When Credico SA’s Risk and Investigation Manager arrived at Afrishore BPO’s Johannesburg headquarters for a BPO compliance site visit, he came prepared with the standard frameworks. What happened next was not standard. He described it as a masterclass in organisational culture. This article explains why those two things, compliance and culture, are inseparable in South Africa’s best BPOs, and what the distinction costs enterprises that get it wrong.
The Site Visit That Rewrote the Script
Senzo Mkhize is a Risk and Investigation Manager at Credico SA, one of Afrishore’s key service partners. His job is finding gaps. In May 2026 he arrived at our Johannesburg headquarters for a routine compliance and operational site visit: the structured walkthrough procurement teams use to benchmark third-party risk.
The first detail worth noting is who gave the tour. I did it personally.
At most BPOs, a compliance site visit is handled by the compliance officer or an operations director. The CEO is briefed afterward. When the Group CEO does the walkthrough, it signals something about how the organisation treats compliance: not as a departmental function, but as a shared responsibility at every level – including the top.

Why Auditors Now Read Rooms, Not Just Manuals
In September 2024, the US Department of Justice updated its Evaluation of Corporate Compliance Programs, the document prosecutors use to determine whether a company’s compliance programme is genuine. The update added explicit cultural metrics: how companies encourage employees to report misconduct, whether they chill speak-up behaviour, and whether they actually measure employees’ willingness to come forward.
This formalised what compliance professionals have known for years: you cannot audit culture from a document. The DOJ now requires that compliance assessors look for behavioural evidence, not just procedural records.
The same shift is happening in third-party compliance assessment. When an enterprise risk manager audits a BPO, the most revealing signals are rarely in the paperwork. They’re in:
- Whether agents know data-handling rules without being prompted
- Whether a floor manager can explain the intent behind a policy, not just its title
- Whether the speak-up process is a known tool or a buried handbook entry
- Whether leadership is present on the floor by habit, not by schedule
Senzo’s assessment (that the experience went beyond standard frameworks) is what it looks like when a compliance auditor arrives at a BPO and finds all four of those signals present.
Related reading: How Afrishore approaches quality assurance in call centre outsourcing, and why QA and compliance culture reinforce each other.
The Stakes: POPIA Enforcement and the Third-Party Breach Premium
For UK and US enterprises outsourcing to South Africa, the compliance stakes are not abstract. South Africa’s Protection of Personal Information Act (POPIA) carries penalties of up to R10 million or 10 years imprisonment for serious violations. After a period of regulatory restraint, enforcement is now accelerating.
The Information Regulator issued its first administrative fine of R5 million against the Department of Justice in 2023. In November 2024 it issued a second R5 million fine, this time against the Department of Basic Education. In April 2025, POPIA regulations were amended to introduce new information officer responsibilities and strengthened data-subject rights. The trajectory is clear: POPIA is an active enforcement environment, not a theoretical risk.
Beyond POPIA, there is a quantifiable financial argument for choosing a culturally compliant BPO partner. IBM’s 2025 Cost of a Data Breach Report found that third-party and supply chain breaches cost an average of USD 4.91 million per incident, $470,000 above the global average. Verizon’s 2025 Data Breach Investigations Report found that 30% of all confirmed data breaches now involve third-party vendors, double the 15% recorded the previous year.
| Metric | Figure | Source |
| Average cost of a third-party breach | USD 4.91m | IBM, 2025 |
| Share of breaches involving third-party vendors | 30% (doubled from 15% in 2024) | Verizon DBIR, 2025 |
| Maximum POPIA fine for serious data violations | R10 million | POPIA / Baker McKenzie, 2025 |
When you outsource to a BPO that treats compliance as a checklist, you do not reduce your risk exposure. You inherit theirs. The question a procurement team should ask is not “do they have a compliance policy?” but “has that policy changed how people behave?”
Important for UK buyers: UK enterprises transferring personal data to South Africa operate under a GDPR–POPIA adequacy framework. A POPIA compliance failure at your BPO partner can trigger concurrent regulatory scrutiny under GDPR. Choose your vendor’s compliance culture carefully: it is your compliance exposure too. See: outsourcing to South Africa for UK businesses.
What Enterprise Buyers Are Actually Screening For
Ryan Strategic Advisory’s 2025 Front Office BPO Omnibus Survey asked 668 enterprise CX decision-makers across eight markets why they had moved, or were considering moving, customer service operations back onshore. The most frequently cited reason was cultural alignment between agent and consumer – ahead of cost, data security, and regulatory compliance.
That finding carries two implications for BPO selection in South Africa.
