Field notes from the practice — written to be used, not filed.
Whitepapers, templates, toolkits, case studies, webinars and podcasts from the faculty and operating teams who actually run the work — across GRC, cybersecurity, data privacy, AI governance and ESG.
- Published resources
- 180+
- Downloads this year
- 42k
- Practice domains
- 6
- Faculty contributors
- 24
Three pieces the faculty keep sending clients.
Implementing ISO/IEC 42001: a 90-day operating model
A staged plan to stand up an AI Management System: scoping, risk register, control mapping to ISO 27001/27701, and the first three internal audit cycles.
GRC Operating Model — RACI, KPIs and committee charters
Editable charters, decision rights, KPI library and board reporting templates used by MAST faculty on live GRC build-outs.
State of GRC in the GCC — 2026 benchmark
Survey of 312 GRC, security and privacy leaders across the GCC: maturity scores, hiring gaps, tool spend and the controls that drove the biggest audit improvements.
Full kits, sequenced for the way the work actually gets done.
Each collection is a working sequence — templates, guides and evaluation gates in the order the faculty deploys them on real programmes. Download the pack or work through it piece by piece.
ISO 27001 launch kit
Everything to move an ISMS from kickoff to Stage 1: scoping guide, SoA template, risk methodology, internal audit programme and evidence taxonomy.
ISO 42001 launch kit
AIMS scoping, model inventory, evaluation gates, incident response and the mapping to ISO 27001/27701 — the whole stack in one collection.
MENA privacy playbook
UAE PDPL, KSA PDPL and GDPR mapped to a single operating model — with DPIAs, transfer assessments and DPO appointment letters.
Six practice areas. One shared standard of craft.
Faculty on the record. Live, small, and always recorded.
AI evaluations that actually catch harm
16:00 GST · 60 min · with Dr. Nadia Al-Hashimi
Board reporting for CISOs — from heatmaps to decisions
17:00 GST · 45 min · with Rahul Menon & Sara Vanhoof
ESG assurance readiness — the auditor's view
15:00 GST · 60 min · with Karim Osman
Everything, filterable.
Sort by format or topic, search across titles, summaries and authors. New items land at the top.
A staged plan to stand up an AI Management System: scoping, risk register, control mapping to ISO 27001/27701, and the first three internal audit cycles.
By Dr. Nadia Al-Hashimi
Editable charters, decision rights, KPI library and board reporting templates used by MAST faculty on live GRC build-outs.
By Rahul Menon
Survey of 312 GRC, security and privacy leaders across the GCC: maturity scores, hiring gaps, tool spend and the controls that drove the biggest audit improvements.
By MAST Research
Pre-mapped SoA covering all 93 Annex A controls with justification language, owner fields and evidence pointers ready for Stage 1.
By Sara Vanhoof
From a failed surveillance audit to a clean recertification in 11 months — what the security team changed in governance, evidence and training.
By Rahul Menon
Updated for the 2026 executive regulations: lawful basis, cross-border transfer assessments, DPO appointment and breach notification timelines.
By Layla Ibrahim
Where most AI policies fail in practice and the seven control patterns (model inventory, evals, human-in-the-loop, incident response) that actually hold up under audit.
By Dr. Nadia Al-Hashimi
Recorded session with three Lead Auditors on sampling strategy, evidence quality and how to write findings management will actually close.
By MAST Faculty Panel
How CISOs in regulated industries are reframing security reporting to boards — moving from heatmaps to decision-grade risk narratives.
By The MAST Briefing
Common evidence mistakes — screenshots without context, policies without ownership, tickets without closure — and the fixes that prevent nonconformities.
By Sara Vanhoof
Three-tier vendor questionnaire, scoring rubric, evidence request list and a board-ready third-party risk dashboard.
By Rahul Menon
How a public-sector health platform embedded DPIAs, consent and data minimisation into product delivery without slowing release cadence.
By Layla Ibrahim
Reasonable vs. limited assurance, ISSB alignment, Scope 3 evidence, and how listed issuers in ADX, DFM and Tadawul are preparing sustainability disclosures.
By MAST Research
BIA workbook, RTO/RPO matrix, incident playbooks and a tabletop exercise script — everything to run a credible first BCMS cycle.
By Karim Osman
Control-by-control checklist for CC-series criteria with owner, evidence type and the common ways auditors reject weak artefacts.
By Sara Vanhoof
Move beyond likelihood × impact heatmaps. A repeatable pattern for decision-grade risk narratives that name the exposure, the owner and the required call.
By Rahul Menon
Side-by-side mapping of lawful bases, DSR timelines, transfer mechanisms and breach thresholds across three regimes, with a single unified control set.
By Layla Ibrahim
Model inventory, intended use, data lineage, evaluation cadence and residual risk scoring — pre-wired for AIMS internal audits.
By Dr. Nadia Al-Hashimi
A career-path conversation with three alumni who moved from GRC analyst roles into Lead Implementer positions across banking, health and government.
By MAST Alumni Panel
Inside the first ISO 42001 certification programme at a Tier-1 telecom operator: governance, model inventory, evaluation gates and the audit surprises.
By Dr. Nadia Al-Hashimi
Vendor risk teams are being asked to assess AI subprocessors they cannot see. What good looks like — contracts, evidence and continuous monitoring.
By The MAST Briefing
A one-page screening tool product managers can run in ten minutes to decide whether a full DPIA is required — and what evidence to gather either way.
By Layla Ibrahim
Control catalogues drift because ownership drifts. Three lightweight practices that keep a control library trusted long after the initial cert audit.
By Rahul Menon
Compensation bands, role scarcity, retention drivers and the certifications that moved the needle for hiring managers across banking, energy and government.
By MAST Research
Long-form conversations with the people running the world's compliance programmes.
New episodes every other Wednesday. CISOs, DPOs, Lead Auditors and heads of risk on what they've stopped doing, what they've started, and why.
One email a month. New frameworks, audit notes, and what we're seeing in the field.
Trusted by 8,400+ GRC, security and privacy leaders. No sponsored posts. Unsubscribe in one click.
We honour GDPR, UAE PDPL and KSA PDPL. Your address is only used for the Briefing.
Ran an interesting programme? We publish practitioner case studies quarterly.
Bring the story — we handle the edit, the visuals and the review. Your team keeps the byline.
