Skip to content
Book a Demo
BLG.00 / BLOG & KNOWLEDGE CENTRE

Governance, risk, and compliance thinking, published for Africa first.

Original analysis on governance, risk, compliance, privacy, cybersecurity, and AI governance — written for the people who carry the framework, not just the vendor selling against it.

2

Articles Published

With many more in progress.

12

Topic Hubs

From governance to digital transformation.

5

Knowledge Series

Multi-part deep dives, in progress.

4

Editorial Teams

Compliance, security, AI governance, and risk.

BLG.01 / FEATURED ARTICLES

Where to start.

Featured · Compliance

Building a Continuous Compliance Program: A Practical Framework

Why continuous compliance replaces the annual-audit cycle with an always-current instrument panel — and where to start.

Compliance Editorial Lead9 min read
  • AI Governance

    What ISO 42001 Actually Requires: A Plain-Language Breakdown

    The first management-system standard written for AI, broken into four things it actually asks an organization to do.

    AI Governance Editorial Lead11 min read
BLG.02 / LATEST ARTICLES

Every article, most recent first.

16 articles catalogued so far — architecture built to scale to thousands.

  • Regulatory Updates

    The Six Things a CBN Examiner Checks First

    A field-level walkthrough of what a Central Bank of Nigeria cybersecurity examination actually inspects.

    Compliance Editorial Lead8 min read

    Coming Soon

  • Vendor Risk

    A Defensible Vendor Risk Scoring Methodology

    How to weight vendor risk so the score means the same thing to procurement, security, and the board.

    Risk & Audit Editorial Lead10 min read

    Coming Soon

  • Privacy

    Data Protection Impact Assessments, in Practice

    Where DPIAs actually break down in African organizations, and how to fix the process, not just the template.

    Compliance Editorial Lead12 min read

    Coming Soon

  • Audit

    Building a Risk-Based Internal Audit Universe

    A structured approach to deciding what your internal audit team actually reviews this year.

    Risk & Audit Editorial Lead9 min read

    Coming Soon

  • Risk

    What a Board Actually Wants From a Risk Report

    Translating a risk register into the four things a board and audit committee ask for every time.

    Risk & Audit Editorial Lead7 min read

    Coming Soon

  • Cybersecurity

    Incident Response When the Clock Is Regulatory, Not Just Technical

    Structuring incident response around regulator notification deadlines, not only technical containment.

    Security Editorial Lead10 min read

    Coming Soon

BLG.06 / KNOWLEDGE DISCOVERY

Find the article for your context.

Every selection is optional — answer as much or as little as you want.

Select any combination above — the more you tell us, the more specific the match.

BLG.07 / AUTHOR PROFILES

Who writes this — by role, not by name yet.

AfriGRC's public author program hasn't launched — these are the editorial teams publishing today.

  • Author Profile Reserved

    Compliance Editorial Lead

    Framework Mapping · Regulatory Change · Audit Readiness

    1 published article

  • Author Profile Reserved

    Security Editorial Lead

    Security Architecture · Incident Response · Cloud Security

    0 published articles

  • Author Profile Reserved

    AI Governance Editorial Lead

    Responsible AI · Model Governance · AI Regulation

    1 published article

  • Author Profile Reserved

    Risk & Audit Editorial Lead

    Enterprise Risk · Internal Audit · Vendor Risk

    0 published articles

BLG.08 / NEWSLETTER

New articles, before anyone else sees them.

Knowledge Centre Digest

A monthly summary of new articles, series updates, and events — direct to your inbox.

BLG.09 / READING JOURNEY

A recommended sequence: from compliance basics to AI governance.

Mark each step read as you go — nothing here is saved to an account yet.

  1. 1

    Step 1 of 4

    Building a Continuous Compliance Program: A Practical Framework

    Why continuous compliance replaces the annual-audit cycle with an always-current instrument panel — and where to start.

  2. 2

    Step 2 of 4

    The Six Things a CBN Examiner Checks First

    A field-level walkthrough of what a Central Bank of Nigeria cybersecurity examination actually inspects.

  3. 3

    Step 3 of 4

    What ISO 42001 Actually Requires: A Plain-Language Breakdown

    The first management-system standard written for AI, broken into four things it actually asks an organization to do.

  4. 4

    Step 4 of 4

    AI Governance, Explained From First Principles

    What governing an AI system actually means, before any specific framework enters the conversation.

0 of 4 read

BLG.10 / YOUR READING DASHBOARD

Recently viewed, bookmarked, and what's next.

A local, in-browser demonstration — nothing here is saved to an account yet.

Try it — click an article to view it, or bookmark it for later

Recently Viewed (0)

Nothing here yet.

Continue Reading (0)

Nothing here yet.

Bookmarked (0)

Nothing here yet.

Recommended (6)

  • Building a Continuous Compliance Program: A Practical Framework
  • What ISO 42001 Actually Requires: A Plain-Language Breakdown
  • The Six Things a CBN Examiner Checks First
  • A Defensible Vendor Risk Scoring Methodology
  • Data Protection Impact Assessments, in Practice
  • Building a Risk-Based Internal Audit Universe
BLG.11 / KNOWLEDGE SERIES

Multi-part deep dives, published as they're written.

  • Knowledge Series

    AI Governance Explained

    A ground-up series on what governing an AI system actually requires, independent of any one framework.

    Coming Soon

  • Knowledge Series

    ISO 42001 Series

    A multi-part walkthrough of ISO 42001, from first inventory to ongoing model monitoring.

    1 part published

  • Knowledge Series

    Privacy Fundamentals

    Core data protection concepts across NDPA, POPIA, and GDPR, explained once and applied throughout.

    Coming Soon

  • Knowledge Series

    Internal Audit Masterclass

    A practitioner's series on planning, testing, and closing findings that actually stay closed.

    Coming Soon

  • Knowledge Series

    Enterprise Risk Series

    Risk identification, scoring, and board reporting, built as one continuous discipline.

    Coming Soon

BLG.12 / EVENTS & WEBINARS

Live sessions that pair with what you're reading.

The same events listed on the Resources hub — webinars, training, workshops, and more.

  • Webinar

    Continuous Compliance: Moving Beyond the Annual Audit

    A live session on shifting from point-in-time evidence to continuous monitoring.

    Schedule to be announced · Virtual

    Details to be announced

  • Webinar

    ISO 42001 in Practice: Governing AI You Already Ship

    What an AI management system looks like once it's actually running.

    Schedule to be announced · Virtual

    Details to be announced

  • Training

    GRC Fundamentals for New Compliance Hires

    A structured onboarding session for teams building out their compliance function.

    Schedule to be announced · Virtual

    Details to be announced

  • Workshop

    Framework Mapping Workshop

    Hands-on session mapping your control set across the frameworks you carry.

    Schedule to be announced · Virtual

    Details to be announced

  • Conference

    State of GRC in Africa

    AfriGRC's annual gathering of compliance, risk, and security leaders across the continent.

    Schedule to be announced · In-person — Lagos

    Details to be announced

  • Office Hours

    Security & Trust Office Hours

    Open Q&A with AfriGRC's security team — bring your architecture questions.

    Schedule to be announced · Virtual

    Details to be announced

  • Certification Session

    ISO 27001 Certification Readiness Session

    A guided walkthrough of what a certification audit actually examines.

    Schedule to be announced · Virtual

    Details to be announced

BLG.13 / FAQ

Frequently Asked Questions.

BLG.14 / GET STARTED

Put this thinking to work in your own program.

See the platform live, explore the wider Resources hub, or bring your team into the conversation.

Blog & Knowledge Centre — AfriGRC