Governance, Risk and Compliance

Governance and compliance built around the rules that actually apply to you.

We help government entities, regulated enterprises and mid-size organisations turn Qatari laws and regulator expectations into practical controls, policies and reporting that their teams can run day to day.

Why it matters

The problems we solve

01

Several regulators, overlapping requirements

QCB, NCSA, PDPPL and sector rules overlap, and nobody owns the full picture.

02

Policies exist only on paper

Documents copied from templates do not match how the organisation actually works.

03

Risk is not visible to the board

Risk registers are out of date and reporting does not support decisions.

04

The same findings keep coming back

Audit and inspection findings are closed on paper and reappear the next year.

Services

What we deliver

Each service can be engaged on its own or combined into a single programme.

01

Regulatory Compliance

Gap assessments and remediation against QCB, NCSA National Information Assurance, PDPPL and sector regulations.

  • QCB, NCSA and PDPPL requirements
  • Gap assessment and prioritised remediation plan
  • Evidence packs for inspections
02

Governance Framework Design

Board and management structures, committees, charters and delegation of authority.

  • Board and committee structures and charters
  • Roles, responsibilities and delegation of authority
  • Governance reporting cycle
03

Enterprise Risk Management

Risk methodology, risk appetite, registers and key risk indicators.

  • Risk methodology and appetite statement
  • Risk registers and key risk indicators
  • Reporting to management and the board
04

ISO 27001 Implementation

Implementation and certification readiness for an information security management system.

  • Scope, risk assessment and statement of applicability
  • Controls implementation and evidence
  • Internal audit and certification readiness
05

Policies and Procedures

A complete, consistent policy suite written for how your organisation actually operates.

  • Information security and data protection policies
  • Operational procedures and standards
  • Annual review cycle
06

Third-Party and Vendor Risk

Due diligence, risk tiering and ongoing monitoring of suppliers and outsourcing arrangements.

  • Vendor risk tiering and due diligence
  • Outsourcing and cloud arrangements
  • Ongoing monitoring and reassessment
07

Internal Audit and Control Testing

Independent testing of the design and operating effectiveness of key controls.

  • Risk-based audit plans
  • Design and operating effectiveness testing
  • Findings tracked to closure
Outcomes

What you get

Regulator-ready documentation
Clear ownership of risks and controls
A roadmap the board can track
How it works

Our approach

01

Assess

Where you stand against each applicable requirement.

02

Design

Framework, policies and controls that fit how you operate.

03

Implement

Roll-out with your teams, including training and evidence.

04

Sustain

Monitoring, testing and reporting so it stays current.

Standards we work to

Standards we work to

QCB regulationsNCSA National Information AssurancePDPPLISO/IEC 27001ISO 22301ISO 31000NIST CSFCOSO
Questions

Frequently asked

Do you work with government entities?

Yes. Our GRC practice works with government entities as well as regulated enterprises and mid-size organisations.

Can you prepare us for ISO 27001 certification?

We take you through implementation and internal audit to certification readiness. Certification itself is issued by an accredited certification body.

Do we need a GRC platform?

Not always. We can run your programme on existing tools, or implement our GRC platform where it adds value.

Get in touch

Tell us what your regulator, auditor or board is asking for.

We will come back to you with how we would approach it, who would work on it and what it would take.