Joint Standard 1 of 2024 · Outsourcing by Insurers

Legacy outsourcing arrangements must comply by 1 December 2026.

Audit and Comply is the South African platform for Joint Standard 1 due diligence: assess every service provider on the Standard's own section 7.5 checklist, keep the evidence the Prudential Authority expects, and re-assess on schedule — with an immutable audit trail for the day a regulator asks.

Free to start — assess your first vendors on the built-in Joint Standard 1 pack today. New: Joint Standard 2 cybersecurity pack — JS2 has been in force since 1 June 2025.

Why now

The Standard is in force.
The transition period is not.

Joint Standard 1 of 2024 (Outsourcing by Insurers) was published by the Prudential Authority and FSCA on 17 May 2024 and came into operation on 1 December 2024. Arrangements that existed before then get 24 months — or until first renewal, whichever comes first — to comply. That period ends on 1 December 2026.

s 5.3

Due diligence on every outsourced activity

Before entering an arrangement — and the assessment must be appropriate to what is being outsourced.

s 7.5

Eight things you must establish about the provider

Governance, risk management and controls; legal compliance; operational capability; financial resources; contingency plans; fit-and-proper key persons. Our Insurance Outsourcing pack mirrors this section, question for question.

s 10.4

Re-assess regularly — not once

Material-function providers must be assessed on the same dimensions on an ongoing basis. Recertification scheduling and evidence-expiry tracking keep the calendar for you.

See it

Sixty seconds, both sides of the platform.

Real product screens against a five-year demonstration dataset: the dashboard, a failed mandatory question no score can hide, evidence review, the supplier portal, and a policy the platform wrote. No audio — captions carry it.

New pack · Joint Standard 2 of 2024

JS1 has a deadline.
JS2 is already in force.

Joint Standard 2 of 2024 (Cybersecurity and Cyber Resilience Requirements) took effect on 1 June 2025 — and it reaches past your own perimeter: information assets managed by third parties must be classified and protected to the same standard, providers with access to your systems must face the same access restrictions as your staff, and if you rely on a provider's control testing, you must be satisfied it matches the risk. Our Cybersecurity & Cyber Resilience pack turns the Standard into an assessment, paragraph by paragraph.

ss 4–6

Governance, strategy & framework

Board-owned cyber risk, a resourced security function, and a governing-body-approved strategy and framework reviewed annually. No approved framework is a kill question — Non-Compliant, whatever else is answered.

s 7

Identify · Protect · Detect · Respond · Recover

Asset inventories and classification, access and data controls, continuous monitoring, tested incident response, backups stored offline, pen testing and simulation exercises — 47 evidence-backed questions across the fundamentals.

ss 8–9

Hygiene & material-incident notification

MFA on critical functions, privileged accounts and internet-facing sensitive apps is a hard requirement — we treat it as one. Plus patching, hardening, malware defence, and the process to notify the responsible authority of material incidents.

The product

A questionnaire is easy to pass.
An audit isn't.

A spreadsheet of self-attested yeses will not survive a Prudential Authority review. Audit and Comply makes every "yes" earn its points — with evidence, review, and consequences when the answer is wrong.

Kill questions

Mandatory requirements that end the debate

A vendor that won’t sign a data-processing agreement, trains models on your data, or can’t commit to breach notification is flagged Non-Compliant instantly — no matter how good the rest of the answers look.

Evidence, not promises

Every claim backed by a document

Certificates, DPAs, pen-test attestations and insurance are uploaded per question, reviewed per assessment, and tracked for expiry with 60/30/7-day reminders. An expired mandatory document degrades the vendor’s status automatically.

Automatic scoring

Scored the moment it’s submitted

Weighted sections, evidence-gated points, and risk bands from Low to Critical. Inherent risk from the vendor’s tier, residual risk from their answers — both on the record.

Review workflow

Four-eyes where it matters

Reviewers verify evidence, raise clarification threads, and override scores only with a written justification. High-risk vendors need a second compliance manager to confirm any outcome.

