Think you’re too small for governance and compliance? Think again

Think you’re too small for governance and compliance? Think again


Graeme Millar, Managing Director, SevenC.

Graeme Millar, Managing Director, SevenC.

When entrepreneurs start a business, they usually think about customers, sales, cashflow and growth, not about governance. Governance and compliance can easily feel like something you only need to prioritise down the line, once the business grows. But retrofitting governance is a bit like trying to strengthen a house’s foundations after you’ve already built the second floor. It can be done, but it’s much simpler to just build the right foundations from the start.

According to Graeme Millar, MD at SevenC, small businesses don’t pay attention to governance and compliance for a variety of reasons. In most cases, it’s not that small businesses are deliberately ignoring the rules. When you’re trying to get a young business off the ground, you have so much on your plate. And because the benefits aren’t immediately apparent and compliance doesn’t directly bring in money, it can easily fall down the priority list. Many also believe governance and compliance apply only to bigger businesses. Rather than taking the time to understand the requirements, it’s often seen as “too complicated” by business owners with limited legal or financial expertise.

But governance and compliance give a growing business the structure and discipline to make good decisions from the start. “If you’re not thinking about compliance and governance early on, you might have the expertise, capacity and track record to tender for a major contract, for example, but can’t do so because you don’t have the required statutory documents or compliance certificates in place,” he says. The same applies if you’re trying to raise capital. Funders might see strong growth potential in your idea, but they need proof that the business operates legitimately and responsibly before they invest.

While obligations differ depending on the business structure, number of employees, turnover and industry, something like CIPC compliance applies to everyone. Under CIPC, businesses must keep their statutory information up to date, file annual returns and maintain the required beneficial ownership and financial records. “If you don’t comply, CIPC can deregister your business.”

Similarly, if you’re a business that touches any kind of personal data, be it information about your customers or your staff, you must comply with the Protection of Personal Information Act (POPIA). POPIA dictates how a business collects, uses, stores, shares and protects information. Millar goes on to explain that when a business hires employees, it’s important to have employment contracts, disciplinary procedures and onboarding/offboarding policies in place. “We see a lot of companies without any staff-related policies in place, and then they’re surprised when a person who left the business two years ago still has access to proprietary data and internal systems,” he says.

“All of these obligations compound as the business gets bigger and bigger. If you don’t have the right structures in place from the start, it can be overwhelming,” he says. “I’m not saying that you now need to go and spend months putting together 50 policy documents just for the sake of it. But I am suggesting that small businesses take some time to understand what governance and compliance expectations apply to them and start with those that present the biggest risks.”

Is your IT compliance-ready? You don’t need 50 policies. You do need to know where your biggest risks are. Book a complimentary 30-minute IT Governance & Compliance Check with SevenC. SevenC will help you identify potential gaps across data protection, user access, security, backup and IT policies – and where you should focus first. Visit https://sevenc.co.za.