governance, risk & compliance
Design and run GRC programmes aligned to organisational goals: policy, control frameworks, internal audit, external audit coordination, and compliance carried through its full renewal cycle.
Governance · Analytics · Commercial assessment · AI engineering
Technology governance, analytics, commercial assessment and AI platform engineering
Nineteen years in technology and telecom. I work where three questions meet: is this defensible to an auditor and a regulator, is it worth the capital, and can it actually be built and run? Most organisations answer those in three separate rooms. I answer them together.
2007Nineteen years, three chapters2026
Operations, systems analysis, technical resolutionTelecom · 2007–2018
Digital business consultingConsulting · 2018–2019
Products & projects control and planning2019 – present
The value I bring
Governance, risk and compliance designed so the answer survives inspection — by an auditor, a regulator, or a customer's security team.
A clear read on whether a product, platform or target earns its capital: value proposition, margin, cost to serve, and a recommendation with a number attached.
Workflow automation, approval engines, assessment tooling and AI platforms — engineered, not specified and outsourced.
Complexity compressed into something an executive can act on in one page, on a cycle that repeats without being rebuilt each time.
I am a technology governance and control professional based in Riyadh, with nineteen years across telecom operations, digital business consulting, and products and projects control. My work is about making sure that what an organisation builds is defensible, that what it funds is worth funding, and that the two conversations inform each other instead of running in parallel.
Two master's degrees frame how I think: one in cybersecurity, one in project management. That pairing is deliberate. Most failures in a technology portfolio are not purely technical or purely managerial — they sit in the seam between the two. Risk assessed but never designed against. A control agreed but never evidenced. A delivery plan that ignores what compliance will cost. I work that seam.
Three things set this apart from a governance role on its own. Commercial judgement — I can tell you what a product, platform or supplier is actually worth and where capital is better spent. Engineering — I build the systems rather than specify them and wait: automation, approval engines, assessment tooling, platforms with their own data model and interface. AI as an owned capability — designed, governed, deployed and operated, not bought as a demo and abandoned.
What that adds up to for an organisation: one person who can say whether the thing is defensible, whether it is worth the money, and then build the workflow that runs it.
Twelve areas of practice. They overlap by design — a governance decision usually becomes a process change, a dashboard, an automation and a cost line at the same time.
Design and run GRC programmes aligned to organisational goals: policy, control frameworks, internal audit, external audit coordination, and compliance carried through its full renewal cycle.
Build security requirements into products before launch. Run assessments and audits that surface real exposure. Master's-level grounding, backed by security management and ethical hacking certification.
Hold discipline on scope, budget and timeline. Run product onboarding and change management with genuine impact assessment and a defined approval path.
Assess product and portfolio value, define the value proposition, compare options on the same basis, and make investment recommendations backed by margin, cost to serve and risk.
Evaluate a target or supplier across commercial, technical, security and compliance dimensions — what is being bought, what liability comes with it, what integration will really cost.
Budget management, procurement optimisation and resource allocation, tied to a measured view of what delivery is actually costing and returning.
Full-stack AI systems: architecture, routing, retrieval over private knowledge, interface, monitoring and governance. Built and operated, not procured and hoped for.
Approval routing, evaluation workflows, action history and audit trail — designed as data models and shipped as working software.
Provisioning, configuration, hardening, access control, monitoring and uptime across virtualised Linux hosts and containerised services.
Turn scattered delivery and performance data into real-time visibility and executive reporting that leads to a decision rather than a discussion.
Process redesign, responsibility mapping and improvement programmes — turning recurring friction into something documented, owned and measured.
Continuity and disaster recovery plans developed and actually exercised, so the plan is tested before the day it is needed.
Interactive dashboards in Power BI, Tableau and MicroStrategy — with role-based access and row-level security, so each audience sees exactly the data it is entitled to and nothing more.
Python and R for trend analysis, forecasting, segmentation, anomaly detection and pattern discovery across large datasets — including customer experience and behaviour.
Not "uses AI." Builds with it, builds systems around it, and governs the result — architecture, routing, retrieval, interface, approval logic, monitoring, and the security and data-protection case that lets it near real work.
The problem, the users, the data it may touch, and what "done" looks like — settled before anything is built.
A build brief precise enough to hold: scope, phased delivery, acceptance criteria, and a specification the implementation cannot drift from.
Infrastructure, routing layer, knowledge base, data model and interface — iterated against the brief rather than against impressions.
Security review, data-protection assessment and a defined approval path before the system touches real work.
Monitoring, access control, uptime, cost and provider fallback. An unmonitored AI system is an unowned one.
Measure where it saves time and where it fails, revise, and fold the change back into the documented process.
Build · platforms
End-to-end systems, from bare virtual machine to a working interface someone can open.
Build · automation
The value is not the model. It is the process the model lets you redesign, and the manual step it lets you delete.
Build · approval & evaluation
Approval is where governance either works or quietly stops working. It should be designed as software, with a data model and an audit trail.
Build · security assessment
Assessment that runs on a schedule beats assessment that runs when someone remembers.
Govern · adoption in regulated environments
In a regulated organisation, an AI system is a control surface. Treating it like one is the difference between deployment and an indefinite pilot.
A dashboard is not a picture of the data. It is a decision surface — and it is only trustworthy if the numbers reconcile, the access is controlled, and someone can tell you why the line moved.
Build · business intelligence
Built in the platform the organisation already runs, not a tool nobody will maintain after I leave.
Govern · access & security
Reporting is where data exposure usually happens. Access is designed into the model, not bolted on at the report.
