mySolutions
IBM OpenPages · AI-Powered GRC Platform

Know the risk. Before it knows you.

IBM OpenPages is the world’s leading AI-powered Governance, Risk and Compliance platform, recognised as a leader by Gartner, Forrester, IDC, and G2. mySolutions brings it to South African organisations with in-house implementation, local regulatory expertise, and full support in ZAR.

218% ROI in the Forrester Total Economic Impact study of IBM OpenPages
Leader Gartner Magic Quadrant, GRC Tools for Assurance Leaders (2025)
2,500+ Concurrent users supported on a single OpenPages deployment
OpenPages · risk & control posture Live
Forrester TEI ROI
218%
Gartner MQ
Leader
Concurrent users
2,500+
Operational31
Financial22
IT & cyber18
Third party11
Unmapped3
Illustrative view · not client data
Customer experience

World-class GRC. Implemented and supported in South Africa.

Your implementation is not outsourced. Your support call is not rerouted. Your risk data stays in South Africa.

Most IBM OpenPages implementations in South Africa are managed offshore, with support queues that cross time zones and consultants who have never set foot in a South African regulatory environment. mySolutions is different. We implement, configure, and support IBM OpenPages entirely in-house, from Pretoria.

Our consultants understand POPIA, King IV, FSCA, SARB, MHSA and the JSE Listings Requirements, so your GRC framework is built around your actual obligations from day one.

RegulationWhat it requiresHow OpenPages addresses it
POPIA · Protection of Personal Information Act Lawful data processing, consent management, data subject access requests, an appointed Information Officer, breach notification within 72 hours, and defensible records of data flows. The Data Privacy Management module maps data flows, manages DSAR workflows, tracks POPIA obligations and generates attestations for the Information Regulator.
King IV · Report on Corporate Governance Principles-based governance for JSE-listed companies and registered entities: ethical leadership, effective risk oversight and integrated reporting, evidenced in practice, not just policy. Maps GRC activities to King IV principles, with board-ready dashboards, audit committee reporting and documented evidence of governance in practice.
FSCA · Financial Sector Conduct Authority Conduct risk management, compliance registers, on-time regulatory returns and proof that customers are treated fairly across all products and channels. Centralises conduct risk registers, automates filing workflows, tracks obligations by deadline and surfaces conduct trends before they become supervisory findings.
MHSA · Mine Health and Safety Act Site-level risk assessments, incident registers, corrective action tracking and demonstrable continuous improvement to the DMRE. Non-compliance can shut operations down. Operational Risk and Internal Audit modules track incidents, corrective actions and site-level registers, with a full audit trail for DMRE inspections.
SARB · Prudential Standards (Basel III/IV) Capital adequacy requirements, operational risk event databases, risk data submissions to the Prudential Authority and model risk governance under BCBS 239. Operational Risk, Model Risk Governance and Financial Controls modules map to Basel and PA requirements, with automated event capture and model inventory management.
JSE · Listings Requirements King IV-aligned governance, an effective audit committee and disclosure of material risk exposures in integrated reports, with directors carrying personal liability. Provides the audit trail, board-level reporting and integrated risk disclosure documentation that listed companies and their directors need.

Local implementation

Full OpenPages implementation and configuration delivered by our in-house South African consulting team. No offshore handover.

SA regulatory expertise

We understand POPIA, King IV, FSCA, SARB, MHSA, and JSE Listings Requirements. Your GRC framework is built around your actual obligations.

In-country support

Support in South African business hours, from a team that knows your configuration. No offshore queues, no overnight turnaround on critical issues.

ZAR pricing

Licensed and supported in Rands, with no foreign exchange exposure at renewal.

The problem

Heavily regulated. Under-governed. Sound familiar?

Your risk is being managed in a spreadsheet. That is not risk management. That is a liability.

Risk lives in a spreadsheet

The risk register is a spreadsheet. The audit tracker is another spreadsheet. Controls testing is in email. Nothing connects, and the board gets a summary that is already two weeks out of date.

POPIA is not a once-off project

POPIA compliance is not something you achieve and file away. Data flows change, vendors change, breaches happen. Without a live compliance platform, your POPIA posture is perpetually stale.

