The standards you answer to, curated once.
One stack of obligations, many hands issuing it.
Comprehensiveness is the value: one system mapped to what you're actually audited against, not a token few frameworks. Solid entries are curated and adoptable today; the rest are next through the same reviewed pipeline.
Central Bank of Nigeria
The primary supervisor of Nigerian banking and payments: AML, cybersecurity, KYC and the conduct of the institutions it licenses.
NFIU & the federal statutes
The financial-intelligence unit your reports land with, and the Acts of the National Assembly beneath the whole financial-crime regime.
South Africa's supervisors
The Information Regulator for privacy, the Financial Intelligence Centre for AML, and the Prudential Authority with the FSCA for cyber resilience.
Kenya's supervisors
The Office of the Data Protection Commissioner, one of Africa's most active privacy regulators, and the Central Bank of Kenya's cyber mandate.
Ghana's supervisors
The Data Protection Commission under Act 843, and the Bank of Ghana's cyber and information security directive.
Egypt's supervisors
The Data Protection Centre's licence-and-permit regime, and the Central Bank of Egypt's AML/CFT requirements with the EMLCU.
Morocco, Rwanda, Tanzania & Uganda
The newer privacy supervisors: Morocco's CNDP, Rwanda's NCSA (with its 48-hour clock and localisation rule), Uganda's PDPO and Tanzania's PDPC.
The regional & continental bodies
The BCEAO's uniform AML law across eight WAEMU states, the ECOWAS data-protection baseline, and the AU's Malabo Convention, in force since 2023.
The international standards bodies
ISO/IEC, the AICPA, the PCI Security Standards Council, NIST, the EU and US HHS: the standards your customers, partners and certifiers audit against.
The wider Nigerian stack
The regulators that reach you by sector or listing: the SEC's digital-asset rules, NDIC deposit insurance and the national governance code.
The industry & sector bodies
SWIFT's Customer Security Programme, attested annually by every participant, and the GSMA's Mobile Money Certification.
Built to a published supervisory expectation.
The Baseline Standards for Automated AML/CFT/CPF (March 2026) require an automated AML system that is defensible, governed, and demonstrably effective, and the institution is responsible regardless of vendor. Our architecture maps to it pillar for pillar.
Audit trails, explainable decisions, traceability, the immutable audit log under every action.
Model ownership, independent validation, change control, the Model Governance module.
Evidence that the control runs and works, the live-evidence engine being built on the AML/KYC rails.
A new circular, mapped once, inherited by all.
The catalog is curated by reviewed release, never edited at runtime. We watch the regulators directly; a human curator drafts, reviews and approves every update, with agent-assisted monitoring in active development. No re-implementation, no version drift.
Authored
A reviewed data file, a stable framework identity, version, and requirements, with normative text paraphrased, never pasted.
Compiled
A deterministic generator turns it into a reviewed, versioned release: the artifact of record. The data file never loads at runtime.
Applied
The release is applied under privileged review. The catalog is read-only to every customer; nothing, not even our console, edits it live.
Inherited
You see the new (framework, version) through the resolver and adopt deliberately. Resolve, never copy: nothing is duplicated into your workspace.
Resolve, never copy. The catalog is never duplicated into customer workspaces, and a new version never silently mutates an adoption: the resolver surfaces the upgrade and you adopt on your terms.
Compliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.