Problem
Citizen identity was fragmented across multiple ministries. The kingdom needed sovereign rails — biometric-ready, OIDC-compliant, and certified for sensitive sectors including health and finance.
90-day go-live for first service. 38 federated relying parties. Sovereign-cloud certified. 100% biometric coverage.
Citizen identity was fragmented across multiple ministries. The kingdom needed sovereign rails — biometric-ready, OIDC-compliant, and certified for sensitive sectors including health and finance.
Sovereign identity rails on certified national cloud, mobile-first wallet, FAPI-grade APIs, federated relying-party onboarding. Operations transferred to local team in month 7.
18M citizens onboarded. 38 federated relying parties live in 9 months. 100% biometric coverage. First service to go live in 90 days.
Five phases. One accountable team. Every phase had a named decision point and a measurable outcome.
Workshops with the Leading Middle East National Authority executive team, baseline metrics, target outcome tree, programme governance set up.
Reference architecture, security blueprint, joint squad model agreed. Data model and integration contracts published.
Vertical slice built and run live-parallel against the existing system. Continuous integration, daily deploys, weekly business demos.
Phased cutover, audit-aligned reconciliation, scaling out of squads, capability transfer to Leading Middle East National Authority teams.
Managed run with named SLOs, quarterly value reviews, and a 15% optimisation budget reserved for improvement work.
Cloud landing zone, identity, network, security baseline. Data fabric with lineage-by-default. Audit-grade observability stack from day one.
Domain-aligned microservices behind a published API surface. Event-driven core with CDC into the data fabric. Live-parallel capability built in, not bolted on.
RBAC, audit logs, lineage, policy-as-code. Model risk records for every production model. Compliance posture on the executive dashboard, not in a quarterly slide.
Production-grade choices, defended by track record. The stack is one engineering decision among many — but a load-bearing one.
Independent assurance reviews at each phase gate. Findings tracked in a single risk register with named owners and remediation deadlines.
ISO 27001, SOC 2 Type II controls applied throughout. Data lineage captured by default; sensitive data tokenised at the edge.
Deployment aligned to national cybersecurity authority controls. Sovereign cloud where data residency requires it.
WCAG-AA on every citizen-facing journey. Arabic-first design with parallel English; user-research panels include accessibility users.
A foundational programme — done at sovereign-grade and on schedule.
D Director General · KSA national authority
9 months from kickoff to first regulated outcome — squad density and decision velocity matter more than headcount.
Joint squads with Leading Middle East National Authority engineers stayed in place after go-live. Ownership did not transfer in a hand-off — it grew in place.
Live-parallel for a meaningful window before cutover bought us trust. The cutover itself was a flag flip, not a war room.
Tell us your sector and your timeline. A senior partner with sector experience will respond within one business day.