Standardize reviews. Mapped controls for consistent auditor output.
TrueStele's guided assessment engine transforms complex regulations into standardized checklists. Your analysts work with plain-language control descriptions, required evidence mapping, and objective compliance scores—ensuring that every audit file matches professional standards.
Assessment metrics vary wildly between auditors.
Inconsistent checklist reviews across analysts cause review backlogs and senior partner friction.
Relying on subjective checklist sheets leads to inconsistent compliance scores, causing review backlogs and senior partner friction before filings are finalized. TrueStele's Guided Control Assessment structures assessments by linking each statutory requirement (NDPA, ODPC Kenya, POPIA, or LGPD) to explicit compliance levels, plain-language guidance, and immediate gap remediation assignments.
Live Control Assessment Console
Simulate guided data protection assessments below. Switch between country frameworks, toggle control compliant states, and watch gap remediation tasks generate automatically.
Governance
Auditor Guidance: This section evaluates whether your organisation has established the foundational governance structures required under the NDP Act, including having a registered and trained DPO, conducting staff training on data protection, and maintaining…
Evidence of NDPC registration, DPO appointment and certification, training records, privacy checklists, and compliance monitoring policies.
Principles of Data Protection
Auditor Guidance: This section checks whether your organisation's data processing practices — both in written policy and as observed during audit — follow all core data protection principles. Select the statements that best describe your practices.
Evidence of privacy policies, data processing records, data retention schedules, consent mechanisms, and data quality management processes.
Lawful Basis for Processing
Auditor Guidance: Select all lawful bases that your organisation relies upon for processing personal data. You must have at least one valid lawful basis for each processing activity.
Documentation of lawful bases relied upon for each category of data processing, including consent records, legal obligation references, and legitimate interest assessments.
Profiling and Marketing
Auditor Guidance: If your organisation engages in profiling or direct marketing, select all lawful bases that apply to those specific processing activities.
Documentation of lawful bases for profiling and marketing, consent records for direct marketing, and opt-out mechanisms.
How guided controls standardize compliance mapping
Every statutory rule transforms into guided review pathways. Mappings keep analysts aligned and automatically track remediation loops.
Statutory Rule Filtering
Toggle Nigeria NDPA, South Africa POPIA, or Kenya DPA. The matrix instantly displays plain-language controls and evidence criteria.
Objective Gap Evaluation
Review uploaded files against explicit compliance guidelines. Switch states to Compliant or Gap to log operational deficiencies.
Gap Remediation Tracking
Assign remediation tasks, set deadlines, and track resolution — connected to the control record that triggered them.
See the Assessment Module in your workflow
See this module with your own client files.
