Skip to main content
NexITC
B17 · CYBERSECURITY · 10–14 WEEKS · BUILD

One risk view.
Across every framework.

B17 · GRC Platform Build™ delivers a unified GRC platform that maps controls across PDPL, ISR, ADHICS v2, NESA, CBUAE, SAMA, and sector-specific frameworks, with automated evidence collection, exception workflows, and executive risk dashboards. Not a spreadsheet. Not a marketing platform. The operating platform your CRO and CISO both run from.

DURATION
10–14 wks
DELIVERABLES
7 named
COMMERCIAL
Fixed fee
B17·PROJECTION / AUDIT PREPARATION TIME
B17
BEFORE
21 days
AUDIT PREP · PER CYCLE
B17
AFTER
4 days
AUDIT PREP · PLATFORM-GENERATED
WK 00
WK 04
WK 08
WK 12
STEADY
DUPLICATED CONTROLS ↓
35%
EVIDENCE AUTOMATION
70%
AUDIT PREP ↓
80%
SCENARIO · UAE FINANCIAL SERVICES GROUP · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY MULTI-FRAMEWORK
COMPLIANCE FAILS.

A UAE group with four licensed entities typically manages PDPL in one spreadsheet, CBUAE requirements in another, ISR or ADHICS v2 in a third, and internal governance in a fourth. The same control — access review, encryption at rest, incident notification — is written four times, owned by four people, evidenced four ways, and reported in four different formats to a board that wants one number.

The instinct is to hire more compliance analysts to keep the spreadsheets aligned. The instinct scales linearly with frameworks and entities, which is exactly the wrong shape. What works is one control library mapped across every in-scope framework, evidence collected once and referenced many times, exceptions managed through a single workflow, and an executive view that consolidates without hiding the entity detail underneath. B17 builds that platform on a fixed scope in 10–14 weeks.

STATE · SILOED
Framework per spreadsheet. Controls duplicated across entities. Audit prep two to three weeks, every cycle.
STATE · CONSOLIDATED
One control library. Evidence collected once. Exceptions on a single workflow. Board view with drill-down.
§ 01 · WORK STREAMS

Six streams,
ending in one platform live.

Framework scoping and control-library mapping front-load weeks 1–5. Risk register, platform configuration, and evidence automation overlap through weeks 4–12. Enablement and validation close weeks 12–14.

STREAM 01
WK 01–02

Framework scoping

In-scope frameworks confirmed, entity coverage agreed, cross-framework overlap mapped before any platform decision is made.

STREAM 02
WK 02–05

Control library mapping

Unified control library built with cross-framework references and ownership assigned per control. One control, many framework citations.

OUTCOME
1
UNIFIED CONTROL LIBRARY
+ EVIDENCE AUTOMATION LIVE
STREAM 03
WK 04–08

Risk register design

Scoring methodology aligned to board risk appetite, register schema, and the drill-down structure the CRO will actually present from.

STREAM 04
WK 06–10

Platform configuration

GRC platform configured, entity structure built, workflow templates deployed against the mapped library.

STREAM 05
WK 09–12

Evidence automation & dashboards

Automated collection from source systems, executive dashboards, and exception workflows with request, approve, expire, review.

STREAM 06
WK 12–14

Enablement & validation

Control owners trained, first audit-pack generated from platform data, validation against a sample cycle with internal audit, handover.

EXPLICITLY NOT COVERED
Policy authoring and framework interpretation
boundary work for your GC and CISO office with legal advisors. B17 platforms the controls; it does not decide what they should say.
Implementing the underlying controls
that is B8 Controls Implementation Build™, frequently paired with B17 in the same programme.
§ 02 · TIMELINE

Fourteen weeks maximum.
Ten minimum. Four phases.

Phase count is fixed. Duration flexes with framework count, entity count, and the number of source systems in scope for evidence automation. Milestones are signed gates — not aspirations.

WK 01020304050607080910111213 · 14Phase 1 · Scoping & control libraryPhase 2 · Risk register & platformPhase 3 · Evidence automationPhase 4 · EnablementControl library signedEND WK 05 · GATE 01Platform configuredEND WK 10 · GATE 02Automation liveEND WK 13 · GATE 03Handover completeEND WK 14 · GATE 04OPERATING RHYTHMDaily standup · Weekly control-owner check-in · Bi-weekly Practice Lead reviewNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalationavailable)
§ 03 · APPROACH

Platforms scored,
not on framework logo count.

Every engagement runs a six-criteria scorecard in weeks 1–3. Each candidate platform scored 1–5 against your framework set, entity structure, and source systems. Signed by CRO and CISO before Phase 2 begins.

