Fluent with global auditors
Built on UK and international GRC practice, so the platform speaks the language of global auditors, boards and investors.
Zemam is the AI-native governance, risk and compliance platform for corporate groups and growing businesses worldwide. It is built on UK and international experience, and fluent in the regulation of every market you operate in, from London to Riyadh. Every AI answer carries its source, page, confidence and model version, so your evidence stands up to any auditor, anywhere.
Zemam is built on UK and international compliance experience, with a working understanding of Gulf regulation. It holds global standards and regional rules to the same bar, so a group that operates across borders stays in control everywhere it does business.
Built on UK and international GRC practice, so the platform speaks the language of global auditors, boards and investors.
Fluent in NCA ECC, SAMA CSF, PDPL, ZATCA and CMA, and aligned with Saudi Vision 2030.
The Regulation Finder maps the right regulators from each entity's country, sector and listing status, wherever it sits.
Other platforms give you an AI verdict and ask you to trust it. Zemam shows its work. Every determination links to the exact document, page and locator it came from.
A team of specialised AI agents — each does one job well, cites its evidence, and hands off to the next, from an uploaded document to a workpaper an auditor will sign. The highlights:
Turn a PDF into structured, cited facts. Every field carries its page and a confidence score.
Owner self-tests, Internal Control reviews, Internal Audit independently verifies — each on its own calendar, with a combined assurance view per control and findings that close only on a passing retest.
Business objectives anchor everything: each one shows its chain — risks, the controls answering them, and what every assurance line last concluded — and draws it as one picture, objective to evidence.
Map controls to requirements as full, partial or gap, with web grounding off so no standard is invented.
Every AI-drafted requirement that cites a source is independently checked against the article it cites, and no AI-drafted requirement, control, mapping, risk, objective, authority line, finding or exception enters its register without a recorded human decision — maker-checker, with two approvers on high risk, enforced by the database. AI test verdicts and parsed evidence are recorded at once under lineage and can be overruled on the record by a named person.
A full risk lifecycle with treatments gated by your risk appetite — in scores and in money — plus seeded Monte Carlo (FAIR Lite): percentiles, loss exceedance curves and an ALE reproducible bit-for-bit from its stored seed. Computed in code, never by the AI.
Auditor-ready workpapers with evidence tables and citations, generated in place.
A grounded assistant that cites every claim, refuses to answer beyond the evidence — and streams its answers live: the first tokens appear as it works, while a full grounded, cited answer takes a few seconds; it answers in the language you ask.
Find the regulators that apply to each entity, and import ISO standards, versioned policies and board resolutions — requirements extracted automatically.
Every user can run the agents on their own Gemini, Claude or OpenAI-style key — encrypted at rest, switchable from the top bar, never shared.
Every record keeps its full change history, and every action is logged with who did it — history survives even deletion.
Law firms and consultancies work inside their clients as consultants and vouch for reference content. Client approvals promote requirements across a shared library — candidate, to global, to a public partner-backed tier — on two independent vetted approvals.
Model your holding company, its legal entities and business units across every country you operate in, each with its own regulators, sector and score, then roll compliance up across the whole group.
Role-based access, scoped to your entities.
A PDF, an image, a policy or a resolution.
Structured facts, each with a page and confidence.
Controls tested, requirements mapped, gaps flagged.
A cited workpaper, and an auditor who never leaves the page.
Every client's workspace is fully separated from every other client's, and we prove it with attack-style tests before every release.
The AI proposes. A person decides, and can edit before accepting. Every action is logged with who did it.
Arabic and English are equal citizens, so the product reads and works naturally either way — and your language follows you between devices; the virtual auditor answers in the language you ask.
Built to deploy in the UK, the EU or in-Kingdom — production runs in-Kingdom today. Your data lives where your regulators require — UK GDPR or Saudi PDPL — and adding a region never means rebuilding the platform.
We publish what works now and what comes next, in the same spirit as the product: nothing claimed without evidence.
In Arabic, زِمام is what secures a thing and keeps it held. The lexica define it figuratively as مِلاك الأمر: that on which a matter turns and by which it is held together. When control is lost, the phrase is أفلت الزمام من يده, and the dictionaries gloss it as عجز عن ضبطه — he could no longer regulate it. That is a definition of internal control written twelve centuries before the term existed. A control is not a policy and not a reporting line. It is the point on which a process actually depends, and the point at which, when things go wrong, the hold gave way.
Zemam is onboarding a small number of design partners, in the UK, the Gulf and beyond. Join them, and shape a compliance platform your auditors will trust, wherever they are.
