KITE 2025 New Product Award โ€” Local IT | SACEEC
Public sector

PFMA coverage that keeps the accounting officer ahead of the audit

Every duty mapped to a control with a named owner, the evidence gathered through the year, and one view of where the institution stands at any point.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What the PFMA requires

Risk and control registers ready from day one

Enterprise risks scored and owned, controls linked to the risks they treat, and evidence of operation captured through the year rather than assembled before audit.

Internal audit tied to risk

Rolling plans derived from the risk assessment, findings tracked to closure with owners, and the reconciliation the audit committee needs produced automatically.

Expenditure tracked to closure

Irregular, unauthorised and fruitless expenditure captured with root cause, responsible official and consequence management status, ready for disclosure at year end.

Reporting from one source of truth

Audit committee packs, quarterly risk reports and annual report inputs drawn from the same live data so the numbers cannot drift apart.

PFMA compliance, covered by default

The law's core duties need systems, not documents. Dimeri supplies those systems out of the box, from risk registers and internal audit plans to expenditure tracking and reporting, so the accounting officer can demonstrate compliance at any point in the year.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

PFMA obligation library

The PFMA's main duties broken into discrete, trackable items with owners, deadlines and evidence requirements pre-configured. No manual extraction from the statute needed.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Enterprise risk register

A risk register that meets the risk management duty from day one. Scored, owned, linked to controls and refreshed on a cycle the Auditor-General can follow.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Internal audit management

Rolling three-year strategic plans, annual plans tied to the risk assessment, findings tracked to closure. The full internal audit cycle the Treasury Regulations expect.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Expenditure registers

Unauthorised, irregular and fruitless and wasteful expenditure captured with root cause, responsible official and consequence management status, ready for disclosure at year end.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Board and committee reporting

Audit committee packs and executive reporting generated from live data, so the numbers the board sees and the numbers in the annual report are always the same.

The obligations Dimeri tracks

Dimeri breaks the PFMA into discrete obligations rather than treating it as one line item. Each one carries its own owner, evidence requirement and due date.

Financial and risk systems

Systems of financial and risk management

The anchor obligation. Effective, efficient and transparent systems of financial and risk management and internal control, maintained continuously rather than assembled before an audit.

  • Enterprise risk register with named risk owners
  • Risk assessment refreshed at least annually
  • Internal control library linked to the risks it treats
  • Evidence of control operation, not just control design
Internal audit

Internal audit and audit committee

A system of internal audit operating under the control and direction of an audit committee, working to a risk based plan.

  • Rolling three year strategic internal audit plan
  • Annual internal audit plan derived from the risk assessment
  • Audit findings tracked to closure with owners and dates
  • Audit committee papers drawn from live register data
Procurement system

Procurement and provisioning system

A procurement system that is fair, equitable, transparent, competitive and cost effective, with the supporting records to prove each of those five characteristics.

  • Procurement risks held in the same register as other risks
  • Deviation and expansion approvals logged with reasons
  • Supplier and third party risk assessments
  • Declaration of interest records held against awards
Expenditure controls

Irregular and fruitless expenditure

Effective and appropriate steps to prevent unauthorised, irregular and fruitless and wasteful expenditure, and to report it when it occurs.

  • Register of unauthorised, irregular and fruitless expenditure
  • Root cause recorded against each item
  • Consequence management actions tracked to conclusion
  • Disclosure note evidence assembled during the year
Reporting

Reporting and annual financial statements

Annual financial statements submitted to the Auditor-General within two months of year end, and an annual report that includes the audited statements and a report on performance against predetermined objectives.

  • Reporting calendar with statutory deadlines and reminders
  • Performance information linked to its supporting evidence
  • Prior year audit findings carried forward and monitored
  • Board and executive reporting packs generated from live data
Financial misconduct

Financial misconduct and consequence management

Proceedings for financial misconduct where an official fails to comply, and criminal offences for the most serious breaches.

  • Case register for alleged financial misconduct
  • Investigation status, outcome and sanction recorded
  • Referrals to law enforcement tracked
  • Reporting to the relevant treasury and the executive authority

Getting PFMA coverage in place

4 steps from where you are today to a PFMA position your auditor can rely on.

Book a demo

Dimeri arrives with the PFMA broken into its obligations and pre-mapped to the Treasury Regulations and the PSRMF. You are adjusting a starting position rather than building from a blank register.

How Dimeri covers PFMA

One control, several frameworks

The risk assessment that satisfies the PFMA's risk management duty is the same assessment the Treasury Regulations and the PSRMF expect. Record the control once in Dimeri and all three scorecards move together. When it is tested and found ineffective, all three flag.

Accountability that matches the statute

The PFMA names one accountable person. Dimeri does the same: every obligation, control and action has a single named owner rather than a department, so the accounting officer can see exactly who holds what and where it has stalled.

Evidence gathered through the year

Evidence is attached to the obligation at the moment the control operates, not reconstructed in the weeks before the audit. When the Auditor-General asks for supporting evidence, the file is already there with its date and its author.

PFMA questions

Does the PFMA or the MFMA apply to us?

The PFMA applies to national and provincial departments, constitutional institutions and listed public entities, together with their subsidiaries. Municipalities and municipal entities fall under the Municipal Finance Management Act instead. Dimeri carries both obligation sets, so a provincial department and a municipal entity in the same group each see the one that applies to them.

What is the difference between an accounting officer and an accounting authority?

An accounting officer is the head of a department or constitutional institution. An accounting authority is the board or controlling body of a public entity. Both carry essentially the same duties, which is why Dimeri holds one obligation set and applies the correct wording based on the institution type.

How does the PFMA relate to the Treasury Regulations?

The PFMA empowers the National Treasury to issue Treasury Regulations, and those regulations carry the operational detail the Act leaves out. The Act says maintain a system of risk management; the Treasury Regulations add the requirement to conduct regular risk assessments and maintain a risk management strategy that includes a fraud prevention plan. The two are read together, and Dimeri maps them together.

Can Dimeri help with irregular expenditure disclosure?

Yes. Irregular, unauthorised and fruitless and wasteful expenditure is held as a register with the root cause, the responsible official, the consequence management action and its status. The disclosure note for the annual financial statements is drawn from that register rather than assembled separately at year end.

Is this a substitute for legal advice?

No. These pages describe how Dimeri structures PFMA obligations so they can be tracked and evidenced. They are not legal advice, and your own legal advisers should confirm which provisions apply to your institution and how.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.