AI-native GRC · global reach, local depth

Regulate what you cannot see. Intelligence you can audit.

Zemam is the AI-native governance, risk and compliance platform for corporate groups and growing businesses worldwide. It is built on UK and international experience, and fluent in the regulation of every market you operate in, from London to Riyadh. Every AI answer carries its source, page, confidence and model version, so your evidence stands up to any auditor, anywhere.

Citation lineage on every output Every client's data fully separated Multi-jurisdiction by design
Group compliance balance
86%
050100
NCA ECC108 / 108
ISO 2700188%
SOC 279%
Evidence agent · running 3 parsed
Aligned to the frameworks that matter, wherever your group operates
SOC 2ISO 27001GDPRNIS2 PDPLNCA ECCSAMA CSFZATCACMA
Global expertise, local fluency

A platform that has seen both worlds.

Zemam is built on UK and international compliance experience, with a working understanding of Gulf regulation. It holds global standards and regional rules to the same bar, so a group that operates across borders stays in control everywhere it does business.

Global grounding

Fluent with global auditors

Built on UK and international GRC practice, so the platform speaks the language of global auditors, boards and investors.

Regional depth

At home in the Gulf

Fluent in NCA ECC, SAMA CSF, PDPL, ZATCA and CMA, and aligned with Saudi Vision 2030.

Every jurisdiction

The right regulators, found

The Regulation Finder maps the right regulators from each entity's country, sector and listing status, wherever it sits.

The difference

Every AI answer, audit-defensible.

Other platforms give you an AI verdict and ask you to trust it. Zemam shows its work. Every determination links to the exact document, page and locator it came from.

  • Source, page, confidence, model and prompt version on every output.
  • The virtual auditor refuses to answer beyond the evidence.
  • Risk figures are computed in code. A model never invents a number.
CTL-014 · Quarterly access reviews Pass
Why this answer?
SourceAccess-recert-Q2.pdf · p.3
Locator§2.1 “reviewed 12 Apr”
Confidence0.92
Modelgemini-2.5-flash
Promptcontrol-testing@1.0
Retrieval distance0.14
The platform

Specialised AI agents. One defensible workflow.

A team of specialised AI agents — each does one job well, cites its evidence, and hands off to the next, from an uploaded document to a workpaper an auditor will sign. The highlights:

Evidence parsing

Turn a PDF into structured, cited facts. Every field carries its page and a confidence score.

Structured, cited facts

Testing on the Three Lines Model

Owner self-tests, Internal Control reviews, Internal Audit independently verifies — each on its own calendar, with a combined assurance view per control and findings that close only on a passing retest.

3 lines · 3 calendars · findings

Objectives at the heart

Business objectives anchor everything: each one shows its chain — risks, the controls answering them, and what every assurance line last concluded — and draws it as one picture, objective to evidence.

Objective → risk → control → assurance

Regulatory mapping

Map controls to requirements as full, partial or gap, with web grounding off so no standard is invented. A run works in the background: leave and come back, or cancel it before any draft lands.

FULL / PARTIAL / GAP

Verified citations, human approval

Every AI-drafted requirement that cites a source is independently checked against the article it cites, and no AI-drafted requirement, control, mapping, risk, objective, authority line, finding or exception enters its register without a recorded human decision — maker-checker, with two approvers on high risk, enforced by the database. AI test verdicts and parsed evidence are recorded at once under lineage and can be overruled on the record by a named person.

Citation review · maker-checker

ISO 31000 risk management, quantified

A full risk lifecycle with treatments gated by your risk appetite — in scores and in money — plus seeded Monte Carlo (FAIR Lite): percentiles, loss exceedance curves and an ALE reproducible bit-for-bit from its stored seed. Computed in code, never by the AI.

ISO 31000 · FAIR · reproducible

Documentation

Auditor-ready workpapers with evidence tables and citations, generated in place.

Ready for your auditor

Virtual auditor

A grounded assistant that cites every claim, refuses to answer beyond the evidence — and streams its answers live: the first tokens appear as it works, while a full grounded, cited answer takes a few seconds; it answers in the language you ask.

