“Regardless of the context, First Principles will always demand both attention and application. Think of sporting codes – in cricket, bowling coaches will regularly remind their players of “line and length” as the success of any delivery rests on those principles. In cycling, before a rider can propel a bicycle forward, they must be well balanced, and their posture must be conducive to an efficient pedal stroke. In soccer, before a player can do anything useful with a soccer ball, they must first learn to control the ball”.
In this article I use a real-life case study to demonstrate that Compliance – First Principles remain supreme.
The discipline of compliance risk management rests on basic principles which must be consistently executed. Fortunately, there is no need to reinvent the wheel because the Generally Accepted Compliance Practice Framework has successfully packaged compliance best practices into a single, easily accessible and easy to use framework.
Let us consider the following case study, from a First Principles point of view:
Case Study 1 – Compliance processes in innovation
Innovation X provides much needed funding to innovators who have successfully demonstrated a Minimum Viable Product. The funding takes the form of interest-bearing loans, grants and some instances where Innovation X will take up an equity stake.
Since inception, Innovation X has never had a compliance function. Each department within innovation X was expected to take charge of its own compliance with laws and regulations. At the level of the Board, it was assumed that Innovation X was fully compliant with all laws applicable to it.
When Innovation X appointed Gatsheni Advisory to assess the maturity of its compliance processes, the organization’s assumptions were that there were existing compliance processes.
What did we establish? Compliance was not formalized by way of a compliance policy, compliance framework, compliance strategy and compliance manual. This explained why Departments were left to their own devices. Furthermore, there was no compliance universe in place to give directions on which laws, regulations and non-binding codes and standards were applicable to Innovation X. Absent a compliance universe, it would not be possible to conduct compliance risk assessments, develop compliance risk management plans and conduct compliance monitoring and reporting.
The gaps mentioned above gave rise to various compliance risks such as non-compliance with the Protection of Personal Information Act, 2013 and non-compliance with the Financial Intelligence Centre Act, 2004, amongst others.
What were the solutions? We recommended that compliance be formalized within the organization by developing a compliance policy, compliance strategy and compliance manual. We also recommended that full-time compliance resources be considered and subsequently appointed.
To date, the policy architecture has been approved which means that once compliance resources are appointed, they will be operating within a formally recognized function complete with the supporting compliance policy frameworks.
Case-study 1 is open to many different interpretations; the following have been my key observations:
“The Board must play a more proactive role in the case of compliance risk management and the necessary compliance policy landscape. The Board should be the first to establish the absence of critical compliance policies, not service providers”.
- Compliance related resources are a foundational concept and as such, conversations on these resources should form part of strategy. For example, Human Capital as a strategic discussion should at least consider critical vacancies that may impede on the organization’s ability to execute on its strategy. Any organization that is in the business of lending money faces material compliance risks and as such must ensure that it has suitable compliance-related personnel to assist with identifying and managing those risks.
- The concept of policies and procedures seems to have lost its true meaning over time. However, to successfully build out a compliance function that can operate effectively, compliance related policies and procedures are inescapable. These provide compliance personnel with a critical reference point in respect of all the work that they do. Likewise, roles and responsibilities are made clear to all material stakeholders.

- Lastly, compliance fundamentals are agnostic across industries. Innovation and compliance risk management are undeniably complementary. For example, it would be futile to fund a startup that is non-compliant with the Companies Act, 2008 and South African Tax legislation – unless they can remedy this non-compliance and tender proof. Likewise, funding start-ups within the context of funder-led compliance controls lessens the possibility of capital being allocated in a reckless manner.
The advent of AI will in many cases temp professionals into believing that First Principles are no longer important. But this case study serves as a stark reminder that not applying First Principles carries fundamental risks that will be difficult and expensive to address.