Governance, risk, and compliance knowledge, built for Africa first.
Guides, frameworks, learning paths, and research for every role in a compliance program — compliance officers, risk managers, privacy officers, auditors, developers, and the students building toward this field.
16
Knowledge Categories
From governance to AI regulation.
19+
Frameworks Covered
African regulatory law and global standards.
8
Learning Paths
Guided journeys by role.
26+
Resources In Development
Growing library, publishing in stages.
Sixteen categories, one library.
Every category routes to the same filterable library below — pick a starting point, or search directly.
Governance
Board structure, accountability, and decision rights.
1 resourcesRisk
Identification, scoring, and treatment of organizational risk.
1 resourcesCompliance
Framework mapping, evidence, and regulator readiness.
4 resourcesPrivacy
Data protection, consent, and cross-border transfer.
2 resourcesCybersecurity
Security architecture, controls, and operations.
3 resourcesAI Governance
Responsible AI, model oversight, and AI risk.
2 resourcesAudit
Internal and external audit planning and evidence.
1 resourcesVendor Risk
Third-party due diligence and continuous monitoring.
1 resourcesBusiness Continuity
Continuity planning and disaster recovery.
1 resourcesPolicy Management
Policy lifecycle, review, and attestation.
1 resourcesRegulatory Updates
What changed, and what it means for your program.
2 resourcesImplementation Guides
Step-by-step rollout and adoption playbooks.
2 resourcesTraining
Structured learning for every GRC role.
1 resourcesCertifications
Preparing for and maintaining formal certification.
1 resourcesDeveloper Resources
API references and integration guides.
1 resourcesIndustry Insights
Sector-specific risk and regulatory context.
2 resources
Tell us your context. We'll surface what's relevant.
Every selection is optional — answer as much or as little as you want.
Select any combination above — the more you tell us, the more specific the match.
Where to start.
A rotating selection across formats — white papers, playbooks, guides, and more.
White Paper
ISO 27001 Readiness: A Board-Level Briefing
What a certification decision actually requires, framed for the people who approve the budget.
Coming Soon
eBook
The State of GRC in Africa
A continent-wide look at how regulated institutions are building compliance programs today.
Coming Soon
Playbook
The CBN Cybersecurity Audit Playbook
A control-by-control walkthrough for preparing a Nigerian bank for its next CBN examination.
Coming Soon
Search and filter the full library.
Keyword search, plus eight facets — category, content type, framework, industry, country, difficulty, reading time, and language. 12 topics tagged across 26 resources.
26 results
White Paper
ISO 27001 Readiness: A Board-Level Briefing
What a certification decision actually requires, framed for the people who approve the budget.
18 minEnglishBeginnerComing Soon
eBook
The State of GRC in Africa
A continent-wide look at how regulated institutions are building compliance programs today.
35 minEnglishBeginnerComing Soon
Playbook
The CBN Cybersecurity Audit Playbook
A control-by-control walkthrough for preparing a Nigerian bank for its next CBN examination.
25 minEnglishIntermediateComing Soon
Template
Data Protection Impact Assessment Template
A structured DPIA template mapped to NDPA, POPIA, and GDPR requirements together.
10 minEnglishIntermediateComing Soon
Checklist
Third-Party Vendor Risk Assessment Checklist
The questions worth asking before a vendor touches your regulated data.
8 minEnglishBeginnerComing Soon
Guide
Implementing ISO 42001: An AI Management System Guide
How to stand up an AI management system without slowing down the team shipping the AI.
30 minEnglishAdvancedComing Soon
Guide
Enterprise Risk Scoring Methodology
A structured, weighted scoring approach for turning identified risks into a comparable, board-ready number.
18 minEnglishIntermediateComing Soon
Reference Document
Cross-Framework Control Mapping Reference
How one control satisfies ISO 27001, SOC 2, and CBN requirements at once — mapped explicitly.
15 minEnglishIntermediateComing Soon
Implementation Framework
The Continuous Controls Monitoring Framework
A structured approach to monitoring controls continuously instead of at each audit cycle.
22 minEnglishAdvancedComing Soon
Assessment Tool
GRC Program Maturity Self-Assessment
A structured self-scoring exercise across five maturity stages — see the Enterprise Maturity Timeline on our Trust Centre for the same model.
