IT Governance & Digital Transformation Advisory

Governance that earns trust, passes audits, and delivers lasting results.

I work with government and regulated organizations to turn complex governance and digital requirements into practical operating models that strengthen accountability, compliance, resilience, and performance.

Standards & Frameworks
ISO/IEC 20000ISO 22301ISO/IEC 42001ISO/IEC 38500COBITITILTOGAF
15+Years experience
20+Transformation programs
100%Certification success
End-to-EndAssessment to implementation
Why clients choose me

The difference is proof, not promises.

Plenty of advisors can design a framework. Far fewer stay through implementation, operationalization, and independent validation. My work is built around outcomes, not documents.

01

End-to-end ownership

From strategy to operation.

I stay from assessment and design through implementation, operationalization, and assurance. Not just delivery of the framework.

02

Proven outcomes

Results that stand up to scrutiny.

Experience supporting organizations through certification, regulatory assessment, audit, and governance maturity improvement.

03

Government & regulated sectors

Built for complex environments.

Hands-on experience across government, healthcare, aviation, financial services, and other regulated environments.

04

Governance that operates

Designed to work, not sit on a shelf.

Governance is translated into clear decision rights, ownership, processes, controls, measures, and ways of working.

05

Integrated expertise

One view across governance and operations.

Governance, service management, risk, resilience, quality, digital transformation, and emerging technology brought together as one operating system.

Services

Helping organizations govern, transform, and build resilient digital capabilities.

From focused advisory to enterprise transformation, each engagement is designed to turn governance requirements into practical, measurable, and sustainable outcomes.

01

IT & Digital Governance

COBIT · ISO/IEC 38500

Design governance frameworks and operating models that drive accountability, quality, and performance.

  • Governance frameworks & operating model
  • Policies, standards & decision rights
  • Governance committees & reporting
  • Quality & performance management
  • Governance maturity assessments
02

Digital Transformation & Strategy

Strategy · Operating Models

Align strategy, governance, and capabilities to deliver sustainable digital transformation.

  • Transformation strategy & roadmap
  • Target operating model & value realization
  • Capability & maturity assessment
  • Business case & portfolio prioritization
  • Vision 2030 & digital alignment
03

AI Governance & Responsible AI

ISO/IEC 42001 · SDAIA

Build trusted AI with secure, auditable, and certification-ready governance.

  • AI governance framework & policy
  • AI risk & impact assessments
  • Data governance & model governance
  • Controls, monitoring & assurance
  • ISO/IEC 42001 readiness & implementation
See the full AI governance approach →
04

IT Service Management & Operations

ITIL 4 · ISO/IEC 20000 · ServiceNow

Deliver reliable services that improve experience, meet SLAs, and achieve audit readiness.

  • ITSM strategy & process design
  • ISO/IEC 20000 readiness & certification
  • Service catalog, SLAs & OLAs
  • ServiceNow advisory & implementation
  • Reporting, KPIs & continual improvement
05

Governance, Risk & Compliance

GRC · Risk · Compliance

Integrate governance, risk, and compliance to strengthen decisions and regulatory confidence.

  • GRC framework & operating model
  • Risk management & internal controls
  • Compliance assessments & monitoring
  • Regulatory readiness (NCA, DGA, Qiyas)
  • Risk registers & governance dashboards
06

Business Continuity & Resilience

ISO 22301 · Resilience

Build organizational resilience and ensure critical services remain available in any disruption.

  • BCM strategy & operating model
  • Business Impact Analysis
  • Risk assessment & scenario planning
  • Crisis & emergency management
  • Testing, training & continual improvement
Selected results

Real work. Real results.

A selection of outcomes delivered across governance, service management, resilience, and digital transformation.

01Governance

From fragmented practices to an operating governance model.

Governance structure, decision rights, controls and performance embedded into day-to-day operations across the organization.

GovernanceQiyasOperating Model
02Resilience

From continuity requirements to an integrated resilience capability.

BCM, risk and emergency management brought together into one practical operating model aligned with national standards.

BCMRisk ManagementResilience
03Service Management

From IT services to a structured, measurable service model.

End-to-end ITSM designed and operationalized with ServiceNow, service governance and quality controls.

ITSMServiceNowISO/IEC 20000
04Certification

From readiness gaps to successful ISO certification.

Assessment, remediation and implementation carried through to independent certification and audit success.

AssessmentImplementationAssurance
The governance ecosystem

From strategy to sustainable operations

An integrated governance model that aligns strategy, enables execution, assures performance, and drives continuous improvement.

Digital Strategy

Sets direction and aligns digital priorities with organizational goals and expected value.

