I did not plan to become the compliance guy.
The plan was to write about automation, because that is what we build. What happened instead is that every time I researched what a South African small business actually struggles with, I hit a rule before I hit a workflow. So I followed the rules. POPIA. FICA. Electronic signatures, twice, because the interesting half is the documents you cannot sign. Tax invoices. Expenses. Invoicing. A workplace AI policy. Annual returns yesterday. Empowerment affidavits today.
That is ten. Enough that a pattern stops being a coincidence.
What I expected to find
I expected ten separate obligations. Ten different departments, ten deadlines, ten unrelated forms, connected only by the fact that the same tired person has to do all of them.
That is how they are written about. Every guide online, including some of mine, treats its subject as a self-contained thing you either did or did not do.
What is actually there
They are not separate. They are a chain, and the links are load bearing.
Here is the one I found yesterday and today, in that order, entirely by accident.
A company has to file an annual return with the companies commission every year. Miss two in a row and there are statutory grounds to remove the company from the register. That is the story I wrote yesterday, and I thought it ended there, with deregistration as the worst case.
Then today I read the empowerment commission's own practice guide, and found that the free route to a B-BBEE certificate, the one issued by the companies commission at no cost, is only available if your annual returns are up to date and your status reads In Business.
So the chain runs: unfiled annual return, then a company status that is not clean, then no free empowerment certificate, then no valid evidence of your status, then a corporate customer who cannot count your invoice toward its own procurement scorecard, then a buyer with a reason to go elsewhere that has nothing to do with your price or your work.
Nobody draws that. Every one of those links is documented, and I could not find a single page that connects them end to end. The annual returns guides talk about deregistration. The affidavit guides talk about ownership percentages. The tender guides talk about points. They are all correct and they all stop at their own edge.
Why that changed my mind about what compliance is
I had compliance filed under avoiding a fine. Something you do so that a bad thing does not happen to you.
Reading ten of these back to back, the fines are the least of it. Almost none of these rules are enforced by someone arriving to punish you. They are enforced by doors that quietly stop opening.
An expired affidavit does not get you prosecuted. It gets your invoice quietly discounted in someone else's scorecard. An unfiled return does not get you raided. It gets your bank review flagged and your certificate route closed. The whole system works less like a police force and more like a set of gates, and the gates do not announce themselves. You find out you were disqualified by not winning, which is indistinguishable from just not winning.
That is a genuinely nasty failure mode, because there is no feedback. You cannot learn from a signal you never receive.
The uncomfortable part
I run a business that sells operational clarity to other businesses, and I did not have this map. I built it accidentally, over three weeks, by researching articles.
If it took ten guides and a stack of primary documents for me to see it, and this is my actual job, then the owner running a business with fifteen staff and no compliance function has no realistic chance of assembling it from what is published. Not because it is hidden. Because it is scattered, and nobody is paid to draw the joins.
I have written before about reading the law directly instead of reading summaries of it, and I still think that was the highest leverage habit I picked up this year. This is the second half of the same lesson. Reading each source is necessary and it is not sufficient. Every source is written from inside its own silo, so reading them all still leaves you assembling the joins yourself, and the joins are where the failures live.
It is the same shape as the duplicate content problem I found in my own sites last week. Three correct decisions, one broken seam, nobody owning the join. I keep finding this and it keeps not being a coincidence.
What I am doing about it
Building the map, and publishing it.
The next thing on the business blog is a hub that connects these ten pieces in dependency order rather than alphabetically, so that the annual return links forward to the empowerment certificate that depends on it, and the empowerment affidavit links back to the filing that gates it. Not a listing page. A map of what unlocks what.
I want to be careful about how I describe the value of that, because there is a version of this post that turns into a pitch, and it would be a worse post. So plainly: the map is useful because the information is public and the arrangement is not. That is all. It is not proprietary knowledge, it is just an ordering nobody has bothered to write down.
The lesson, if there is one
For three weeks I thought I was writing ten articles. I was actually assembling one, badly, in the wrong order, without knowing it.
The general version, which I am fairly sure applies well outside compliance: when you have looked at ten things in a domain and they still feel like ten things, you probably have not finished looking. Sets of rules that were written by different people at different times to solve different problems still end up depending on each other, because they all attach to the same business. The dependencies are real even when nobody has documented them.
So the question I am adding to my list, next to what does the visitor I never am actually get served, is this one: what does this thing depend on that nobody has told me about?
Both questions only ever produce bad news. Both keep being worth asking.
Frequently Asked Questions
Which compliance obligations are actually connected? The clearest chain runs from company annual returns, through the company's registered status, to eligibility for the free empowerment certificate the companies commission issues, and on to whether a corporate customer can recognise your invoice in its own procurement scorecard.
Why is that chain not documented anywhere? Because each rule is administered by a different body and each guide is written from inside one of them. Every individual source is correct and stops at its own boundary. The joins between them belong to nobody.
Is compliance mostly about avoiding fines? In my experience of researching ten of these, no. Enforcement by penalty is rare. Enforcement by lost eligibility is constant, and it is invisible, because a door that does not open sends you no notification.
What are you doing with what you found? Publishing a hub on the business blog that arranges the compliance guides in dependency order rather than as a list, so each one links to what it unlocks and what it depends on.
More of the build, and the mistakes, at heinoux.nexbdm.co.za.