Briefing · Cross-sector

Vendor due diligence for AI in regulated Zimbabwean sectors

The Reserve Bank's August 2025 guideline reads as if it were written for AI vendors. This briefing turns its third-party section, the Act's processor rules and SI 155's written-contract requirement into a twelve-criterion scoring table, a list of contract clauses, and the questions that end most vendor conversations early.

Every AI vendor selling into a Zimbabwean bank, insurer, telco or mining house will at some point hand over a security questionnaire answered for a different market. The questionnaire this briefing proposes is built the other way round: from the obligations the buyer actually carries here. Three documents supply almost all of them.

The Reserve Bank’s Cybersecurity and Resilience Guideline (August 2025) devotes section 5 to third-party service providers. It requires comprehensive due diligence before engagement (5.3): the provider’s cybersecurity policies, controls and resilience; subcontractor (“fourth-party”) dependencies; how the provider accesses, processes, stores or transmits the institution’s data; and independent certifications and reports. It requires contracts that define roles, security controls including secure development, audit rights, data protection and segregation (especially for cloud), portability to prevent lock-in, and business continuity, incident response and exit arrangements (5.6). It requires ongoing monitoring, an inventory of third parties and an assessment of substitutability (5.7, 5.14), supply-chain assessment including fourth parties (5.9), and early notice to the Reserve Bank of cloud outsourcing of critical functions (5.12). Para 6.4(b) adds that third-party providers must be properly licensed and not subject to international sanctions or restrictions.

The Data Protection Act requires the controller to appoint only processors that “provide sufficient guarantees regarding the technical and organisational security measures” (s.18(7)) and to have a written contract ensuring the processor maintains those measures (s.18(8)). SI 155 s.10(4)(f) repeats the written-agreement requirement for licensees, and s.28–29 govern any transfer the vendor makes out of the country.

The Model Risk standard, for banks, treats an “external model” as in scope: the register, documentation and validation obligations do not disappear because the model belongs to someone else, and validation may be outsourced only to validators with the technical capacity (2.4.12).

The scoring table

Score each criterion 0 (absent), 1 (partial or unevidenced), 2 (evidenced). Weights reflect how often the criterion decides the outcome in practice. Maximum 40.

#CriterionWeightEvidence that scores 2Basis
1Data location and flow: where prompts, documents, embeddings, logs and backups are stored and processed, including sub-processors2A data-flow diagram naming countries and sub-processors; contractual commitment to a regionAct s.28; RBZ 5.3(b)–(c), 5.13(a)
2Processor contract and guarantees2Signed data processing agreement with security schedule, breach notice within hours, audit rightsAct s.18(7)–(8); SI 155 s.10(4)(f); RBZ 5.6
3Sub-processor transparency and change notice1Published list; advance notice and objection rightRBZ 5.3(b), 5.9
4Independent security assurance2Current SOC 2 Type II or ISO/IEC 27001 certificate with scope covering the service; penetration test summaryRBZ 5.3(d)
5AI-specific controls: prompt-injection defences, output handling, tool permissioning, tenant isolation of indexes2Design documentation; results of red-team testing; per-tenant partitioning of vectorsOWASP LLM01, LLM05, LLM06, LLM08; RBZ 6.4
6Model provenance and change control: which models, which versions, who may change them and with what notice2Pinned versions or documented change windows; changelog; evaluation set accessRBZ PS 02-2023 (external models, model log)
7Training-data use: whether your data trains or tunes any model, and the opt-out1Contractual exclusion by defaultAct s.13(c) purpose limitation
8Logging, audit and reconstruction: can you obtain every prompt, retrieval and action for a given identity and period2Export capability demonstrated; retention configurableAct s.14; SI 155 s.17(5); RBZ 6.4(c)
9Licensing, ownership and sanctions status of the vendor and its model suppliers1Registration documents; sanctions screening recordRBZ 6.4(b)
10Exit and portability: data return in usable formats, deletion certification, substitutability2Exit plan in the contract; tested exportRBZ 5.6(d)–(e), 5.7(d)
11Incident cooperation: notification timelines aligned to 3 hours (RBZ) and 24 hours (POTRAZ), joint drills2Contractual timelines shorter than your regulatory ones; a completed drillRBZ 4.30, 5.8, 5.11; SI 155 s.17
12Commercial resilience: currency of billing, price-change notice, financial standing1Fixed-term pricing; audited accounts or equivalentRBZ 5.7(d) (substitutability); internal

