Governance you can prove, built by people who understand why it matters.
AfriGRC exists to make governance, risk, and compliance provable — not just claimed — for every regulated organization in Africa. Built from African regulatory reality first, mapped outward to the global standards your partners require.
Five chapters, one continuous thread.
01 · The Challenge
Compliance in Africa carries a dual burden.
Regulated organizations across the continent answer to CBN, NDPR, POPIA, and NAICOM — and, increasingly, to the global standards their international partners and investors require: ISO 27001, SOC 2, GDPR. Most GRC platforms are built for one or the other, treating African regulation as a checkbox added after the fact.
02 · The Opportunity
AI makes continuous, evidence-linked compliance possible.
Manual, spreadsheet-driven compliance was the only option for a generation. Continuous evidence collection, live control mapping, and an AI Copilot that cites what it draws from are not — the technology to make governance provable in real time now exists, and Africa's regulated institutions deserve it built for their reality first.
03 · Why AfriGRC Exists
Built from African regulatory reality, mapped outward.
AfriGRC starts from CBN, NDPR, POPIA, and NAICOM, and maps outward to the global standards your international partners require — not the reverse. The result is a system that satisfies your regulator and your investor from the same evidence base, without maintaining two compliance programs in parallel.
04 · Vision for Africa
A continent where compliance is proven, not asserted.
We want every bank, fintech, insurer, telecom, government agency, and enterprise across Africa to be able to demonstrate its governance posture as readily as it reports its financials — to a regulator, a board, or an international partner, on demand.
05 · Future Direction
Deeper coverage, wider reach, the same discipline.
More frameworks, more regions, more of the platform running on AI that reasons over real evidence — built with the same engineering rigor and evidence-forward standard we hold ourselves to today. See Innovation Roadmap below for the themes guiding that work.
What we're building, and why it's built this way.
Mission
To make governance, risk, and compliance provable — not just claimed — for every regulated organization in Africa.
We build the system of record that turns manual, point-in-time compliance work into continuous, evidence-linked practice, mapped to the regulatory reality of the markets we serve.
Vision
A continent where every institution can prove its compliance posture as readily as it reports its financials.
Global-standard rigor, built from African regulatory reality first — not retrofitted onto a system designed for someone else's regulator.
Core Values
Precision
Every claim is evidenced. Nothing is rounded up or overstated.
Custodianship
We protect what we're trusted with, and verify it continuously.
Transparency
Governance built in the open — for our customers, and for ourselves.
Partnership
Long-term relationships over one-time deployments.
Rigor
Engineering discipline over hype, in the product and in how we build it.
Innovation Principles
AI that cites its evidence, never a black box.
Every AI-generated answer on the platform links back to the control or evidence record it drew from. We build for evidenced automation, not confident guessing.
Customer Promise
A named team, not a ticket number, for the life of the relationship.
From your first discovery call through ongoing Customer Success, the same evidence-forward standard we hold ourselves to governs how we work with you.
Seven principles that govern every decision, not seven biographies.
Our executive team isn't publicly announced yet — these are the principles guiding the company today, and the format leadership profiles will use once it is.
Customer-first
Every product decision is weighed against what it does for the compliance officer using it.
Security-first
Security is a design constraint from the first line of code, not a feature added later.
Compliance-by-design
Controls and evidence structures are built into the platform's architecture, not bolted on.
Privacy-first
Data minimization and purpose limitation apply to how we operate, not just what we sell.
AI responsibility
AI capabilities ship with evidence citations and human oversight, never as an unaccountable black box.
Continuous innovation
The platform evolves with the regulatory environment, not on a fixed annual release cycle.
Long-term partnerships
We measure success in years of relationship, not the size of a single deal.
Profile Reserved
Leadership profiles will appear here as our executive team is announced.
Profile Reserved
Leadership profiles will appear here as our executive team is announced.
Profile Reserved
Leadership profiles will appear here as our executive team is announced.
Measured in coverage, not in claims we can't back up.
14
Industries Served
From banking to healthcare, each mapped to sector-specific regulatory requirements.
20+
Framework Coverage
African regulatory law and global standards, tracked in one library.
6
Countries Supported
Jurisdictions with active regulatory coverage today.
20
Platform Capabilities
Modules spanning governance, risk, compliance, privacy, and audit.
Continuous
AI Innovation
An AI Copilot that cites its evidence, evolving with every framework we add.
Growing
Partner Ecosystem
Technology, consulting, and implementation partners building alongside us.
Seven reasons regulated institutions choose to build on AfriGRC.
Enterprise Architecture
Multi-entity, role-based, and built to scale from a single team to a banking group.
African Expertise
Built from CBN, NDPR, POPIA, and NAICOM outward — not retrofitted from a foreign system.
Global Standards
ISO 27001, ISO 42001, SOC 2, GDPR, and more, mapped alongside African regulatory law.
AI-Powered Platform
Evidence-linked AI throughout — risk scoring, drafting, and gap detection that cites its source.
Secure Engineering
Independently certified to ISO 27001, ISO 42001, and ISO 27701, the same standards we help customers reach.
