PLATFORM
Governance, risk and compliance, on one record.
eGRC is the platform underneath all three. Your risk register, the obligations you owe your regulator, the policies your staff attest to, and the pack your board committee reads — every one of them written to the same record, with a trail behind every change.
- Likelihood
- 1 rare → 5 almost certain
- Impact
- 1 insignificant → 5 severe
Sample register — illustrative data, not a client's
RSK-008 · Operational
Internal fraud in cash handling
- Owner
- Head of Internal Audit
- Inherent
- L3 × I5 · High
- Residual
- L2 × I4 · Elevated
- Treatment
- Segregation of duties enforced; surprise cash counts monthly
- Status
- In progress
Treatment moves 11 of 12 risks down at least one band.
Select a risk to read it. Switch to residual to see where treatment leaves the register.
PROBLEM
Almost everything we are shown is a spreadsheet.
The risk register, the obligations list, the policy log, the audit findings tracker — four files, four owners, four versions. That is not a discipline failure. The teams we meet are careful and well trained. It is a tooling failure, and it shows up in the same four places every time.
-
Nobody is certain which version is current
The register is emailed, renamed and edited by whoever has it open. Two people update the same risk in different copies. The version that reaches the committee is the one somebody happened to attach.
-
The ratings have nothing behind them
A control is marked effective because someone believes it is. When the auditor asks what test was performed, by whom and on what date, the answer is a search through inboxes and shared drives.
-
The pack is assembled in a fortnight of chasing
Owners are chased for updates, the heat map is rebuilt by hand, and the numbers are reconciled against last quarter's pack the night before the papers go out.
-
You can show position, but not movement
A spreadsheet shows where risk sits today. Showing the committee that risk moved, and that a specific treatment is what moved it, means keeping the old versions and comparing them manually.
A spreadsheet has no owner field that chases people, no evidence store, and no audit trail. Those three absences are the whole problem.
DISCIPLINES
Three disciplines, one system underneath.
Governance, risk and compliance are usually bought as three tools and reconciled by hand before every committee meeting. They are the same evidence viewed three ways, so eGRC keeps them on one record.
GOV
Governance
Can you show how the decision was made?
Your board and its committees decide, and the record has to survive an auditor, a regulator and a change of company secretary. eGRC holds the reporting that reaches them and the trail behind every change. eBoard carries the meetings, papers and resolutions themselves, and takes its pack from the same record.
- Assurance reporting and committee packs generated from the live register
- An immutable trail of every change, with the user, the timestamp and the previous value
- Role-based access, so a committee member sees the reporting view and not the working papers
- Board meetings, papers, resolutions and action points, through eBoard
RISK
Risk
Do you know where your risk sits, and can you show it moving?
One register with named owners, inherent and residual scoring, appetite thresholds and treatment plans with dates. Controls mapped to the risks they mitigate and tested against evidence rather than belief. Incidents and losses captured against the risks they belong to, so the register learns from what actually happened.
- Risk register with inherent and residual scoring and appetite thresholds
- Control library, with design and operating effectiveness tested separately
- Incidents, loss events and near-misses linked to the risks they belong to
- Due diligence and internal audit, through eDiligence and eAudits
COMP
Compliance
Can you prove you did what you are required to do?
Every statutory and licence obligation with a named owner, a due date, the control that satisfies it and the evidence behind it. Policies through drafting, review, approval and staff attestation. Every audit, inspection and self-assessment finding tracked to evidenced closure, in one place instead of three trackers that disagree.
- Obligations register and filing calendar, mapped to owners, controls and evidence
- Policy lifecycle, approval workflow and staff attestation campaigns
- Issues and actions from internal audit, external audit and regulator inspection
- Contract obligations and renewals, through eContracts
GOV
Governance
- Committee reporting
- Resolutions and actions
- Access by role
RISK
Risk
- Register, inherent and residual
- Control tests and evidence
- Incidents and losses
COMP
Compliance
- Obligations and due dates
- Policy attestation
- Findings to closure
ONE RECORD
Written once. A control test failing here changes a residual score, raises an issue and lands in the pack, without anyone retyping it.
