Corporate Governance and Control is a core topic in the University of Johannesburg (UJ) BCom Accounting curriculum, particularly in modules such as ACC3CGN: Corporate Governance and Ethics and ACC3CGE: Corporate Governance and Control. These notes provide an integrated, exam‑oriented guide aligned with South African corporate governance practice, including the King IV Report on Corporate Governance for South Africa, the Companies Act 71 of 2008, JSE Listings Requirements, and common exam themes similar to those found in UNISA modules like MNM3702, ACN203S, and governance questions in TAX3701.
The focus is on how governance frameworks, structures, and internal control systems operate in practice within South African companies, with specific emphasis on what BCom Accounting students at UJ are expected to understand for tests, assignments, and examinations. Definitions, frameworks, examples, and exam‑style insights are integrated throughout to build a comprehensive, practice‑ready understanding of corporate governance and control.
1. Foundations of Corporate Governance in South Africa
1.1 Definition, Purpose and Key Principles
Corporate governance refers to the systems, processes, structures, and relationships by which companies are directed and controlled. In the South African context, governance is strongly influenced by the King IV Report on Corporate Governance for South Africa (2016) and the Companies Act 71 of 2008, which affect companies studied in UJ modules such as ACC3CGN and ACC3CGE.
Common exam definition (adaptable for ACC3CGN):
Corporate governance is the framework of rules, relationships, systems and processes within and by which authority is exercised and controlled in corporations. It encompasses mechanisms by which companies, and those in control, are held to account.
Core purposes of corporate governance:
- Accountability – ensuring the board and management are answerable to shareholders and key stakeholders.
- Transparency – enabling informed decision‑making by stakeholders through clear, accurate, and timely disclosures.
- Fairness – protecting minority shareholders and balancing the interests of different stakeholders.
- Responsibility – ensuring compliance with laws, ethical standards, and internal codes of conduct.
- Value creation and sustainability – promoting long‑term sustainable performance, not just short‑term profit.
These purposes link directly to King IV’s governing objectives, which examiners at UJ frequently assess:
- Ethical culture
- Good performance
- Effective control
- Legitimacy
1.2 Agency Theory and Other Theoretical Foundations
Understanding theoretical underpinnings is common in essay‑type questions for both ACC3CGN at UJ and governance components in similar modules at UNISA (e.g. MNM3702 – Strategic Marketing, which covers stakeholder management).
1.2.1 Agency Theory
Agency theory is the dominant framework in corporate governance:
- Principals – shareholders (owners of the company).
- Agents – directors and management who control the company’s resources.
Agency problem: Agents may pursue their own interests (e.g., higher bonuses, perks, empire building) instead of shareholder wealth maximisation. This leads to:
- Excessive risk‑taking or excessive risk avoidance.
- Over‑investment in low‑return projects.
- Manipulation of earnings (earnings management).
- Misappropriation or inefficient use of company assets.
Agency costs are incurred to mitigate these conflicts:
- Monitoring costs – costs of supervising management (e.g., internal audit, external audit fees, board oversight).
- Bonding costs – costs borne by management to commit to acting in shareholders’ interests (e.g., performance‑linked remuneration).
- Residual loss – remaining loss due to imperfect alignment.
Corporate governance mechanisms studied in UJ’s BCom Accounting (e.g. audit committees, independent non‑executive directors, internal control systems) are designed to reduce these agency costs.
1.2.2 Stakeholder Theory
Stakeholder theory is highly relevant in the South African environment and emphasised in King IV:
- Companies have responsibilities not only to shareholders, but also to employees, customers, suppliers, communities, government, and the environment.
- Decisions must consider the legitimate and reasonable needs, interests and expectations of these stakeholders.
In exam questions, you may be asked to contrast shareholder primacy (maximising shareholder value) with stakeholder inclusivity (King IV’s approach). For example:
- A mining company considering closing a loss‑making shaft: shareholder primacy might support closure; stakeholder inclusivity would weigh job losses, community impact, and environmental consequences.
1.2.3 Stewardship Theory and Other Views
Stewardship theory assumes that managers are stewards whose motives are aligned with organisational goals—seeking achievement, growth, and satisfaction rather than self‑interest. This theory supports:
- Empowering executives.
