-
Digital and Analytics
We have developed distinctive capabilities in digital advisory and data analytics that are key to the success of dynamic organisations.
-
Business Consulting
Our business consulting services help organisations improve operational performance and productivity throughout the growth life cycle.
-
Corporate Finance & Restructuring
We combine our insights and experience to provide a comprehensive range of advisory and corporate finance and restructuring solutions.
-
Internal Audit
Our internal audit service is designed to provide both assurance and consulting assistance on the adequacy and effectiveness of an organisation’s system of internal controls.
-
Business Risk Services
Our service is focused on enabling broader risk coverage and proactive management of risks for the achievement of organisational strategy.
-
Business Process Solutions
We work with a multitude of organizations to improve their finance function efficiency, reduce costs associated with business processes and provide a complete solution to the challenge faced by South African organizations.
-
Programme Assurance & Advisory
Our aim is to protect shareholder value by providing Assurance and Advisory services on change portfolios and large-scale programmes to assist organisations.
-
Forensic Services
Our forensic capability is integrated with our wider advisory services – not an add-on.
-
Cyber Advisory
Our Cyber Advisory service is designed to help you identify, protect, detect, respond and recover from cyber-attacks.
-
IT Advisory Services
We help clients to navigate the complexities and provide you with robust independent assurance that your IT risks, key management priorities and core systems are being appropriately managed.
-
SNG ARGEN
We have a dynamic actuarial team set to assist businesses to comply with the audit standards where actuarial services are required.
-
General Audit
We provide a sound statutory audit of financial statements specialising in both listed entities and state-owned organisations.
-
Financial Services Group (FSG)
The Financial Services Group (FSG) offers specialised audit and advisory solutions to the banking, treasury and financial services sectors.
-
Technical Excellence
We have a well-established specialized technical division, with in-depth, local and international knowledge and experience, which consists of three units namely; Accounting, Audit and Sustainability reporting.
-
Corporate Tax
We offer your business access to a global network of tax specialists in over 130 countries with extensive corporate tax technical skills to provide meaningful advice and adding value to your organization.
-
Value-Added Tax
We can manage your overall exposure to indirect taxes, guide you through complex South African Value-Added Tax (VAT) legislation.
-
Global Mobility
Taxes can be complicated, but the SNG Grant Thornton approach is to assist the new assignee with a clear and easy process.
-
Customs and Excise Tax
Our Customs and Excise team assist traders with driving cost-effective supply chains while maintaining legitimate trade.
-
Tax Technology
This is the lynchpin of our tax audit and advisory approach in making the tax function of our clients effective in data management tools.
-
International Tax & Transfer Pricing
Our team is ideally suited to serve large multinationals and other global companies that need on the ground expertise in multiple jurisdictions, given our extensive network of offices around the globe.
-
Specific Focus Areas
We have a team of dedicated tax specialists with deep knowledge to bring practical and cost-effective tax solutions to our clients and assist entities operating within these sectors to effectively manage their tax needs.
-
Tax Dispute Resolution (TDR) Services
Taxpayers are experiencing significant increase in number and size of tax audits by SARS which are leaving taxpayers with additional assessments and penalties, sources of tax disputes.
-
Business Consulting
We provide fit-for-purpose solutions to address major challenges the Education sector faces by supporting our clients.
-
Employees’ Tax Services
Its important to ensure that the institution complies with the tax legislation and that all payroll records are accurate and complete.
-
Programme Assurance & Advisory
The need for sound project management and effective solution delivery gives you the edge in competitive markets.
-
Forensic Services
Fraud detection review and forensic investigation for Higher Education
-
Digital and Analytics
The digitalisation of processes within the higher education sector leads to increased data generation. This data can be an essential asset when leveraged correctly.
-
Cyber Security Services
There is no one-size-fits-all security solution to preventing all attacks, but we have cybersecurity strategies that education institutions can use to minimise cyber threats.

