Joint Standards 1 and 2 of 2024 make your security posture your clients' regulatory problem. ISO/IEC 27001 is the answer that ends the questionnaires — and Evidently runs your whole certification, from scope to audit day, in one system of record.
Insurers must complete due diligence on their material service providers. Legacy arrangements must comply by 1 December 2026. If you administer policies, collect premiums or touch claims, that means you.
Your clients now answer to the FSCA and Prudential Authority for your cyber resilience. Questionnaires are how that lands on your desk — again and again.
One certification answers every client's diligence at once. Evidently is the system that gets you there and keeps you there.
The full framework — management clauses and all 93 Annex A controls — seeded and version-stamped. Amendment 1:2024 included.
Draft, approve, supersede. Immutable version history, review clocks, and every document linked to the controls it satisfies.
Your own likelihood and impact scales, treatment actions with owners, and a recorded acceptance for every residual risk — invalidated automatically if the score changes.
Work all 93 controls with justifications. The completeness view shows exactly what an auditor will ask about next.
Assets, suppliers, compliance obligations (POPIA and the Joint Standards pre-seeded), and incidents with the notify-without-undue-delay record built in.
Recurring tasks — backup checks, DR tests, access reviews — generate occurrences, land on a calendar, and capture append-only evidence when completed.
Records are timestamped, attributable and append-only. Corrections are new records. Your audit trail is the product, not an afterthought.
Link suppliers to their Audit and Comply assessments and their assurance status renders as live evidence against the supplier controls.
Register your workspace, set roles, and define your risk methodology — the platform enforces the right order.
Score risks against your own scales, choose treatments, record acceptance.
Decide and justify every control. Link the documents and risks that substantiate each one.
Recurring tasks capture evidence as your team completes them — no year-end scramble.
Every control answers with its chain: policy, risk, evidence, dates, names.
Evidently is the sibling of Audit and Comply, the vendor-assessment platform your insurer clients may already use. Run your ISMS in Evidently and your supplier controls answer with live assurance status — being assessed stops being a fire drill and starts being a read-out.
Free to start. Your first hour sets up scope, roles and risk methodology.
Create your workspaceOccasional product and deadline updates from Evidently and Audit and Comply. Unsubscribe any time.