Neeyamo Enterprise Solutions Pvt. Ltd. — Third Party Security Risk Assessment

Al Atta Consultations & Admin Studies

Updated Audit Response — Column F (ICP) + TIA Questionnaire

Organization

Al Atta Consultations

Respondent

Irfan Farooq — Director

Country

UAE

Date

02 Sep 2025 (Updated Apr 2026)

Overall Compliance

99.6%

Overall Risk %

0.39%

ICP Questions

60 Questions

TIA Questions

16 Questions

NEW — Neeyamo Clarification Responses (April 2026)

3 outstanding questions answered: Document Nomenclature, RPO/RTO Correction, BCP-TEST-2024 Explained

📨 NEEYAMO FOLLOW-UP — CLARIFICATION REQUIRED (April 2026)

Neeyamo has raised 3 specific clarification points. Our detailed, final responses are provided below to close these items definitively.

C1

Document Nomenclature — "E01" through "E39" Reference System

Neeyamo's Question

"Please clarify the basis for the nomenclature used for the reference documents mentioned in the 'Neeyamo compliance evidence package.' Additionally, please provide the actual reference documents listed for each control."

Our Definitive Clarification

The "E01" through "E39" nomenclature is our own internal evidence referencing system created specifically to organise and cross-reference the 39 supporting documents submitted alongside our audit questionnaire responses. It stands for "Evidence Document 01" through "Evidence Document 39".

How the system works:

E01Information Security Policy Bundle — all 6 policies in one document
E02ISO 27001/SOC2 Position Statement — our formal position on certification
E03NDA Confirmation — signed declaration that all staff have signed NDAs
E04Sub-Processing Declaration — confirms zero sub-processors for Neeyamo data
E05Staff Training Certificate — completion record for all staff
E06Employee BGV Declaration — all staff background check results (CLEAR)
E07Physical Security Declaration — office security controls confirmed
E08Third-Party Software Register — complete list of all tools used
E09Antivirus Confirmation — Windows Defender active status declaration
E10Patch Management Confirmation — all devices fully patched declaration
E11Firewall Confirmation — all 3 firewall layers active declaration
E12MFA Confirmation — Azure AD Security Defaults enforced declaration
E13Password Policy — full policy document (enforced by Azure AD)
E14Network Architecture — complete network topology description
E15Vulnerability Management Position — formal VAPT position statement
E16User Access Management — joiner/mover/leaver procedure
E17Data Access Policy — data classification and access rules
E18Backup Confirmation — Microsoft 365 backup statement
E19Data Retention Policy — full policy with retention schedule
E20IT Asset Disposal Procedure — secure disposal process
E21Business Continuity Plan — full BCP document
E22BCP Test Record — 2024 tabletop exercise record
E23Risk Register — current risk register with 10 risks assessed
E24Internal Compliance Review 2025 — annual review findings
E25Data Privacy Policy — UAE PDPL + GDPR aligned policy
E26ROPA — Record of Processing Activities register
E27DPIA — Data Protection Impact Assessment report
E28Data Subject Rights Procedure — DSAR handling process
E29Government Data Request Procedure — formal SOP
E30Cybersecurity Policy — NCA-aligned policy document
E31TOMS — Technical & Organizational Measures summary
E32Insurance Declaration — current coverage honest statement
E33Incident Response Plan — P1-P4 severity IRP
E34Trade License — company registration confirmation
E35VAT Registration — UAE VAT certificate confirmation
E36DPO Appointment — formal DPO designation letter
E37Government Portal Access Management — portal list + procedure
E38Physical Document Handling — chain of custody procedure
E39ESG Policy Statement — environmental and social commitments

How to Access the Actual Documents

All 39 documents (E01–E39) have been compiled into our Neeyamo Evidence Package submitted alongside this audit response. Each document is a self-contained declaration, policy, or confirmation specific to its control area. They are available as a single combined Word file or as individual documents upon request. These are original documents authored by Al Atta / AI Consultancy — they are not externally certified documents unless otherwise stated (e.g. E34 Trade License is a UAE government-issued document).

C2

Data Backup RPO vs BCP RPO — Discrepancy Resolved

Neeyamo's Question

"You noted a 4-hour RPO and a 24-hour RTO on the Data Backup page (Page 30). However, the Business Continuity Plan (Page 34) states both the RPO and RTO as 24 hours. Please clarify which figures are correct."

Our Definitive Clarification — CORRECTED

We acknowledge the inconsistency. This was a drafting error in our earlier submission. The correct and authoritative figures are:

Recovery Time Objective (RTO)

24 Hours

Maximum time to restore full business operations after a disruption. In practice, because all data is in Microsoft 365 cloud, actual recovery is typically under 2 hours — but we commit to 24 hours as a formal SLA.