First, it tells you what enterprise buyers are already measuring on a site visit, whether they articulate it that way or not. When a procurement team walks a contact centre floor and feels something is off, they’re often reading cultural signals: agent disengagement, inconsistent manager behaviour, a floor where people look uncertain about what they’re allowed to do. Those are not checklist failures. They’re culture failures.
Second, it tells you that South Africa’s structural advantage in cultural alignment in customer support only delivers if the alignment is real and observable, not claimed on a slide deck. South Africa was ranked the #1 offshore CX destination for US enterprise buyers in the same survey, and BPESA benchmarks SA’s CX quality 18% higher than comparable offshore markets. That advantage is not built on cost arbitrage. South Africa costs 60–70% less than UK and Australia, but so do other destinations. The premium buyers pay for South Africa is cultural. And that culture is only worth the premium if it extends to compliance.

The Checklist Trap: Why Most BPOs Are Moving in the Wrong Direction
The compliance industry’s own data reveals a troubling drift. Navex’s 2025 Global Risk and Compliance Statistics report found that only 47% of risk and compliance professionals now consider building an ethical culture of compliance “very important,” down from 76% in 2023. That 29-point drop in two years represents a sector-wide retreat from genuine compliance culture toward documentation compliance: the kind that passes an audit on the day, but doesn’t change behaviour the rest of the year.
PwC’s 2025 Global Compliance Survey found that only 7% of organisations describe themselves as “leading” in compliance, and that 77% say compliance complexity has negatively impacted growth. The same survey identified the single most effective driver of compliance culture: senior management sponsorship, “tone at the top,” cited by 55% of compliance professionals as the primary enabler.
What checklist compliance looks like in practice: a laminated policy on the break room wall, an annual e-learning module, a folder of certifications in the compliance officer’s drawer, and agents who know the acronyms but not the reasoning behind them. It satisfies an auditor for one afternoon. It does not survive a relationship.
What culture-led compliance looks like: an agent who, when asked by a customer to share a colleague’s extension, explains without hesitation that they’re not permitted to share internal staff contact details under their data protection policy, and doesn’t need to check with anyone to know that. That knowledge is not in a checklist. It’s in a conversation that happened at onboarding, and every week since.
Related reading: Compliance culture in specific verticals: AML compliance in iGaming BPO (how Afrishore handles Anti-Money Laundering obligations in a heavily regulated sector). Also: CMMC-compliant offshore customer service for US defence contractors.
What BPO Compliance in South Africa Looks Like on the Floor
You cannot read compliance culture from a document pack. Here are six observable signals that distinguish a culturally compliant BPO from one that has the paperwork in order.
1. Agent knowledge without prompting Agents who can explain, without referencing a script, what they are not permitted to do with a customer’s personal information, and why, are agents working in a culture where compliance is a daily conversation, not a quarterly module. Ask an agent a question that isn’t in their script. Watch what they do.
2. Floor manager policy recall Ask a floor manager to explain the organisation’s data retention policy without referring to a document. The quality of that answer tells you more about compliance culture than any ISO certificate on the wall. The target answer is not “I’ll check with compliance.” The target answer is accurate, immediate, and includes the reason behind the rule.
3. Visible speak-up infrastructure Only 53% of organisations globally have a formal whistleblower hotline, and only 49% have non-retaliation policies in writing (Navex 2025). In a genuine compliance culture, the speak-up process is known by name, actively used, and regularly discussed, not buried in an onboarding handbook that 80% of staff never reopen. Ask: can any agent tell you how to raise a compliance concern right now?
4. Leadership presence on the floor PwC’s survey named “tone at the top” as the single most effective driver of compliance culture. Leadership presence is not a quarterly walkthrough; it is a visible, regular habit. When the CEO personally leads a compliance site visit, that is a live demonstration of tone at the top. It signals to every person on that floor that compliance is not someone else’s department.
5. Training recency and specificity Generic annual compliance training satisfies an audit requirement. Role-specific training updated to reflect the last regulatory development (POPIA’s April 2025 amendments, for example, which introduced new information officer responsibilities) indicates a compliance function that is responsive rather than ceremonial. Ask when compliance training was last updated and what specifically changed.
6. Internal incident reporting rates This one surprises people: a higher number of reported internal compliance incidents is often a sign of a healthier culture, not a weaker one. It means people feel safe raising concerns. Organisations with suspiciously low internal reporting and clean external audits are frequently suppressing signals, not eliminating problems.
