Regulatory coverage
One audit universe, every framework you answer to
The frameworks below are a sample, the ones Saudi audit functions ask about first. Oversight ships with more than a hundred frameworks ready out of the box, works with any regulatory framework you upload, and hundreds more can be added as you go. Each page describes how a regulation becomes your audit universe, engagement programs, evidence requests and committee reporting.
- SAMA CSFSAMA Cyber Security FrameworkCyber security controls and maturity expectations for SAMA-regulated financial institutions.Saudi Central Bank (SAMA)
- SAMA BCMSAMA Business Continuity Management FrameworkBusiness continuity and resilience requirements for institutions regulated by SAMA.Saudi Central Bank (SAMA)
- SAMA ITGCSAMA IT Governance FrameworkIT governance, operations and change requirements for SAMA-regulated institutions.Saudi Central Bank (SAMA)
- NCA ECCNCA Essential Cybersecurity ControlsThe baseline cyber security controls for government entities and critical national infrastructure.National Cybersecurity Authority (NCA)
- PDPLPersonal Data Protection LawSaudi Arabia's personal data protection law and its implementing regulations.Saudi Data and AI Authority (SDAIA)
- CMACapital Market Authority regulationsGovernance, conduct and reporting requirements for listed companies and capital market institutions.Capital Market Authority (CMA)
- ZATCAZATCA tax and e-invoicing requirementsZakat, VAT and e-invoicing obligations, including integration with ZATCA's Fatoora system.Zakat, Tax and Customs Authority (ZATCA)
- ISO 27001ISO/IEC 27001 information security managementThe international standard for an information security management system and its Annex A controls.International Organization for Standardization (ISO)
Have a framework that is not listed?
Over a hundred come built in, and any framework you upload becomes criteria the same day, a new circular, an internal standard, or the next thing your regulator publishes.