The governance, risk, and compliance operating system for regulated Africa.
AfriGRC is not a compliance checklist tool. It is the operating system underneath governance, risk management, regulatory compliance, and internal audit — twenty connected disciplines sharing one control taxonomy, evidenced continuously, and provable on demand.
Built for the people who carry the risk
Chief Information Security Officers · Chief Risk Officers · Compliance Officers · Internal Auditors · Data Protection Officers · Regulators
Twenty modules. One connected system.
Every platform area reads from and writes to the same control taxonomy — a risk identified in the register, a control tested for an audit, and a policy attested by an employee are the same underlying record, viewed from five different disciplines.
- GovernStructure, policy, and accountability across every entity.Governance ManagementPolicy ManagementMulti-Entity ManagementUser & Role Management
- Manage RiskRisk scored, registered, and treated continuously.Enterprise Risk ManagementRisk RegisterVendor & Third-Party RiskBusiness Continuity
- Ensure ComplianceControls mapped once, satisfying every framework.Regulatory ComplianceControls LibraryPrivacy ManagementAI Governance
- AssureAudit, incidents, and evidence, closed to verified completion.Internal AuditIssue & Incident ManagementCorrective ActionsEvidence Management
- OperateDashboards, automation, and reporting the board can trust.Executive DashboardsWorkflow AutomationReporting & AnalyticsAPI & Integrations
Diagram of five module categories — Govern, Manage Risk, Ensure Compliance, Assure, and Operate — connected to a central AfriGRC core. Each category below lists its modules.
Direction flows down. Evidence flows up.
Governance sets the standard; Risk and Compliance apply it in parallel; Audit and Evidence prove it happened; the Copilot reasons over that evidence; the board sees the result.
Twenty modules, five disciplines, no feature you'll outgrow.
Select a module for its business benefits, key capabilities, and how a team actually uses it.
Govern
Governance Management
The structural record of who owns what, decided how, and accountable to whom — across every entity you govern.
Policy Management
A version-controlled policy library mapped directly to the controls it governs, with structured review and attestation.
Multi-Entity Management
Group-wide governance across subsidiaries that each carry a different framework mix, rolling up to one board view.
User & Role Management
Role-based access aligned to segregation-of-duties requirements, so who can see and change what is never ambiguous.
Manage Risk
Enterprise Risk Management
Organizational risk scored continuously from live control data, not recalculated at the next workshop.
Risk Register
The living record of every identified risk, its treatment, and its current status — not a spreadsheet that's out of date by the time it's opened.
Vendor & Third-Party Risk
Vendor risk scored and monitored continuously, not reassessed once a year on a spreadsheet.
Business Continuity
Business-continuity planning evidenced under ISO 22301 alongside your security program, not maintained in a separate binder.
Ensure Compliance
Regulatory Compliance
Manual checklist work turned into automated evidence capture, mapped to every framework you carry.
Controls Library
A single, structured repository of every control you operate — implemented once, reused everywhere it applies.
Privacy Management
Data-subject rights, consent, and cross-border transfer governed to the same standard NDPA, POPIA, and GDPR each expect.
AI Governance
The management-system discipline ISO 42001 expects, applied to every AI system your organization builds, buys, or deploys.
Assure
Internal Audit
The full audit lifecycle — universe, planning, fieldwork, findings, and follow-up — in one workspace your auditor can access directly.
Issue & Incident Management
Findings and incidents assigned to an owner and tracked against regulatory notification deadlines, from detection to closure.
Corrective Actions
The closed loop between a finding and its fix — tracked to verified completion, not just marked done.
Evidence Management
Continuous evidence collection from the systems you already run, held to an immutable, cryptographically timestamped standard.
Operate
Executive Dashboards
Board-ready visibility into risk, compliance, and audit posture, generated on demand instead of assembled the week before.
Workflow Automation
The manual handoffs between governance, risk, and compliance teams replaced with routing that just happens.
Reporting & Analytics
Regulator submissions and internal reports generated from the same evidence base, formatted to whoever is asking.
API & Integrations
The evidence and identity systems you already run, connected once, feeding evidence in continuously.
An AI Copilot embedded in every discipline, not bolted onto one.
Ask it what's missing before an audit, what a new regulation changed, or which control already covers a requirement — every answer cites the control or evidence record behind it, not a guess.
Copilot — illustrative session
› What's missing before my next CBN audit?
3 controls need fresh evidence before Nov 30:
—CBN 4.2 Access Review — evidence expires in 6 days
—CBN 7.1 Incident Log — no evidence linked
—CBN 9.3 Vendor Assessment — evidence expires in 14 days
Risk analysis
Scores organizational risk from live control and evidence data, not a quarterly estimate.
