Scale by Peregrine

PESIFA Compliance Engine

Every great organization has a compliance story. This is the engine that helps you tell it.

Peregrine EMS transforms the compliance journey — from chaotic first audit to certified, confident, continuously compliant — for consultants and the clients they serve.

The compliance journey

It starts with a challenge

Every hero's journey begins with a call. For most organizations, that call arrives as a tender that requires ISO 27001. A regulator asking for NDPC filings. A client due-diligence questionnaire with 200 questions. A board asking, "Are we actually compliant?"

Suddenly, compliance is no longer a back-office task — it's the gate between where you are and where you need to be.

And for the consultants answering that call, the challenge is even bigger: juggling multiple clients, scattered evidence, endless spreadsheets, and the sinking feeling that one missed renewal or untracked consent could undo months of work.

Enter the Compliance Engine

Every hero needs a mentor — a guide who has walked the path a thousand times. The Peregrine Compliance Engine is that guide. It doesn't just store your documents; it walks with you through every stage of the journey:

Compliance Engine dashboard — readiness score, gap register, framework coverage
  • Discover what frameworks apply and where your gaps are
  • Build policies, procedures, and registers that meet regulatory standards
  • Collect and organize evidence without the spreadsheet chaos
  • Train staff, track awareness, and prove it happened
  • Monitor continuously — so you're never surprised by an audit again

The tools that carry you through every trial

Two worlds, one engine — Nigeria's data protection rules and global ISO standards, handled side by side.

The journey has five stages. Each one is powered by tools built for real regulatory work — not generic checklists.

NDPC logo
ISO Certified badge
Stage 01

The Discovery

— Assess where you stand
  • Pre-Assessment Readiness scoring across ISO 27001, 22301, 9001, 14001, 45001, PCI DSS and more
  • Gap Analysis and Gap Registers that turn uncertainty into a plan
  • Risk Assessment frameworks that score and prioritize what matters
The Discovery
Stage 02

The Preparation

— Build the foundations
  • A Policy Review & Scoring Studio that grades your existing policies A–F, then rewrites them to a ready-to-implement standard — with before/after comparison documents
  • AI-assisted document generation for policies, SOPs and work instructions tailored to your organization's context
  • Governance Role Registry, ISMS Scope Builder, and Process Registry to structure the program properly from day one
Preparation step 1
Stage 03

The Proof

— NDPR and ISO, in parallel

The NDPR Toolkit — built for Nigeria's Data Protection Act

  • NDPC Assessment Center with Schedule 2, 3, 4, 8 and 9 filing forms — fill them directly on the official PDF templates and export clean, submission-ready documents
  • Consent Engine with shareable consent campaigns (signature, initials or yes/no), recipient tracking and automated reminders
  • Records of Processing Activities (ROPA), DPIA engine, Processor Register and Data Subject Request handling — the full NDPA toolkit
  • Privacy Incident module and Retention & Deletion engine
The NDPR Toolkit — built for Nigeria's Data Protection Act

The ISO & Framework Toolkit

  • Evidence Repository with control mapping across every framework
  • Evidence Collection Tasks with assignees, due dates and review workflows
  • Training & Awareness builder — generate training manuals, run scored quizzes, issue certificates, and capture policy acknowledgments
  • Surveillance System that schedules internal audits, management reviews, document reviews and re-validations — with automatic reminders before anything goes overdue
The ISO & Framework Toolkit
Stage 04

The Ordeal

— Audit day, without the fear
  • Audit Trail that records who did what, and when — every action traceable
  • Compliance Journey panel showing a complete, visual history from first assessment to certification
  • Client Portal so your clients see their progress, their documents and their next steps — live, any time
The Ordeal
Stage 05

The Return

— Certification and beyond
  • Certification Readiness dashboard — know exactly when you're ready to face the certifier
  • Ongoing surveillance and retainer management so compliance never lapses after the certificate is framed
  • One unified Registers page — consents, incidents, processors, requests, evidence — always current
NDPR badgeISO Certified badge

Built for the people who guide the journey

Most compliance tools are built for a single company managing itself. Peregrine is built for the consultant managing many.

Consultant Workspace with multiple client engagement cards
  • A multi-client Consultant Workspace — every engagement, client and framework in one place
  • Client Onboarding & Risk Assessment framework with engagement models, retainers and review logs
  • Handover management — from one-time build-and-handover to ongoing retained engagements
  • Client invitations and access levels (view, comment, full) so clients stay informed without risking your work
  • Multi-tenant Client Portals — each client sees only their own compliance world
  • Automated reminders and surveillance so nothing slips between engagements

"Instead of chasing five clients through five sets of spreadsheets, I run every engagement from one dashboard — and my clients can finally see the value I deliver."

Your clients stop fearing compliance — and start benefiting from it

For the organizations on the other side of the journey:

Client-facing readiness dashboard
  • See the whole picture — a live readiness score instead of vague status updates
  • Fill NDPC and compliance forms directly on official templates, with nothing to install
  • Watch their consent records, training completion and evidence grow in real time
  • Be audit-ready every day — not just the month before the audit

The reward at the end of the road

Organizations that complete the journey with Peregrine walk away with:

Certification-ready compliance programs across ISO and NDPA frameworks

Documented, evidenced, defensible data protection practices

Staff who are trained, tested and on record

A consultant relationship that runs on progress, not paperwork

The one thing every hero earns at journey's end: confidence