Remediation & risk acceptance

Findings that actually close

Every gap becomes a finding with an owner and a due date. Vendors respond with corrective evidence in the portal. Risk acceptances need a named senior owner — and reopen automatically when they expire.

Audit trail

Reconstruct anything, years later

Every answer, override, verdict and outcome is logged append-only — immutable to every role, administrators included. One click exports a regulator-ready assessment report.

Company Vault

Your policies, governed like evidence

Store policy documents with a full lifecycle — draft, approval sign-off, versioning — plus review-cycle reminders and recurring obligations like an annual pen test, each completed as an evidence-backed checklist the platform drafts for you.

NEW · Policy Studio

Missing a policy? The platform writes it

Asked for an incident response plan you don’t have? Generate it — drafted for your business from your company profile, with a first-30-days implementation guide and its recurring duties installed as tracked obligations. You edit and approve; the signed-off Word version files itself as attachable evidence.

Free gap check

Find out where you stand — free

Run the lite self-assessment for any standard and get the full gap report: every failing control, classified into the policy, practice or recurring duty that fixes it. Seeing the fix is free; one click to generate it is Pro.

Non-responsive vendors

Silence becomes a recorded decision

Automatic reminders before the deadline and weekly chases after it — every send logged. When a vendor never answers, close the assessment as unresponsive: the audit entry cites the documented attempts and the vendor is rated non-compliant.

One workspace

Both sides of compliance, one account

Respond to the assessments your customers send and run due diligence on your own providers from the same workspace. No second login, no switching — your role in the chain is a capability, not a separate product.

How it works

From onboarding to recertification, one lifecycle.

Every transition logged with who, what and when — and the schedule keeps itself: recertification per risk tier, evidence expiry watched continuously in between.

STEP 01

Register the vendor

Name, tier, data types accessed — or import your whole vendor book from CSV.

STEP 02

Issue the assessment

The right questionnaire for the vendor’s category and risk tier, delivered with a secure invitation.

STEP 03

Vendor completes it

Section by section with plain-language help, saving as they go, evidence attached where it’s mandatory.

STEP 04

Scored on submission

Instant score, risk rating and kill-question verdict. Non-compliance is visible the second it exists.

STEP 05

Outcome & remediation

Approve, approve with conditions, or send findings back for remediation — with recertification scheduled automatically.

The network

Underwriting managers sit in the middle.
So does the platform.

A UMA is assessed by its insurers and must assess its own providers — on Audit and Comply that is literally one account: every company is a single workspace that responds and assesses by capability, not by which door it signed up through. Suppliers complete a standard framework pack once, share it with every company that assesses them, and earn a badge on the private network registry. Assessors accept the shared assessment instead of sending yet another spreadsheet — and keep an immutable copy of exactly what they relied on.

Pack · Insurance Outsourcing (JS1 s7.5) Pack · Cybersecurity & Cyber Resilience (JS2) Pack · POPIA Privacy (Act 4 of 2013) Pack · Information Security Baseline Pack · B-BBEE certificate capture New · Policy Studio — the platform writes your missing policies → Free forever · Responding to assessments ZAR billing · Local support Four plans · Compare side by side →
Built for South African responsible parties

POPIA isn't a section of the questionnaire.
It's the spine of it.

Every question is tagged to the statute it serves — operator agreements, breach notification, cross-border transfers, special personal information — with GDPR and ISO 27001 mappings alongside, so one assessment answers three frameworks.

POPIA ss 20–21 · Operator agreements & safeguardsPOPIA s 22 · Breach notification dutiesPOPIA s 72 · Cross-border transfersPOPIA ss 23–25 · Data subject rightsPOPIA ss 26–35 · Special personal informationPOPIA ss 55–57 · Information Officers & prior authorisation

1 December is a date. Your outsourcing register is the evidence.

Register your company, load your provider book, and issue Joint Standard 1 due-diligence assessments this week.

Create your company account

or start with the JS1 s7.5 checklist →

One email a month until 1 December 2026, then it stops. Double opt-in, unsubscribe in one click — we practise the POPIA we preach.