Priced for the organization you are, not the seat count you have.
Five tiers, built around organizational maturity — from a single-entity SME pursuing its first certification to a multi-country banking group or a sovereign government agency. Enterprise and Government terms are scoped with you directly, because a fixed number would misrepresent the engagement.
Jump to a plan
Five tiers, organized by maturity.
Every tier includes the same evidence-linked control mapping — the difference is breadth, deployment flexibility, and how much of the compliance function AfriGRC runs for you.
Starter
Certification-grade compliance, sized for a growing team.
From [price]/month
Ideal Customer
SMEs and early-growth fintechs pursuing their first framework — typically ISO 27001 or SOC 2 — with a single entity and a lean compliance function.
Key Capabilities
- Single-framework control mapping
- Guided onboarding, live in a day
- Core evidence automation
- Standard policy library
- Email support
Recommended Industries
Platform Modules
Deployment
Cloud (shared multi-tenant)
Book a DemoSupport
Email support, next-business-day response
Growth
The full platform and guided onboarding, for teams scaling past one framework.
From [price]/month
Ideal Customer
Mid-market fintechs, insurers, and multi-product companies managing two to four frameworks across a single entity or a small group structure.
Key Capabilities
- Multi-framework control mapping
- AI Risk Engine
- Continuous controls monitoring
- Vendor & third-party risk
- Guided onboarding
- Priority support
Recommended Industries
Platform Modules
Deployment
Cloud (shared multi-tenant); dedicated tenant available
Book a DemoSupport
Priority support, same-business-day response
Business
Full framework breadth and dedicated support for an established compliance function.
From [price]/month
Ideal Customer
Banks, insurers, and enterprises running five or more frameworks across multiple entities, with an internal audit function and board-reporting requirements.
Key Capabilities
- Unlimited framework mapping
- AI Governance module
- Incident & corrective action management
- Executive dashboards & board reporting
- Dedicated Customer Success Manager
- Priority support, phone included
Recommended Industries
Platform Modules
All 20 platform modules
Frameworks Supported
Full framework library
Deployment
Cloud (dedicated tenant) or Private Cloud
Book a DemoSupport
Dedicated Customer Success Manager, phone + priority support
Enterprise
Multi-entity governance, custom deployment, and a named implementation team.
Contact Sales
Ideal Customer
Large enterprises and banking groups operating across multiple countries and subsidiaries, requiring custom deployment, SSO/SAML, and a dedicated security review.
Key Capabilities
- Multi-entity, group-wide governance
- Custom deployment — Private Cloud, on-premises, or hybrid
- SSO/SAML and advanced access controls
- Custom workflow automation
- Full API access
- Named implementation & security review team
Recommended Industries
Platform Modules
All 20 platform modules
Frameworks Supported
Full framework library
Deployment
Private Cloud, on-premises, or hybrid — customer's choice
Contact SalesSupport
Named implementation team, dedicated security review
Government
Sovereign hosting, procurement-ready documentation, and public-sector deployment terms.
Contact Sales
Ideal Customer
Government agencies, regulators, and public-sector bodies requiring in-country data sovereignty, formal procurement documentation, and long-term partnership terms.
Key Capabilities
- In-country / sovereign hosting
- On-premises and hybrid deployment options
- Procurement-ready documentation (RFP support pack)
- Multi-agency, group-wide governance
- Dedicated public-sector implementation team
- Named account and security contact
Recommended Industries
Platform Modules
All 20 platform modules
Frameworks Supported
Full framework library
Deployment
On-premises, Private Cloud, or hybrid — sovereign hosting available
Contact SalesSupport
Named account manager and dedicated security contact
Not sure which tier fits? Configure your organization.
Nine questions, answered instantly — no form submission, no data leaves your browser.
Configure your organization
Recommended Plan
Starter
Certification-grade compliance, sized for a growing team.
Why this plan
Your current configuration fits comfortably within our smallest tier.
Suggested Modules
Relevant Frameworks
Recommended Deployment
Cloud (shared multi-tenant)
Every tier, every dimension, at a glance.
