شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Govern & comply

Third-party risk & GRC platformAssessed vendors, and compliance managed from one place

We build your third-party risk programme and run it on a GRC platform that brings controls, risks, evidence and vendors into one register.

At a glance

Frameworks

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • NIST CSF

Deliverables

  • Vendor tiering methodology and third-party policy
  • Control-mapped assessment questionnaires
  • Contract clauses and data processing agreement
  • GRC platform configured with frameworks and registers
  • Vendor and compliance dashboard

The challenge

The NCA Essential Cybersecurity Controls (ECC) devote a whole domain to third-party and cloud cybersecurity, and the SAMA Cyber Security Framework (CSF) requires vendors to be assessed before contracting and throughout the relationship. The Personal Data Protection Law (PDPL) makes you accountable for what processors do on your behalf.

In practice these requirements are handled in scattered spreadsheets and emailed questionnaires that get lost between departments. Nobody knows how many vendors reach your data, when each was last assessed, or where the compliance evidence is when the auditor asks.

A single GRC platform links controls to risks to evidence to vendors, so management gets one picture and the auditor gets a traceable record.

How we work

  1. 1

    Programme design

    We tier vendors by criticality and access type (data, systems, sites), and define questionnaires, contractual controls and assessment cycle per tier.

  2. 2

    Platform configuration

    We configure the GRC platform with ECC, CSCC, CCC, SAMA CSF, PDPL and ISO 27001, link controls to risks and policies, and import the vendor register and existing evidence.

  3. 3

    Operate and monitor

    We run the vendor assessment cycle, track remediation plans and publish management dashboards, with periodic programme reviews.

What is included

  • Vendor tiering

    A tiering methodology based on business impact and access to personal data and critical systems.

  • Pre-contract due diligence

    Control-mapped questionnaires, review of certificates and reports, and external security posture assessment of the vendor.

  • Contractual controls

    Ready-to-use cybersecurity and data protection clauses for contracts and PDPL data processing agreements.

  • Continuous monitoring

    Tracking of posture changes at critical vendors, periodic reassessment and monitoring of their disclosed incidents.

  • Control and evidence management

    A unified control register across frameworks, with evidence, review dates and owners, audit-ready at any time.

  • Risk and policy management

    A risk register, treatment and acceptance workflows, and policy publication with acknowledgement tracking.

  • Dashboards and reporting

    Dashboards for management and the risk committee showing compliance status, overdue vendors and open risks.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • SAMA CSF
  • PDPL
  • ISO 27001
  • NIST CSF

Frequently asked questions

Which GRC platform do you use?

We work with established market platforms and with one you may already own. The choice depends on organisation size, applicable frameworks and budget, and we help you compare.

Is the programme run by our team or yours?

Both are available: we build the programme and hand it to your team with training, or run it on your behalf as a managed service.

What about vendors who refuse to be assessed?

The programme sets a minimum per tier. A refusal is recorded as a risk escalated to management for an acceptance or alternative decision.

Is the platform hosted inside the Kingdom?

We prefer in-Kingdom or on-premises hosting to meet data residency requirements, and set out each platform's options before selection.

What affects the cost and effort of a third-party risk programme?

The number of vendors and how they split across criticality tiers, and how deeply each tier is assessed, from a questionnaire to evidence review or an on-site visit. The number of frameworks configured on the platform, the platform's licensing and hosting option, and whether we run the programme for you or hand it to your team also matter. We set this out in a written proposal after reviewing your vendor list.

Which Saudi regulations require third-party risk management?

The NCA Essential Cybersecurity Controls (ECC) require cybersecurity clauses in third-party contracts, including confidentiality, secure deletion of your data at the end of the service and incident communication procedures, and, for outsourcing and managed services, a cybersecurity risk assessment before signing. The SAMA Cyber Security Framework (CSF) expects the financial institutions it regulates to address cyber security requirements before contract signing and to monitor compliance throughout the contract. Under the Personal Data Protection Law (PDPL), a controller must choose processors that provide the necessary guarantees and verify their compliance, without losing its own responsibility.

What do you need from us to get started?

Your current vendor list with contract owners, and an indication of which vendors reach personal data, critical systems or your premises. Existing questionnaires, contract templates and policies help us reuse what already works, and we need to know which frameworks apply to you. A sponsor in procurement or risk keeps decisions moving.

  • Govern & comply

    GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

  • Govern & comply

    Compliance assessment

    Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.

  • Assess & test

    Cloud security assessment

    Review of cloud configuration, identity and data against recommended practice.

  • Solutions & infrastructure

    Data security

    Data classification, loss prevention and encryption aligned with PDPL.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.