- Trust‑based relationships.
- Less heavy monitoring.
In practice, South African governance blends both agency and stewardship views: boards monitor management (agency), but also support them as partners in value creation (stewardship).
Other relevant views:
- Resource dependence theory – the board provides access to critical resources and external networks.
- Institutional theory – governance practices are influenced by laws, regulations, and norms (e.g. JSE Listings Requirements).
1.3 Corporate Governance in South Africa: Historical Context
Corporate governance in South Africa evolved through several phases that UJ examiners sometimes ask you to outline:
- King I (1994) – Focus on financial and regulatory aspects; voluntary code aimed at listed companies.
- King II (2002) – Introduced the triple bottom line (economic, social, environmental); broadened to risk management and sustainability.
- King III (2009) – Applied to all entities (public, private, and non‑profit); introduced “apply or explain”.
- King IV (2016) – Principles‑based; focused on outcomes; changed to “apply and explain”; emphasised integrated thinking and stakeholder inclusivity.
Companies Act 71 of 2008 (effective 2011) strengthened governance by:
- Clarifying directors’ duties and liabilities.
- Introducing the Company Secretary for certain companies.
- Compulsory Audit Committees for public and certain state‑owned companies.
- Regulation of financial reporting standards (IFRS/IFRS for SMEs).
1.4 King IV Principles (High‑Level Overview)
King IV includes 17 principles applicable to all organisations. In UJ exams, you are rarely required to list all 17, but you must understand key themes:
- Ethical and effective leadership (Principle 1).
- Performance and value creation (Strategy and performance principles).
- Risk governance (Governance of risk and opportunity).
- Technology and information governance (IT governance).
- Compliance governance (laws, rules, codes, standards).
- Remuneration (fair, responsible, transparent pay).
- Assurance (combined assurance model).
- Stakeholder relationships (inclusive, transparent engagement).
Example exam directive:
“Discuss, with reference to King IV, how the board of a JSE‑listed manufacturing company should govern risk and opportunity.”
You would integrate:
- The board’s overall responsibility for risk governance.
- The need for a formal risk management policy.
- The role of the risk committee.
- Embedding risk consideration in strategy and decision‑making.
1.5 Good vs Poor Corporate Governance: Why It Matters
Benefits of good corporate governance:
- Lower cost of capital (investors and lenders demand lower risk premiums).
- Improved access to finance (especially for JSE‑listed companies).
- Better decision‑making and long‑term performance.
- Enhanced reputation and legitimacy (important in South Africa where corporate scandals erode trust).
- Reduced likelihood of corporate failures and fraud.
Consequences of poor corporate governance (often tested with case‑style questions inspired by South African examples):
- Financial misstatements and restatements.
- Fraud and corruption (e.g., procurement irregularities).
- Regulatory penalties and litigation.
- Share price collapse and loss of investor confidence.
- Business failure and job losses.
In ACC3CGN/ACC3CGE, you may be given a scenario similar to well‑known South African cases of governance failure and asked to:
- Identify governance weaknesses.
- Link them to appropriate King IV principles.
- Propose improvements (e.g., stronger independent oversight, enhanced internal controls, whistle‑blowing mechanisms).
2. Board Structures, Roles, and Committees (UJ ACC3CGE Focus)
2.1 The Board of Directors: Composition and Responsibilities
The board of directors is central to corporate governance and is a core topic in UJ BCom Accounting modules dealing with corporate governance and control.
Board composition:
- Executive directors – employees with management responsibilities (e.g. CEO, CFO).
- Non‑executive directors (NEDs) – not part of management; provide oversight and independent judgment.
- Independent non‑executive directors (INEDs) – NEDs who meet specific independence criteria (no material relationship with the company).
King IV expectations for JSE‑listed companies:
- A majority of non‑executive directors.
- A majority of independent directors.
- Chair of the board should be an independent non‑executive director.
Primary responsibilities (often examined in essay or short‑answer form):
- Setting the company’s strategic direction and approving major policies.
