What does a GRC consulting engagement typically include?
It depends on where you start. A typical first engagement covers a maturity assessment of your governance, risk and compliance arrangements, a gap analysis against the frameworks you are supervised under — SAMA, NCA or PDPL — and a sequenced roadmap. Later phases build the operating model: charters, risk registers, obligations mapping, control libraries and the tooling to run them.
Can you build an enterprise risk management framework from scratch?
Yes. We build ERM end to end — board-approved risk appetite, taxonomy, assessment methodology, registers, KRIs and reporting — grounded in ISO 31000 and COSO ERM. The framework is implemented in the GRC Vantage platform, so registers and reporting are live from day one rather than sitting in a document.
How do you handle overlapping frameworks like SAMA CSF, NCA ECC and ISO 27001?
Through a unified control framework. We rationalise your overlapping control sets into a single library, map each control across every applicable framework, and give it one owner and one body of evidence — so a control is tested once and the result satisfies every framework that references it.
Do you deliver artefacts in Arabic?
Yes. Charters, policies, risk registers, methodologies and board reporting are delivered in Arabic and English as standard, from our teams in Riyadh and Dammam.