MARSAD
LIVE TWIN
Observe · Map · Comply

This is your bank, observed.

MARSAD is the operational twin of bank resilience. It reads from the systems you already trust and keeps a living model of your services, dependencies and blast radius. Every change is sealed onto a hash chain, and the evidence it produces can be checked by anyone, without trusting MARSAD at all.

Frameworks6
Controls743
Hash chains14
Verifierkey-free
Deploymentsovereign
AI outputsgrounded
Why now

Six frameworks. One regulator. Disconnected tools.

SAMA's expectations have multiplied; the bank's GRC stack hasn't kept up.

01

Regulator pressure

ITGF, CSF, Counter-Fraud, BCM, CRFR and Outsourcing each carry their own controls catalogue, assessment cycle and evidence demands. SAMA expects the bank to tell one coherent story across all six.

02

GRC fragmentation

Spreadsheets, siloed GRC tools, point solutions and document libraries each hold part of the picture. None of them connect finding, fix, test, attestation and closure into the single end-to-end record the regulator wants to see.

03

Audit overhead

Every cycle, the bank rebuilds its evidence pack from scratch. MARSAD generates the pack from a frozen, sealed snapshot, so the same pack can be regenerated six months later and checked against the original, byte for byte.

MARSAD is a regulatory-evidence platform. It doesn't replace your CMDB or your GRC tooling. It composes what those systems already know into one operational-resilience narrative that your regulator can read, and independently check.

Read-only over your systems of record

Services, applications, vendors and dependencies come from your CMDB and monitoring estate through pluggable connectors. MARSAD models them, renders them and scores them. It never owns them.

First-class for the assessment work

Findings, attestations, drills, control tests, framework assessments and board declarations all live in MARSAD, each with a full lifecycle, an audit trail and a sign-off ceremony.

Evidence anyone can re-verify

Every closed cycle produces a signed pack that carries its own proof. A single open script re-checks the entire history with nothing but SHA-256. No MARSAD licence, no key, no trust required. How verification works.

The platform

Three modules. One observed model.

Foundation holds the register. The Operational Twin keeps it alive. Framework + CAP turns it into regulator-ready evidence.

MODULE 01

Foundation

The bank's register of record: entities sourced read-only from your CMDB and monitoring estate, plus the declarations the board signs.

  • Services, vendors, capabilities, products, CIs
  • Channels, journeys, risk-appetite statements
  • IBS register with a governed admission ceremony
  • MVB declarations with dual board sign-off
SEE THE MVB REGISTER →
MODULE 02

Operational Twin

The living model. Dependency cascade, blast radius, capability map and live telemetry: the bank that has to keep running, rendered as it runs.

  • The constellation: the full dependency graph
  • Cascade, fragility radar, channel heatmap
  • Scenarios, drills, recovery calibration, war room
  • Telemetry in; findings and evidence out
SEE THE CONSTELLATION →
MODULE 03

Framework + CAP

Six SAMA framework lenses over one assessment spine, worked through Preparer, Reviewer and Approver positions to a sealed evidence pack.

  • Assessment cycles with ML 1–5 scoring
  • Control testing: design, implementation, effectiveness
  • Document locker and gap analysis per framework
  • CAPs, letter intake, attestations, regulatory change
  • Resilience-maturity roadmap with board sign-off
SEE AN ASSESSMENT CYCLE →
From observation to evidence

Evidence your examiner can check without us.

Every control assessment runs against the observed model, not a questionnaire. When a cycle closes, MARSAD produces a signed pack: PDF for reading, JSON for computing, and a proof file covering all fourteen hash chains. Every assertion traces to a source, a time and an assessor.

The pack carries its own verifier: one open Python file that re-computes every chain from genesis using nothing but the standard library. If a single sealed row was altered after the fact, verification fails. The examiner doesn't have to trust MARSAD, or even run it.

Read the proof format and download the verifier →

OpRes scorecard · Payments CHAIN-AUDITED
Impact tolerance declaredIBS-PAY-01 · board-approved
Done
Severe-but-plausible scenarios4 of 5 tested this cycle
80%
Dependency map verified1,892 edges · 31 days since refresh
93%
Vendor exit plansCloud KSA · Card Switch
2 of 4
Recovery tested within tolerancelast drill 12 days ago
Done
The Marsad Engine

AI your regulator can live with.

