Compliance, with evidence attached.
Joint Standards 1 and 2 of 2024 make insurers answerable to the regulator for their outsourcing and for their suppliers’ cyber resilience. We build for both sides of that table — the insurer running due diligence, and the service provider being assessed.
Legacy outsourcing arrangements must comply by 1 December 2026.
Insurers must complete due diligence on their material service providers. Joint Standard 2 — cybersecurity and cyber resilience — has been in force since 1 June 2025.
compliance period ends
One standard, two seats.
Insurers & UMAs
You must complete due diligence on every material service provider — on the Standard’s own terms, with evidence the Prudential Authority expects, re-assessed on schedule. Questionnaires in spreadsheets don’t survive a regulator’s visit.
Service providers
If you administer policies, collect premiums, or touch claims, you are in scope. Your clients now answer to the FSCA and Prudential Authority for your cyber resilience — and questionnaires are how that lands on your desk, again and again.
A product for each seat.
Audit and Comply
Evidence-backed vendor compliance
Assess every service provider on Joint Standard 1’s own section 7.5 checklist. Kill questions flag non-compliance, weighted scoring places vendors in risk bands, evidence carries expiry reminders, and four-eyes review with an immutable audit trail keeps you ready for the day a regulator asks.
- Joint Standard 1 & 2 assessment packs
- Evidence tracking with expiry reminders
- Weighted risk scoring & kill questions
- Four-eyes review · immutable audit trail
- Network registry — vendors share assessments across insurers
Evidently
Run your ISO 27001 ISMS in one system of record
ISO/IEC 27001 is the answer that ends the questionnaires — and Evidently runs the whole certification, from scope to audit day. All 93 Annex A controls pre-seeded, controlled documents with immutable version history, and recurring tasks that capture timestamped, append-only evidence.
- Full ISO 27001:2022 framework, pre-seeded
- Statement of Applicability workspace
- Controlled documents · immutable versions
- Registers: assets, suppliers, obligations, incidents
- Calendar-based evidence — no year-end backlog
The two connect: a supplier’s Evidently ISMS feeds live assurance into their clients’ Audit and Comply assessments — evidence, not promises, flowing both ways. Both are free to start.
Not sure which seat is yours?
Some firms sit in both — assessed by insurers, assessing their own suppliers. Tell us where you sit and we’ll point you at the right starting line.
send a note ↗