National Treasury blacklisting and your evidence problem
A private security industry body says Eskom referred 26 black-owned companies to National Treasury for blacklisting without due process. Eskom denies it, and says only one of the 53 suppliers it referred provides security services at all. The answer to an allegation like that is not a lawyer first. It is shift records, and most guarding firms cannot produce them quickly.
That is the part of this story no one will write about, and it is the part that decides outcomes. A company can be entirely honest and still lose a contract because it could not assemble the evidence inside the time it was given.
What is known, and what is not
The number 26 belongs to the accuser, not to Eskom, and that distinction matters. Daily Investor reports the accusation of unfair targeting, which comes from TAPSOSA, the Association of Private Security Owners of South Africa. "For some of those companies that have been referred by Eskom to the National Treasury to be blacklisted, it had nothing to do with them being fraudulent or corrupt," spokesperson Sindiswa Changuion said. Companies among the 26 have gone to court to compel disclosure of the reasoning behind the blacklistings.
Eskom did not comment to Daily Investor, but published a statement the same week, and it disputes both the process and the shape of the group. Eskom says 101 suppliers were restricted between February 2023 and 31 March 2026 through its Supplier Review Committee, and that 53 of those were referred to National Treasury. Of those 53, it says, only one provides security-related services. As at 20 August 2026, National Treasury had recorded 35 companies and 45 directors or owners on its restricted suppliers database off the back of those referrals.
Hold those two accounts side by side, because most coverage has collapsed them. TAPSOSA describes 26 black-owned companies referred without due process. Eskom describes 53 referrals of which one is a security firm. Nobody has reconciled those numbers publicly, and this piece will not do it either.
What is worth noticing is that a private security body took up the complaint. That is why the sector is reading this as its own story, even though Eskom's own count of security suppliers in the referrals is one.
Everything past that is unestablished at the time of writing: what notice a referred supplier receives, what right of reply exists and how long it runs, and how National Treasury decides. Anyone facing a referral needs the primary source and an attorney, in that order.
What can be said with confidence is what the evidence looks like, because that part does not change with the process. A guarding contract produces the same records everywhere in South Africa.
What a guarding contract actually rests on
An allegation about a security contract is almost always an allegation about one of three things. That guards were billed for and not posted. That the guards posted were not the guards contracted for, in grade, registration or number. Or that hours invoiced do not match hours worked.
Each of those is answered by documents that already exist:
- The roster. Who was scheduled, at which site, on which shift, at what grade.
- Site attendance. Who actually arrived, when they signed on and when they signed off.
- The occurrence book. The running record kept at the site, including incidents, visits and handovers.
- Supervisory visit records. Proof that a supervisor attended and what was found.
- Payroll. What each of those people was actually paid, for which hours.
- The invoice. The number the client received, and the line items behind it.
Answering the allegation means showing that those six agree with each other, for a named site, over a named period. Not one of them individually. All six, reconciled.
Where they live in a real security business
This is where it comes apart, and it has nothing to do with honesty.
The roster is a spreadsheet on the operations manager's laptop, overwritten each week, with no version from March. Site attendance is a book at the site, or a clocking device the client controls, or a WhatsApp group where a supervisor posts a photo at the start of a shift. The occurrence book is paper, in a drawer at the gate, and last year's is in storage somewhere.
Payroll sits in a system that has never seen the client's contract, so it knows the guard and the hours but not the site or the rate that was billed. The invoice was assembled at month end from a summary somebody typed, and the working that produced it was not kept.
Every one of those records is real. Together they cannot be reconciled by a person in a fortnight, and that is the whole exposure. The business is not missing evidence. It is missing the connection between six kinds of evidence it already holds.
Readiness comes before the accusation
The same point gets made about winning work, and it is the same underlying failure. Speaking at the 2026 SME Funding Summit, procurement specialist Lerato Sebata told business owners that readiness has to come before the opportunity. Sebata noted how often businesses lose out through plain administrative oversight, such as submitting an expired document when a current one exists.
"I think we underestimated the administration that goes into it," Sebata said.
Read that forward. If a firm cannot produce a current certificate on request, it will not produce eleven months of reconciled site attendance under pressure either. Losing a tender to a stale document is the cheap version of this failure. A referral is the expensive one.
What actually has to change
Not the guarding. The record keeping around it, and specifically the joins.
Every shift needs to produce one record that carries the site, the date, the guard, the grade, the hours and the contract it bills to, captured once at the time and not reassembled afterwards. Where a client controls the clocking system, the firm needs its own parallel record, because evidence you cannot retrieve without the other party's cooperation is not evidence you control.
The invoice then has to be produced from those records rather than typed alongside them. If an invoice line cannot be expanded into the shifts behind it, the invoice proves nothing.
This is joining systems a firm already runs, which is where Zorah starts. Connect the scheduling tool, the payroll package and the billing spreadsheet, so that a query about one site in March is a search rather than an excavation. Private security is a sector where that gap is unusually wide and unusually costly.
What to do on Monday
Pick one site and one month from last year. Give yourself two hours to produce the roster, the attendance record, the occurrence book pages and the payroll entries for it, and to show that they agree with the invoice you sent.
If two hours is not enough, you have found the thing that would decide an allegation against you, and you have found it while nobody is asking.
