Why I built GRC Shop
Nineteen years of assembling scattered records into decisions, turned into a system so nobody else has to.
I spent nineteen years as the person who had to produce the picture.
Auditing clerk, financial accountant, group financial manager, acting CFO, CFOO. Different companies, different countries, the same problem underneath every one of them: the information existed, but it was scattered. Printed copies in folders. Files across shared drives. Critical records sitting on somebody's own desktop, which left the building when they did.
Getting hold of it required meetings. Meetings for things that should have taken a minute. Then the real work started, which was assembling all of it into a timeline so that a logical picture could form, a picture that should have been there from the beginning.
Days of that. And at the end of it, exhausted, we would finally have something to decide with. Except by then something else had become urgent, the decision got deferred, and the whole cycle began again. Days of compiling fatigue, for no decision at all.
The part that stayed with me was how it looked from outside. Everyone in the business grew frustrated. And you look inefficient, while what you are actually doing is solving other people's messes.
I did eventually fix it in finance, and not by working harder. We put in SAP. We moved a manual process to paperless. Audit preparation dropped by over a month. Not because anyone became cleverer, but because the record finally lived in one place and stayed current on its own.
Then I started 02X, and found the same problem waiting for me in compliance, only worse, because there is no ERP for compliance.
Every Act arrives in its own wrapper. Even where two Acts are plainly meant to work together, they stay separate. The law does not have to be coherent. The business still has to comply with all of it. So you end up with the OHS file in one place, the POPIA register in another, the employment equity submission somewhere else, the contract or contracts sitting in an email account that needs recovery after someone left, no minutes whatsoever, and no single view nor a holistic risk register of whether you are actually covered and not.
I looked at what the market offered. Paper. Scattered files. Or software built for very large enterprises at prices that assume you have a compliance department.
So the opportunity was obvious, and it was the same move that had already happened to accounting: one system of record, everything current, one place to look before you decide.
I am not a developer. I built it anyway, because it is very difficult to explain a problem to someone else when you are not the one living it. When you are solving the problem yourself, you know what it actually is, and you are better placed to solve it than someone who has only had it described to them.
What I want GRC Shop to do is reduce the chaos.
South African business conditions are hard enough. Margins are thin. Laws arrive that were designed politically rather than practically, with enforcement that was not thought through, landing on an already over-burdened system. Business owners are asked to achieve outcomes that are poorly explained, and most of the time people do not know what they do not know.
Meanwhile, the business still has to do the thing it was created to do.
GRC Shop exists so that the compliance information is in one place, current, and ready when a decision has to be made, so that the time goes back to running the business.
We run the machine, so you can run the business.
Philip de Witt
ACMA, CGMA (CIMA) · MBA (UCT Graduate School of Business)
Founder, 02X (Pty) Ltd t/a GRC Shop
Chartered management accountant with nineteen years in financial governance and risk. ISO 45001:2018 Occupational Health and Safety Management Systems training through the SABS Training Academy. Led a healthcare group to a Cape Town Stock Exchange listing in thirteen months and R200 000 under budget, and cleared eight to nine years of statutory backlogs to get there.