KITE 2025 New Product Award โ€” Local IT | SACEEC
Public sector

MFMA SCM Regulations SCM Regulations coverage that catches findings at the transaction

Every deviation, declaration and committee resolution captured at the point it happens, with the evidence held against the control it satisfies and one view of where you stand.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What the SCM Regulations require

Bid committees with a full trail

Composition, attendance, conflicts, recusals and resolutions captured per procurement. Dimeri evidences the separation the regulations require at every transaction.

Deviations recorded in real time

Every deviation logged with its ground, the reasons recorded at the time, accounting officer approval and reporting to council, live rather than reconstructed at year end.

Supplier screening per award

Declarations of interest, state employee checks, arrears screening and restricted supplier checks held against each award as evidence the auditor can pull.

Irregular expenditure traced to a control

Each item in the expenditure register linked to the SCM control that failed, turning the register into a diagnosis rather than a tally.

MFMA SCM Regulations compliance, covered by default

Most irregular expenditure in local government traces back to a supply chain step that was skipped or undocumented. Dimeri captures the deviation, the declaration and the committee resolution when they happen, not when an auditor asks for them.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

SCM policy mapped to controls

Every part of the adopted SCM policy is tied to the control that implements it. Any part with no control behind it surfaces immediately as the starting gap list.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Bid committee evidence

Committee composition, quorum, attendance, conflicts, recusals and resolutions captured per procurement, the record the Auditor-General tests at the transaction level.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Deviation register

Every deviation logged with the reason behind it, recorded at the time, plus accounting officer approval and reporting to council, live rather than reconstructed at year end.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Supplier screening and declarations

Declaration of interest, persons in the service of the state checks, municipal account arrears checks and restricted supplier screening, all held against each award.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Contract lifecycle tracking

Contract register with expiry dates, performance monitoring, amendments and expansions, each with an approval trail and supplier risk reviewed through the contract life.

The obligations Dimeri tracks

Dimeri treats each SCM rule as a transactional control with evidence attached, because that is the level at which the Auditor-General tests it.

SCM policy adopted and implemented

A supply chain management policy that meets the prescribed minimum content, adopted by council and actually operated.

  • Policy held against its review and adoption dates
  • Policy clauses mapped to the controls that implement them
  • Delegations recorded with their current holders
  • Gap analysis against the prescribed framework

Bid committee system

Bid specification, evaluation and adjudication committees properly constituted, with the separation between them maintained and evidenced.

  • Committee composition recorded per procurement
  • Quorum and attendance captured with the resolution
  • Conflicts declared and recusals documented
  • Evaluation reports held with the adjudication decision

Procurement thresholds

The value of a procurement determines whether petty cash, verbal or written quotations, formal written price quotations or a competitive bidding process applies.

  • Threshold applied and recorded per transaction
  • Splitting of orders flagged for review
  • Minimum quotation counts evidenced
  • Advertising periods tracked for competitive bids

Deviations from the SCM process

Deviation is permitted in defined circumstances, including emergency and sole supplier, but the reasons must be recorded and reported.

  • Deviation register with the ground relied on
  • Reasons recorded at the time, not reconstructed
  • Accounting officer approval captured
  • Reporting to council and inclusion in the next report

Abuse, prohibited awards and declarations

Measures to combat abuse of the system, the prohibition on awards to persons in the service of the state, and the rules on awards where municipal accounts are in arrears.

  • Declaration of interest held against each award
  • Screening against persons in the service of the state
  • Municipal account arrears check evidenced
  • Restricted and blacklisted supplier checks recorded

Contract management

Contracts monitored on a monthly basis, with amendments and expansions handled through the proper process rather than by practice.

  • Contract register with expiry and renewal dates
  • Performance monitoring recorded against the contract
  • Amendments and expansions with their approval trail
  • Supplier risk reviewed through the contract life

Getting MFMA SCM Regulations coverage in place

4 steps from where you are today to a MFMA SCM Regulations position your auditor can rely on.

Book a demo

Your adopted SCM policy is loaded and each clause is tied to the control that implements it. Clauses with no control behind them are the starting gap list.

How Dimeri covers MFMA SCM Regulations

Deviations that cannot go dark

Every deviation is logged with its ground, its reasons and its approver at the time it is taken. The register is live, so the pattern of deviations by department, supplier and value is visible long before it appears in an audit report.

Irregular expenditure traced to a control

When irregular expenditure is recorded in the MFMA register, Dimeri links it to the SCM control that failed. Over a year that turns the expenditure register into a diagnosis rather than a tally.

Supplier and third party risk in the same place

Supplier screening, declarations, performance and contract expiry live alongside the procurement controls rather than in a separate vendor system, so a supplier problem and a compliance problem are visible as one thing.

MFMA SCM Regulations questions

Do the SCM Regulations apply to municipal entities?

Yes. The MFMA obliges every municipality and municipal entity to have and implement a supply chain management policy, and the regulations set the framework that policy must meet. Dimeri holds each entity's SCM controls separately and rolls them into the parent municipality's view.

How does Dimeri handle procurement thresholds?

Thresholds are configured to match your adopted policy and the prescribed framework, and each transaction records which threshold was applied and why. Where orders appear to have been split to stay below a threshold, the pattern is flagged for review rather than left to be found at audit.

What does the regulation on deviations actually require?

The regulations permit the accounting officer to dispense with the prescribed procurement processes in specified circumstances, including emergencies and where a sole supplier exists, but the reasons must be recorded and reported. The failure is almost never the deviation itself. It is the absence of a contemporaneous record of why it was taken.

Can this replace our procurement system?

No, and it is not meant to. Dimeri holds the compliance and risk layer over whatever procurement or financial system you run: the controls, the declarations, the deviations, the approvals and the evidence. The transactions themselves stay where they are.

Is this a substitute for legal advice?

No. This page describes how Dimeri structures municipal supply chain obligations for tracking and evidence. It is not legal advice, and your legal advisers should confirm the current regulations, thresholds and how they apply to you.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.