PLATFORM

Governance, risk and compliance, on one record.

eGRC is the platform underneath all three. Your risk register, the obligations you owe your regulator, the policies your staff attest to, and the pack your board committee reads — every one of them written to the same record, with a trail behind every change.

Likelihood
1 rare → 5 almost certain
Impact
1 insignificant → 5 severe
Show the register at inherent or residual risk

Sample register — illustrative data, not a client's

RSK-008 · Operational

Internal fraud in cash handling

Owner
Head of Internal Audit
Inherent
L3 × I5 · High
Residual
L2 × I4 · Elevated
Treatment
Segregation of duties enforced; surprise cash counts monthly
Status
In progress

Select a risk to read it. Switch to residual to see where treatment leaves the register.

PROBLEM

Almost everything we are shown is a spreadsheet.

The risk register, the obligations list, the policy log, the audit findings tracker — four files, four owners, four versions. That is not a discipline failure. The teams we meet are careful and well trained. It is a tooling failure, and it shows up in the same four places every time.

  • Nobody is certain which version is current

    The register is emailed, renamed and edited by whoever has it open. Two people update the same risk in different copies. The version that reaches the committee is the one somebody happened to attach.

  • The ratings have nothing behind them

    A control is marked effective because someone believes it is. When the auditor asks what test was performed, by whom and on what date, the answer is a search through inboxes and shared drives.

  • The pack is assembled in a fortnight of chasing

    Owners are chased for updates, the heat map is rebuilt by hand, and the numbers are reconciled against last quarter's pack the night before the papers go out.

  • You can show position, but not movement

    A spreadsheet shows where risk sits today. Showing the committee that risk moved, and that a specific treatment is what moved it, means keeping the old versions and comparing them manually.

A spreadsheet has no owner field that chases people, no evidence store, and no audit trail. Those three absences are the whole problem.

DISCIPLINES

Three disciplines, one system underneath.

Governance, risk and compliance are usually bought as three tools and reconciled by hand before every committee meeting. They are the same evidence viewed three ways, so eGRC keeps them on one record.

GOV

Governance

Can you show how the decision was made?

Your board and its committees decide, and the record has to survive an auditor, a regulator and a change of company secretary. eGRC holds the reporting that reaches them and the trail behind every change. eBoard carries the meetings, papers and resolutions themselves, and takes its pack from the same record.

  • Assurance reporting and committee packs generated from the live register
  • An immutable trail of every change, with the user, the timestamp and the previous value
  • Role-based access, so a committee member sees the reporting view and not the working papers
  • Board meetings, papers, resolutions and action points, through eBoard

RISK

Risk

Do you know where your risk sits, and can you show it moving?

One register with named owners, inherent and residual scoring, appetite thresholds and treatment plans with dates. Controls mapped to the risks they mitigate and tested against evidence rather than belief. Incidents and losses captured against the risks they belong to, so the register learns from what actually happened.

  • Risk register with inherent and residual scoring and appetite thresholds
  • Control library, with design and operating effectiveness tested separately
  • Incidents, loss events and near-misses linked to the risks they belong to
  • Due diligence and internal audit, through eDiligence and eAudits

COMP

Compliance

Can you prove you did what you are required to do?

Every statutory and licence obligation with a named owner, a due date, the control that satisfies it and the evidence behind it. Policies through drafting, review, approval and staff attestation. Every audit, inspection and self-assessment finding tracked to evidenced closure, in one place instead of three trackers that disagree.

  • Obligations register and filing calendar, mapped to owners, controls and evidence
  • Policy lifecycle, approval workflow and staff attestation campaigns
  • Issues and actions from internal audit, external audit and regulator inspection
  • Contract obligations and renewals, through eContracts
SCHEMATIC How one record replaces four spreadsheets

MODULES

Nine modules over one record.

They are not separate products. A control test failing in one place changes a residual score in another, raises an issue in a third, lands in the committee pack, and is recorded once in the audit trail.

Read what each module does →

SUITE

The suite that runs on the platform.

eGRC is the platform. These are the products that sit on it — each deployed on its own, each writing to the same record, so your risk register feeds the board pack instead of being retyped into it.

The platform

  • eGRC The platform: register, controls, obligations, policies and reporting
    You are here

Governance

Risk

  • eDiligence Counterparty, third-party and investment due diligence
  • eAudits Internal audit planning, fieldwork and findings

Compliance

  • eContracts Contract lifecycle, obligations and renewals

Products marked “Request now” are not in general release. Tell us which one you need and we will tell you plainly what it takes to deliver it, and when.

WHO

Built for the people who sign the return.

Everyone here is personally accountable to a committee, a regulator, or both.

Head of Risk
You own the register and the appetite statement. You need movement you can defend at the committee, not a snapshot that was rebuilt last week.
Head of Compliance
You own the obligations and the returns. You need one list with named owners and due dates, and the evidence attached to each obligation rather than filed somewhere near it.
Company Secretary
You assemble the committee pack and hold the governance record. You need the pack to come out of a system with a trail behind it, in time for the papers to go out.
Head of Internal Audit
You raise findings and follow them to closure. You need management working in the same tracker you are, so the two of you stop reconciling separate spreadsheets.
Chief Finance Officer
You answer for the control environment to the board and the external auditor. You need to see what is overdue before they point it out to you.

See it by sector and regulator →

REFERENCES

Institutions that already trust Sibasi with their systems.

Development finance institutions, regulators, public utilities, humanitarian operations, research bodies and government agencies across Africa and beyond. Almost every one of them answers to a board, a committee or a donor — which is the same room this product was built for.