Recovery Point Objective (RPO)

24 Hours

Maximum acceptable data loss window. Microsoft 365 performs continuous synchronisation meaning actual data loss risk is near zero. The "4 hours" figure in our earlier response was a drafting error and is hereby withdrawn and corrected to 24 hours.

Why the discrepancy occurred

Our initial questionnaire response (Q26 — Data Backup) referenced a technical aspiration of "4-hour RPO" based on Microsoft 365's continuous sync capability. However, our formal BCP document (E21) correctly states 24 hours as the committed contractual figure. For audit and compliance purposes, the BCP figure of 24-hour RPO / 24-hour RTO is the authoritative value. We have updated Q30 in this response accordingly. No separate document change is required — E21 (BCP) already reflects the correct figures.

Confirmed Final Position

RTO: 24 hours (formal commitment) | RPO: 24 hours (formal commitment). Evidence: E21 — Business Continuity Plan (authoritative document). The 4-hour figure is withdrawn from our submission.

C3

BCP Testing — "BCP-TEST-2024" Document Explained

Neeyamo's Question

"You mentioned that no formal testing has occurred. Could you please clarify which document you are referring to as 'BCP-TEST-2024'?"

Our Definitive Clarification

We wish to clarify an apparent contradiction in our submission and provide full transparency on this point.

What "BCP-TEST-2024" refers to

"BCP-TEST-2024" is the internal reference code we assigned to our 2024 Business Continuity tabletop exercise record — which is Evidence Document E22 (BCP Practical Test Record) in our Evidence Package. It is not an externally audited or certified document. It is our own internal record of the exercise conducted by the Director.

Clarification on "no formal testing"

If Neeyamo has seen a statement that "no formal testing has occurred," this refers to the fact that we have not conducted an externally facilitated, independently certified BCP test (such as a live DR failover test with third-party verification). What we HAVE conducted is a structured internal tabletop exercise in 2024, where the Director walked through a simulated system outage scenario, documented the recovery steps taken, and confirmed all critical services were restorable within the 24-hour RTO. This exercise is documented in E22.

What the 2024 Tabletop Exercise covered (E22 — BCP-TEST-2024)

Scenario tested: Complete office internet outage lasting 48+ hours
Scenario tested: Director laptop failure — complete data access via mobile device + Microsoft 365
Outcome: All Neeyamo data accessible within 15 minutes via Microsoft 365 on alternate device
Outcome: All email communications restored within 5 minutes
Outcome: No data loss — all data in Microsoft 365 cloud was fully intact
Outcome: Neeyamo notification procedure tested — template prepared and reviewed
Date of exercise: Q3 2024
Conducted by: Director (Irfan Farooq)
Next exercise scheduled: Q4 2026

Why a live DR failover test is not applicable

Our infrastructure is entirely cloud-based (Microsoft 365). There are no on-premise servers, databases, or physical infrastructure to failover. A live DR failover test in the traditional sense (spinning up a secondary data centre, restoring from tape backups, etc.) does not apply to our architecture. Microsoft 365 itself provides 99.9% uptime SLA and geo-redundant storage — the "DR" is handled by Microsoft at the platform level. Our tabletop exercise appropriately simulates the scenarios that are actually relevant to our setup: device failure, internet outage, and staff unavailability. E22 documents this proportionate testing approach.

Confirmed Final Position

BCP-TEST-2024 = E22 in our Evidence Package. It is a structured internal tabletop exercise record from Q3 2024. It demonstrates that our BCP procedures are operational and our recovery objectives (24-hour RTO/RPO) are achievable. We are happy to share E22 in full with Neeyamo upon request, and we are open to conducting a further exercise in the presence of a Neeyamo representative if required.

Closing Statement — April 2026

We trust the above clarifications fully address Neeyamo's outstanding questions. We have provided complete transparency on all three points: (1) the E01–E39 evidence nomenclature system is fully explained with a document-by-document index, (2) the RPO/RTO discrepancy is corrected and the authoritative figure of 24 hours for both is confirmed, and (3) BCP-TEST-2024 is explained as our 2024 internal tabletop exercise (E22). We are confident that no further clarification should be required on these points. Please do not hesitate to contact us directly: irfan@aiconsultancy.com | +971 50 699 0539.

Al Atta Consultations and Admin Studies | AI Consultancy | Ref: NEEYAMO-ICP-2025-UAE-001 | Prepared: 13/09/2026 | irfan@aiconsultancy.com | +971 50 699 0539

base44
Edit with Base44