Audit preparation consumes the quarter

Auditors arrive and your team spends three weeks pulling evidence from multiple systems. The audit itself takes less time than the preparation. This is a systems problem, not a people problem.

Third-party risk you cannot see

Your vendors, suppliers, and service providers carry risk into your organisation every day. If a key vendor fails or is breached, do you know your exposure today, before it becomes a headline tomorrow?

Every business unit manages risk differently

Finance has their risk framework. IT has theirs. Operations has theirs. They do not connect, and the board sees three different risk pictures and cannot tell which one is true.

Regulatory change is constant

POPIA. King IV. FSCA Conduct Standards. SARB guidance. Mining regulations. Emerging AI governance requirements. Every change requires manual updates to policies, controls, and evidence. This cannot scale.

No evidence trail for the regulator

When FSCA, SARB, or the JSE asks for evidence of regulatory compliance, how quickly can you produce it? If the answer is “we need a few days”, you have a GRC platform problem.

Attestation by attachment

Policy sign-off is collected as PDFs and screenshots, then re-collected next year from scratch.

Platform overview

Already on OpenPages? You may be using 40% of what you paid for.

Many organisations that implemented IBM OpenPages several years ago are still running versions that pre-date the platform’s most significant advances: AI-powered risk scoring, automated regulatory change tracking, and the GRC Canvas visual workflow environment. If your implementation was done by a partner who has since disengaged, or your team has inherited a system nobody fully understands, mySolutions can help.

We assess where you are, close the configuration gaps, migrate you to the current version, and train your team to use the platform the way it was designed to be used.

OpenPages Health Check

We audit your current implementation: workflows, data model, user adoption, version currency, and give you a clear picture of what is and is not working.

Version upgrade

Migration from any prior version to IBM OpenPages 9.x, including data migration, configuration review, and user retraining.

Module activation

Most implementations use 3 or 4 of the available 11 modules. We activate and configure the modules your organisation needs but has not deployed.

Ongoing managed support

Monthly retainer support for organisations without in-house OpenPages administrators: configuration changes, user management, report building.

Regulatory framework updates

Your POPIA, Basel, or ISO framework mapping updated when regulations change, not left as a one-time configuration from day one.

Free to find out

The health check tells you exactly what version you are on, which modules you are not using, and what it would take to get you to current. No obligation.

Eleven integrated modules. One risk platform.

Licence what your governance model needs now and add modules as it matures. All eleven share one data model, one workflow engine and one reporting layer, on OpenPages 9.2.

01

Operational Risk Management

RCSA, loss events, KRIs and scenario analysis in one hierarchy, with appetite thresholds and escalation built in.

02

Regulatory Compliance Management

Regulatory library, obligations mapping and attestation campaigns, with automated regulatory change tracking.

03

Internal Audit Management

Audit planning, fieldwork, findings and remediation tracked to closure with evidence attached.

04

Policy Management

Policy lifecycle, approvals and attestation campaigns with automatic reminders.

05

Financial Controls Management

Control testing, certification and deficiency tracking tied to financial statement line items.

06

Third-Party Risk Management

Vendor assessments, due diligence and ongoing monitoring against your own control set.

07

IT Governance

IT risk, controls and compliance mapped to frameworks such as ISO 27001 and NIST.

08

Business Continuity Management

Business impact analysis, continuity plans and testing evidence in the same risk hierarchy.

09

Model Risk Governance

Model inventory, validation, monitoring and retirement, integrated with IBM watsonx.governance.

10

Data Privacy Management

POPIA and GDPR data flows, DSAR workflows and breach notification obligations.

11

Risk Management for ESG

Track, measure, and report on environmental, social, and governance risk obligations. Connects ESG commitments to the enterprise risk framework for integrated board reporting.

Implementation

Scoped to your governance model, stated up front.

A first module typically runs live within a quarter. Multi-module programmes are phased so each reporting cycle proves itself before the next module starts.

Assess

Current registers, frameworks, committee structures and reporting lines documented and rationalised. For existing OpenPages clients, this is the health check.

Configure

Risk taxonomy, controls, workflows and attestation cycles built and tested with your risk team, module by module.

Run live

First reporting cycle run in parallel with internal audit, then the spreadsheets get retired.

Frameworks & inputs

Built around the frameworks you already report on.