  • Trade & Development Bank (TDB Group) logo Development Finance
  • FSD Africa logo Financial Sector Development
  • Kenya Development Corporation logo Development Finance
  • ICDC logo Investment & Development
  • Competition Authority of Kenya logo Regulator
  • CrossBoundary Group logo Investment & Energy
  • Kenya Power logo Public Utility & Energy
  • TradeMark Africa logo Trade & Development
  • Concern Worldwide logo International Development
  • Médecins Sans Frontières (MSF) logo Humanitarian & Health
  • Somali Cash Consortium logo Humanitarian & Development
  • Africa Public Health Foundation logo Public Health
  • Biovision Africa Trust logo Agriculture & Health
  • icipe logo Research & Science
  • ICRW logo Research & Development
  • OWSD logo Science & Education
  • Kenya Wildlife Conservancies Association logo Conservation
  • AfCAA — African Council for Accreditation and Accountability logo Accreditation & Accountability
  • GrowthAfrica logo Enterprise Development
  • Kenya Tourism Board logo Tourism & Trade
  • Zambia Airways logo Airline & Transport
  • WIOCC logo Telecoms & Digital Infrastructure
  • Liquid Telecom logo Telecommunications
  • Australian Government (Geoscience Australia) logo Government & Geoscience
  • AutoXpress logo Retail & Automotive
  • Nairobi Java House logo Restaurants & Hospitality
  • Afrimac Nut Ltd logo Agribusiness & Export
  • Belva Digital logo Digital & Creative

These are Sibasi client references from across our portfolio, not eGRC deployments.

SIBASI

Why buy this from us.

Five arguments, each of which you can test rather than take on trust.

  • FIT

    Built around the framework you actually report against

    eGRC ships no fixed rulebook. Your obligations register is built from the licences, statutes and supervisory guidance that apply to you — in whichever markets you are supervised — rather than from a template written for a US bank holding company that you then spend three months deleting. Groups reporting to more than one supervisor hold all of them on the same register.

  • MSFT

    Microsoft-native, because you already are

    Sibasi is a Microsoft Solutions Partner and eGRC is built to sit inside the Microsoft estate you already pay for. Sign-in is Entra ID, so your identity, groups and conditional access policies govern access without a second user directory to maintain and deprovision.

  • SUITE

    eGRC is the platform, not a point tool

    eGRC is the record that governance, risk and compliance all write to. eBoard, our board and committee platform, is already in production and listed on Microsoft AppSource, and it takes its pack from that same record instead of having it retyped. eContracts, eDiligence, eAudits, eEvaluate and eDisclosures run on the same platform and are delivered on request.

  • PRICE

    Priced for institutions, not for the Fortune 500

    Our pricing is published, starts at USD 9,600 a year, and is quoted in a currency you can budget in. We are not going to tell you what a global platform would charge you — they do not publish list prices and we are not going to invent one. Compare our number against the quotes you already have.

  • SUPPORT

    Implemented and supported by the people who build it

    There is no reseller between you and the product team. The people who configure your obligations register work for the company that writes the code, and they can change the product when what you need is reasonable and missing.

Read the full case, including what we will not claim →

PROOF

Reasons to think we are safe to buy.

Every one of these is something you can check yourself in a few minutes. None of it is a customer count or a review score, because we do not publish figures we cannot show you the working for.

  • SUITE

    eBoard is already live

    eBoard, our board and committee governance platform, is in production with paying clients and listed on Microsoft AppSource. eGRC is the second product in the same suite, built by the same team on the same platform.

  • MSFT

    Microsoft Solutions Partner

    eGRC signs in with Entra ID, so your existing identity, groups and conditional access policies apply from day one. Notifications go to Teams. Reports export to the Microsoft 365 your organisation already runs.

  • LOCAL

    A company you can look up

    Sibasi Ltd was incorporated in 2017 and has its head office in Nairobi. We implement and support this ourselves — there is no reseller between you and the people who build it — and the organisations we work with operate across Africa and further afield.

  • SCOPE

    A platform, not a point tool

    eGRC is the record underneath governance, risk and compliance — not a risk register with extras. eBoard already runs on it and takes its board pack from it. eContracts, eDiligence, eAudits, eEvaluate and eDisclosures run on it too, and are delivered on request rather than sold off a shelf.

ASKED

Questions we are asked first.

What is eGRC?

eGRC is a governance, risk and compliance platform. It holds your risk register with inherent and residual scoring, the controls that mitigate each risk and the evidence that they were tested, your regulatory obligations and their due dates, your policies and staff attestations, incidents and losses, and every audit or inspection finding tracked to closure — with an immutable audit trail over all of it.

Who typically buys it?

Heads of Risk, Heads of Compliance, Company Secretaries, Heads of Internal Audit and Chief Finance Officers at SACCOs and banks, insurers, pension schemes, development finance institutions and investment funds, large NGOs, and government agencies and state corporations. We work with institutions across Africa and with international organisations operating in several countries at once.

We already have a risk register in Excel. What changes?

Three things a spreadsheet cannot do. Every risk gets an owner the system can chase, with a treatment plan and a date. Evidence attaches to the control test rather than sitting in an inbox. And every change is recorded, so you can reconstruct what the register said on any date for a regulator or an auditor. The scoring model itself can stay exactly as you have it.

How long does implementation take?

It depends on how many registers you are consolidating and whether your obligations list already exists in writing. We scope it in discovery and give you a duration before you commit, rather than publishing an average that will not describe your project.

Does it work with Microsoft 365?

Yes. Sibasi is a Microsoft Solutions Partner and eGRC signs in with Entra ID, so your existing identity, groups and conditional access policies apply. Notifications and approvals reach people in Teams, and reports export to Word, Excel and PDF.

See it against your own register.

A working demo with someone who has implemented this in a regulated institution, not a slide deck. Tell us what you report and to whom, and we will show you that part.