MARSAD
Methodology/ Obligations

One regulatory mandate, many framework citations.

SAMA expresses the same mandate in six different framework lenses. MARSAD records it once and links it to every control that cites it, so evidence attached to the mandate satisfies every framework at once.

What it is

An obligation is a regulator-issued mandate: a single discrete thing the bank must do. SAMA expresses the same mandate in many places: ITGF cites it from a governance angle, CSF from a cyber angle, CRFR from a resilience angle. In the prototype era those citations were treated as independent controls, with the bank silently duplicating evidence to satisfy each.

MARSAD lifts the obligation up as a first-class entity. Each regulator clause becomes one row in the obligation catalogue; the framework controls that cite it become links to that row. The dedup payoff is immediate: evidence attached to the obligation satisfies every framework that cites it.

Why it matters

Saudi banks running against the full SAMA stack (ITGF, CSF, CRFR, BCM, Counter-Fraud, Outsourcing) sit on 743 framework controls. Tracked control by control, the evidence pack swells, the auditor reads near-identical paragraphs under different control IDs, and the bank carries an audit burden shaped by how the frameworks are numbered rather than by what the regulator actually mandated.

MARSAD folds those 743 controls onto 135 distinct obligations, each gathering the controls that state one requirement. Evidence attaches at the obligation, so it scales with what the regulator mandated, not with how many controls cite it, and the citation trail back to every control stays intact.

The dedup payoff

The catalogue surfaces three headline metrics, the numbers a regulator demo opens on:

N obligations: distinct regulator mandates M citations: framework controls pointing at them K frameworks: distinct lenses contributing

At full SAMA loading, 743 controls fold onto 135 obligations: each obligation gathers five to six controls on average. On top of that sit cross-framework equivalences: where two frameworks state the same mandate, the Marsad Engine proposes the pair, an operator confirms it, and the confirmed link becomes navigable in both directions. Both numbers are live figures in the product, not marketing claims.

Worked example. The obligation CSF 3.1.1, Cyber Security Governance is one row in the catalogue, gathering the ten CSF controls that state the committee-and-governance requirement. ITGF 3.1.1 carries the IT-governance twin of the same mandate (the ITSC and its charter). The Engine proposes the pair as equivalent; once an operator confirms it, evidence of an active governance committee (charter, minutes, attendance) answers both lenses, with every control citation intact.

How MARSAD builds the catalogue

Obligations are extractor-managed; there is no admin write surface. The extraction is idempotent, so the catalogue rebuilds cleanly whenever the control catalogues change:

Regulator perspective vs framework perspective

The catalogue gives the bank two complementary lenses on the same underlying truth:

The obligations catalogue sits next to those framework surfaces, not in place of them. The bank can switch between “show me by mandate” and “show me by framework” depending on who's asking.

What customers see

What's coming next. Act 2 of the obligations track promotes each obligation's coverage state to a hash-chained snapshot, mirroring the four chains already live (resilience_state / blast_radius / process). The snapshot answers “what was this bank's coverage of obligation X on date Y, who signed it off, and what evidence did they cite?”. The regulator-defensible time-travel view.

Related methodology