- Overseeing risk governance and ensuring that risk and opportunity are integrated into strategy.
- Ensuring the company has an adequate and effective system of internal controls.
- Approving annual financial statements and integrated reports.
- Appointing, monitoring, and (if necessary) dismissing the CEO and senior executives.
- Approving the remuneration policy and ensuring executive remuneration is aligned with long‑term value creation.
- Ensuring compliance with laws, regulations, and codes of best practice (e.g., King IV, JSE Listings Requirements).
- Safeguarding the interests of shareholders and other key stakeholders.
2.2 Separation of Roles: Chairperson vs CEO
A typical exam multiple‑choice question in ACC3CGN might ask: “Which is a key King IV recommendation regarding the roles of chair and CEO?”
Best practice:
- The roles of Chairperson and CEO should be separate.
- The Chairperson should be an independent non‑executive director.
- If the Chair is not independent, a lead independent director (LID) must be appointed.
Rationale:
- Prevents concentration of power.
- Enhances board independence and objectivity.
- Improves oversight of management.
Chairperson’s role:
- Leads the board, not the company’s day‑to‑day operations.
- Ensures effective functioning of the board and its committees.
- Facilitates constructive relationships between board members.
- Ensures that directors receive accurate, timely information.
CEO’s role:
- Leads management and day‑to‑day operations.
- Implements board‑approved strategy and policies.
- Reports to the board on performance, risks, and opportunities.
2.3 Board Committees: Types, Roles, and Exam Focus
King IV and the Companies Act require or strongly recommend certain board committees. UJ exam questions often provide a scenario and ask you to:
- Identify which committee should handle a particular issue.
- Describe its composition and responsibilities.
- Explain how it contributes to good governance and control.
2.3.1 Audit Committee
Mandatory for: Public companies, state‑owned companies, and certain other categories under the Companies Act.
Composition:
- At least three independent non‑executive directors.
- Members must be financially literate; at least one member should have accounting or auditing expertise.
- Chaired by an independent non‑executive director who is not the board chair.
Key responsibilities:
- Oversee the integrity of financial reporting:
- Review annual financial statements, integrated reports, and interim reports.
- Assess suitability of accounting policies and significant estimates.
- Oversee the external audit:
- Recommend the appointment or reappointment of the external auditor.
- Monitor the auditor’s independence (e.g. non‑audit services caps).
- Review the audit plan and findings.
- Oversee the internal audit function:
- Approve the internal audit charter.
- Review internal audit plans, resources, and reports.
- Evaluate the independence and effectiveness of internal audit.
- Oversee the system of internal controls and combined assurance:
- Assess whether internal controls are adequate and effective.
- Coordinate assurance from management, internal audit, external audit, and other providers.
- Oversee risk related to financial reporting and fraud:
- Monitor significant financial risks.
- Review procedures for whistle‑blowing and fraud reporting.
Exam tip (UJ ACC3CGE): Practice answering scenario questions such as:
“Explain how the audit committee of XYZ Ltd (a JSE‑listed entity) should respond when internal audit reports significant weaknesses in revenue recognition controls.”
You would discuss:
- Investigating findings.
- Engaging with management on remediation.
- Considering the impact on financial statements.
- Communicating with external auditors.
- Monitoring the corrective action plan.
2.3.2 Risk Committee (or Combined Audit and Risk Committee)
Some companies have a separate risk committee; others combine it with the audit committee (Audit and Risk Committee). King IV recommends:
- A dedicated focus on risk governance.
- Clear terms of reference.
- Formalised reporting to the board.
Responsibilities:
- Develop and recommend a risk management policy and framework.
- Identify and assess key risks (strategic, financial, operational, compliance, IT).
- Monitor risk mitigation strategies.
- Ensure risk is considered in strategy, capital allocation, and performance management.
- Oversee business continuity and disaster recovery planning.
Risk is also intensively tested in UJ accounting modules’ internal control questions (e.g., linking risks to specific control activities in sales, purchases, payroll cycles).
2.3.3 Remuneration Committee
In many South African companies, remuneration issues are handled by a Remuneration Committee or a Remuneration and Nominations Committee (RemCo/NomCo).
