The Governance Operating System for Audit Firms

ISQM 1. AML. PDPL. NCA ECC. Independence. Performance. One platform. Built for the GCC. Live in 8 weeks.

firm360.ai

Governance Operating System

100%

ISQM 1 Obligation

Every SOCPA firm must comply now

SAR 5M

PDPL Fine Exposure

Enforceable since September 2024

8 wks

To Full Deployment

Not 18 months. Live.

ISQM 1 · AML · PDPL · NCA ECC · Independence · CPD · Performance

Arabic & English · Live in 8 weeks · Powered by Falconry Solutions

SOCPA peer review inspections active

PDPL fully enforceable — SAR 5M exposure

✦ 3 of the Big 10 KSA audit firms live on firm360.ai

NCA ECC controls now mandatory

3+

of the Big 10 KSA audit firms

Already live on firm360.ai — with additional leading firms in advanced commercial discussions and local KSA practices on the Essentials tier.

  • International network affiliates
  • Mid-tier KSA practices
  • GCC expansion underway

Live in production today

Three forces converging — all at once

The challenges keeping partners awake at night

Audit firms in the GCC are navigating three simultaneous regulatory obligations
most still managing them with disconnected spreadsheets.

100%

ISQM 1 Compliance

SOCPA Inspections Active

Every SOCPA-registered firm must maintain a documented System of Quality Management. Manual processes expose firms to inspection findings, remediation orders, and licence risk.

SAR 5M

PDPL Fine Exposure

Data Privacy is Enforceable

Saudi Arabia's PDPL has been fully enforceable since September 2024. No grace period remains. Audit firms handling client personal data are directly and materially in scope.

40%

Partner Time Lost

Operational Blind Spots

Siloed timesheets, engagement tracking, and KPI monitoring create blind spots for leadership — eroding profitability and frustrating partners with duplicated manual effort.

The unified governance platform

Three pillars. One connected system. No blind spots.

Not a generic GRC tool adapted for auditors — every module built around the workflows, obligations, and regulatory environment of audit firms in the GCC. In Arabic and English.

ISQM 1 Quality Management (SoQM)

Automated SoQM annual evaluation, cold file review, root cause analysis, and ISQM 2 EQR — inspection-ready at any time.

Independence Monitoring

Continuous independence tracking across the firm's portfolio — financial interests and relationships flagged automatically.

CPD & Learning Compliance

CPD tracking against SOCPA, ICAEW, and ACCA requirements. Automated deficit alerts ensure your team stays compliant.

Client Acceptance & Continuance

Risk-scored onboarding with AML screening, UBO verification, independence checks, and automated annual continuance review.

AML & Regulatory Compliance

Real-time AML screening, OFAC/UN/SAMA sanctions checks, regulatory breach detection, and automated reporting.

Regulatory Change Monitoring

Real-time monitoring across SOCPA, CMA, NCA, SAMA, and SDAIA — alerts and impact assessments surfaced automatically.

Enterprise Risk Management

Firm-wide risk register with owner assignment, scoring, mitigation tracking, and heat maps — full partner visibility.

PDPL Data Privacy Compliance

Full PDPL compliance: data mapping, RoPA, 72-hour breach notification, DPIAs, and cross-border transfer controls.

Incident Response Management

Structured incident lifecycle from detection through remediation — with 72-hour PDPL breach notification built in.

NCA ECC Cybersecurity Governance

All 65 NCA ECC 2025 controls mapped, evidenced, and monitored. SAMA Cybersecurity Framework aligned.

Third-Party Risk Management

Supplier and vendor risk assessments, contract monitoring, and automated due diligence workflows.

AI Governance (SDAIA)

Policy framework and risk controls for AI tool usage within the firm — aligned to SDAIA guidelines.

Time & Timesheet Management

Automated time capture, approval workflows, and analytics revealing where firm capacity is spent and lost.

Engagement Monitoring & WIP

Live engagement progress, budget vs. actual tracking, and partner-level dashboards. WIP monitoring prevents leakage.

Leadership Dashboards & KPIs

Managing partner dashboards — governance health, compliance status, engagement profitability, and team performance.

Staff Performance Management

Annual objectives, per-engagement feedback, mid-year check-in, and year-end calibrated review — ISQM 1 aligned.

Resource Utilisation

Firm-wide resource planning, capacity mapping, and utilisation metrics to optimise staff deployment.

Saudization & Workforce Compliance

Nitaqat tier tracking, Saudization ratio monitoring, and workforce compliance dashboards for Vision 2030.