Engineer · large-scale data
Volume changes the method. What works on a spreadsheet stops working three orders of magnitude later.
Analyse · advanced methods
Where a dashboard shows what happened, this answers why, and what is likely next.
Apply · customer experience
Satisfaction scores tell you the temperature. The analysis has to tell you what to change.
A consulting discipline applied inside the operating business: what is this product, platform or target actually worth, what does it cost to run, what liability comes attached, and should capital go into it or somewhere else?
Every product in a portfolio is either earning its place or being carried. The job is to know which, with evidence.
What is being bought is rarely just the asset. It is also the exposure and the integration bill.
| Ref | Dimension | The question it answers |
|---|---|---|
| D-01 | strategic fit | Does this belong in the portfolio at all, or is it adjacent activity competing for the same capital? |
| D-02 | value proposition | What does the customer actually get, and why buy it here? |
| D-03 | revenue & margin | How does money arrive, how reliably, and what is left after cost? |
| D-04 | cost to serve | What does it consume in delivery, support, infrastructure and licensing? |
| D-05 | billing integrity | Does what is delivered match what is charged? |
| D-06 | compliance exposure | What regulatory and certification obligations does it create or inherit? |
| D-07 | security posture | What is the residual risk after controls, and who carries it? |
| D-08 | integration cost | What does it take to connect this to what already exists? |
| D-09 | delivery readiness | Can the organisation actually run it — people, process, tooling? |
| D-10 | continuity & exit | What happens if it fails, or if we need to leave? |
Same dimensions, same weighting, every candidate — which is what makes a comparison a comparison rather than an argument.
The case holds across all ten dimensions. Fund it, and name the metric it will be judged on.
Commercially sound, but one or more dimensions carry unresolved risk. Fund against explicit remediation gates.
The evidence is not there yet. Name what would have to be true, and what it costs to find out.
It is being carried. Stop, migrate, or hand it to someone whose portfolio it fits.
Independent platform work, built outside the day job. Product decisions, architecture, data model and go-live — the same discipline applied where I am the one carrying the risk.
An Arabic-language learning marketplace: instructor-led courses, downloadable digital files, and printed titles, with a trainer onboarding path so subject-matter experts can publish and teach.
A second platform under development. Not yet launched — details and a link will go here once it is ready to be seen.
Concrete outputs, not activity. Each one is something an organisation can use, defend or act on.
A control environment mapped to the standards that apply, with owners, evidence requirements and a renewal calendar — designed to be maintained, not rebuilt each audit cycle.
Preparation that treats the audit as predictable: evidence organised in advance, control gaps identified early, and a defined response and closure process.
A scored evaluation of a product, platform, supplier or target across ten dimensions, ending in one of four recommendations with the reasoning attached.
The commercial argument written so it survives challenge: what is proposed, what it returns, what it costs to serve, and what would make it wrong.
Process maps, responsibility boundaries and approval paths that reflect how work actually flows — then the automation that removes the manual steps.
Dashboards and reporting cycles that produce the same view every period without manual assembly, sized for a decision rather than a status meeting.
The security, data-protection and approval position an organisation needs before AI touches real work — plus the pilot that proves it in practice.
Working software: routing, evaluation workflows, audit trails and generated documents, built against a data model rather than bolted onto spreadsheets.
Plans that have been exercised, with the gaps the exercise revealed already closed.
Interactive dashboards on a governed metric layer with a role-based access model, documented so someone else can own them.
A question answered with evidence: trend, drivers, segments and a forecast with its confidence stated — plus what would change the conclusion.
Where experience degrades across the journey, what moves the score, and the ranked list of fixes worth funding first.
The mandates this background is built for — permanent, interim or advisory.
Own the control environment end to end: frameworks, internal audit, external audit, compliance programmes, and the reporting line into the executive.
Bring discipline to a portfolio that has outgrown its governance — scope, budget, timeline, change control, and reporting executives actually read.
Sit between product, security and compliance: onboarding standards, risk assessment, change management and the approval path that keeps launches moving.
Evaluate where technology capital goes: product value, build-versus-buy, supplier selection, and diligence on targets.
Get AI from pilot to production in a regulated organisation — the security and data-protection case, the approval path, and the first systems that clear it.
Diagnose, model and redesign: operating model, process, controls and reporting, delivered as something implemented rather than recommended.
Translate strategy into measures, keep the reporting honest, and give a technology leader one place where delivery, cost and compliance are reconciled.
Own the reporting estate: platform choice, the metric layer, access model, and the shift from descriptive dashboards to analysis that anticipates.
Defined-scope work: a compliance readiness review, an investment assessment, an AI adoption framework, or an automation build.
Categories of system I work in and across. Fluency here is what makes an assessment specific instead of theoretical.
Operations, then consulting, then control. Each move traded breadth of hands-on work for depth of accountability — without giving up the hands-on part.
2019 — PresentRiyadh
Technology division, enterprise solutions provider
Accountable for governance, risk and compliance across project and product control, alongside strategic alignment, operational efficiency, and the financial and delivery performance of what the division ships.
2018 — 2019Riyadh
Consulting practice
Consulted on digital business transformation: client delivery, project management, commercial modelling and operational improvement, with governance system implementation running alongside.
2007 — 2018Kingdom-wide
National telecom operator
Eleven years across operations and technical support, building the network fluency and operational scale the later governance and assessment work rests on.
Midocean University · 2024
Arab Open University, Riyadh
Native
Professional
Get in touch
Roles, advisory work, or a defined-scope assessment. Tell me what you are trying to decide and I will tell you whether I am the right person for it.