Composition:
- Majority independent non‑executive directors.
- Chair is an INED (not the board chair, unless justified).
Responsibilities:
- Develop and recommend the remuneration policy for directors and executives.
- Ensure alignment of remuneration with long‑term value creation and company strategy.
- Oversee the design of short‑term and long‑term incentive schemes.
- Ensure pay structures are fair, responsible, and transparent.
- Oversee the preparation of the remuneration report and engage shareholders on it (advisory vote at AGM).
2.3.4 Social and Ethics Committee (SEC)
The Social and Ethics Committee is mandated by the Companies Act and is especially relevant to South African corporates. UJ examiners may ask about:
- Purpose of the SEC.
- Its composition.
- Its role in promoting ethical conduct.
Composition:
- At least three directors or prescribed officers.
- At least one non‑executive director.
Responsibilities:
- Monitor the company’s activities relating to:
- Social and economic development.
- Good corporate citizenship.
- Environment, health, and public safety.
- Consumer relationships.
- Labour and employment (e.g., transformation, diversity, fair labour practices).
- Oversee ethics management and whistle‑blowing mechanisms.
- Report to the board, shareholders, and other stakeholders.
2.3.5 Nominations Committee
Often combined with RemCo, the Nominations Committee focuses on:
- Board composition, diversity, and succession planning.
- Identifying and recommending new directors.
- Evaluating performance of the board, committees, and individual directors.
2.4 Director Duties and Liabilities under Companies Act 71 of 2008
UJ BCom Accounting students must be familiar with legal duties of directors (often tested in case‑style questions).
Key statutory duties:
- Fiduciary duties – to act:
- In good faith.
- In the best interests of the company.
- For a proper purpose.
- With a duty to avoid conflicts of interest.
- Duty of care, skill, and diligence:
- Exercise the degree of care, skill, and diligence that may reasonably be expected of someone:
- Carrying out the same functions.
- With the general knowledge, skill, and experience of that person.
- Exercise the degree of care, skill, and diligence that may reasonably be expected of someone:
Examples of breach:
- Approving financial statements without adequate understanding or inquiry.
- Entering into transactions where the director has a personal interest without proper disclosure and approval.
- Neglecting to implement necessary controls leading to significant losses.
Liability:
- Personal liability for losses resulting from breach of duty.
- Possible disqualification as a director.
- Criminal liability in cases of fraud or reckless/negligent trading.
2.5 Board Evaluation and Continuous Improvement
King IV encourages regular performance evaluations of:
- The board as a whole.
- Board committees.
- Individual directors.
- The Chairperson and CEO.
Evaluations may be:
- Internal (self‑assessment questionnaires).
- Assisted by external governance specialists (for objectivity).
Findings are used to:
- Address skill gaps.
- Enhance board processes.
- Refine committee structures and mandates.
In exam answers, linking board evaluation to improved governance outcomes and accountability is a strong indicator of understanding.
3. Internal Control Systems and the COSO Framework (UJ Corporate Governance and Control Core)
3.1 Definition and Objectives of Internal Control
Internal control is a central theme in ACC3CGE and related UJ accounting modules, as well as UNISA internal control questions (e.g., in FAC3703). A standard definition (COSO‑aligned) that works well in exams:
Internal control is a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
Key objectives:
- Effectiveness and efficiency of operations (e.g., profitability, safeguarding assets).
- Reliability of reporting (financial and non‑financial).
- Compliance with laws and regulations.
Note the phrase reasonable assurance – internal control cannot guarantee success; limitations exist due to human error, collusion, management override, and cost‑benefit constraints.
3.2 COSO Internal Control – Integrated Framework
UJ and UNISA often rely on the COSO framework for describing internal control components. COSO identifies five interrelated components:
- Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring Activities
3.2.1 Control Environment
The control environment is the foundation of all other components:
- Reflects the tone at the top and organisational culture.
- Influenced by:
- Integrity and ethical values.
- Commitment to competence.
- Board and audit committee oversight.
- Organisational structure.
- Assignment of authority and responsibility.
- Human resource policies and practices.
