Skip to content
Book a Demo
RES.00 / RESOURCES & KNOWLEDGE HUB

Governance, risk, and compliance knowledge, built for Africa first.

Guides, frameworks, learning paths, and research for every role in a compliance program — compliance officers, risk managers, privacy officers, auditors, developers, and the students building toward this field.

16

Knowledge Categories

From governance to AI regulation.

19+

Frameworks Covered

African regulatory law and global standards.

8

Learning Paths

Guided journeys by role.

26+

Resources In Development

Growing library, publishing in stages.

RES.02 / ENTERPRISE RESOURCE FINDER

Tell us your context. We'll surface what's relevant.

Every selection is optional — answer as much or as little as you want.

Select any combination above — the more you tell us, the more specific the match.

RES.03 / FEATURED RESOURCES

Where to start.

A rotating selection across formats — white papers, playbooks, guides, and more.

White Paper

ISO 27001 Readiness: A Board-Level Briefing

What a certification decision actually requires, framed for the people who approve the budget.

18 minEnglishBeginner

Coming Soon

eBook

The State of GRC in Africa

A continent-wide look at how regulated institutions are building compliance programs today.

35 minEnglishBeginner

Coming Soon

Playbook

The CBN Cybersecurity Audit Playbook

A control-by-control walkthrough for preparing a Nigerian bank for its next CBN examination.

25 minEnglishIntermediate

Coming Soon

RES.04 / ADVANCED SEARCH

Search and filter the full library.

Keyword search, plus eight facets — category, content type, framework, industry, country, difficulty, reading time, and language. 12 topics tagged across 26 resources.

26 results

  • White Paper

    ISO 27001 Readiness: A Board-Level Briefing

    What a certification decision actually requires, framed for the people who approve the budget.

    18 minEnglishBeginner

    Coming Soon

  • eBook

    The State of GRC in Africa

    A continent-wide look at how regulated institutions are building compliance programs today.

    35 minEnglishBeginner

    Coming Soon

  • Playbook

    The CBN Cybersecurity Audit Playbook

    A control-by-control walkthrough for preparing a Nigerian bank for its next CBN examination.

    25 minEnglishIntermediate

    Coming Soon

  • Template

    Data Protection Impact Assessment Template

    A structured DPIA template mapped to NDPA, POPIA, and GDPR requirements together.

    10 minEnglishIntermediate

    Coming Soon

  • Checklist

    Third-Party Vendor Risk Assessment Checklist

    The questions worth asking before a vendor touches your regulated data.

    8 minEnglishBeginner

    Coming Soon

  • Guide

    Implementing ISO 42001: An AI Management System Guide

    How to stand up an AI management system without slowing down the team shipping the AI.

    30 minEnglishAdvanced

    Coming Soon

  • Guide

    Enterprise Risk Scoring Methodology

    A structured, weighted scoring approach for turning identified risks into a comparable, board-ready number.

    18 minEnglishIntermediate

    Coming Soon

  • Reference Document

    Cross-Framework Control Mapping Reference

    How one control satisfies ISO 27001, SOC 2, and CBN requirements at once — mapped explicitly.

    15 minEnglishIntermediate

    Coming Soon

  • Implementation Framework

    The Continuous Controls Monitoring Framework

    A structured approach to monitoring controls continuously instead of at each audit cycle.

    22 minEnglishAdvanced

    Coming Soon

  • Assessment Tool

    GRC Program Maturity Self-Assessment

    A structured self-scoring exercise across five maturity stages — see the Enterprise Maturity Timeline on our Trust Centre for the same model.

    12 minEnglishBeginner

    Coming Soon

  • Case Study

    How a Tier-1 Nigerian Bank Cut Audit Prep to Nine Days

    Illustrative — pending a named, permissioned customer story.

    10 minEnglishIntermediate

    Coming Soon

  • Research Paper

    AI Risk Scoring in Regulated Financial Systems

    Research into evidence-linked AI risk scoring for institutions that cannot afford a black box.

    40 minEnglishAdvanced

    Coming Soon

  • Video

    NDPA in Ten Minutes: What Changed From NDPR

    A short explainer on Nigeria's current data protection law and what it means for existing programs.

    10 minEnglishBeginner

    Coming Soon

  • Webinar

    Continuous Compliance: Moving Beyond the Annual Audit

    A live session on shifting from point-in-time evidence to continuous control monitoring.

    45 minEnglishIntermediate

    Coming Soon

  • Podcast

    GRC Leaders: Building Compliance Programs From the Ground Up

    Conversations with compliance and risk leaders building programs across African markets.

