A GCC-native advisory and technology firm helping Saudi boards, regulated institutions, giga-projects and government-linked entities create value, protect trust and transform with confidence — in the region's largest and most actively enforced regulatory market.
Advisory & delivery base
Riyadh · Jeddah · Eastern Province
Senior specialists, local presence
Diversification, trust & capability
The Kingdom is the GCC's largest market and its most actively enforced regulatory environment — a place of giga-projects, rapid diversification and regulators that no longer just publish rules, but check and fine. Falconry is built to help institutions move fast and stay compliant.
Based in Riyadh and working Kingdom-wide — engaged for the long term and accountable locally, not a team that arrives for a workshop and leaves.
Senior specialists who have built, run and audited these functions inside regulated and government-linked institutions — backed by the depth of a wider GCC advisory and technology firm.
Our work is framed around the Kingdom's transformation — economic diversification, a deep financial sector, national capability and digital government.
Saudi Arabia's regulatory strength is also its complexity. A single Saudi bank answers to SAMA, the CMA, the NCA and SDAIA at once — with frameworks that overlap but never quite align. Managing them separately creates duplicated effort and compliance fatigue.
A licensed financial institution must satisfy SAMA's Cyber Security Framework and the NCA's Essential Cybersecurity Controls simultaneously, while also meeting PDPL for customer data. The 2026 expansion of NCA baseline controls to effectively all private-sector firms widened this further.
We map these overlapping obligations to a single set of controls and evidence — so you satisfy every regulator once, not each one separately.
Financial sector cyber
National baseline controls
Personal data
Capital-market institutions
Corporate and portfolio strategy, operating-model design, digital and AI enablement, and transformation assurance for consequential change.
In the Kingdom: supporting giga-project delivery, PIF-linked entity transformation and diversification agendas under Vision 2030.
Board and committee design, ERM, compliance, internal audit and ICFR working as one operating model.
In the Kingdom: Aligned to SAMA and CMA expectations for banks, insurers and capital-market institutions.
Cyber GRC, privacy operating models, technology risk, business continuity and operational resilience.
In Kingdom: SAMA CSF and NCA ECC readiness mapped together, plus PDPL compliance under active SDAIA enforcement.
Workforce and leadership capability, Saudisation-aligned talent development, ESG governance and sustainability reporting.
In Kingdom: Building national capability and long-term value in step with Saudisation and Vision 2030 human-capital goals.
Each stage delivers a usable outcome and prepares the next. We shape the answer, embed it as a working system, sustain it as a managed service, and transfer ownership to your people — so capability stays in the institution.
Diagnose the priority and design the target operating model — grounded in the Kingdom's regulators and enforcement reality.
Turn frameworks into live workflows, evidence, dashboards and automation through the platform and FalconryX.
Run the capability with you — capacity, cadence and virtual leadership that keep governance, risk and resilience live.
Transfer knowledge to your teams — building national capability in step with Saudisation, not dependency.
Saudi Arabia has one of the region's most demanding and actively enforced regulatory environments — with financial, cyber and data authorities whose mandates overlap. Our propositions are designed to help you meet them with evidence, not just intent.
The central bank and prudential regulator for banks, insurers and finance companies. Its Cyber Security Framework (CSF) is mandatory for licensed financial institutions, alongside outsourcing and third-party risk requirements — with regular self-assessment and audit expected.
Enterprise and operational risk, SAMA CSF readiness, outsourcing and third-party risk, and board-level risk reporting.
The regulator of the Saudi capital market, licensing and supervising capital-market institutions, listed companies and funds — with its own cybersecurity and governance expectations. (A distinct body from the UAE and Kuwait CMAs.)
Governance, disclosure readiness, ICFR, internal audit quality and assurance for listed and CMA-licensed entities.
The Kingdom's cyber regulator, issuing the Essential Cybersecurity Controls (ECC-2:2024) and related frameworks. The NCNICC-1:2025 release (Jan 2026) extended mandatory baseline controls to effectively all private-sector firms.
Cyber GRC, ECC readiness, control mapping, evidence health and remediation — reconciled with SAMA CSF where both apply.
The Saudi Data & AI Authority is the PDPL regulator, with the NDMO setting national data-governance policy. The PDPL has been in full force since 2024, with active enforcement — fines up to SAR 5 million and 72-hour breach notification.
Privacy operating models, RoPA, DPIAs, DPO-as-a-service, cross-border transfer and breach response aligned to PDPL.
Where a proposition references SAMA, CMA, NCA or PDPL alignment, it denotes capability designed to meet those expectations — not certification or endorsement by any Saudi authority. Regulatory frameworks evolve; we track changes and map our propositions accordingly.
Every seat gets a flagship engagement — delivered as consulting and sustained through managed services and automation — mapped to the regulator and the mandate that leader answers to in the Kingdom.
Governance effectiveness, assurance mapping and board reporting aligned to SAMA and CMA expectations.
A live board-reporting pack and assurance dashboard, refreshed each cycle.
Strategy & enterprise-risk operating model; transformation assurance for Vision 2030 programmes.
Live strategy-to-risk dashboard with automated performance and risk signals.
ICFR, controls and internal-audit quality for listed and CMA-regulated entities.
Managed IA support and ICFR office; automated control testing and evidence health.
ERM, appetite and multi-regulator readiness across SAMA, CMA, NCA and PDPL.
Managed GRC Office; automated obligation-to-control mapping across systems.
SAMA CSF and NCA ECC reconciled into one control set, with a PDPL-ready privacy model.
Managed Cyber GRC with vCISO/vDPO; automated evidence, breach workflows and control health.
Operational resilience, BCM and crisis readiness for critical services and giga-projects.
Managed resilience: BIA refresh, plan maintenance and exercise cadence.
Vision 2030 is transforming Saudi Arabia into a diversified, knowledge-led economy with a deep financial sector, world-class giga-projects and capable national talent. Our model is built to leave capability behind — transferring ownership to Saudi teams rather than creating dependency on outside advisors.
Governance and risk foundations for non-oil growth and giga-projects.
Assurance and controls aligned to SAMA and CMA expectations.
Saudisation-aligned talent development and knowledge transfer.
Cyber, continuity and AI governance under NCA and SDAIA.
Sovereign-fund entities, giga-projects and government-linked companies delivering Vision 2030 at scale.
Banks, insurers and capital-market institutions under SAMA and CMA supervision, strengthening risk and digital trust.
Critical-service and industrial organisations managing cyber, resilience and regulatory exposure at national scale.
Listed companies and diversified groups strengthening governance, controls, assurance and long-term value.
Based in Riyadh, accountable locally and engaged for the long term — not a visiting advisory team.
We reconcile SAMA, CMA, NCA and PDPL into one control set — turning compliance fatigue into one connected effort.
Advice that becomes live workflows, evidence and decision intelligence — and can be run for you as a managed service.
Knowledge transfer to your teams in step with Saudisation — we build ownership, not dependency.
SAMA or NCA readiness, PDPL under active enforcement, resilience for critical services, or a Vision 2030 transformation — we start focused, deliver locally, and build capability that lasts.
© 2026 Falconry Solutions. All Rights Reserved.