Examples in a South African company:
- Adopting a formal code of ethics.
- Training employees on anti‑fraud and anti‑corruption policies.
- Strong support from top management for compliance and integrity.
- Independent and competent audit committee providing rigorous oversight.
Exam tip: When asked to “identify weaknesses in the control environment”, look for:
- Dominant CEO with weak board.
- Lack of segregation of duties at senior levels.
- Inadequate HR screening of staff in sensitive positions.
3.2.2 Risk Assessment
Risk assessment is the process of:
- Identifying relevant risks to the achievement of objectives.
- Analysing their likelihood and impact.
- Determining how to respond (accept, avoid, reduce, transfer).
Steps in a typical risk assessment:
- Establish objectives (e.g., accurate financial reporting, safeguarding cash).
- Identify potential events that could threaten achievement of objectives (e.g., fraud, system failures).
- Assess inherent risk (before controls) in terms of likelihood and impact.
- Identify mitigating controls.
- Assess residual risk (after controls) and determine if acceptable.
Example for ACC3CGE:
- Objective: Prevent theft of inventory.
- Risk: Employees could steal high‑value stock.
- Control: CCTV in storeroom, secure access controls, independent stock counts.
- Residual risk: Reduced but not eliminated; monitored via variance analysis and surprise counts.
3.2.3 Control Activities
Control activities are the specific policies and procedures that help ensure management directives are carried out. Common types include:
- Authorisation and approval – e.g., credit limits for customers.
- Segregation of duties – dividing responsibilities among different people to reduce risk of error or fraud.
- Physical controls – safes, locks, access cards, CCTV.
- Reconciliations and reviews – bank reconciliations, management reviews of budgets vs actuals.
- IT controls – password policies, access rights, system change controls.
Segregation of duties is especially important in exam questions. Functions that should be separated:
- Custody of assets.
- Recording of transactions.
- Authorisation of transactions.
- Reconciliation of records.
For example, in a sales cycle scenario:
- The sales clerk (front office) should not also be the debtors clerk (recording) and the cashier (custody of cash).
3.2.4 Information and Communication
Effective internal control requires:
- Relevant, accurate, and timely information (internal and external).
- Communication of responsibilities and expectations to all levels of the organisation.
Examples:
- Clear policy manuals and procedures.
- Internal reporting (e.g., management accounts, KPI dashboards).
- Whistle‑blower hotlines to report irregularities.
3.2.5 Monitoring Activities
Monitoring involves:
- Ongoing activities (e.g., routine supervision, management reviews).
- Separate evaluations (e.g., internal audit reviews, external consultants).
Monitoring ensures that internal controls:
- Remain effective over time.
- Are updated to address new risks (e.g., new IT systems, changes in regulation).
3.3 Limitations of Internal Control (Exam‑Relevant Points)
Internal control systems, no matter how well designed, have inherent limitations:
- Human error – mistakes due to carelessness, misunderstanding, or fatigue.
- Collusion – two or more employees working together to bypass controls.
- Management override – senior management overriding established controls.
- Cost‑benefit constraint – cost of a control should not exceed expected benefit.
Examiners often test whether you recognise that a system can only provide reasonable assurance.
3.4 Internal Control in Key Business Cycles
In both UJ and UNISA accounting modules, internal control questions are frequently framed around specific transaction cycles. You may be asked to:
- Identify risks in a cycle.
- Recommend appropriate controls.
- Evaluate the design and implementation of current controls.
3.4.1 Revenue and Receivables Cycle
Key activities:
- Customer orders.
- Credit approval.
- Dispatch of goods or services provided.
- Invoicing.
- Receipt of cash or electronic payment.
- Recording in accounting records.
- Follow‑up on overdue accounts.
Key risks:
- Selling to customers with poor credit (bad debts).
- Dispatching goods without authorised orders.
- Dispatch recorded but invoice not raised (understatement of revenue).
- Misappropriation of cash received.
- Failure to record sales (shadow sales).
Typical control activities:
- Credit checks and approval by credit manager.
- Pre‑numbered sales orders, delivery notes, and invoices.
- Matching of orders, delivery notes, and invoices before posting.