Filter by category, or view the full comparison — users, modules, frameworks, AI capabilities, storage, integrations, reporting, support, SSO, API access, custom workflows, and audit features.
| Feature | Starter | Growth | Business | Enterprise | Government |
|---|---|---|---|---|---|
| Access & Scale | |||||
| Users | Up to 10 | Up to 50 | Up to 250 | Unlimited | Unlimited |
| Platform modules | 5 core modules | 10 modules | All 20 modules | All 20 modules | All 20 modules |
| Compliance frameworks | 1 framework | Up to 4 frameworks | Unlimited | Unlimited | Unlimited |
| Multi-entity / group structure | Up to 3 entities | Included | Included | Included | |
| AI & Automation | |||||
| AI Risk Engine | Included | Included | Included | Included | |
| AI Governance module | Included | Included | Included | ||
| Continuous controls monitoring | Included | Included | Included | Included | |
| Custom workflow automation | Limited | Included | Included | ||
| Data & Integrations | |||||
| Evidence storage | Standard | Extended | Extended | Custom retention terms | Custom retention, sovereign hosting |
| Integrations | Core integrations | Full integration library | Full integration library | Full integration library + custom | Full integration library + custom |
| API access | Read-only | Included | Included | Included | |
| Reporting & Audit | |||||
| Reporting & dashboards | Standard reports | Executive dashboards | Executive dashboards | Custom board reporting | Custom board & regulator reporting |
| Audit management | Limited | Included | Included | Included | |
| Evidence & audit readiness | Included | Included | Included | Included | Included |
| Support & Deployment | |||||
| Support level | Priority email | Dedicated CSM | Named implementation team | Named account + security contact | |
| SSO / SAML | Included | Included | Included | ||
| Deployment model | Cloud | Cloud | Cloud or Private Cloud | Private Cloud, on-prem, or hybrid | On-prem, Private Cloud, or hybrid |
The operational value, made visible — not a fabricated percentage.
Every organization's baseline is different, so we don't publish a universal savings figure. Configure the estimator below with your own numbers to see which improvements apply to your scenario.
Improved audit readiness
Evidence stays current between cycles instead of assembled under deadline pressure.
Reduced manual compliance effort
A control mapped once is reused across every framework that requires it.
Better executive visibility
Governance, risk, and compliance posture roll into one view the board actually reviews.
Faster reporting
Board and regulator reports generate from evidence you already have, not a manual assembly exercise.
Improved governance
Every control and finding is traceable to a named owner, sitewide.
Better risk visibility
Vendor and organizational risk scored continuously, not just at renewal or annual review.
Increased operational efficiency
One system of record replaces the spreadsheets and point tools most compliance teams stitch together.
250
2
2
2
10
4
Operational improvements for this scenario
Improved audit readiness
Evidence collected continuously rather than assembled from scratch before each audit cycle.
Example — With 2 audits a year, evidence stays continuously ready between cycles instead of a scramble before each one.
Reduced manual compliance effort
A control mapped once is shared across every framework that requires it, instead of being re-evidenced per framework.
Example — Managing 2 frameworks means overlapping controls are mapped once, not re-collected per framework.
Better executive visibility
One dashboard rolls governance, risk, and compliance posture into the view leadership actually reviews.
Example — Across 2 business units, one roll-up view replaces separately assembled unit-level reports.
Faster reporting
Board and regulator reports generate on demand from live evidence, not a manual quarterly assembly exercise.
Example — Reports draw from evidence already collected, rather than being assembled from scratch each reporting cycle.
Improved governance
Accountability for every control and finding is traceable to a named owner, sitewide.
Example — 4 risk assessments a year stay comparable over time, scored on the same continuous basis rather than reset each cycle.
Better risk visibility
Vendor and third-party risk scored continuously, rather than reviewed only at renewal.
Example — 10 vendors monitored continuously, instead of reviewed only at contract renewal.
Increased operational efficiency
One system of record replaces the spreadsheets and point tools most compliance teams stitch together.
Example — At 250 employees, a single system of record scales with headcount instead of adding a tool per team.
Qualitative, illustrative estimates based on the scenario you configure above — not a guarantee of savings or performance. No data you enter here is stored or transmitted.
Where AfriGRC runs is your decision, not ours.
Business, Enterprise, and Government tiers can mix and match deployment model to match data-residency and procurement requirements.
Cloud
Shared multi-tenant hosting on AfriGRC's managed infrastructure — the fastest path to live, with no infrastructure to manage.
Best for — SME and mid-market teams who want to be live in days, not months.
- Fully managed by AfriGRC
- Automatic updates and patching
- In-region hosting available
- Fastest time to go-live
Private Cloud
A dedicated tenant on AfriGRC's infrastructure, isolated from other customers, with the same managed operations.