12 minEnglishBeginnerComing Soon
Case Study
How a Tier-1 Nigerian Bank Cut Audit Prep to Nine Days
Illustrative — pending a named, permissioned customer story.
10 minEnglishIntermediateComing Soon
Research Paper
AI Risk Scoring in Regulated Financial Systems
Research into evidence-linked AI risk scoring for institutions that cannot afford a black box.
40 minEnglishAdvancedComing Soon
Video
NDPA in Ten Minutes: What Changed From NDPR
A short explainer on Nigeria's current data protection law and what it means for existing programs.
10 minEnglishBeginnerComing Soon
Webinar
Continuous Compliance: Moving Beyond the Annual Audit
A live session on shifting from point-in-time evidence to continuous control monitoring.
45 minEnglishIntermediateComing Soon
Podcast
GRC Leaders: Building Compliance Programs From the Ground Up
Conversations with compliance and risk leaders building programs across African markets.
30 minEnglishBeginnerComing Soon
Infographic
Where ISO 27001, SOC 2, and CBN Requirements Overlap
A single visual showing exactly which controls are shared across three major frameworks.
5 minEnglishBeginnerComing Soon
Playbook
The Regulated-Sector Incident Response Playbook
A response plan structured around regulator notification deadlines, not just technical containment.
20 minEnglishIntermediateComing Soon
Guide
Designing a Policy Review Cycle That Actually Runs
A practical approach to scheduled review and attestation that doesn't rely on email reminders.
14 minEnglishBeginnerComing Soon
Template
Business Continuity Plan Template
A BCP structure aligned to ISO 22301, ready to adapt to your entity structure.
12 minEnglishIntermediateComing Soon
Guide
Guide de Conformité à la Protection des Données pour l'Afrique
Un aperçu des principales lois africaines de protection des données, en français.
20 minFrenchBeginnerComing Soon
Checklist
Access Control & Segregation of Duties Checklist
A checklist for reviewing role-based access before your next audit cycle.
9 minEnglishBeginnerComing Soon
Reference Document
AfriGRC API: Evidence Integration Reference
How to stream evidence from your own systems into AfriGRC's evidence store via the API.
25 minEnglishAdvancedComing Soon
White Paper
Choosing the Right Certification Pathway
ISO 27001, SOC 2, or both — a framework for deciding what your customers actually require.
16 minEnglishIntermediateComing Soon
eBook
NAICOM Solvency Reporting: A Practical Guide
Preparing solvency and risk reports insurers can defend to NAICOM without a quarter of spreadsheet work.
22 minEnglishIntermediateComing Soon
Video
GRC Fundamentals: A Training Course for New Compliance Hires
A structured onboarding course covering the vocabulary and workflow of a modern GRC program.
60 minEnglishBeginnerComing Soon
Guide
Certification-Grade Compliance at SME Scale
What a small team can realistically build toward ISO 27001 in a single quarter.
15 minEnglishBeginnerComing Soon
A guided journey for every role.
Select a path to see its full timeline and the resources that support it.
Executives
Board-level fluency in governance posture, risk exposure, and what to ask your compliance team.
4 steps · ~2 hours
Compliance Officers
Framework mapping, evidence collection, and running a program that scales past one framework.
5 steps · ~4 hours
Risk Managers
Risk identification, scoring methodology, and treatment planning that holds up to scrutiny.
5 steps · ~3.5 hours
Privacy Officers
Data protection law across African jurisdictions, DPIAs, and cross-border transfer.
5 steps · ~4 hours
Auditors
Planning an audit universe, testing controls, and tracking findings to closure.
4 steps · ~3 hours
Developers
API integration, evidence automation, and building against AfriGRC's platform.
4 steps · ~3 hours
Security Teams
Security architecture, incident response, and continuous controls monitoring.
5 steps · ~4 hours
Students
Foundational GRC vocabulary and concepts for anyone starting a career in governance, risk, or compliance.
4 steps · ~2.5 hours
Executives path — 4 steps, ~2 hours
- 01
Governance Fundamentals
What board-level oversight of a GRC program actually requires. - 02
Reading a Risk Report
How to interpret a risk register and heat map without a translator. - 03
The Regulator's Perspective
What examiners and auditors look for first. - 04
Board Reporting Cadence
Building a reporting rhythm the board can actually rely on.
