Member-first. Governance-led. Secure by design.Enterprise preview EN
Compliance & assurance

Controls, evidence and responsible operations

Asonge Sonke treats compliance as an operating discipline spanning financial integrity, member protection, privacy, security, responsible credit, technology governance and operational resilience.

Assurance statement: This page describes control objectives, implemented capabilities and readiness/alignment efforts. It does not by itself represent independent certification, regulator registration, legal advice or a guarantee that every framework applies to every service.

Enterprise control framework

Compliance domains built into the operating model

Detailed evidence is restricted to authorised governance, risk, compliance and audit reviewers. Applicability depends on the service, transaction type, jurisdiction and role performed by Asonge Sonke.

FICA / KYC / AML

FICA, KYC & AML controls

Identity verification, beneficial-owner checks, risk classification, PEP/sanctions screening and evidence workflows support applicable FICA and AML/CFT obligations.

NCA / NCR

Responsible credit

Loan workflows support affordability and eligibility checks, controlled approval, repayment evidence, interest review and responsible-credit controls where the National Credit Act applies.

IFRS / IFRS 9

Financial reporting integrity

Reconciliation, double-entry evidence, traceable transactions, impairment and interest controls support reliable accounting and IFRS/IFRS 9-oriented reporting processes.

ISO 27001 / SOC 2

Information security

Role-based access, MFA, encryption, audit evidence, vulnerability controls and security monitoring support an ISO/IEC 27001 and SOC 2-oriented control environment.

PCI DSS

Payment-card security

Payment-card handling is designed to minimise cardholder-data exposure and support PCI DSS control requirements where card data enters system scope.

ISO 9001

Quality governance

Documented change control, production gates, incident management, corrective actions and evidence reviews support ISO 9001-oriented quality practices.

ISO 42001

AI governance

AI-assisted features operate with data minimisation, human review, restricted actions and auditable approval boundaries intended to support ISO/IEC 42001-aligned governance.

ECTA

Electronic transactions

Electronic records, notices, consent and online transaction processes are structured with South Africa’s electronic-transactions framework in mind.

Consumer protection

Consumer & member protection

Clear records, complaint channels, consent controls, accessible statements and governed service changes support fair and transparent member treatment.

HIPAA — if applicable

Conditional health-information scope

HIPAA safeguards are relevant only if Asonge Sonke acts in a covered-entity or business-associate context involving regulated electronic health information.

WCAG

Accessibility

Responsive interaction, keyboard-friendly controls, semantic structure and readable content support WCAG-oriented accessibility improvement.

BCP / DR

Business continuity & resilience

Backup, restore, recovery testing, incident readiness and disaster-recovery evidence support operational resilience and continuity planning.

Legal information

Privacy and service terms

Read how personal information is handled and the rules governing use of the Asonge Sonke digital service.

Ready to access your member services?

Create your member account or sign in to continue securely.

RegisterLogin