Compliance report

No significant environmental, social and/or governance-related incidents occurred during 2025. These include incidents of legal non-compliance (whether under investigation, pending finalisation or finalised), directives, compliance notices, warnings, investigations and any public controversies.

No fines, settlements, penalties, or other monetary losses were suffered concerning ESG incidents.

REGULATORY COMPLIANCE REPORT

The IRCC oversees regulatory compliance responsibilities. The Committee monitors, assesses, researches and reports on the regulatory environment in which Blu Label operates. The IRCC reports to the Audit, Risk and Compliance Committee (ARCC).

The process of compliance management encompasses:

  • identifying and prioritising all Acts and regulations at a national level applicable to Blu Label;
  • incorporating regulatory requirements into control measures such as standard operating procedures, processes, manuals and policies;
  • recommending corrective measures or steps to ensure compliance; and
  • monitoring compliance through the adequacy and effectiveness of control measures.

The risk of non-compliance is being managed through:

  • the quarterly review and update of the Blu Label regulatory universe;
  • the compilation of compliance risk management plans for high-risk legislation utilising external service providers; and
  • the continuous monitoring of the regulatory environment.

The regulatory environment changes constantly. We proactively contribute to and manage our regulatory environment by considering the interests of all our stakeholders and clients.

The Board is satisfied that Blu Label has complied with all relevant provisions of the Companies Act of South Africa and the JSE Listings Requirements and has complied with Blu Label’s MOI during the year.

No substantial complaints have been received concerning breaches of customer privacy, categorised by complaints from data subjects and complaints or requests for information from the Information Regulator.

APPROACH TO TAX

Taxation compliance

Taxation is managed as part of the regulatory compliance process managed under the IRCC and overseen by the ARCC. There were no significant penalties or disputes with the South African Revenue Service during the year under review. Expert advice is obtained in managing compliance with any complex areas of tax legislation. Blu Label does not have any significant foreign subsidiaries.

The total tax incurred by Blu Label in the current year amounted to R1 051.5 million. The total amount consists of the following categories of taxes:

Category     2025 
R'000 
   2024 
R'000 
Income taxes     330 818     136 033 
Property taxes     2 680     2 918 
Net non-creditable/(creditable) VAT     449 875     (18 919)
Employer-paid payroll tax     268 081     224 676 
Other taxes     —     1 343 

The information below summarises how Blu Label has managed the requirements of two pieces of significant South African legislation:

Protection of Personal Information Act, 2013 (POPIA)

POPIA gives effect to section 14 of the Constitution, which provides everyone the right to privacy. The Act protects personal information processed by public and private bodies and balances the right to privacy against other rights such as access to information.

The following POPIA initiatives have been embedded to ensure compliance at 31 May 2025:

  • The Blu Label Compliance Framework and Privacy Notice have been updated and approved by the Audit and Risk Committee.
  • POPIA information update sessions have been presented to the various subsidiaries.
  • POPIA-related policy documents have been updated.
  • Promotion of Access to Information Act, No 2 of 2000 (PAIA) manuals have been updated.
  • Record of Processing Activities (RoPAs) and POPIA Impact Assessments (PIAs) have been updated to identify and mitigate POPIA gaps. These RoPAs and PIAs are ongoing based on new products or initiatives being introduced throughout Blu Label.
  • Formal appointment of Deputy Information Officers throughout the Group to assist in monitoring POPIA compliance.
  • The POPIA Steering Committee met quarterly to monitor POPIA compliance and roll out policies.

Cybercrimes Act, 19 of 2020

Blu Label operations rely heavily on technology platforms to facilitate service delivery, which increases the risk of cybercrime. Therefore, it is critical to maintain the integrity and stability of key IT systems to protect stakeholder interests against increasingly sophisticated targeted attempts at digitally assisted fraud, one of the main objectives of the Cybercrimes Act, 19 of 2020.

Cybersecurity threats remain a critical ongoing risk and as a result makes up a significant part of our technology investments.

Stringent standards for information and infrastructure security controls are constantly being reviewed and reinforced to ensure our efforts continue strengthening our cybersecurity posture. We proactively assess our vulnerabilities and risk of exposure on an ongoing basis while driving cyber risk prevention, assessment and education programmes to maintain vigilance. Blu Label is embedding security as a core component within the platform delivery via governed development mechanisms and implementing detection capabilities and response processes in our environment.

Our implementation of the NIST cybersecurity framework is still ongoing. In line with our approved cybersecurity strategy, we have implemented the applicable suite of NIST controls and conducted a self-assessment on the maturity achieved through the implementing and operationalising of these controls. Internal audit independently reviewed the outcome of our self-assessment.

The following has been accomplished:

Initiative   Description
Implementation of SOC services.   Our SOC has been fully implemented and is currently operational, which provides 24/7 cybersecurity monitoring for our environment.
Security awareness training campaigns through the KnowBe4 platform.   Monthly security awareness training campaigns are rolled out to staff, covering various security domains.
Designed and implemented cybercrimes and incident management processes.   Cybercrimes and incident management processes are still in effect.
An annual review of the processes was conducted.   Internal audit performed reviews of processes supporting compliance with the Cyber Crimes Act.
Developed incident response and incident response testing as well as scenario planning.   Incident response processes are still in place and scenario testing will be performed during 2025/26.
Developed and implemented an ISMS aligned to ISO 27001.  

We have achieved certification against ISO 27001:2022 for our ISMS. Our core trading platform and environment operate stringent security controls to safeguard our customer and employee data. Maintenance of ISMS is ongoing. As part of this programme, we invest heavily in our continuous improvement initiatives which actively contribute to our security posture and maturity.

Surveillance audits are conducted to ensure the continued compliance and maintenance of the certification.