Maker-checker
Key approvals follow delegated authority, with the actor recorded on the case.
Trust Centre
Governance, security, audit, resilience and privacy are mapped to what the platform does — and to the evidence funders and auditors can review.
Control Outcomes
Key approvals follow delegated authority, with the actor recorded on the case.
Traffic uses TLS/HTTPS. Records are encrypted at rest.
Rating, pricing and committee outcomes stay linked to the facility.
Permissions follow role and mandate — credit, operations, collections and client.
Control Matrix
Filter by domain. Each row shows the objective, how it is implemented, the evidence it produces, and how often it is reviewed.
| Domain | Control objective | How it is implemented | Evidence | Review |
|---|---|---|---|---|
| Governance | Separate duties across the credit lifecycle. | Role-based access and stage ownership. | Role mapping, permissions and event history. | On user change |
| Governance | Require maker-checker on key approvals. | Workflow routing and delegated authority. | Approval sequence and actor trail. | Per decision |
| Governance | Keep accountable case ownership. | Case linkage for operational records. | Case register and linked communications. | Continuous |
| Security | Protect data in transit. | HTTPS/TLS required. | Environment configuration and access policy. | Continuous |
| Security | Limit privileged operational access. | Restricted administrative accounts. | Admin account review and access history. | Monthly |
| Security | Block unauthorised actions. | Signed-in sessions with a permission check on each action. | Access logs and denied-action records. | Continuous |
| Audit | Reconstruct credit decisions end to end. | Workflow events, rating outputs and decision records. | Application audit trail and decision packs. | Per decision |
| Audit | Track client communications and follow-through. | Notification stream and task assignment. | Notification ledger and task history. | Daily |
| Audit | Preserve repayment traceability. | Schedule, allocation and servicing records. | Ledger and allocation history. | Per transaction |
| Resilience | Recover from data disruption. | Routine backup and restore. | Backup logs and restore checks. | Daily |
| Resilience | Keep production operations stable. | Monitoring and incident handling. | Incident records and review notes. | Continuous |
| Resilience | Reduce change-related release risk. | Version-controlled change and review. | Commit history and release trail. | Per release |
| Privacy | Capture only the fields needed to operate the book. | Structured intake and role-scoped access. | Schema and permission reviews. | Quarterly |
| Privacy | Keep user-level accountability for data handling. | User-linked, timestamped workflow events. | Event logs with actor and time. | Continuous |
| Privacy | Hold a governance-ready privacy posture. | POPIA-conscious access design and control reviews. | Internal control review records. | Quarterly |
Operating Rhythm
Evidence
Approval and decision history on the facility.
Role and permission mappings.
Repayment and allocation records.
Task and notification history.
Next Step
We can take your risk, audit or technology team through the matrix with a live platform session.
Request a trust review