CyberArrow GRC
Cloud GRC platform that automates control monitoring, evidence collection, policy management, risk registers and audit workflows across multiple frameworks simultaneously, with real-time dashboards for executives and regulators.
CyberArrow is a governance, risk and compliance (GRC) automation company headquartered in Dubai, with offices in Riyadh, London, Dublin, Madrid and San Jose. Co-founded by chief executive Amar Basic, it is known for putting compliance on autopilot: continuously monitoring controls, collecting audit evidence through more than 80 integrations and mapping more than 3,000 pre-built risks and mitigations across 100-plus frameworks, for customers that include IKEA, Emirates and Revolut.
CyberArrow is a governance, risk and compliance (GRC) automation company headquartered in Dubai, with offices in Riyadh, London, Dublin, Madrid and San Jose. Co-founded by chief executive Amar Basic, it is known for putting compliance on autopilot: continuously monitoring controls, collecting audit evidence through more than 80 integrations and mapping more than 3,000 pre-built risks and mitigations across 100-plus frameworks, for customers that include IKEA, Emirates and Revolut.
Its products, CyberArrow GRC, CyberArrow Awareness and CyberArrow Phishing, are built around the regulations that matter in the Gulf, including NCA ECC, NCA NCNICC-1:2025, SAMA CSF and the Saudi PDPL, alongside ISO 27001, ISO 42001, SOC 2, NIS2, DORA and NIST. Government entities, banks, healthcare providers and technology firms in Saudi Arabia and the wider Middle East use it to replace spreadsheets with a single, audit-ready system.
Cloud GRC platform that automates control monitoring, evidence collection, policy management, risk registers and audit workflows across multiple frameworks simultaneously, with real-time dashboards for executives and regulators.
Pre-mapped content for NCA ECC, NCA NCNICC-1:2025, SAMA CSF and the Saudi PDPL, so Gulf organisations can evidence compliance with local mandates alongside ISO 27001, SOC 2 and other global standards.
Enterprise and IT risk registers with automated assessments, treatment plans, cyber-security KPI monitoring and asset-inventory integrations that keep an organisation's risk posture current between formal audits.
Structured AI risk assessments, ISO/IEC 42001 and NIST AI RMF control sets and continuous monitoring that let organisations govern their own AI systems and document accountability for regulators.
Security awareness training with short, story-driven content and phishing simulation, connected to the GRC platform so training completion and human-risk metrics feed directly into compliance reporting.
CyberArrow describes its platform as AI-powered GRC: algorithms automate risk assessments, map controls across frameworks and collect evidence through integrations, which the company says removes up to 90 percent of the manual work in compliance programmes. It is also an active voice on agentic GRC, in which AI agents continuously monitor controls and initiate governance actions within defined boundaries.
In 2026 the platform added ISO/IEC 42001 and NCA NCNICC-1:2025 support, an AI risk register and audit-trail history for controls, and in September 2026 CyberArrow partnered with KPMG to combine advisory services with its enterprise AI GRC platform. This gives Middle East organisations a practical route to operationalise AI governance across policies, risks, controls and evidence.
Where CyberArrow fits in the four-layer AI stack we bring to partners.
Explore the layerCyberArrow and KPMG combined advisory expertise with CyberArrow's enterprise AI GRC platform to help organisations operationalise AI governance through centralised policy management, AI risk registers, automated workflows, continuous compliance monitoring and audit readiness.
A platform update added ISO/IEC 42001 for AI management systems and Saudi Arabia's NCA NCNICC-1:2025 national cybersecurity controls, plus a History tab that gives a complete audit trail of control changes, evidence updates and approvals.
In a company update published during GITEX Global 2025, CyberArrow described its expansion from Dubai to customers on multiple continents, with multi-framework automation across ISO, SOC, NIST and SOX for finance, government, healthcare and technology clients.
Architecture, sizing and proof-of-concept support so partners propose the right configuration first time.
02Certification paths, workshops and demo access that build partner capability around the portfolio.
03Local stock, professional services, escalation and RMA handling across Saudi Arabia and the region.
Speak with our team about availability, solution design and partner enablement.