Designing Falconry360 Use Cases for NCA/SAMA Cyber and GCC PDPL in One Blueprint

KSA’s NCA / SAMA cybersecurity regimes and GCC-wide PDPL data protection laws are now two of the strongest forces shaping governance in the region. For most banks and large institutions, the majority of new governance, risk, and compliance work traces back to one of these two streams: hard cyber controls and evolving data protection requirements. Trying to implement them separately—one project for NCA, one for SAMA, another for PDPL in each country—creates duplication, inconsistency, and unnecessary cost. Falconry360 allows you to design a single implementation blueprint where NCA/SAMA cyber controls and GCC PDPL are modelled once and then reused across entities, regulators, and use cases. Step 1: Start from Shared Libraries, Not Separate Projects The foundation of the blueprint is three shared libraries in Falconry360: Control Library – one canonical cyber and privacy control set that you can map to: NCA ECC, OTCC, CCC, DCC, CSCC, NCNICC‑1 SAMA Cyber Security Framework domains and principles GCC PDPL obligations (KSA PDPL, UAE FDPL/PDPL, Oman, Qatar). Obligations Library – NCA/SAMA clauses and GCC PDPL articles represented as structured obligations with tags for regulator, country, theme, and risk type. Data / Asset / Service Library – shared records of critical systems, business services, data categories, and third parties that are reused by cyber, privacy, and vendor risk. By investing in these libraries first, you avoid building separate “mini frameworks” for each regulation. Step 2: Design Two Primary Use-Case Streams Once libraries exist, you can structure Falconry360 configuration around two major streams, each spanning several layers (ANTICIPATE, COMPLY, WITHSTAND, ASSURE). NCA/SAMA Cyber Governance Stream Core use cases: Cyber Risk Register (ANTICIPATE) Cyber risks aligned to NCA domains (e.g., governance, defence, resilience, third‑party) and SAMA CSF pillars. Linked to assets, services, vendors, and controls from the central library. NCA/SAMA Obligation Mapping (COMPLY) ECC/OTCC/CCC/DCC/CSCC/NCNICC‑1 and SAMA CSF clauses mapped to controls, policies, and evidence. Coverage and gap views per entity (e.g., SAMA‑regulated bank vs non‑CNI private sector). Cyber Incidents and Issues (WITHSTAND/ASSURE) Common incident model that captures NCA/SAMA impact, affected controls, and required reporting. Issues and remediation plans tracked against the same controls and obligations. FalconryX can then: read NCA/SAMA updates, suggest new obligations, propose mappings, and draft impact assessments. GCC PDPL Compliance Stream Core use cases: PDPL Obligations and Data Inventory (COMPLY / ANTICIPATE) Common PDPL themes (lawful basis, consent, rights, retention, security, transfers) mapped once and tagged by country. Data processing inventory linking systems, purposes, and data categories to PDPL obligations. Privacy Controls and Workflows Controls from the central library (access control, encryption, logging, DPIAs, rights handling) linked to PDPL obligations and processing activities. Standard workflows for DPIAs, new products, vendor onboarding, and change management that automatically pull in PDPL requirements. Incidents and Rights Requests Incidents with PDPL impact flags per country and required notification timelines. Rights requests tracked end‑to‑end, linked to systems and obligations. FalconryX can: extract PDPL obligations from new guidance, help draft DPIAs, and generate regulator‑ready breach summaries. Step 3: Reuse the Same Objects Across Both Streams The key to this blueprint is deliberate reuse. A cloud platform might be: A critical system under NCA CSCC/CCC and SAMA CSF. A PDPL‑relevant system processing customer data in KSA and UAE. A vendor might simultaneously be: In scope for NCA OTCC/DCC third‑party cyber controls. A PDPL “processor” handling personal data across multiple GCC markets. By modelling these as single assets and vendors, with multiple tags, you avoid double‑counting and conflicting views. Step 4: Anchor Both Streams in the Five Falconry360 Layers Map the blueprint explicitly to Falconry360’s layers: GOVERN – Policies and charters for NCA/SAMA cyber, PDPL, AI, and vendor governance. ANTICIPATE – Cyber, operational, and privacy risks connected to NCA/SAMA and PDPL obligations. COMPLY – All NCA, SAMA, and PDPL clauses as obligations with mappings to controls and evidence. WITHSTAND – Resilience scenarios where cyber incidents or data breaches impact important business services. ASSURE – Audit and ICFR scopes that include NCA/SAMA and PDPL controls, with shared issues and remediation. This ensures NCA/SAMA and PDPL are not separate “programmes” but part of one governance operating system. Step 5: Deliver a Clear Story to Regulators and Boards With this blueprint, you can explain to stakeholders: To regulators: how NCA, SAMA, and PDPL obligations are captured, mapped, executed, and assured in one model. To boards: how cyber and privacy risks sit on the same map of critical services, systems, and vendors, and how actions are prioritised. Falconry360 provides the structure; FalconryX provides the intelligence layer that keeps it current and reduces manual effort.