Scalable Platform
From Starter to Government, the same evidence-linked architecture underneath every tier.
Customer Success
A named contact for the life of the relationship, not a rotating support queue.
How AfriGRC governs itself — the same discipline we sell.
Ethics
We hold ourselves to the same standard of evidenced, honest claims we require of the platform.
Transparency
Governance decisions and their reasoning are documented, not left implicit.
Accountability
Every control and decision has a named owner, inside AfriGRC as much as inside the product.
Security
Independently certified to ISO 27001 and ISO 42001 — verified, not self-declared.
Privacy
Data minimization and purpose limitation, applied to how we operate as a company.
Responsible AI
AI systems are governed under the same ISO 42001 discipline we help customers achieve.
Regulatory Alignment
We track regulatory change the week it's published — for our customers, and for ourselves.
Five stages, wherever your organization is today.
A general model of how GRC programs mature — not a claim about how quickly you'll move through it.
- 01
Reactive
Compliance work happens after an incident or audit finding, not before. - 02
Foundational
Core policies and controls exist, but evidence is gathered manually, per request. - 03
Managed
Controls are mapped to frameworks and reviewed on a fixed schedule. - 04
Integrated
Evidence collection is continuous, and controls are shared across every framework that needs them. - 05
Optimized
Risk posture is visible in real time, and the board sees governance the way it sees financials.
Six themes guiding where the platform goes next.
Strategic focus areas, not a release calendar — explore what each one means below.
Focus Area
Platform Evolution
Deeper control-mapping intelligence and a more unified evidence model across every module.
Focus Area
AI Capabilities
Broader evidence-linked reasoning across risk scoring, drafting, and regulatory change analysis.
Focus Area
Regional Expansion
Wider African regulatory coverage, tracked with the same rigor as our founding markets.
Focus Area
Integration Ecosystem
More of the tools compliance teams already run, connected as native evidence sources.
Focus Area
Developer Ecosystem
API-first access for teams who want to build on top of AfriGRC's evidence model directly.
Focus Area
Knowledge Platform
Guides, glossary, and regulatory-watch content that keeps pace with how fast the rules change.
Pick a theme. See the questions we're exploring.
This is direction, not a roadmap with dates.
Each theme below represents a strategic area of focus. What ships, and when, is scoped the same way everything else at AfriGRC is — evidenced, not promised in advance.
Focus Area
Platform Evolution
Deeper control-mapping intelligence and a more unified evidence model across every module.
Questions We're Exploring
- How can one control satisfy more frameworks with less manual re-mapping?
- What does a single, unified evidence model look like across governance, risk, and compliance together?
The kind of company we're building, deliberately.
Learning
Regulation changes constantly — so does what we know, deliberately and continuously.
Collaboration
Product, engineering, and compliance practitioners work from the same table, not separate ones.
Integrity
We say what's true about the platform, including what it doesn't do yet.
Innovation
New capability is judged by the evidence it produces, not the demo it enables.
Customer Success
Everyone at AfriGRC can trace their work back to a customer outcome.
Diversity
Built by people who understand the regulatory realities of the markets we serve, from the inside.
Professional Growth
A team built to grow into the scale of the problem we're solving, deliberately.
African by origin, building toward continental and global reach.
Headquartered in Lagos, with regional offices in Nairobi and Johannesburg. Team members work remotely across the continent — our capability isn't bounded by a single office's working hours, and our international partnerships extend reach beyond where we have a physical presence.
- Headquarters
Lagos, Nigeria
1 Marina Road, Lagos, Nigeria
Africa/Lagos (WAT, UTC+1)
- Regional Office
Nairobi, Kenya
Africa/Nairobi (EAT, UTC+3)
- Regional Office
Johannesburg, South Africa
Africa/Johannesburg (SAST, UTC+2)
- Planned
Cairo, Egypt
Africa/Cairo (EET, UTC+2)
- Planned
Accra, Ghana
Africa/Accra (GMT, UTC+0)
ABT.09.1 / AFRICA INNOVATION MAP
Regions of strategic focus, not a claim of office presence.
These five regional groupings mark where our regulatory coverage and go-to-market focus are headed next — distinct from the office and jurisdiction map above, which reflects where AfriGRC operates today.
Regional focus areas — illustrative, not current office locations
West Africa — focus regionNorth Africa — focus regionEast Africa — focus regionSouthern Africa — focus regionCentral Africa — focus regionSix categories of partner, built alongside us.
See Partner With Us on the Contact page to start a conversation in any of these categories.
Technology
Integration partners connecting AfriGRC to the tools compliance teams already run.
Partners — coming soon
Consulting
Advisory firms bringing framework and audit-readiness expertise to shared customers.
Partners — coming soon
Training
Certification and training partners building GRC capability across the region.
Partners — coming soon
Cloud
Infrastructure partners supporting in-region hosting and data residency.
Partners — coming soon
Implementation
Delivery partners scaling rollout capacity for multi-entity deployments.
Partners — coming soon
Compliance
Audit and assurance firms working from the same evidence base as your team.
Partners — coming soon
Frequently Asked Questions.
Join the institutions building governance they can prove.
Whichever door fits, it reaches a named person.