Free tool · no signup
The 12-point POPIA & NCA readiness check.
Twelve questions on the controls a regulated capital intermediary must have. A scored report names your specific gaps — and the APEX control that closes each one.
0 / 12 answered
01 · NCA pre-screening
Are your minimum lending criteria enforced automatically at application stage — with no way to bypass them?
E.g. R1m minimum turnover and 3+ active supply clients at application.
02 · Credit assessment
Is every application credit-assessed with documented affordability and a reproducible risk score?
The NCA's affordability assessment is a substantive obligation, not a formality.
03 · Segregation of duties
Are large-deal approvals segregated from the person who originated the deal (maker-checker or committee)?
Loans above R1,000,000 should require committee sign-off.
04 · Information Officer
Is an Information Officer appointed and registered with the Information Regulator?
Required under POPIA for every responsible party.
05 · Consent records
Do you hold verifiable consent records for every data subject whose information you process?
Verifiable, not implied.
06 · Access logging
Can you prove who accessed each client's personal information, and when?
Field-level, not file-level.
07 · DSAR process
Do you have a tracked DSAR workflow with an SLA for the 21-business-day deadline?
Data subject access requests must be answered in 21 business days.
08 · Retention & deletion
Are retention schedules and data deletion enforced by the system — not by someone's memory?
Deletion is a POPIA condition.
09 · Audit trail
Does every action on a deal have an immutable, exportable trail?
Who changed what, from what to what, when.
10 · Anomaly detection
Are unusual access patterns flagged before they become a breach?
Proactive monitoring, not post-hoc discovery.
11 · Breach response
Do you have a documented breach response and notification process?
POPIA requires notification to the Regulator and data subjects.
12 · Training & awareness
Is POPIA/NCA training tracked for every staff member with access to client data?
Proof of training, not a workshop in the past.
No signup · your answers never leave your browser
Compliance isn't a page of promises. It's a system of enforced controls.
See the eight controls APEX enforces by default — NCA pre-screening, the weighted risk engine, field-level POPIA logging, committee approval and the 7-year audit trail.