- Segregation of duties between sales, dispatch, invoicing, and receipting.
- Daily cash‑up and independent bank reconciliations.
- Monthly customer statements and follow‑up of discrepancies.
3.4.2 Purchases and Payables Cycle
Key activities:
- Requisitioning goods or services.
- Supplier selection and order placement.
- Receiving goods or services.
- Matching supplier invoices with orders and goods received.
- Recording liabilities.
- Authorising payments.
- Payment and reconciliation.
Risks:
- Ordering goods not needed or at excessive prices.
- Receiving goods but not recording liabilities (understated expenses).
- Paying for goods not received.
- Duplicate payments or fraudulent payments.
Controls:
- Purchase requisitions authorised by department managers.
- Approved supplier list.
- Pre‑numbered purchase orders.
- Receiving reports matched to orders and invoices.
- Segregation of duties between ordering, receiving, recording, and paying.
- Payment runs reviewed and authorised by senior management.
3.4.3 Payroll Cycle
Key activities:
- Hiring and termination.
- Timekeeping and attendance.
- Payroll preparation.
- Payment (EFT or cash).
- Recording in the general ledger.
Risks:
- Ghost employees (fraudulent salaries).
- Incorrect pay rates or hours.
- Unauthorised overtime.
- Non‑compliance with statutory deductions (PAYE, UIF, SDL).
Controls:
- HR department controlling employee master file (hires and terminations).
- Supervisory approval of timesheets and overtime.
- Segregation of duties between HR, payroll processing, and payments.
- Monthly reconciliation of payroll to bank and general ledger.
- Independent review of payroll variance reports.
3.5 Role of Internal Audit in Internal Control and Governance
Internal audit is a key assurance provider in corporate governance. In UJ’s ACC3CGE and similar modules at UNISA (e.g., AUI3703), you must understand its role and independence.
Definition:
Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organisation’s operations.
Key roles:
- Evaluate the adequacy and effectiveness of internal controls.
- Assess risk management processes.
- Review compliance with policies, procedures, and laws.
- Provide recommendations for improvement.
Reporting lines:
- Functionally to the audit committee (or board).
- Administratively to the CEO or a senior executive.
This dual reporting helps maintain independence while ensuring practical access to information and resources.
4. Risk Management, IT Governance, and Combined Assurance (UJ ACC3CGN/ACC3CGE Integration)
4.1 Enterprise Risk Management (ERM)
Enterprise Risk Management (ERM) is a structured, organisation‑wide approach to managing all categories of risk and opportunity. In the South African context, ERM should align with King IV and the COSO ERM framework.
ERM objectives:
- Identify and manage risks that could affect the achievement of strategic, operational, reporting, and compliance objectives.
- Support better decision‑making.
- Enhance resilience and value creation.
4.2 Risk Governance under King IV
King IV Principle on risk: The governing body should govern risk and opportunity in a way that supports the organisation in setting and achieving its strategic objectives.
Board’s role in risk governance:
- Set the risk appetite and risk tolerance.
- Approve the risk management policy and framework.
- Oversee implementation of ERM by management.
- Ensure integration of risk into:
- Strategy formulation.
- Budgeting and planning.
- Performance measurement and rewards.
Risk Committee’s role:
- Oversee detailed risk identification, assessment, and mitigation.
- Review risk registers and risk heat maps.
- Ensure adequacy of risk responses.
Management’s role:
- Identify, assess, and manage risks within their operations.
- Report on risk exposures and mitigation progress.
4.3 Risk Categories and Examples
Common risk categories relevant to South African companies:
- Strategic risk – risks affecting long‑term objectives.
- Example: Entry of a strong new competitor; failure to adapt to technology trends.
- Operational risk – risks arising from day‑to‑day operations.
- Example: Production breakdowns; supply chain disruptions.
- Financial risk – credit, liquidity, market, and currency risks.
- Example: Sudden interest rate increase; customer defaults.
- Compliance risk – failure to comply with laws and regulations.
- Example: Non‑compliance with tax legislation; environmental laws breaches.
- Reputational risk – damage to company’s image and stakeholder trust.