    30 minEnglishBeginner

    Coming Soon

  • Infographic

    Where ISO 27001, SOC 2, and CBN Requirements Overlap

    A single visual showing exactly which controls are shared across three major frameworks.

    5 minEnglishBeginner

    Coming Soon

  • Playbook

    The Regulated-Sector Incident Response Playbook

    A response plan structured around regulator notification deadlines, not just technical containment.

    20 minEnglishIntermediate

    Coming Soon

  • Guide

    Designing a Policy Review Cycle That Actually Runs

    A practical approach to scheduled review and attestation that doesn't rely on email reminders.

    14 minEnglishBeginner

    Coming Soon

  • Template

    Business Continuity Plan Template

    A BCP structure aligned to ISO 22301, ready to adapt to your entity structure.

    12 minEnglishIntermediate

    Coming Soon

  • Guide

    Guide de Conformité à la Protection des Données pour l'Afrique

    Un aperçu des principales lois africaines de protection des données, en français.

    20 minFrenchBeginner

    Coming Soon

  • Checklist

    Access Control & Segregation of Duties Checklist

    A checklist for reviewing role-based access before your next audit cycle.

    9 minEnglishBeginner

    Coming Soon

  • Reference Document

    AfriGRC API: Evidence Integration Reference

    How to stream evidence from your own systems into AfriGRC's evidence store via the API.

    25 minEnglishAdvanced

    Coming Soon

  • White Paper

    Choosing the Right Certification Pathway

    ISO 27001, SOC 2, or both — a framework for deciding what your customers actually require.

    16 minEnglishIntermediate

    Coming Soon

  • eBook

    NAICOM Solvency Reporting: A Practical Guide

    Preparing solvency and risk reports insurers can defend to NAICOM without a quarter of spreadsheet work.

    22 minEnglishIntermediate

    Coming Soon

  • Video

    GRC Fundamentals: A Training Course for New Compliance Hires

    A structured onboarding course covering the vocabulary and workflow of a modern GRC program.

    60 minEnglishBeginner

    Coming Soon

  • Guide

    Certification-Grade Compliance at SME Scale

    What a small team can realistically build toward ISO 27001 in a single quarter.

    15 minEnglishBeginner

    Coming Soon

RES.05 / LEARNING PATHS

A guided journey for every role.

Select a path to see its full timeline and the resources that support it.

Executives

Board-level fluency in governance posture, risk exposure, and what to ask your compliance team.

4 steps · ~2 hours

Compliance Officers

Framework mapping, evidence collection, and running a program that scales past one framework.

5 steps · ~4 hours

Risk Managers

Risk identification, scoring methodology, and treatment planning that holds up to scrutiny.

5 steps · ~3.5 hours

Privacy Officers

Data protection law across African jurisdictions, DPIAs, and cross-border transfer.

5 steps · ~4 hours

Auditors

Planning an audit universe, testing controls, and tracking findings to closure.

4 steps · ~3 hours

Developers

API integration, evidence automation, and building against AfriGRC's platform.

4 steps · ~3 hours

Security Teams

Security architecture, incident response, and continuous controls monitoring.

5 steps · ~4 hours

Students

Foundational GRC vocabulary and concepts for anyone starting a career in governance, risk, or compliance.

4 steps · ~2.5 hours

Executives path — 4 steps, ~2 hours

  • 01

    Governance Fundamentals

    What board-level oversight of a GRC program actually requires.
  • 02

    Reading a Risk Report

    How to interpret a risk register and heat map without a translator.
  • 03

    The Regulator's Perspective

    What examiners and auditors look for first.
  • 04

    Board Reporting Cadence

    Building a reporting rhythm the board can actually rely on.

Recommended because you're exploring the Executives path

White Paper

ISO 27001 Readiness: A Board-Level Briefing

What a certification decision actually requires, framed for the people who approve the budget.

18 minEnglishBeginner

Coming Soon

Assessment Tool

GRC Program Maturity Self-Assessment

A structured self-scoring exercise across five maturity stages — see the Enterprise Maturity Timeline on our Trust Centre for the same model.

12 minEnglishBeginner

Coming Soon

Podcast

GRC Leaders: Building Compliance Programs From the Ground Up

Conversations with compliance and risk leaders building programs across African markets.

30 minEnglishBeginner

Coming Soon

RES.06 / COMPLIANCE LIBRARY

Every framework AfriGRC tracks, browsable.

Filter by topic, country, status, and industry — or search directly. The same data that backs /frameworks.