The regulatory clock is running

Why the time to act is now

Four forces have converged simultaneously. Firms that delay face inspection findings, regulatory fines, and reputational damage that cannot be undone.

ISQM 1 Annual Evaluation — Active

SOCPA peer review inspections are running. Firms without documented SoQM evidence face findings and licence risk. Every month of delay increases exposure.

NCA Cybersecurity Controls — 2025

New NCA ECC mandatory controls for all private sector entities in 2025. Audit firms handling client financial data are directly in scope across all 65 controls.

PDPL Fully Enforceable — No Grace Period

Fines up to SAR 5 million apply. Every audit firm handling client personal data is directly in scope — no exceptions.

Profitability Under Structural Pressure

Rising regulatory burden, talent costs, and manual governance are shrinking partner income. Firms that automate will outperform those that remain reactive.

The business case

What partners gain from day one

Measurable outcomes from the first sprint — not after a 12-month implementation.

60%

Faster Compliance

Reduction in time spent on compliance documentation and evidence gathering — freeing partners for high-value advisory work.

Zero

Governance Blind Spots

All risks visible on a single platform — no spreadsheets, no missed obligations, no last-minute inspection scrambles.

Real-time

Revenue Protection

Engagement profitability and WIP monitoring prevents revenue leakage at the partner level — before it becomes a write-off.

24/7

Partner Confidence

Leadership dashboards giving complete oversight — governance health, team performance, and engagement status from any device.

10×

AI-Powered Automation

Faster workflow completion with intelligent automation — ISQM 1 evidence generated, CPD tracked, AML screened automatically.

Always

Inspection Ready

Audit-ready ISQM 1 governance documentation available at the touch of a button — whenever SOCPA calls.

Regulatory intelligence

Built for every obligation your firm faces

Pre-configured for KSA and GCC regulatory requirements. Global frameworks for internationally active firms.

ISQM 1 & 2
IAASB quality standards
SOCPA
Peer review readiness
PDPL
Saudi data privacy law
NCA ECC
Cybersecurity controls 2025
CMA
Listed entity audit reqs
SAMA CSF
Cybersecurity framework
ZATCA
Tax compliance integration
AML / KYC
FATF / SAMA / MENAFATF
SDAIA
AI governance guidelines
ICAEW
UK / international CPD
ACCA
Global CPD standards
GCCAAO
GCC accounting standards
Regulatory intelligence

Live in 8 weeks — not 18 months

Pre-configured for KSA and GCC regulatory requirements. Global frameworks for internationally active firms.

Phase 01

Discovery & Design

Weeks 1–2

Phase 02

Configure & Integrate

Weeks 3–5

Phase 03

Pilot & Train

Weeks 6–7

Phase 04

Go Live & Optimise

Week 8+

Why firm360.ai & Falconry Solutions

Purpose-built.
Proven in the region.

Not a generic GRC tool adapted for auditors — every module built around the specific workflows, standards, and obligations of audit firms in the GCC.

Purpose-Built for Audit Firms

Every module designed around the specific workflows, standards, and obligations of accounting and audit firms — not adapted from a corporate GRC tool.

Arabic & English Throughout

Native bilingual platform with SOCPA-translated ISQM 1 framework built in. No localisation workarounds — Arabic interface, Arabic regulatory language.

AI-Enhanced, Not AI-Dependent

AI accelerates workflows and surfaces insights — but partners remain in control. Every decision has a human in the loop, with full audit trails.

GCC Regulatory Intelligence

Every module designed around the specific workflows, standards, and obligations of accounting and audit firms — not adapted from a corporate GRC tool.

Falconry Solutions — 10+ Years GCC

Falconry Solutions has delivered governance, cybersecurity, and GRC programmes across Saudi Arabia, UAE, Qatar, and Oman for leading enterprises.

Secure Cloud, Data Sovereignty

Hosted on secure cloud infrastructure with data residency options aligned to KSA requirements. ISO 27001-aligned security practices throughout.

Join the leading KSA firms on firm360.ai

3 of the Big 10 audit firms in Saudi Arabia have already made this decision. Same journey — three simple steps to get started.

Three steps to get started

Book a personalised demonstration

Live demo tailored to your firm's ISQM 1 obligations, regulatory exposure, and operational priorities.

Free firm readiness assessment

Structured review of your ISQM 1 maturity, cyber posture, and compliance gaps — at no cost.

Receive your tailored roadmap

Bespoke implementation plan and commercial proposal. Live in 8 weeks.