Grounded · cited · refuses

Regulation discovery & sources

Find the regulators that apply to each entity, and import ISO standards, versioned policies and board resolutions — requirements extracted automatically.

Country · sector · listing

Bring your own AI key

Every user can run the agents on their own Gemini, Claude or OpenAI-style key — encrypted at rest, switchable from the top bar, never shared.

Encrypted · per-user · never shared

Version history & audit trail

Every record keeps its full change history, and every action is logged with who did it — history survives even deletion.

Who · what · when · why

Partners & a shared library

Law firms and consultancies work inside their clients as consultants and vouch for reference content. Client approvals promote requirements across a shared library — candidate, to global, to a public partner-backed tier — on two independent vetted approvals.

Candidate · global · public
Group structure

One group, across borders, in balance.

Model your holding company, its legal entities and business units across every country you operate in, each with its own regulators, sector and score, then roll compliance up across the whole group.

Acme Group HoldingGROUP86%
Acme UKUK · Fintech90%
Acme ArabiaKSA · Retail88%
Riyadh operationsBU91%
Acme EUEU · SaaS81%
How it works

From evidence to a defensible position, in one pass.

01

Sign in

Role-based access, scoped to your entities.

02

Upload evidence

A PDF, an image, a policy or a resolution.

03

Parse & cite

Structured facts, each with a page and confidence.

04

Test & map

Controls tested, requirements mapped, gaps flagged.

05

Workpaper & auditor

A cited workpaper, and an auditor who never leaves the page.

Trust by design

Global standards, secure by architecture.

Isolation

Your data stays yours

Every client's workspace is fully separated from every other client's, and we prove it with attack-style tests before every release.

Oversight

Approval-gated AI

The AI proposes. A person decides, and can edit before accepting. Every action is logged with who did it.

Region

Bilingual and right to left

Arabic and English are equal citizens, so the product reads and works naturally either way — and your language follows you between devices; the virtual auditor answers in the language you ask.

Residency

Host where the law requires

Built to deploy in the UK, the EU or in-Kingdom — production runs in-Kingdom today. Your data lives where your regulators require — UK GDPR or Saudi PDPL — and adding a region never means rebuilding the platform.

Where the platform stands

Shipped today. Built for tomorrow.

We publish what works now and what comes next, in the same spirit as the product: nothing claimed without evidence.

