IT audit · GRC · Cybersecurity · BCM · SAMA · NCA

Four practices. One standard of assurance.

Advisory for regulated Saudi organisations — technology audit, GRC, cybersecurity and business continuity — delivered by certified practitioners from Riyadh and Dammam, in Arabic and English, and anchored in the frameworks your regulator supervises against.

Practice areas

Twenty-six service lines across four practices

Each practice publishes its full service catalogue — every line below opens the detailed scope, approach and deliverables.

Practice 01

IT Audit & Technology Risk

Technology assurance delivered to inspection standard — risk-based IT audits, control testing and technology risk programmes your audit committee and regulator can rely on.

Explore this practice
Practice 02

GRC Advisory

Governance, risk and compliance designed as one connected system — operating models, frameworks and registers your team runs after the engagement ends.

Explore this practice
Practice 03

Cybersecurity Advisory

Strategy, governance, policy and architecture advisory anchored in NCA ECC and SAMA CSF — including AI security and governance. Vendor-independent, with nothing to resell.

Explore this practice
Practice 04

BCM Advisory

Business continuity built to be exercised — business impact analysis, continuity and DR planning, crisis management and exercise programmes aligned with SAMA BCM and ISO 22301.

Explore this practice
How we engage

Scope, assess, deliver — then keep it live

01Scope

A working session to understand your regulatory obligations, risk posture and timeline — and to define exactly what the engagement must produce.

02Assess

Structured fieldwork against defined criteria: maturity assessments, control testing or gap analysis, with evidence captured as we go.

03Deliver

Findings, frameworks and artefacts built to be operated — reviewed with your team, in Arabic and English, before sign-off.

04Sustain

Frameworks land in the GRC Vantage platform where they stay live — registers maintained, actions tracked, evidence ready for the next inspection.

The Vantage difference

Advisory backed by a platform

Most consultancies leave you a report. Our engagements land in the GRC Vantage platform — risk registers stay live, control mappings stay current, and evidence is ready for the next inspection, not reassembled for it. Platform delivery, on-premise installation and training are available as dedicated services.

Talk to us

Not sure which practice you need?

Most engagements start with a single conversation about your regulatory timeline. Tell us what you are being supervised against, and we will recommend where to start.