Compliance That Builds
Reputation and Trust
22
Fixed-Fee Services in This Division
ESG strategy, POPIA/GDPR compliance, King IV governance, and B-BBEE advisory - protecting your business and building the stakeholder trust that unlocks capital and contracts.
Immediate Risk
POPIA review overdue?
POPIA has been enforceable since July 2021. Fines reach R10M. Most SA businesses are still non-compliant.
Immediate Risk
No valid Privacy Policy?
A generic or copied privacy policy is not POPIA-compliant. It exposes your business to complaints and regulator action.
Immediate Risk
No risk register?
Lenders, insurers, and DFIs increasingly require a live risk register before engagement. Without one, you are leaving capital on the table.
Audit Flag
Regulator investigation?
If you have received a complaint or investigation notice, you need specialist support immediately - not a generalist consultant.
Not sure where you stand? Take the 10-minute Business Health Check ->
Core Services
Every service is delivered by a practitioner - not a generalist - with domain-specific credentials and measurable outcomes.
POPIA Compliance
Full POPIA gap analysis, policy development, staff training, data flow mapping, and PAIA manual development - with an appointed Information Officer if required.
ESG Strategy & Reporting
Material ESG assessment, target-setting, and integrated reporting aligned to GRI, SASB, and JSE Sustainability Disclosure Requirements.
King IV Governance
Board governance assessments, committee charter development, and King IV compliance reporting for listed, SOE, and large private entities.
B-BBEE Advisory
B-BBEE scorecard strategy, ownership structuring, skills development planning, and supplier development programme design to maximise your BBBEE rating.
GDPR & Data Protection
GDPR gap assessments and remediation for South African businesses with EU data subjects - including DPA agreements, breach protocols, and DPO services.
Regulatory Affairs
Ongoing regulatory monitoring, licence applications, and compliance calendars for heavily regulated sectors - financial services, healthcare, and mining.
Service Pricing
Fixed-fee engagements. Prices are standard rates - final scope confirmed at proposal stage for complex mandates. All prices exclude VAT.
| Code | Service | Model | Investment (ZAR, excl. VAT) |
|---|---|---|---|
| IMP-001 | Process Efficiency Audit (Lean Six Sigma) | Fixed Project | R 16,500 |
| IMP-002 | Standard Operating Procedures (per SOP) | Fixed Project | R 8,500 |
| IMP-003 | Operational Excellence Assessment | Fixed Project | R 18,000 |
| IMP-004 | ISO 9001 Gap Assessment | Fixed Project | R 14,500 |
| IMP-005 | Continuous Improvement Programme Design | Fixed Project | R 22,000 |
| IMP-006 | Process Governance Framework | Fixed Project | R 14,500 |
| IMP-007 | POPIA Compliance Gap Assessment | Fixed Project | R 14,000 |
| IMP-008 | POPIA Full Implementation Programme | Fixed Project | R 78,000 |
| IMP-009 | POPIA Document Toolkit | Fixed Project | R 4,800 |
| IMP-010 | GDPR Compliance Programme | Fixed Project | R 64,000 |
| IMP-011 | Outsourced Information Officer (per month) | Retainer | R 6,500 |
| IMP-012 | Privacy Impact Assessment | Fixed Project | R 12,000 |
| IMP-013 | PAIA Section 51 Manual | Fixed Project | R 8,500 |
| IMP-014 | Data Breach Response Plan | Fixed Project | R 12,000 |
| IMP-015 | Annual Data Protection Audit | Fixed Project | R 14,000 |
| IMP-016 | King IV Governance Assessment | Fixed Project | R 22,000 |
| IMP-017 | Enterprise Risk Register | Fixed Project | R 22,000 |
| IMP-018 | Internal Control Framework | Fixed Project | R 18,500 |
| IMP-019 | Compliance Programme Design | Fixed Project | R 28,000 |
| IMP-020 | ESG Reporting Framework | Fixed Project | R 28,000 |
| IMP-021 | Business Continuity Plan | Fixed Project | R 22,000 |
| IMP-022 | Annual Governance Health Check | Fixed Project | R 16,000 |
Our Engagement Process
A structured, time-bound methodology that delivers results - not reports.
Compliance Audit
Gap analysis against applicable frameworks - POPIA, King IV, ESG, B-BBEE.
Remediation Plan
Prioritised, costed plan with clear ownership and timelines.
Implementation
Policy development, staff training, system changes, and documentation.
Ongoing Monitoring
Quarterly reviews, regulatory change alerts, and audit support.
