page version with the full rubric and our contact details.
"Built to stand the test of time."
Llevarg Projects · OHS Auditing · Compliance · Skills Development