Every AI vendor selling into a Zimbabwean bank, insurer, telco or mining house will at some point hand over a security questionnaire answered for a different market. The questionnaire this briefing proposes is built the other way round: from the obligations the buyer actually carries here. Three documents supply almost all of them.
The Reserve Bank’s Cybersecurity and Resilience Guideline (August 2025) devotes section 5 to third-party service providers. It requires comprehensive due diligence before engagement (5.3): the provider’s cybersecurity policies, controls and resilience; subcontractor (“fourth-party”) dependencies; how the provider accesses, processes, stores or transmits the institution’s data; and independent certifications and reports. It requires contracts that define roles, security controls including secure development, audit rights, data protection and segregation (especially for cloud), portability to prevent lock-in, and business continuity, incident response and exit arrangements (5.6). It requires ongoing monitoring, an inventory of third parties and an assessment of substitutability (5.7, 5.14), supply-chain assessment including fourth parties (5.9), and early notice to the Reserve Bank of cloud outsourcing of critical functions (5.12). Para 6.4(b) adds that third-party providers must be properly licensed and not subject to international sanctions or restrictions.
The Data Protection Act requires the controller to appoint only processors that “provide sufficient guarantees regarding the technical and organisational security measures” (s.18(7)) and to have a written contract ensuring the processor maintains those measures (s.18(8)). SI 155 s.10(4)(f) repeats the written-agreement requirement for licensees, and s.28–29 govern any transfer the vendor makes out of the country.
The Model Risk standard, for banks, treats an “external model” as in scope: the register, documentation and validation obligations do not disappear because the model belongs to someone else, and validation may be outsourced only to validators with the technical capacity (2.4.12).
The scoring table
Score each criterion 0 (absent), 1 (partial or unevidenced), 2 (evidenced). Weights reflect how often the criterion decides the outcome in practice. Maximum 40.
| # | Criterion | Weight | Evidence that scores 2 | Basis |
|---|---|---|---|---|
| 1 | Data location and flow: where prompts, documents, embeddings, logs and backups are stored and processed, including sub-processors | 2 | A data-flow diagram naming countries and sub-processors; contractual commitment to a region | Act s.28; RBZ 5.3(b)–(c), 5.13(a) |
| 2 | Processor contract and guarantees | 2 | Signed data processing agreement with security schedule, breach notice within hours, audit rights | Act s.18(7)–(8); SI 155 s.10(4)(f); RBZ 5.6 |
| 3 | Sub-processor transparency and change notice | 1 | Published list; advance notice and objection right | RBZ 5.3(b), 5.9 |
| 4 | Independent security assurance | 2 | Current SOC 2 Type II or ISO/IEC 27001 certificate with scope covering the service; penetration test summary | RBZ 5.3(d) |
| 5 | AI-specific controls: prompt-injection defences, output handling, tool permissioning, tenant isolation of indexes | 2 | Design documentation; results of red-team testing; per-tenant partitioning of vectors | OWASP LLM01, LLM05, LLM06, LLM08; RBZ 6.4 |
| 6 | Model provenance and change control: which models, which versions, who may change them and with what notice | 2 | Pinned versions or documented change windows; changelog; evaluation set access | RBZ PS 02-2023 (external models, model log) |
| 7 | Training-data use: whether your data trains or tunes any model, and the opt-out | 1 | Contractual exclusion by default | Act s.13(c) purpose limitation |
| 8 | Logging, audit and reconstruction: can you obtain every prompt, retrieval and action for a given identity and period | 2 | Export capability demonstrated; retention configurable | Act s.14; SI 155 s.17(5); RBZ 6.4(c) |
| 9 | Licensing, ownership and sanctions status of the vendor and its model suppliers | 1 | Registration documents; sanctions screening record | RBZ 6.4(b) |
| 10 | Exit and portability: data return in usable formats, deletion certification, substitutability | 2 | Exit plan in the contract; tested export | RBZ 5.6(d)–(e), 5.7(d) |
| 11 | Incident cooperation: notification timelines aligned to 3 hours (RBZ) and 24 hours (POTRAZ), joint drills | 2 | Contractual timelines shorter than your regulatory ones; a completed drill | RBZ 4.30, 5.8, 5.11; SI 155 s.17 |
| 12 | Commercial resilience: currency of billing, price-change notice, financial standing | 1 | Fixed-term pricing; audited accounts or equivalent | RBZ 5.7(d) (substitutability); internal |
Interpretation is deliberately blunt. A score below 24 means the vendor cannot be used with personal data in a regulated institution yet. A zero on criterion 1, 2 or 11 is disqualifying regardless of total, because those are the criteria that turn into a breach report.
