Joint Standard 1 took effect on 15 November 2024. Joint Standard 2 followed on 1 June 2025. For the more than six thousand financial services providers authorised by the FSCA, the question of whether to comply was settled by those dates, and what remains is the considerably harder question of how, particularly for the substantial majority of providers who have no internal governance, risk and compliance function and no realistic prospect of building one.
The options available until now have been unsatisfactory in predictable ways. Hire a compliance officer, at a total cost of employment that most small and mid size providers cannot justify, and who will in any case typically cover conduct rather than information security. Engage a consultant hourly, receive a policy suite, and then discover that the committee facilitation, the log reviews, the annual audit and the technical implementation all remain yours to manage. Or do nothing, and hope.
Siyaxhuma IT Governance is built for the space those options leave open.
What it is
A fixed monthly retainer covering the full lifecycle of information security compliance for FSCA regulated providers, from the initial gap analysis through to ongoing governance and annual audit. Everything is inside the monthly fee. There is no separate implementation or onboarding charge, which means the substantial build work at the start of the relationship is absorbed rather than invoiced.
The retainer is priced by employee band, so a ten person advisory practice and a hundred and fifty person administrator pay according to the scale of what their environment actually requires.
What the retainer covers
- An initial policy audit and gap analysis, scoped to your specific regulatory footprint and benchmarked against Joint Standard 1, Joint Standard 2, FAIS and FICA, with every finding categorised so that you can see exactly where you stand before anything is built.
- The build or rectification of every missing or outdated policy in your information security suite, document numbered, versioned, formatted and branded to your business.
- All required risk registers and log registers, built, version controlled and then maintained rather than handed over.
- Information Security Committee establishment, including the terms of reference, the membership roster and the charter.
- Quarterly Information Security Committee meeting facilitation, with preparation, agenda, minutes and action tracking.
- Cybersecurity awareness training for every member of staff through a learning management system, licensed per employee, with tracking and reporting on completion.
- Quarterly log storage and structured review, so that the evidence exists in the form a reviewer expects to find it.
- A quarterly compliance report written for your board or governance committee.
- An annual compliance audit with a formal findings report.
- IT control implementation facilitation, which is the component that distinguishes this product and which is described in full below.
The part that makes this different
Most compliance engagements in this market end when the policy is signed. This one does not, and the reason is the tenth item on that list.
Every policy in an information security suite creates technical obligations. The access control policy implies a configuration. The remote access policy implies an authentication standard. The backup policy implies a tested restoration cycle. If nobody verifies that those configurations actually exist in the environment, the business holds a document describing a control regime it may not have, which is a weaker position than having no document at all, because the gap between the two is now written down.
We work directly with your IT provider, or deliver it ourselves where we hold that function, to implement or verify each technical control the policy suite requires. That covers firewall configuration, multi factor authentication rollout, endpoint detection and response deployment, email authentication including SPF, DKIM and DMARC, patching, privileged access management, cloud security configuration, backup restoration testing, mobile device management and encryption.
The output is a signed IT Control Evidence Report documenting the verified status of every required control, produced at onboarding and refreshed thereafter, with a spot check every quarter. It is the document that turns a policy suite into a defensible compliance position.
We are able to do this because Siyaxhuma is both a compliance provider and an IT provider. The gap between the policy and the technical reality is closed by one team holding both sides, rather than by two firms attempting to coordinate across a commercial boundary that neither of them owns.
What you are actually buying
It is worth stating plainly, because the distinction determines whether the money is well spent. You are not buying a policy suite. Policy suites are available from a number of capable firms and they are a commodity, in the sense that any competent consultant can produce a good one.
You are buying a compliance function. Something that runs continuously, produces evidence on a defined cycle, sits in your committee meetings, reviews your logs, tests your controls, reports to your board and turns up with an audit at the end of the year. The artefacts are the visible part. The function is the thing.
What it is not
Two boundaries are worth being explicit about.
Siyaxhuma is not a registered Compliance Practice under FAIS and cannot be appointed as your external compliance officer. This product addresses information security and IT governance compliance. Your conduct compliance arrangements remain separate and we will say so in any conversation where the distinction matters.
It is also not a certification. We do not issue one and nobody in this market can. What the engagement produces is a documented, evidenced and continuously maintained compliance position that stands up to inspection.
The engagement begins with a gap analysis, which produces a structured findings report showing exactly where your current position sits against Joint Standard 1 and Joint Standard 2. Get in touch to arrange one.