Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    Audit, Assurance and Regulatory Engagement

    under Saudi PDPL

    Masterclass #1812 August 2026Basmah Alsubaie

    A recap of the Pyxos masterclass with Basmah Alsubaie.

    Knowing the text of the law has never been what separates a comfortable audit from a difficult one. That was the premise Basmah Alsubaie, CEO of Privacy Professionals and former CEO of National Data Governance at SDAIA, set at the top of this masterclass on audit, assurance, and regulatory engagement. The difference, she argued, is whether you can put the evidence on the table quickly, and whether it holds up under questioning. Under the PDPL, accountability is not a passive obligation; it is the requirement to demonstrate compliance on request, which converts a policy exercise into an evidence exercise.

    Her opening test made that concrete. If SDAIA wrote to you this afternoon asking for your record of processing activities and your last three impact assessments, how long would it take to respond, and would you be comfortable? The windows in practice are short, often five business days, and Alsubaie described regulators, plural, inspecting government and private entities of every size across the market. Audit work is therefore a permanent fixture of the DPO office rather than an occasional event: scheduled internal audits, unannounced regulator inquiries, sharply increased board requests, post-incident reviews, and a coming certification regime, with a draft on accreditation and certification bodies already out for public consultation, can each land in any given quarter. The stakes are equally familiar: repeat work under supervision after a failed audit, enforcement action, reputational damage that travels quickly between regulated entities, and remediation deadlines that consume the same people who run daily privacy operations.

    The session's most useful definition was what regulator-grade evidence actually means: complete, current, traceable to operations, and consistent with what the organization has already submitted, because the regulator keeps a profile of prior submissions and reads each new response against it. Currency was the property she pressed hardest. A record of processing accurate in January is a liability in September if the business has launched new services in between. And control drift is the risk people underestimate: nobody decides to stop doing access reviews, but owners change, employees leave, systems migrate, vendors are replaced, and six months later the control exists on paper only.

    Her survey of where audits fail landed on a single diagnosis: what links the recurring failures, from inventory and retention to access, vendors, cross-border transfers, and training, is not missing controls but missing evidence. The consent example was the sharpest. If you cannot reproduce what a specific individual was told and agreed to, with notice versions and timestamps, you do not have consent evidence; you have design intention. The same logic runs through what regulators scrutinize: a board-signed policy proves intent, while a log showing the control executed proves operation, and sensitive data, incident readiness, and third-party governance draw the deepest sampling, with follow-up questions to match: when did you last test this, and what did you learn?

    On engagement itself, her counsel was disarmingly simple. Answer precisely what is asked, and be straightforward about gaps you have already identified: a documented gap with a remediation plan and a named owner is received far better than a confident claim that later proves unsupported. Choose carefully who speaks for the organization, and review every response before it goes out. The live case simulations worked that posture through scenarios her audience recognized immediately, a fourteen-month-old record demanded in five days, and missing assessments for high-risk processing including biometric data, where the defensible move was to restrict the processing until the assessment is complete. The six-step audit lifecycle the session was built around, and the documentation toolkit that supports it, are best taken from the recording and the takeaways.

    The closing idea is the one to keep. The audit lifecycle is a cycle, not a line, and most organizations enter it at execution, when the auditor has already arrived and everything is compressed and reactive. The work you do between audits determines how the next one goes.

    About the presenter

    • Basmah Alsubaie

      Basmah Alsubaie

      Basmah Alsubaie is CEO of Privacy Professionals and a former regulator, previously CEO of National Data Governance at SDAIA.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.