Combined Assurance in Practice: Connecting Risk, Compliance, and Audit Functions

Many organizations recognise the idea of “combined assurance”: risk, compliance, and internal audit should coordinate their efforts so the board receives a coherent view of assurance over key risks. In practice, this often fails because each function runs its own tools, taxonomies, and plans. A governance operating system makes combined assurance a practical reality. Rather than trying to coordinate three separate worlds, it allows them to share the same risk and control landscape while retaining their distinct roles. What Goes Wrong Without Integration Without a shared platform, combined assurance typically faces: Overlap and duplication: multiple functions testing the same controls in slightly different ways. Gaps: important risks or processes that everyone assumes someone else is covering. Conflicting messages: different ratings or opinions about the same risk or control. Boards and executive committees receive multiple reports that are hard to reconcile, weakening confidence in the overall assurance picture. A Shared View, Different Responsibilities In an integrated model: Risk management (first/second line) owns and manages risks and controls as part of daily operations. Compliance ensures obligations are identified, implemented, and monitored. Internal audit provides independent assurance on the design and effectiveness of the governance, risk, and control framework. All three functions work from the same underlying data model: Shared risk taxonomy Shared control library Shared obligations and policies Shared records of incidents, issues, and remediation This doesn’t blur responsibilities; it aligns them. How Combined Assurance Works Day to Day On a platform like Falconry360, combined assurance becomes tangible: Annual and multi‑year assurance plans can be built on the same risk and control data, showing which functions will cover which areas and when. Overlaps and gaps can be identified visually and resolved in planning, rather than discovered later. Assurance results from risk, compliance, and audit activities feed back into a single picture of control effectiveness. Boards can then see, for each key risk or process: Which controls are in place. Which functions have tested them (risk/control testing, compliance monitoring, internal audit, external audit). What the combined results say about residual risk and control strength. The Role of FalconryX Intelligence further strengthens combined assurance by: Highlighting risks and controls with high levels of activity (incidents, issues, test failures) that might merit additional assurance. Suggesting areas where testing is sparse, indicating potential blind spots. Helping draft integrated assurance reports that combine perspectives from risk, compliance, and audit. Combined assurance moves from concept to operating practice—supported by data rather than slides.
