African regulation and global standards, mapped to the same controls.
AfriGRC carries the data-protection laws written for African jurisdictions — NDPA, POPIA, Kenya DPA, and more — alongside the international standards your global partners require: ISO 27001, SOC 2, GDPR, and beyond. One control, implemented once, satisfies every framework that shares its requirement.
A single library, not a folder of PDFs per regulator.
Most GRC platforms bolt African regulation onto a system built for GDPR and SOC 2. AfriGRC's library starts from the same control taxonomy for every framework it carries, so a control implemented once is evidenced everywhere it applies.
0
Frameworks tracked in one library
0
African jurisdictions covered
1,200+
Pre-mapped controls shared across frameworks
Control count is illustrative pending a verified, current figure — consistent with the same disclosure on the homepage.
Built from the regulation, in the jurisdictions that wrote it.
Six African jurisdictions, each with its data-protection law tracked at the statute level — not inferred from GDPR. Hover a jurisdiction to see its law; select it to open the framework page.
Implement a control once. It satisfies every framework that shares it.
Select a control your team already owns. Every framework below lights up where that control counts as evidence — African regulation and international standard, in the same view.
Access Control Policy — evidenced for
Every framework, searchable by name, jurisdiction, or focus.
20 of 20 frameworks
Nigeria
NDPA
Nigeria's data protection statute, enforced by the Nigeria Data Protection Commission — the current-generation law governing how personal data is collected, processed, and stored.
- Control mapping kept current with NDPC guidance
- Consent, breach-notification, and DPIA workflows built in
Nigeria
NDPR
The regulation NDPA supersedes. Tracked for organizations mid-transition or still bound by NDPR-era commitments and filings.
- Transition mapping from NDPR obligations to NDPA controls
- Historical filing and audit-trail continuity
Kenya
Kenya DPA
Kenya's data protection statute, overseen by the Office of the Data Protection Commissioner, governing registration, consent, and cross-border transfer of personal data.
- ODPC registration and DPIA evidence tracked in one place
- Cross-border transfer controls mapped to GDPR equivalents
Ghana
Ghana DPA
Ghana's data protection statute, enforced by the Data Protection Commission, setting registration and processing obligations for data controllers and processors.
- Data Protection Commission registration tracked with renewal alerts
- Processor and controller obligations kept distinct
South Africa
POPIA
South Africa's data protection act, enforced by the Information Regulator, setting conditions for the lawful processing of personal information.
- Information Officer duties and PAIA overlap tracked together
- Cross-border transfer conditions mapped to GDPR Chapter V
Egypt
Egypt PDPL
Egypt's data protection law, administered by the Personal Data Protection Center, governing consent, licensing, and cross-border transfer of personal data.
- PDPC licensing and registration status tracked centrally
- Consent and processing records held to a single evidence standard
Rwanda
Rwanda DPPL
Rwanda's data protection and privacy law, overseen by the National Cyber Security Authority, setting obligations for data collection, processing, and storage.
- NCSA reporting obligations tracked against live control data
- Data localization requirements flagged by hosting region
Global
ISO 27001
The global standard for information security management systems — the certification most enterprise buyers and auditors ask for first.
- Statement of Applicability generated from your live control set
- Annex A controls pre-mapped to CBN, NDPA, and POPIA
Global
ISO 27701
The privacy information management extension to ISO 27001 — the standard that formally bridges African data-protection law and global privacy expectations.
- Extends an existing ISO 27001 base rather than starting a new program
- PII controller and processor roles mapped explicitly
Global
ISO 42001
The management-system standard for organizations that build or deploy AI — the standard AfriGRC's own Copilot is designed to be audited against.
- AI risk assessment templates aligned to Annex A of the standard
- Model lifecycle and change-management evidence captured automatically
Global
ISO 22301
The global standard for business continuity management systems — planning, response, and recovery for disruptive incidents.
- Business impact analysis and recovery plans versioned and tracked
- Test and exercise evidence collected on a defined cycle
Global
ISO 20000-1
The global standard for IT service management systems, covering service delivery, incident handling, and continual improvement.
- Service management processes evidenced alongside security controls
- Incident and change records shared with ISO 27001 evidence
Global
SOC 2
The trust services report international customers and investors ask for — security, availability, and confidentiality, evidenced continuously rather than assembled once a year.
- Type II evidence collected continuously, not the week before the audit
- Trust services criteria pre-mapped to ISO 27001 Annex A
Global
PCI DSS
The security standard for any organization that stores, processes, or transmits payment card data — required for banks, fintechs, and payment processors alike.
- Cardholder data environment scoped and tracked separately
- Quarterly scan and penetration-test evidence held centrally
European Union
GDPR
The EU's data protection regulation — the standard your European partners, investors, and customers expect African operations to meet as a baseline.
- Article 30 records of processing generated from live system data
- Cross-border transfer mechanisms tracked against every African law you carry
Global
NIST CSF
The risk-based cybersecurity framework widely referenced by regulators and enterprise security teams as a common language for maturity, even without formal certification.
