Board Evaluation in Saudi Arabia
How Saudi boards run an annual performance evaluation — who conducts it, what it covers, and what the CMA expects. Common questions, answered.
Anti-Money Laundering (AML) Compliance
Customer due diligence, suspicious transaction reporting, and what SAMA and the AML Law expect of regulated entities. Common questions, answered.
Cybersecurity Governance and NCA Compliance
What the Essential Cybersecurity Controls require, who owns cyber risk at board level, and how to build governance that holds up. Common questions, answered.
Conflict of Interest Policy
How to build a conflict-of-interest policy that goes beyond related-party transactions — disclosure, recusal, and what governance requires. Common questions, answered.
Building an Internal Audit Function
When a company needs its first internal audit function, how it should report, and what it actually does day to day. Common questions, answered.
Building an Enterprise Risk Management Framework
Risk appetite, a working risk register, ownership, and what the board should see — an ERM framework built to be used, not filed.
PDPL Compliance in Saudi Arabia
A governance approach: data mapping, lawful basis, vendor data terms, breach response, and what the audit committee should oversee.
Anti-Bribery and Corruption Compliance
A practical framework: risk mapping, gifts and hospitality limits, third-party due diligence, and what a program needs to hold up under real scrutiny.
Whistleblowing and Speak-Up Channels
Most fraud is uncovered by a tip, not an audit. How to build a channel employees actually trust — confidentiality, non-retaliation, and independent routing.
Related-Party Transactions: Governing the Deals Closest to Home
The deals where conflicts of interest and value leakage concentrate. How to identify, price, disclose, and independently approve them — for listed and family companies alike.
The Audit Committee: The Board's Line of Sight
Where financial reporting, the external audit, and internal control are held to account. Its role, composition, and independence — and what the CMA expects of a listed company's committee.
The Delegation of Authority: From Founder's Instinct to Institution
Who can commit the company to what, and above which limits a decision must rise. The document that turns "the owner decides" into a structure the board and auditors can rely on.
Segregation of Duties When the Team Is Small
The control auditors test first is the hardest for small finance teams. How to separate the four functions — and the compensating controls that work when you can't.
Board Readiness for a Tadawul Listing: A Governance Checklist
An IPO is a governance test before it is a financial one. What the CMA expects of your board, committees, and controls — and when to start.
Internal Controls Before an External Audit: Closing the Gaps
Audits go smoothly when the controls already work. A practical readiness map — segregation of duties, evidence, and owner sign-off.
Governance for Saudi Family Businesses: From Owner-Led to Board-Governed
The transition that protects the enterprise across generations — a family charter, a real board, and a clean line between ownership and management.
Building an Internal Control Framework with COSO
The five components auditors and regulators recognize — and how to stand them up in a way that maps to Saudi requirements.
Risk Appetite Statements: A Practical Framework for Boards
Board ownership, specific thresholds, and how a risk appetite statement connects to the risk register — written to be used, not filed.
The Nomination & Remuneration Committee: Role and Best Practices
Board composition, succession planning, and executive pay — what the committee actually decides, and how to run it well.
ESG Governance and Disclosure for Saudi-Listed Companies
Board oversight, data quality, and what Tadawul-listed companies are expected to disclose — ESG governance beyond the annual report.
Fraud Risk Management: Building a Prevention and Detection Framework
Risk assessment, control design, and the detection mechanisms that catch what prevention misses.
Third-Party and Vendor Risk Management: A Governance Framework
Due diligence, contract controls, and ongoing monitoring — before an outside relationship becomes your exposure.
