A living model of the bank that has to keep running. Bounded scope, chain-audited, defensible to SAMA. A short walk through the concepts the platform is organised around.
MARSAD is the operational twin: a living model of the bank that has to keep running, distinct from the paper controls that traditional GRC platforms manage. The twin is bounded to operational resilience: services, dependencies, blast radius, resilience state, obligations. It is deliberately not financial, customer, or treasury twinning. Faithfulness, freshness, time-queryability, and simulation-capability are the four axes that make the claim defensible.
Operationally, that means read-only over the bank's truth (CMDB, HR directory, incident records) and first-class for the work regulators ask for: identifying the services that matter, evidencing that they stay available, and showing your working across the SAMA frameworks. The pages below explain each concept the platform is organised around, at the level of a buyer briefing rather than an internal handbook.
If you want the operating detail behind any of these, it ships with the deployment. Get in touch via hello@marsadcomply.com.
Identify, map, test, declare, evidence, the recurring cycle SAMA's framework expects, and how the four governance pillars feed it. Read this first; the rest of the methodology hangs off this cycle.
Read → 02 · OpRes spineHow important business services get identified, justified, and kept current as the bank's offering evolves. The spine of the OpRes cycle.
Read → 03 · OpRes spineThe floor of services that must remain available under stress, and how it gets declared, drilled, and signed off. Reads after IBS, since MVB is a scoped subset of the IBS register.
Read → 04 · OpRes spineThe non-IBS half of the regulator-facing story: four-class taxonomy on every service in the SSoT, anchored on SAMA ITGF 3.2.1-CR5. Closes SAMA’s “show me you considered every service” gap.
Read → 05 · Top-down lensBIAN service landscape with KSA-specific additions (mada, SADAD, SARIE, REDF, SIMAH, Nafath, Tanfeeth) and a per-tenant overlay. The top-down view that complements the IBS register’s bottom-up inventory. Populated by admin curation, staged CSV import and connector-derived edges.
Read → 06 · Cross-framework dedupSAMA mandates expressed once and cited many times across the six framework lenses. The dedup model that lets evidence attached to one mandate satisfy every framework that cites it. Closes the prototype-era “duplicate evidence across frameworks” gap and seeds the Act 2 snapshot chain.
Read → 07 · Framework lensesHow a control catalogue (ITGF, CSF, CRFR, BCM, Counter-Fraud, Outsourcing) gets assessed on a recurring cycle, and how findings flow back to the OpRes spine.
Read → 08 · LiftA graduated ladder from "starting out" to "advanced", with clear next-stage criteria so banks can see where they are without third-party assessment.
Read → 09 · Operating modelConfigurable patterns for review, peer-check, and dual sign-off across pillars, with an immutable audit log underneath.
Read → 10 · ReferenceThe terms used across the platform and in regulator conversations, in plain language. Useful when onboarding a new colleague to OpRes work.
Read →