Skip to content
Book a Demo
FRM.00 / COMPLIANCE FRAMEWORKS

African regulation and global standards, mapped to the same controls.

AfriGRC carries the data-protection laws written for African jurisdictions — NDPA, POPIA, Kenya DPA, and more — alongside the international standards your global partners require: ISO 27001, SOC 2, GDPR, and beyond. One control, implemented once, satisfies every framework that shares its requirement.

FRM.01 / THE LIBRARY

A single library, not a folder of PDFs per regulator.

Most GRC platforms bolt African regulation onto a system built for GDPR and SOC 2. AfriGRC's library starts from the same control taxonomy for every framework it carries, so a control implemented once is evidenced everywhere it applies.

  • 0

    Frameworks tracked in one library

  • 0

    African jurisdictions covered

  • 1,200+

    Pre-mapped controls shared across frameworks

Control count is illustrative pending a verified, current figure — consistent with the same disclosure on the homepage.

FRM.02 / AFRICA COVERAGE

Built from the regulation, in the jurisdictions that wrote it.

Six African jurisdictions, each with its data-protection law tracked at the statute level — not inferred from GDPR. Hover a jurisdiction to see its law; select it to open the framework page.

FRM.03 / ONE CONTROL, MANY FRAMEWORKS

Implement a control once. It satisfies every framework that shares it.

Select a control your team already owns. Every framework below lights up where that control counts as evidence — African regulation and international standard, in the same view.

Access Control Policy — evidenced for

NDPANDPRKenya DPAGhana DPAPOPIAEgypt PDPLRwanda DPPLISO 27001ISO 27701ISO 42001ISO 22301ISO 20000-1SOC 2PCI DSSGDPRNIST CSFCIS ControlsCBNNAICOMNCC
FRM.04 / FRAMEWORK LIBRARY

Every framework, searchable by name, jurisdiction, or focus.

20 of 20 frameworks

Nigeria

NDPA

Nigeria's data protection statute, enforced by the Nigeria Data Protection Commission — the current-generation law governing how personal data is collected, processed, and stored.

  • Control mapping kept current with NDPC guidance
  • Consent, breach-notification, and DPIA workflows built in
View framework
Legacy

Nigeria

NDPR

The regulation NDPA supersedes. Tracked for organizations mid-transition or still bound by NDPR-era commitments and filings.

  • Transition mapping from NDPR obligations to NDPA controls
  • Historical filing and audit-trail continuity
View framework

Kenya

Kenya DPA

Kenya's data protection statute, overseen by the Office of the Data Protection Commissioner, governing registration, consent, and cross-border transfer of personal data.

  • ODPC registration and DPIA evidence tracked in one place
  • Cross-border transfer controls mapped to GDPR equivalents
View framework

Ghana

Ghana DPA

Ghana's data protection statute, enforced by the Data Protection Commission, setting registration and processing obligations for data controllers and processors.

  • Data Protection Commission registration tracked with renewal alerts
  • Processor and controller obligations kept distinct
View framework

South Africa

POPIA

South Africa's data protection act, enforced by the Information Regulator, setting conditions for the lawful processing of personal information.

  • Information Officer duties and PAIA overlap tracked together
  • Cross-border transfer conditions mapped to GDPR Chapter V
View framework

Egypt

Egypt PDPL

Egypt's data protection law, administered by the Personal Data Protection Center, governing consent, licensing, and cross-border transfer of personal data.

  • PDPC licensing and registration status tracked centrally
  • Consent and processing records held to a single evidence standard
View framework

Rwanda

Rwanda DPPL

Rwanda's data protection and privacy law, overseen by the National Cyber Security Authority, setting obligations for data collection, processing, and storage.

  • NCSA reporting obligations tracked against live control data
  • Data localization requirements flagged by hosting region
View framework

Global

ISO 27001

The global standard for information security management systems — the certification most enterprise buyers and auditors ask for first.

  • Statement of Applicability generated from your live control set
  • Annex A controls pre-mapped to CBN, NDPA, and POPIA
View framework

Global

ISO 27701

The privacy information management extension to ISO 27001 — the standard that formally bridges African data-protection law and global privacy expectations.

  • Extends an existing ISO 27001 base rather than starting a new program
  • PII controller and processor roles mapped explicitly
View framework

Global

ISO 42001

The management-system standard for organizations that build or deploy AI — the standard AfriGRC's own Copilot is designed to be audited against.

  • AI risk assessment templates aligned to Annex A of the standard
  • Model lifecycle and change-management evidence captured automatically
View framework

Global

ISO 22301

The global standard for business continuity management systems — planning, response, and recovery for disruptive incidents.

  • Business impact analysis and recovery plans versioned and tracked
  • Test and exercise evidence collected on a defined cycle
View framework

Global

ISO 20000-1

The global standard for IT service management systems, covering service delivery, incident handling, and continual improvement.

  • Service management processes evidenced alongside security controls
  • Incident and change records shared with ISO 27001 evidence
View framework

Global

SOC 2

The trust services report international customers and investors ask for — security, availability, and confidentiality, evidenced continuously rather than assembled once a year.

  • Type II evidence collected continuously, not the week before the audit
  • Trust services criteria pre-mapped to ISO 27001 Annex A
View framework

Global

PCI DSS

The security standard for any organization that stores, processes, or transmits payment card data — required for banks, fintechs, and payment processors alike.