Platform today
  • Specialised AI agents for every step, every register write approval-gated and every output lineage-stamped
  • Complete separation between client workspaces, proven by attack-style tests before every release
  • Bilingual UI, Arabic right-to-left as an equal citizen
  • Control-testing register with due dates, risk–control linkage with tested residual scores
  • Redundant-control optimisation, public trust center, encrypted per-user AI keys
  • Version history on every record and a full audit trail
  • Business-objective chains: objective → risk → control → three-line assurance in one view
  • Mandated-policy gap engine (mandatory vs guiding, seeded from the CMA regulations) and a versioned Delegation of Authority matrix
  • Findings & remediation with the raising-line closure rule, and citation-backed KSA + UK legal starter packs
  • One human review queue for every agent — maker-checker and two approvers on high risk, enforced by the database
  • Independent citation review: AI-drafted requirements verified against the cited article, with verdicts that gate approval
  • Content licensing tiers: proprietary standards are never ingested — Zemam-authored Tier A summaries cite clause numbers only
  • Seeded Monte Carlo FAIR quantification — reproducible bit-for-bit, from a quick point estimate to a decomposed threat-frequency × vulnerability model (with vulnerability suggested from your pass-tested controls), flagging risks where ratings and money disagree
  • Partner registry with a consensus-promoted shared library: client approvals lift requirements from candidate to global to a public, partner-backed tier (two independent vetted approvals, a configurable Zemam moderation flag), plus a consultant role for firms working inside their clients
  • Persona workspaces with an intent gateway (“What would you like to do today?”) that names the view your roles and your ownership imply, states the one question that view answers and opens there — while never hiding a screen your role may open, guided save-and-resume wizards for setup, risk and testing, per-workspace onboarding checklists, one search (Ctrl/Cmd+K) that reaches the screens and your own registers alike — controls, obligations, risks, findings and people, in either script, contextual help on every screen — what it is for, how to work it, how to do the work well, and where to go next — a board register with point-in-time authority testing, and the grounded Ask assistant
  • Licence attestations: attest a licence you already hold and Zemam ingests that proprietary standard's full text — citations verified against it, verbatim quotes capped at 25 words by a server-side guard
  • Hire expert help: a marketplace of accredited firms with a full engagement lifecycle and a hard auditor-independence firewall — no assurance within 12 months of advisory by the same firm, enforced server-side
  • Deeper governance: per-category risk appetite overriding the tenant default, an exceptions & waivers register with mandatory expiry, and transaction-structuring detection over imported transactions against your authority thresholds
  • Board-ready oversight: key risk indicators with live platform-derived metrics, a one-click board committee pack computed entirely by the platform, and policy attestation campaigns with completion tracking
  • An Internal Controls workspace converging everything that needs a control — uncovered obligations, unmitigated risks, delegated-authority lines — with AI-suggested controls through the same approval lifecycle; the setup wizard now brings in requirement sources and AI-drafted requirements with inline approval, and AI framework suggestions beyond the catalog can be adopted with one click
  • Run the compliance week, not just the register: an attention bell for everything ageing silently (approvals, overdue tests, expiring waivers), evidence requests with due dates and overdue chase, and one-click CSV export on every register — plus an AI reviewer that gives approvers a second opinion on citations, sector language and cross-regulation conflicts, advisory only, with a workspace-level opt-out for shared-library contribution
  • A shared risk library that earns trust the same way: reusable risk scenarios other organisations and accredited firms have vetted, promoted candidate → global → public by two independent vetted approvals — import one sized and ready, or contribute your own
  • Real accountability: every control carries an accountable position — with whoever holds it today — and a department; filter to what you hold, move a leaver's items in one action, and get pinged when an accepted risk is due for re-review
  • People can overrule the AI's test verdict — on the record: a manual determination carries the person's name and written justification, becomes the authoritative result without editing history, and passing over a failure follows your workspace's approval ladder
  • Your own email server: each workspace configures its outbound SMTP like an API key — Zemam sends evidence-request chases and your attention digest from your own domain, encrypted at rest and never from a Zemam address
  • Approvals that fit how you actually work: choose per workspace whether approval happens outside the system, needs a maker and a checker, or a maker and two approvers — the same rule for items people type in and items AI suggests, enforced by the database, with safety floors that never relax
  • Usage accounting built in: every AI request is measured — tokens in and out, and who funded them — with per-workspace spend estimates and storage figures for admins and the platform owner
