Treasury Regulations, from the fraud prevention plan to the audit committee pack
The Treasury Regulations carry the operational detail the PFMA leaves out. Regulation 3.2 is where the duty to manage risk becomes a duty to run assessments, hold a strategy and maintain a fraud prevention plan. Dimeri tracks each of those as an obligation with an owner, a cycle and a file behind it.
What the Treasury Regulations require
Section 76 of the Public Finance Management Act empowers the National Treasury to make regulations, and those regulations are where the Act's broad duties acquire shape. The PFMA says maintain a system of risk management. The Treasury Regulations say how often to assess, what the strategy must contain, who directs internal audit, and what the audit committee must do with the result.
Part 3 carries most of what a risk and assurance function needs. Regulation 3.1 deals with internal audit: the institution must have an internal audit function, it must prepare a rolling three year strategic internal audit plan based on an assessment of key areas of risk, and it must prepare an annual plan for the first year of that rolling plan. Regulation 3.2 deals with risk management: the accounting officer must ensure that a risk assessment is conducted regularly to identify emerging risks, and that a risk management strategy, which must include a fraud prevention plan, is used to direct internal audit effort and priority.
That last clause is the one most institutions under-read. The regulation does not just require a risk assessment and a fraud prevention plan as separate documents. It requires the risk management strategy to actually drive where internal audit spends its time. If the audit plan cannot be traced back to the risk register, the regulation has not been met even where both documents exist.
The obligations Dimeri tracks
Dimeri holds the Treasury Regulations as operational obligations on a cycle rather than as documents on a shelf, because that is how they are tested.
Regular risk assessment
A risk assessment conducted regularly to identify emerging risks, not a single annual exercise that goes stale by the second quarter.
- Assessment cycle with scheduled reviews and reminders
- Emerging risk capture between formal cycles
- Inherent and residual scoring with a documented basis
- Version history showing how the picture changed
Risk management strategy and fraud prevention plan
A risk management strategy that includes a fraud prevention plan, communicated to all officials so they understand what it asks of them.
- Strategy and fraud prevention plan held against their review dates
- Fraud risks recorded with their specific preventive controls
- Distribution and acknowledgement records for officials
- Approval trail through the risk committee and accounting officer
Risk strategy directing internal audit
The link the regulation requires and most institutions cannot evidence: the risk management strategy used to direct internal audit effort and priority.
- Audit plan line items traced to register entries
- Coverage view showing which top risks are unaudited
- Rationale recorded where a high risk is deliberately not audited
- Reconciliation produced for the audit committee
Internal audit function and plans
An internal audit function working to a rolling three year strategic plan based on key areas of risk, with an annual plan for the first year.
- Rolling three year plan held against the risk assessment
- Annual plan with engagement status and resourcing
- Findings tracked to closure with owners and due dates
- Follow up on previously agreed management actions
Audit committee oversight
An audit committee that receives and evaluates the work, with papers it can rely on rather than reconstruct.
- Committee calendar with standing agenda items
- Packs generated from live register and findings data
- Matters arising tracked between meetings
- Annual committee report inputs assembled through the year
Public entity equivalents
Public entities carry equivalent risk management and internal audit duties, applied through the accounting authority rather than an accounting officer.
- Entity obligation set with the correct statutory wording
- Board and committee reporting lines reflected in the workflow
- Group view across entities for a parent department
- Consolidated risk reporting to the executive authority
How Dimeri covers Treasury Regulations
The Treasury Regulations, the PFMA and the Public Sector Risk Management Framework describe overlapping duties in different words. Dimeri treats them as one control set with three views.
The audit plan reconciliation
Dimeri produces the view that regulation 3.2 implies: every significant risk on one axis, every planned audit engagement on the other, and the uncovered cells visible. This is usually the fastest thing to fix and the hardest to produce from spreadsheets.
Fraud risk held with everything else
The fraud prevention plan stops being a standalone document. Fraud risks live in the same register as operational and financial risk, with the same scoring, the same owners and the same control evidence, which is what makes the plan auditable.
Cycles that run themselves
Regular means on a schedule. Assessment reviews, control tests, strategy refreshes and committee dates run as recurring obligations with reminders and escalation, so a missed cycle surfaces while it can still be fixed.
Shared credit with the PFMA and PSRMF
One risk assessment satisfies TR 3.2, PFMA section 38(1)(a)(i) and the PSRMF risk identification and assessment chapters. Dimeri records it once and reflects it in each framework scorecard.
Getting Treasury Regulations coverage in place
- 1
Load Part 3 as obligations
Regulations 3.1 and 3.2 arrive broken into their component duties, pre-mapped to the matching PFMA sections and PSRMF chapters so you are not maintaining three registers.
- 2
Attach the existing documents
The current risk management strategy, fraud prevention plan and audit plans are loaded and dated. Anything past its review date shows immediately, which is often the first finding.
- 3
Build the risk to audit link
Audit plan engagements are tied to the register entries that justify them. The uncovered high risks become a conversation for the audit committee rather than a finding for the Auditor-General.
- 4
Set the cycle running
Review dates, test schedules and committee dates are loaded with owners and reminders, so regular becomes a property of the system rather than an intention.
Treasury Regulations questions
Which Treasury Regulations matter most for risk and assurance?
Part 3 does most of the work. Regulation 3.1 covers internal audit, including the rolling three year strategic plan based on key areas of risk and the annual plan. Regulation 3.2 covers risk management, including regular risk assessment and a risk management strategy incorporating a fraud prevention plan. Public entities carry equivalent duties under regulation 27.2.
Do the Treasury Regulations require a fraud prevention plan?
Yes. Regulation 3.2 requires the risk management strategy to include a fraud prevention plan. In Dimeri the plan is not a standalone file: the fraud risks it addresses sit in the main register with their own controls and evidence, so the plan can be shown to be operating rather than simply to exist.
What does it mean that the risk strategy must direct internal audit?
Regulation 3.2 requires the risk management strategy to be used to direct internal audit effort and priority. In practice an auditor will ask you to show which risks drove which engagements. Dimeri maintains that link directly, so the reconciliation between the risk register and the audit plan is a report rather than a project.
How often is regularly?
The regulation says regularly rather than naming a frequency, which leaves it to the institution to set a defensible cycle and then keep to it. Most institutions run a full annual assessment with quarterly reviews and continuous capture of emerging risks. Dimeri enforces whichever cycle you set and shows when it slips.
Is this a substitute for legal advice?
No. This page describes how Dimeri structures Treasury Regulations obligations for tracking and evidence. It is not legal advice, and your legal advisers should confirm the current text and which provisions apply to your institution.
Go further on Treasury Regulations
Put Treasury Regulations on one register
Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.