A global agenda with a local test
This week in Abu Dhabi, 119 countries adopted a five-year global roadmap on crime. For South African businesses, particularly SMMEs, the practical question is whether that global commitment eventually translates into better protection against the procurement fraud they encounter at home.
Justice and Constitutional Development Minister Mmamoloko Kubayi is leading South Africa’s delegation to the 15th United Nations Congress on Crime Prevention and Criminal Justice. The delegation includes departments across the JCPS (Justice, Crime Prevention and Security) cluster. On the opening day, member states adopted the Abu Dhabi Declaration by acclamation. More than 40 justice ministers and over 5,100 participants from government, civil society, academia and the private sector are attending.
The Declaration names cybercrime and fraud as priority threats. For a South African SMME owner, that is not theory. It is the email that arrives on a Saturday evening, bearing a department’s logo, inviting a quote.
Countries committed to making greater use of technology themselves, including by digitalizing justice systems and harnessing artificial intelligence in criminal justice responses. At the same time, the Declaration stresses that safeguards must accompany those changes, including human oversight, transparency, due process and data protection.
The emphasis on human oversight is particularly relevant to the security question about the growing use of artificial intelligence. In and of itself, AI does not remove the need for human judgement and accountability.
Fake tender scheme
The scheme is simple and it keeps working. A business receives a request for quotation that appears to come from a government department, a municipality or a large corporate buyer. The item is often specific and slightly odd, such as drill bits, laptops or cleaning chemicals. The deadline is tight.
The “buyer” then points the business to a named supplier for the goods. That supplier is also fake, and part of the same syndicate. The business pays the supplier, delivers nothing because nothing arrives, and never hears from the buyer again. News24 reported that fraudsters impersonate both the department and the supplier, and that businesses have lost millions this way.
SMMEs can be particularly exposed. Three factors help explain why:
- Need. Irregular cash flow can make a seemingly government order hard to ignore.
- Limited verification capacity. Smaller companies may not have dedicated procurement or compliance and fraud-risk functions to check a buyer.
- Credible cover. Transformation programmes make an approach to a black-, women- or youth-owned SMME look attractive. Anglo American, for example, specifically warns that SMMEs, B-BBEE companies, host-community suppliers and women- and youth-owned SMMEs are targeted in scams conducted in its name.
Departments issue warnings regularly. The DPME’s alert shows the classic tell: a domain ending with “dpme-gov.org” instead of the genuine “dpme.gov.za”. The warnings help, but they can reach businesses after the losses had occurred.
What Abu Dhabi says about this
The Declaration speaks directly to the environment in which this type of fraud operates. It warns of “crime as a service” and of criminals exploiting digital infrastructure, and it calls for action against cybercrime and fraud. The Middle East Online’s report on the Declaration also notes its concern with illicit networks exploiting cutting-edge technologies and generative AI to run fraud schemes.
What can a South African businesses do now?
The Declaration is an international policy framework agreed between states. Its value to a South African business owner will depend on how government implements it at home. As UNODC’s head, Monica Juma made the point: the impact of the Declaration will depend on implementation.
While its implementation will take years, verification by a South African business owner takes minutes and need no specialist skill. It is important to note that AI now makes documents more convincing than ever. But a cloned letterhead or a false domain need no specialist skill. Before responding to any tender or RFQ, a business should check five things:
- The advert. Search the opportunity on the National Treasury eTender Portal. If you cannot independently trace the opportunity through the relevant official procurement channel, stop and verify it directly with the institution before responding.
- The domain. Check whether the sender uses the institution’s genuine official domain. For South African national and provincial government departments, official addresses generally use gov.za. Look for additional words, hyphens, misspellings or different domain endings.
- The buyer, independently. Call the department’s switchboard using a number from its official website, never the number in the email.
- The money. An upfront “registration fee”, “tender document fee” or payment to a nominated supplier should stop the process until independently verified.
- The supplier. If you must buy stock to fulfil an order, vet the supplier yourself. Check its CIPC registration, physical address and trading history.
From declaration to delivery
The Abu Dhabi Declaration provides a global framework. The test for South Africa will be what follows from it. It will be whether a small supplier in Rustenburg or Middleburg is less likely to lose its working capital to a fake invitation in 2027 than in 2026.
Business has a role in meeting that test. Companies that verify before they quote, report what they see, and share intelligence on fraud patterns make the Declaration’s public-private cooperation real. Government can strengthen that effort by making reporting easier, improving information sharing and making enforcement visible.
GI Advisory is a member in good standing of the Press Council of South Africa. GI Advisory News operates as its editorial wing. We work with organisations in the broader corporate intelligence field.