Recommended because you're exploring the Executives path
White Paper
ISO 27001 Readiness: A Board-Level Briefing
What a certification decision actually requires, framed for the people who approve the budget.
Coming Soon
Assessment Tool
GRC Program Maturity Self-Assessment
A structured self-scoring exercise across five maturity stages — see the Enterprise Maturity Timeline on our Trust Centre for the same model.
Coming Soon
Podcast
GRC Leaders: Building Compliance Programs From the Ground Up
Conversations with compliance and risk leaders building programs across African markets.
Coming Soon
Every framework AfriGRC tracks, browsable.
Filter by topic, country, status, and industry — or search directly. The same data that backs /frameworks.
19 results
- Regulatory
Nigeria
Nigeria Data Protection Act
Data protection
View NDPA →AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards - Regulatory
South Africa
Protection of Personal Information Act
Data protection
View POPIA →Security & Data ResidencyTrust CenterPolicy Management - Third-party certified
Global
ISO/IEC 27001
Information security management
View ISO 27001 →AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards - Third-party certified
Global
ISO/IEC 27701
Privacy information management
View ISO 27701 →Vendor & Third-Party RiskEvidence Automation & IntegrationsSecurity & Data Residency - Third-party certified
Global
ISO/IEC 22301
Business continuity management
View ISO 22301 →AI Risk EngineIncident & Issue ManagementContinuous Controls Monitoring - Third-party certified
Global
ISO/IEC 20000-1
IT service management
View ISO 20000-1 →Vendor & Third-Party RiskContinuous Controls MonitoringAudit Management - Third-party certified
Global
SOC 2
Trust services criteria
View SOC 2 →Compliance AutomationEvidence Automation & IntegrationsTrust Center - Third-party certified
Global
PCI DSS
Payment card data security
View PCI DSS →AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards - Regulatory
European Union
General Data Protection Regulation
Data protection
View GDPR →Compliance AutomationEvidence Automation & IntegrationsTrust Center - Self-attested
Global
NIST Cybersecurity Framework
Cybersecurity risk management
View NIST CSF →AI Risk EngineIncident & Issue ManagementContinuous Controls Monitoring - Self-attested
Global
CIS Controls
Cybersecurity best practices
View CIS Controls →Vendor & Third-Party RiskContinuous Controls MonitoringAudit Management - Regulatory
Nigeria — Banking
CBN Cybersecurity & Prudential Guidelines
Banking cybersecurity & prudential risk
View CBN →AI Risk EngineContinuous Controls MonitoringReporting & Board Dashboards - Regulatory
Nigeria — Insurance
NAICOM Guidelines
Insurance risk & solvency
View NAICOM →AI Risk EngineReporting & Board DashboardsPolicy Management - Regulatory
Nigeria — Telecom
NCC Regulatory Framework
Telecom compliance & subscriber data
View NCC →Continuous Controls MonitoringIncident & Issue ManagementSecurity & Data Residency
Governing AI, not just building it.
Seven topics spanning how AfriGRC — and the platform it builds — thinks about AI governance, risk, and regulation.
AI Governance
The management-system discipline for how an organization builds, buys, and deploys AI — inventory, oversight, and accountability.
See ISO 42001 →Responsible AI
Human oversight, explainability, and transparency — see how AfriGRC applies these principles to its own AI on the Trust Centre.
See Responsible AI at AfriGRC →AI Risk
Assessing and scoring the risk an AI system introduces before it ships, not after an incident.
AI Compliance
Mapping AI-specific obligations across the jurisdictions an AI system operates in.
AI Security
Securing AI systems to the same standard as the rest of the platform — not a separate, less-governed layer.
Model Governance
Lifecycle and change-management discipline applied to a model, from training through retirement.
AI Regulations
Tracking how AI-specific regulation is emerging globally and across African jurisdictions.
Navigate the library visually.
Pick a dimension — topic, industry, or framework — then a value within it.
Guide
Enterprise Risk Scoring Methodology
A structured, weighted scoring approach for turning identified risks into a comparable, board-ready number.
