Governance · Risk · Assurance

Confidence, made provable.

We help regulated institutions across the Gulf turn governance, risk and assurance from an obligation into a durable advantage — designing the frameworks, raising the maturity, and building the evidence that holds when a regulator looks closely.

16+

Years advising regulated institutions across the UAE, KSA and India

50+

Organisations guided to ISO and CMMI certification

95%

Reduction in audit non-conformities at engagement scale

3000+

End-to-end processes digitised as a single source of truth

What we do

Six capabilities, one standard of proof.

We work where governance, maturity and assurance meet regulation — engaging end to end, from first assessment through certification and the discipline that sustains it.

01

Governance & Operating Models

We design the architecture of decision-making — committees, delegation-of-authority matrices, control frameworks and policy lifecycles that give boards clear sightlines and regulators clean answers.

COBIT 2019 · ITIL 4 · ISO/IEC 38500
02

Process Maturity & CMMI

We take institutions through the full CMMI journey — from gap analysis to appraisal readiness at Levels 3 through 5 — embedding quantitative management that turns process performance into board-grade insight.

CMMI DEV & SVC v3.0 · QPM · OPP · SPC
03

Assurance & Certification

We run certification programmes end to end and close regulator findings under statutory pressure — designing the controls, assembling the evidence, and standing with clients through external audit.

ISO 20000-1 · 27001 · 22301 · 9001
04

AI & Emerging-Technology Governance

We help institutions adopt generative and applied AI responsibly — assessing governance readiness, designing control structures, and building the oversight regulators are beginning to demand.

AI Governance (AIGP) · AI Audit (AAIA)
05

Operational Excellence & Transformation

We re-engineer core processes to remove friction and cost — modelling the future state in BPMN 2.0, standing up PMO and EPMO structures, and instrumenting performance so gains are measured, not assumed.

BPMN 2.0 · Lean Six Sigma · PMO / EPMO
06

Capability & Academy

We transfer capability so the discipline stays after we leave — developing internal auditors, high-maturity practitioners and governance leaders through structured, hands-on programmes.

Internal Audit · High Maturity · SPC Workshops
Our approach

We do not deliver frameworks. We deliver outcomes that hold.

Generalist consultancies leave before implementation; auditors can only name what is wrong. We work the space between — designing, building, evidencing and sustaining, with the rigour of a team that has sat on the appraisal side of the table.

01 · ASSESS

Diagnose the gap

An evidence-based read of current maturity, control health and regulatory exposure — the honest baseline everything is built on.

02 · DESIGN

Architect the target

Frameworks, controls and processes designed to be audited from day one, not retrofitted before the appraisal.

03 · IMPLEMENT

Build the evidence

Hands-on delivery through documentation, training and internal assessment until the chain of evidence is complete.

04 · SUSTAIN

Institutionalise it

Sustainment governance and internal capability so maturity holds between cycles — and the certificate keeps its meaning.

Industries

Built for institutions the regulator watches closely.

Our work concentrates where oversight is intense, the stakes are board-level, and governance is not optional.

01

Banking & Islamic Finance

Enterprise governance, PMO, and process control aligned to central-bank expectations.

02

Insurance

Maturity programmes and process re-engineering for large, regulated insurers.

03

Government & Public Sector

Certification and governance for national and semi-government entities.

04

Education & Research

End-to-end ITSM and continuity certification for knowledge institutions.

05

Technology & IT Services

High-maturity CMMI and quality systems for global delivery organisations.

06

Regulators & Frameworks

Alignment to SAMA, NCA ECC, DGA, CBUAE, CITC and UAE IA.

Sanad insights

Perspectives on governance, maturity and trust.

Field-tested points of view from work inside regulated institutions — written for the leaders who carry the audit.

Point of View

Why most CMMI programmes fail after the certificate, not before it

The appraisal creates urgency; sustainment is what erodes. Three practices that keep maturity from drifting between cycles.

Read the perspective →
Briefing

AI is arriving faster than its governance. What boards should ask now.

Responsible adoption is a control problem before it is a technology one. A readiness lens for regulated institutions.

Read the briefing →
Field Note

The evidence chain: what separates a passed audit from a failed one

Controls rarely go missing. Proof does. How to build governance that answers before the question is asked.

Read the field note →
The firm

Sanad — the verified chain of transmission. A claim without a chain is an opinion.

In classical scholarship, the sanad is the documented line of authority that proves a claim can be trusted. That principle is the whole of our practice: not asserting that controls exist, but proving them, through an evidenced chain that runs from policy to practice to audit.

The firm is built on more than sixteen years inside regulated institutions across the Gulf and India, led by practitioners with formal CMMI Level 5 appraisal experience — the rare vantage of having examined the evidence, not only prepared it.

That perspective sits behind every engagement we take. We hold accreditations spanning programme and audit, AI governance, process maturity, and the full ISO family — but credentials are the starting point, not the promise. The promise is an outcome that holds when the regulator looks closely.

Start a conversation

Is there a deadline on your desk?

A certification target, a regulatory commitment, a tender requirement, or an audit finding to close. Those are the conversations we are built for — and the first one costs nothing.