-
Sustainable Development Goals (SGDs)
SDG Impact Standards Training Course
- South Africa
- Grant Thornton Morocco
- Grant Thornton Namibia
- Grant Thornton Malawi
- Grant Thornton Gabon
- Grant Thornton Algeria
- Grant Thornton Togo
- Grant Thornton Côte d'Ivoire
- Grant Thornton Zimbabwe
- Grant Thornton Cameroon
- Grant Thornton Zambia
- Grant Thornton Botswana
- Grant Thornton Mauritius
- Grant Thornton Senegal
- Grant Thornton Uganda
- Grant Thornton Nigeria
- Grant Thornton Kenya

Background and Overview
The South African Reserve Bank (SARB) has issued directives and Joint Standards that impact IT and Cybersecurity, setting a comprehensive regulatory framework to enhance the security and resilience of financial institutions. On May 17, 2024, the SARB issued Directive No. 01 of 2024, titled “Directive in Respect of Cybersecurity and Cyber-Resilience within the National Payment System.” This directive, along with Joint Standard 1 of 2023 (IT Governance and Risk Management Requirements for Financial Institutions) and Joint Standard 2 of 2024 (Cybersecurity and Cyber Resilience Requirements for Financial Institutions), establishes a regulatory framework for strengthening cybersecurity and resilience within South Africa’s financial sector. These regulations mandate financial institutions to adopt stringent cybersecurity controls, ensure robust IT governance, conduct risk assessments, and develop resilience frameworks to mitigate cyber threats. They also require institutions to maintain compliance with industry best practices, safeguard critical financial infrastructure, and implement strict oversight mechanisms for third-party service providers.
Impacted Businesses
The directive and standards apply to a broad range of entities, including:
• Financial Institutions: Banks, mutual banks, insurers, investment fund managers, pension funds, credit rating agencies, and discretionary FSPs.
• Payment Institutions: Clearing system participants, settlement system participants, third-party payment providers, and system operators.
• Market Infrastructure Entities: Financial market infrastructures, pension fund administrators, and over-the-counter (OTC) derivative providers.
• Third-Party IT Service Providers: Entities that provide IT services to financial institutions and payment operators.
Key Implications for Businesses
-
Strengthened Cybersecurity and Risk Management
Entities must implement cybersecurity frameworks incorporating governance, risk management, and resilience strategies in compliance with Joint Standard 1 of 2023 and Joint Standard 2 of 2024. This includes IT risk assessments, monitoring cyber threats, and implementing defense mechanisms such as multi-factor authentication (MFA) and encryption. -
Regulatory Compliance and Accountability
• Board and Senior Management Responsibilities: Institutions must establish clear governance structures where the board and senior management oversee cybersecurity risk management.
• Compliance Monitoring and Reporting: Regular cybersecurity audits and incident reports must be submitted to regulatory bodies. -
Cyber Resilience and Business Continuity
Businesses must develop disaster recovery and resilience strategies, ensuring that they can detect, respond to, and recover from cyber incidents within defined timelines. SARB Directive 01 of 2024 requires critical financial systems to resume operations within two hours of disruption, with a maximum recovery time of eight hours. -
Enhanced Third-Party Risk Management
Under Joint Standard 2 of 2024, institutions must conduct due diligence and risk assessments on third-party vendors and cloud service providers, ensuring compliance with data security and privacy regulations. -
Cybersecurity Testing and Incident Response
• Institutions must perform regular penetration testing and vulnerability assessments to proactively identify security gaps.
• A structured incident response plan is required, ensuring rapid containment, mitigation, and recovery from cyberattacks.
Emerging Cybersecurity Trends and Statistics
- Rising Cyber Threats: 2023 saw a 20% increase in cyber-attacks on financial institutions globally, with many targeting payment systems.
- Digital Transformation: Over 70% of payment transactions in South Africa are now digital, making cybersecurity a top priority.
- Financial Impact: The average cost of a financial sector data breach in 2023 was $5.85 million, underscoring the importance of robust security frameworks.
- Regulatory Evolution: Over 80 countries have introduced new cybersecurity laws in the last five years, reflecting a global move towards stricter financial sector regulations.
Compliance Requirements for Businesses
To comply with the directive and standards, financial institutions must:
- Develop a Cybersecurity Strategy – Establish governance frameworks and align cybersecurity strategies with business risk tolerance.
- Conduct Regular Risk Assessments – Identify vulnerabilities in IT systems and third-party services.
- Implement Security Controls – Deploy MFA, encryption, access control policies, and security information and event management (SIEM) systems.
- Maintain Incident Response Plans – Define cyber event detection, response, and recovery mechanisms.
- Continuous Monitoring and Employee Training – Ensure staff is trained on cybersecurity risks, phishing detection, and secure data handling.
How we can help
Our cybersecurity advisory services assist businesses in complying with SARB and FSCA regulations, offering:
- Cybersecurity Maturity Assessments – Evaluate your organization’s security posture and identify gaps.
- Regulatory Compliance Support – Assist with aligning cybersecurity frameworks with Joint Standards 1 and 2 of 2024 and SARB Directive 01 of 2024.
- Penetration Testing & Vulnerability Assessments – Identify security weaknesses before attackers do.
- Cybersecurity Training Programs – Educate employees on best practices for managing cyber risks.
- Incident Response Planning & Testing – Develop and test response strategies for cyber incidents.
Partner with us to build a secure and resilient financial ecosystem that complies with evolving cybersecurity regulations.