- Example: Social media scandals; product recalls.
- Information technology and cyber risk – data breaches, system failures.
- Example: Ransomware attacks; loss of critical customer data.
Exam technique: When given a case study about a South African company (e.g., a manufacturing or retail group), classify risks under these headings and propose suitable responses.
4.4 IT Governance and Information Security
King IV places particular emphasis on technology and information governance (often tested in governance and control modules).
Board’s responsibility:
- Understand the strategic role of IT.
- Approve an IT governance framework.
- Ensure alignment of IT strategy with business strategy.
- Oversee protection of information assets and cybersecurity.
IT governance topics relevant to UJ exams:
- IT risk management – identifying and managing IT‑related risks.
- IT policies and procedures – security policies, acceptable use, change management.
- Access controls – user ID management, strong passwords, role‑based access.
- Segregation of duties in IT – system development, testing, and production roles separated.
- Business continuity and disaster recovery – data backups, failover systems, recovery plans.
Information security controls:
- Firewalls and intrusion detection systems.
- Encryption of sensitive data.
- Regular patching and updating of software.
- User awareness training to prevent phishing attacks.
4.5 Combined Assurance Model
A key King IV concept and common exam topic is the combined assurance model.
Definition:
Combined assurance is the process of integrating and aligning assurance processes in an organisation to maximise the overall level of assurance obtained from management, internal assurance providers, and external assurance providers.
Levels of assurance providers:
- Management – owns, manages, and monitors risks and controls (first line).
- Internal assurance providers – internal audit, risk management, compliance (second line).
- External assurance providers – external auditors, regulators, certifiers, rating agencies (third line).
Purpose of combined assurance:
- Reduce duplication of assurance efforts.
- Identify gaps and overlaps in assurance coverage.
- Improve efficiency and effectiveness of assurance.
- Enhance reliability of information for decision‑making.
Role of the audit committee in combined assurance:
- Oversee the combined assurance model.
- Ensure significant risks are adequately covered by assurance activities.
- Coordinate interaction between internal and external auditors.
4.6 Ethics Management and Fraud Risk Management
Ethical conduct and fraud prevention lie at the intersection of corporate governance, internal control, and risk management.
4.6.1 Ethics Management
King IV emphasises creating an ethical culture. Key components include:
- Code of ethics or code of conduct.
- Ethics training for all employees.
- Leadership commitment to ethical behaviour (tone at the top).
- Procedures for reporting unethical conduct (whistle‑blowing).
- Disciplinary mechanisms for breaches.
The Social and Ethics Committee plays a key role in monitoring ethics performance.
4.6.2 Fraud Risk Management
Fraud is a significant risk in many South African organisations. Effective fraud risk management includes:
-
Prevention:
- Robust internal controls (segregation of duties, approvals).
- Recruitment screening and background checks.
- Ethics training and culture of honesty.
- Strong disciplinary processes.
-
Detection:
- Data analytics (e.g., unusual patterns in transactions).
- Whistle‑blower hotlines.
- Surprise audits and inspections.
-
Response:
- Clear fraud response plan.
- Investigation protocols.
- Reporting to authorities when appropriate.
- Disciplinary and legal action.
UJ exams may provide a scenario involving suspected fraud (e.g., inventory shrinkage, fictitious suppliers) and ask you to:
- Identify control weaknesses.
- Recommend improved controls.
- Discuss the roles of internal audit, management, and the audit committee in responding to the fraud.
5. Exam‑Focused Application for UJ BCom Accounting Students (ACC3CGN / ACC3CGE)
5.1 Linking Governance Theory to Exam Scenarios
In UJ BCom Accounting modules such as ACC3CGN: Corporate Governance and Ethics and ACC3CGE: Corporate Governance and Control, as well as cross‑referenced to similar UNISA modules (e.g., ACN203S, AUI3703, FAC3703), questions often blend:
- Governance concepts (King IV, Companies Act).
- Board structures and committees.
- Internal control and COSO.
- Risk management and ethics.
Typical question styles:
- Short‑answer theory questions:
- Define corporate governance and explain its purpose.
