Practical guides. No email required
Long-form walkthroughs of the work — written by people who run compliance programmes in the Kingdom, for people who have to do the same. Read them, print them, send them to a colleague. We do not ask for anything first.
Implementing the ECC from a standing start
Scoping, the control library, ownership, and the order that avoids rework. For organisations that have been told they are in scope and have not started.
Read the guide → AssessmentPreparing for your first NCA assessment
What gets asked for, what evidence has to look like, and the findings that recur because the programme was built for a deadline rather than for operation.
Read the guide → Saudi PDPLBuilding a PDPL programme in 90 days
Records of processing, lawful basis, rights workflow, breach process and transfers — in the order that gets you defensible fastest rather than complete first.
Read the guide → ControlsOne control library, several frameworks
How to build a control set that carries the ECC, the SAMA CSF, ISO 27001 and the PDPL at once — and the mapping mistakes that make it fall apart in year two.
Read the guide → EvidenceEvidence that survives an audit
What makes an artefact acceptable, how validity periods work, and why most evidence problems are ownership problems wearing a different label.
Read the guide → BuyingChoosing a GRC platform
The questions worth asking every vendor, including us — hosting, evidence handling, integrations, AI, and how to tell a demo from a product.
Read the guide →Guides are updated when the underlying requirements change, and each one carries the date it was last reviewed. Where a guide describes a regulatory obligation, the published document from the relevant authority is the authoritative source — these are practical explanations, not legal advice.
Guide, framework page, or glossary?
Three kinds of thing on this site, answering three different questions. Worth thirty seconds if you are not sure where to start.
How to do something, end to end. Sequenced, opinionated about order, and written for someone who has to produce a result rather than understand a topic. Longest of the three and the one to read once properly.
What a specific framework requires, who assesses it, and how it is run in practice. The reference you come back to when you need the structure, the scoring, or the answer to a particular question.
What a term means, briefly. For the moment in a meeting when someone uses an acronym and nobody wants to ask.
Shorter, and tied to something current — a change in requirements, a pattern we keep seeing, a question that came up several times in a month.
What we will not publish here
Stated because the category is full of the opposite, and because it is a useful commitment to be held to.
- Sequences that say what to do first and why
- The mistakes that cost the most, named plainly
- What a requirement asks for in operational terms
- Where our own advice stops and yours has to start
- The date each guide was last reviewed
- Anything called an "ultimate" or "complete" guide
- A product brochure with a guide label on it
- Regulatory interpretation presented as legal advice
- A form between you and the content
- Fear-led framing built on penalty figures
If a guide here reads like marketing, tell us — [email protected] reaches the people who wrote it, and that is a fair criticism to make.
What should we write next?
If there is a piece of this work nobody has explained properly, tell us. The guides that get written are usually the ones somebody asked for.