NexBDM

NexBDM Blog

Compliance Tracker: why the spreadsheet is the list, and how to turn it into a system that reminds you

By NexBDM Team · 2026-09-15

Key takeaways

  • A compliance tracker is a list until it can derive dates from rules, remind the right person from the obligation itself, and close a row only when the evidence is filed. Four deadlines read from SARS and CIPC, the three shapes they take, and the six steps to build in order.

A compliance tracker is a list until it can derive dates from rules, remind the right person from the obligation itself, and close a row only when the evidence is filed. Four deadlines read from SARS and CIPC, the three shapes they take, and the six steps to build in order.

A compliance tracker is a list of every filing your business owes, with the date each one falls due. Most small businesses keep one in a spreadsheet. The spreadsheet is the list. It is not the system, because a list cannot remind you, cannot work out the date from the rule, and cannot tell you whether the filing was done.

This post is the bridge between two things we already published. The business compliance checklist lists every obligation a South African company carries, with its trigger and its source. The business process automation map sets out the order in which a business should automate: capture once, reuse, route, remind, report. Compliance sits exactly where those two meet. It is a list of dated obligations, and dated obligations are the easiest thing in a business to hand to a system, provided the list is built properly first. Every deadline quoted below was read from the SARS or CIPC page on 15 September 2026.

What is a compliance tracker, and what is it not?

The version most owners have is a sheet with three columns: the filing, the date, and a tick. It gets built once, usually after a penalty, and then it drifts. Somebody stops updating it, the year-end changes, a new employee pushes the business over a threshold, and the sheet still says what it said the day it was made.

A tracker that works holds four things per obligation that a spreadsheet row usually does not:

What the row needsWhat it meansExample
The rule, not the dateThe date is derived from a fact about your business, and the fact is what you store"Within six months of the start of the year of assessment", not "31 August"
The triggerThe event that makes the obligation exist at allRegistering a company creates the annual return. Paying a salary creates the EMP201.
The evidenceThe document that proves the filing happened, stored against the obligationThe eFiling submission receipt, not a tick
The consequenceWhat lateness costs, in the words of the authority that charges itA penalty rate, a suspended status, a deemed nil estimate

The first row is the one that changes everything. A spreadsheet stores dates. A system stores rules and produces dates. That difference is the whole reason one of them can remind you and the other cannot.

Four deadlines, read from the source, and what each one is derived from

Here is what the rule looks like for four obligations almost every employing South African company carries. Each is quoted from the authority's own page.

1. Monthly PAYE: seven days after month end

SARS's Pay As You Earn page says the amount deducted "must be paid within seven days after the end of the month during which the amount was deducted." The derived fact is the month a salary was paid. The reminder should come from the payroll run, not from a calendar, because the payroll run is the event that created the obligation.

2. Provisional tax: six months from the start of the year of assessment

SARS's provisional tax page: "The first provisional tax payment must be made within six months of the start of the year of assessment." The derived fact is your financial year-end. Change the year-end and every provisional date moves with it. The same page carries the consequence for the final return: a taxpayer who "does not submit the final provisional tax return within four months after the last day of the year of assessment" is "deemed to have submitted an estimate of an amount of nil taxable income." We covered the first period in detail in the provisional tax first period guide.

3. CIPC annual return: thirty business days from the due date

CIPC's annual returns page: "Companies have 30 business days from the date when annual returns become due to file annual returns before they are considered non-compliant with the Companies Act." The derived fact is the incorporation date, which never changes, so this is the easiest deadline in the business to automate and the one most often missed, because nothing in the month reminds anyone of it. The consequence on the same page: a company that "does not file Annual Returns for two years it will be placed under deregistration process status", and "will remain suspended to conduct any form of business until you file Annual Returns and/or Beneficial Ownership declarations." The full mechanics are in our CIPC annual returns post.

4. The EMP501 interim reconciliation: a fixed window, announced each year

This one is different, because the date is set by notice rather than derived from a fact about you. SARS's notice dated 31 August 2026 fixes the 2026 interim window at 21 September to 31 October 2026, and the late penalty at "1% of your annual PAYE", which "increases by 1% for every month the return remains outstanding, up to a maximum of 10%". A fixed-window obligation is the one case where the tracker has to be told the date, and the safe way to do that is to store the source notice against the row, so that next year the row asks to be re-read rather than assumed. Yesterday's post on the confirmed EMP501 window is the current notice.