The live demo runs on a demonstration server. Anything you enter there — your name, your email, any document you upload — is stored on that server, is visible to our team, and you use it at your own risk. Write to us instead if you would rather not.
Version 2026-09-05
The Service. Zemam is a governance, risk and compliance software service operated by Perficio, a limited company registered in England and Wales ("Perficio", "we"). These terms govern all use of the service.
Accounts and eligibility. The service is offered to businesses and their personnel aged 18 or over. You are responsible for the confidentiality of your sign-in and for all actions taken under your account.
Customer content and responsibility. All data provided to the service is provided at the client's responsibility. The client warrants it has the right to upload and process that data, and remains responsible for its accuracy, lawfulness and completeness. Workspace content remains the client's; Perficio receives only the rights needed to operate the service.
AI outputs. AI outputs are suggestions, not decisions: every AI-drafted item requires a recorded human approval before it becomes part of the official record, and figures are computed by the platform, never invented by a model. AI outputs may nonetheless contain errors; the client is responsible for reviewing them before reliance.
No advice; shared-library content. Zemam is software. It does not provide legal, tax, financial, audit or other professional advice, and nothing in the service — including requirements, controls, policies and regulatory content drawn from the shared library — is a substitute for advice from a qualified professional. Shared-library content is contributed and approved by the organisations and accredited firms shown against it and is distributed by Perficio as provided; it is not authored by Perficio, and where an attestation is recorded it is shown with the attesting firm and date. The client remains responsible for determining the law and regulation applicable to it and for its own compliance.
Availability. The service is provided as-is during its current phase, without an availability guarantee. We take backups and operate with care; the client should retain originals of critical evidence.
Partner programme. Partner-firm and consultant accounts that register interest in the partner programme are reviewed and accredited at Perficio's discretion; accreditation may be declined or revoked.
Termination. Either party may close a workspace at any time. On closure, its content is deleted after a short operational period except where the law requires longer retention.
Liability. To the extent permitted by law, Perficio's aggregate liability for the service is limited to the fees paid for it in the preceding 12 months (or GBP 1.00 where the service is free). Nothing limits liability that cannot lawfully be limited.
Governing law. These terms are governed by the laws of England and Wales, and the courts of England and Wales have jurisdiction.
Contact. hello@perficio.org.uk.
Version 2026-09-05
Controller. Zemam is operated by Perficio, a limited company registered in England and Wales. Perficio is the controller, under applicable data-protection law, of your account details, sign-up profile and consent records. Contact for privacy matters: privacy@perficio.org.uk.
Data we process. Account details (name, email, sign-in provider); the content your organisation places in its workspace; and, if provided at sign-up, your company profile together with your consent choices and the terms version accepted. For workspace content, your organisation is the controller and Perficio processes it only to operate the service; a data-processing agreement is available on request.
Purposes and legal bases. We process account and workspace data to perform our contract with you; the optional sign-up profile on your consent; and security and audit records under our legitimate interest in operating a safe service. We contact you about partnership or product updates only if you gave the separate contact consent, which is withdrawable at any time and never a condition of the storage consent.
Client responsibility. All data provided to the service is provided at the client's responsibility; clients must not submit personal data they lack the right to process.
Storage and transfers. Data is stored and processed in the United Kingdom and, in some cases, outside it, including by the third-party AI model providers that serve AI requests. Wherever personal data is processed, we apply the security measures described in this notice and work to protect it in line with applicable data-protection law.
Security. We maintain appropriate technical and organisational measures designed to protect personal data, including logical separation of each customer's workspace, encryption in transit, and role-based access controls. Content is never shared with other workspaces unless your organisation explicitly contributes it to the shared library.
Your rights. You may request access to, a copy of, correction of, deletion of, or restriction of your personal data, object to processing, and withdraw any consent at any time (withdrawing the storage consent removes the sign-up profile and re-gates the workspace). Write to privacy@perficio.org.uk; we respond within 30 days. You may also lodge a complaint with the relevant data-protection authority.
Retention. Profiles and consents are kept while the workspace exists; audit records and short-lived operational backups expire on a rolling basis after closure, except where the law requires longer retention.
Automated decision-making. No decision with legal effect is made about you by automated means; every AI output requires a recorded human approval.
Cookies and device storage. The service uses no advertising, analytics or tracking cookies, and our website embeds no third-party tracking. A single short-lived security cookie is set only if you choose to sign in through an external provider; it protects that sign-in exchange, lasts ten minutes, cannot be read by scripts, and is deleted once sign-in completes. While you are signed in, your browser also holds your session token and a small number of interface preferences — your language and the entity you are viewing — so that the service works and remembers where you were; clearing your browser storage removes them.