GRC PLATFORM SELECTION SCORECARD · TEMPLATE
CRITERIA · 06 · WEIGHTED 1–5
ILLUSTRATIVE SAMPLE RENDERING — actual scores are engagement-specific and derived from evidence gathered during discovery.
01
Multi-framework native support
Native mapping across your framework set — not framework-shaped consulting services billed as product capability.
5/5
02
UAE data residency
In-country storage for evidence and risk data — PDPL, ADHICS v2, and CBUAE cloud oversight where applicable.
5/5
03
Native evidence-automation connectors
Connectors to the source systems you actually run. Every missing connector is custom integration cost.
4/5
04
Multi-entity and multi-jurisdiction support
Entity structures with separate ownership and consolidated reporting. Common in UAE group structures.
4/5
05
Executive dashboard flexibility
Board-appropriate summarisation with drill-down to entity, framework, and control. Not a screenshot pasted into a deck.
4/5
06
Three-year TCO
Total cost against your framework and entity count, including growth in both.
3/5
!
DISCLOSURE · VENDOR-NEUTRALITY
NexITC maintains commercial arrangements with several GRC platforms, IRM tools, and evidence-automation vendors — these are how specialist consultancies build sustainable practices. We do not disclose which arrangements exist publicly because we do not want them to influence tool choice by anyone reading this page. The scorecard exists precisely so selection happens on evidence, not on economics. In practice, we have recommended tools with which we have no partnership when the scorecard result favoured them.
§ 04 · ARCHITECTURE

From framework silos
to one operating view.

A typical pre-engagement state runs a spreadsheet per framework per entity, duplicated controls, no consolidated risk view, and two to three weeks of audit preparation every cycle. The engagement consolidates that into one platform with automated collection.

BEFORE · T=0
TYPICAL STATE
ARTIFACT_01
Spreadsheet per framework
PER ENTITY
ARTIFACT_02
Duplicated control text
FOUR OWNERS
ARTIFACT_03
No consolidated risk view
BOARD BLIND
ARTIFACT_04
Manual evidence gathering
PER CYCLE
AUDIT · TIME
2–3 weeks of preparation per audit cycle, per entity
OPERATIONAL REALITY
  • The same control written and evidenced four times
  • No single number the board can be given
  • Exceptions tracked in email threads
  • Compliance headcount scales with framework count
B17 · CONSOLIDATE
AFTER · STEADY STATE
TARGET-STATE
PLATFORM_01
GRC Platform
Risk Register · Control Library · Evidence Workflows · Dashboards
PLATFORM_02
Evidence Automation
Source-System Connectors · Scheduled Manual · Exception Workflow
↓ MAPPED · COLLECTED ONCE · REPORTED MANY ↓
SOURCE SYSTEMS · RETAINED
Connected, not replaced
STEADY-STATE OUTCOME
  • One control library across every in-scope framework
  • Evidence collected once, cited by many frameworks
  • Exceptions on a single request/approve/expire workflow
  • Audit pack generated from platform data in days

Reference pattern. Some engagements keep scheduled manual collection for source systems without a usable API. What always changes is that the collection is scheduled, owned, and visible rather than improvised before an audit.

§ 05 · REPRESENTATIVE SCENARIO

A financial services group,
consolidated.

Representative pattern for a UAE financial services group of this scale — four entities, PDPL, CBUAE, and ISR managed in spreadsheets. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / B17 / UAE FINANCIAL SERVICES · 4 ENTITIES
DURATION · 12 WKS
DUPLICATED CONTROLS
−35%
Collapsed into cross-referenced library
EVIDENCE AUTOMATION RATE
70%
Controls with automated collection
AUDIT PREP TIME
3 wks 4 days
First cycle generated from platform data
SITUATION

UAE financial services group with four licensed entities. PDPL, CBUAE, and ISR obligations tracked in separate spreadsheets per entity, the same controls written multiple times with different owners, no consolidated risk view for the board, and two to three weeks of audit preparation every cycle.

ENGAGEMENT

12-week B17. Weeks 1–5 framework scoping and a unified control library with cross-framework references. Weeks 5–10 risk register design against board risk appetite and platform configuration across the four entities. Weeks 9–12 evidence automation from source systems, exception workflows, executive dashboards, and validation with internal audit.

OUTCOME

Duplicated control text down 35% through cross-framework mapping. Evidence automation at 70% of in-scope controls, with the remainder on scheduled manual workflows and named owners. First audit pack generated in four days instead of three weeks. Group moved to C6 ComplianceOps™ UAE to operate the platform.

§ 06 · DELIVERABLES

Seven artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

GRC Platform MVP

Configured, integrated, and live for the first wave of entities and frameworks.

D_02

Unified Risk Register

Scoring methodology aligned to board risk appetite, with entity structure and drill-down.

D_03 · CORE

Control Library

Mapped across all in-scope frameworks with cross-references and per-control ownership. One control, many citations.

D_04

Evidence Automation Workflows

Connectors to source systems where the API supports it, scheduled manual workflows for the rest.

D_05

Exception Management Workflow

Request, approve, expire, review — with escalation when an exception ages past its date.

D_06

Executive Risk Dashboards

Board-appropriate summarisation with drill-down to entity, framework, and control.