  • Cardholder data environment scoped and tracked separately
  • Quarterly scan and penetration-test evidence held centrally
View framework

European Union

GDPR

The EU's data protection regulation — the standard your European partners, investors, and customers expect African operations to meet as a baseline.

  • Article 30 records of processing generated from live system data
  • Cross-border transfer mechanisms tracked against every African law you carry
View framework

Global

NIST CSF

The risk-based cybersecurity framework widely referenced by regulators and enterprise security teams as a common language for maturity, even without formal certification.

  • Identify, Protect, Detect, Respond, Recover functions scored from live data
  • Maturity reporting board members already recognize
View framework

Global

CIS Controls

The prioritized set of cybersecurity safeguards from the Center for Internet Security — a practical baseline technical teams implement ahead of formal certification.

  • Implementation Groups tracked by asset and control ownership
  • Safeguards mapped directly to ISO 27001 and NIST CSF
View framework

Nigeria — Banking

CBN

The Central Bank of Nigeria's cybersecurity and prudential guidelines — mandatory for licensed banks and payment service providers operating in Nigeria.

  • Board and CBN submission packages generated on demand
  • Prudential and cybersecurity requirements tracked in one register
View framework

Nigeria — Insurance

NAICOM

The National Insurance Commission's regulatory guidelines governing risk management, solvency, and governance for insurers operating in Nigeria.

  • Solvency and risk reporting evidenced continuously, not annually
  • Governance requirements mapped to ISO 27001 and NDPA together
View framework

Nigeria — Telecom

NCC

The Nigerian Communications Commission's regulatory framework governing telecom operators, including subscriber-data protection obligations.

  • Subscriber-data protection evidenced alongside NDPA controls
  • License compliance tracked against live obligations
View framework
FRM.05 / COMPARISON

How the frameworks compare, at a glance.

Grouped by category, so you can see where a jurisdiction's law and a global standard ask for the same thing.

Framework comparison by category
FrameworkJurisdictionFocusCertificationAfriGRC
African Regulations
NDPANigeriaData protectionRegulatory
NDPRLegacyNigeriaData protectionRegulatory
Kenya DPAKenyaData protectionRegulatory
Ghana DPAGhanaData protectionRegulatory
POPIASouth AfricaData protectionRegulatory
Egypt PDPLEgyptData protectionRegulatory
Rwanda DPPLRwandaData protectionRegulatory
International Standards
ISO 27001GlobalInformation security managementThird-party certified
ISO 27701GlobalPrivacy information managementThird-party certified
ISO 42001GlobalAI management systemsThird-party certified
ISO 22301GlobalBusiness continuity managementThird-party certified
ISO 20000-1GlobalIT service managementThird-party certified
SOC 2GlobalTrust services criteriaThird-party certified
PCI DSSGlobalPayment card data securityThird-party certified
GDPREuropean UnionData protectionRegulatory
NIST CSFGlobalCybersecurity risk managementSelf-attested
CIS ControlsGlobalCybersecurity best practicesSelf-attested
Industry Frameworks
CBNNigeria — BankingBanking cybersecurity & prudential riskRegulatory
NAICOMNigeria — InsuranceInsurance risk & solvencyRegulatory
NCCNigeria — TelecomTelecom compliance & subscriber dataRegulatory
FRM.06 / HOW AFRIGRC HELPS

Less duplicated compliance effort, more governance you can show.

  • NDPA, POPIA, and ISO 27701 share the same underlying control for data-subject rights.

    A control mapped once is evidenced everywhere it applies — no duplicate work per framework.

    New framework added to your mix reuses controls you've already implemented.

  • Evidence streams from the systems you already run — no framework-by-framework re-collection.

    Drift in one control is flagged once, and every framework it maps to is flagged with it.

    No separate audit-prep sprint per regulator or certification body.

  • Regulatory Watch tracks changes across every jurisdiction AfriGRC covers.

    A new circular or amendment is mapped to affected controls the week it's published.

    You see exactly what changed and which existing evidence already covers it.

  • One-click reports formatted for the specific regulator or certification body requesting them.

    Every figure links back to the underlying evidence, for whichever framework is being reviewed.

    The same evidence base defends every framework in your mix, not just the one under audit.

FRM.08 / AI-ASSISTED COMPLIANCE

An AI Copilot that cites its evidence.

Ask AfriGRC's Copilot what's missing before your next CBN audit, and it answers with a mapped list of controls, evidence status, and a direct link to the gap — not a guess.

Gap detection

Surfaces exactly which controls lack current evidence.

Regulatory change summarization

Digests a new circular into what changed for you.

Evidence-linked answers, always

Every claim resolves to a control or evidence record.

See the Copilot in a live demo

Copilot — illustrative session

What's missing before my next CBN audit?

3 controls need fresh evidence before Nov 30:

CBN 4.2 Access Review — evidence expires in 6 days

CBN 7.1 Incident Log — no evidence linked

CBN 9.3 Vendor Assessment — evidence expires in 14 days

Every line links to its source evidence
FRM.09 / FAQ

Frequently Asked Questions.

See what your compliance program looks like, verified.

Twenty minutes with our team. No slide deck — a live look at your framework mix, mapped.

Compliance Frameworks — AfriGRC