Committee pack
generated, not assembled
Regulator return
with the evidence attached
Attestation status
who has signed, who has not
MODULES
Nine modules over one record.
They are not separate products. A control test failing in one place changes a residual score in another, raises an issue in a third, lands in the committee pack, and is recorded once in the audit trail.
- RISK
Risk register
You keep one register, and it is always the current one.
- CTRL
Control library
You can show which control reduces which risk, and whether it worked.
- OBLG
Compliance obligations
You hold one list of what you owe your regulator, and who owes it.
- POLY
Policy management
You know which policy is current, when it was approved, and who has read it.
- INCD
Incidents and loss events
You capture what went wrong while people still remember it.
- ISSU
Issues and actions
You track every finding to closure in one place, whoever raised it.
- ASSR
Assurance reporting
You build the committee pack from the register, not from memory.
- TRAIL
Audit trail
You can prove what the register said on any date, and who changed it.
- AI
AI assistance
You get a first draft, and you keep the decision.
SUITE
The suite that runs on the platform.
eGRC is the platform. These are the products that sit on it — each deployed on its own, each writing to the same record, so your risk register feeds the board pack instead of being retyped into it.
The platform
- eGRC The platform: register, controls, obligations, policies and reportingYou are here
Governance
- eBoard Board and committee meetings, papers and resolutions
- eDisclosures Interest, gift and related-party disclosures
- eEvaluate Board, committee and staff evaluation
Risk
- eDiligence Counterparty, third-party and investment due diligence
- eAudits Internal audit planning, fieldwork and findings
Compliance
- eContracts Contract lifecycle, obligations and renewals
Products marked “Request now” are not in general release. Tell us which one you need and we will tell you plainly what it takes to deliver it, and when.
WHO
Built for the people who sign the return.
Everyone here is personally accountable to a committee, a regulator, or both.
- Head of Risk
- You own the register and the appetite statement. You need movement you can defend at the committee, not a snapshot that was rebuilt last week.
- Head of Compliance
- You own the obligations and the returns. You need one list with named owners and due dates, and the evidence attached to each obligation rather than filed somewhere near it.
- Company Secretary
- You assemble the committee pack and hold the governance record. You need the pack to come out of a system with a trail behind it, in time for the papers to go out.
- Head of Internal Audit
- You raise findings and follow them to closure. You need management working in the same tracker you are, so the two of you stop reconciling separate spreadsheets.
- Chief Finance Officer
- You answer for the control environment to the board and the external auditor. You need to see what is overdue before they point it out to you.
REFERENCES
Institutions that already trust Sibasi with their systems.
Development finance institutions, regulators, public utilities, humanitarian operations, research bodies and government agencies across Africa and beyond. Almost every one of them answers to a board, a committee or a donor — which is the same room this product was built for.
-
Development Finance -
Financial Sector Development -
Development Finance -
Investment & Development -
Regulator -
Investment & Energy
-
Public Utility & Energy -
Trade & Development -
International Development -
Humanitarian & Health -
Humanitarian & Development -
Public Health -
Agriculture & Health -
Research & Science -
Research & Development -
Science & Education -
Conservation -
Accreditation & Accountability -
Enterprise Development -
Tourism & Trade -
Airline & Transport -
Telecoms & Digital Infrastructure -
Telecommunications -
Government & Geoscience
-
Retail & Automotive -
Restaurants & Hospitality
-
Agribusiness & Export -
Digital & Creative
These are Sibasi client references from across our portfolio, not eGRC deployments.
SIBASI
Why buy this from us.
Five arguments, each of which you can test rather than take on trust.
- FIT
Built around the framework you actually report against
eGRC ships no fixed rulebook. Your obligations register is built from the licences, statutes and supervisory guidance that apply to you — in whichever markets you are supervised — rather than from a template written for a US bank holding company that you then spend three months deleting. Groups reporting to more than one supervisor hold all of them on the same register.