Always Audit-Ready: How a Single Source of Truth Changes Internal Audit and ICFR

Internal audit and ICFR (Internal Control over Financial Reporting) are often constrained by one fundamental issue: they are forced to reconstruct the organization’s reality from multiple, inconsistent sources. Risk systems show one picture, compliance trackers another, finance and operations a third, and many details live only in spreadsheets and emails. A single source of truth changes this dynamic completely. When risk, controls, obligations, processes, incidents, and issues all live in one integrated model, internal audit stops acting as a data reconciler and starts operating as a strategic assurance function. The Problem with Fragmented Audit Evidence In traditional environments, audit and ICFR teams must: Extract and reconcile data from multiple systems to define scope and plan audits. Duplicate control documentation because they cannot easily reuse management’s control records. Spend disproportionate time on evidence collection and validation, rather than on analysis and insight. This fragmentation leads to longer audit cycles, higher cost, and more friction between lines of defense. It also weakens the ability to react quickly when regulators or boards request targeted assurance. What a Single Source of Truth Looks Like for Audit In a governance operating system like Falconry360, a single source of truth means: Risks, controls, and processes are defined once and shared across risk, compliance, finance, operations, and audit. Regulatory obligations and internal policies are mapped to the same controls and processes. Incidents, issues, test results, and remediation actions are logged in one place, with clear linkages. For internal audit and ICFR, this provides an always‑current baseline of what exists, what is supposed to happen, and where weaknesses have already been flagged. How Internal Audit Changes in This Model With a single source of truth, internal audit can: Perform risk-based planning using live data on risks, controls, incidents, and regulatory exposure rather than static, manually compiled lists. Design audit programs that link directly to the controls and obligations defined in the platform, avoiding re-documentation. Access evidence (documents, logs, approvals, test results) that is already attached to controls and workflows, reducing ad hoc requests. Testing moves from “recreate and re-prove everything” to “evaluate and challenge what management already relies on,” which is what regulators and boards increasingly expect. ICFR on a Shared Data Model For ICFR, a single source of truth means: Financial reporting risks can be aligned with the broader enterprise risk taxonomy, not maintained in isolation. Key controls over financial reporting can be tagged and managed as a subset of the overall control library. Control testing, deficiencies, and remediation can be tracked consistently with other control-related activities. This simplifies coordination between finance, risk, and audit and reduces duplication of controls and testing. In the UAE, this is becoming particularly important as the Securities and Commodities Authority (SCA) moves toward mandatory ICFR disclosure. The trial phase for implementing ICFR frameworks has been extended until the end of 2026, giving listed companies time to design and test controls. From 2027, annual reports must include an external auditor’s opinion on ICFR effectiveness, and from 2028 the scope expands to cover broader risk management, using the COSO Framework for design and ISAE 3000 as the assurance standard. This raises the bar on how transparent, well‑documented, and continuously monitored ICFR environments must be. Always Audit-Ready in Practice Being “always audit-ready” does not mean audits never require work. It means: Scope definition, risk assessment, and control selection are much faster because the data is already organized. Evidence is readily available and traceable to specific controls, risks, and obligations. Follow‑up on issues and remediation is transparent and continuously monitored. In this model, a request from the board, regulator, or external auditor does not trigger a scramble. It triggers a structured, data‑backed response generated from the governance operating system. Falconry360’s ICFR capabilities are designed to align with COSO and ISAE 3000 expectations, so UAE‑listed entities can move smoothly from the current SCA trial phase into full external assurance and public disclosure without rebuilding their control and evidence model.
