KITE 2025 New Product Award โ€” Local IT | SACEEC
Public sector

Treasury Regulations coverage that connects risk to audit by design

Every obligation tracked on a cycle with a named owner, the fraud prevention plan operating inside the register, and the audit plan reconciled to risk automatically.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What the Treasury Regulations require

Risk assessments on a defensible cycle

Scheduled reviews, emerging risk capture and version history showing how the picture changed, so regular means demonstrably regular.

Fraud prevention inside the register

Fraud risks sit alongside operational and financial risk with the same scoring, owners and control evidence. The plan is auditable because it is operating, not filed.

Audit plan traced to risk

Every engagement linked to the register entry that justifies it, with a coverage view showing which top risks are unaudited and why.

Committee papers from live data

Audit committee packs generated from the register and findings data, with the risk to audit reconciliation included as a standing report.

Treasury Regulations compliance, covered by default

The Treasury Regulations turn the PFMA's broad duties into working requirements, from risk assessments and fraud prevention plans to audit plans and committee papers. Dimeri delivers each one as a working system rather than a document to maintain.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Risk management obligations mapped

Risk assessment cycles, the risk management strategy, the fraud prevention plan and the link to internal audit. Each is held as a tracked obligation with its own review date and owner.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Fraud prevention plan

Fraud risks live in the main register with their own controls and evidence, so the plan is auditable and operating rather than a standalone document filed once a year.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Risk-to-audit reconciliation

The view the rules imply, every significant risk on one axis and every planned engagement on the other, produced automatically from the register and the audit plan.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Audit committee packs

Committee papers drawn from live register and findings data, with the reconciliation between the risk register and the audit plan included as a standing report.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Cycle enforcement

Assessment reviews, control tests, strategy refreshes and committee dates run as recurring obligations with reminders and escalation, so regular means regular.

The obligations Dimeri tracks

Dimeri holds the Treasury Regulations as operational obligations on a cycle rather than as documents on a shelf, because that is how they are tested.

Regular risk assessment

A risk assessment conducted regularly to identify emerging risks, not a single annual exercise that goes stale by the second quarter.

  • Assessment cycle with scheduled reviews and reminders
  • Emerging risk capture between formal cycles
  • Inherent and residual scoring with a documented basis
  • Version history showing how the picture changed

Risk management strategy and fraud prevention plan

A risk management strategy that includes a fraud prevention plan, communicated to all officials so they understand what it asks of them.

  • Strategy and fraud prevention plan held against their review dates
  • Fraud risks recorded with their specific preventive controls
  • Distribution and acknowledgement records for officials
  • Approval trail through the risk committee and accounting officer

Risk strategy directing internal audit

The link most institutions cannot evidence: the risk management strategy used to direct internal audit effort and priority.

  • Audit plan line items traced to register entries
  • Coverage view showing which top risks are unaudited
  • Rationale recorded where a high risk is deliberately not audited
  • Reconciliation produced for the audit committee

Internal audit function and plans

An internal audit function working to a rolling three year strategic plan based on key areas of risk, with an annual plan for the first year.

  • Rolling three year plan held against the risk assessment
  • Annual plan with engagement status and resourcing
  • Findings tracked to closure with owners and due dates
  • Follow up on previously agreed management actions

Audit committee oversight

An audit committee that receives and evaluates the work, with papers it can rely on rather than reconstruct.

  • Committee calendar with standing agenda items
  • Packs generated from live register and findings data
  • Matters arising tracked between meetings
  • Annual committee report inputs assembled through the year

Public entity equivalents

Public entities carry equivalent risk management and internal audit duties, applied through the accounting authority rather than an accounting officer.

  • Entity obligation set with the correct statutory wording
  • Board and committee reporting lines reflected in the workflow
  • Group view across entities for a parent department
  • Consolidated risk reporting to the executive authority

Getting Treasury Regulations coverage in place

4 steps from where you are today to a Treasury Regulations position your auditor can rely on.

Book a demo

The internal audit and risk management duties arrive broken into their component parts, pre-mapped to the matching PFMA and PSRMF requirements so you are not maintaining three registers.

How Dimeri covers Treasury Regulations

The audit plan reconciliation

Dimeri produces the view the regulations call for: every significant risk on one axis, every planned audit engagement on the other, and the uncovered cells visible. This is usually the fastest thing to fix and the hardest to produce from spreadsheets.

Fraud risk held with everything else

The fraud prevention plan stops being a standalone document. Fraud risks live in the same register as operational and financial risk, with the same scoring, the same owners and the same control evidence, which is what makes the plan auditable.

Cycles that run themselves

Regular means on a schedule. Assessment reviews, control tests, strategy refreshes and committee dates run as recurring obligations with reminders and escalation, so a missed cycle surfaces while it can still be fixed.

Treasury Regulations questions

Which Treasury Regulations matter most for risk and assurance?

The internal audit and risk management provisions do most of the work. One set covers internal audit, including the rolling three year strategic plan based on key areas of risk and the annual plan. The other covers risk management, including regular risk assessment and a risk management strategy incorporating a fraud prevention plan. Public entities carry equivalent duties.

Do the Treasury Regulations require a fraud prevention plan?

Yes. The risk management provisions call for the strategy to include a fraud prevention plan. In Dimeri the plan is not a standalone file: the fraud risks it addresses sit in the main register with their own controls and evidence, so the plan can be shown to be operating rather than simply to exist.

What does it mean that the risk strategy must direct internal audit?

The regulations call for the risk management strategy to be used to direct internal audit effort and priority. In practice an auditor will ask you to show which risks drove which engagements. Dimeri maintains that link directly, so the reconciliation between the risk register and the audit plan is a report rather than a project.

How often is regularly?

The regulations say regularly rather than naming a frequency, which leaves it to the institution to set a defensible cycle and then keep to it. Most institutions run a full annual assessment with quarterly reviews and continuous capture of emerging risks. Dimeri enforces whichever cycle you set and shows when it slips.

Is this a substitute for legal advice?

No. This page describes how Dimeri structures Treasury Regulations obligations for tracking and evidence. It is not legal advice, and your legal advisers should confirm the current text and which provisions apply to your institution.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.