Sitoza was founded by Brenda Funo, an IT audit, governance and business-intelligence leader with more than 20 years across South African banking and insurance, who kept seeing the same thing across boardrooms: alarming reports leadership couldn’t act on.
The advice was either too technical to govern by, or too vague to trust. So the firm was built around a simple discipline: every claim is traceable to evidence, every finding maps to a control, and every report is written for the people who have to make the decision.
Today Sitoza serves regulated enterprises across banking, mining, energy, the public sector and beyond, combining independent IT audit and technology assurance with cybersecurity and AI assurance. It stays deliberately local: rooted in South African law and reality, POPIA, King IV and the Information Regulator, and continuously monitoring posture rather than checking in once a year.




