GRC insights
Notes from the compliance trenches
Regulatory updates, framework walkthroughs, and practical notes for governance, risk, and compliance practitioners.

Everybody Is at Level 3
Run a maturity self-assessment across a large organisation and the results cluster in the middle with suspicious consistency. It is not that everyone is genuinely at the same level. It is that the middle is the safest place to stand. Here is what the levels are supposed to mean and why the jump to level 4 is the one that actually costs something.

Red, Amber, Green Is Not a Number
Someone on the board asks what the exposure is worth, and the heat map cannot answer. It was never built to. Here is what goes wrong when ordinal scales get treated as arithmetic, what quantifying a risk actually involves, and which risks are not worth quantifying at all.

The Supplier You Never Signed a Contract With
Three of your critical vendors go down on the same morning. None of them are competitors, none share an owner, and nothing in your register connects them. They were all running on the same platform underneath. Here is why fourth-party concentration is invisible to most vendor programmes, and what it takes to see it.

One GRC Programme, Many Jurisdictions: Structuring for Multi-Entity Groups
When entities in a group answer to different regulators, most organisations either force one standard on everyone or let each entity run its own programme. Both fail. Here is the structure that works.

Map Once, Satisfy Many: How Control Mapping Actually Works
Most organisations answer to several frameworks at once and end up maintaining a separate control set for each. Here is how a single control library with proper mapping removes that duplication, and where the approach genuinely breaks down.

ISO 27001 and NIST CSF Together: Where They Overlap and Where They Don't
Plenty of organisations run both. They are not competing standards and they are not interchangeable: one is a certifiable management system, the other is a risk-outcome language. Here is how they fit together in one programme.

PDPL Compliance Checklist: A Practical Self-Assessment
Saudi Arabia's Personal Data Protection Law is now enforced. Use this practical checklist to assess your organization's compliance posture across data inventory, consent, rights management, breach response, and third-party obligations.

How SAMA CSF Shapes Cybersecurity in Saudi Banking
The Saudi Arabian Monetary Authority Cyber Security Framework defines mandatory cybersecurity standards for every bank, insurer, and financial institution in the Kingdom. Here's what it requires and how to comply.

Understanding NCA ECC: A Complete Guide for Saudi Enterprises
The National Cybersecurity Authority's Essential Cybersecurity Controls are mandatory for Saudi organizations. This guide explains the framework structure, assessment approach, and what your organization needs to do to comply.

PDPL Compliance in Saudi Arabia: A Practical Guide for Organizations
Saudi Arabia's Personal Data Protection Law is now enforced. Here's what your organization needs to do to comply with SDAIA's requirements and avoid penalties.

SAMA CSF and Third-Party Risk: What Saudi Banks Need to Manage Vendor Cybersecurity
The SAMA Cyber Security Framework places significant obligations on Saudi financial institutions to assess and manage cybersecurity risk in their vendor and supplier relationships.