PFMA compliance, mapped to the controls that satisfy it
The Public Finance Management Act puts a personal duty on accounting officers and accounting authorities to maintain effective systems of financial and risk management and internal control. Dimeri holds every one of those duties as a tracked obligation, linked to the control that satisfies it, the evidence behind it and the official who owns it.
What the PFMA requires
The Public Finance Management Act 1 of 1999 governs how national and provincial government, constitutional institutions and public entities manage money. It is not a procedural rulebook so much as an accountability statute: it names a single person at each institution, the accounting officer in a department or the accounting authority in a public entity, and makes that person answerable for the systems that keep public money safe.
Two sections carry most of the weight. Section 38(1)(a) obliges the accounting officer of a department to maintain effective, efficient and transparent systems of financial and risk management and internal control, a system of internal audit operating under the control of an audit committee, and a procurement system that is fair, equitable, transparent, competitive and cost effective. Section 51(1)(a) places the identical obligation on the accounting authority of a public entity. Section 38(1)(c)(ii) then requires the accounting officer to take effective and appropriate steps to prevent unauthorised, irregular and fruitless and wasteful expenditure.
Because the duty is personal, the consequences are personal. Chapter 10 treats a failure to comply as financial misconduct, and section 86 creates criminal offences carrying a fine or imprisonment of up to five years. In practice this means an accounting officer needs to be able to demonstrate, at any point in the year and not only at audit, that the systems required by section 38 exist, are being operated, and are working.
The obligations Dimeri tracks
Dimeri breaks the PFMA into discrete obligations rather than treating it as one line item. Each one carries its own owner, evidence requirement and due date.
Systems of financial and risk management
The anchor obligation. Effective, efficient and transparent systems of financial and risk management and internal control, maintained continuously rather than assembled before an audit.
- Enterprise risk register with named risk owners
- Risk assessment refreshed at least annually
- Internal control library linked to the risks it treats
- Evidence of control operation, not just control design
Internal audit and audit committee
A system of internal audit operating under the control and direction of an audit committee, working to a risk based plan.
- Rolling three year strategic internal audit plan
- Annual internal audit plan derived from the risk assessment
- Audit findings tracked to closure with owners and dates
- Audit committee papers drawn from live register data
Procurement and provisioning system
A procurement system that is fair, equitable, transparent, competitive and cost effective, with the supporting records to prove each of those five characteristics.
- Procurement risks held in the same register as other risks
- Deviation and expansion approvals logged with reasons
- Supplier and third party risk assessments
- Declaration of interest records held against awards
Irregular and fruitless expenditure
Effective and appropriate steps to prevent unauthorised, irregular and fruitless and wasteful expenditure, and to report it when it occurs.
- Register of unauthorised, irregular and fruitless expenditure
- Root cause recorded against each item
- Consequence management actions tracked to conclusion
- Disclosure note evidence assembled during the year
Reporting and annual financial statements
Annual financial statements submitted to the Auditor-General within two months of year end, and an annual report that includes the audited statements and a report on performance against predetermined objectives.
- Reporting calendar with statutory deadlines and reminders
- Performance information linked to its supporting evidence
- Prior year audit findings carried forward and monitored
- Board and executive reporting packs generated from live data
Financial misconduct and consequence management
Proceedings for financial misconduct where an official fails to comply, and criminal offences for the most serious breaches.
- Case register for alleged financial misconduct
- Investigation status, outcome and sanction recorded
- Referrals to law enforcement tracked
- Reporting to the relevant treasury and the executive authority
How Dimeri covers PFMA
The PFMA repeats itself across departments and entities and overlaps heavily with the Treasury Regulations and the Public Sector Risk Management Framework. Dimeri maps the obligation once and credits it everywhere it applies.
One control, several frameworks
The risk assessment that satisfies section 38(1)(a)(i) is the same assessment the Treasury Regulations require under TR 3.2 and the same one the PSRMF expects. Record the control once in Dimeri and all three scorecards move together. When it is tested and found ineffective, all three flag.
Accountability that matches the statute
The PFMA names one accountable person. Dimeri does the same: every obligation, control and action has a single named owner rather than a department, so the accounting officer can see exactly who holds what and where it has stalled.
Evidence gathered through the year
Evidence is attached to the obligation at the moment the control operates, not reconstructed in the weeks before the audit. When the Auditor-General asks for support for a section 38 assertion, the file is already there with its date and its author.
Audit findings that close
Prior year findings, internal audit findings and material irregularities are tracked in one place with owners, due dates and escalation. Repeat findings are the most common audit outcome in the public sector, and they are usually a tracking failure rather than a remediation failure.
Getting PFMA coverage in place
- 1
Load the obligation set
Dimeri arrives with the PFMA broken into its obligations and pre-mapped to the Treasury Regulations and the PSRMF. You are adjusting a starting position rather than building from a blank register.
- 2
Assign accountability
Each obligation is given a named owner and a reviewer. Where the entity is a Schedule 3A public entity rather than a department, the section 51 wording replaces the section 38 wording automatically.
- 3
Link controls and find the gaps
Existing controls are attached to the obligations they satisfy. What is left over is the gap list, ranked by the risk sitting behind it, which becomes the remediation plan the audit committee sees.
- 4
Run the reporting cycle
Quarterly risk reports, audit committee packs and the annual report inputs are produced from the same live data, so the numbers in the board pack and the numbers in the annual report cannot drift apart.
PFMA questions
Does the PFMA or the MFMA apply to us?
The PFMA applies to national and provincial departments, constitutional institutions and the public entities listed in Schedules 2 and 3 of the Act, together with their subsidiaries. Municipalities and municipal entities fall under the Municipal Finance Management Act instead. Dimeri carries both obligation sets, so a provincial department and a municipal entity in the same group each see the one that applies to them.
What is the difference between an accounting officer and an accounting authority?
An accounting officer is the head of a department or constitutional institution and carries the duties in section 38. An accounting authority is the board or controlling body of a public entity and carries the equivalent duties in section 51. The substance of the two sections is close to identical, which is why Dimeri holds one obligation set and applies the correct statutory wording based on the institution type.
How does the PFMA relate to the Treasury Regulations?
Section 76 of the PFMA empowers the National Treasury to issue Treasury Regulations, and those regulations carry the operational detail the Act leaves out. The Act says maintain a system of risk management; TR 3.2 says conduct regular risk assessments and maintain a risk management strategy that includes a fraud prevention plan. The two are read together, and Dimeri maps them together.
Can Dimeri help with irregular expenditure disclosure?
Yes. Irregular, unauthorised and fruitless and wasteful expenditure is held as a register with the root cause, the responsible official, the consequence management action and its status. The disclosure note for the annual financial statements is drawn from that register rather than assembled separately at year end.
Is this a substitute for legal advice?
No. These pages describe how Dimeri structures PFMA obligations so they can be tracked and evidenced. They are not legal advice, and your own legal advisers should confirm which provisions apply to your institution and how.
Put PFMA on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.