MARSAD is the operational twin of bank resilience. It reads from the systems you already trust and keeps a living model of your services, dependencies and blast radius. Every change is sealed onto a hash chain, and the evidence it produces can be checked by anyone, without trusting MARSAD at all.
SAMA's expectations have multiplied; the bank's GRC stack hasn't kept up.
ITGF, CSF, Counter-Fraud, BCM, CRFR and Outsourcing each carry their own controls catalogue, assessment cycle and evidence demands. SAMA expects the bank to tell one coherent story across all six.
Spreadsheets, siloed GRC tools, point solutions and document libraries each hold part of the picture. None of them connect finding, fix, test, attestation and closure into the single end-to-end record the regulator wants to see.
Every cycle, the bank rebuilds its evidence pack from scratch. MARSAD generates the pack from a frozen, sealed snapshot, so the same pack can be regenerated six months later and checked against the original, byte for byte.
MARSAD is a regulatory-evidence platform. It doesn't replace your CMDB or your GRC tooling. It composes what those systems already know into one operational-resilience narrative that your regulator can read, and independently check.
Services, applications, vendors and dependencies come from your CMDB and monitoring estate through pluggable connectors. MARSAD models them, renders them and scores them. It never owns them.
Findings, attestations, drills, control tests, framework assessments and board declarations all live in MARSAD, each with a full lifecycle, an audit trail and a sign-off ceremony.
Every closed cycle produces a signed pack that carries its own proof. A single open script re-checks the entire history with nothing but SHA-256. No MARSAD licence, no key, no trust required. How verification works.
Foundation holds the register. The Operational Twin keeps it alive. Framework + CAP turns it into regulator-ready evidence.
The bank's register of record: entities sourced read-only from your CMDB and monitoring estate, plus the declarations the board signs.
The living model. Dependency cascade, blast radius, capability map and live telemetry: the bank that has to keep running, rendered as it runs.
Six SAMA framework lenses over one assessment spine, worked through Preparer, Reviewer and Approver positions to a sealed evidence pack.
Every control assessment runs against the observed model, not a questionnaire. When a cycle closes, MARSAD produces a signed pack: PDF for reading, JSON for computing, and a proof file covering all fourteen hash chains. Every assertion traces to a source, a time and an assessor.
The pack carries its own verifier: one open Python file that re-computes every chain from genesis using nothing but the standard library. If a single sealed row was altered after the fact, verification fails. The examiner doesn't have to trust MARSAD, or even run it.
The Engine drafts assessments, maps policy documents to framework expectations and suggests remediations. It decides nothing; people sign everything.
The Engine runs on a language model you host inside your own trust domain. Nothing leaves the deployment. No calls to a foreign AI service, ever.
Every suggestion must cite the real source it read. Citations that don't exist in your data are dropped and reported, and each result shows its grounding verdict on screen.
Every Engine output is hashed onto its own chain, with the prompt and response fingerprints alongside. What the AI said, when, and from what: all of it re-verifiable in the pack.
All 743 controls are transcribed from the regulator's published text and verified against the source documents, not paraphrased. Each control runs through the same shape: catalogue, cycle, assessment, ML 1–5 score, finding, evidence. The MVB declaration and the OpRes lifecycle sit on the same spine.
No composite case studies, no invented telemetry. These are properties of the shipped platform, and the evidence format lets you verify the ones that matter.
One isolated deployment per customer. KSA-domiciled by default. Air-gap-friendly when you need it.
MARSAD ships as one isolated stack per customer. There is no shared data plane between deployments, and your governance data never leaves your trust domain. A deliberately narrow management plane handles licence issuance, software updates and aggregated telemetry: metadata only, never customer data.
For SAMA-regulated banks the default is the Microsoft Azure Saudi region, with customer-managed keys, Customer Lockbox and the full Microsoft Cloud for Sovereignty programme.
Most banks start with the discovery workshop. Indicative pricing sits in the pricing brochure.
Walk the platform end to end against your bank's actual SAMA exposure and map your current GRC stack to the MARSAD modules. You leave with a gap analysis and a sized roll-out proposal.
Stand up MARSAD with Foundation plus one module and run a single assessment cycle through to a sealed, verifiable evidence pack. You leave with an artefact you can put in front of your next audit.
All licensed modules, production hardening, identity integration, onboarding rails and full role-based access. You leave with MARSAD operating across the OpRes programme.
Thirty minutes is enough for the first conversation. If you'd rather sketch the shape before talking, start with the pricing brochure.