Before you start

This checklist is a way to take stock, not a test you can fail. Most organisations, including large ones, score lower than they expect the first time. That is normal and useful: it shows you where to start.

Take 20–30 minutes, ideally with two or three colleagues from different parts of the business. For each question, choose:

  • 0: Not yet, or we don't know.
  • 1: Partly, or in some parts of the business.
  • 2: Yes, consistently and written down.

There are 30 questions, so the maximum score is 60. The questions are the platform's own. They draw on widely used public frameworks, especially the US NIST AI Risk Management Framework, whose four functions are Govern, Map, Measure and Manage (NIST) [F], and ISO/IEC 42001, the international standard for AI management systems published in December 2023 (ISO) [S]. NIST also offers an Arabic translation of its framework (NIST) [F].

This is general guidance, not legal advice. Laws differ between GCC states and free zones.


1. Strategy and purpose (4 questions)

#Question0 / 1 / 2
1.1We can say, in one or two sentences, what we want AI to help our customers or staff achieve.
1.2We have listed our three to five most time-consuming or error-prone tasks.
1.3Leadership (owner, board or family council) has agreed who is responsible for AI decisions.
1.4We measure a baseline (time, cost, errors, customer satisfaction) before trying new tools, so we can tell if they help.

2. Data (4 questions)

#Question0 / 1 / 2
2.1Our key records (customers, products, invoices, contracts) are digital, not only on paper.
2.2Each key dataset has one agreed "master" copy, not several conflicting spreadsheets.
2.3We know what personal data we hold, why we hold it and who can access it.
2.4We know where our data is stored (which country and cloud region) and whether any of it must stay in-country. Examples: health data in the UAE under Federal Law No. 2 of 2019, Art. 13 (DLA Piper); the UAE e-invoicing framework requires records to be kept in the UAE (KPMG).

3. Processes (4 questions)

#Question0 / 1 / 2
3.1Our main processes (for example, order-to-cash or enquiry-to-resolution) are written down step by step.
3.2We have simplified at least one process before automating it.
3.3We issue and receive invoices electronically, and we know our e-invoicing obligations: ZATCA in Saudi Arabia (ZATCA) and, in the UAE, B2B phases from 2027 (KPMG).
3.4For any automated step, we know the point at which a person reviews or approves.

4. People and skills (4 questions)

#Question0 / 1 / 2
4.1Staff have had basic, practical training in using AI tools safely (what to share, what not to, and how to check outputs).
4.2We have told staff honestly how AI will and won't change their roles, and invited their ideas.
4.3At least one person has time set aside to lead AI and digital improvements.
4.4Our AI plans are consistent with our national-workforce commitments, such as Emiratisation targets for UAE firms with 50+ employees (Gulf News) or equivalent programmes in other GCC states.

5. Technology (3 questions)

#Question0 / 1 / 2
5.1Our core systems (accounting, sales, operations) are cloud-based or can connect to other tools (for example, through APIs).
5.2We keep a simple list of the software and AI tools we use, including free ones staff have signed up for.
5.3We choose tools with good Arabic and English support where customers or staff need both.

6. Governance and law (4 questions)

#Question0 / 1 / 2
6.1We know which data-protection law applies to us: UAE federal PDPL (Decree-Law 45/2021), DIFC or ADGM rules, Saudi PDPL, Bahrain Law 30/2018, Oman Royal Decree 6/2022, Qatar Law 13/2016 (or QFC rules), or Kuwait's CITRA regulation. See the roadmap.
6.2For every AI system we use, there is a named owner who is accountable for it.
6.3We have written "never" rules: decisions AI must not make on its own (for example, refunds above a limit, hiring decisions or anything affecting a person's legal rights). Saudi PDPL requires consent for decisions based solely on automated processing, and the UAE PDPL gives a right to object to such decisions (HFW; DLA Piper).
6.4If we are regulated (for example, by a central bank or free-zone authority), we have read the relevant AI guidance, such as the CBUAE's February 2026 Guidance Note (CBUAE) or DIFC Data Protection Regulation 10 (Mayer Brown).

7. Security and resilience (4 questions)

#Question0 / 1 / 2
7.1We have backups of critical data in more than one location or cloud region, and we have tested restoring them. (In 2026, AWS said it could not restore some data that had been hosted in only one affected Gulf location, fact base A3.)
7.2We use multi-factor authentication and remove access promptly when people leave.
7.3We have a simple plan for running the business if a key system, supplier or shipping route becomes unavailable.
7.4Staff know not to paste confidential or personal data into public AI tools unless approved.

8. Customers and trust (3 questions)

#Question0 / 1 / 2
8.1Customers are told when they are dealing with an AI system, in Arabic and English where relevant.
8.2Customers can always reach a person, and complaints about automated decisions are reviewed by a person.
8.3We check AI outputs for accuracy, fairness and cultural appropriateness before they reach customers.

What your score means

ScoreWhere you areA calm next step
0–15Laying foundations. Most businesses start here.Focus on the basics: digital records, one clean customer list, backups in two places, and staff guidance on safe AI use. See roadmap stages 0–1.
16–30Getting organised. Some good foundations are in place.Pick one well-understood process, simplify it and try a supervised tool. Write your "never" rules. Roadmap stages 1–3.
31–45Ready for careful AI use. You have data, processes and ownership.Introduce AI assistants in one or two areas with measurement and human approval. Start an AI inventory. Roadmap stages 3–4.
46–60Ready to explore agentic workflows. You have strong governance and data.Pilot a bounded agent with clear limits, logs and a stop mechanism. Review regularly. Roadmap stages 4–5.

Also look at your lowest area, not just the total. A low score in Governance and law (section 6) or Security and resilience (section 7) matters more than a high score elsewhere. Fix those first.

How the checklist maps to the NIST AI RMF

NIST function (NIST's definition, summarised)Checklist sections
Govern: a culture of risk management, with roles and policies1.3, 4.2–4.4, 6.1–6.4
Map: understand the context and the risks of each AI use1.1–1.2, 2.3–2.4, 3.1, 3.4
Measure: assess, test and track AI risks and performance1.4, 8.3
Manage: prioritise and act on risks, including incident response5.2, 7.1–7.4, 8.1–8.2

The mapping is the platform's own and intended as a guide, not a formal crosswalk.