Interpretation is deliberately blunt. A score below 24 means the vendor cannot be used with personal data in a regulated institution yet. A zero on criterion 1, 2 or 11 is disqualifying regardless of total, because those are the criteria that turn into a breach report.

The contract clauses that matter

Most of the score lives in the contract. The clauses that a Zimbabwean regulated buyer should insist on, in the order they usually get argued:

  1. Processing location named by country, with a prohibition on transfer without written consent and a duty to support the buyer’s s.28 adequacy assessment and SI 155 s.10(2)(c) notification.
  2. No training on customer data by default, including derived data such as embeddings and evaluation traces.
  3. Breach notification to the buyer within a fixed number of hours that leaves room for the buyer’s own 3-hour and 24-hour obligations, with the information the Form DP3 requires.
  4. Audit and inspection rights, including for the buyer’s regulator.
  5. Model change notice: advance notice of model or version changes for material use cases, with the right to defer, so the Model Risk standard’s re-validation can happen first.
  6. Data segregation and tenant isolation for indexes and logs, especially in shared cloud.
  7. Exit: export in documented formats, deletion with certification, and a transition period.
  8. Sub-processors: current list, notice of additions, right to object.
  9. Sanctions and licensing warranties with a duty to notify changes.
  10. Currency and pricing: billing currency stated; price-change notice; where ZiG settlement is required by the buyer’s rules, a mechanism agreed in advance.

Questions that end conversations early

Three questions, asked in the first meeting, save most of the effort.

“Show me the list of actions your agent can take without a human, and the audit record for the last one it took.” A vendor that cannot show both is not ready for a regulated environment.

“Which country will my customers’ names be in at 02:00 tomorrow, and who else can read them?” The answer is either specific or the vendor has not thought about s.28.

“When you change the model, how do I find out, and can I say no?” This is the Model Risk standard in one sentence, and it separates vendors who build for banks from vendors who build for consumers.

Keep the file

The Reserve Bank says institutions “must maintain evidence of risk assessments, approvals, vendor due diligence, and technology audit trails for regulatory review” (6.4(c)). Keep the completed scoring table, the evidence behind each score, the signed contract and the sanctions screening in one file per vendor, and update the third-party inventory (5.14) the day the contract is signed. The security page carries the broader threat model; the governance checklist scores the vendor domain against five controls.

Sources

  1. RBZ Cybersecurity and Resilience Guideline (August 2025) — section 5 and para 6.4 — https://www.rbz.co.zw/documents/Regulations_Acts/2025/Cybersecurity_and_Resilience_Guideline_-_August_2025.pdf
  2. Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.18, s.28–29 — https://t3n9sm.c2.acecdn.net/wp-content/uploads/2024/11/Data-Protection-Act-5-of-2021.pdf
  3. Statutory Instrument 155 of 2024 — s.10(4)(f), s.16, s.17 — https://www.potraz.gov.zw/wp-content/uploads/2025/02/sI-155-of-2024-Cyber-and-Data-Protection-Normal_240913_1250178.pdf
  4. RBZ Prudential Standard No. 02-2023/BSD Model Risk Management — external models, outsourced validation — https://www.rbz.co.zw/documents/BLSS/Guidelines/2023/Model_Risk_Management_Prudential_Standard_Final_June_2023.pdf
  5. OWASP Top 10 for LLM Applications 2025 — LLM03 Supply Chain — https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
  6. ISO/IEC 42001:2023 — AI management systems — https://www.iso.org/standard/42001