The MAST Library

Field notes from the practice — written to be used, not filed.

Whitepapers, templates, toolkits, case studies, webinars and podcasts from the faculty and operating teams who actually run the work — across GRC, cybersecurity, data privacy, AI governance and ESG.

Published resources
180+
Downloads this year
42k
Practice domains
6
Faculty contributors
24
Featured this quarter

Three pieces the faculty keep sending clients.

Browse by topic

Six practice areas. One shared standard of craft.

Upcoming live sessions

Faculty on the record. Live, small, and always recorded.

See all webinars
22 Jul 2026

AI evaluations that actually catch harm

16:00 GST · 60 min · with Dr. Nadia Al-Hashimi

312 registered
05 Aug 2026

Board reporting for CISOs — from heatmaps to decisions

17:00 GST · 45 min · with Rahul Menon & Sara Vanhoof

204 registered
19 Aug 2026

ESG assurance readiness — the auditor's view

15:00 GST · 60 min · with Karim Osman

148 registered
The full library

Everything, filterable.

Sort by format or topic, search across titles, summaries and authors. New items land at the top.

Format
Topic
Showing 24 of 24 resources
WhitepaperAI Governance
Implementing ISO/IEC 42001: a 90-day operating model
New

A staged plan to stand up an AI Management System: scoping, risk register, control mapping to ISO 27001/27701, and the first three internal audit cycles.

By Dr. Nadia Al-Hashimi

Jun 2026 22 min readOpen
ToolkitGRC
GRC Operating Model — RACI, KPIs and committee charters
New

Editable charters, decision rights, KPI library and board reporting templates used by MAST faculty on live GRC build-outs.

By Rahul Menon

Jun 2026 Toolkit · 14 filesOpen
ReportIndustry Research
State of GRC in the GCC — 2026 benchmark

Survey of 312 GRC, security and privacy leaders across the GCC: maturity scores, hiring gaps, tool spend and the controls that drove the biggest audit improvements.

By MAST Research

May 2026 48 pagesOpen
TemplateCybersecurity
Statement of Applicability — ISO 27001:2022

Pre-mapped SoA covering all 93 Annex A controls with justification language, owner fields and evidence pointers ready for Stage 1.

By Sara Vanhoof

May 2026 Template · DOCX + XLSXOpen
Case StudyCybersecurity
How a regional bank rebuilt its ISMS in two cohorts

From a failed surveillance audit to a clean recertification in 11 months — what the security team changed in governance, evidence and training.

By Rahul Menon

May 2026 9 min readOpen
ChecklistData Privacy
UAE PDPL readiness checklist (v3)

Updated for the 2026 executive regulations: lawful basis, cross-border transfer assessments, DPO appointment and breach notification timelines.

By Layla Ibrahim

Apr 2026 Checklist · 64 itemsOpen
WhitepaperAI Governance
AI governance: from policy to operating control

Where most AI policies fail in practice and the seven control patterns (model inventory, evals, human-in-the-loop, incident response) that actually hold up under audit.

By Dr. Nadia Al-Hashimi

Apr 2026 18 min readOpen
WebinarAudit
Internal audit programmes that actually find issues

Recorded session with three Lead Auditors on sampling strategy, evidence quality and how to write findings management will actually close.

By MAST Faculty Panel

Mar 2026 Webinar · 52 minOpen
PodcastLeadership
The CISO's seat at the audit committee

How CISOs in regulated industries are reframing security reporting to boards — moving from heatmaps to decision-grade risk narratives.

By The MAST Briefing

Mar 2026 Podcast · 38 minOpen
BlogAudit
What a Lead Auditor wants to see in your evidence

Common evidence mistakes — screenshots without context, policies without ownership, tickets without closure — and the fixes that prevent nonconformities.

By Sara Vanhoof

Feb 2026 7 min readOpen
TemplateGRC
Vendor risk assessment pack — tiered by criticality

Three-tier vendor questionnaire, scoring rubric, evidence request list and a board-ready third-party risk dashboard.

