The 7 components
- AI usage policy. What employees can and cannot do with AI tools. Includes acceptable data types, prohibited use cases, approval processes, and consequences.
- AI inventory & risk register. A list of every AI system in use — vendor, internal, embedded in third-party software — scored for risk (data sensitivity, decision impact, customer exposure).
- Model risk management. Pre-deployment review, ongoing monitoring, bias and fairness checks, drift detection, retraining triggers. Standard practice for high-risk AI.
- Vendor & third-party AI risk. Due diligence on AI vendors — security posture, DPAs, sub-processors, AI model provenance, training data origin. Critical given AI is increasingly embedded in SaaS.
- Audit evidence & logging. What prompts went in, what outputs came out, who saw them, what action was taken. Required for incident response and regulatory inquiry.
- Role-based training. AI literacy for all staff, governance-specific training for risk/compliance/audit teams, technical training for engineering teams. Cannot govern what staff do not understand.
- Board-level reporting. Quarterly or biannual updates to the board (or board risk committee) on AI risk posture, incidents, and program maturity.
UAE regulators & standards to align to
| Regulator / Standard | Applies to |
|---|---|
| UAE PDPL 2021 | All UAE-based AI handling personal data |
| CBUAE | UAE banks, payments, NBFCs |
| SCA | Capital markets, asset managers, brokers |
| DHA, DOH Abu Dhabi, MOHAP | Healthcare providers, SaMD developers |
| DIFC & ADGM Data Protection | Organisations in DIFC / ADGM free zones |
| ISO 42001 | AI management system — voluntary, increasingly expected |
| NIST AI RMF | US-aligned organisations, cross-border operations |
| EU AI Act | UAE organisations selling AI into EU markets |
How AI Guru helps
- AI Governance & Ethics training — 1–2 day program for risk, compliance, audit, and legal leads.
- Governance program design — 90-day engagement to build all 7 components for your organisation.
- Board-level reporting framework — Quarterly AI risk posture template, aligned to your regulators.
- AssuranceOps — AI Guru product delivering SOC 2 evidence packets in 10 days. Reusable for UAE-relevant audit needs.
- AI Governance Diagnostic — Free 5-minute self-assessment at diagnostic.aiguru.one.
Related: Governance services overview.