The Engine drafts assessments, maps policy documents to framework expectations and suggests remediations. It decides nothing; people sign everything.

Your model, your jurisdiction

The Engine runs on a language model you host inside your own trust domain. Nothing leaves the deployment. No calls to a foreign AI service, ever.

Grounded, or discarded

Every suggestion must cite the real source it read. Citations that don't exist in your data are dropped and reported, and each result shows its grounding verdict on screen.

Sealed like any other evidence

Every Engine output is hashed onto its own chain, with the prompt and response fingerprints alongside. What the AI said, when, and from what: all of it re-verifiable in the pack.

Six frameworks, one spine.

Assessed once against the observed model, evidenced across every lens.
ITGF
IT Governance
240 controls
CSF
Cyber Security
158 controls
BCM
Business Continuity
75 controls
CRFR
Cyber Resilience
24 controls
CF
Counter-Fraud
196 controls
OUTS
Outsourcing
50 controls

All 743 controls are transcribed from the regulator's published text and verified against the source documents, not paraphrased. Each control runs through the same shape: catalogue, cycle, assessment, ML 1–5 score, finding, evidence. The MVB declaration and the OpRes lifecycle sit on the same spine.

The platform, in numbers

Every number on this page is checkable.

No composite case studies, no invented telemetry. These are properties of the shipped platform, and the evidence format lets you verify the ones that matter.

743CONTROLS
Across six SAMA frameworks, each transcribed from the regulator's text and verified against the source
14HASH CHAINS
Register changes, assessments, sign-offs and AI outputs, sealed append-only
3MODULES
Foundation, Operational Twin, Framework + CAP, over one observed model
1OPEN VERIFIER
One standard-library Python file re-checks any pack. No licence, no key.
Sovereign-deployable

Your data stays in your jurisdiction.

One isolated deployment per customer. KSA-domiciled by default. Air-gap-friendly when you need it.

MARSAD ships as one isolated stack per customer. There is no shared data plane between deployments, and your governance data never leaves your trust domain. A deliberately narrow management plane handles licence issuance, software updates and aggregated telemetry: metadata only, never customer data.

For SAMA-regulated banks the default is the Microsoft Azure Saudi region, with customer-managed keys, Customer Lockbox and the full Microsoft Cloud for Sovereignty programme.

  • Customer-managed encryption keys (BYOK / HYOK)
  • Customer Lockbox prevents provider access without per-session approval
  • Air-gap-tolerant: works indefinitely without outbound connectivity
  • Audit log + evidence pack stable across re-runs
  • Single inbound port, allowlistable outbound channels

Deployment shapes

Azure Saudi region
AKS + managed Postgres + Key Vault. Sovereign Landing Zone reference. Full PaaS automation.
GCP Dammam region
GKE + Cloud SQL + Sovereign Controls. Strong second target.
On-prem in bank DC
Single-VM Compose or air-gapped package. For the most regulator-conservative customers.
STC Cloud / Mobily Cloud
Locally-operated sovereignty narrative. Compose-on-VM shape.
Engagement model

Three engagement shapes. Pick whichever fits today.

Most banks start with the discovery workshop. Indicative pricing sits in the pricing brochure.

Discovery workshop

HALF A DAY, WITH YOUR OPRES AND GOVERNANCE LEADS

Walk the platform end to end against your bank's actual SAMA exposure and map your current GRC stack to the MARSAD modules. You leave with a gap analysis and a sized roll-out proposal.

Pilot cycle

8–12 WEEKS, ONE FRAMEWORK LENS, ONE IBS SUBSET

Stand up MARSAD with Foundation plus one module and run a single assessment cycle through to a sealed, verifiable evidence pack. You leave with an artefact you can put in front of your next audit.

Full deployment

FROM 12 WEEKS, PRODUCTION ROLL-OUT

All licensed modules, production hardening, identity integration, onboarding rails and full role-based access. You leave with MARSAD operating across the OpRes programme.

Plot a roll-out against your SAMA timeline.

Thirty minutes is enough for the first conversation. If you'd rather sketch the shape before talking, start with the pricing brochure.