  • Sanctions and PEP screening built in: partner firms are vetted before accreditation, and a third-party register screens your vendors and counterparties — screening informs, and a human confirms every disposition with a recorded reason
  • Try it yourself: sign in with Google or LinkedIn and get your own private workspace with sample data — no sales call, no card
  • See it working on a real group, not a screenshot: a complete demonstration workspace — a food group across Saudi Arabia, the Netherlands, Qatar and the United Kingdom, with the obligations that genuinely bind it, evidence that passes, fails and is honestly insufficient, live findings, and a payment pattern the platform detects on its own
  • The whole workspace as one picture: an Assurance Map linking objectives, risks, controls, obligations and evidence — with a replay of the picture assembling over time — plus an honest agent theatre showing what the AI is doing, what is checking it, and what waits on a person. And the AI now learns from your recorded decisions: every suggestion names the past human decisions that informed it, precedent never outranks a regulation, and every lesson is traceable to the person, the date and their own words
  • Every control, obligation and risk now has its own fact sheet: one page with its relations drawn from the assurance graph — counted groups you can walk item to item — its testing state and its full version history. Coverage renders as a wall of tiles per framework, and the risk register gains a risk-by-control matrix plus a portfolio chart where bubble size is the computed loss figure and a never-quantified risk shows as an honest hollow ring
  • The organisation as positions, not just people: every entity's structure — who holds each seat and since when, who reports to whom, who may bind the company — imported from a spreadsheet that is checked whole before anything is written, reconstructable on any past date, and the owner of every control, obligation, risk, finding and objective, so a leaver's items are visibly vacant and shown escalating up the line instead of disappearing
  • Boards and committees on the record: each entity's board and committees with dated memberships by role and class, a composition rule per body with breaches named beside it, the committees an entity is required to have — from your own articles today, attested content per jurisdiction as it is published — and governance readiness in the attention bell
  • Regulatory watch: the regulators that bind your entities are checked nightly on your own AI key — the platform detects a changed page, the AI describes the instrument and clause that changed, and a person records whether it matters; new obligations arrive as drafts in the review queue, never as silent register changes
  • Built for registers that have grown: every list now states its own bound — how many rows you are seeing of how many the register holds, the moment one outgrows a page — and search across your registers returns exactly the rows that register would show you, never more. The audit trail filters by date range and exports the whole filtered set rather than the slice on the screen, naming the range in the file itself. The filters you re-apply every morning save under a name and follow you between devices, and a comfortable-or-compact switch sets row height with the screen, where that choice belongs
  • Assurance you can put in front of a board: an auditor's home gathering what has been tested and what is still outstanding — findings split by the line that raised them, lapsed tests counted apart from controls never tested at all — and an assurance rollup that says whether each objective's chain reaches a passing control, names the line that pass came from, and refuses to call an objective assured when nothing was examined. The screen and the exported board pack print the same verdict, and every control, obligation and risk now shows its chain up to the objective, and says plainly where that chain stops
  • A new workspace reads as a beginning: every register says what it will hold and offers the first step
  • A three-step introduction on first sign-in, dismissed once for good
  • Works on a phone: the same screens, the navigation in a drawer, canvases that scroll in their frame
  • Each workspace keeps its own time zone: today's date, due dates and expiries follow its calendar, the same day for everyone in it
  • A getting-started guide in Arabic and English, produced with every release — every screen in both languages /doc · /doc/ar
On the roadmap
  • NextGovernance foundations, next stages: reviewer competence and approver assignment to positions with a recorded approval trail, governance findings without a control to hang on, and attested committee-mandate content per jurisdiction
  • NextRegulatory watch, next stages: an amended instrument marks its attestations stale and reopens accepted findings, and monitoring is shared across workspaces through the library
  • NextSingle sign-on with your organisation's identity provider
  • NextManaged evidence storage with secure, expiring share links
  • PlannedFull partner portal: partner logins with scoped, revocable client access and an accreditation wizard
  • PlannedAdvanced FAIR quantification: the full risk-analysis node tree, all six loss forms, and control-strength modelling
  • PlannedProduction environments in the UK and the EU (in-Kingdom production is live today)
  • PlannedContinuous monitoring and executive reporting dashboards
The name

