Corporate governance
From individual decisions to a documented, auditable institutional system.
- Group governance framework
- Board and committee charters
- Delegation of authority matrix
- Board performance evaluation

A methodology grounded in international reference frameworks — ISO 37301 · ISO 31000 · COSO ERM and the IIA Three Lines Model — fully aligned with Saudi regulations in force.
Madinah — Kingdom of Saudi Arabia
Innovestment Capital — a Saudi house of expertise in governance, compliance and financial advisory, serving multi-entity groups and their boards.
To be the driving strategic partner in the Kingdom for designing and developing governance, compliance and risk management systems, through integrated solutions built on international best practice and aligned with national regulatory requirements.
To enable boards and executive management to build effective, sustainable governance and compliance systems through specialised advisory services and practical, implementable solutions that raise performance and create lasting value for all stakeholders.
The most recurrent gaps we observe across our engagements with multi-entity groups.
The absence of an approved delegation-of-authority matrix leads to decisions outside the statutory framework and conflict between holding and subsidiaries.
Decisions recorded without adequate minutes and attachments make it hard to evidence compliance before regulators.
Uncontrolled treatments in returns and e-invoicing turn into assessments and penalties.
Operating across several countries raises sanctions, transfer pricing and customs compliance risk.
Concentrated-ownership groups need a framework that separates ownership from management and safeguards decision continuity.
Without impact analysis and tested recovery plans, critical operations remain unprotected.
An integrated package approved at holding level and cascaded to subsidiaries, with a named responsible partner and independent technical quality review before every delivery.
From individual decisions to a documented, auditable institutional system.
A compliance programme built on ISO 37301 requirements with a full lifecycle.
Establishing, operating and measuring the effectiveness of second and third line functions.
Supporting growth, funding and restructuring decisions with documented quantitative evidence.
International frameworks define the method and Saudi regulations define the obligation — our deliverables combine both in a single board-approvable document.
Enterprise risk management framework linked to strategy and performance.
The international standard for compliance management systems and their lifecycle.
Principles and guidelines for risk management at group level.
The 2020 Institute of Internal Auditors model for allocating control roles.
Issued by Royal Decree M/132 of 2022 and its implementing regulations, governing the holding company and its subsidiaries.
Board, committee and disclosure requirements issued by the Capital Market Authority.
Zakat and tax returns and e-invoicing across both phases.
Local Content and Government Procurement Authority regulation and qualification requirements.
Ministry of Human Resources requirements, Nitaqat and occupational safety conditions.
Counterparty due diligence and international sanctions screening before contracting.
Who owns the risk, who monitors it, and who independently assures control effectiveness.
Own the risk and apply controls in day-to-day operations.
Set the framework, monitor compliance and report to management.
Independent assurance on governance and control effectiveness to the audit committee.
The board and audit committee are the highest oversight body, relying on independent assurance from the third line and the external auditor under the IIA model (2020).
Five phases with defined deliverables and formal approval points at the end of each phase.
Assess the current state and identify statutory and control gaps.
Build the frameworks, policies and matrices suited to the group structure.
Present deliverables to the board and committees for formal approval.
Cascade to subsidiaries with training and knowledge transfer.
Control testing, evidence packs and quarterly reviews.
A suggested duration of 4–6 months for the foundational phase, followed by annual operational support with quarterly reviews before the audit committee.