Rectiva Portico Risk managed. Value created.

Turning uncertainty into advantage.

The governance work a regulator expects, held in one place.

Rectiva Portico is a Governance, Risk and Compliance (GRC) platform built for small-to-medium sized regulated financial institutions (or those pending licence issuance): the institutions expected to demonstrate the same controls as a top tier bank, without a top tier bank's GRC department in terms of budget and resources.

The compliance landscape

Twice as much
the compliance burden on the smallest regulated institutions compared to their largest peers, for the same standard, the same scrutiny, and the same expectation from the examiner
CSBS Working Paper 25-01, 2025
61%
growth in bank compliance hours from 2016 to 2023, at three times the rate of overall headcount growth. The obligation is outpacing every institution's capacity to meet it
Bank Policy Institute, October 2024
80%
of bank risk chiefs worldwide who cite data quality and availability as the primary barrier to effective risk management: not regulation, not budget, but the records themselves
EY / IIF 15th Annual Global Bank Risk Management Survey, February 2026
KSh 191 million
in CBK fines in the year to June 2024, nearly triple the prior year, before new legislation raised the per-breach ceiling to KSh 20 million or three times the financial benefit gained
Business Daily Africa, citing CBK Annual Report 2024
Grey-listed
Kenya placed on FATF's increased-monitoring list in February 2024. Documented governance is now a commercial necessity for every regulated institution's cross-border activity
FATF: Jurisdictions under Increased Monitoring, February 2024

The platform

Registers, assessments and evidence that stay connected

Most institutions already do this work. It lives in spreadsheets that disagree with each other, and the connections between them exist only in one person's head.

Regulatory horizon scanning

Continuous monitoring across regulatory, enforcement and news sources, drafted into a weekly briefing by AI and written against your own open risks and outstanding tasks — not a generic newsletter. Reviewed and published by your own super admin or second line before it reaches your inbox.

Risk register

A structured register covering inherent and residual exposure, treatment plans, and periodic review. Every risk has an owner, a signed-off assessment, and a clear connection to the controls that mitigate it.

Compliance monitoring

Recurring assessments mapped to the frameworks that apply to your licence and jurisdiction. Questions are structured to surface genuine gaps rather than generate compliance-theatre paperwork.

Incidents and near misses

A register for reporting, investigating and closing incidents, with a direct link to the underlying risk. Patterns across reporting periods become visible rather than buried in individual files.

Policy library

Versioned policies with named owners, scheduled review dates, and a record of staff acknowledgements you can produce on request.

Third-party register

Suppliers catalogued and tiered by criticality, with due diligence requirements that scale to the tier. A supplier handling customer data is assessed considerably more rigorously than a stationery supplier.

Annual assessments

Risk maturity, compliance, and a business-wide financial crime risk assessment following the FATF Recommendation 1 methodology, which is what regulators look for.

Board reporting

A board pack assembled from your live data, with follow-up actions tracked to closure. Produced from the same records rather than retyped from them.

Full audit trail

A complete record of who changed what and when, visible to your own administrators. This includes any access by our own staff, so you are never asked to take our word for it.

What is in the box

Content, not just software

The questionnaires, policy templates and methodologies are written in and shipped with the platform. You are not buying an empty database to fill in yourself.

28
compliance domains, ready to schedule
129
assessment questions with guidance and evidence requirements
9
regulatory frameworks mapped, from CBK and BoU to FATF and ISO 27001
10
policy templates, personalised to your institution

Who it's for

Built for the institutions the market usually skips

Geographies

Institutions overseen by regulators such as the Central Bank of Kenya (CBK), Office of Data Protection Commissioner (ODPC), Communications Authority of Kenya (CA), Financial Reporting Centre (FRC), Office of the Registrar of Companies (BRS) and Kenya Revenue Authority (KRA), and their equivalents in Uganda. Questionnaires are jurisdiction-aware: a Kenyan institution is not assessed against Ugandan rules, and the annexes relevant to one jurisdiction appear only where they apply. Coverage in Tanzania and Rwanda is on the near-term roadmap.