19 results

  • Regulatory

    Nigeria

    Nigeria Data Protection Act

    Data protection

    AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards
    View NDPA
  • Regulatory

    Kenya

    Kenya Data Protection Act

    Data protection

    View Kenya DPA
  • Regulatory

    Ghana

    Ghana Data Protection Act

    Data protection

    View Ghana DPA
  • Regulatory

    South Africa

    Protection of Personal Information Act

    Data protection

    Security & Data ResidencyTrust CenterPolicy Management
    View POPIA
  • Regulatory

    Egypt

    Personal Data Protection Law

    Data protection

    View Egypt PDPL
  • Regulatory

    Rwanda

    Data Protection and Privacy Law

    Data protection

    View Rwanda DPPL
  • Third-party certified

    Global

    ISO/IEC 27001

    Information security management

    AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards
    View ISO 27001
  • Third-party certified

    Global

    ISO/IEC 27701

    Privacy information management

    Vendor & Third-Party RiskEvidence Automation & IntegrationsSecurity & Data Residency
    View ISO 27701
  • Third-party certified

    Global

    ISO/IEC 42001

    AI management systems

    View ISO 42001
  • Third-party certified

    Global

    ISO/IEC 22301

    Business continuity management

    AI Risk EngineIncident & Issue ManagementContinuous Controls Monitoring
    View ISO 22301
  • Third-party certified

    Global

    ISO/IEC 20000-1

    IT service management

    Vendor & Third-Party RiskContinuous Controls MonitoringAudit Management
    View ISO 20000-1
  • Third-party certified

    Global

    SOC 2

    Trust services criteria

    Compliance AutomationEvidence Automation & IntegrationsTrust Center
    View SOC 2
  • Third-party certified

    Global

    PCI DSS

    Payment card data security

    AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards
    View PCI DSS
  • Regulatory

    European Union

    General Data Protection Regulation

    Data protection

    Compliance AutomationEvidence Automation & IntegrationsTrust Center
    View GDPR
  • Self-attested

    Global

    NIST Cybersecurity Framework

    Cybersecurity risk management

    AI Risk EngineIncident & Issue ManagementContinuous Controls Monitoring
    View NIST CSF
  • Self-attested

    Global

    CIS Controls

    Cybersecurity best practices

    Vendor & Third-Party RiskContinuous Controls MonitoringAudit Management
    View CIS Controls
  • Regulatory

    Nigeria — Banking

    CBN Cybersecurity & Prudential Guidelines

    Banking cybersecurity & prudential risk

    AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards
    View CBN
  • Regulatory

    Nigeria — Insurance

    NAICOM Guidelines

    Insurance risk & solvency

    AI Risk EngineReporting & Board DashboardsPolicy Management
    View NAICOM
  • Regulatory

    Nigeria — Telecom

    NCC Regulatory Framework

    Telecom compliance & subscriber data

    Continuous Controls MonitoringIncident & Issue ManagementSecurity & Data Residency
    View NCC
RES.07 / AI GOVERNANCE LIBRARY

Governing AI, not just building it.

Seven topics spanning how AfriGRC — and the platform it builds — thinks about AI governance, risk, and regulation.

  • AI Governance

    The management-system discipline for how an organization builds, buys, and deploys AI — inventory, oversight, and accountability.

    See ISO 42001
  • Responsible AI

    Human oversight, explainability, and transparency — see how AfriGRC applies these principles to its own AI on the Trust Centre.

    See Responsible AI at AfriGRC
  • AI Risk

    Assessing and scoring the risk an AI system introduces before it ships, not after an incident.

  • AI Compliance

    Mapping AI-specific obligations across the jurisdictions an AI system operates in.

  • AI Security

    Securing AI systems to the same standard as the rest of the platform — not a separate, less-governed layer.

  • Model Governance

    Lifecycle and change-management discipline applied to a model, from training through retirement.

  • AI Regulations

    Tracking how AI-specific regulation is emerging globally and across African jurisdictions.

RES.08 / INTERACTIVE KNOWLEDGE EXPLORER

Navigate the library visually.

Pick a dimension — topic, industry, or framework — then a value within it.

Guide

Enterprise Risk Scoring Methodology

A structured, weighted scoring approach for turning identified risks into a comparable, board-ready number.

18 minEnglishIntermediate

Coming Soon

Research Paper

AI Risk Scoring in Regulated Financial Systems

Research into evidence-linked AI risk scoring for institutions that cannot afford a black box.

40 minEnglishAdvanced

Coming Soon

RES.09 / LEARNING PROGRESS TRACKER

Track your own path through the library.