Cross-GCC View: Building a Single Governance Framework Across SAMA, CBUAE, QCB, CBB, CBK, & CBO

Financial institutions operating across the GCC face a complex regulatory map: central banks and regulators in Saudi Arabia, UAE, Qatar, Bahrain, Kuwait, and Oman each issue their own rules, guidance, and expectations. Many themes overlap—governance, risk, capital, AML, resilience, technology—but the details differ. The traditional response is to build separate compliance programs for each jurisdiction. The more strategic approach is to design a single governance framework that can flex to local requirements while maintaining group‑wide consistency. For many of Falconry360’s current KSA implementations, 80–90% of the cyber governance and compliance workload is directly tied to NCA’s control frameworks (ECC, OTCC, CCC, DCC, CSCC, NCNICC‑1) and the SAMA CSF, making a unified, automation‑friendly model essential. Common Themes, Local Nuances Across SAMA, CBUAE, QCB, CBB, CBK, and CBO, common regulatory themes include: Strong corporate governance and board oversight of risk and compliance. Robust risk management frameworks covering credit, market, liquidity, and operational risk. Clear expectations around IT, cyber, outsourcing, and operational resilience. Enhanced conduct, consumer protection, and financial crime controls. The differences lie in the specifics: wording, thresholds, timelines, and supervisory styles. In Saudi Arabia, the National Cybersecurity Authority (NCA) and SAMA set the tone for cyber and technology risk. NCA’s Essential Cybersecurity Controls (ECC‑1:2018 and ECC‑2:2024), alongside specialised frameworks such as OTCC, CCC, DCC, CSCC, and the new NCNICC‑1:2025 for non‑CNI entities, define mandatory cybersecurity baselines for government, CNI and, increasingly, private sector. In parallel, the SAMA Cyber Security Framework (SAMA CSF) sets detailed governance, defence, and third‑party requirements for regulated financial institutions. Designing a Group-Level Governance Framework A single governance framework should define: Group‑wide principles for governance, risk management, compliance, resilience, and assurance. A unified risk taxonomy, control library, and set of core policies applicable across the group. A standard approach to incident management, issues, and remediation. This becomes the “spine” onto which local regulatory requirements are mapped. Mapping Local Regulations to the Group Framework Using a platform like Falconry360, institutions can: Create separate obligation sets for each regulator (SAMA, CBUAE, QCB, CBB, CBK, CBO). Map those obligations to the group‑level risk, control, and policy framework, tagging where additional local controls or variations are required. Identify common control sets that satisfy multiple regulators, reducing duplication and conflict. This “many regulators, one framework” approach supports efficient compliance and clearer internal understanding. For example, group-level cyber and technology controls can be mapped once and then cross‑referenced to NCA ECC / OTCC / CCC / DCC / CSCC / NCNICC‑1 and the SAMA CSF, instead of maintaining separate, conflicting control sets per entity. Entity-Level Views and Responsibilities A single framework does not mean a single view. Each regulated entity still needs clear, tailored oversight. Within the same platform, groups can: Maintain entity-specific views showing which obligations, risks, and controls apply to each entity. Support local risk and compliance teams with dashboards and workflows aligned to their regulator. Ensure that entity‑level incidents, breaches, and issues are visible both locally and at group level. This allows both central and local teams to work from the same data while fulfilling their distinct responsibilities. Role of FalconryX in Cross-GCC Governance FalconryX can accelerate and enhance this cross‑GCC approach by: Reading and summarising regulatory documents from multiple central banks, highlighting common and divergent requirements. Suggesting mappings between local obligations and group-level controls and policies. Helping draft comparative analyses and impact assessments for group and board review. Over time, this builds a more intelligent, reusable understanding of how different GCC regulators approach similar themes, allowing the group to respond in a coherent, confident way.
Free Zone Expectations: Aligning with DFSA and FSRA Across Risk, Compliance, and Audit

Firms operating in Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) face a distinct set of regulatory expectations from the Dubai Financial Services Authority (DFSA) and the Financial Services Regulatory Authority (FSRA). While many themes overlap with CBUAE—governance, risk, conduct, resilience—the detailed requirements and supervisory styles differ. For groups that operate both onshore and in the free zones, alignment becomes a multi‑dimensional challenge. A single governance operating model can make this manageable. Understanding the Free Zone Lens DFSA and FSRA place particular weight on: Strong, documented governance and oversight structures within the licensed entity. Clear risk management frameworks proportionate to the firm’s nature, scale, and complexity. Conduct, market integrity, and customer protection, especially for retail and wealth‑focused activities. Effective internal audit and compliance functions with direct access to governing bodies. Firms must be able to demonstrate not just broad frameworks, but how those frameworks are applied specifically to the free zone entity. Building a Combined Obligations Model Instead of maintaining separate, isolated compliance trackers for DFSA and FSRA, firms can: Create a combined obligations register that includes DFSA and FSRA rules, mapped to common themes (governance, systems and controls, risk management, conduct, financial crime, etc.). Tag obligations by regulator and entity, so it’s clear where requirements are unique and where they overlap. Link obligations to shared