By Rahul Menon

Feb 2026 Template · 6 filesOpen
Case StudyData Privacy
Privacy-by-design in a national health programme

How a public-sector health platform embedded DPIAs, consent and data minimisation into product delivery without slowing release cadence.

By Layla Ibrahim

Jan 2026 11 min readOpen
ReportESG
ESG assurance in the Middle East — what auditors expect in 2026
New

Reasonable vs. limited assurance, ISSB alignment, Scope 3 evidence, and how listed issuers in ADX, DFM and Tadawul are preparing sustainability disclosures.

By MAST Research

Jun 2026 36 pagesOpen
ToolkitResilience
ISO 22301 business continuity starter kit

BIA workbook, RTO/RPO matrix, incident playbooks and a tabletop exercise script — everything to run a credible first BCMS cycle.

By Karim Osman

May 2026 Toolkit · 9 filesOpen
ChecklistCybersecurity
SOC 2 Type II readiness — 120-day sprint

Control-by-control checklist for CC-series criteria with owner, evidence type and the common ways auditors reject weak artefacts.

By Sara Vanhoof

Apr 2026 Checklist · 87 itemsOpen
BlogGRC
Writing a risk statement your board will actually act on

Move beyond likelihood × impact heatmaps. A repeatable pattern for decision-grade risk narratives that name the exposure, the owner and the required call.

By Rahul Menon

Mar 2026 6 min readOpen
WhitepaperData Privacy
GDPR × UAE PDPL × KSA PDPL — a comparative controls map

Side-by-side mapping of lawful bases, DSR timelines, transfer mechanisms and breach thresholds across three regimes, with a single unified control set.

By Layla Ibrahim

Mar 2026 26 min readOpen
TemplateAI Governance
AI model risk register — ISO 42001 aligned

Model inventory, intended use, data lineage, evaluation cadence and residual risk scoring — pre-wired for AIMS internal audits.

By Dr. Nadia Al-Hashimi

Feb 2026 Template · XLSXOpen
WebinarLeadership
From analyst to Lead Implementer in 18 months

A career-path conversation with three alumni who moved from GRC analyst roles into Lead Implementer positions across banking, health and government.

By MAST Alumni Panel

Feb 2026 Webinar · 47 minOpen
Case StudyAI Governance
Building an AI Management System at a national telco

Inside the first ISO 42001 certification programme at a Tier-1 telecom operator: governance, model inventory, evaluation gates and the audit surprises.

By Dr. Nadia Al-Hashimi

Jan 2026 13 min readOpen
PodcastGRC
Third-party risk when your fourth party is an LLM

Vendor risk teams are being asked to assess AI subprocessors they cannot see. What good looks like — contracts, evidence and continuous monitoring.

By The MAST Briefing

Jan 2026 Podcast · 42 minOpen
ChecklistData Privacy
DPIA quick-start — 12 questions before you approve

A one-page screening tool product managers can run in ten minutes to decide whether a full DPIA is required — and what evidence to gather either way.

By Layla Ibrahim

Dec 2025 Checklist · 12 itemsOpen
BlogGRC
Why most control libraries rot within a year

Control catalogues drift because ownership drifts. Three lightweight practices that keep a control library trusted long after the initial cert audit.

By Rahul Menon

Dec 2025 5 min readOpen
ReportIndustry Research
Cybersecurity talent index — GCC 2026

Compensation bands, role scarcity, retention drivers and the certifications that moved the needle for hiring managers across banking, energy and government.

By MAST Research

Nov 2025 28 pagesOpen
The MAST Podcast

Long-form conversations with the people running the world's compliance programmes.

New episodes every other Wednesday. CISOs, DPOs, Lead Auditors and heads of risk on what they've stopped doing, what they've started, and why.

The MAST Briefing

One email a month. New frameworks, audit notes, and what we're seeing in the field.

Trusted by 8,400+ GRC, security and privacy leaders. No sponsored posts. Unsubscribe in one click.

We honour GDPR, UAE PDPL and KSA PDPL. Your address is only used for the Briefing.

Contribute

Ran an interesting programme? We publish practitioner case studies quarterly.

Bring the story — we handle the edit, the visuals and the review. Your team keeps the byline.