Control recommendations
Suggests which existing control satisfies a new framework requirement before you build one.
Policy generation
Drafts a first version of a policy from your framework mix, ready for review, not from scratch.
Audit preparation
Assembles the evidence package an auditor will ask for, before they ask for it.
Compliance gap identification
Flags exactly which controls are short of evidence, for which framework, today.
Executive reporting
Turns the current risk and compliance posture into a board-ready summary on request.
Evidence organization
Links every piece of collected evidence to the control and framework it satisfies, automatically.
Regulatory intelligence
Tracks regulatory change across every jurisdiction you carry and maps it to affected controls.
A closed loop, not a checklist you run once a year.
Identify, Assess, Treat, Monitor, Audit, Report, Improve — and back to Identify, stronger than before.
Risk register populated from your sector's known risk landscape, not a blank spreadsheet.
Every control inventoried against the frameworks it's meant to satisfy.
Ownership assigned at the point of identification, not after the fact.
Risk scores recalculate as the underlying control and evidence data changes.
Control effectiveness tested on a defined cadence, not once a year.
Assessment results feed directly into the risk register, not a separate report.
Every treatment plan has a named owner and a target date.
Overdue treatments escalate automatically, not after someone notices.
Residual risk recalculated once treatment is verified complete.
Evidence streams in continuously from the systems you already run.
Drift in one control surfaces every framework it affects, at once.
No quarterly monitoring sprint — the system is always watching.
Audit findings link directly to the control and risk they originated from.
External auditors access the same evidence your team already trusts.
Findings aren't closed until remediation is verified, not just claimed.
Executive dashboards reflect the same numbers a report will show.
Regulator submissions formatted to the specific framework being reported.
Every figure in every report traces back to its source evidence.
Root-cause analysis updates the control, not just the finding.
Lessons from one entity's audit inform every entity that shares the control.
The next Identify cycle starts from a stronger baseline than the last.
Connects to the tools you already run.
No rip-and-replace — evidence flows in from systems your team already trusts.
Identity & Access
Provisioning and access reviews stay in sync with your identity provider.
Azure ADOktaSSO (SAML / OIDC)Productivity & Collaboration
Evidence and notifications reach the tools your teams already work in.
Microsoft 365Google WorkspaceSlackMicrosoft TeamsITSM & Workflow
Findings and corrective actions route into the systems that already own them.
JiraServiceNowData & Extensibility
Build what a pre-built connector doesn't cover yet.
REST APIsWebhooksCSV Import / Export
The board sees what the system has held all quarter.
No deck assembled by hand the night before. Risk posture, compliance status, and audit progress, generated on demand from the same evidence base every module writes to.
See a live dashboard walkthroughExecutive summary — illustrative
- Open findings
- 0
- Controls at risk
- 0
- Frameworks on-track
- 0/20
—Board pack generated — Executive Summary, Q3
—CBN submission package — ready for review
—3 controls re-evidenced — ISO 27001 surveillance
Secured to the same standard we help you meet.
Encryption
Data encrypted at rest and in transit, with keys managed to the standard your own security team would expect.
Role-Based Access Control
Segregation of duties enforced down to the individual permission, not just documented.
Multi-Factor Authentication
Required on every account, with no exceptions carved out for convenience.
Audit Logs
Every access, change, and export logged immutably — for your audit and ours.
Data Residency
Regional hosting is on our infrastructure roadmap; dedicated and on-premises deployment tiers already let you keep data inside your own jurisdiction today.
Backups
Automated and tested — a recovery plan that hasn't been tested isn't a recovery plan.
High Availability
Built for the uptime a board can rely on, not a marketing claim.
Compliance
Pursuing ISO 27001, ISO 42001, and ISO 27701 certification — held to the same standards we help you meet.
The business case, not just the feature list.
Reduced compliance effort
One control implemented once satisfies every framework that shares it — not a separate program per regulation.
Improved visibility
Risk and compliance posture visible between review cycles, not just reconstructed for them.
Lower audit costs
Evidence collected continuously means less external audit time spent gathering it.
Faster reporting
Board and regulator reports generated on demand from live data, not assembled by hand.
Improved governance
Accountability traceable to a named owner, across every entity you govern.
Enterprise scalability
New entities, frameworks, and business units onboard onto an existing taxonomy, not a rebuild.
Frequently Asked Questions.
See what your compliance program looks like, verified.
Twenty minutes with our team. No slide deck — a live look at your framework mix, mapped.