In early 2026, QatarEnergy put an internal audit management solution out to international tender. The public listing gives a useful picture of what a large Gulf function asks for: around 75 internal auditors as users, audits touching more than 5,000 people across the group and its subsidiaries, and roughly 70 audits a year. The scope ran from risk-based assessment and strategic planning through scheduling, documentation and reporting to follow-up — with alignment to the IIA's professional framework, centralised dashboards, easy user on- and off-boarding, and reliable vendor support.

That is a good shape for any RFP in the region. What follows is a checklist for writing one in Saudi Arabia or Qatar: what to size, which rules shape the procurement and the hosting, what to ask about the audit lifecycle, and how to test the answers. It is written to be vendor-neutral — use it on us as hard as on anyone else.

1. Size it before you write it

Licensing, implementation effort and hosting all follow from a handful of numbers. Put them in the RFP rather than letting each vendor guess.

Sizing item Why it matters
Named internal auditors (and co-source / guest auditors) The core licence metric for most vendors
Auditees who will respond to findings and actions Some vendors license auditee access separately
Audits per year, and the size of the audit universe Drives storage, workflow volume and reporting
Entities, subsidiaries and countries in scope Determines data segregation and consolidated reporting
Languages for working papers and committee reporting Arabic, English, or both from the same record
Committee packs per year Board and audit committee reporting cadence
Existing methodology and templates to migrate The biggest single driver of implementation time

2. Know your procurement route

Saudi Arabia. Government entities procure through the Etimad platform under the Government Tenders and Procurement Law (Royal Decree M/128 of 1440H), and companies that are more than 51% state-owned follow its principles. A new Government Tenders and Procurement Law was published in Umm Al-Qura in September 2026 and replaces M/128 from 120 days after publication — so an RFP issued now may be awarded under the new regime. Local-content and SME preference rules, administered by the Local Content and Government Procurement Authority, can affect how bids are evaluated. Ask your procurement team which rules will apply at award, not at issue.

Qatar. Government entities tender under Law No. 24 of 2015 on Tenders and Auctions, through the Ministry of Finance's Monaqasat portal. Some bodies — QatarEnergy among them — are outside that law and run their own supply-management portals. The Ministry of Finance has signalled that in-country value certificates in financial bids become mandatory from the start of 2027.

The practical point: the procurement route sets the timetable, the bid-bond and validity terms, and the evaluation weights. Settle it before you write the technical sections.

3. Hosting and data: ask the right regulator

Where audit evidence may live is usually the first gate. It is also the area most often summarised wrongly.

Saudi Arabia.

  • The NCA's 2024 updates to the Essential Cybersecurity Controls (ECC-2:2024) and the Cloud Cybersecurity Controls (CCC-2:2024) removed the earlier sub-controls that required hosting inside the Kingdom; data localisation now sits with the National Data Management Office at SDAIA. Ask your data office what localisation rules apply to audit data before you write a hosting requirement.
  • Banks: SAMA's Rules on Outsourcing require SAMA's no-objection for material outsourcing, with additional justification where the provider is outside the Kingdom.
  • Personal data in working papers falls under the PDPL and SDAIA's rules on transfers outside the Kingdom.

Qatar.

  • Banks: QCB's Cloud Computing Regulation (2024) requires personal and financial information to be processed within Qatar and requires QCB's prior approval for cloud arrangements.
  • Government entities: work within the NCSA's National Data Classification Policy and the government cloud policies that reference it.
  • Personal data falls under the PDPPL (Law No. 13 of 2016).

4. The audit lifecycle, written against the Standards

The IIA's 2024 Global Internal Audit Standards do not require software. They do expect the chief audit executive to strive to give the function the technology it needs and to evaluate it regularly (Standard 10.3). The most useful way to write lifecycle requirements is to tie each one to what the Standards expect the function to evidence.

Requirement Ask the vendor to show IIA 2024
Risk-based plan from a maintained audit universe How risk ratings drive the plan, and how plan changes are approved and recorded 9.4
Reliance on other assurance providers Where the basis for relying on others is documented 9.5
Engagement risk assessment and work programme Programme approval before fieldwork, and reuse from a library 13.2, 13.6
Working papers that stand on their own Preparer and reviewer sign-off, evidence linked to each step, an audit trail 14.6
Findings and reporting Finding rating, management response, and the report built from the record 11.3, 14.3
Follow-up to closure Action owners, due dates, evidence of implementation, escalation 15.2
Quality programme Supervision evidence and internal assessment data on demand 8.3, 12.1, 12.3

5. Arabic: test it, don't tick it

"Arabic supported" can mean anything from a translated menu to a fully bilingual record. Ask:

  • Can a finding be written in Arabic, reviewed in Arabic and reported in Arabic — with the English version of the same record kept in step?
  • Do reports and committee packs render right-to-left with correct Arabic typography, or does Arabic sit inside an English layout?
  • Are dates, numbering and exports (PDF, Word, Excel) correct in Arabic?

6. Commercial terms that decide year three

  • Licence metric: per auditor, per auditee, per entity, or consumption-based (including AI usage). Ask for a three-year cost at your sizing.
  • Implementation: who configures your methodology, how long it takes, and what you must provide.
  • Support: hours in your time zone, Arabic-speaking support, and response targets.
  • Exit: data export in open formats, and source-code escrow where you host it yourself.
  • Security evidence: what certifications and penetration-test results the vendor will share under NDA.

7. Run a scripted demo on your data

Give every shortlisted vendor the same script and the same sample data: one auditable entity, one engagement, three findings (one in Arabic), one overdue action, and one committee pack. Score what they show, not what they say. Most selection regret comes from choosing on a feature list and discovering the workflow later.

How ControlVista answers this checklist

We built ControlVista's audit management software for this buyer: on-premise or private cloud by default, Arabic and English from the same record, and designed around the 2024 IIA Standards and the complete internal audit lifecycle. Use the checklist on us exactly as you would on anyone else — and see the Saudi Arabia and Qatar pages for how we map to each market's regulators.

Sources

  • QatarEnergy tender LT26101000, "Internal Audit Management Solution" — public listing: TenderDetail; QatarEnergy supply management: tenders
  • Saudi Ministry of Finance, Government Tenders and Procurement Law FAQ: mof.gov.sa; new law in Umm Al-Qura (September 2026): uqn.gov.sa
  • Saudi local-content preference regulations: mof.gov.sa
  • NCA, Essential Cybersecurity Controls ECC-2:2024: nca.gov.sa; Cloud Cybersecurity Controls CCC-2:2024: nca.gov.sa
  • SAMA Rules on Outsourcing: SAMA Rulebook
  • QCB Cloud Computing Regulation (April 2024): QNA
  • Qatar Monaqasat portal: monaqasat.mof.gov.qa
  • The IIA, Global Internal Audit Standards (2024): theiia.org