We configure to your existing obligations rather than importing a generic template you then have to argue with.

King IV POPIA FSCA SARB / Basel III & IV MHSA JSE Listings Requirements ISO 27001 SOX GDPR COSO Active Directory / SSO SAP & ERP feeds Power BI
Embedded AI

GRC that thinks. IBM OpenPages with embedded AI.

OpenPages 9.2 embeds AI across the platform, and every recommendation operates within the rules your risk team sets. Just as important, OpenPages governs AI as well as using it: as your organisation deploys models in finance, credit decisions, fraud detection and customer analytics, Model Risk Governance manages the full model lifecycle, integrated with IBM watsonx.governance, so your AI is transparent, tested, and regulatorily defensible.

AI-driven audit planning

Recommends which areas to audit based on risk signals, historical findings, and control gaps, so audit coverage goes where the risk actually is.

Grounded risk statements

Proposes contextualised risk statements drawn from your own Risk Library, for consistent, accurate language without manual drafting.

Similarity AI agent

Automatically identifies related risks, controls, and activities across the platform, preventing duplication and surfacing connections your team would not find manually.

GRC Canvas

A visual, bow-tie risk mapping environment: threats, controls, and consequences in a connected diagram rather than a table, understandable to non-technical stakeholders.

Automated child object creation

Generates related child records (sub-risks, sub-controls, findings) from parent objects, dramatically reducing manual data entry.

GRC for your AI

Model Risk Governance with watsonx.governance manages development, validation, monitoring, and retirement of your own AI models.

Deployment options

Recognised as a leader, everywhere it is measured.

Gartner

Magic Quadrant Leader · Governance, Risk and Compliance Tools for Assurance Leaders (2025)

IDC MarketScape

Leader · Worldwide AI-Enabled Financial Governance, Risk, and Compliance 2026 Vendor Assessment

Forrester

Wave Leader · AI Governance Solutions, Q3 2025

Chartis

Category Leader · GRC Digital Resilience Solutions, Operational Resilience (2025)

G2

Best Governance, Risk & Compliance Software (2025)

IDC SaaS CSAT

Award · Financial GRC (2025), for exceptional customer satisfaction

Sources: publicly available analyst reports and IBM announcements.

Case studies

Proof, from IBM’s public record.

4 → 1
General Motors

Consolidated four separate risk systems into one OpenPages platform.

−75%
Continental AG

75% fewer duplicated risks after standardising the risk taxonomy.

−50% audit fees
Navigator Gas

The world’s largest handysize liquefied gas fleet cut internal audit fees by more than half while improving compliance capability.

−70% data entry
CNP Vita Assicura

The Italian insurer reduced data entry requirements by up to 70% after deploying OpenPages.

MVP in under a year
IBM CIO Organisation

IBM runs its own internal GRC on OpenPages: 700+ employees globally, delivered by a small team.

38 locations
SCOR SE

One of the world’s largest reinsurers standardised GRC across 38 global locations.

6 weeks
IBM Privacy Office

New enterprise-wide AI compliance programmes launch in six weeks on OpenPages, the core of IBM’s AI privacy management system.

1,000s of hours
Citi

AI-assisted internal audit saves thousands of manual audit hours, redirecting specialist time to strategic risk analysis.

Professional services

Book a free OpenPages Health Check.

Already running OpenPages? We will tell you exactly what version you are on, which modules you are not using, and what it would take to get you to current. Free health check, no obligation, from the South African support team.

Questions we get asked first

Yes. We start with a free health check covering workflows, data model, user adoption and version currency, then offer upgrades to 9.x, activation of unused modules, and monthly managed support with regulatory framework updates when the rules change.

No. Most SA deployments start with operational risk or internal audit and add modules as the governance model matures.

Yes, on-premise, our local hosted environment, or cloud. Data residency is usually the deciding factor for regulated clients.

Configuration first, always. Custom development happens only where a genuine local requirement has no configurable equivalent.

The consultants who configured your instance, in role-specific sessions, with a follow-up after the first live reporting cycle.

Ready to move GRC off spreadsheets?

Talk to our team. We will assess your current risk and compliance environment, map it to the right OpenPages modules, and show you what enterprise GRC looks like in practice, with South African regulatory context built in from day one.