KITE 2025 New Product Award โ€” Local IT | SACEEC
Public sector

MFMA coverage that keeps the position known before audit

Every obligation mapped to a control with a named owner, the evidence held against it, and one view of where you stand across directorates, entities and the statutory calendar.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What the MFMA requires

Risk register by directorate

A risk register segmented by directorate with named owners, scored and refreshed on a cycle the audit committee and oversight bodies can follow.

Findings that close on schedule

Prior year findings, internal audit findings and material irregularities tracked with owners, due dates and escalation so repeat findings stop repeating.

Expenditure with its cause attached

Unauthorised, irregular and fruitless expenditure logged with the control that failed, the root cause, the responsible person and the consequence management outcome.

One calendar for every reporting deadline

Monthly, quarterly, mid-year and annual reporting running off the same live record, with reminders and escalation so statutory dates are met.

MFMA compliance, covered by default

Municipalities run on a statutory calendar with monthly, quarterly, mid-year and annual reporting, a small risk team and heavy oversight from council, the provincial treasury and the Auditor-General. Dimeri is built for exactly that environment.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

MFMA obligation set with statutory dates

Core MFMA duties and the statutory reporting calendar arrive together, pre-mapped to the SCM Regulations and the PSRMF, so the first view is what is due and who holds it.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Municipal risk register

A risk register segmented by directorate with named owners, scored and refreshed on a cycle the audit committee and the Auditor-General can follow.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Findings that close

Prior year findings, internal audit findings and material irregularities tracked in one place with owners, due dates and escalation, because repeat findings are the most common audit outcome in local government.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Expenditure and consequence tracking

Unauthorised, irregular and fruitless expenditure logged with the control that failed, the root cause, the responsible person and the consequence management outcome.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Council and committee reporting

Audit committee packs, council reports and provincial treasury returns generated from the same live data. Figures that reconcile by construction rather than by hand each quarter.

The obligations Dimeri tracks

The MFMA runs on a calendar. Dimeri holds the duties and the dates together, so a deadline that is about to be missed is visible while there is still time to act.

Financial and risk management systems

Effective, efficient and transparent systems of financial and risk management and internal control, maintained and demonstrable throughout the year.

  • Municipal risk register with named owners per directorate
  • Risk assessment cycle with scheduled reviews
  • Control library linked to the risks it treats
  • Evidence captured as controls operate

Internal audit unit and audit committee

An internal audit unit operating under the control and direction of an audit committee, with the committee advising council on risk management, internal control and compliance.

  • Risk based internal audit plan tied to the register
  • Findings tracked to closure with owners and dates
  • Audit committee packs drawn from live data
  • Committee advice to council recorded and followed up

Unauthorised, irregular and fruitless expenditure

Steps to prevent it, a duty to report it, and liability for the political office bearers and officials who caused it.

  • Expenditure register with classification and root cause
  • Responsible person recorded against each item
  • Consequence management tracked to an outcome
  • Recovery and write off decisions evidenced

Evaluation of major capital projects

A system for properly evaluating all major capital projects before a commitment is made, which in practice means a documented assessment a court or an auditor could follow.

  • Project risk assessments held against the capital programme
  • Feasibility and affordability evidence attached
  • Approval trail from assessment to commitment
  • Post commitment monitoring of project risks

Reporting cycle

Monthly budget statements, a mid year budget and performance assessment, annual financial statements to the Auditor-General within two months of year end, and an annual report tabled within seven months.

  • Statutory reporting calendar with owners and reminders
  • Performance information linked to supporting evidence
  • Prior year audit findings carried into the current cycle
  • Annual report inputs assembled through the year

Financial misconduct

Allegations of financial misconduct investigated and dealt with, including the disciplinary board arrangements introduced by the financial misconduct regulations.

  • Case register with status and outcome
  • Investigation evidence held with the case
  • Reporting to council, treasury and where required the police
  • Trend reporting on repeat causes

Getting MFMA coverage in place

4 steps from where you are today to a MFMA position your auditor can rely on.

Book a demo

The MFMA duties and their statutory dates arrive together, pre-mapped to the SCM Regulations and the PSRMF, so the first thing you see is what is due and who holds it.

How Dimeri covers MFMA

One register, every audience

The municipal risk register feeds the risk committee report, the audit committee pack, the periodic reporting narrative and the annual report. Each audience gets its own view of the same underlying record, so the versions cannot contradict one another.

Expenditure with its cause attached

Irregular expenditure is recorded with the control that failed, not only the amount and the reference. That turns the annual disclosure note into a by-product of the year's work and gives consequence management something specific to act on.

Entities consolidated with the parent

Municipal entities carry their own duties under the MFMA. Dimeri holds each entity's register separately and rolls it into a group view for the parent municipality, so the accounting officer sees the whole picture without chasing spreadsheets.

MFMA questions

Does the MFMA apply to municipal entities as well as municipalities?

Yes. Municipal entities carry duties under the MFMA through their accounting officer and board of directors, and the parent municipality has its own oversight responsibilities in respect of them. Dimeri holds each entity's obligations separately and consolidates them into a group view for the parent.

What does the MFMA expect of the municipal manager?

The MFMA places a duty on the accounting officer to take all reasonable steps to ensure the municipality has and maintains effective financial and risk management, internal control, internal audit under an audit committee, an appropriate procurement system, and a system for evaluating major capital projects before commitment. Dimeri tracks each of those duties with a named owner.

How does Dimeri help with repeat audit findings?

Repeat findings usually happen because a management action was agreed and then not followed to completion. Dimeri holds every finding as an action with a named owner, a due date and escalation, and carries unresolved items forward into the next cycle automatically rather than letting them fall off a spreadsheet.

Can we report to council and the audit committee from the same data?

Yes, and that is the point. Council reporting, audit committee packs and provincial treasury returns are generated from the same register, so the figures reconcile by construction instead of being reconciled by hand each quarter.

Is this a substitute for legal advice?

No. This page describes how Dimeri structures MFMA obligations for tracking and evidence. It is not legal advice, and your legal advisers should confirm which provisions apply to your municipality or entity.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.