Skip to content
Skip to main content

The regulatory model

Regulated maps software to obligations.

Regulated reads your system, code, configuration and UI, and maps it to the South African obligations that apply, with the evidence attached and the uncertain flagged for review. Where needed, we help you or your team design and build the solution.

What we do

Regulated connects stated controls to evidence in the system. We identify what the system does, what is missing, and what requires review. Where controls need to change, we help design and implement the solution.

Documented control

RetentionPersonal data is retained for as long as necessary
DeletionRecords are deleted when their purpose has ended
Control ownerData protection policy

The intended control, taken from policies, questionnaires and review input.

System evidence

FAIL
popia.retention_limit POPIA

No deletion condition is implemented for customer records.

models/customer.py · retention_days = null

PASS
fica.record_retention FICA

Identity records are retained for the required period.

models/customer.py · audit_log

REVIEW
popia × fica Conflicting requirements

The same field may be subject to both retention and deletion requirements. Human review is required.

Evidence linked to the system. Findings remain traceable and reproducible.

How it works

From your code to an implemented and verified control, with a human in the loop where necessary.

customer.py
class Customer:
retention_days = None

01

Inspect

Read the code, configuration, interfaces, schemas and documentation.

modelsroutesconfigflowsdocs

02

Map

Connect system evidence to the obligations and controls that apply.

PASS fica.records
FAIL popia.retention
REVIEW cross-border

03

Review

Resolve gaps, uncertainty and anything requiring human judgement.

remediation-plan.md
retention: deletion job
BUILD · tests + audit trail

04

Implement

Design and build the agreed controls with the technical team.

verification-report.pdf
retention control
PASS · evidence attached

05

Verify

Re-test the system and attach evidence to the updated findings.

Who it’s for

The same regulatory architecture, viewed from different responsibilities.

KYCLedgerAccess controlAudit logMonitoringSanctionsConsentRetentionDisclosureBreachCross-borderRG controls

For technical teams

Map requirements to services, data, controls and evidence. Find gaps before review, and show how the system meets its obligations.

KYCLedgerAccess controlAudit logMonitoringSanctionsConsentRetentionDisclosureBreachCross-borderRG controls

For compliance practices and consultants

Connect obligations to technical evidence, apply a consistent review method across clients, and identify what changes when the rules change.

See your system through the regulatory lens.

Start with a scope report, a readiness report, or a guided review.