Compliance & Governance
POPIA-ready, audit-ready, insurer-ready — without the consultancy bloat.
CIS Controls implementation, IT governance, risk assessments and POPIA compliance readiness.
Sound Familiar?
Governance work almost always begins with a question from outside the business that nobody inside it can answer:
- A customer's procurement team has sent a security questionnaire and you can't answer half of it.
- You know POPIA applies to you, but not what it actually means for your IT.
- Your cyber insurance renewal asks for things you have no way to evidence.
- Security decisions get made, but none of them are written down anywhere.
- Nobody owns IT governance — it happens when somebody has time.
- You've been told you need policies, without being told which ones or why.
What's included in our IT Compliance service
Everything you need from a modern it compliance partner — delivered by our engineering team.
- CIS Controls v8 implementation
- Security baselines and hardening
- IT governance frameworks
- Risk assessments and registers
- POPIA and compliance readiness
- Cyber insurance readiness reports
How we handle governance work
Most governance problems are not really about controls. They are about the absence of a record — decisions were taken, work was done, and none of it can be shown to anyone who asks.
Readiness and evidence, not certificates
We help you align technical controls to recognised frameworks and produce the documentation that evidences it. We are not a law firm and will not tell you that you are compliant — that determination sits with your legal advisors, and any IT provider claiming otherwise is overreaching.
Documentation that exists before you need it
The questionnaire, the insurance renewal and the audit all arrive with a deadline. Having the asset inventory, the access records and the control documentation already in place turns a fortnight of scrambling into an afternoon of retrieval.
Sized for your business
Governance frameworks are written for large organisations and adapted downwards, usually badly. A business of fifty people does not need a committee structure. It needs a handful of decisions recorded, reviewed periodically, and owned by someone.
The technical work and the paperwork in one place
Documenting a control you don't have is just a longer way of finding out you don't have it. Where an assessment identifies a gap, the same team can close it.
Frequently asked questions
Can you make us POPIA compliant?
No, and neither can any other IT provider. POPIA compliance is a legal determination that covers far more than technology — how you collect information, what you tell people, your contracts, your retention, your processes. What we can do is align the technical controls, help you evidence them, and support the parts of your obligations that are genuinely IT-related. Your legal advisor determines whether you are compliant. We would rather be clear about that boundary than sell you comfort.
What does IT governance mean for a business our size?
Something much smaller than the word suggests. Knowing what assets you have, who has access to what, which decisions were taken and why, what risks you have accepted deliberately, and reviewing that periodically. Not a committee, not a binder nobody opens — a short set of records that someone owns.
Customers keep sending us security questionnaires. Can you help?
Yes, and this is one of the most common reasons businesses come to us. The questionnaires are broadly similar because they draw on the same frameworks, so the underlying work carries across. Once the controls and documentation exist, answering the next one stops being a crisis.
How is this different from a CIS assessment?
A CIS assessment measures your technical controls against a specific framework and tells you what to fix. Governance is the layer above it — who decides, what gets recorded, what gets reviewed, and how you show a third party that any of it happened. Most businesses need both, and the assessment is usually the sensible starting point.
Do we actually need formal policies?
You need the ones you will use and can evidence. A policy nobody follows is worse than none, because it documents a standard you are visibly failing. We would rather help you produce a small number that reflect how the business genuinely operates than a library that exists to be pointed at.
Other IT services
Cybersecurity Services
ROI Technologies delivers end-to-end cybersecurity services including EDR/XDR endpoint protection, vulnerability scanning, network security and compliance. We support SentinelOne and Sophos Intercept X for endpoint protection.
Learn moreManaged IT Services
Fully managed IT support, proactive monitoring, helpdesk and device management for South African businesses that are serious about IT.
Learn moreProfessional Services & Consulting
IT strategy, technology roadmaps, IT health checks, project management and digital transformation.
Learn moreNeed IT Compliance?
Get a free assessment today and see how ROI Technologies can streamline your IT.
Book a Free Assessment