control libraries wherever possible, while allowing for free zone specific nuances. This enables a “single brain, multiple faces” model: a shared understanding of controls and risks, with tailored reporting for each regulator. Aligning Risk and Control Frameworks Risk and control frameworks should not diverge simply because the licensed entity is in a free zone. Using a unified platform, firms can: Maintain a single risk taxonomy across the group, with the ability to view and assess risks at entity level (including each DFSA/FSRA firm). Use common control definitions, while permitting local variations where DFSA or FSRA impose specific requirements. Ensure incidents, breaches, and issues relating to free zone entities are logged and managed consistently with group standards. This approach reduces duplication and enables group‑wide insights, while still respecting each regulator’s expectations. Internal Audit and Combined Assurance DFSA and FSRA expect robust internal audit and oversight. A shared operating model helps. Firms can: Build an audit universe that reflects both group and free zone-specific risks and processes. Plan risk‑based audits that consider DFSA/FSRA priorities alongside other regulatory requirements. Link audit findings and remediation actions to the same risks, controls, and obligations used by risk and compliance teams. This strengthens combined assurance: risk, compliance, and audit speak the same language and draw from the same data. How Falconry360 Simplifies Free Zone Alignment Using Falconry360: DFSA and FSRA obligations sit alongside CBUAE and other frameworks within one model. Risks, controls, and incidents are captured once and reused; local nuances are handled through tags and views rather than separate systems. FalconryX can assist in reading DFSA/FSRA rule updates, suggesting mappings, and drafting impact analyses. The result is a coherent, efficient approach to free zone governance that reduces friction and demonstrates a mature, group‑wide control environment.
Ethics and Culture: The Foundation of Effective Risk Management

Explore why strong ethics and a healthy culture are essential to controlling risk and ensuring compliance. When organizations think about risk management, they often focus on frameworks, policies, and controls. These are essential—but they only work when supported by the right foundation: ethics and culture. A robust risk management program doesn’t succeed in spite of organizational culture—it succeeds because of it. Culture determines how policies are interpreted, whether issues are raised early, and how employees respond under pressure. Why does ethics and culture matter so much? Because even the best-designed controls can fail if people feel incentivized to bypass them, fear retaliation for speaking up, or lack shared values that guide good judgment. Tone at the Top Sets Expectations Leadership commitment is the single most important driver of culture. Boards and executives must model ethical behavior, communicate clear expectations, and demonstrate that shortcuts or ethical lapses will not be tolerated—even when they appear profitable in the short term. Frequent, authentic messaging reinforces that doing the right thing is non-negotiable. Align Values with Decision-Making A written code of conduct is not enough if it sits ignored in a drawer. Organizations must embed values into daily decision-making. This can include ethics training that uses realistic scenarios, decision frameworks that incorporate ethical considerations, and open discussions about “gray areas” employees may face. Making values operational helps prevent issues before they arise. Encourage Speaking Up An effective risk culture requires psychological safety. Employees must feel empowered to raise concerns, highlight errors, and share observations without fear of retaliation or blame. Anonymous reporting channels, whistleblower protections, and visible follow-up on raised issues all build trust in the system. By surfacing small problems early, organizations can prevent them from growing into crises. Reward the Right Behaviors Incentives shape behavior. Organizations need to ensure their reward systems don’t unintentionally encourage risk-taking or ethical lapses. This means aligning bonuses and performance metrics with not just results, but how those results are achieved. Recognizing employees who demonstrate ethical leadership reinforces that integrity matters. Integrate Ethics into Risk Management Processes Ethical considerations should not be an afterthought in risk assessments. For example, when evaluating third-party vendors, assess not only financial and operational risks but also their labor practices, environmental impact, and compliance history. Similarly, product development processes should consider customer safety and data privacy from the start. Monitor and Adapt Culture is not static. Organizations must measure it—through surveys, exit interviews, hotline data, and audit results—and respond to findings. Regular reviews help leadership identify trends, address emerging issues, and ensure the culture evolves with business changes. Conclusion Controls and policies are necessary, but they are not enough on their own. A strong ethical culture is the foundation that ensures risk management processes work in practice, not just on paper. By fostering transparency, integrity, and accountability, organizations don’t just avoid scandals—they build trust with customers, employees, investors, and regulators. At Falconry360, we help companies embed ethics and culture into their governance, risk, and compliance programs—creating organizations that are not only safer, but stronger and more resilient. How Falconry360 Helps Falconry360 supports ethical culture building with policy acknowledgment tracking, ethics training modules, misconduct case management, and real-time dashboards. Companies can reinforce values, improve transparency, and embed accountability into everyday operations.
