Kim Rew, Partner at Webber Wentzel, shares expert insight into the proposed PRECCA amendments and what they could mean for businesses, directors and compliance professionals.
South Africa has been fighting corruption with legislation that, frankly, lacked teeth. The Prevention and Combating of Corrupt Activities Act 12 of 2004 (PRECCA) has long been the cornerstone of the country's anti-corruption framework — criminalising bribery, fraud and a broad range of corrupt conduct in both the public and private sectors. The law was there. The convictions, historically, were not. That is rapidly changing.
The PRECCA Amendment Bill of 2026 (Bill 19-2026), introduced to the National Assembly in March 2026 and tabled in Parliament (during the week of 13 July), proposes two deceptively simple but far-reaching changes: mandatory minimum sentences for corruption convictions and a dramatically lower threshold for the obligation to report suspected fraud and corruption. Together, these amendments signal a new era of accountability, one that will be felt across boardrooms, audit committees, insurance towers and professional practices throughout South Africa.
The two amendments in plain language
Mandatory minimum sentences: The era of discretion is over
Currently, PRECCA prescribes maximum sentences but leaves sentencing largely to judicial discretion. Courts have frequently imposed sentences well below what the gravity of the offence warrants. The Amendment Bill changes that, with sentences now as follows:
- High Court - a minimum of 18 years’ imprisonment up to life, plus a fine.
- Regional Court - a minimum of 15 years, not exceeding 18 years, plus a fine.
- Magistrates’ Court - a minimum of five years, not exceeding ten years, plus a fine.
- Failure-to-report offences (section 28(6)(b)) - fine doubled from ZAR 250,000 to ZAR 500,000 and imprisonment raised to five years.
A court may still deviate from the minimum sentence, but only if it records substantial and compelling circumstances on the record. This is the same framework applied under the Criminal Law Amendment Act 105 of 1997 for serious violent crimes. The message is unambiguous: corruption is now categorised alongside the most serious offences in our criminal justice system.
The reporting threshold slashed: From ZAR 100,000 to ZAR 30,000
This is the amendment that will catch most people by surprise. Section 34 of PRECCA already places a mandatory reporting obligation on persons in positions of authority: if they know or reasonably suspect that an employee or colleague has committed corruption or certain other offences, they must report it to the Directorate for Priority Crime Investigation (the Hawks). Failure to do so is itself a criminal offence.
Currently, the threshold triggering this obligation is fraud, theft, extortion, forgery or uttering a forged document involving ZAR 100,000 or more. The Amendment Bill slashes that threshold to ZAR 30,000. To put that in context — a fraudulent supplier invoice of ZAR 30,000, a payroll manipulation of ZAR 30,000, a petty cash misappropriation discovered during an internal audit — all of these now trigger a mandatory obligation to report to the Hawks. Not an internal disciplinary process. Not a quiet settlement. A formal report to law enforcement.
Who should be paying attention?
Corporates and their boards — The combination of the 2026 amendment and the already-enacted section 34A (introduced by the Judicial Matters Amendment Act 15 of 2023, operational from 3 April 2024) creates a compliance landscape that no corporate can afford to treat casually.
Section 34A already makes a company criminally liable if a person associated with it commits a corrupt act for the company's benefit, unless the company can demonstrate it had adequate procedures in place to prevent that conduct. The prosecution does not need to prove the company knew. The burden falls on the company to prove it has controls.
Now add mandatory minimum sentences. The individuals who sat on audit committees and failed to act. The executives who received the whistle-blower report and chose to "manage it internally." The directors who approved the procurement process without asking uncomfortable questions. Individuals in these positions may now face the very real prospect of a minimum 15 to 18-year sentence, not a suspended sentence, not a fine, if they are convicted.
Board-level governance of anti-corruption compliance is no longer a box-ticking exercise. It is a personal liberty issue.
Directors and senior executives — Directors occupy positions of authority within the meaning of PRECCA. The mandatory reporting obligation at the ZAR 30,000 threshold applies directly to them. A director who knows or reasonably suspects that the CFO has approved a fraudulent payment of ZAR 40,000 and does nothing commits a criminal offence. This is not hypothetical. It is the plain wording of the amended statute.
