IT audit · ITGC · Technology risk · COBIT · SAMA · NCA

Technology assurance, delivered to inspection standard.

From ITGC testing to cloud and third-party technology risk, we plan, execute and report technology audits using evidence-first, risk-based methodologies aligned with applicable Saudi regulatory requirements.

In detail

What each service line covers

01 · Service line

IT Audit

We plan and execute full-scope IT audits using a risk-based methodology aligned to IIA Global Standards and the expectations of SAMA and NCA supervision. Every audit is scoped from your risk universe, executed against defined control criteria, and reported with findings and management actions your audit committee can track to closure.

What we deliver
  • Risk-based IT audit universe and multi-year audit plan
  • Fieldwork executed against defined control criteria with full workpapers
  • Findings rated by risk, with root-cause analysis and agreed management actions
  • Audit committee reporting and follow-up tracking
Enquire about this service
02 · Service line

ITGC Assessment

IT general controls underpin the reliability of every financially and operationally significant system. We assess ITGC design and operating effectiveness across access management, change management, IT operations and backup and recovery — whether for external audit reliance, regulatory readiness or internal assurance.

What we deliver
  • ITGC scoping tied to significant systems and data flows
  • Design and operating-effectiveness testing with documented sampling rationale
  • Deficiency evaluation and aggregation analysis
  • Remediation roadmap with control owners and target dates
Enquire about this service
03 · Service line

Application Controls

Automated application controls fail silently. We test the configurable and inherent controls inside core banking, ERP and line-of-business systems — input validation, processing logic, calculations, interface reconciliations and segregation of duties — so you know the controls you rely on actually operate.

What we deliver
  • Application control identification benchmarked against business process risks
  • Testing of configurable controls, calculations and interface reconciliations
  • Segregation-of-duties and sensitive-access analysis
  • Control gaps mapped to business process impact
Enquire about this service
04 · Service line

Technology Risk

We build and run technology risk assessment programmes: identifying, analysing and evaluating risk across infrastructure, applications, data, resilience and emerging technology — and translating the results into a maintained risk register with KRIs and board-level reporting rather than a one-off report.

What we deliver
  • Technology risk taxonomy and assessment methodology
  • Risk assessments across infrastructure, applications, data and resilience
  • KRI design with thresholds and escalation paths
  • Board and committee technology risk reporting packs
Enquire about this service
05 · Service line

IT Governance

We design and implement IT governance structures aligned to COBIT 2019 and SAMA's IT Governance Framework — decision rights, committee structures, policy architecture and performance measurement — so technology decisions are made, and evidenced, at the right level of the organisation.

What we deliver
  • IT governance maturity assessment against COBIT 2019 and SAMA ITGF
  • Committee charters, decision rights and escalation model
  • IT policy and standards architecture
  • Governance metrics and board reporting cadence
Enquire about this service
06 · Service line

Cloud Risk

Cloud adoption in the Kingdom is governed by specific rules — the NCA Cloud Cybersecurity Controls, SAMA's outsourcing and cloud requirements, and PDPL data-residency obligations. We assess cloud risk across your estate, from provider due diligence to workload-level control reviews, and build the governance to keep adoption compliant as it scales.

What we deliver
  • Cloud risk and readiness assessments aligned with NCA CCC and applicable SAMA requirements
  • Cloud service provider due-diligence and exit-strategy frameworks
  • Data residency and PDPL impact analysis
  • Cloud governance model with guardrails and approval workflows
Enquire about this service
07 · Service line

Third-Party Technology Risk

Regulators hold you accountable for your vendors' technology failures. We build third-party technology risk programmes covering tiering, due diligence, contractual controls, ongoing monitoring and exit planning — aligned to SAMA's outsourcing requirements and NCA third-party controls.

What we deliver
  • Vendor tiering methodology by criticality and data sensitivity
  • Technology due-diligence assessments and control questionnaires
  • Contractual control requirements and right-to-audit clauses
  • Ongoing monitoring cadence with concentration-risk analysis
Enquire about this service
08 · Service line

Internal Audit Advisory

Most internal audit functions are short on deep technology skills. We provide co-sourced and outsourced technology audit capacity, build IT audit methodologies and workpaper standards, and prepare functions for external quality assessments — so your audit plan stops deferring technology audits for lack of expertise.

What we deliver
  • Co-sourced or outsourced execution of technology audits
  • IT audit methodology, workpaper templates and rating models
  • Technology audit universe and plan development
  • External quality assessment readiness against IIA Standards
Enquire about this service
Why Vantage

Assurance built for the Saudi supervisory cycle

Regulator-fluent

Practitioners who have delivered through SAMA and NCA inspection cycles. Reports written in the language supervisors expect to read.

Platform-backed fieldwork

Engagements run on the GRC Vantage platform — evidence, findings and follow-up actions tracked in one system, not scattered across email.

Certified practitioners

CISA, CRISC, CISSP and CIA-certified teams with financial services, government and critical infrastructure experience.

Bilingual delivery

Arabic and English fieldwork and reporting, delivered from Riyadh and Dammam — on-site where your systems are.

FAQ

Frequently asked questions

What is an ITGC assessment, and who needs one?

An ITGC assessment tests the IT general controls — access management, change management, IT operations and backup/recovery — that underpin the reliability of your significant systems. Organisations need one when external auditors want to place reliance on systems, when a regulator such as SAMA expects evidence of control effectiveness, or when management wants independent assurance before an inspection.

Do Saudi regulators require IT audits?

Yes. SAMA-regulated institutions are expected to subject technology and cybersecurity controls to periodic independent audit under the SAMA Cyber Security Framework and IT Governance Framework, and NCA ECC requires periodic cybersecurity review and audit of control implementation. Internal audit functions are also expected to cover technology as part of third-line assurance.

Can you co-source technology audits with our internal audit team?

Yes. We provide co-sourced and fully outsourced technology audit capacity — executing audits from your approved plan under your methodology, or bringing ours. We also build IT audit methodologies, workpaper standards and audit universes so your function can run technology audits independently over time.

Which frameworks do you audit against?

SAMA CSF and the SAMA IT Governance Framework, NCA ECC and the NCA Cloud Cybersecurity Controls, ISO 27001, and COBIT 2019 — alongside your own policies and control library. Findings are mapped to the specific control references your regulator supervises against.

Frameworks we work in

Our technology audit and risk work is mapped to the control frameworks your regulator supervises against — so findings land against the requirements that matter.

Talk to us

Scope your next technology audit with us

Whether you need a full IT audit plan, a one-off ITGC assessment or co-sourced capacity for your internal audit function, our team will scope the engagement and propose an approach — at no cost.