ZenoXCare — marketing
Loading standards & compliance…
ZenoXCare pulls health, privacy, money handling, and newer tech rules into one place—you can see exactly what is live, underway, planned, or paused. Country rules are listed plainly; nothing is sold as “done” when it is not.

Straight from our rule lists; totals refresh weekly where noted.
Active means paperwork from an outside reviewer is on file today. Aligned means we built to match that rule book and can show how—without saying a seal is framed on the wall. In progress means staff are still gathering proof or someone is formally reviewing us. Labels are not swapped to sound better than they are.
ISO, AICPA, HL7, WHO, NIST, OWASP
Short country pages with law, office, and rollout wave
Outside sign-off we can show on request
Privacy and security work—including Ghana data office path
What is finished, what is moving, and where to open the binder. Every row links out for detail.
External CPA firm (engagement TBD)
External CPA firm (engagement TBD)
Accredited certification body (e.g., BSI, DNV, TÜV)
Accredited certification body (joint scope with 27001)
Data Protection Commission, Ghana
External CREST/OSCP-credentialed pentest firm (engagement TBD)
Self-assessed; QSA validation when card data scope expands
HITRUST-authorised external assessor
Each topic links through to the original writer of the rule. We refresh checks every quarter and keep what is finished or moving in the sections above—not buried here.
Foundational ISMS controls and third-party attestations governing how ZenoXCare protects systems, data, and customer trust.
ISO/IEC
International standard for an Information Security Management System (ISMS) — risk-based controls covering organisation, people, processes, and technology.
AICPA
Reporting framework on controls relevant to Security, Availability, Confidentiality, Processing Integrity, and Privacy of a service organisation.
AICPA
Reporting framework on controls relevant to user entities' Internal Control over Financial Reporting (ICFR).
Privacy-by-design controls extending the ISMS to personal data lifecycle management.
Verification standards for secure software development and runtime defence.
Operational continuity, disaster recovery, and incident-response disciplines.
Card and mobile-money compliance, settlement integrity, and payout safeguards.
Open standards for safely exchanging clinical information between systems.
Globally-recognised vocabularies for unambiguous clinical meaning.
Sector-specific operating standards for digital health systems and clinical workflows.
ISO
Health-sector application of ISO/IEC 27002 — security management in health using ISO/IEC 27002 controls.
World Health Organization
Standards-based, Machine-readable, Adaptive, Requirements-based, Testable — WHO's framework for digital adaptation kits in health systems.
Lifecycle controls for trustworthy, ethical, and human-supervised AI in healthcare.
ISO/IEC
AI Management System — requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation.
NIST (USA)
AI Risk Management Framework — voluntary guidance to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
World Health Organization
Ethics and governance of artificial intelligence for health — six principles ensuring AI works to the public benefit of all countries.
Standards held in reserve until any feature is classified as Software as a Medical Device.
Continental and regional instruments framing pan-African data, privacy, and digital-trade obligations.
African Union
African Union Convention on Cyber Security and Personal Data Protection — continental instrument harmonising data protection and cybersecurity.
African Union
Continental policy framework governing data, cross-border flows, and digital trade across African Union member states.
ECOWAS
ECOWAS Supplementary Act on Personal Data Protection — regional instrument governing data processing across West African member states.
National statutes that overlay the pan-African baseline as ZenoXCare enters each market.
Data Protection Commission, Ghana
Statutory data protection law in Ghana; controllers and processors must register with the Data Protection Commission.
Information Regulator, South Africa
Protection of Personal Information Act — South Africa's primary data protection statute; requires Information Officer registration.
Nigeria Data Protection Commission
Nigeria Data Protection Act, 2023 — established the Nigeria Data Protection Commission; recognises lawful bases including contract, legal obligation, and vital interests.
Each topic page pulls from the same live registries as this hub, in language people can scan quickly.
AI Governance
Testing you can replay, checks before each release, guards against misuse of prompts and tools, offline-friendly assist where it fits, plus public discovery for partner tools.
Open
Conformity matrix
Live cross-mapping of every regulatory framework to its declared standards and the certifications that satisfy it.
Open
Live calendar
Forward-looking compliance events derived live from the certifications registry. Overdue items pinned at the top.
Open
Regression bar
Published budgets per intent, latest archived run, pass/fail per metric — surfaced from the repo's eval artifacts.
Open
Security findings
Severity → remediation SLA matrix, finding-status workflow, and live counts. CI gates breaches at build time.
Open
Auto-KYC v1
Ghana Card / NIA, passive liveness, sanctions screen, GhanaPostGPS, three-band decisioning with reviewer co-pilot.
Open
Audit roadmap
Every active, in-progress, and planned third-party attestation with renewal cadence and scope.
Open
Pan-African coverage
Per-country data-protection statute, regulator engagement, and rollout wave for every African Union member state.
Open
Each country lists the privacy law in plain terms, who regulates it, and how far we have rolled out.
Answers draw from the published compliance registry. Optional quick help runs in your browser when your device allows it; otherwise you get the same answers from the built-in FAQ—usable offline once the page has loaded.

Our compliance and security teams are ready to help. Get detailed audit documentation, compliance reports, or speak directly with our experts.
All documentation is checked and ready for reviewers