The revelation has sparked serious concerns over Sassa's data management and record-keeping systems.
Last week, Sassa presented its audit action plan for the 2023/2024 financial year following the release of the Auditor-General of South Africa (AGSA) findings and recommendations.
Despite ongoing efforts to modernise and digitise its records, Sassa continues to face challenges with data synchronisation and the timely reporting of deaths.
Sassa Chief Financial Officer, Tsakeriwa Chauke, explained that payment files for the upcoming month are prepared at the end of each month. This process ensures beneficiaries receive their grants at the beginning of every new month. However, if a beneficiary dies between the preparation of payment files and the actual payment date, the grant may still be disbursed.
As a result, more than 75,000 deceased individuals were paid social grants during the last financial year.
Sassa Executive Manager for Grants Administration, Brenton Van Vrede, noted that these family members are often financially disadvantaged and therefore unable to repay the funds.
Van Vrede suggested that an aggressive life certification system could be implemented to prevent payments to deceased individuals in the future. However, he acknowledged that this solution comes with challenges.
With 19 million beneficiaries, this would place a significant burden on both the beneficiaries and the administrative resources needed to manage monthly certifications.
Digitisation Efforts Underway
Sassa has undertaken a digitisation drive aimed at improving audit readiness and data accuracy.
According to Van Vrede, the agency is currently scanning every record to create electronic versions that will be accessible for auditing by the AGSA. The goal is to complete this process by the beginning of the new financial year.
One of the key issues flagged by the Auditor-General was the lack of alignment between Sassa’s two databases. The agency used the Beneficiary Records Management (BRM) system and the Social Grant Payment System (SOCPEN).
The challenge is that not all beneficiaries who received grants were recorded in the BRM system.
Chauke confirmed that internal audits also revealed discrepancies and missing information in certain cases. Officials confirmed that a population analysis will be conducted to compare records between SOCPEN and BRM and resolve any discrepancies.
Whatever exceptions we find, we will resolve.
Manual Registers Raise Further Concerns
The Auditor-General also highlighted problems related to the use of manual registers in local Sassa offices.
Chauke explained that when individuals visit Sassa offices, their information is captured in manual registers. However, auditors discovered that some beneficiaries listed in these registers were not reflected in Sassa’s internal control and assurance systems.
This raised questions about the completeness of enquiry records and whether all interactions were properly logged in digital systems. Sassa is working to close these gaps and is gradually phasing out manual registrations, except when digital systems are unavailable.
The vulnerability of sensitive beneficiary data was also raised as a critical issue.
Jabulani Makondo, Acting Chief Information Officer, explained that Sassa uses various technologies to prevent data loss. This includes the use of firewalls to monitor incoming and outgoing data, antivirus software, and encryption methods to protect organisational and staff data from unauthorised access. He added that regular backups are conducted on a monthly and weekly basis, and data is stored in offsite environments to ensure security and resilience.
These data loss prevention (DLP) measures are crucial in protecting the personal and financial information of millions of South Africans.





