Cybersecurity Compliance Sentinel
The AI-native compliance platform for the SAMA Cybersecurity Framework.
Sentinel turns the SAMA CSF assessment from a months-long spreadsheet exercise into a guided, AI-assisted workflow. Licensed entities self-assess, evidence is reviewed by AI, and SAMA decides, all in one supervised workspace.


Six capabilities. One platform
Built specifically for the SAMA Cybersecurity Framework, from first self-assessment to SAMA's final decision.
Structured Self-Assessment
Score every applicable subdomain against SAMA's 0–5 maturity model, with the principle, objective, and control considerations on screen. Subdomains below target are flagged automatically as gaps.
AI Co-Reviewer
The AI reads your uploaded evidence against each control, suggests a maturity level with rationale, and flags missing or weak evidence with a confidence score. SAMA makes the final call, always.
Evidence Management
Upload, version, and tag evidence files to specific controls. Encrypted at rest, scanned on upload, retained for the full audit cycle. Every claim is backed by traceable documentation.
Multi-Role Workflow
Contributors prepare. CISOs approve and submit. SAMA reviews and decides. One platform, three roles, one chain of custody, with rejected items routed back automatically.
Real-Time Dashboards
Track maturity, completion, gaps, and roadmap progress across all four domains, at entity, sector, and SAMA-reviewer level. Anonymised peer benchmarking included.
Instant Reporting
Export full assessment reports, roadmaps, and audit trails to PDF or Excel in one click, ready for internal review, board reporting, or regulatory submission.
One workspace, from first score to final decision
A live picture of maturity, completion, gaps, and AI review confidence across all four SAMA CSF domains.
- 01
Self-assess
The licensed entity scores every applicable subdomain against the 0–5 maturity model, with completion and gaps in view.
Sentinel · Assessment Workspace2026 CycleOverall Maturity3.2 / 5Target level 3 across domainsCompletion78%25 of 32 subdomains scoredGaps Found7below target maturityDomain Maturity% of target3.1 · Leadership & Governance88%3.2 · Risk Management & Compliance72%3.3 · Operations & Technology60%3.4 · Third-Party Cyber Security91%AI ReviewAssesses evidence against every control and flags weak or missing documentation.86%DraftPending CISOSubmitted to SAMA - 02
AI reviews the evidence
Uploaded evidence is read against each control; the AI suggests a level with its rationale and a confidence rating, and the CISO accepts or adjusts.
Sentinel · Evidence ReviewAI-assisted3.2 · Risk Management & CompliancePDFRisk_Management_Policy_v3.pdfscanned ✓AI suggestion82%Suggested maturity: Level 3Policy documents the risk framework and review cadence. Board sign-off is still to be evidenced, which caps the level.
Accept (CISO)AdjustThe CISO approves; SAMA makes the final call.
- 03
SAMA decides, gaps become a roadmap
Each flagged gap becomes a prioritised remediation item, and SAMA makes the final call.
Sentinel · Remediation Roadmap7 gaps33.3 · Operations & Technologytarget L3High23.2 · Risk Managementtarget L3Medium13.1 · Leadership & Governancetarget L3Low13.4 · Third-Party Cybertarget L4LowEach flagged gap becomes a prioritised remediation item.

Purpose-built for Saudi financial institutions regulated by SAMA
Professional, institutional teams operating in a high-stakes regulatory environment, where accuracy and audit trail matter more than speed.
Commercial Banks
Retail and corporate banks meeting their SAMA CSF obligations.
Insurance Companies
Insurers and reinsurers under SAMA supervision.
Finance Companies
Financing and lending institutions licensed by SAMA.
Financial Market Infrastructure
Exchanges, clearing and settlement, and payment systems.