Skip to main content

📋 Compliance Overview

BayanCore incorporates Saudi Arabian regulatory requirements directly into its technical architecture. Every workflow, transactional log, and data storage design aligns with local laws by default.


1. Compliance Matrix & Implementation Status

Below is the master matrix mapping regulations to system implementations and statuses:

RegulationEnforcing AuthorityKey RequirementImplementation StatusTarget Module
ZATCA Phase 2ZATCAReal-time XML clearance (B2B) & reporting (B2C) within 24h🟡 In Testing (Sandbox)Billing & Invoicing
VAT RulesZATCAStandard 15% VAT calculation, invoice display, returns🟢 Fully SupportedAccounts Receivable/Payable
PDPLSDAIAData residency, consent logging, right to erasure🟢 Fully SupportedSystem Infrastructure / Core DB
Wage Protection (WPS)MHRSDMonthly payroll banking export in SIF format🟢 Fully SupportedHRMS & Payroll
GOSI InsuranceGOSIAutomatic calculation of employee & employer GOSI percentages🟢 Fully SupportedHRMS & Payroll
NCA CybersecurityNCAZero-trust RBAC, encrypted secrets, inactivity timeouts🟡 Implementation PhaseAPI Gateway & Operations
Saudi Labor LawMHRSDOvertime calculations, EOSB gratuity, Nitaqat tracking🟢 Fully SupportedHRMS & Payroll

2. Key Compliance Principles

  1. Sovereignty First: All production data, search indices, backups, and AI embeddings remain strictly within the geographical borders of the Kingdom of Saudi Arabia.
  2. Immutability: Transaction records, particularly financial postings and ZATCA compliance stamps, are write-once, append-only objects with cryptographic tamper-evident hashes.
  3. Bilingual Generation: Customer-facing documents (invoices, receipts, contracts) are generated in both Arabic and English natively.
  4. Audit Readiness: The system provides built-in reports, Excel exports, and audit trails explicitly structured for government auditors (ZATCA, GOSI, MHRSD).

3. Compliance Documentation Index

To explore specific implementation details, refer to the following specifications: