Advertisement

Disciplinary Action

  • UWC charged three managers in the Work Study Office over ghost workers after last month’s revelations.

  • The three appeared at a disciplinary hearing and are going through the internal process.

    Advertisement

Payroll and Student Funds

  • Ghost workers were introduced into the Adapt-IT payroll system, an online system.

  • Over 85 ghost workers were paid.

  • Funds meant for students ran out.

  • Disadvantaged UWC students were not paid for over 3 months.

Data and Investigations

  • UWC data moved into the new system is still not in UWC’s custody.

  • The data is currently held by the vendor because UWC has not complied with contract requirements.

  • UWC commissioned two independent investigators to look into matters raised in last month’s report.

KPMG Report Covers

  • Governance collapse / executive capture: Control of the UWC Council and governance oversight by executive management, neutralizing independent accountability.

  • Auditor interference: External auditors restricted in scope and directed on what to audit, preventing independent forensic deep-dives.

  • Lack of IT audit function: No functional, independent internal audit department or IT audit capability to evaluate security and financial controls.

  • Unapproved policies: Policies drafted and repeatedly shelved without formal Council approval, while unauthorized payments and vendor renewals continued.

  • Concealment of cyber-attacks: Major cyber-attacks and compromised systems hidden since 2022, breaching statutory reporting duties.

  • Library data destruction: Severe infrastructure failure caused loss of research data; staff manually created placeholder records to hide the destruction from breach notifications.

  • Vendor fraud and overbilling: First Technology Western Cape allegedly added unauthorized markup and inflated invoices by about R1.8 million above the agreed baseline.

  • Telecom and VPN loss: A R20 million material financial loss from compromised student VPN credentials and systematic airtime abuse.

  • Payroll vulnerabilities: Adapt IT modules led to missing Work-Study funds and unverified “ghost workers” inserted into active payroll.

  • Compromised fraud hotline: KPMG FairCall lacked proper firewalling, causing confidential whistleblower reports to leak directly to implicated executives.

  • Retaliation against whistleblowers: Unlawful occupational detriment after protected disclosures, including suspension, hostile disciplinary hearings, summary dismissal, and legal threats.

  • Information security failures: 169,000 unreviewed Active Directory accounts, unvetted third-party administrative access during outages, and low overall cybersecurity maturity.

Advertisement