For South African financial-services suppliers

Your insurer clients are auditing you. Evidently is how you pass.

Joint Standards 1 and 2 of 2024 make your security posture your clients' regulatory problem. ISO/IEC 27001 is the answer that ends the questionnaires — and Evidently runs your whole certification, from scope to audit day, in one system of record.

Why now

The due-diligence wave has a date on it.

Joint Standard 1 of 2024 — outsourcing

Insurers must complete due diligence on their material service providers. Legacy arrangements must comply by 1 December 2026. If you administer policies, collect premiums or touch claims, that means you.

Joint Standard 2 of 2024 — cybersecurity

Your clients now answer to the FSCA and Prudential Authority for your cyber resilience. Questionnaires are how that lands on your desk — again and again.

ISO/IEC 27001 ends the loop

One certification answers every client's diligence at once. Evidently is the system that gets you there and keeps you there.

What's inside

Everything your certification needs. Nothing it doesn't.

CLAUSES 4-10 + ANNEX A

ISO 27001:2022 built in

The full framework — management clauses and all 93 Annex A controls — seeded and version-stamped. Amendment 1:2024 included.

CLAUSE 7.5

Controlled documents

Draft, approve, supersede. Immutable version history, review clocks, and every document linked to the controls it satisfies.

CLAUSES 6.1, 8.2-8.3

Risk, done properly

Your own likelihood and impact scales, treatment actions with owners, and a recorded acceptance for every residual risk — invalidated automatically if the score changes.

CLAUSE 6.1.3(D)

Statement of Applicability

Work all 93 controls with justifications. The completeness view shows exactly what an auditor will ask about next.

ANNEX A REGISTERS

Registers that stay current

Assets, suppliers, compliance obligations (POPIA and the Joint Standards pre-seeded), and incidents with the notify-without-undue-delay record built in.

THE ENGINE

Evidence on a schedule

Recurring tasks — backup checks, DR tests, access reviews — generate occurrences, land on a calendar, and capture append-only evidence when completed.

NO BACKFILL

Evidence you can defend

Records are timestamped, attributable and append-only. Corrections are new records. Your audit trail is the product, not an afterthought.

A.5.19-A.5.22

Live supplier assurance

Link suppliers to their Audit and Comply assessments and their assurance status renders as live evidence against the supplier controls.

How it works

Scope to certificate, one system.

Scope your ISMS

Register your workspace, set roles, and define your risk methodology — the platform enforces the right order.

Assess your risks

Score risks against your own scales, choose treatments, record acceptance.

Work the SoA

Decide and justify every control. Link the documents and risks that substantiate each one.

Operate on a calendar

Recurring tasks capture evidence as your team completes them — no year-end scramble.

Walk into the audit ready

Every control answers with its chain: policy, risk, evidence, dates, names.

The loop

Already being assessed on Audit and Comply?

Evidently is the sibling of Audit and Comply, the vendor-assessment platform your insurer clients may already use. Run your ISMS in Evidently and your supplier controls answer with live assurance status — being assessed stops being a fire drill and starts being a read-out.

Start before your client's next questionnaire.

Free to start. Your first hour sets up scope, roles and risk methodology.

Create your workspace

Occasional product and deadline updates from Evidently and Audit and Comply. Unsubscribe any time.