Skip to Content
OCCUPATIONAL HEALTH AND SAFETY COMPLIANCE

Compliance files go stale. Our system keeps yours current.

Your appointments, registers, certificates and evidence stay live between audits, not just on the day one is done. Run to the Act and the regulations, remote by design, anywhere in South Africa.

GRC Shop gives South African businesses one central operating layer for compliance. Activate the APP that fits your needs now, then expand over time without rebuilding the record, workflows or visibility. Software handles the tracking, reminders and paperwork; qualified people own the review and sign-off.

B-BBEE Exempt Micro Enterprise (EME) · Reg. 2025/768856/07

South Africa focused APP-led onboarding Built to expand by APP Advisors can collaborate
Appointment letters
S16(2)
Statutory registers
Kept live
Certificate expiry
Tracked
Incident reporting
GAR 9
Risk assessment
HIRA
Inspector evidence
Ready
GRC Core
ENGINE
Your OHS Act duties, kept current between audits

Talk to us about your OHS compliance

Tell us where you are exposed and we will come back to you within two business days. No obligation.

What GRC Shop does

GRC Shop is an outsourced occupational health and safety compliance service for South African employers. We take on your duties under the Occupational Health and Safety Act 85 of 1993: statutory appointments and their letters, the registers you are required to keep, certificate and expiry tracking, incident reporting timelines, and the evidence an inspector asks to see.

The work is done remotely and supervised, and every appointment and register is traced to the section or regulation that requires it. You get an app you can log into, so the current state of your compliance is visible rather than sitting in someone else’s filing cabinet.

Occupational health and safety is the only service available today. POPIA, labour, CIPC, SARS and FICA are on the roadmap and are not services you can buy from us yet. The checklists we publish for those areas are free guides, not products.

How you can check us before you commit

We are a young firm, so rather than ask you to take our word for it, here is work you can inspect yourself right now.

Every requirement is sourced

Our published OHS Inspection Register carries 52 citations to sections of the Occupational Health and Safety Act and 74 to its regulations. Where a figure is our operating practice rather than an explicit legal ratio, the page says so instead of presenting it as law.

We publish our corrections

When we get something wrong we correct it in public and date it, rather than quietly editing the page. Our most recent published correction is dated 25 August 2026.

The site is tested, not assumed

Automated WCAG 2.1 AA testing with axe-core on 30 August 2026 returned zero violations on our OHS service page, the inspection register and the FAQ. Automated testing does not catch everything, so we say what was measured and when.

What you actually see

Every requirement we track is separated into what the law requires and what is good practice, with the section or regulation named beside it. Nothing is asserted without a source.

GRC Shop client compliance view for a demonstration company, showing statutory Layer 1 requirements separated from Layer 2 best practice, with the section of the Act or regulation cited beside each line.
The client compliance view. Figures shown are demonstration data, not a real client.
01
Live record

One managed operating layer keeps obligations, workflows, evidence and visibility current.

02
One App per Domain

Start with one compliance domain, then add more APPs without rebuilding the model.

03
Continuous oversight

Internal changes, specialist input and regulatory updates keep the record live over time.

Centralised and live

One live compliance record replaces fragmented files, scattered updates and version confusion.

Continuous oversight

Reviews, actions, renewals and follow-through stay active after the first setup.

Remote model built to scale

National reach, tighter turnaround and less cost drag than visit-heavy delivery models.

Controlled cost and control

Clients keep visibility and approvals without carrying the full admin burden internally.

PLATFORM OVERVIEW
The GRC Shop client dashboard: live compliance status, fine-exposure calculator and what needs attention, for a South African business

What clients see every day: live compliance status, fine-risk exposure and exactly what needs attention.

One operating layer for compliance

Centralise records, actions, evidence and approvals in one managed environment. The platform keeps every active APP connected so the compliance record stays visible and current.

The Platform is not just where you start. It is the integration layer that connects every APP you add. One record. One place. No disconnected systems.

Central record

It keeps the compliance record live across documents, actions, evidence, permissions, reviews and renewals, not just at setup but continuously.

APP-based domains

Each APP covers one compliance domain with its own workflows, documents and obligations, all running inside the same managed environment.

Explore the compliance apps: OHS · POPIA · Labour · FICA / AML · CIPC · SARS

Client control

Client approvals stay where needed. Outside advisors can contribute when needed. The master record still stays centralised and visible.

Traditional models fragment ownership

Files, updates and responsibilities get split across email threads, folders, consultants and internal teams.

Updates get lost between events

Injuries, appointments, renewals, staffing changes and regulatory updates keep moving, even when the documentation pack is already "done".

Many businesses lack in-house capacity

Most businesses do not have the time, systems or specialist coordination needed to keep compliance current on an ongoing basis.

REMOTE BY DESIGN

Remote by design. Built to stay active.

GRC Shop is delivered remotely by design so the service can respond faster, keep process control tighter and support clients across South Africa without travel drag.

01
National reach without travel drag

More clients, more consistency, less time lost to logistics and scheduling friction.

02
Structured records beat ad-hoc files

The operating system becomes the source of truth, and documents are outputs of that system.

03
Better unit economics

The model scales by process, product and platform, not only by adding more consultants.

