Arduredu automates evidence collection, risk management, audit preparation, and incident tracking across SAMA, NCA-ECC, ISO 27001, and 9 other frameworks β deployed on your own server in 30 minutes.
See how Arduredu automates compliance evidence, manages risk, and prepares your organisation for SAMA and NCA audits β live on your own server.
Banks, government entities, and critical infrastructure operators across the GCC face growing regulatory pressure β with tools that were never built for local frameworks.
Compliance teams spend weeks collecting screenshots, logs, and documents from 15β20 different systems before every SAMA or NCA assessment.
Risk, compliance, audit, policy, and incidents live in separate tools. No CISO can answer "Are we SAMA-compliant right now?" with confidence.
Organisations discover gaps during SAMA or NCA assessments β not before. By then it's too late to fix, and findings lead to sanctions.
Global GRC tools (ServiceNow, Archer, MetricStream) cost millions, take 6β12 months to deploy, and still don't cover SAMA or NCA natively.
Real-time compliance score per framework, updated continuously as your environment changes. See exactly which controls pass, fail, or need evidence β across all 12 frameworks simultaneously.
Real-timeUpload any policy document, audit report, or certificate β Arduredu's AI engine automatically extracts evidence and maps it to the right controls with confidence scoring. No manual mapping needed.
AI-poweredVisual 5Γ5 risk heat map, risk appetite settings by category, and full treatment workflow (Mitigate, Accept, Transfer, Avoid). Assign risk owners, set due dates, and track financial exposure.
Heat MapFull incident register with NCA 72-hour notification countdown timer. Automatic sync from ServiceNow and Jira. Log notifications to NCA, SAMA, and SDAIA with reference number tracking.
NCA-ECC-5-1Manage internal and external audit programmes, findings, and corrective action plans (CAPs). Annual audit planning calendar, external auditor register, and one-click evidence package export for regulators.
CAPs & CalendarFull policy lifecycle with approval workflow β Draft, Review, Approve, Publish, Retire. Version control saves every change. Staff acknowledgement tracking. GRC Officer and CEO sign-off built in.
Approval WorkflowAll 244 SAMA Data Collection Questionnaire questions pre-loaded. Answers auto-populated from connected systems. Export to Excel in the exact SAMA submission format β reducing weeks of work to hours.
244 QuestionsFull evidence registry with gap analysis, expiry tracking, and bulk evidence requests. Know exactly what evidence you have, what's missing, and what's expiring β per framework, per control.
Audit-readyTrack all third-party vendors with risk tier classification, SAMA security clause compliance, DPA status, contract expiry alerts, BitSight and SecurityScorecard continuous monitoring.
SAMA-13One-click gap analysis showing every failing control, regulatory reference, AI-generated remediation guidance, and what evidence is needed. Board and auditor ready with export.
Board-readyGlobal tools don't cover SAMA, NCA-ECC or SDAIA natively. Arduredu is built specifically for GCC regulatory requirements β plus all major international frameworks.
Mandatory for all financial institutions supervised by SAMA. Full control mapping with automated evidence from 27+ connectors and SAMA DCQ auto-fill.
Saudi Arabia's national cybersecurity framework β mandatory for government entities, banks, and critical sectors. Includes NCA 72-hour incident notification tracking.
NCA framework for cloud service adoption in Saudi Arabia. Covers cloud governance, data classification, and shared responsibility model compliance.
NCA framework for data classification, data lifecycle management, and data protection requirements for Saudi organisations.
Saudi Arabia's Personal Data Protection Law. Covers consent, cross-border transfers, breach notification, and data subject rights.
Global standard for information security management. Opens enterprise procurement internationally. 93 controls mapped to Annex A requirements.
EU data privacy law β fines up to β¬20M or 4% of global turnover. Essential for any organisation handling EU personal data or with EU operations.
UAE's national information assurance framework for government and critical infrastructure. Aligned with UAE Cybersecurity Council requirements.
NIS2 (EU cybersecurity), DORA (EU financial resilience), SOC 2 (US enterprise), and PCI-DSS v4 (payment card security) β all available in the same platform.
27+ connectors with read-only access. Evidence collected automatically. One scan updates compliance scores across all frameworks simultaneously.
Arduredu deploys on-premise β your data never leaves your environment. Docker-based installation, one command, fully automated.
Submit your download request. Arduredu reviews and provides a secure, time-limited download link within 24 hours.
Two packages: Application Server and AI Server. Extract and configure your environment file with your organisation details.
One command: ./install.sh β deploys all services, configures SSL, and starts the platform automatically.
Connect your existing security systems. Compliance scores appear immediately. Evidence collected automatically from day one.
Book a live demo, request a pilot deployment, or ask us anything about SAMA, NCA-ECC, or GCC compliance. We respond within 24 hours.
Arduredu is an enterprise on-premise platform. All pricing is customised per organisation. Contact us for a tailored proposal.
Request Download Access βWe understand the pressure of regulatory audits, the complexity of GCC frameworks, and the gap between what compliance teams need and what legacy tools deliver.
We invented Arduredu to solve a problem no existing tool could β making SAMA, NCA-ECC, and GCC regulatory compliance truly automatic.
To make regulatory compliance effortless for every organisation in the GCC and beyond β through automation, intelligence, and deep local regulatory knowledge.
To become the most trusted GRC platform in the GCC market and beyond β the platform that every CISO, Compliance Officer, and Board member relies on before every regulatory audit.
Transparency in everything we build. Accuracy in every compliance score. Respect for the complexity of regulatory work β and relentless innovation to make it simpler.