D_07 · OPERATOR-READY

Operating Model & Owner Enablement

Playbook per control owner, first audit-pack template generated from platform data, sample cycle validated with internal audit — the pack a CRO defends to the board without translating from consulting jargon.

HANDOVER
WK 14
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not "the platform is deployed." It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at post-handover steady state.

THE AUDIT PREPARATION JOURNEY · REPRESENTATIVE
Twenty-one days to four, across the four phases.
4daysAUDIT PREP · STEADY
25 d19 d13 d6 d021 dBaselinePRE-ENGAGEMENT12 dLibrary mappedEND WK 056 dAutomation liveEND WK 134 dSteady state30 DAYS POST
01 · COVERAGE
95+%
Control coverage across all in-scope frameworks.
02 · AUTOMATION
60–75%
Evidence automation rate across in-scope controls.
03 · RISK REGISTER
100%
Risk register completeness against agreed scope and entities.
04 · EXCEPTIONS
<14days
Exception resolution cycle time at steady state.
05 · AUDIT PREP
80%
Reduction in audit preparation time per cycle.
06 · REPORTING
3
Executive reporting cadences adopted — weekly, monthly, board.
§ 08 · FIT

Honest scoping.

B17 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
Multiple frameworks genuinely in scope

The economics of a platform come from cross-framework reuse. One framework rarely justifies the build.

02
CRO and CISO both engaged

Risk methodology and control ownership are decided jointly. One without the other stalls at Phase 2.

03
Source-system access agreed

Evidence automation depends on it. Access negotiation after Phase 3 begins is the most common cause of slippage.

04
Entity structure defined

Which licensed entities are in scope, and how they consolidate for board reporting.

05
First audit deadline outside four months

Inside that window we scope to a defensible MVP subset, or recommend sequencing differently.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
Single framework, single entity

B8 Controls Implementation Build™ is likely more cost-effective. A platform for one framework is overhead.

You need a policy library, not a platform

Policy authoring is a different discipline — your GC and CISO office with legal advisors.

You want managed compliance, not a platform

C6 ComplianceOps™ UAE as a first engagement, with the platform question revisited later.

Audit deadline inside four months

Honest scoping conversation — a defensible MVP subset where feasible, and a clear statement of what stays uncovered.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based.

Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.

STANDARD MODEL
ENGAGEMENT MODEL
Fixed fee
PAYMENT CADENCE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 7 named deliverables with acceptance criteria
  • Named Practice Lead throughout the engagement
  • Bi-weekly executive sponsor reviews
  • 30/60/90-day post-handover check-ins
  • Written scope amendment process for any changes
01

Signed scope statement

Every engagement begins with a signed scope statement fixing deliverables, timeline, milestones, and commercial terms. No verbal agreements. No moving targets.

02

No scope creep

Scope changes require a signed scope amendment. If scope changes, so does the commercial arrangement — always in writing, always signed by both parties.

03

Named accountability

The Practice Lead is accountable for commercial and delivery outcomes throughout the engagement, with escalation to the CEO within 24 hours if needed.

§ 10 · QUESTIONS

Five, most asked.

Q_01How is this different from Compliance Fast-Track™?

A3 Compliance Fast-Track™ UAE is a 2–4 week readiness assessment — it tells you where you stand and what the backlog is.

B17 is the platform that operationalises multi-framework compliance at scale. Different scope entirely, and frequently sequenced A3 → B17.

Q_02Which frameworks can be mapped?
PDPL, ISR (Dubai), ADHICS v2 (Abu Dhabi), NESA, CBUAE, SAMA (for KSA operations), and internal governance requirements. Sector-specific frameworks are added per engagement once the control overlap has been mapped.
Q_03Does this actually automate evidence collection?
Where the underlying systems support it, yes — and the automation rate is scorecard-driven, not vendor-promise-driven. Controls without automation potential get scheduled manual workflows with named owners. We are honest in the deliverable about which control is which.
Q_04Multi-entity support?
Yes. Consolidated executive view across entities with drill-down to the entity, framework, and control. Common in UAE group structures with multiple licensed operations reporting to one board.
Q_05What comes next?
C6 ComplianceOps™ UAE operates the platform continuously — evidence workflows, exception management, audit-pack preparation, and the executive reporting cadence. If you have an internal compliance function with capacity, B17 hands over to them with the operating model documented.
§ 11 · NAMED ACCOUNTABILITY

One name
on the engagement letter.

A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.

THE ROLE

Practice Lead — Cybersecurity

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 7 deliverables.

03
Bi-weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

Thirty minutes.
No slide deck.

A structured 30-minute scope conversation with the Practice Lead. You describe the frameworks in scope, the entity structure, and where evidence lives today. We describe whether B17 is the right engagement — and if not, what is.

Book a clinic →Email directly
DURATION
30 minutes
PREPARATION
None required
FOLLOW-UP
Written scope, 5 business days