Zemam — زِمام

In Arabic, زِمام is what secures a thing and keeps it held. The lexica define it figuratively as مِلاك الأمر: that on which a matter turns and by which it is held together. When control is lost, the phrase is أفلت الزمام من يده, and the dictionaries gloss it as عجز عن ضبطه — he could no longer regulate it. That is a definition of internal control written twelve centuries before the term existed. A control is not a policy and not a reporting line. It is the point on which a process actually depends, and the point at which, when things go wrong, the hold gave way.

Start with a conversation.

Zemam is onboarding a small number of design partners, in the UK, the Gulf and beyond. Join them, and shape a compliance platform your auditors will trust, wherever they are.

The live demo runs on a demonstration server. Anything you enter there — your name, your email, any document you upload — is stored on that server, is visible to our team, and you use it at your own risk. Write to us instead if you would rather not.

Terms of Service

Version 2026-09-05

The Service. Zemam is a governance, risk and compliance software service operated by Perficio, a limited company registered in England and Wales ("Perficio", "we"). These terms govern all use of the service.

Accounts and eligibility. The service is offered to businesses and their personnel aged 18 or over. You are responsible for the confidentiality of your sign-in and for all actions taken under your account.

Customer content and responsibility. All data provided to the service is provided at the client's responsibility. The client warrants it has the right to upload and process that data, and remains responsible for its accuracy, lawfulness and completeness. Workspace content remains the client's; Perficio receives only the rights needed to operate the service.

AI outputs. AI outputs are suggestions, not decisions: every AI-drafted item requires a recorded human approval before it becomes part of the official record, and figures are computed by the platform, never invented by a model. AI outputs may nonetheless contain errors; the client is responsible for reviewing them before reliance.

No advice; shared-library content. Zemam is software. It does not provide legal, tax, financial, audit or other professional advice, and nothing in the service — including requirements, controls, policies and regulatory content drawn from the shared library — is a substitute for advice from a qualified professional. Shared-library content is contributed and approved by the organisations and accredited firms shown against it and is distributed by Perficio as provided; it is not authored by Perficio, and where an attestation is recorded it is shown with the attesting firm and date. The client remains responsible for determining the law and regulation applicable to it and for its own compliance.

Availability. The service is provided as-is during its current phase, without an availability guarantee. We take backups and operate with care; the client should retain originals of critical evidence.

Partner programme. Partner-firm and consultant accounts that register interest in the partner programme are reviewed and accredited at Perficio's discretion; accreditation may be declined or revoked.

Termination. Either party may close a workspace at any time. On closure, its content is deleted after a short operational period except where the law requires longer retention.

Liability. To the extent permitted by law, Perficio's aggregate liability for the service is limited to the fees paid for it in the preceding 12 months (or GBP 1.00 where the service is free). Nothing limits liability that cannot lawfully be limited.

Governing law. These terms are governed by the laws of England and Wales, and the courts of England and Wales have jurisdiction.

Contact. hello@perficio.org.uk.

Privacy Notice

Version 2026-09-05

Controller. Zemam is operated by Perficio, a limited company registered in England and Wales. Perficio is the controller, under applicable data-protection law, of your account details, sign-up profile and consent records. Contact for privacy matters: privacy@perficio.org.uk.

Data we process. Account details (name, email, sign-in provider); the content your organisation places in its workspace; and, if provided at sign-up, your company profile together with your consent choices and the terms version accepted. For workspace content, your organisation is the controller and Perficio processes it only to operate the service; a data-processing agreement is available on request.

Purposes and legal bases. We process account and workspace data to perform our contract with you; the optional sign-up profile on your consent; and security and audit records under our legitimate interest in operating a safe service. We contact you about partnership or product updates only if you gave the separate contact consent, which is withdrawable at any time and never a condition of the storage consent.

Client responsibility. All data provided to the service is provided at the client's responsibility; clients must not submit personal data they lack the right to process.

Storage and transfers. Data is stored and processed in the United Kingdom and, in some cases, outside it, including by the third-party AI model providers that serve AI requests. Wherever personal data is processed, we apply the security measures described in this notice and work to protect it in line with applicable data-protection law.

Security. We maintain appropriate technical and organisational measures designed to protect personal data, including logical separation of each customer's workspace, encryption in transit, and role-based access controls. Content is never shared with other workspaces unless your organisation explicitly contributes it to the shared library.

Your rights. You may request access to, a copy of, correction of, deletion of, or restriction of your personal data, object to processing, and withdraw any consent at any time (withdrawing the storage consent removes the sign-up profile and re-gates the workspace). Write to privacy@perficio.org.uk; we respond within 30 days. You may also lodge a complaint with the relevant data-protection authority.

Retention. Profiles and consents are kept while the workspace exists; audit records and short-lived operational backups expire on a rolling basis after closure, except where the law requires longer retention.

Automated decision-making. No decision with legal effect is made about you by automated means; every AI output requires a recorded human approval.

Cookies and device storage. The service uses no advertising, analytics or tracking cookies, and our website embeds no third-party tracking. A single short-lived security cookie is set only if you choose to sign in through an external provider; it protects that sign-in exchange, lasts ten minutes, cannot be read by scripts, and is deleted once sign-in completes. While you are signed in, your browser also holds your session token and a small number of interface preferences — your language and the entity you are viewing — so that the service works and remembers where you were; clearing your browser storage removes them.