The standards you answer to, curated once.

The frameworks regulated organisations are audited against, the horizontal core (ISO 27001 and 27701, SOC 2, NIST CSF, ISO 22301), the standards that apply when they apply to you (PCI DSS, DORA, SWIFT CSP, HIPAA), and the African market regimes US- and EU-built tools never reach, across nine markets and the regional bodies. Map a control once; it counts everywhere it applies.
0+
frameworks curated
0+
requirements, resolved to 132 controls
0+
control ⇄ requirement mappings
0
map once, every customer inherits

One stack of obligations, many hands issuing it.

Comprehensiveness is the value: one system mapped to what you're actually audited against, not a token few frameworks. Solid entries are curated and adoptable today; the rest are next through the same reviewed pipeline.

Curated today, with its own page
On the curation roadmap
Browse the full catalog

Central Bank of Nigeria

The primary supervisor of Nigerian banking and payments: AML, cybersecurity, KYC and the conduct of the institutions it licenses.

CBN AML/CFT/CPFCBN Automated-AML BaselineCBN Three-tier KYCCBN Cybersecurity FrameworkNSBPCorporate governanceConsumer protectionOutsourcing & BCMBVN frameworkOpen bankingPrudential / Basel

Nigeria Data Protection Commission

The privacy regulator: the NDPA 2023, the NDPR it superseded, and the GAID 2025 directive operationalising both.

NFIU & the federal statutes

The financial-intelligence unit your reports land with, and the Acts of the National Assembly beneath the whole financial-crime regime.

NFIU ReportingMLPPA 2022TPPA 2022BOFIA 2020Cybercrimes Act

South Africa's supervisors

The Information Regulator for privacy, the Financial Intelligence Centre for AML, and the Prudential Authority with the FSCA for cyber resilience.

Kenya's supervisors

The Office of the Data Protection Commissioner, one of Africa's most active privacy regulators, and the Central Bank of Kenya's cyber mandate.

Ghana's supervisors

The Data Protection Commission under Act 843, and the Bank of Ghana's cyber and information security directive.

Egypt's supervisors

The Data Protection Centre's licence-and-permit regime, and the Central Bank of Egypt's AML/CFT requirements with the EMLCU.

Morocco, Rwanda, Tanzania & Uganda

The newer privacy supervisors: Morocco's CNDP, Rwanda's NCSA (with its 48-hour clock and localisation rule), Uganda's PDPO and Tanzania's PDPC.

The regional & continental bodies

The BCEAO's uniform AML law across eight WAEMU states, the ECOWAS data-protection baseline, and the AU's Malabo Convention, in force since 2023.

The international standards bodies

ISO/IEC, the AICPA, the PCI Security Standards Council, NIST, the EU and US HHS: the standards your customers, partners and certifiers audit against.

The wider Nigerian stack

The regulators that reach you by sector or listing: the SEC's digital-asset rules, NDIC deposit insurance and the national governance code.

SEC VASP RulesNDIC ObligationsFRC CodeBOFIA 2020Cybercrimes Act

The industry & sector bodies

SWIFT's Customer Security Programme, attested annually by every participant, and the GSMA's Mobile Money Certification.

Built to a published supervisory expectation.

The Baseline Standards for Automated AML/CFT/CPF (March 2026) require an automated AML system that is defensible, governed, and demonstrably effective, and the institution is responsible regardless of vendor. Our architecture maps to it pillar for pillar.

Defensibility

Audit trails, explainable decisions, traceability, the immutable audit log under every action.

Governance

Model ownership, independent validation, change control, the Model Governance module.

Demonstrable effectiveness

Evidence that the control runs and works, the live-evidence engine being built on the AML/KYC rails.

A new circular, mapped once, inherited by all.

The catalog is curated by reviewed release, never edited at runtime. We watch the regulators directly; a human curator drafts, reviews and approves every update, with agent-assisted monitoring in active development. No re-implementation, no version drift.

01

Authored

A reviewed data file, a stable framework identity, version, and requirements, with normative text paraphrased, never pasted.

02

Compiled

A deterministic generator turns it into a reviewed, versioned release: the artifact of record. The data file never loads at runtime.

03

Applied

The release is applied under privileged review. The catalog is read-only to every customer; nothing, not even our console, edits it live.

04

Inherited

You see the new (framework, version) through the resolver and adopt deliberately. Resolve, never copy: nothing is duplicated into your workspace.

Resolve, never copy. The catalog is never duplicated into customer workspaces, and a new version never silently mutates an adoption: the resolver surfaces the upgrade and you adopt on your terms.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.