Institution types

Digital Credit Providers (DCPs), SACCOs, credit-only microfinance institutions, and other non-deposit-taking financial institutions. Sized for institutions of up to 500 staff, held to bank-equivalent regulatory standards without bank-equivalent headcount.

Three lines of defence

Access is organised the way an institution's governance already is. Internal audit has read access it cannot write through, first line sees its own business unit, and the separation is enforced in the database rather than only in the interface.

Cost comparison

See how much you could save versus hiring additional GRC staff

Answer a few questions about your institution and get an estimate of how the platform compares with the cost of resourcing this function with additional headcount.

Pricing

Simple, transparent pricing

Pick your plan, then a billing cadence — add-ons are shown below, priced for the plan you picked.

Essentials

Up to 25 staff

$300/mo
$270/mo
$255/mo
$300/moSave 10%
$300/moSave 15%

Every core register, assessment and reporting module.

Request a demonstration

Growth

26–75 staff

$450/mo
$405/mo
$383/mo
$450/moSave 10%
$450/moSave 15%

Everything in Essentials, sized for a bigger team.

Request a demonstration

Scale

76–200 staff

$700/mo
$630/mo
$595/mo
$700/moSave 10%
$700/moSave 15%

Everything in Essentials, sized for a bigger team.

Request a demonstration

Enterprise

201–500 staff

$1,100/mo
$990/mo
$935/mo
$1,100/moSave 10%
$1,100/moSave 15%

Everything in Essentials, sized for a bigger team. Add-ons below carry a further Enterprise discount.

Request a demonstration

Enterprise+

500+ staff

Custom

Quoted against seat count and the modules you need — we would rather discuss the detail than publish a number that fits nobody. Add-ons below carry a further Enterprise+ discount.

Talk to us

Add-ons

Priced for your plan

Independent of the platform subscription — choose any cadence for each. Enterprise and Enterprise+ plans get a further discount, already reflected below.

Training

Add-on

$180/mo
$162/mo
$153/mo
$171/mo
$153/mo
$144/mo
$162/mo
$144/mo
$135/mo
$180/moSave 10%
$180/moSave 15%
$180/moSave 5%
$180/moSave 15%
$180/moSave 20%
$180/moSave 10%
$180/moSave 20%
$180/moSave 25%

Includes your Enterprise discount.

Includes your Enterprise+ discount.

Bite-sized compliance courses with certificates regulators can see.

Ask about Training

Horizon Scan+

Add-on

$200/mo
$180/mo
$170/mo
$190/mo
$170/mo
$160/mo
$180/mo
$160/mo
$150/mo
$200/moSave 10%
$200/moSave 15%
$200/moSave 5%
$200/moSave 15%
$200/moSave 20%
$200/moSave 10%
$200/moSave 20%
$200/moSave 25%

Includes your Enterprise discount.

Includes your Enterprise+ discount.

Personalised weekly briefings, the East Africa risk map, and regulatory horizon scanning.

Ask about Horizon Scan+

All prices in USD.

Security and data protection

We hold your compliance records, so we publish our own posture

A GRC vendor that is vague about its own controls is asking you to apply a standard it will not meet.

  • Two-step sign-in required for every user, without exception
  • Role-based access along the three lines of defence, enforced at database level
  • Tenant isolation verified by an automated test suite against the live database
  • Encrypted in transit and at rest
  • Append-only audit log covering access and configuration change
  • Data hosted in the European Union (Frankfurt). EU data-protection standards apply throughout. For institutions in Kenya or Uganda, transfers are supported by equivalent safeguards and standard contractual arrangements; the nature of data typically held in the platform means data-localisation requirements are unlikely to be triggered, though we confirm the position for each institution before contracting.
  • Staff access to your data requires a time-boxed session opened with a recorded reason
  • That access is written into your organisation's own audit log, not only into an internal record you would have to request from us
  • Retention configurable to your regulator's requirement
  • Every register exportable on demand as a single workbook — your data is portable whenever you need it, not held hostage to keep you subscribed

Read the full security and data-protection statement →

Get in touch

See it against your own obligations

A demonstration works best when it is run against the frameworks that actually apply to your licence. Tell us who regulates you and what you are required to evidence, and we will show you that rather than a generic tour.

See full pricing for the base platform and add-ons.