Direction
Define where we are going
Objectives
Set what we aim to achieve
Priorities
Focus on what matters most
Value
Define the outcomes that matter

Governance

Provides decision-making and oversight to keep digital initiatives aligned, accountable, and controlled.

Evaluate
Assess needs, options, and risks
Direct
Set direction and decision rights
Monitor
Oversee performance and compliance

Delivery & Enablement

Turns strategic direction into the capabilities required to deliver and operate digital services.

People
Build capability and accountability
Process
Establish effective ways of working
Technology
Enable scalable digital capabilities
Services
Deliver and operate reliable services

Assurance

Provides confidence that performance, risks, obligations, and resilience are effectively managed.

Risk
Identify and manage uncertainty
Compliance
Meet regulatory obligations
Resilience
Protect continuity of critical services
Quality & Performance
Measure and improve outcomes
Continuous Improvement
Assure Learn Adapt Improve
The Outcomes
Create Value
Deliver meaningful outcomes
Manage Risk
Reduce uncertainty and exposure
Ensure Compliance
Meet regulatory obligations
Drive Performance
Improve effectiveness and efficiency
Build Resilience
Strengthen continuity and adaptability
Building trusted AI systems

From AI adoption to trusted AI.

Govern AI with the accountability, controls, and assurance needed to scale responsibly.

What organizations gain

Govern with clarity

Establish ownership, decision rights, policies, and oversight.

Stay compliant

Align AI governance with ISO/IEC 42001, SDAIA requirements, and internal obligations.

Manage AI risk

Identify and control risks across models, data, use cases, and the AI lifecycle.

Build trust & assurance

Create monitoring, evidence, and accountability that make AI auditable and sustainable.

Engagement process

What happens after you get in touch.

A clear path from first conversation to a governance system that works in practice, implemented, operational, and certification-ready where required.

1

Discovery Call

A short conversation to understand your mandate, regulators, and goals.

2

Assessment

A clear-eyed look at where you stand against the standard or regulation.

3

Proposal

A scoped plan with deliverables, timeline, and outcomes — no surprises.

4

Implementation

We build and embed it with your teams, generating evidence as we go.

5

Assurance / Certification

Internal audit, remediation, and a system ready to pass the real thing.

Insights & research

The thinking behind the practice.

Peer-reviewed research and thought leadership on IT governance, AI governance, and digital transformation in the Middle East.

2026
From Principles to Practice: How ISO 42001 Helps Saudi Organizations Meet SDAIA's Responsible-AI ExpectationsThought-leadership article — in progress
Article
2026
Using AI to Strengthen IT Governance in Saudi ArabiaThrough COBIT 2019 & ISO/IEC 38500 · European Scientific Journal
Peer-reviewed
2025
IT Service Management to Accelerate Digital Government TransformationAligned to Vision 2030 · European Scientific Journal
Peer-reviewed
2024
Cloud Computing Adoption for SMEs in the Middle EastEuropean Scientific Journal
Peer-reviewed
Speaking & workshops

Training that leaves teams able to run it.

In-person in Riyadh or remotely across the GCC.

Training & Capability Building

Accredited and tailored programs designed to build practical organizational capability.

ITIL 4 (Foundation → Specialist)COBIT 2019ISO 20000 / 22301 readinessExecutive & team workshopsGovernance & BCM
Speaking & Executive Sessions

Keynotes, leadership briefings, and focused sessions on governance, digital transformation, AI governance, and resilience.

AI governance & ISO 42001IT governance (Qiyas / DGA)Digital transformationBCM & resilienceITSM
About

Fifteen years turning governance from a document into how an organization actually runs.

I started my career in engineering and built hands-on experience across IT operations, service delivery, and transformation. Over time, that experience shaped my path into governance, connecting strategy with the structures, decisions, and ways of working that make organizations run better.

Today, I bring those perspectives together to design and operationalize governance, service management, and resilience systems that work in practice. My approach is practical and people-centered, turning standards into everyday ways of working and helping organizations build lasting capability.

I believe good governance should enable an organization, not slow it down. The goal is always to leave behind something that teams can own, operate, and continuously improve long after the engagement ends.

Credentials

Certifications that back the work.

ISO/IEC 42001 – Lead Implementer (AI Management)
ISO/IEC 38500 – Lead IT Corporate Governance
ISO/IEC 20000 – Lead Implementer
ISO/IEC 22301 – Lead Implementer
ITIL 4 Master
ITIL 5 Bridge
ITIL 4 Practice Manager
ITIL 4 Specialist (5 modules)
COBIT 2019 Foundation
TOGAF – Enterprise Architecture
PMP – Project Management Professional
PRINCE2 Agile – Foundation & Practitioner
Get in touch

Have a governance challenge worth solving?

Tell me about your organization's situation and I'll come back with how I'd approach it.

Book a 30-minute call