The GRC platform

One platform for every
compliance requirement.

OCS replaces spreadsheets, disconnected tools, and manual processes with a unified compliance workspace. Map controls, collect evidence, manage risks, and run audits — all in one place.

Platform overview

Built for how compliance
actually works.

Compliance isn’t a one-time project. It’s a continuous process of mapping requirements, gathering evidence, assessing risks, and preparing for audits. OCS is designed around this reality.

01

Map

Connect your controls to SAMA CSF, NCA ECC, SDAIA PDPL, ISO 27001, and seven more frameworks. See exactly where you stand against every requirement.

02

Collect

Upload evidence, automate collection via API, and maintain a tamper-proof record. Every artifact is versioned and traceable.

03

Monitor

Track compliance posture in real time. Risk scoring, gap analysis, and automated alerts keep you ahead of issues.

04

Audit

Give auditors a dedicated workspace. Streamline the entire lifecycle from planning through findings to closure.

Core capabilities

Everything you need,
nothing you don’t.

01

Control Framework Manager

Map organizational controls to multiple frameworks simultaneously. Track implementation status, identify gaps, and generate compliance scorecards across all 11 supported frameworks and 1,638 controls — including SAMA CSF, SAMA ITGF, NCA ECC, SDAIA PDPL, and ISO 27001:2022.

Multi-framework mappingGap analysisCompliance scoringRequirement tracking
02

Evidence Locker

A tamper-proof repository for all compliance artifacts. Gather evidence automatically from 33 connected systems — AWS, Azure, Google Cloud, Azure AD, CrowdStrike, Splunk, Qualys, Jira and more — or upload manually. Every document is versioned, tagged to specific controls, and tracked with expiry alerts.

Automated gathering33 integrationsVersion historyExpiry alerts
03

Risk Register

Identify, score, and track risks with treatment plans. Quantify exposure with heat maps, link risks to controls, and monitor remediation progress across your organization.

Risk scoringHeat mapsTreatment plansControl linkage
04

Audit Workspace

A dedicated environment for internal and external auditors. Review controls, request evidence, issue findings, and track remediation — all within a structured workflow.

Auditor portalFinding managementEvidence requestsLifecycle tracking
05

Reporting & Dashboards

Executive dashboards, framework-specific reports, and audit-ready exports. Get a real-time view of your compliance posture with data you can share with boards and regulators.

Executive dashboardsFramework reportsAudit exportsReal-time posture
06

Multi-organization Management

Purpose-built for audit firms and enterprise groups. Manage multiple entities, compare compliance posture across organizations, and run parallel assessments from a single workspace.

Multi-tenantCross-org comparisonParallel assessmentsCentralized oversight
07

Policy Library

Start with 25 regulator-aligned policies, not a blank page. Corporate governance, AML/CTF, capital adequacy, consumer protection, Sharia compliance, Saudization and more — 129 clauses, each citing the specific regulatory obligation it satisfies. Written Arabic-first, then adopted, versioned and attested by your own team.

25 ready policiesObligation-cited clausesAdoption workflowStaff attestations
08

Third-Party Risk

Onboard, assess and monitor vendors against the same control set you run internally. Link each vendor to the controls they touch, so third-party exposure shows up in your compliance posture — not in a separate spreadsheet.

Vendor registerControl linkageLifecycle trackingRisk scoring
09

Data Residency

Continuous verification that every data-bearing subsystem stays inside the Kingdom. Any integration routing data abroad raises a finding automatically — PDPL data localization you can evidence, not just assert.

KSA residency checksPer-integration statusAutomatic findingsPDPL alignment
Framework support

Native support for every
major Saudi framework.

SAMA ITGF

410 controls

Saudi Arabian Monetary Authority IT Governance Framework. IT governance controls covering strategy, risk, and performance management.

SAMA CFF

210 controls

Saudi Arabian Monetary Authority Counter-Fraud Framework. Fraud prevention, detection, and response controls for financial institutions.

NCA ECC

200 controls

National Cybersecurity Authority Essential Cybersecurity Controls. Structured requirements with implementation guidance.

NCA CCC

175 controls

National Cybersecurity Authority Cloud Cybersecurity Controls. Security requirements for cloud service providers and tenants.

SAMA CSF

148 controls

Saudi Arabian Monetary Authority Cyber Security Framework. Full control mapping with domain-level gap analysis.

CMA CSG

148 controls

Capital Market Authority Cybersecurity Guidelines for Capital Market Institutions. Security requirements for licensed capital market firms.

SDAIA PDPL

103 controls

SDAIA Personal Data Protection Law. Data processing requirements, consent management, and cross-border transfer controls.

ISO 27001:2022

93 controls

International information security standard. Annex A controls with Statement of Applicability support.

SAMA BCF

76 controls

Saudi Arabian Monetary Authority Business Continuity Management Framework. Continuity planning and operational resilience controls for financial institutions.

NCA DCC

66 controls

National Cybersecurity Authority Data Cybersecurity Controls. Controls for protecting sensitive data across its lifecycle.

CMA Real Estate Ownership

9 controls

Capital Market Authority controls on the ownership of real estate by listed companies, investment funds, and special-purpose entities.

Ready to see OCS
in action?

Schedule a walkthrough with our team. We’ll show you how OCS maps to your specific regulatory requirements.

Get in touch