A local, in-browser demonstration — nothing here is saved to an account yet.

Try it — click a resource to update its status

Completed (0)

Nothing here yet.

In Progress (0)

Nothing here yet.

Recommended Next (6)

  • ISO 27001 Readiness: A Board-Level Briefing
  • The State of GRC in Africa
  • The CBN Cybersecurity Audit Playbook
  • Data Protection Impact Assessment Template
  • Third-Party Vendor Risk Assessment Checklist
  • Implementing ISO 42001: An AI Management System Guide

Bookmarks (0)

Nothing here yet.

RES.10 / DOWNLOADS CENTRE

Templates, policies, and tools, in one place.

Publishing in stages — request anything below directly via the Resource Request Portal.

  • DOCX bundle

    Policy Template Pack

    Starter templates for the policies most GRC programs need first.

    Not yet available — request below

  • XLSX

    Risk Register Template

    A structured risk register template ready to adapt to your taxonomy.

    Not yet available — request below

  • DOCX

    Acceptable Use Policy

    A baseline acceptable-use policy mapped to common control frameworks.

    Not yet available — request below

  • DOCX

    Data Retention Policy

    A retention policy structure aligned to African data protection law.

    Not yet available — request below

  • PDF

    SOC 2 Readiness Checklist

    The trust services criteria, broken into a working checklist.

    Not yet available — request below

  • PDF

    Vendor Onboarding Checklist

    What to confirm before a new vendor touches regulated data.

    Not yet available — request below

  • XLSX

    GRC Maturity Assessment

    A structured self-scoring tool across five maturity stages.

    Not yet available — request below

  • XLSX

    Framework Gap Analysis Tool

    Identify control gaps against any framework in AfriGRC's library.

    Not yet available — request below

  • PDF

    African Regulatory Glossary

    Plain-language definitions for the region's compliance vocabulary.

    Not yet available — request below

  • PDF

    Framework Comparison Reference

    A side-by-side comparison of the frameworks most AfriGRC customers carry.

    Not yet available — request below

RES.11 / UPCOMING EVENTS & WEBINARS

Live sessions, when they're scheduled.

Webinars, training, workshops, conferences, office hours, and certification sessions — subscribe below to hear the moment a date is confirmed.

  • Webinar

    Continuous Compliance: Moving Beyond the Annual Audit

    A live session on shifting from point-in-time evidence to continuous monitoring.

    Schedule to be announced · Virtual

    Details to be announced

  • Webinar

    ISO 42001 in Practice: Governing AI You Already Ship

    What an AI management system looks like once it's actually running.

    Schedule to be announced · Virtual

    Details to be announced

  • Training

    GRC Fundamentals for New Compliance Hires

    A structured onboarding session for teams building out their compliance function.

    Schedule to be announced · Virtual

    Details to be announced

  • Workshop

    Framework Mapping Workshop

    Hands-on session mapping your control set across the frameworks you carry.

    Schedule to be announced · Virtual

    Details to be announced

  • Conference

    State of GRC in Africa

    AfriGRC's annual gathering of compliance, risk, and security leaders across the continent.

    Schedule to be announced · In-person — Lagos

    Details to be announced

  • Office Hours

    Security & Trust Office Hours

    Open Q&A with AfriGRC's security team — bring your architecture questions.

    Schedule to be announced · Virtual

    Details to be announced

  • Certification Session

    ISO 27001 Certification Readiness Session

    A guided walkthrough of what a certification audit actually examines.

    Schedule to be announced · Virtual

    Details to be announced

RES.12 / NEWSLETTER & COMMUNITY

Stay current, and stay connected.

Knowledge Alerts

New guides, regulatory updates, and event invitations — direct to your inbox, as they publish.

  • Community Updates

    Peer discussion with other compliance and risk practitioners across Africa.

    Get in Touch
  • Event Notifications

    Be first to know when a webinar, workshop, or training session is scheduled.

    See Upcoming Events
  • Join the Conversation

    Follow AfriGRC for regulatory updates and platform announcements.

    Connect on LinkedIn
RES.13 / RESOURCE REQUEST PORTAL

Don't see what you need? Ask for it.

Template, framework coverage, a guide, training, or a research topic — tell us and it's routed to the team building the library.

Step 1 of 2

What would you like to see?

Tell us the type of resource and the topic.

RES.14 / FAQ

Frequently Asked Questions.

RES.15 / GET STARTED

Put this knowledge to work in your own program.

See the platform live, or bring your team into the conversation.

Resources & Knowledge Hub — AfriGRC