Coming Soon
Research Paper
AI Risk Scoring in Regulated Financial Systems
Research into evidence-linked AI risk scoring for institutions that cannot afford a black box.
Coming Soon
Track your own path through the library.
A local, in-browser demonstration — nothing here is saved to an account yet.
Try it — click a resource to update its status
Completed (0)
Nothing here yet.
In Progress (0)
Nothing here yet.
Recommended Next (6)
- ISO 27001 Readiness: A Board-Level Briefing
- The State of GRC in Africa
- The CBN Cybersecurity Audit Playbook
- Data Protection Impact Assessment Template
- Third-Party Vendor Risk Assessment Checklist
- Implementing ISO 42001: An AI Management System Guide
Bookmarks (0)
Nothing here yet.
Templates, policies, and tools, in one place.
Publishing in stages — request anything below directly via the Resource Request Portal.
DOCX bundle
Policy Template Pack
Starter templates for the policies most GRC programs need first.
Not yet available — request below
XLSX
Risk Register Template
A structured risk register template ready to adapt to your taxonomy.
Not yet available — request below
DOCX
Acceptable Use Policy
A baseline acceptable-use policy mapped to common control frameworks.
Not yet available — request below
DOCX
Data Retention Policy
A retention policy structure aligned to African data protection law.
Not yet available — request below
PDF
SOC 2 Readiness Checklist
The trust services criteria, broken into a working checklist.
Not yet available — request below
PDF
Vendor Onboarding Checklist
What to confirm before a new vendor touches regulated data.
Not yet available — request below
XLSX
GRC Maturity Assessment
A structured self-scoring tool across five maturity stages.
Not yet available — request below
XLSX
Framework Gap Analysis Tool
Identify control gaps against any framework in AfriGRC's library.
Not yet available — request below
PDF
African Regulatory Glossary
Plain-language definitions for the region's compliance vocabulary.
Not yet available — request below
PDF
Framework Comparison Reference
A side-by-side comparison of the frameworks most AfriGRC customers carry.
Not yet available — request below
Live sessions, when they're scheduled.
Webinars, training, workshops, conferences, office hours, and certification sessions — subscribe below to hear the moment a date is confirmed.
- Webinar
Continuous Compliance: Moving Beyond the Annual Audit
A live session on shifting from point-in-time evidence to continuous monitoring.
Schedule to be announced · VirtualDetails to be announced
- Webinar
ISO 42001 in Practice: Governing AI You Already Ship
What an AI management system looks like once it's actually running.
Schedule to be announced · VirtualDetails to be announced
- Training
GRC Fundamentals for New Compliance Hires
A structured onboarding session for teams building out their compliance function.
Schedule to be announced · VirtualDetails to be announced
- Workshop
Framework Mapping Workshop
Hands-on session mapping your control set across the frameworks you carry.
Schedule to be announced · VirtualDetails to be announced
- Conference
State of GRC in Africa
AfriGRC's annual gathering of compliance, risk, and security leaders across the continent.
Schedule to be announced · In-person — LagosDetails to be announced
- Office Hours
Security & Trust Office Hours
Open Q&A with AfriGRC's security team — bring your architecture questions.
Schedule to be announced · VirtualDetails to be announced
- Certification Session
ISO 27001 Certification Readiness Session
A guided walkthrough of what a certification audit actually examines.
Schedule to be announced · VirtualDetails to be announced
Stay current, and stay connected.
Knowledge Alerts
New guides, regulatory updates, and event invitations — direct to your inbox, as they publish.
Community Updates
Peer discussion with other compliance and risk practitioners across Africa.
Get in TouchEvent Notifications
Be first to know when a webinar, workshop, or training session is scheduled.
See Upcoming EventsJoin the Conversation
Follow AfriGRC for regulatory updates and platform announcements.
Connect on LinkedIn
Don't see what you need? Ask for it.
Template, framework coverage, a guide, training, or a research topic — tell us and it's routed to the team building the library.
Step 1 of 2
What would you like to see?
Tell us the type of resource and the topic.
Frequently Asked Questions.
Put this knowledge to work in your own program.
See the platform live, or bring your team into the conversation.