How a Gulf holding group is building group-wide assurance from a single workflow
The group began not with a governance programme, but with one obligation — deployed on sovereign cloud, on a data model the rest of the estate will inherit.
Not named while the engagement is in progress · no performance outcomes claimed
Case studyRisk & Resilience4 min readISO 37002ISO 22301Third-party riskData residency
Exposure is aggregate. The records are not.
The group holds several operating companies, each with its own:
Management — its own management
Systems — its own systems
Governance interpretation — its own interpretation of what good governance looks like
Group internal audit is deliberately small. Assurance is largely delegated downward.
That works until the group is asked a question at group level. Where two operating companies share a contractor, a regulator or a failure mode, nothing in the estate makes the connection.
And because data residency rules require information to remain in-country, most international governance software was excluded before the evaluation began.
Regulation is not the burden. Fragmentation is.
So the group did not begin with a group-wide governance programme. It began with one workflow: a confidential speak-up and disclosure channel operating across every operating company.
The decision that mattered
The reasoning was commercial rather than architectural. Speak-up has:
Smallest change footprint — minimal disruption to operations
Single accountable owner — clear responsibility
Quick board visibility — results within weeks
It is the workflow most likely to succeed first — which matters more than the workflow that looks most strategic on a roadmap.
The lesson is clear: a governance programme that stalls in month four teaches the operating companies that group initiatives stall. One that lands teaches them the opposite.
Start with one workflow. Add the next without rebuilding anything
A disclosure raised in a subsidiary is recorded against the same objects that will carry risks, findings and third-party assessments when those capabilities are switched on. Nothing raised today has to be re-mapped tomorrow. The sequence follows the group's actual exposure rather than a product tier.
Sovereign by deployment, not by exception
The platform and its AI layer run on in-country sovereign cloud infrastructure:
Data residency — data does not leave the jurisdiction
Full AI capability — not withdrawn as the price of sovereignty
Complete feature parity — same drafting, mapping and assessment support inside the sovereign boundary as outside it
Local content and in-country value requirements are met through a nationally-owned implementation partner. This approach keeps the group inside its own procurement qualification rules rather than seeking exemptions from them.
One platform, one licence, one implementation
The group is not:
Buying modules to be integrated later — no complex integration work
Signing separate agreements — no new contracts for each capability
Enablement is included rather than sold:
Academy — training resources for the group's risk and audit teams
Practitioner community — peer learning and best practices
Working resource library — ready-to-use templates and frameworks
All at no additional charge.
The reality: Governance deployments rarely fail on software. They fail on capability and adoption in the first line.
What the board gets: A single view of exposure across operating companies, assembled from records created in the course of the work rather than compiled for the meeting. As each capability is added, that view widens without anything already built being replaced.