Best for — Regulated organizations that need tenant isolation without operating their own infrastructure.
- Dedicated, isolated tenant
- Fully managed by AfriGRC
- Custom retention & backup terms
- In-region hosting
On-Premises
AfriGRC deployed inside your own data center or sovereign cloud environment, under your infrastructure team's operational control.
Best for — Government agencies and banks with data-sovereignty mandates that require infrastructure to stay in-house.
- Runs inside your infrastructure
- Full data sovereignty
- Your team controls operations
- Named implementation support
Hybrid
Core platform hosted in your environment, with select services — like AI model updates — delivered from AfriGRC's managed cloud.
Best for — Enterprises balancing strict data-residency requirements against the operational load of running everything in-house.
- Data stays in your environment
- Managed AI/service updates
- Flexible per-module placement
- Named implementation support
Built to move through your procurement process, not around it.
AfriGRC supports enterprise and public-sector procurement directly — from first call to a named Customer Success relationship, not a one-time sale.
- 01
Discovery Call
A scoping conversation to understand your framework mix, entity structure, and current compliance maturity.No pre-built package pitched before we understand your risk landscape.
Framework mix and entity structure captured directly from your team.
Sets the agenda for the product demonstration that follows.
- 02
Product Demonstration
A live walkthrough of the modules relevant to your organization, not a generic feature tour.Scoped to the solution areas identified in discovery.
Shown against a configuration close to your actual framework mix.
Your compliance, risk, and IT stakeholders see the same session.
- 03
Requirements Assessment
Your framework mix, integrations, and deployment requirements documented against the platform.Existing policies, controls, and evidence inventoried.
Integration and data-residency requirements confirmed in writing.
Forms the baseline the proposal is scoped against.
- 04
Pilot
A scoped pilot with a subset of controls or a single business unit, for organizations that want to validate fit before a full commitment.Not required for every engagement — offered where a committee-based buyer needs it.
Scoped to a defined control set or business unit, with a fixed timeframe.
Findings feed directly into the proposal, not discarded afterward.
- 05
Proposal & Pricing
A written proposal scoped to your entity count, framework mix, and deployment model.Pricing reflects the assessment, not a generic tier card.
Deployment model and support level confirmed before contracting begins.
Enterprise and Government proposals route through the named account team.
- 06
Security Review
AfriGRC's own security documentation — SOC 2/ISO 27001 evidence, sub-processor list, DPA — supplied for your security and procurement teams.The same evidence-forward standard AfriGRC holds its customers to.
RFP support pack available for public-sector and bank procurement teams.
Runs in parallel with contracting, not as a blocking sequential step.
- 07
Procurement
Contracting, terms, and any RFP or public-sector procurement process your organization requires.Government and bank procurement cycles are supported directly, not worked around.
Downloadable, shareable collateral supplied so an internal champion can advance approval without another call.
Terms scoped to match your organization's procurement cycle, not a fixed annual default.
- 08
Implementation
Controls, policies, and integrations go live, following the same Scope → Connect → Map & Migrate → Go Live process used across the platform.Existing policies and past audit evidence imported and mapped, not re-collected.
Your team and any advisors have access from day one.
Timeline scoped during Requirements Assessment, not estimated after signing.
- 09
Customer Success Onboarding
A named Customer Success contact takes over for ongoing support, framework updates, and account growth.Continuity from the sales and implementation team, not a cold handoff.
Regulatory change tracked and mapped to your controls on an ongoing basis.
The relationship a long-term partnership, not a one-time deployment.
Beyond the platform, when you need it.
Scoped and quoted separately from your subscription — sized to what your team actually needs, not bundled by default.
Implementation
Controls, policies, and integrations configured and live, run alongside your team rather than handed over as a manual.
Migration
Existing policies, controls, and historical audit evidence imported and mapped from spreadsheets or another platform.
Training
Role-based onboarding for compliance, risk, and audit teams — and for the auditors and reviewers who need read access.
Consulting
Framework selection, control design, and audit-readiness advisory from practitioners who've run the process, not just built the software.
Managed Compliance
AfriGRC's team operates day-to-day evidence collection and control monitoring on your behalf, for organizations without a standing compliance function.
Frequently Asked Questions.
Talk to us before you commit to a tier.
A twenty-minute scoping call tells you more than any comparison table can.