BASE / 01
Client core record
ALWAYS ON
APP / 02
OHS workspace
FIRST APP
APP / 03
POPIA workspace
PLANNED NEXT
OPS / 04
Reviews + renewals + escalations
MANAGED
ACCESS / 05
Client + advisor permissions
CONTROLLED
FREQUENTLY ASKED QUESTIONS

Questions before you start

Is GRC Shop software or a managed service? +
It is a managed compliance service delivered through a platform. Clients get the structure, visibility and operating layer of software, but the value is in the managed service that keeps the record current.
What exactly is an APP? +
An APP is a managed compliance domain: a structured workspace that covers one area of compliance (such as OHS or POPIA) with its own workflows, documents, obligations and oversight processes, all running inside the shared platform.
Why do we need the platform if we are starting with one APP? +
The platform is what makes the APP expandable. It holds the central record, permissions and operating structure that every APP connects to. Starting with one APP on the platform means you never have to rebuild when you add the next one.
What keeps the compliance record live? +
The managed service does. GRC Shop monitors obligations, tracks renewals, flags changes and follows through on action items, so the record stays current without the client having to chase it internally.
Can we start with only one APP? +
Yes. Clients activate at least one domain from day one and expand over time. The platform is designed to grow with the business without requiring a rebuild each time.
What does it cost? +
Pricing is tailored to the business size, number of APPs and operational complexity. Contact us to get a scoped proposal based on your specific situation.
Can external advisors or auditors access the platform? +
Yes. Advisor access is role-based and client-controlled. Outside advisors can work inside the live record without taking over the client file. Access stays visible and permission-based.
How do regulatory changes get reflected in our record? +
GRC Shop monitors regulatory changes and updates documents, obligations and workflows within the platform as required. Clients are notified and approvals are requested where needed.

What you can check before you talk to us

We are early and we would rather be checkable than impressive. Everything below is either published on this site or verifiable independently, so you can form a view without taking our word for anything.

The OHS service is live, not a demo

The occupational health and safety app is in service and carrying real statutory obligations. The screenshots on this site are the actual client portal, not mockups: the modelled fine exposure position, the compliance status, the appointment letters and the registers.

See what it manages

Our workings are published, with the section behind them

Five free compliance checklists covering POPIA, Labour, FICA, CIPC and SARS, plus an OHS Act guide. Every item carries the section of the Act or the regulation it comes from, so you can check us against the primary source rather than against our confidence.

Read the checklists

We publish where the market gets it wrong

The widely repeated ratio of one health and safety representative per 20 employees is not what the Act says. We set out the correct position, with the subsection, because a provider who repeats the market version will compute your shortfall wrongly.

See the thresholds

Our own compliance is on the table

02X (Pty) Ltd t/a GRC Shop, registration 2025/768856/07, verifiable at CIPC. Our PAIA manual, our public POPIA policy and our B-BBEE Exempt Micro Enterprise certificate are all published and downloadable, not available on request.

Read the PAIA manual

A named person signs off

Software handles the tracking, the reminders and the paperwork. A qualified person owns the review and the sign-off, and that person is named, with credentials you can verify against the professional bodies that issued them.

Who signs off, and the credentials behind it

We say what stays with you

We surface the obligation, the evidence and the gap. You decide on remediation and you remain the party the regulator holds responsible, because that is how the statutes are written and no service agreement changes it. Anyone promising otherwise is overselling.

How the split works

Professional indemnity cover is in place

We carry professional indemnity insurance for the compliance work we do. Written confirmation of cover is available on request, and we confirm it in writing before any engagement starts.

Why there are no testimonials on this page. Our client relationships are confidential, and we will not publish a quote we do not have written consent for, or one we wrote ourselves. When a client is willing to be named and quoted, their words will appear here and nobody else’s will. In the meantime, the checkable things above are a better basis for a decision than a paragraph in quotation marks.

Our own record

Method metrics, not client outcomes

We will not publish an aggregate drawn from a single client, so instead we publish what can be checked about how we work. Every number below is verifiable on this website without asking us for anything.

52 and 74sections and regulations

Cited in our public OHS inspection register, each item anchored to the provision behind it rather than asserted.

Zeroaccessibility violations

Automated WCAG 2.1 AA testing on the pages we audit, re-run after every material change. Automated testing catches part of the picture, so this is a floor and not a certificate.

25 August 2026a correction, published

We had a statutory detail wrong. We corrected it in the register, in the guide that repeated it and in the diagram that illustrated it, and we said so in writing instead of editing quietly.

Twobusiness days

The response commitment on every enquiry from this website, stated the same way on every page that carries a form.

What is deliberately not here: client counts, hours saved and percentage improvements. We have one external client onboarding and no permission to name them, so any aggregate would mislead you. When there is a client outcome to publish, it will carry a name and a number.

WHO STANDS BEHIND YOUR COMPLIANCE

Named people, not a faceless app

GRC Shop is run by 02X (Pty) Ltd, a registered South African company. Qualified people build the work, review it, and sign it off. Software handles the tracking, reminders and paperwork; people own the accountability.

Registered company

02X (Pty) Ltd t/a GRC Shop. Registration 2025/768856/07. B-BBEE Exempt Micro Enterprise.

Qualified sign-off

Founder Philip de Witt: Chartered Management Accountant (ACMA, CGMA), MBA from the UCT Graduate School of Business, and an ISO 45001:2018 occupational health and safety qualification from the SABS.

Chartered finance and governance

A CA(SA) chartered accountant on our team keeps the financial and governance controls sound.

POPIA and PAIA

Your information is handled under POPIA, and our PAIA manual is published and available on request.

Qualified people own the review and sign-off on the compliance work we produce for you. Meet the founder.

NEXT STEP

Get started with the right setup

Tell us where the biggest compliance pressure is right now. We will review the context, share your Platform link, and guide you to the APP or APPs that fit your business, location and risk profile.

Platform link Select APPs Structured onboarding Live managed record
Get started →