GRC Software for South African Organisations
South African organisations operate within one of the most demanding governance, risk, and compliance environments in the world.
Built for how South Africa actually works
South Africa's corporate governance landscape is shaped by the King Reports, which have been the definitive governance standard for all types of organisations — listed companies, state-owned entities, municipalities, non-profits, and private enterprises — since King I was published in 1994. King IV, effective since 2016, introduced the apply-and-explain regime and shifted governance from a compliance checkbox exercise to an outcomes-based approach built around ethical culture, value creation, and stakeholder inclusivity. King V, published on 31 October 2025 by the Institute of Directors in South Africa, builds on this foundation with 13 governance principles, a simplified structure, and the King V Disclosure Framework — a standardised format for governance reporting that replaces the ad hoc narrative disclosures organisations previously used. For boards and risk committees, this means governance reporting must now be more structured, consistent, and evidence-based than ever before.
King IV/V Governance & Disclosure Framework
King IV and King V require organisations to demonstrate governance outcomes across leadership, ethics, strategy, risk, compliance, and stakeholder relationships. Dimeri maps every risk in your register to the relevant King IV or King V governance principle, tracks the status of each governance outcome, and generates disclosure reports aligned to the King V Disclosure Framework. Board members and risk committee chairs can see at a glance which governance principles are fully addressed, which have gaps, and what remediation actions are underway. When King V requires you to disclose how your governing body oversees technology and information governance, AI governance, or stakeholder relationship management, Dimeri provides the structured evidence trail that supports each disclosure.
POPIA Compliance Management
POPIA compliance requires documented lawful basis for every category of personal information processed, impact assessments, breach notification procedures, operator agreements, and evidence of ongoing compliance. Dimeri creates a structured POPIA compliance register that links every processing activity to its lawful basis, tracks consent records and data subject requests, manages operator agreements and cross-border transfer documentation, and logs breach incidents with notification timelines. When the Information Regulator requests evidence of compliance, everything is traceable in a single system with a complete audit trail — no more chasing spreadsheets across departments.
Combined Assurance & Three Lines Model
The IIA Three Lines Model and King IV/V both require organisations to implement combined assurance — coordinating the activities of management (first line), risk and compliance functions (second line), and internal and external audit (third line) to provide comprehensive assurance coverage without duplication or gaps. Dimeri maps assurance activities across all three lines to the risks and controls they cover, identifies assurance gaps and overlaps, tracks the status and findings of each assurance activity, and presents a single combined assurance dashboard to the audit and risk committee. The result is a complete view of who is providing assurance over what, where the coverage gaps are, and what the findings show — updated in real time as assurance activities are completed.
Board Risk Reporting & Governance Outcomes
South African boards and risk committees require governance reports that are structured, evidence-based, and aligned to King IV/V outcomes. Dimeri generates board-ready risk and governance reports that present the current risk profile mapped to governance principles, the status of compliance obligations, combined assurance coverage, emerging risk trends identified by AI, and remediation progress against previous committee recommendations. Reports are generated in the format expected by South African boards — with governance outcome ratings, trend arrows, risk appetite indicators, and supporting evidence references — eliminating the weeks of manual preparation that most organisations currently invest in board pack production.
One platform, every obligation
Risk, controls, incidents and reporting on a single record, so the same work serves every framework you answer to.
The frameworks you answer to
Mapped out of the box, with shared controls written once and credited to each framework rather than rebuilt for every one.
King IV/V governance mapping maintained in a static Word document or spreadsheet that is outdated within weeks of creation
Living governance register that maps risks to King IV and King V principles in real time, updated automatically as risks and controls change
POPIA processing records scattered across department spreadsheets with no central view of compliance status or evidence trail
Centralised POPIA compliance register with full traceability from processing activity to lawful basis, impact assessment, and compliance evidence
Controls that carry evidence
Preventive, detective and corrective controls with their test results and owners, linked to the risks they treat.
Frequently Asked Questions
Common Questions
Put your whole risk picture on one register
AI analysis has identified that the King V Principle 11 risk governance gap (SA-001) and the POPIA Section 19 security safeguards deficiency (SA-002) share a common root cause: inconsistent documentation practices across business units. Three departments lack formalised procedures for documenting risk decisions and data processing activities. Addressing the documentation gap through a centralised policy framework would reduce residual risk scores for both items by an estimated 35% and close two audit findings simultaneously.
Book a demo