Between these four you have the three shapes every compliance deadline takes: a recurring date derived from an event (PAYE), a date derived from a fixed fact about the business (provisional tax, annual returns), and a window set by the authority each year (EMP501). Our SARS deadline calendar lists the dated ones for the year ahead; the checklist above holds the rest.

How the work gets reduced: what a system does that the sheet does not

This is the section that matters, and the mechanism is specific.

  1. Capture the facts once. Incorporation date, financial year-end, VAT registration date, first payroll date, number of employees. Five fields. Every derived deadline in the business comes off those five, and they are captured at onboarding, once, not re-keyed into a sheet each year.
  2. Store the rule, generate the date. "Seven days after month end" is a rule. "Six months from the start of the year of assessment" is a rule. The system produces the date from the rule and the fact, so a change to the fact regenerates every date that depends on it. Nobody edits a spreadsheet.
  3. Hold the weekend rule in one place. Several of this year's SARS dates fall on a weekend, and the working rule shifts them to the last business day before. That rule lives once in the system and applies to every generated date, instead of being remembered per row.
  4. The reminder comes from the obligation, not the calendar. A calendar reminder says "annual return" to whoever owns the calendar. An obligation reminder goes to the person assigned to that obligation, carries the derived date, the source rule, and a link to where the evidence gets filed, and escalates if the evidence has not landed by a set number of days before the date.
  5. Evidence closes the row. The row is not done when someone ticks it. It is done when the submission receipt is attached to it. That is what turns the tracker into a record you can hand to an accountant, a bank or SARS without a search.
  6. Fixed-window rows expire. A row whose date came from a notice rather than a rule carries the notice and a "re-read by" date. The EMP501 row for 2027 should not carry 2026's dates; it should ask to be re-read in August.

None of this needs an AI model. It needs five captured facts, a small set of rules, a reminder engine and a place to file evidence. That is the boring end of automation and it is where most of the value in a small business sits. It is also exactly the pattern in our workflow automation guide: capture once, reuse everywhere.

What to build first, in order

  1. Write down the five facts. If you cannot state your incorporation date and year-end without looking, that is the first gap.
  2. List every obligation from the checklist that applies to you, and beside each one write the rule in the authority's words, not a date.
  3. Mark which rows are derived and which are set by notice. The notice rows get a source link and a re-read date.
  4. Assign one owner per row. Not a department, a person.
  5. Decide where evidence lives, and make the row point at it.
  6. Only now put a reminder on it. A reminder on a list that was wrong is a reminder to do the wrong thing on time.

Frequently Asked Questions

Is a spreadsheet good enough as a compliance tracker?

It is good enough as the list, and most businesses should start there. It is not a system, because it stores dates rather than rules, it cannot remind anyone, and a tick is not evidence. Build the list in the sheet, then move the reminders and the evidence out of it.

Which compliance deadlines can be worked out automatically?

Any deadline expressed as a rule against a fact about your business: monthly PAYE from the payroll month, provisional tax from the year-end, the annual return from the incorporation date. Fixed windows announced by notice, such as the EMP501 reconciliation, have to be read and entered each year.

What happens if a CIPC annual return is missed?

CIPC's page says a company has 30 business days from the due date before it is non-compliant, and that a company which does not file for two years is placed under deregistration process status and is suspended from conducting business until it files.

Does compliance automation need AI?

No. Deadline tracking is rules, dates, reminders and evidence. A system that captures five facts once and derives every date from them removes most of the work without a model anywhere in it. AI earns its place later, on documents and questions, not on dates.

The short version

A compliance tracker is a list until it can derive dates from rules, remind the right person from the obligation itself, and close a row only when the evidence is filed. The four deadlines above show the three shapes every obligation takes, and the six steps show the order to build in. If you want to see which of your deadlines still live in someone's head, and which facts about your business are typed into a sheet every year instead of captured once, that is what a Business Autopsy finds, and a discovery call is where it starts.

Sources, read directly on 15 September 2026: South African Revenue Service, Pay As You Earn page (payment within seven days after month end; "What's New" notice dated 31 August 2026 fixing the interim EMP501 window and the late penalty); South African Revenue Service, Provisional Tax page (first payment within six months of the start of the year of assessment; deemed nil estimate where the final return is not submitted within four months of year-end); Companies and Intellectual Property Commission, Annual Returns page (30 business days from the due date; deregistration process status after two years of non-filing). Every quoted phrase is the authority's own wording. No figure in this post is ours.

Book a free strategy call →