- MSFT
Microsoft-native, because you already are
Sibasi is a Microsoft Solutions Partner and eGRC is built to sit inside the Microsoft estate you already pay for. Sign-in is Entra ID, so your identity, groups and conditional access policies govern access without a second user directory to maintain and deprovision.
- SUITE
eGRC is the platform, not a point tool
eGRC is the record that governance, risk and compliance all write to. eBoard, our board and committee platform, is already in production and listed on Microsoft AppSource, and it takes its pack from that same record instead of having it retyped. eContracts, eDiligence, eAudits, eEvaluate and eDisclosures run on the same platform and are delivered on request.
- PRICE
Priced for institutions, not for the Fortune 500
Our pricing is published, starts at USD 9,600 a year, and is quoted in a currency you can budget in. We are not going to tell you what a global platform would charge you — they do not publish list prices and we are not going to invent one. Compare our number against the quotes you already have.
- SUPPORT
Implemented and supported by the people who build it
There is no reseller between you and the product team. The people who configure your obligations register work for the company that writes the code, and they can change the product when what you need is reasonable and missing.
PROOF
Reasons to think we are safe to buy.
Every one of these is something you can check yourself in a few minutes. None of it is a customer count or a review score, because we do not publish figures we cannot show you the working for.
- SUITE
eBoard is already live
eBoard, our board and committee governance platform, is in production with paying clients and listed on Microsoft AppSource. eGRC is the second product in the same suite, built by the same team on the same platform.
- MSFT
Microsoft Solutions Partner
eGRC signs in with Entra ID, so your existing identity, groups and conditional access policies apply from day one. Notifications go to Teams. Reports export to the Microsoft 365 your organisation already runs.
- LOCAL
A company you can look up
Sibasi Ltd was incorporated in 2017 and has its head office in Nairobi. We implement and support this ourselves — there is no reseller between you and the people who build it — and the organisations we work with operate across Africa and further afield.
- SCOPE
A platform, not a point tool
eGRC is the record underneath governance, risk and compliance — not a risk register with extras. eBoard already runs on it and takes its board pack from it. eContracts, eDiligence, eAudits, eEvaluate and eDisclosures run on it too, and are delivered on request rather than sold off a shelf.
ASKED
Questions we are asked first.
What is eGRC?
eGRC is a governance, risk and compliance platform. It holds your risk register with inherent and residual scoring, the controls that mitigate each risk and the evidence that they were tested, your regulatory obligations and their due dates, your policies and staff attestations, incidents and losses, and every audit or inspection finding tracked to closure — with an immutable audit trail over all of it.
Who typically buys it?
Heads of Risk, Heads of Compliance, Company Secretaries, Heads of Internal Audit and Chief Finance Officers at SACCOs and banks, insurers, pension schemes, development finance institutions and investment funds, large NGOs, and government agencies and state corporations. We work with institutions across Africa and with international organisations operating in several countries at once.
We already have a risk register in Excel. What changes?
Three things a spreadsheet cannot do. Every risk gets an owner the system can chase, with a treatment plan and a date. Evidence attaches to the control test rather than sitting in an inbox. And every change is recorded, so you can reconstruct what the register said on any date for a regulator or an auditor. The scoring model itself can stay exactly as you have it.
How long does implementation take?
It depends on how many registers you are consolidating and whether your obligations list already exists in writing. We scope it in discovery and give you a duration before you commit, rather than publishing an average that will not describe your project.
Does it work with Microsoft 365?
Yes. Sibasi is a Microsoft Solutions Partner and eGRC signs in with Entra ID, so your existing identity, groups and conditional access policies apply. Notifications and approvals reach people in Teams, and reports export to Word, Excel and PDF.
See it against your own register.
A working demo with someone who has implemented this in a regulated institution, not a slide deck. Tell us what you report and to whom, and we will show you that part.