Audit and Comply is the South African platform for Joint Standard 1 due diligence: assess every service provider on the Standard's own section 7.5 checklist, keep the evidence the Prudential Authority expects, and re-assess on schedule — with an immutable audit trail for the day a regulator asks.
Free to start — assess your first vendors on the built-in Joint Standard 1 pack today. New: Joint Standard 2 cybersecurity pack — JS2 has been in force since 1 June 2025.
Joint Standard 1 of 2024 (Outsourcing by Insurers) was published by the Prudential Authority and FSCA on 17 May 2024 and came into operation on 1 December 2024. Arrangements that existed before then get 24 months — or until first renewal, whichever comes first — to comply. That period ends on 1 December 2026.
Before entering an arrangement — and the assessment must be appropriate to what is being outsourced.
Governance, risk management and controls; legal compliance; operational capability; financial resources; contingency plans; fit-and-proper key persons. Our Insurance Outsourcing pack mirrors this section, question for question.
Material-function providers must be assessed on the same dimensions on an ongoing basis. Recertification scheduling and evidence-expiry tracking keep the calendar for you.
Real product screens against a five-year demonstration dataset: the dashboard, a failed mandatory question no score can hide, evidence review, the supplier portal, and a policy the platform wrote. No audio — captions carry it.
Joint Standard 2 of 2024 (Cybersecurity and Cyber Resilience Requirements) took effect on 1 June 2025 — and it reaches past your own perimeter: information assets managed by third parties must be classified and protected to the same standard, providers with access to your systems must face the same access restrictions as your staff, and if you rely on a provider's control testing, you must be satisfied it matches the risk. Our Cybersecurity & Cyber Resilience pack turns the Standard into an assessment, paragraph by paragraph.
Board-owned cyber risk, a resourced security function, and a governing-body-approved strategy and framework reviewed annually. No approved framework is a kill question — Non-Compliant, whatever else is answered.
Asset inventories and classification, access and data controls, continuous monitoring, tested incident response, backups stored offline, pen testing and simulation exercises — 47 evidence-backed questions across the fundamentals.
MFA on critical functions, privileged accounts and internet-facing sensitive apps is a hard requirement — we treat it as one. Plus patching, hardening, malware defence, and the process to notify the responsible authority of material incidents.
A spreadsheet of self-attested yeses will not survive a Prudential Authority review. Audit and Comply makes every "yes" earn its points — with evidence, review, and consequences when the answer is wrong.
A vendor that won’t sign a data-processing agreement, trains models on your data, or can’t commit to breach notification is flagged Non-Compliant instantly — no matter how good the rest of the answers look.
Certificates, DPAs, pen-test attestations and insurance are uploaded per question, reviewed per assessment, and tracked for expiry with 60/30/7-day reminders. An expired mandatory document degrades the vendor’s status automatically.
Weighted sections, evidence-gated points, and risk bands from Low to Critical. Inherent risk from the vendor’s tier, residual risk from their answers — both on the record.
Reviewers verify evidence, raise clarification threads, and override scores only with a written justification. High-risk vendors need a second compliance manager to confirm any outcome.
Every gap becomes a finding with an owner and a due date. Vendors respond with corrective evidence in the portal. Risk acceptances need a named senior owner — and reopen automatically when they expire.
Every answer, override, verdict and outcome is logged append-only — immutable to every role, administrators included. One click exports a regulator-ready assessment report.
Store policy documents with a full lifecycle — draft, approval sign-off, versioning — plus review-cycle reminders and recurring obligations like an annual pen test, each completed as an evidence-backed checklist the platform drafts for you.
Asked for an incident response plan you don’t have? Generate it — drafted for your business from your company profile, with a first-30-days implementation guide and its recurring duties installed as tracked obligations. You edit and approve; the signed-off Word version files itself as attachable evidence.
Run the lite self-assessment for any standard and get the full gap report: every failing control, classified into the policy, practice or recurring duty that fixes it. Seeing the fix is free; one click to generate it is Pro.
Automatic reminders before the deadline and weekly chases after it — every send logged. When a vendor never answers, close the assessment as unresponsive: the audit entry cites the documented attempts and the vendor is rated non-compliant.
Respond to the assessments your customers send and run due diligence on your own providers from the same workspace. No second login, no switching — your role in the chain is a capability, not a separate product.
Every transition logged with who, what and when — and the schedule keeps itself: recertification per risk tier, evidence expiry watched continuously in between.
Name, tier, data types accessed — or import your whole vendor book from CSV.
The right questionnaire for the vendor’s category and risk tier, delivered with a secure invitation.
Section by section with plain-language help, saving as they go, evidence attached where it’s mandatory.
Instant score, risk rating and kill-question verdict. Non-compliance is visible the second it exists.
Approve, approve with conditions, or send findings back for remediation — with recertification scheduled automatically.
A UMA is assessed by its insurers and must assess its own providers — on Audit and Comply that is literally one account: every company is a single workspace that responds and assesses by capability, not by which door it signed up through. Suppliers complete a standard framework pack once, share it with every company that assesses them, and earn a badge on the private network registry. Assessors accept the shared assessment instead of sending yet another spreadsheet — and keep an immutable copy of exactly what they relied on.
Every question is tagged to the statute it serves — operator agreements, breach notification, cross-border transfers, special personal information — with GDPR and ISO 27001 mappings alongside, so one assessment answers three frameworks.
Register your company, load your provider book, and issue Joint Standard 1 due-diligence assessments this week.
Create your company accountor start with the JS1 s7.5 checklist →
One email a month until 1 December 2026, then it stops. Double opt-in, unsubscribe in one click — we practise the POPIA we preach.