Skip to content
Book a Demo
PLT.00 / THE PLATFORM

The governance, risk, and compliance operating system for regulated Africa.

AfriGRC is not a compliance checklist tool. It is the operating system underneath governance, risk management, regulatory compliance, and internal audit — twenty connected disciplines sharing one control taxonomy, evidenced continuously, and provable on demand.

Built for the people who carry the risk

Chief Information Security Officers · Chief Risk Officers · Compliance Officers · Internal Auditors · Data Protection Officers · Regulators

PLT.01 / ARCHITECTURE

Twenty modules. One connected system.

Every platform area reads from and writes to the same control taxonomy — a risk identified in the register, a control tested for an audit, and a policy attested by an employee are the same underlying record, viewed from five different disciplines.

  • GovernStructure, policy, and accountability across every entity.Governance ManagementPolicy ManagementMulti-Entity ManagementUser & Role Management
  • Manage RiskRisk scored, registered, and treated continuously.Enterprise Risk ManagementRisk RegisterVendor & Third-Party RiskBusiness Continuity
  • Ensure ComplianceControls mapped once, satisfying every framework.Regulatory ComplianceControls LibraryPrivacy ManagementAI Governance
  • AssureAudit, incidents, and evidence, closed to verified completion.Internal AuditIssue & Incident ManagementCorrective ActionsEvidence Management
  • OperateDashboards, automation, and reporting the board can trust.Executive DashboardsWorkflow AutomationReporting & AnalyticsAPI & Integrations
PLT.01.1 / THE AFRIGRC OPERATING SYSTEM

Direction flows down. Evidence flows up.

Governance sets the standard; Risk and Compliance apply it in parallel; Audit and Evidence prove it happened; the Copilot reasons over that evidence; the board sees the result.

PLT.02 / PLATFORM MODULES

Twenty modules, five disciplines, no feature you'll outgrow.

Select a module for its business benefits, key capabilities, and how a team actually uses it.

Govern

  • Governance Management

    The structural record of who owns what, decided how, and accountable to whom — across every entity you govern.

  • Policy Management

    A version-controlled policy library mapped directly to the controls it governs, with structured review and attestation.

  • Multi-Entity Management

    Group-wide governance across subsidiaries that each carry a different framework mix, rolling up to one board view.

  • User & Role Management

    Role-based access aligned to segregation-of-duties requirements, so who can see and change what is never ambiguous.

Manage Risk

  • Enterprise Risk Management

    Organizational risk scored continuously from live control data, not recalculated at the next workshop.

  • Risk Register

    The living record of every identified risk, its treatment, and its current status — not a spreadsheet that's out of date by the time it's opened.

  • Vendor & Third-Party Risk

    Vendor risk scored and monitored continuously, not reassessed once a year on a spreadsheet.

  • Business Continuity

    Business-continuity planning evidenced under ISO 22301 alongside your security program, not maintained in a separate binder.

Ensure Compliance

  • Regulatory Compliance

    Manual checklist work turned into automated evidence capture, mapped to every framework you carry.

  • Controls Library

    A single, structured repository of every control you operate — implemented once, reused everywhere it applies.

  • Privacy Management

    Data-subject rights, consent, and cross-border transfer governed to the same standard NDPA, POPIA, and GDPR each expect.

  • AI Governance

    The management-system discipline ISO 42001 expects, applied to every AI system your organization builds, buys, or deploys.

Assure

  • Internal Audit

    The full audit lifecycle — universe, planning, fieldwork, findings, and follow-up — in one workspace your auditor can access directly.

  • Issue & Incident Management

    Findings and incidents assigned to an owner and tracked against regulatory notification deadlines, from detection to closure.

  • Corrective Actions

    The closed loop between a finding and its fix — tracked to verified completion, not just marked done.

  • Evidence Management

    Continuous evidence collection from the systems you already run, held to an immutable, cryptographically timestamped standard.

Operate

  • Executive Dashboards

    Board-ready visibility into risk, compliance, and audit posture, generated on demand instead of assembled the week before.

  • Workflow Automation

    The manual handoffs between governance, risk, and compliance teams replaced with routing that just happens.

  • Reporting & Analytics

    Regulator submissions and internal reports generated from the same evidence base, formatted to whoever is asking.

  • API & Integrations

    The evidence and identity systems you already run, connected once, feeding evidence in continuously.

PLT.03 / AI COPILOT

An AI Copilot embedded in every discipline, not bolted onto one.

Ask it what's missing before an audit, what a new regulation changed, or which control already covers a requirement — every answer cites the control or evidence record behind it, not a guess.

Copilot — illustrative session

What's missing before my next CBN audit?

3 controls need fresh evidence before Nov 30:

CBN 4.2 Access Review — evidence expires in 6 days

CBN 7.1 Incident Log — no evidence linked

CBN 9.3 Vendor Assessment — evidence expires in 14 days

Every line links to its source evidence
  • Risk analysis

    Scores organizational risk from live control and evidence data, not a quarterly estimate.

  • Control recommendations

    Suggests which existing control satisfies a new framework requirement before you build one.

