Skip to Content

The compliance platform for South African businesses

One managed platform that keeps your compliance current. AI does the document and tracking work; our human team supervises and handles the judgement calls.

How the platform runs

GRC Shop runs an eight-phase compliance harness: intake, gap analysis, document generation, legislation mapping, client communications, monitoring, reporting, and orchestration. Each phase has a defined output and a defined owner. There is a human gate before anything is published or filed on your behalf. Every compliance area we cover (OHS first; POPIA, Labour, FICA/AML, CIPC and SARS to follow) plugs into the same harness, so onboarding a new area is fast and consistent.

Inside the GRC Shop platform: the My Compliance view showing every OHS duty and its live status for a South African business

Inside the platform: every area of your compliance, and exactly where each one stands. Live client view.

What the platform does

Intake & classification

Captures your organisation, employee count, sites, COIDA risk tier and the legislation that applies to you, in one structured pass. No long onboarding form.

Gap analysis

Runs per site and per legal entity, mapping your current state to the required state. The output is a clear punch list, not a vague heat map, that the team can act on immediately.

Document generation

Builds the policies, registers, statutory appointments, HIRA, COIDA returns, incident workflows and notices you need, populated from your gap analysis. Output is reviewed by a qualified human before going to you.

Legislation mapping

Keeps the framework current as regulators issue amendments, directives and gazettes. You always know which act, regulation and standard applies to a given control.

Client communications

Handles the back and forth: uploads, evidence collection, signatures and escalations, without you chasing inboxes. You see what is outstanding on a single page.

LiveMonitoring, reporting and orchestration

Quietly running between events: deadline reminders, renewal trackers, audit-ready reports for management or the board, and orchestration of the work flowing across phases.

What the platform is responsible for

Compliance software usually fails in one of two ways. Either it becomes a document library that ages quietly, or it hands the work back to the client under a nicer interface. The platform is designed around avoiding both, which means it is responsible for specific things rather than for a general feeling of being organised.

One client record

Sites, legal entities, employees, contractors and documents held once and reused by every app. Adding a second compliance domain does not mean re-entering the business.

Requirements, computed

What each site actually requires is computed from its headcount, its activities and its risk profile against the sourced statutory rules, rather than typed in by hand. When the headcount crosses a threshold, the requirement changes with it.

Evidence linked to obligation

An appointment letter is linked to the certificate that supports it. When the certificate lapses, the appointment stops counting. A register that looks complete but is held up by an expired certificate is exactly what an inspection finds.

Deadlines that run themselves

Renewals, review cycles, quarterly meetings, statutory return dates and investigation clocks run on the record rather than on somebody remembering. The reminder goes to the person who owns the action.

An inspection ready view

The registers, appointments, certificates, incident records and risk assessments a Department of Employment and Labour inspector asks for, in one place, current, with the dates visible.

A rule set that is maintained

Statutory rules are sourced from the Act and the gazetted regulation, held as data with the reference attached, and updated when the law moves. That maintenance is part of the service, not an upgrade.

What stays with you. The platform surfaces the obligation, the evidence and the gap. You decide on remediation and you remain the party the regulator holds responsible, because that is how the statutes are written and no service agreement changes it. What we are accountable for is that the obligation was identified correctly, raised in time and evidenced properly.

Questions about the platform

Do I need the platform if I only want one app?

Yes, and you get it either way. The platform is the layer that makes an app work: the client record, the sites and employees, the document store, the evidence trail, the permissions and the reminder engine. It is not a separate purchase decision.

Where does our data live, and who can see it?

Client records are held per client with role based access, so a client sees only their own position. Data is treated on a purpose basis, with retention set by why the record exists rather than by a single blanket period, and categories the law protects separately are handled separately. We do not sell client data and we do not use it for any purpose outside delivering the service.

What happens when the law changes?

Statutory rules are held as sourced data with the gazette reference attached, rather than scattered through application code, and amendments are tracked against the Government Gazette and applied to the rule set. That matters more than it sounds: three South African occupational health and safety regulation sets were amended in 2025 and 2026, and one long standing set is repealed in September 2026.

Can we get our records out if we leave?

Yes. The documents, registers and evidence in your record are yours. The platform holds them in standard formats and they are exportable, because a compliance record you cannot take with you is not really a compliance record.

Ready to start?

Tell us where you stand. We will come back within one business day with a tailored scope.

Book a Discovery CallSend us a message

Explore: Apps · FAQ · Resources · Contact