Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
TheAudit.org publishes practitioner guidance on IT audit, risk management and governance, risk and compliance (GRC) for organisations operating under Gulf regulation. We cover the frameworks that actually determine the outcome of an audit in this region: the NCA Essential Cybersecurity Controls and Critical Systems Cybersecurity Controls, the SAMA Cyber Security and IT Governance frameworks, Saudi Arabia’s Personal Data Protection Law (PDPPL), and Qatar’s NIA framework — alongside the international standards they sit on top of, including ISO/IEC 27001:2022, COBIT 2019, NIST CSF 2.0 and the IIA Global Internal Audit Standards.
Most IT audit and cybersecurity content assumes a US or European regulatory context. If you are an auditor in Riyadh, Dammam or Doha, that content tells you how to run an engagement for someone else’s regulator. The control catalogue you are assessed against, the evidence your assessor expects, and the maturity model your programme is rated on are all different.
We write for the practitioner doing the work here: the internal auditor scoping an ITGC review against NCA classification rules, the risk manager building a register a SAMA assessor will accept, the compliance lead mapping ISO 27001 controls onto the ECC so the same evidence serves both.
Articles are published under our editorial team byline. The team are working practitioners in IT audit, risk and compliance who build governance, risk and compliance software for the Gulf market — including ControlVista (audit management), GRCVantage (Saudi framework compliance), BCMStack (operational resilience) and AuditGRC (enterprise risk for financial institutions).
That dual role is worth stating plainly, because it cuts both ways. It means the guidance here comes from people who work to these frameworks daily rather than summarising them from a distance. It also means we have a commercial interest in some of the categories we write about. Where an article discusses a product we build, we say so in the article itself. Our editorial policy sets out how we handle that.
Regulatory control catalogues are revised, and we get things wrong sometimes. If you find an error — particularly in a control reference or a framework requirement — tell us and we will correct it and note the correction. Contact us here.