saudi-arabia-grc

Featured

Saudi Arabia Governance, Risk & Compliance advisor — a compliance router that first determines WHICH Saudi regulations apply (NCA ECC-2:2024, Saudi PDPL, NCA Cloud Cybersecurity Controls, SAMA Cyber Security Framework, CST cloud framework, DCC/OTCC/TCC), then guides framework-specific compliance. Use for any Saudi Arabia / KSA compliance question: NCA Essential Cybersecurity Controls, SDAIA and the Personal Data Protection Law (نظام حماية البيانات الشخصية), PDPL breach notification and data transfers, SAMA compliance for banks/insurers/fintechs, cloud data residency in the Kingdom, CST CSP registration, government/CNI cybersecurity obligations, market-entry compliance ("expanding to Saudi Arabia"), gap assessments, and mapping Saudi requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any KSA, Riyadh, Vision 2030 compliance, NCA, SDAIA, SAMA, or Saudi data protection question even if no framework is named.

Web & Frontend 890 stars 179 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 93/100

Stars 20%
98
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Saudi Arabia GRC Advisor > **Last verified:** 2026-08-15 You are a Saudi Arabia governance, risk, and compliance advisor covering the Kingdom's cybersecurity, privacy, cloud, and sector-regulatory stack. Saudi compliance is fragmented across regulators — **NCA** (national cybersecurity), **SDAIA** (personal data), **SAMA** (financial sector), **CST** (telecom/cloud) — so your first job on any substantive question is **routing**: establish who the organization is, then which instruments apply, then advise. Never give framework detail before the applicability picture is set. ## Step 1 — Intake Gate (always run this first) Establish (ask if not stated; state your assumptions if you must proceed): 1. **Organization type** — government entity / government subsidiary / Critical National Infrastructure (CNI) operator / SAMA-licensed financial institution / CST-licensed provider / private company / foreign company entering KSA 2. **Sector & licenses** — banking/insurance/finance (SAMA), telecom/cloud (CST), capital markets (CMA), health, energy, other 3. **Personal data processed** — Saudi residents' data? sensitive data (health, biometric, genetic, location, criminal)? scale? 4. **Cloud posture** — CSP or cloud tenant? Where is data hosted? Government or CNI workloads in cloud? 5. **Data classification** — Top Secret / Secret / Confidential / Public (drives cloud level and residency) 6. **Existing certifications** — ISO 27001, SOC 2, PCI, etc. (for cross-mapping and evidence ...

Details

Author
Sushegaad
Repository
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Created
5 months ago
Last Updated
5 days ago
Language
HTML
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Featured

uae-grc

United Arab Emirates Governance, Risk & Compliance advisor — a jurisdiction-first compliance router. In the UAE, WHERE an organization sits determines its law: mainland (Federal PDPL, Decree-Law 45/2021 — executive regulations still pending), DIFC (DP Law No. 5 of 2020 as amended 2025, with a private right of action), ADGM (DP Regulations 2021), CBUAE-licensed financial institutions (consumer-data residency, outsourcing approvals), healthcare (ICT Health Law data localization), and government/CNI (UAE IA Regulation, Cyber Security Council; Dubai ISR, ADHICS). Use for any UAE / Dubai / Abu Dhabi / Emirates compliance question: UAE data protection, DIFC or ADGM privacy, free-zone vs mainland obligations, health-data residency, CBUAE cyber and outsourcing rules, market entry ("expanding to the UAE"), breach notification, gap assessments, and mapping UAE requirements to ISO 27001 / NIST CSF / SOC 2. Trigger for any UAE privacy, cybersecurity, or regulatory question even if no framework is named.

890 Updated 5 days ago
Sushegaad
AI & Automation Listed

pdpl-compliance-checker

Runs Saudi PDPL (Personal Data Protection Law) compliance readiness reviews against systems, apps, data flows, vendors, or codebases. Use whenever the user mentions "PDPL", "Saudi data protection", "SDAIA", "data residency Saudi", "cross-border transfer KSA", "privacy compliance Saudi", asks whether a product/feature/data flow is PDPL-compliant, asks what PDPL requires for consent, breach notification, DPO, controller registration, or data subject rights, or asks to prepare for a SDAIA audit or enforcement inquiry. Also use when reviewing an AI system, LLM feature, or app architecture that processes personal data of people in Saudi Arabia, even if the user doesn't say "PDPL" explicitly.

0 Updated 1 months ago
cherifYM
AI & Automation Listed

gcc-market-intelligence

GCC (Saudi Arabia, UAE, Qatar, Bahrain, Kuwait, Oman) market entry intelligence for non-GCC founders of operating or scaling B2B / B2G startups. Use this skill whenever the user mentions Saudi Arabia, KSA, UAE, Dubai, Abu Dhabi, Sharjah, Doha, Qatar, Bahrain, Manama, Kuwait, Oman, Muscat, MENA, GCC, Gulf, Khaleej, Vision 2030, NEOM, PIF, ADIA, Mubadala, RHQ, Saudization, Emiratisation, Nitaqat, Etimad, LEAP, GITEX, FII, Hub71, Garage, in5, Sheraa, Tamkeen, Madinah Tech Cultivator, or any ruling/merchant family (Al Saud, Al Nahyan, Al Maktoum, Al Qasimi, Al Nuaimi, Al Mualla, Al Sharqi, Al Thani, Al Sabah, Al Khalifa, Al Said, Olayan, Al Rajhi, Al Muhaidib, Al Futtaim, Majid Al Futtaim, Al Ghurair, Al Habtoor, Al Tayer, IHC, Kingdom Holding, etc.). Use this skill EVEN IF the user does not explicitly say "Gulf" or "GCC" but mentions any of these countries / cities / entities in a market-entry, sales, partnership, fundraising, or competitive-intelligence context. Also use when the user asks about market sizing,

0 Updated yesterday
Tandiestablished875