Compliance Monitoring Toolkit 2026 — ISO 37301 & the South African Compliance Officer: Monitoring Plans, FSCA Reporting & Fit-and-Proper (Guide, Flash Cards & 50-Question Self-Assessment)
Every FSP must monitor its compliance. Somebody has to build the plan, run the file sampling, write the FSCA report, and sign their name to it. This toolkit is for that person.
Most compliance material covers either the international standard (ISO 37301) or the local regime (FAIS) — never both. The Compliance Monitoring Toolkit deliberately covers the bridge, because that's where the actual job lives: a South African compliance officer works under FAIS but increasingly benchmarks against ISO.
What's inside — one interactive file, three tools:
📘 Ten chapters of compliance craft:
- ISO 37301 properly explained — the certifiable Type A standard, its PDCA structure, how it replaced ISO 19600, and the 3-year certification cycle with annual surveillance audits
- Current to the latest developments — Amendment 1:2024 (the February 2024 climate amendment to clauses 4.1 and 4.2) and the companion standards ISO 37302 (evaluating CMS effectiveness) and ISO 37303 (compliance competence), both published July 2025 — coverage most compliance guides haven't caught up with
- The compliance officer in South Africa — the s17(1) appointment trigger, when a sole-KI FSP needs no separate CO, outsourcing to approved compliance practices, and the handover report when officers change
- Fit and proper for compliance officers — the FSP Form 12 application, the five pillars, the real approval criteria under the s17 Notice (recognised qualification, three years' experience, the regulatory exam) — including why the popular belief in a "qualification exemption" for KIs and directors is a myth this product names and corrects
- Building a risk-based monitoring plan — file sampling, onsite assessments, thematic reviews, corrective-action tracking, and the breach register that feeds the next cycle
- FSCA compliance reporting done precisely — annual for Category I, bi-annual for Category II, IIA, and III, the e-services submission process, and the s13 competence register
- Compliance as the second line — the IIA's Three Lines Model (2020) and where compliance sits relative to risk and internal audit
- Whistleblowing — the Protected Disclosures Act 26 of 2000 (as amended in 2017) and ISO 37002 speak-up systems
- A key-numbers table and a full compliance glossary
🃏 40 Flash Cards — standards, sections, deadlines, and thresholds, filterable by topic.
📝 50-question self-assessment — timed mode (75 minutes, 70% benchmark) or practice mode with instant explanations, per-topic results, and unlimited retakes with reshuffled questions.
Who it's for: Aspiring and newly appointed compliance officers, key individuals who personally carry the compliance function, external compliance practices inducting junior monitors, RE1 candidates heading for the compliance officer path, and risk and governance teams aligning with ISO 37301.
Honesty, as on every product we publish: there is no public "compliance monitoring exam" in South Africa, and ISO 37301 certification is awarded to organisations, not individuals. This is the onboarding and self-assessment toolkit for the compliance officer's actual job — not exam prep dressed up as something else.
How it works: Instant download. One HTML file — any browser, any device, works offline. No account, no expiry.
Sovereignty by Char (Pty) Ltd is an independent publisher, not affiliated with ISO, the SABS, the FSCA, or any certification body. This toolkit is education, not compliance advice — full disclaimers inside.