- List and explain the main components of the COSO internal control framework.
- Application questions:
- Given a case study, identify weaknesses in corporate governance.
- Recommend measures to strengthen internal control in a given business cycle.
- Essay‑type questions:
- Discuss how the board of XYZ Ltd should govern risk and opportunity in terms of King IV.
- Critically evaluate the role of the audit committee in ensuring the reliability of financial reporting.
To prepare effectively, practice mapping exam scenarios to:
- Relevant King IV principles.
- Appropriate board committees.
- Correct internal control components.
- Risk management steps.
5.2 Integrating Governance, Control, and Ethics in Answers
For higher marks, answers must integrate multiple aspects instead of treating governance, control, and ethics as isolated topics.
Example integrated approach:
Scenario: A South African retail company, ABC Retail Ltd, has rapidly expanded its online sales platform. Recently, there have been complaints of incorrect billing, delayed deliveries, and suspected unauthorised access to customer data.
In your answer:
-
Corporate governance:
- Board responsibility for overseeing the impact of the new online strategy.
- Risk committee’s role in identifying and managing strategic, operational, and IT risks.
- Need for IT governance framework aligned with King IV.
-
Internal controls:
- COSO components: control environment (tone at the top), risk assessment (e‑commerce risks), control activities (order processing controls, IT access controls), information and communication, monitoring.
- Specific controls for online sales (authorisation, validation checks, reconciliations).
-
Risk management:
- Categorisation of risks (operational, IT, reputational).
- Risk responses (improved system controls, customer communication plan).
-
Ethics and compliance:
- Protection of personal information (compliance with POPIA).
- Transparency with customers about data breaches, if any.
- Ethical obligation to rectify billing errors.
This integrated approach aligns with how governance is taught in UJ BCom Accounting and is tested in exam questions that mirror real‑world complexity.
5.3 Common Exam Pitfalls and How to Avoid Them
- Vague definitions: Always give clear, concise definitions aligned with COSO, King IV, or the Companies Act where relevant.
- Ignoring South African context: Refer to King IV, Companies Act 71 of 2008, JSE Listings Requirements, and relevant South African practices.
- Listing without application: Where a question requires discussion or analysis, go beyond listing points—explain and apply to the scenario.
- Not linking controls to risks: When recommending controls, always explain which specific risk each control addresses.
- Overlooking ethical dimensions: In governance questions, consider ethics, stakeholder impact, and culture, not just structure and procedures.
5.4 Study Strategy for ACC3CGN / ACC3CGE and Related Modules
A practical study plan for UJ BCom Accounting students:
-
Master definitions and frameworks:
- Corporate governance.
- Agency and stakeholder theory.
- COSO internal control components.
- King IV themes (ethical leadership, performance, control, legitimacy).
-
Understand South African legal and regulatory context:
- Companies Act 71 of 2008: directors’ duties, audit committee, social and ethics committee.
- King IV Report: application and explanation.
- JSE Listings Requirements (for listed company scenarios).
-
Practice application to scenarios:
- Work through past UJ question papers for ACC3CGN and ACC3CGE.
- Compare with similar governance and control questions in UNISA resources (e.g., ACN203S, AUI3703).
-
Develop structured answer techniques:
- Use headings in long answers: “Governance Strengths”, “Governance Weaknesses”, “Recommendations”.
- Where appropriate, structure answers around COSO: “Control Environment”, “Risk Assessment”, etc.
- When asked for controls, use the format: risk – control – explanation.
-
Link to financial reporting and auditing:
- Relate how internal control and governance affect audit risk and financial statement reliability.
- Consider the role of external auditors alongside internal governance mechanisms.
By thoroughly understanding the foundations of corporate governance in South Africa, the roles and responsibilities of boards and their committees, the COSO internal control framework, risk and IT governance, and ethics management, UJ BCom Accounting students can approach ACC3CGN, ACC3CGE, and related exams with confidence. Consistent practice in applying these principles to realistic organisational scenarios—similar to those tested at UJ and in UNISA modules such as ACN203S and AUI3703—will build the analytical skills needed for both academic success and future professional practice in accounting and auditing.