Internal Controls for Growth: Making ICFR Work for You

Leverage Internal Controls over Financial Reporting (ICFR) to strengthen governance and enable strategic growth. Many companies treat Internal Controls over Financial Reporting (ICFR) as a compliance burden—an annual ritual to satisfy auditors and regulators. But smart organizations see ICFR as much more than a checkbox. When designed and maintained well, internal controls build trust with investors, enhance operational discipline, and create the foundation for sustainable, strategic growth. Why does ICFR matter? ICFR helps ensure that financial statements are reliable, free of material misstatement, and reflective of the business’s true health. This integrity underpins investor confidence, access to capital, and even M&A readiness. But its benefits extend far beyond financial reporting. Strengthen Governance and Accountability A robust ICFR framework clarifies roles and responsibilities throughout the organization. By documenting processes, defining control owners, and requiring sign-offs, companies reduce ambiguity and ensure accountability. This structure doesn’t just prevent fraud or errors—it reinforces good governance practices that support strategic decision-making. Drive Process Discipline and Efficiency Control documentation and testing often uncover inefficiencies, redundancies, and manual workarounds in core processes. Instead of seeing this as criticism, leading companies treat ICFR assessments as opportunities to streamline operations. Automating controls, standardizing workflows, and eliminating unnecessary steps improve both compliance and productivity. Enable Confidence During Growth and Change Growth introduces complexity. Expanding into new markets, launching new products, or acquiring businesses all create risks of control gaps. A mature ICFR program provides a consistent framework for managing change. By embedding controls into new processes early, companies avoid surprises during audits or due diligence—and maintain stakeholder confidence. Improve Risk Awareness Across the Business ICFR is a lens for identifying broader operational risks. For example, a gap in revenue recognition controls might indicate weaknesses in sales processes or contract management. By connecting financial control testing to enterprise risk management (ERM), companies gain a richer, more actionable view of their risk landscape. Support Regulatory and Investor Expectations Public companies—and many private firms seeking investment—face rising expectations for control environments. Auditors and regulators want evidence of effective design and operation of controls, while investors expect transparency and reliability. A well-run ICFR program provides that assurance, reducing the cost of capital and improving market reputation. Integrate Technology for Better Outcomes Modern control environments increasingly leverage technology: Automated controls reduce human error. Integrated risk and compliance platforms centralize documentation and testing. Data analytics support continuous monitoring of anomalies. These tools make ICFR more effective and efficient—turning what was once a manual burden into a source of strategic insight. Conclusion Internal Controls over Financial Reporting aren’t just about ticking regulatory boxes—they’re about building trust, enabling disciplined growth, and fostering a culture of accountability. By viewing ICFR as an enabler, not an obstacle, organizations can turn compliance requirements into a competitive advantage. At Falconry360, we help businesses design, implement, and manage internal control frameworks that not only meet regulatory standards but also drive real business value. How Falconry360 Helps Falconry360 strengthens internal controls with a centralized, audit-ready platform for control libraries, testing schedules, evidence collection, and role-based approvals. By automating workflows and mapping controls to frameworks, companies ensure reliable reporting and support growth with disciplined governance.