powered by
CostusWorx
bruce@costusworx.co.za  |  +27 82 650 9098
costusworx.co.za  |  August 2026
Live in production Regulatory compliance complipath.costusworx.co.za

When the regulator asks, the answer is a report

Competence and CPD tracking for regulated businesses. Every obligation is derived from one date — the representative’s date of first appointment — so classes of business, regulatory exams, qualification and the CPD cycle all recalculate themselves. Change the DOFA and every downstream deadline moves with it.

FAIS ยท Board Notice 194DOFA-derived deadlinesAppend-only CPD logKey Individual dashboardOn-demand registerConfigurable engine
1date drives everythingDOFA
6/12/18CPD hour targetsby classes of business
RAGstatus per personfrom real deadline arithmetic
PDFregister on demandgenerated from live data

The problem

What CompliPath is for

Financial services compliance fails quietly. Nobody misses a deadline on purpose; they miss it because the deadline lived in a spreadsheet nobody owned, and the person who did own it left. CompliPath makes the deadlines structural rather than remembered.

Capabilities

What it does

Built on the framework, not around it
  • Phase one implements FAIS under Board Notice 194 of 2017
  • Licence-date label, CPD metric, cycle boundaries and register template are configuration
  • Adding a second regulated profession is a database row, not a rewrite
  • Supervision status tracked per representative
DOFA-derived deadline engine
  • Classes of business at 12 months from first appointment
  • Regulatory examinations at 24 months
  • Full qualification at six years
  • CPD cycle running June to May, recalculated on every change
CPD that survives an audit
  • Activities logged with provider, hours and certificate
  • Classified as regulatory, ethics, technical or business skills
  • Nothing counts until the Key Individual approves it
  • Append-only history — corrections supersede, they never overwrite
The Key Individual’s view
  • The whole register on one screen, ranked by what is closest to going wrong
  • Red / amber / green status driven by real deadline arithmetic, not a manual flag
  • Who is under supervision, and when that supervision lapses
  • CPD entries queued for approval, with rejection notes and an audit trail
The representative’s view
  • One person, their own deadlines, and nothing else
  • Log an activity and attach the certificate from a phone
  • See exactly what is outstanding and by when
  • Personal CPD summary against the current cycle target
Register & evidence export
  • Per-industry register templates
  • PDF register generated on demand from live data — never a stale saved copy
  • CSV export for internal reconciliation
  • Certificate documents stored outside the web root, served through a checked route
Alerting
  • Nightly job raises alerts as deadlines approach
  • De-duplicated so people are warned, not spammed
  • Escalation to the Key Individual on overdue items
  • Command-line only — the job refuses to run over HTTP
Multi-tenancy & administration
  • FSP tenants with seat counts and isolated data
  • User creation and role assignment per tenant
  • Learner profile onboarding
  • Cross-tenant access refused at the query, not the interface

In practice

How an obligation runs

01AppointCapture the representative and their date of first appointment
02DeriveEvery downstream deadline calculates automatically
03LogThe representative records CPD with a certificate attached
04ApproveThe Key Individual approves, rejects with notes, or queries
05EvidenceThe register exports on demand, generated from live data
Under the hood
  • PHP 8.x + MySQL 8 on cPanel shared hosting
  • Configurable industry engine — rules live in a configuration row, not in code
  • Server-side PDF register generation
  • Vanilla PHP templates, no JavaScript framework to maintain
  • Automated test suites covering the compliance calculation itself
Security & compliance
  • Role middleware with injected database handle — no ambient authority
  • Cross-tenant requests refused at the data layer
  • CSRF protection on all mutating actions
  • Uploaded certificates stored outside the web root and path-traversal checked
  • Login throttling and an immutable audit trail
Who it is for
  • FSPs carrying FAIS obligations for their representatives
  • Key Individuals with personal regulatory accountability
  • Motor and insurance groups tracking F&I consultants across branches
  • Any regulated profession where CPD and competence must be evidenced
On the roadmap
Second regulated profession onboarded as configuration
Bulk CSV import and WhatsApp deadline alerts
Self-service POPIA consent capture and password reset

See it running, not in a slide

Live demo — an FSP licence with sixteen people on it