The contract clauses that matter
Most of the score lives in the contract. The clauses that a Zimbabwean regulated buyer should insist on, in the order they usually get argued:
- Processing location named by country, with a prohibition on transfer without written consent and a duty to support the buyer’s s.28 adequacy assessment and SI 155 s.10(2)(c) notification.
- No training on customer data by default, including derived data such as embeddings and evaluation traces.
- Breach notification to the buyer within a fixed number of hours that leaves room for the buyer’s own 3-hour and 24-hour obligations, with the information the Form DP3 requires.
- Audit and inspection rights, including for the buyer’s regulator.
- Model change notice: advance notice of model or version changes for material use cases, with the right to defer, so the Model Risk standard’s re-validation can happen first.
- Data segregation and tenant isolation for indexes and logs, especially in shared cloud.
- Exit: export in documented formats, deletion with certification, and a transition period.
- Sub-processors: current list, notice of additions, right to object.
- Sanctions and licensing warranties with a duty to notify changes.
- Currency and pricing: billing currency stated; price-change notice; where ZiG settlement is required by the buyer’s rules, a mechanism agreed in advance.
Questions that end conversations early
Three questions, asked in the first meeting, save most of the effort.
“Show me the list of actions your agent can take without a human, and the audit record for the last one it took.” A vendor that cannot show both is not ready for a regulated environment.
“Which country will my customers’ names be in at 02:00 tomorrow, and who else can read them?” The answer is either specific or the vendor has not thought about s.28.
“When you change the model, how do I find out, and can I say no?” This is the Model Risk standard in one sentence, and it separates vendors who build for banks from vendors who build for consumers.
Keep the file
The Reserve Bank says institutions “must maintain evidence of risk assessments, approvals, vendor due diligence, and technology audit trails for regulatory review” (6.4(c)). Keep the completed scoring table, the evidence behind each score, the signed contract and the sanctions screening in one file per vendor, and update the third-party inventory (5.14) the day the contract is signed. The security page carries the broader threat model; the governance checklist scores the vendor domain against five controls.
Sources
- RBZ Cybersecurity and Resilience Guideline (August 2025) — section 5 and para 6.4 — https://www.rbz.co.zw/documents/Regulations_Acts/2025/Cybersecurity_and_Resilience_Guideline_-_August_2025.pdf
- Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.18, s.28–29 — https://t3n9sm.c2.acecdn.net/wp-content/uploads/2024/11/Data-Protection-Act-5-of-2021.pdf
- Statutory Instrument 155 of 2024 — s.10(4)(f), s.16, s.17 — https://www.potraz.gov.zw/wp-content/uploads/2025/02/sI-155-of-2024-Cyber-and-Data-Protection-Normal_240913_1250178.pdf
- RBZ Prudential Standard No. 02-2023/BSD Model Risk Management — external models, outsourced validation — https://www.rbz.co.zw/documents/BLSS/Guidelines/2023/Model_Risk_Management_Prudential_Standard_Final_June_2023.pdf
- OWASP Top 10 for LLM Applications 2025 — LLM03 Supply Chain — https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
- ISO/IEC 42001:2023 — AI management systems — https://www.iso.org/standard/42001