Skip to content

GRC for Saudi regulated firms

GRC,simplified.

One GRC platform for banks, finance companies, insurers and capital market firms regulated by SAMA, the CMA and the Insurance Authority.

Screens show a sample organisation. Some are in preview.A two-minute film with music and on-screen titles, no narration. Separate tools for risk, compliance, internal audit, cyber security, data protection, finance and HR come together into one platform: Sastrum. It then shows onboarding an organisation, built-in GRC packs, a policy drafted in one click, dashboards for each leadership role, one enterprise view with each function's data kept separate, and Lumina suggesting actions with their sources, reviewed and accepted by a person.

Who it is for

Same regulations. Smaller teams. Smaller budgets.

  • Banks
  • Finance companies
  • Insurance companies and brokers
  • Capital market institutions
  1. SAMA's Cyber Security Framework and NCA's Essential Cybersecurity Controls set detailed controls that regulated firms must evidence.
  2. The Personal Data Protection Law, fully enforceable since September 2024, requires breach notice to SDAIA within 72 hours.
  3. Firms answer to several authorities at once: SAMA, the CMA or the Insurance Authority for their sector, NCA for cybersecurity and SDAIA for personal data.

Same SAMA circulars. Same NCA controls. Same penalties.

A fraction of the team and budget.

Our aim Affordable, easy-to-use, enterprise-grade GRC for every small and mid-size firm.

Industry content packs

Packs for the industries we serve in Saudi Arabia.

A pack is the regulations, controls, risks, policies and audit tests for one industry, mapped before you start. Banking and finance ships today; the rest follow.

  • Available

    Banking and finance

    Banks, finance companies, insurers, capital market institutions

    Maps to SAMA CSF, NCA ECC, PDPL, CMA

  • Coming

    IT and ITES

    Software, cloud and managed service providers

    Maps to NCA ECC, NCA CCC, PDPL, ISO 27001

  • Coming

    Telecom

    CST licensees and network providers

    Maps to CST Cybersecurity Regulatory Framework, NCA ECC, PDPL

  • Coming

    Manufacturing

    Industrial and process plants

    Maps to NCA ECC, NCA OTCC, ISO 27001

  • Coming

    Energy and utilities

    Power, water and oil and gas operators

    Maps to NCA ECC, NCA OTCC, NCA CCC, PDPL

Why this matters now

GRC failures now cost real money, not just audit points.

Saudi figures, each linked to its source.

What makes it different

Same breadth as the global suites. Built for smaller firms.

One control library that every framework maps to, with six things the global suites do not give a smaller firm.

  1. Your regulator, already inside.

    SAMA CSF, NCA ECC and PDPL are in the product, alongside ISO 27001, NIST CSF and PCI DSS.

    See the frameworks
  2. Live in minutes.

    Describe your organisation. Sastrum scopes your risk universe, suggests your controls and drafts your first policies, the same day.

    See risk scoping
  3. AI a regulator can audit.

    Lumina suggests and drafts, and shows the clauses it relied on. A named person approves every decision, and every AI action is logged.

    Lumina drafts. People sign.

    How Lumina works
  4. One record, separate lanes.

    Risk, compliance and audit share the same controls and evidence. Each keeps its own data and approvals. The board sees one view across three lines of defence.

    Explore the platform
  5. One licence.

    Governance, compliance, audit and incidents under one licence. In our cloud, your private cloud or on your premises, with the same features.

    Security and deployment
  6. Platform plus people.

    With the product come our services: virtual CISO, managed GRC and security testing.

    Talk to us

Our experience, built into the product

20years of GRC advisory and regulatory audits

We did not start from a blank page. Every lesson from those years has gone into the product, so you buy the learning with the software.

  • GRC advisory
  • Regulatory audits
  • Learning, built in

Built with a national bank against 300 tendered requirements.

What we are working on now

This is just the start.

  • Board

    Board-level risk simulation

    Coming soon

  • Chief Risk Officer

    Risk quantification and predictive risk

    Coming soon

  • Chief Compliance Officer

    Continuous compliance and regulation-change impact simulation

    Coming soon · Q4 2026

  • CISO

    Continuous control monitoring and quantum computing impact simulation

    Coming soon

  • Chief Internal Auditor

    Automatic work papers

    Coming soon

  • Data Protection Officer

    Continuous data protection

    Coming soon

Build the next chapter with us.

See Sastrum run on your own regulators, help shape it for your sector, or join as a founding customer.

  • See it running

    Thirty minutes, opened on a risk universe already scoped to your sector and regulators.

  • Partners

    Design partners shape the content for their sector or country. Consultants, integrators and regulatory experts take Sastrum to each launch market.

Born in India. Built for the world.