Compliance you can prove — across every framework.
Submarine is the governance, risk & compliance platform for insurers and brokers in the UAE, Saudi Arabia and the wider GCC. Maintain one control set, satisfy many frameworks, and stay audit-ready continuously.
Control coverage
78%
Open risks
12
Frameworks
5
Coverage by framework
Frameworks
Regional & international, out of the box
NCA ECC-2:2024
Saudi Arabia · NCA
SAMA CSF
Saudi Arabia · SAMA
OTCC
Saudi Arabia · NCA
ADHICS v2
Abu Dhabi · DoH
UAE IA
UAE · TDRA
CBUAE Rulebook
UAE · Central Bank
DHA NABIDH
Dubai · DHA
ISO/IEC 27001
International
NIST CSF
International · NIST
NIST 800-53
International · NIST
EU AI Act
European Union
Saudi PDPL
Saudi Arabia · Data protection
For the C-suite
Your whole compliance posture, on one board-ready screen
CEOs, COOs and CROs open Submarine to a live dashboard — control coverage, open risk, and framework readiness — without waiting on a spreadsheet refresh.
- Real-time coverage & risk metrics
- Per-role, configurable dashboards
- Evidence the board and regulators trust
Control coverage
78%
Open risks
12
Frameworks
5
Coverage by framework
For risk managers
Enterprise risk management that scores, ranks and links to controls
Run a configurable register — multi-dimension impact, your own rating bands, residual scoring after controls, and risk appetite. Track Key Risk Indicators and incidents, run AI residual-risk assessments, and tie every risk to its mitigating controls and action plans.
- Inherent + residual heatmaps, bands & appetite
- KRIs, incident register & action plans
- AI residual-risk assessments & third-party risk
Heatmap
impact × likelihood
For compliance & security
Define a control once, satisfy every framework
Map a single common control set across NCA ECC, ISO 27001, NIST CSF, the EU AI Act and more. Test once, comply many — with evidence and findings tracked in place.
- One control graph across frameworks
- Evidence & control testing
- Findings & remediation workflow
AC-2
Account management
Satisfies — one control, four frameworks
AI, built in
An AI Copilot that knows your program
Ask the Copilot about your gaps, risks and controls in plain language, grounded in your live data — every answer scoped to what you are allowed to see.
- AI Copilot grounded in your org's data
- Answers cite the records behind them
- Plan-aware — stays within your entitlements
Everything a regulated team needs, in one place
Append-only audit trail
Every change recorded with who, what and when — by default.
Configurable to your org
Custom risk categories, fields and Excel import on every register.
Policies & documents
Full policy lifecycle and a versioned document store (Enterprise).
Business continuity
Continuity & recovery plans with objectives and test cadence (Enterprise).
API & access control
Role personas, per-module permissions, SSO and a REST API (Enterprise).
Built for the GCC
Regional frameworks, data-residency awareness and an RTL-ready UI.
See your compliance posture in one place
Enterprise and Basic plans available. Contact us to get started.