Skip to content
Sentinel Unity

GRC insights

Notes from the compliance trenches

Regulatory updates, framework walkthroughs, and practical notes for governance, risk, and compliance practitioners.

Two colleagues in discussion at a table, one gesturing while explaining, a laptop showing a diagram beside them
Practitioner Guide

Everybody Is at Level 3

Run a maturity self-assessment across a large organisation and the results cluster in the middle with suspicious consistency. It is not that everyone is genuinely at the same level. It is that the middle is the safest place to stand. Here is what the levels are supposed to mean and why the jump to level 4 is the one that actually costs something.

Maturity ModelCompliance OperationsAssessment
18 Aug 20268 min read
Read article
A screen showing a dashboard of metric tiles with line charts and percentage figures
Practitioner Guide

Red, Amber, Green Is Not a Number

Someone on the board asks what the exposure is worth, and the heat map cannot answer. It was never built to. Here is what goes wrong when ordinal scales get treated as arithmetic, what quantifying a risk actually involves, and which risks are not worth quantifying at all.

Risk QuantificationEnterprise RiskRisk Appetite
21 Jul 20269 min read
Read article
An aerial view of a container terminal, stacked freight containers and gantry cranes beside the water
Practitioner Guide

The Supplier You Never Signed a Contract With

Three of your critical vendors go down on the same morning. None of them are competitors, none share an owner, and nothing in your register connects them. They were all running on the same platform underneath. Here is why fourth-party concentration is invisible to most vendor programmes, and what it takes to see it.

Third-Party RiskFourth PartiesSupply Chain
16 Jun 20269 min read
Read article
The Earth photographed at night from orbit, city lights scattered across the dark
Practitioner Guide

One GRC Programme, Many Jurisdictions: Structuring for Multi-Entity Groups

When entities in a group answer to different regulators, most organisations either force one standard on everyone or let each entity run its own programme. Both fail. Here is the structure that works.

Multi-EntityEnterprise RiskGovernance
6 May 20258 min read
Read article
Curved shelves of a large library, rising several storeys
Practitioner Guide

Map Once, Satisfy Many: How Control Mapping Actually Works

Most organisations answer to several frameworks at once and end up maintaining a separate control set for each. Here is how a single control library with proper mapping removes that duplication, and where the approach genuinely breaks down.

Control MappingCompliance OperationsISO 27001
8 Apr 20259 min read
Read article
Two people working through hand-drawn diagrams on paper beside open laptops
Framework Guide

ISO 27001 and NIST CSF Together: Where They Overlap and Where They Don't

Plenty of organisations run both. They are not competing standards and they are not interchangeable: one is a certifiable management system, the other is a risk-outcome language. Here is how they fit together in one programme.

ISO 27001NIST CSFControl Mapping
18 Mar 20258 min read
Read article
A modern office corridor with glass-partitioned meeting rooms
Compliance Guide

PDPL Compliance Checklist: A Practical Self-Assessment

Saudi Arabia's Personal Data Protection Law is now enforced. Use this practical checklist to assess your organization's compliance posture across data inventory, consent, rights management, breach response, and third-party obligations.

PDPLData PrivacySDAIA
20 Feb 20257 min read
Read article
An empty boardroom with a long table and city view
Regulatory Update

How SAMA CSF Shapes Cybersecurity in Saudi Banking

The Saudi Arabian Monetary Authority Cyber Security Framework defines mandatory cybersecurity standards for every bank, insurer, and financial institution in the Kingdom. Here's what it requires and how to comply.

SAMA CSFBankingFinancial Services
5 Feb 20257 min read
Read article
High-voltage transmission towers silhouetted against a sunset
Compliance Guide

Understanding NCA ECC: A Complete Guide for Saudi Enterprises

The National Cybersecurity Authority's Essential Cybersecurity Controls are mandatory for Saudi organizations. This guide explains the framework structure, assessment approach, and what your organization needs to do to comply.

NCA ECCSaudi ArabiaCybersecurity
20 Jan 20258 min read
Read article
Server racks in a dark data hall, patch cables lit by status LEDs
Compliance Guide

PDPL Compliance in Saudi Arabia: A Practical Guide for Organizations

Saudi Arabia's Personal Data Protection Law is now enforced. Here's what your organization needs to do to comply with SDAIA's requirements and avoid penalties.

PDPLData PrivacySDAIA
10 Jan 20257 min read
Read article
A person signing a printed document with a fountain pen
Regulatory Update

SAMA CSF and Third-Party Risk: What Saudi Banks Need to Manage Vendor Cybersecurity

The SAMA Cyber Security Framework places significant obligations on Saudi financial institutions to assess and manage cybersecurity risk in their vendor and supplier relationships.

SAMA CSFTPRMFinancial Services
20 Nov 20246 min read
Read article