Impact Works Across Every Sector
Compliance obligations vary by industry. Our practitioners bring sector-specific knowledge to every engagement.
Financial Services
FSCA licensing, POPIA, FICA compliance, and risk governance for banks, insurers, and wealth managers.
Healthcare
Health data protection, POPIA health information rules, and clinical governance frameworks for hospitals and clinics.
Professional Services
Law firms, accounting practices, and consultancies needing client data governance and professional body compliance.
Technology & SaaS
POPIA and GDPR compliance for tech platforms processing user data across multiple jurisdictions.
Retail & E-Commerce
Consumer data governance, cookie compliance, marketing consent, and supply chain ESG requirements.
Mining & Resources
Environmental compliance, stakeholder reporting, and ESG frameworks aligned to JSE Sustainability Disclosure Requirements.
Education
Learner data protection, POPIA obligations for educational records, and governance frameworks for private institutions.
Manufacturing
Employee data compliance, supplier governance, B-BBEE strategy, and occupational safety regulatory requirements.
NGOs & NPOs
Donor reporting frameworks, governance structures for NPO Act compliance, and ESG alignment for impact investors.
Property & Construction
Client data governance, contractor compliance, CIDB requirements, and ESG reporting for large developments.
Bundled Packages
Combine compliance services into a cohesive programme - and save up to 15% versus individual pricing. All prices exclude VAT.
Entry Level
POPIA Essentials
Everything a small-to-medium business needs to become POPIA compliant - fast. Gap assessment, core documentation, and staff training in one mandate.
- POPIA Compliance Gap Assessment
- Privacy Policy & PAIA Section 51 Manual
- Data Flow Mapping
- Staff Awareness Training (half day)
Delivered in 4-6 weeks - Fixed fee, no surprises
Enquire About This PackOperations Focus
Ops Sprint
Compliance, risk, and operational governance combined into a single 8-week engagement. Ideal for businesses preparing for a funding round or major contract.
- POPIA Full Implementation
- Enterprise Risk Register
- Internal Controls Assessment
- Compliance Calendar (12 months)
Delivered in 6-8 weeks - Includes 30-day post-delivery support
Enquire About This PackMost Popular
Governance Bundle
Board-level governance, POPIA compliance, and ESG foundations for growth-stage businesses that need to demonstrate institutional credibility.
- King IV Governance Assessment
- POPIA Full Implementation
- ESG Baseline & Reporting Framework
- B-BBEE Scorecard Analysis
Delivered in 10-12 weeks - Quarterly review included
Enquire About This PackEnterprise
Full Programme
End-to-end compliance transformation - POPIA, GDPR, King IV, ESG, B-BBEE, and business continuity. For organisations that need to demonstrate full accountability to regulators and investors.
- POPIA + GDPR Full Implementation
- King IV Governance Programme
- ESG Reporting (GRI/SASB aligned)
- B-BBEE Strategy & Roadmap
- Business Continuity Plan
- Outsourced IO (12 months)
Delivered in 16-20 weeks - Annual retainer option available
Enquire About This PackWhat Our Clients Report
Compliance done right doesn't just protect you - it opens doors. Here's what our clients experienced.
After implementing Kaymerc X's POPIA compliance programme, we passed our Information Regulator audit without a single finding. Zero findings. That's the standard they set.
Their ESG framework helped us land a R15M contract with a JSE-listed client that required full ESG disclosure. It paid for itself many times over within the first quarter.
Frequently Asked Questions
Key questions about our compliance, governance, and ESG services.
What are my POPIA obligations as a South African business?
What fines can the Information Regulator impose for POPIA non-compliance?
What is an Information Officer (IO) and does my business need one?
Does GDPR apply to my South African business?
What is King IV and does my business need to comply?
What does Lean Six Sigma have to do with compliance and governance?
Do you provide an Outsourced Information Officer service?
How do Impact's services integrate with the rest of Kaymerc X?
What Pairs Well With Impact
Compliance is foundational - but it's most powerful when integrated with the right training, technology, and capital strategy.
Kaymerc X Academy
Frameworks are only effective if your people understand them. Academy delivers the POPIA, governance, and compliance training that brings your Impact programme to life.
Explore Academy → Division 04Kaymerc X Tech
Cybersecurity, IT governance, and data infrastructure - the technical layer that makes your POPIA, GDPR, and King IV commitments enforceable and auditable.
Explore Tech → Division 02Kaymerc X Capital
Investors and DFIs require governance and ESG compliance before they invest. Impact and Capital work together to make your business investment-grade.
Explore Capital →