Four practices.
One standard of assurance.
Advisory for regulated Saudi organisations — technology audit, GRC, cybersecurity and business continuity — delivered by certified practitioners from Riyadh and Dammam, in Arabic and English, and anchored in the frameworks your regulator supervises against.
Twenty-six service lines across four practices
Each practice publishes its full service catalogue — every line below opens the detailed scope, approach and deliverables.
IT Audit & Technology Risk
Technology assurance delivered to inspection standard — risk-based IT audits, control testing and technology risk programmes your audit committee and regulator can rely on.
Explore this practiceGRC Advisory
Governance, risk and compliance designed as one connected system — operating models, frameworks and registers your team runs after the engagement ends.
Explore this practiceCybersecurity Advisory
Strategy, governance, policy and architecture advisory anchored in NCA ECC and SAMA CSF — including AI security and governance. Vendor-independent, with nothing to resell.
Explore this practiceBCM Advisory
Business continuity built to be exercised — business impact analysis, continuity and DR planning, crisis management and exercise programmes aligned with SAMA BCM and ISO 22301.
Explore this practiceStart from the regulator you answer to
Dedicated service pages for the Kingdom's main supervisory regimes — what each requires, and how platform and advisory combine to meet it.
NCA Compliance Services
ECC, CSCC, CCC, OTCC, DCC and TCC — applicability, requirements mapping and self-assessment support.
Explore SAMASAMA Compliance Services
CSF, IT Governance, BCM, third-party risk and counter-fraud — one posture for SAMA-supervised institutions.
Explore PDPLPDPL Compliance Services
Records of processing, DPIAs, data subject rights, the 72-hour breach rule and transfer analysis.
ExploreScope, assess, deliver — then keep it live
A working session to understand your regulatory obligations, risk posture and timeline — and to define exactly what the engagement must produce.
Structured fieldwork against defined criteria: maturity assessments, control testing or gap analysis, with evidence captured as we go.
Findings, frameworks and artefacts built to be operated — reviewed with your team, in Arabic and English, before sign-off.
Frameworks land in the GRC Vantage platform where they stay live — registers maintained, actions tracked, evidence ready for the next inspection.
Advisory backed by a platform
Most consultancies leave you a report. Our engagements land in the GRC Vantage platform — risk registers stay live, control mappings stay current, and evidence is ready for the next inspection, not reassembled for it. Platform delivery, on-premise installation and training are available as dedicated services.
Not sure which practice you need?
Most engagements start with a single conversation about your regulatory timeline. Tell us what you are being supervised against, and we will recommend where to start.