Compliance

Compliance

We build to the obligation,

not around it.

Compliance is not a document exercise. It is the ability to produce

 evidence, inside a defined window, that a specific control was 

working on a specific date. We design architectures that generate 

that evidence as a by-product of running properly.

Frameworks we work to

Nigeria

CBN Risk-Based Cybersecurity Framework for DMBs and PSBs

Nigeria

Nigeria Data Protection Act 2023 and GAID 2025

Ghana

Bank of Ghana Cyber & Information Security Directive 2026

Ghana

Act 843 and Act 1038

Kenya

CBK Guidance Note on Cybersecurity

Kenya

Data Protection Act 2019

International

ISO/IEC 27001, ISO 22301, ISO/IEC 42001, ISO/IEC 20000-1

Payment

PCI DSS v4.0.1

What we deliver

Control mapping

Clause-by-clause mapping of your existing and planned controls to the frameworks that supervise you, showing full coverage, partial coverage and gaps.

Evidence packs

Audit-ready documentation assembled in the structure the assessor expects, so an audit becomes a review rather than a scramble.

Gap assessment

Where you stand, what is required, and a
sequenced plan to close the distance inside the reporting cycle.

Compliance automation and risk management

Control monitoring, evidence collection and risk registers run on a platform rather than a spreadsheet, so the position is current on any given day and a board report takes an hour instead of a fortnight.

Continuous compliance

Monitoring and reporting that keeps evidence current between audits instead of rebuilding it before each one.

This page describes our technical and advisory services. It is not legal advice 

and does not constitute certification of complianc.

Scroll to Top