From policy to control
Most IT policies say what should happen. An auditor needs to know who does what, how often, and what evidence it leaves. Rewriting our policies into that shape changed more than their format.
What we have learned building and running AI, data and delivery work for ourselves and for our clients across South Africa, Mauritius and the wider continent. Written by the people who did the work.
Companies with one foot in Mauritius and one in South Africa get described as having two offices. The useful description is what each base does for an initiative in another African country, and what the partner on the ground gets back.
Read it →Most IT policies say what should happen. An auditor needs to know who does what, how often, and what evidence it leaves. Rewriting our policies into that shape changed more than their format.
Last of three. A process can be dramatically faster while the business barely moves. The smaller number was far less impressive and much more useful.
A control document drafted from good intentions describes a better-run organisation than the real one. The review that matters most is the one done by the people who operate the systems.
For many automotive suppliers a TISAX label is a condition of trade. What a readiness baseline found, and why the gap is usually between a control being designed and a control being switched on.
Second of three. We compared what we had produced against what anyone had actually asked for. A large share of it could not be matched to a question, and that changed how we choose what to work on.
First of three. We believed more output would create more value. Measuring outcomes rather than activity changed what we believed, and the biggest lesson turned out not to be about AI.
SARS has put a digital VAT model out for consultation. It is not a mandate and there is no confirmed date, but the direction is clear enough that finance and IT should read it now rather than in 2029.
Ask why an AI programme stalled and the answer comes back technical. Underneath it there is usually a question nobody had formed properly, with nobody waiting for the answer.
A year ago the boardroom conversation was about use cases and proofs of concept. The question now is harder, and the research says most organisations have not answered it yet.
Wellbeing products are full of impressive numbers. Most of them measure how people feel about themselves. That is worth measuring, as long as everyone is clear that it is what is being measured.
Most AI initiatives stop at the pilot. The reason is usually not the model. It is that nothing connects an AI output to a decision anyone is willing to be accountable for.
Standards applied the same way on every engagement are what let a small development team keep its pace after the first month. What that looks like in practice.
AI changes the rate at which delivery work is produced. It changes nothing about who is answerable for it. Where that line sits decides whether AI-assisted delivery is an advantage or a liability.
People record things in a wellbeing app that they would keep from almost anyone. For UMOYA Zone we started from the assumption that the safest personal data is the data we never hold.
The build-or-buy debate treats a sequencing problem as an ownership problem. The better question is which parts of this you will still want to control in five years.
Unstructured data is the harder half of retiring an old platform. When documents are wired into daily work, the aim is a migration the users never notice, and the risk sits in places that are not code.
Most of our work is building software that a client owns. UMOYA Zone is different. It is a joint venture, and co-owning a product has taught us things that client work does not.
AI assistance made a difference to our delivery that we did not expect. It widened the gap between work built on something proven and work started from nothing.
Every major cloud now has infrastructure in South Africa. That is not the same as your AI running here, and the difference is the first thing a serious buyer in this region asks about.
When an investor looks under a growing platform, the questions are about credentials, data and whether the fixes are real. What we learned taking a technical due diligence from first review to verified remediation.
The first correction in our AI work had nothing to do with AI. What an organisation knows is usually scattered, undated and contradictory, and a model working from that will answer confidently and wrongly.
Earlier this year we could describe everything we had built with AI and almost nothing about what it had changed. This is the first of a series on what we did about that.
Digitising a regulated public-sector process is mostly a question of rules and agreement between institutions. The software is the part that goes to plan.
An unsupported CRM is expensive to keep and dangerous to switch off, because a decade of customer history lives inside it. The answer we used keeps the history and retires the application.
If something here maps onto a problem you are working on, we would rather have the conversation than send you a brochure.