- Identify, Protect, Detect, Respond, Recover functions scored from live data
- Maturity reporting board members already recognize
Global
CIS Controls
The prioritized set of cybersecurity safeguards from the Center for Internet Security — a practical baseline technical teams implement ahead of formal certification.
- Implementation Groups tracked by asset and control ownership
- Safeguards mapped directly to ISO 27001 and NIST CSF
Nigeria — Banking
CBN
The Central Bank of Nigeria's cybersecurity and prudential guidelines — mandatory for licensed banks and payment service providers operating in Nigeria.
- Board and CBN submission packages generated on demand
- Prudential and cybersecurity requirements tracked in one register
Nigeria — Insurance
NAICOM
The National Insurance Commission's regulatory guidelines governing risk management, solvency, and governance for insurers operating in Nigeria.
- Solvency and risk reporting evidenced continuously, not annually
- Governance requirements mapped to ISO 27001 and NDPA together
Nigeria — Telecom
NCC
The Nigerian Communications Commission's regulatory framework governing telecom operators, including subscriber-data protection obligations.
- Subscriber-data protection evidenced alongside NDPA controls
- License compliance tracked against live obligations
How the frameworks compare, at a glance.
Grouped by category, so you can see where a jurisdiction's law and a global standard ask for the same thing.
| Framework | Jurisdiction | Focus | Certification | AfriGRC |
|---|---|---|---|---|
| African Regulations | ||||
| NDPA | Nigeria | Data protection | Regulatory | |
| NDPRLegacy | Nigeria | Data protection | Regulatory | |
| Kenya DPA | Kenya | Data protection | Regulatory | |
| Ghana DPA | Ghana | Data protection | Regulatory | |
| POPIA | South Africa | Data protection | Regulatory | |
| Egypt PDPL | Egypt | Data protection | Regulatory | |
| Rwanda DPPL | Rwanda | Data protection | Regulatory | |
| International Standards | ||||
| ISO 27001 | Global | Information security management | Third-party certified | |
| ISO 27701 | Global | Privacy information management | Third-party certified | |
| ISO 42001 | Global | AI management systems | Third-party certified | |
| ISO 22301 | Global | Business continuity management | Third-party certified | |
| ISO 20000-1 | Global | IT service management | Third-party certified | |
| SOC 2 | Global | Trust services criteria | Third-party certified | |
| PCI DSS | Global | Payment card data security | Third-party certified | |
| GDPR | European Union | Data protection | Regulatory | |
| NIST CSF | Global | Cybersecurity risk management | Self-attested | |
| CIS Controls | Global | Cybersecurity best practices | Self-attested | |
| Industry Frameworks | ||||
| CBN | Nigeria — Banking | Banking cybersecurity & prudential risk | Regulatory | |
| NAICOM | Nigeria — Insurance | Insurance risk & solvency | Regulatory | |
| NCC | Nigeria — Telecom | Telecom compliance & subscriber data | Regulatory | |
Less duplicated compliance effort, more governance you can show.
NDPA, POPIA, and ISO 27701 share the same underlying control for data-subject rights.
A control mapped once is evidenced everywhere it applies — no duplicate work per framework.
New framework added to your mix reuses controls you've already implemented.
Evidence streams from the systems you already run — no framework-by-framework re-collection.
Drift in one control is flagged once, and every framework it maps to is flagged with it.
No separate audit-prep sprint per regulator or certification body.
Regulatory Watch tracks changes across every jurisdiction AfriGRC covers.
A new circular or amendment is mapped to affected controls the week it's published.
You see exactly what changed and which existing evidence already covers it.
One-click reports formatted for the specific regulator or certification body requesting them.
Every figure links back to the underlying evidence, for whichever framework is being reviewed.
The same evidence base defends every framework in your mix, not just the one under audit.
The frameworks that apply to your sector, already grouped.
Banks
CBNISO 27001PCI DSSFinTechs
NDPAISO 27001PCI DSSInsurance
NAICOMISO 27001POPIATelecom
NCCNDPAISO 27001Healthcare
NDPAPOPIAISO 27701Energy
ISO 27001ISO 22301NIST CSFGovernment
NDPAPOPIANIST CSFLarge Enterprise
ISO 27001SOC 2GDPRSME
ISO 27001NDPASOC 2Manufacturing
Technology
Education
NGOs & Nonprofits
Professional Services
An AI Copilot that cites its evidence.
Ask AfriGRC's Copilot what's missing before your next CBN audit, and it answers with a mapped list of controls, evidence status, and a direct link to the gap — not a guess.
Gap detection
Surfaces exactly which controls lack current evidence.
Regulatory change summarization
Digests a new circular into what changed for you.
Evidence-linked answers, always
Every claim resolves to a control or evidence record.
Copilot — illustrative session
› What's missing before my next CBN audit?
3 controls need fresh evidence before Nov 30:
—CBN 4.2 Access Review — evidence expires in 6 days
—CBN 7.1 Incident Log — no evidence linked
—CBN 9.3 Vendor Assessment — evidence expires in 14 days
Frequently Asked Questions.
See what your compliance program looks like, verified.
Twenty minutes with our team. No slide deck — a live look at your framework mix, mapped.