  • Policy generation

    Drafts a first version of a policy from your framework mix, ready for review, not from scratch.

  • Audit preparation

    Assembles the evidence package an auditor will ask for, before they ask for it.

  • Compliance gap identification

    Flags exactly which controls are short of evidence, for which framework, today.

  • Executive reporting

    Turns the current risk and compliance posture into a board-ready summary on request.

  • Evidence organization

    Links every piece of collected evidence to the control and framework it satisfies, automatically.

  • Regulatory intelligence

    Tracks regulatory change across every jurisdiction you carry and maps it to affected controls.

PLT.04 / ENTERPRISE WORKFLOW

A closed loop, not a checklist you run once a year.

Identify, Assess, Treat, Monitor, Audit, Report, Improve — and back to Identify, stronger than before.

  • Risk register populated from your sector's known risk landscape, not a blank spreadsheet.

    Every control inventoried against the frameworks it's meant to satisfy.

    Ownership assigned at the point of identification, not after the fact.

  • Risk scores recalculate as the underlying control and evidence data changes.

    Control effectiveness tested on a defined cadence, not once a year.

    Assessment results feed directly into the risk register, not a separate report.

  • Every treatment plan has a named owner and a target date.

    Overdue treatments escalate automatically, not after someone notices.

    Residual risk recalculated once treatment is verified complete.

  • Evidence streams in continuously from the systems you already run.

    Drift in one control surfaces every framework it affects, at once.

    No quarterly monitoring sprint — the system is always watching.

  • Audit findings link directly to the control and risk they originated from.

    External auditors access the same evidence your team already trusts.

    Findings aren't closed until remediation is verified, not just claimed.

  • Executive dashboards reflect the same numbers a report will show.

    Regulator submissions formatted to the specific framework being reported.

    Every figure in every report traces back to its source evidence.

  • Root-cause analysis updates the control, not just the finding.

    Lessons from one entity's audit inform every entity that shares the control.

    The next Identify cycle starts from a stronger baseline than the last.

PLT.05 / INTEGRATIONS

Connects to the tools you already run.

No rip-and-replace — evidence flows in from systems your team already trusts.

  • Identity & Access

    Provisioning and access reviews stay in sync with your identity provider.

    Azure ADOktaSSO (SAML / OIDC)
  • Productivity & Collaboration

    Evidence and notifications reach the tools your teams already work in.

    Microsoft 365Google WorkspaceSlackMicrosoft Teams
  • ITSM & Workflow

    Findings and corrective actions route into the systems that already own them.

    JiraServiceNow
  • Data & Extensibility

    Build what a pre-built connector doesn't cover yet.

    REST APIsWebhooksCSV Import / Export
PLT.06 / EXECUTIVE DASHBOARDS

The board sees what the system has held all quarter.

No deck assembled by hand the night before. Risk posture, compliance status, and audit progress, generated on demand from the same evidence base every module writes to.

See a live dashboard walkthrough

Executive summary — illustrative

Open findings
0
Controls at risk
0
Frameworks on-track
0/20

Board pack generated — Executive Summary, Q3

CBN submission package — ready for review

3 controls re-evidenced — ISO 27001 surveillance

PLT.07 / SECURITY & RELIABILITY

Secured to the same standard we help you meet.

Visit our Trust Center
  • Encryption

    Data encrypted at rest and in transit, with keys managed to the standard your own security team would expect.

  • Role-Based Access Control

    Segregation of duties enforced down to the individual permission, not just documented.

  • Multi-Factor Authentication

    Required on every account, with no exceptions carved out for convenience.

  • Audit Logs

    Every access, change, and export logged immutably — for your audit and ours.

  • Data Residency

    Regional hosting is on our infrastructure roadmap; dedicated and on-premises deployment tiers already let you keep data inside your own jurisdiction today.

  • Backups

    Automated and tested — a recovery plan that hasn't been tested isn't a recovery plan.

  • High Availability

    Built for the uptime a board can rely on, not a marketing claim.

  • Compliance

    Pursuing ISO 27001, ISO 42001, and ISO 27701 certification — held to the same standards we help you meet.

Pursuing ISO 27001Pursuing ISO 42001Pursuing ISO 27701
PLT.08 / PLATFORM BENEFITS

The business case, not just the feature list.

  • Reduced compliance effort

    One control implemented once satisfies every framework that shares it — not a separate program per regulation.

  • Improved visibility

    Risk and compliance posture visible between review cycles, not just reconstructed for them.

  • Lower audit costs

    Evidence collected continuously means less external audit time spent gathering it.

  • Faster reporting

    Board and regulator reports generated on demand from live data, not assembled by hand.

  • Improved governance

    Accountability traceable to a named owner, across every entity you govern.

  • Enterprise scalability

    New entities, frameworks, and business units onboard onto an existing taxonomy, not a rebuild.

PLT.09 / FAQ

Frequently Asked Questions.

See what your compliance program looks like, verified.

Twenty minutes with our team. No slide deck — a live look at your framework mix, mapped.

Platform — AfriGRC