IT Compliance Advisory: Evidence Ready
An auditor or the Information Regulator won't ask for your policy, they'll ask for the dated log, sign-off or access review behind it. Most Johannesburg SMEs can produce the first, not the second. We map your business against the one framework that applies, POPIA first, ISO 27001 where a tender demands it, then build a live gap register: every line owned, dated and closed before the audit.
Where A Policy-Only Approach Fails The Real Audit
IT compliance advisory services exist because a policy document and an evidence trail are not the same thing. Most SA businesses can produce the policy; almost none can produce the dated proof behind it, and that gap is exactly where a real audit or an Information Regulator request finds them out.
No Information Officer
POPIA requires every business processing personal information to appoint and register an Information Officer with the Information Regulator. Most SMEs we assess have never made the appointment.
No Breach Response Plan
A breach process only proves itself once it has been tested, not once it has been written. We regularly find a document describing what should happen, with no escalation path, notification timeline, or drills run against it.
No Data Processing Register
POPIA expects a business to know what personal information it holds, where it sits, and why it is processed. Without a register mapping that out, there is no way to answer a regulator request, or a client audit, with anything more than a guess.
No Evidence Trail Behind The Policy
A policy folder proves intent, not practice. What an auditor actually asks for on the day are access reviews, incident logs, and sign off records dated against real events, and that dated trail is usually the whole gap.
Policy vs Technical Control
A governance policy is not the same as the control that enforces it. Email authentication and DMARC controls are configured and monitored as a technical service; this advisory work covers the framework those controls have to sit inside.
Most businesses don't lose control through one bad decision, they lose it gradually. A vendor recommends the tool they resell. An internal team defends the system they already built. Nobody's sitting outside those incentives asking whether it's actually the right call.
Advisory control means bringing in that outside view, someone with no stake in who wins, so the recommendation is judged on what's right for the business, not on who benefits from the answer.
What's Inside A Compliance Gap Assessment
This work sits inside our wider IT consulting services at Executive Solutions, run as its own scoped engagement with its own deliverable: a gap register you can hand to an auditor, not a slide deck.
Framework Selection
We confirm which framework actually applies: POPIA by default, plus ISO 27001, PCI DSS, King IV or a sector rule such as FSCA or HPCSA where a tender or regulator requires it.
Current Clause Mapping
Current policies, controls and existing evidence get checked against that framework’s specific clauses, not a generic checklist bought off a template site.
Live Gap Register Building
Every shortfall goes into a live register with an owner, the evidence still needed, and a target date, so nothing sits as an unassigned paragraph.
Evidence Preparation
We prepare the artefacts an auditor asks for on the day: incident logs, access reviews, data processing records and sign off trails.
MOCK COMPLIANCE REVIEW
Keeping The Register Current
ISO 27001 runs on annual surveillance audits and POPIA is an ongoing obligation, so the register is built to stay live.
The Proof Behind Every Gap Register We Hand Over
A gap register is only worth trusting if you can see what one actually looks like before you commission it. These are the artefacts we can show on request, not a description of a process.
Gap Sample
Enforced on every tenant we manage, executives and administrators included. It’s not optional, because the accounts attackers go for first are the ones with the widest access.
Mapping Doc
The framework mapping document shows the specific clauses covered against the chosen standard, not a marketing summary of what that framework generally requires.
Audit Result
A real past client outcome, audit passed, certification achieved, or the number of gaps closed before the actual audit ran, as the result the process was built to produce.
Accreditation
The named accreditations and certifications our compliance advisory team holds against the frameworks it assesses for, ISO 27001 lead auditor, POPIA practitioner, so you can verify who is doing the assessing.
What Actually Sets The Price Of Compliance Advisory
Every quote starts with the framework question. POPIA applies to nearly every South African business by default, while ISO 27001, PCI DSS or sector rules only apply if a client, tender or regulator actually demands them. From there, price moves with how many gaps the mapping finds, how urgent the deadline is, and whether the register gets built once or kept live and reviewed every year after.
01 Which Framework Actually Applies
02 How Many Gaps And Their Risk
03 Your Tender Or Audit Deadline
04 Fixed Fee Or Ongoing Retainer
Who this is for
This fits a Johannesburg SME facing a tender that names ISO 27001, a POPIA obligation nobody has mapped to a gap register, or a client audit request the current policy folder cannot survive. It also fits a business with no appointed Information Officer or data processing register. A broader, multi-year technology roadmap belongs with our Virtual CIO service instead.
How it works
frequently asked questions
Does this cover POPIA specifically, or is that handled as a separate service?
POPIA is where almost every engagement starts, because it applies to any business holding personal information whether that business has addressed it or not. Once the register shows a technical control is missing, such as email authentication, TrustLock implements it separately from this advisory work.
Who closes the gaps between the assessment and the real audit, us or ES?
That depends on the scope agreed upfront. Some clients close every gap themselves from the register on their own timeline, others ask us to own specific items through to the evidence that proves each one closed.
What evidence will we personally need to produce, and how long does gathering it take?
You will need to pull existing policies, access logs, past incident records and any data processing registers you already hold. Most clients underestimate this: gathering it usually takes longer than the assessment itself, which is exactly why we start with a document request list on day one, not on day ten.
Is this a one off report or ongoing support as the framework changes?
The assessment produces a gap register, not a report that gets filed once. POPIA compliance is an ongoing obligation and ISO 27001 certification requires annual surveillance audits, so the register needs an owner keeping it current after we hand it over.
Your Compliance Gap Register Should Prove Readiness, Not Just Describe It
Get the evidence trail started.