
Disciplinary Action
-
UWC charged three managers in the Work Study Office over ghost workers after last month’s revelations.
-
The three appeared at a disciplinary hearing and are going through the internal process.
Advertisement
Payroll and Student Funds
-
Ghost workers were introduced into the Adapt-IT payroll system, an online system.
-
Over 85 ghost workers were paid.
-
Funds meant for students ran out.
-
Disadvantaged UWC students were not paid for over 3 months.
Data and Investigations
-
UWC data moved into the new system is still not in UWC’s custody.
-
The data is currently held by the vendor because UWC has not complied with contract requirements.
-
UWC commissioned two independent investigators to look into matters raised in last month’s report.
KPMG Report Covers
-
Governance collapse / executive capture: Control of the UWC Council and governance oversight by executive management, neutralizing independent accountability.
-
Auditor interference: External auditors restricted in scope and directed on what to audit, preventing independent forensic deep-dives.
-
Lack of IT audit function: No functional, independent internal audit department or IT audit capability to evaluate security and financial controls.
-
Unapproved policies: Policies drafted and repeatedly shelved without formal Council approval, while unauthorized payments and vendor renewals continued.
-
Concealment of cyber-attacks: Major cyber-attacks and compromised systems hidden since 2022, breaching statutory reporting duties.
-
Library data destruction: Severe infrastructure failure caused loss of research data; staff manually created placeholder records to hide the destruction from breach notifications.
-
Vendor fraud and overbilling: First Technology Western Cape allegedly added unauthorized markup and inflated invoices by about R1.8 million above the agreed baseline.
-
Telecom and VPN loss: A R20 million material financial loss from compromised student VPN credentials and systematic airtime abuse.
-
Payroll vulnerabilities: Adapt IT modules led to missing Work-Study funds and unverified “ghost workers” inserted into active payroll.
-
Compromised fraud hotline: KPMG FairCall lacked proper firewalling, causing confidential whistleblower reports to leak directly to implicated executives.
-
Retaliation against whistleblowers: Unlawful occupational detriment after protected disclosures, including suspension, hostile disciplinary hearings, summary dismissal, and legal threats.
-
Information security failures: 169,000 unreviewed Active Directory accounts, unvetted third-party administrative access during outages, and low overall cybersecurity maturity.