What to Ask on a BPO Compliance Site Visit
If you’re in the process of selecting and verifying an offshore BPO, the site visit is your most reliable data point. These questions probe culture rather than documentation.
| Question to ask | Red flag answer |
| “Walk me through what happens when an agent believes a policy has been breached.” | Vague or uncertain – nobody knows the process by memory |
| “What was the most significant compliance change your operations dealt with in the last 12 months?” | Blank pause, or they cite a change from 3+ years ago |
| “Who owns compliance culture – HR, the compliance team, or line managers?” | “The compliance team” – siloed ownership is a structural weakness |
| “Can you show me your last internal audit finding and what changed as a result?” | No documented action taken, or outcomes are vague |
| “What does your agent onboarding cover on POPIA / GDPR data handling?” | “It’s covered in the compliance module” – no specifics, no recency |
Three observable signals that go beyond the questions:
- Do agents acknowledge visitors without stopping their work? Confidence without disruption signals a floor used to operating well under observation, not performing for it.
- Is process documentation visible at workstations, not just in a shared drive? Compliance that lives in a folder nobody opens is aspirational. Compliance that lives on the desk is operational.
- Is the tour given or narrated? Someone who explains why things work the way they do, the reasoning behind a policy, the history of a process, is in a different compliance culture to someone who shows you where things are.
For more on evaluating offshore partners, see our guide to building long-term BPO partnerships and what to look for beyond the initial contract.
Compliance Culture Scorecard
Five questions. Tally A = 2 pts, B = 1 pt, C = 0 pts.
1. If you asked a front-line agent what to do with a customer’s personal data after the call, they would…
- A: Know the rule immediately and explain the reason behind it
- B: Follow the script they were trained on
- C: Ask a team leader to confirm
2. Your floor manager’s relationship with your data protection policy is…
- A: They cite it from memory and can explain the intent behind specific rules
- B: They refer to the policy document when needed
- C: They escalate compliance questions to the dedicated compliance team
3. Your whistleblowing / speak-up process is…
- A: Known by name, used by staff, and discussed during team briefings
- B: Documented in the employee handbook and referenced in onboarding
- C: You’d need to check whether one exists in formal documentation
4. When senior leadership last visited the operations floor…
- A: Leadership presence is a regular, visible habit, not a scheduled event
- B: It was a quarterly or half-yearly structured review
- C: It was tied to an audit or a specific incident
5. Compliance training in your BPO was last updated…
- A: Within the last six months, specifically to reflect a regulatory or policy change
- B: Annually as part of a standard compliance refresh
- C: It’s hard to say – training is managed by a third-party LMS
Your score: 8–10 = Culture-led · 4–7 = Developing · 0–3 = Checklist BPO
Key Takeaways
- The DOJ formally added cultural metrics to compliance programme evaluation in September 2024 – auditors now assess speak-up culture, tone at the top, and anti-retaliation posture, not just documentation.
- Third-party breaches cost an average of USD 4.91m and now account for 30% of all confirmed data breaches – double the prior year. Your BPO’s compliance culture is your compliance exposure.
- POPIA enforcement is accelerating in South Africa: two R5m fines in 12 months, with April 2025 amendments expanding information officer obligations.
- Cultural alignment (not cost or certifications) was the single most-cited reason enterprise buyers reshored BPO contracts, per Ryan Strategic Advisory 2025. Buyers already screen for culture, whether BPOs know it or not.
- Only 47% of compliance professionals now rate ethical culture as essential, down from 76% in 2023. The sector is drifting toward checklist compliance. The BPOs that resist that drift are the ones worth a long-term contract.
- Six observable signals separate compliance culture from compliance paperwork: agent knowledge without prompting, floor manager policy recall, visible speak-up infrastructure, regular leadership presence, specific and recent training, and healthy internal incident reporting rates.
Conclusion
A compliance site visit that turns into a conversation about culture is not a detour. It is the destination. When Senzo Mkhize arrived at Afrishore’s floor, he brought a risk framework. What he found was a workforce that had already internalised that framework – not because of a policy document, but because of 20 years of building a BPO where compliance is embedded in how people behave at eight in the morning on a Tuesday, not just on the day of the audit.
The enterprises that get this right are the ones who ask better questions during site visits, look for culture signals rather than certificate displays, and measure the compliance partnership over months rather than days. The financial case is clear: USD 4.91 million per third-party breach, doubling year-on-year, makes that standard of scrutiny straightforward to justify.
For more on what to look for in an offshore BPO partner, see our overview of BPO companies in South Africa and our guide to why enterprises outsource to South Africa.
Ready to audit a culture, not a checklist? Afrishore BPO operates from Johannesburg with 750 seats, 20 years of delivery experience, and a compliance culture that extends from the CEO to every workstation. Talk to Afrishore BPO.
Frequently Asked Questions
What compliance frameworks does Afrishore BPO operate under?
