Client Background
The client is a new digital bank being established in Saudi Arabia, built on a cloud-first, API-centric strategy with a lean organisation and a strong reliance on partners and outsourced capabilities. Its business strategy had approved a high-level technology structure, but the bank still needed to define how its IT function would actually be organised, governed, sourced and measured. That design had to satisfy local regulatory expectations on technology risk, data protection, outsourcing and workforce localisation from the first day of operation. As part of a wider engagement spanning seven workstreams and 32 policy and architecture documents, Cedar was mandated to design the bank's IT target operating model, governance framework, roles and KPIs.
Cedar’s Approach
Cedar developed a six-pillar IT target operating model framework anchored in five design principles: integrated and collaborative delivery, strategic alignment and agility, scalable and modular architecture, risk-first and secure-by-design, and value-driven service delivery. Each pillar was built out as a discrete module:
Sourcing, Talent and Roles – Using a three-step method, Cedar identified 19 relevant IT functions, compared the approved structure with industry-aligned models to surface missing roles, and mapped every role to logical functions split between run-the-bank and change-the-bank. Responsibilities and KPIs with targets were defined for each role across areas such as the application centre of excellence, IT strategy, demand, risk and vendor management, PMO and governance, core banking, enterprise architecture and data, culminating in a target IT organisation structure built around a hybrid in-house and outsourced model.
IT Capabilities – Ten capabilities essential to a digital bank were defined, from IT strategy and governance, security and cloud platform engineering to data management, operations monitoring and partnership-led innovation, each with its key attributes and relevance to the bank.
Service Delivery – Cedar set out a DevOps and DevSecOps delivery approach and team structure, an IT service catalogue covering architecture, security, infrastructure, business and open banking services, and an IT4IT value-stream view of the service lifecycle.
IT Risk and Compliance – The model embedded a technology risk management framework with risk identification, assessment, mitigation and a risk register, an incident management lifecycle and SLAs aligned to ITIL 4, ISO 27001 and COBIT, and layered audit logging and monitoring practices, supported by an evaluation of leading security monitoring solutions.
IT Governance and Processes – A COBIT 2019 governance charter was defined across its four domains, with strategic, tactical and operational committees plus data governance, change advisory and IT risk and compliance forums, each with membership, cadence and terms of reference. Five core processes (change, demand, software development lifecycle, release and incident management) were documented with lifecycles and end-to-end flows.
Strategic Outcome and Way Forward
The bank received a complete, regulator-aware blueprint for how its technology function will be structured, governed and operated: a defined IT organisation with clear role accountabilities and measurable KPIs, a capability map, a service delivery model and a governance forum structure that ties technology decisions to business strategy from launch. Because the model was designed alongside the enterprise architecture, security, data and continuity workstreams, it gives the bank a coherent foundation for hiring, vendor onboarding and control design rather than a set of disconnected policies.
The way forward covers the companion sourcing strategy, which weighs people and technology sourcing options against cost, resource constraints and time to market, together with detailed policies for change, software development, incident and release management, completing the operating model ahead of the bank's build-out.