SACCO
The register your supervisor expects, kept the way your board approved it.
Deposit-taking SACCOs, banks and microfinance institutions carry the heaviest reporting load of anyone we work with, and almost all of them carry it in a spreadsheet. eGRC holds the register, the controls, the obligations calendar and the audit findings in one place, with the evidence attached.
Supervisory bodies institutions in this sector report to
- SASRA SACCO Societies Regulatory Authority · Kenya
- CBK Central Bank of Kenya · Kenya
- BoU Bank of Uganda · Uganda
- CBN Central Bank of Nigeria · Nigeria
- BoG Bank of Ghana · Ghana
- PA Prudential Authority · South Africa
eGRC does not ship a fixed rulebook. Your obligations register is built from the licences, statutes and supervisory guidance that apply to you, in whichever markets you are supervised — including groups reporting to more than one.
PRESSURE
What makes this hard in your sector.
Written from what we are shown when we sit down with organisations like yours. If none of it is true for you, this is probably not the right product for you yet.
-
The board risk committee meets whether the register is ready or not
The pack has a date. Chasing branch and department heads for updates in the fortnight before it, then rebuilding the heat map by hand, is a job that repeats every quarter and never gets easier.
-
Credit, liquidity and operational risk live in different places
Credit risk sits with the credit team, liquidity with treasury, operational risk with whoever was assigned it last. The board sees three views that were never reconciled against each other.
-
Supervisory returns are remembered, not scheduled
The people who know the filing dates hold them in their heads and their calendars. When one of them is on leave, a return is late, and a late return is a finding.
-
Internal audit and management keep separate trackers
Internal audit has a findings register. Management has an action list. They disagree, and reconciling them is the first twenty minutes of every audit committee meeting.
-
Anti-money-laundering and data protection duties sit outside the risk framework
They are usually managed well and separately, which means the board sees them as separate reports rather than as risks with owners, controls and evidence like everything else.
OUTCOME
What changes once the register is in one place.
These are the things clients in this sector set up first.
- One register covering credit, liquidity, operational, compliance and strategic risk, with a single owner per risk
- A filing calendar with named owners, so a supervisory return has a person and a date rather than a habit
- Controls mapped to the risks they mitigate, tested on a schedule, with the evidence attached to the test
- Internal audit findings and management actions in one tracker both sides work in
- A committee pack generated from the live register, including what moved since the last meeting
- An audit trail that can reconstruct the register as at any date for an inspection
MODULES
The modules that carry most of the weight here.
Every tier includes the register and the audit trail. These are the ones this sector leans on hardest.
- RISK
Risk register
You keep one register, and it is always the current one.
- CTRL
Control library
You can show which control reduces which risk, and whether it worked.
- OBLG
Compliance obligations
You hold one list of what you owe your regulator, and who owes it.
- ISSU
Issues and actions
You track every finding to closure in one place, whoever raised it.
- INCD
Incidents and loss events
You capture what went wrong while people still remember it.
- ASSR
Assurance reporting
You build the committee pack from the register, not from memory.
- TRAIL
Audit trail
You can prove what the register said on any date, and who changed it.
See it set up for SASRA and CBK reporting.
Tell us which returns you file and when your board risk committee sits. We will configure the demo environment to match before we meet.