The personal stakes could not be higher. A conviction under PRECCA, even one that results in a suspended sentence, triggers disqualification from serving as a director under the Companies Act 71 of 2008. The new mandatory minimum sentences mean that for the most serious offences, a suspended sentence may not even be available. Directors in public entities face the additional consequence of being barred from public office.
Any director who does not have a documented, board-approved anti-corruption policy and a clear reporting protocol operates at personal risk.
Audit firms and independent auditors — The recent legislative developments serve as a stark warning to the audit profession. Audit committees and auditors can be exposed to information that could constitute knowledge or reasonable suspicion of fraud or corrupt activities. They should seek legal advice where appropriate in respect of their reporting obligations.
Insurers and the directors’ and officers’ (D&O) market — Directors' and officers' liability insurers should expect the mandatory minimum sentencing regime to trigger a significant re-assessment of risk. The prospect of an executive facing an 18-year minimum sentence, rather than a suspended sentence, a fine or a brief correctional order, changes the risk calculus fundamentally.
Criminal fines and penalties are uninsurable as a matter of South African public policy. D&O cover responds to defence costs and civil claims; it does not absorb criminal sentences. Insurers underwriting D&O cover in the South African market need to be asking harder questions about the anti-corruption compliance infrastructure of their insureds. Companies with no documented adequate procedures under section 34A are materially higher-risk propositions than those with robust programmes.
Expect underwriters to incorporate PRECCA compliance assessments into their renewal questionnaires. Expect premiums to reflect the answer.
SMEs and owner-managed businesses — The ZAR 30,000 threshold is not aimed only at large corporates. A small business owner who discovers that a bookkeeper has been submitting fraudulent invoices totalling ZAR 35,000 is now legally obliged to report this to the Hawks, regardless of whether they prefer to deal with it quietly, recover the money or simply dismiss the employee. That option is no longer available without criminal risk.
This is a profound shift in the obligations of the small business community, most of whom have no awareness of it whatsoever.
The AI impact
No discussion of corruption compliance in 2026 is complete without addressing artificial intelligence. AI is reshaping the corruption risk landscape in two ways — as a powerful enabler of the very fraud and corruption that PRECCA targets and as one of the most effective tools available for detecting and preventing it. Understanding both sides of that equation is no longer optional.
The amended ZAR 30,000 reporting threshold is not an arbitrary number. It reflects a deliberate policy choice to catch corruption earlier before it compounds. That urgency is made more acute by a reality that most compliance teams have not fully absorbed: AI has dramatically lowered the cost and complexity of committing financial fraud at precisely the scale the amendment targets.
Sophisticated AI tools can generate convincing fraudulent invoices, fabricate supporting documentation, clone supplier identities and construct layered payment trails in minutes and at scale. Deepfake audio and video technology is now sufficiently advanced to impersonate a CFO authorising a payment over a call. AI-generated emails from synthetic "vendors" pass basic due diligence checks. The ZAR 30,000 fraudulent transaction that triggers a reporting obligation under the amended section 34 may not look like fraud at all to a human reviewer working without AI-assisted detection.
The practical implication is significant: a compliance programme that relied on human review of financial transactions as its primary fraud detection mechanism is already structurally inadequate. The amendment lowers the threshold at which liability attaches. AI lowers the floor for what competent fraud prevention must look like.
AI compliance tools and the "adequate procedures" defence
The section 34A defence, that a company had adequate procedures in place to prevent corrupt conduct by an associated person, is currently undefined in statute. South African courts are likely to look to the six principles developed under the UK Bribery Act 2010 as interpretive guidance: proportionate procedures, top-level commitment, risk assessment, due diligence, communication and monitoring and review.
That final principle, monitoring and review, is where AI compliance technology becomes an evidentiary asset, not merely a commercial convenience. AI-powered transaction monitoring tools can analyse payment flows, flag anomalies, identify patterns consistent with procurement fraud and cross-reference supplier data against watchlists in real time. A company that deploys such tools as part of a documented compliance architecture is materially better placed to demonstrate adequate procedures than one that conducts annual policy reviews and calls it done.
This is an example of the kind of proportionate, risk-based, continuously monitored programme that section 34A demands. It creates the audit trail that a company will need if it is ever called upon to demonstrate its procedures in criminal proceedings. Businesses that have not yet considered AI-assisted compliance tools should be asking why not, and what the cost of not having them would be if prosecuted.
