GOVT
Findings closed on the record, not in correspondence.
In a state corporation the hardest governance question is rarely what the risks are. It is what happened to last year's audit findings, who owned them, and what evidence exists that they were closed. eGRC makes that a report rather than an investigation.
Supervisory bodies institutions in this sector report to
- OAG Office of the Auditor-General · Kenya
- PPRA Public Procurement Regulatory Authority · Kenya
- AGSA Auditor-General of South Africa · South Africa
- OAuGF Office of the Auditor-General for the Federation · Nigeria
eGRC does not ship a fixed rulebook. Your obligations register is built from the licences, statutes and supervisory guidance that apply to you, in whichever markets you are supervised — including groups reporting to more than one.
PRESSURE
What makes this hard in your sector.
Written from what we are shown when we sit down with organisations like yours. If none of it is true for you, this is probably not the right product for you yet.
-
Audit findings accumulate across years and sources
The Auditor-General, internal audit, and parent ministry reviews all raise findings. They land in different files, and the same underlying issue appears three times under three references.
-
Closure is asserted in a letter rather than evidenced in a record
A finding is reported as addressed. The evidence supporting that lives in a correspondence file, if it can be found at all, and the next review raises it again.
-
Governance reporting is a document exercise
Codes of governance for state corporations, including Mwongozo, expect a functioning risk management framework. Producing evidence of one takes longer than operating one would.
-
Procurement risk is real, visible and poorly evidenced
Everyone knows where procurement risk sits. Showing the control that addresses it, when it was last tested and what the test found is a different matter.
OUTCOME
What changes once the register is in one place.
These are the things clients in this sector set up first.
- One issues register covering Auditor-General, internal audit and self-assessment findings, tracked to evidenced closure
- Duplicate findings from different sources linked to the same underlying issue
- Statutory, procurement and reporting obligations held with named owners and due dates
- A risk register and control framework you can show an oversight reviewer without preparation
- Board and audit committee reporting generated from the register, quarter after quarter, in the same format
- An audit trail showing who changed what and when, exportable for any review period
MODULES
The modules that carry most of the weight here.
Every tier includes the register and the audit trail. These are the ones this sector leans on hardest.
- ISSU
Issues and actions
You track every finding to closure in one place, whoever raised it.
- RISK
Risk register
You keep one register, and it is always the current one.
- CTRL
Control library
You can show which control reduces which risk, and whether it worked.
- OBLG
Compliance obligations
You hold one list of what you owe your regulator, and who owes it.
- POLY
Policy management
You know which policy is current, when it was approved, and who has read it.
- ASSR
Assurance reporting
You build the committee pack from the register, not from memory.
- TRAIL
Audit trail
You can prove what the register said on any date, and who changed it.
See it set up for audit findings.
Tell us how many open Auditor-General and internal audit findings you carry. We will show you what tracking them to evidenced closure looks like.