Governance, risk, and compliance
One programme. Every regulator you answer to. You operate across borders, so your compliance work should not restart at each one. We build a single control set that satisfies your national obligations and your international certifications at the same time, and we run it with you until the certificate is on the wall.
Four reasons this lands on someone's desk.
A client made it a condition
ISO 27001 certification has become a condition of the contract, not a nice-to-have on the vendor questionnaire.
A new market, a new law
You entered a new African market with a data protection law your compliance programme hasn't mapped yet.
A filing is overdue
Your CNDP filing — or its equivalent in whichever market you operate — is overdue and someone finally noticed.
The fourth questionnaire this quarter
You're answering the same security questionnaire for the fourth time this quarter, and each one takes a week.
One control set, built once and reused everywhere.
- 01Gap assessment. A clear-eyed read of where you stand today against the framework you're targeting, before anything is written.
- 02One control set, several frameworks. ISO 27001 Annex A mapped once, then cross-referenced to SOC 2, GDPR, and whichever national law applies — so a single control satisfies several obligations at once.
- 03Policy and documentation. Written in English or French depending on who has to read it, and specific to how you actually operate — never templated.
- 04Risk management. A risk register with treatment plans, named owners, and review dates, not a spreadsheet that's opened once a year.
- 05Third-party and supplier risk. The obligations you carry because of who you work with, assessed and tracked alongside your own.
- 06Audit support. We sit through the certification and surveillance audits with you, not just the preparation beforehand.
Six frameworks. One control set.
Alongside the national frameworks that apply where you operate: Morocco's Loi 09-08 and CNDP, and Loi 05-20 and DGSSI; Nigeria's Data Protection Act and the NDPC; Egypt's Law 151 of 2020; Ivory Coast's Loi 2013-450 and ARTCI; and sector directives from Bank Al-Maghrib, the Central Bank of Nigeria, and the Central Bank of Egypt.
A programme you can point to, not a binder on a shelf.
- 01A gap report with a closure plan that's costed and sequenced, so you know what to fix first and what it takes.
- 02A complete policy and procedure set, version-controlled, so you can show what changed and when.
- 03A risk register and statement of applicability that auditors and regulators can actually follow.
- 04An evidence library, mapped control-by-control, so a questionnaire or audit request is answered in minutes, not a week.
- 05Named support through the certification audit itself.
How long it takes, by scope.
| Engagement | Typical duration | Outcome |
|---|---|---|
| Gap report, single framework | 10 working days | You know the cost and the scope |
| ISO 27001 readiness | 4 – 6 months | Audit-ready |
| Multi-market programme | 6 – 9 months | One control set, every jurisdiction |
| Ongoing management | Retained, monthly | Surveillance, filings, and questionnaires handled |
Most clients start with a gap report against the framework that matters most right now, then decide whether to extend into a full readiness or multi-market programme.
Straight answers, before you ask.
Can one programme satisfy both our national regulator and an international certification like ISO 27001?
Yes — that's the point. We build a single control set mapped to ISO 27001 Annex A and cross-referenced to your national law and any other certification you need, so you maintain one system instead of parallel ones.
How long does ISO 27001 certification readiness take?
Typically 4 to 6 months to audit-ready, depending on your starting point. If you want to know cost and scope first, a gap report scoped to a single framework takes 10 working days.
Do you help across multiple African markets at once?
Yes. A multi-market programme mapping every jurisdiction you operate in onto one control set typically runs 6 to 9 months, covering national frameworks such as Morocco's Loi 09-08 and CNDP, Nigeria's Data Protection Act, Egypt's Law 151 of 2020, and Ivory Coast's Loi 2013-450 and ARTCI.
Do policies get delivered in French as well as English?
Yes. We write policy and documentation in English or French depending on which markets and regulators need to read them — never templated, always specific to how you actually operate.
Will someone sit through the certification audit with us?
Yes. Named support carries through the certification or surveillance audit itself, not just the preparation before it.
Know your gap in ten working days.
Same NDA, same named consultant, same report format described above — scoped to governance, risk, and compliance. Get your ISO 27001 gap report in ten working days.
Governance, risk & compliance.
Request received.
A named consultant will reply within one business day to scope the NDA and the gap assessment.