The liability question nobody is asking: When AI facilitates the corruption
There is a harder question sitting just below the surface of the current debate and it will need to be answered sooner than most practitioners expect. What is the legal position when it is not a human employee who facilitates the corrupt transaction, but an AI system deployed by the company?
Consider a procurement AI that autonomously selects suppliers, approves purchase orders and initiates payments. If that system is manipulated, by a bad actor within the business, by a third-party vendor or through a vulnerability in the model itself and the result is a payment that constitutes corrupt conduct under PRECCA, who within the company "knew or ought reasonably to have known"? Which director or senior executive had a position of authority over a system they may not fully understand and cannot directly supervise in real time? Does deploying an AI procurement tool without adequate human oversight itself constitute a failure of adequate procedures under section 34A?
PRECCA was not drafted with autonomous AI systems in mind. Its language of "knowledge", "suspicion", "position of authority" and "associated persons" maps imperfectly onto a world where consequential financial decisions are being made by machine learning models at speed and scale. These questions have not yet been tested in South African courts. They are likely to arise. Companies that are deploying AI in financial, procurement or compliance-sensitive functions should be taking legal advice on their exposure now — before those questions are answered in a case involving their own systems.
A word of caution: The Bill has not yet been enacted
It bears noting that this is a private member's bill introduced by ActionSA and, not yet enacted legislation. It must complete the parliamentary process — committee hearings, possible amendments, National Council of Provinces consideration and Presidential assent, before it becomes law. Private member's bills face a more uncertain parliamentary passage than government-initiated legislation.
However, the direction of travel is clear. South Africa's post-state-capture legislative landscape, the recommendations of the Zondo Commission, South Africa's recent grey-listing by the Financial Action Task Force and growing international pressure from trading partners all point firmly in the same direction: tougher anti-corruption enforcement, expanded corporate liability and lower tolerance for quiet non-reporting.
Even if this specific Bill is amended or delayed, the underlying policy trajectory is irreversible. Getting compliant now is not premature — it is prudent.
Whether you are a CEO, a director, a compliance officer, an auditor or a business owner, the time for a comfortable passivity about PRECCA compliance has passed. The following steps are essential components of a credible compliance framework:
- Audit your current compliance posture. Do you have a written anti-corruption and anti-bribery policy? Is it board-approved? When was it last reviewed? Does it reflect the obligations under section 34A and the amended section 34?
- Map your reporting obligations. Who in your organisation holds a position of authority? Who has access to financial information that could disclose a reportable offence? Is there a clear protocol for what happens when such information surfaces?
- Review your third-party relationships. Section 34A reaches conduct by persons associated with your entity — contractors, agents, distributors and intermediaries. Your anti-corruption due diligence must extend to these relationships.
- Assess your AI exposure. If your business uses AI tools in financial, procurement or payment functions, take legal advice on whether your current governance arrangements adequately address your PRECCA exposure — both the risk of AI-enabled fraud against you and the risk that your own AI systems could, if manipulated or poorly supervised, facilitate conduct that engages criminal liability.
- Brief your board. Anti-corruption compliance is a governance matter that requires board-level ownership. Directors must understand their personal obligations and the personal consequences of non-compliance.
- Train your people. A policy that sits on a SharePoint server unread is not an adequate procedure. Training, communication and documented roll-out are essential.
- Take legal advice — now, not after the problem arises. The time to understand your obligations, build your defences and establish your reporting protocols is before the Hawks knock on the door.
South Africa is serious about corruption. The Zondo Commission produced 295 findings of corruption. The FATF grey listing has placed South Africa's financial system under international scrutiny. The courts are convicting. The Hawks are investigating. The NPA is prosecuting.
The PRECCA Amendment Bill of 2026 is not a legislative outlier — it is the next chapter in a story that has been building since the state capture era. The mandatory sentencing framework, coupled with the already-in-force corporate liability offence under section 34A, means that the South African anti-corruption regime is now, in structural terms, one of the most demanding in the world.
The businesses and individuals who will navigate this landscape successfully are not those who wait to see whether the Bill passes. They are the ones who treat the direction of travel as a prompt to act — and who seek proper legal advice before they find themselves on the wrong side of it.