Governance
AI Governance Toolkit
A practical set of policies, templates and routines for using AI responsibly: who decides, how use cases are classified by risk, how systems are documented, how people stay in control and how incidents are handled. Proportionate by design, and built to work alongside applicable regulation.
Purpose
Why it exists
Governance should make it easier to use AI well, not harder to use it at all. The toolkit provides the minimum set of instruments an organisation needs, scaled to the risk of each use case: light for an internal drafting assistant, stricter for a system that influences decisions about people.
It is designed with widely used approaches in mind, including the risk-based classification of the EU AI Act, the AI ethics principles published by SDAIA and data protection requirements such as Saudi Arabia’s Personal Data Protection Law. It does not replace legal advice, and adopting it does not by itself meet those requirements. What it gives your legal, risk and technology teams is a shared, working structure.
Instruments are introduced when the lifecycle needs them: policy and classification before building, documentation and oversight while building, monitoring and incident response once the system runs.
What it needs
- 01Existing policies on information security, data protection and risk
- 02Current and planned AI use cases
- 03The people accountable for legal, risk, data and technology
- 04Applicable sector rules and regulator expectations
Method
How it works
| Instrument | 01Assess | 02Advise | 03Build | 04Enable | 05Operate | 06Scale |
|---|---|---|---|---|---|---|
| Policy and roles | Assess: does not apply | Advise: applies | Build: does not apply | Enable: applies | Operate: does not apply | Scale: does not apply |
| Risk classification | Assess: applies | Advise: applies | Build: applies | Enable: does not apply | Operate: does not apply | Scale: does not apply |
| System documentation | Assess: does not apply | Advise: does not apply | Build: applies | Enable: applies | Operate: does not apply | Scale: does not apply |
| Human oversight | Assess: does not apply | Advise: does not apply | Build: applies | Enable: does not apply | Operate: applies | Scale: does not apply |
| Monitoring and incidents | Assess: does not apply | Advise: does not apply | Build: does not apply | Enable: does not apply | Operate: applies | Scale: applies |
| Periodic review | Assess: does not apply | Advise: does not apply | Build: does not apply | Enable: does not apply | Operate: applies | Scale: applies |
Policy and roles
- Advise
- Enable
Risk classification
- Assess
- Advise
- Build
System documentation
- Build
- Enable
Human oversight
- Build
- Operate
Monitoring and incidents
- Operate
- Scale
Periodic review
- Operate
- Scale
Step by step
The steps in detail
01
Policy and roles
An AI policy with acceptable-use rules, and clear roles for approving, owning and overseeing AI systems.
02
Risk classification
A short questionnaire that places each use case in a risk tier, which then sets the controls that apply.
03
System documentation
Templates that record the purpose, data sources, model choices, evaluation results and known limitations of each system.
04
Human oversight
Defined points where people review, approve or override AI outputs, with escalation paths for uncertain cases.
05
Monitoring and incidents
What is monitored in production (quality, drift, misuse and cost), who is alerted, and how incidents are handled and learned from.
06
Periodic review
A review cadence per risk tier to confirm that systems still serve their purpose and that the controls work.
Outputs
What you receive
- 01
AI policy and acceptable-use rules
- 02
Risk classification questionnaire and tier definitions
- 03
System documentation templates
- 04
Oversight and escalation procedures
- 05
Monitoring and incident response playbook
- 06
Review calendar and responsibilities
Lifecycle position
Where it sits in an engagement
Used in Advise, Build and Operate.
The full lifecycle01
Assess
02
Advise
Stages where this framework is used
03
Build
Stages where this framework is used
04
Enable
05
Operate
Stages where this framework is used
06
Scale
In practice
Where it is applied
Offers that use it
AI Strategy & Transformation Roadmap
A strategy and roadmap that link AI and digital initiatives to business objectives: prioritised use cases, target architecture, governance, capability needs and a phased investment plan that leadership can approve and track. Suited to organisations moving from isolated pilots to a coordinated transformation programme.
from SAR 49,500
Request a proposalEnterprise AI System
A production-grade AI system integrated into core operations, such as document intelligence, forecasting, computer vision or a knowledge assistant, engineered with monitoring, access control and governance from the start. Suited to organisations ready to move a proven use case into daily operations.
from SAR 120,000
Request a proposalManaged AI Partnership
Ongoing operation and improvement of your AI and data systems after go-live: monitoring performance, data quality, cost and model behaviour, handling changes and planning the next improvements with your team. Suited to organisations that want their systems to keep delivering value without first building a full in-house operations team.
from SAR 15,000
Request a proposal
Billed in Saudi riyals. Starting prices are confirmed, together with the final scope and any applicable taxes, in your proposal or booking.
See all pricesPractices
Related capabilities
Related
Frameworks used alongside it
Enterprise AI Architecture
A reference architecture for running AI inside an enterprise estate: channels, orchestration and agents, models and retrieval, and data and integration, all within your security boundary, with identity, observability and governance across every layer.
MethodologyAdvise, Build and Scale
NLAI system stack
The four layers of a complete AI system: data infrastructure, AI systems, an intelligence layer and the operational outcomes they serve. We use it to check that a solution is designed as a whole, not as an isolated model.
MethodologyAdvise, Build and Scale
Engineering principles
Four principles that shape every system we design and build: outcome-driven, production-minded, responsible end to end, and engineered for your context.
MethodologyBuild, Operate and Scale
Next step
Governance that fits your risk
Discuss which instruments your organisation needs first, and how to introduce them without slowing adoption.