Afrishore BPO operates under South Africa’s Protection of Personal Information Act (POPIA) as the primary data protection framework. For UK clients, we operate within the GDPR–POPIA adequacy framework, ensuring cross-border data transfers meet both regulatory standards. Our operations also adhere to ISO quality management principles, BPESA’s sector governance standards, and client-specific compliance requirements across verticals including iGaming (AML/KYC), insurance (FSCA), and healthcare (HIPAA for US clients). Compliance frameworks are applied at the operational level, not maintained only in documentation.
How does POPIA affect UK and US companies outsourcing to South Africa?
UK companies transferring personal data to a South African BPO must ensure the transfer is lawful under UK GDPR. South Africa is regarded as providing adequate protection for UK data transfers, but the adequacy determination rests on your BPO partner actually complying with POPIA – not merely having a POPIA policy. A POPIA compliance failure at your BPO can trigger GDPR scrutiny of your transfer arrangements. For US companies, POPIA obligations apply to personal data of South African data subjects processed in South Africa; US companies should ensure their BPO has appropriate information officer designations and breach notification procedures in place following the April 2025 POPIA amendments.
What is the difference between compliance certification and compliance culture?
Compliance certification is a point-in-time assessment: a document audit, an ISO review, a POPIA readiness checklist. It verifies that processes exist and documentation is in order. Compliance culture is the ongoing state of how people actually behave when no one is auditing – whether agents handle data correctly because they understand why it matters, whether managers reinforce compliance daily rather than during audit preparation, whether the organisation’s leadership treats compliance as a shared responsibility at every level. Certifications can be manufactured for an audit cycle. Culture cannot.
How should a procurement team assess compliance culture during a BPO site visit?
Prioritise questions that probe behaviour over documentation. Ask floor managers to explain a specific policy without referring to a document. Ask agents what they do when they’re unsure whether a customer request is compliant. Ask who specifically is responsible for compliance culture. The right answer involves line managers and leadership, not just a compliance team. Observe whether the floor has visible process documentation, whether leadership is present, and whether agents work confidently under observation rather than performing. The most revealing questions are those that probe the reasoning behind rules, not just awareness of their existence.
What are the financial risks of outsourcing to a non-compliant BPO?
IBM’s 2025 Cost of a Data Breach Report quantifies the third-party breach premium at USD 4.91 million per incident, $470,000 above the global average. Verizon’s 2025 DBIR found that 30% of all confirmed breaches now involve third-party vendors, double the prior year. POPIA penalties reach R10 million per serious violation. Under a GDPR–POPIA adequacy framework, a breach at your South African BPO can also trigger GDPR investigation of your data transfer arrangements, with GDPR fines reaching up to 4% of global annual turnover. Noncompliance-linked breaches also take significantly longer to resolve: IBM found supply chain compromise takes an average of 267 days to contain, extending the period of operational disruption and reputational damage.
Is South Africa a safe jurisdiction for offshore data processing?
South Africa is widely regarded as one of the more mature data protection jurisdictions in Africa, with POPIA aligned to GDPR principles including lawful basis requirements, data subject rights, breach notification obligations, and information officer accountability. The country’s GBS sector, now employing over 150,000 offshore-facing agents, operates under BPESA governance frameworks and client-specific security requirements. Critically, South Africa is ranked #1 for offshore CX by US enterprise buyers (Ryan Strategic Advisory 2025), with its regulatory maturity cited alongside cultural alignment as a key selection factor. The jurisdiction is safe; the variable is whether your specific BPO partner treats compliance as culture or documentation.
What should a BPO compliance audit checklist include beyond standard certifications?
Standard certifications (ISO, POPIA readiness, data processing agreements) are the minimum. A culture-oriented compliance audit should also include: behavioural observation of agents and floor managers under normal working conditions; review of internal compliance incident reporting rates and actions taken; assessment of speak-up / whistleblower infrastructure and staff awareness; confirmation that compliance training has been updated within six months to reflect recent regulatory changes; evidence of leadership presence on the operational floor (not just in governance meetings); and a random sample of agent knowledge testing on a specific data-handling scenario without advance notice.
How does Afrishore BPO train agents on POPIA compliance?
Compliance training at Afrishore is role-specific and updated to reflect regulatory changes, not a static annual module. All agents receive POPIA onboarding that covers data handling obligations relevant to their specific role and client vertical, including sector-specific requirements (AML/KYC for iGaming, claims handling protocols for insurance). Training is reinforced through regular team briefings and floor-level conversations rather than reserved for annual review cycles. The April 2025 POPIA amendments – which introduced new information officer responsibilities and updated data-subject rights processes – were incorporated into operational briefings within weeks of enactment. For more on training standards, see our page on BPO agent training and quality.



