Every financial services provider carrying an obligation under Joint Standard 1 and Joint Standard 2 has three realistic routes available, and they differ from each other far more in what they leave behind than in what they cost at the point of purchase. It is worth setting them alongside each other honestly, including the case against the option we sell.
Route one: hire a compliance officer
A mid level compliance officer in South Africa represents a total cost to company in the region of R480,000 to R720,000 a year, before recruitment cost, before management time, and before the risk that they leave within eighteen months and the position has to be filled again.
For a large provider this is straightforwardly the right answer. For a provider with ten or thirty or sixty staff it is difficult to justify, and there is a further complication that is often missed at the point of hiring. Compliance is not one discipline. The candidates available in this market are overwhelmingly conduct specialists, meaning FAIS and FICA, and information security governance is a materially different field requiring a materially different background. A provider who hires a compliance officer to solve their Joint Standard exposure frequently discovers that they have hired for a different problem, and that the technical governance work still has to be outsourced.
Where this route wins is presence. Somebody in the business, every day, who knows the organisation intimately. That is genuinely valuable and no external arrangement replicates it fully.
Route two: engage a consultant hourly
This is the most common route and it produces good work. A capable consultant will interview the business, establish the regulatory footprint, and deliver a policy suite that reads correctly and would satisfy a reviewer examining it in isolation.
The structural weakness is not the quality of the work, it is where the engagement stops. The policy is the deliverable, so the engagement concludes when it is signed, and everything that follows returns to the provider. The committee has to be chartered and then convened every quarter. The logs have to be collected, stored and reviewed. The registers have to be maintained as circumstances change. The annual audit has to happen. Staff training has to be arranged and tracked. And the technical controls the policies describe have to be implemented by an IT provider who has generally never seen the document.
The provider has bought a document and inherited a function. That is a rational purchase if the internal capacity exists to run the function, and most small providers discover within two quarters that it does not, at which point the policy suite begins ageing and the committee stops meeting.
There is also a cost characteristic worth naming. Hourly consulting has no fixed endpoint, so the total is not knowable in advance and tends to be revisited each time the regulatory position changes.
Route three: a fixed monthly retainer
This is what we have built, so read the following with that in mind, and note the limitations we set out at the end.
The retainer covers the gap analysis, the policy build, the registers, the committee establishment and quarterly facilitation, the staff training, the quarterly log review, the quarterly board reporting, the annual audit and the verification of every technical control the policies require. There is no separate implementation fee, which means the substantial build work at the start is absorbed rather than invoiced, and the cost is one predictable monthly figure banded by employee count.
Compared against an internal hire, the retainer is a fraction of the cost and covers a scope that a conduct focused compliance officer would not. Compared against hourly consulting, the difference is not primarily price, it is that the function continues after the policy is signed rather than reverting to you.
The honest case against the retainer
Three situations where one of the other routes is the better decision.
If you already have internal governance, risk and compliance capacity, you do not need a retainer covering committee facilitation and quarterly reporting, and you would be paying for a function you already run. A one off gap analysis and technical verification would serve you better.
If you are large enough that a full time appointment is justifiable, make it. An internal officer with daily presence and organisational knowledge will outperform any external arrangement, provided you hire for information security governance specifically rather than assuming a conduct background transfers.
And if your primary exposure is conduct rather than information security, this is not the product. We are not a registered Compliance Practice under FAIS and cannot act as your external compliance officer, and any provider telling you otherwise about their own similar product is worth questioning closely.
The question that actually decides it
Set the price comparison aside for a moment, because it is not usually the deciding factor once the alternatives are properly costed. The question that matters is what happens in the quarter after the policy suite is delivered.
If you have somebody who will convene the committee, collect and review the logs, chase the IT provider on the outstanding technical controls, maintain the registers and prepare the board report, then a consultant engagement is sufficient and you should take it. If, when you picture that quarter honestly, you cannot name the person who will do those things, then you are not choosing between a document and a retainer. You are choosing between a compliance position that is maintained and one that begins decaying from the day it is signed.
The gap analysis is where any of these routes should begin, because none of the three decisions can be made sensibly without knowing your current position. Get in touch to arrange one.