Before you start
This checklist is a way to take stock, not a test you can fail. Most organisations, including large ones, score lower than they expect the first time. That is normal and useful: it shows you where to start.
Take 20–30 minutes, ideally with two or three colleagues from different parts of the business. For each question, choose:
- 0: Not yet, or we don't know.
- 1: Partly, or in some parts of the business.
- 2: Yes, consistently and written down.
There are 30 questions, so the maximum score is 60. The questions are the platform's own. They draw on widely used public frameworks, especially the US NIST AI Risk Management Framework, whose four functions are Govern, Map, Measure and Manage (NIST) [F], and ISO/IEC 42001, the international standard for AI management systems published in December 2023 (ISO) [S]. NIST also offers an Arabic translation of its framework (NIST) [F].
This is general guidance, not legal advice. Laws differ between GCC states and free zones.
1. Strategy and purpose (4 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 1.1 | We can say, in one or two sentences, what we want AI to help our customers or staff achieve. | |
| 1.2 | We have listed our three to five most time-consuming or error-prone tasks. | |
| 1.3 | Leadership (owner, board or family council) has agreed who is responsible for AI decisions. | |
| 1.4 | We measure a baseline (time, cost, errors, customer satisfaction) before trying new tools, so we can tell if they help. | |
2. Data (4 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 2.1 | Our key records (customers, products, invoices, contracts) are digital, not only on paper. | |
| 2.2 | Each key dataset has one agreed "master" copy, not several conflicting spreadsheets. | |
| 2.3 | We know what personal data we hold, why we hold it and who can access it. | |
| 2.4 | We know where our data is stored (which country and cloud region) and whether any of it must stay in-country. Examples: health data in the UAE under Federal Law No. 2 of 2019, Art. 13 (DLA Piper); the UAE e-invoicing framework requires records to be kept in the UAE (KPMG). | |
3. Processes (4 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 3.1 | Our main processes (for example, order-to-cash or enquiry-to-resolution) are written down step by step. | |
| 3.2 | We have simplified at least one process before automating it. | |
| 3.3 | We issue and receive invoices electronically, and we know our e-invoicing obligations: ZATCA in Saudi Arabia (ZATCA) and, in the UAE, B2B phases from 2027 (KPMG). | |
| 3.4 | For any automated step, we know the point at which a person reviews or approves. | |
4. People and skills (4 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 4.1 | Staff have had basic, practical training in using AI tools safely (what to share, what not to, and how to check outputs). | |
| 4.2 | We have told staff honestly how AI will and won't change their roles, and invited their ideas. | |
| 4.3 | At least one person has time set aside to lead AI and digital improvements. | |
| 4.4 | Our AI plans are consistent with our national-workforce commitments, such as Emiratisation targets for UAE firms with 50+ employees (Gulf News) or equivalent programmes in other GCC states. | |
5. Technology (3 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 5.1 | Our core systems (accounting, sales, operations) are cloud-based or can connect to other tools (for example, through APIs). | |
| 5.2 | We keep a simple list of the software and AI tools we use, including free ones staff have signed up for. | |
| 5.3 | We choose tools with good Arabic and English support where customers or staff need both. | |
6. Governance and law (4 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 6.1 | We know which data-protection law applies to us: UAE federal PDPL (Decree-Law 45/2021), DIFC or ADGM rules, Saudi PDPL, Bahrain Law 30/2018, Oman Royal Decree 6/2022, Qatar Law 13/2016 (or QFC rules), or Kuwait's CITRA regulation. See the roadmap. | |
| 6.2 | For every AI system we use, there is a named owner who is accountable for it. | |
| 6.3 | We have written "never" rules: decisions AI must not make on its own (for example, refunds above a limit, hiring decisions or anything affecting a person's legal rights). Saudi PDPL requires consent for decisions based solely on automated processing, and the UAE PDPL gives a right to object to such decisions (HFW; DLA Piper). | |
| 6.4 | If we are regulated (for example, by a central bank or free-zone authority), we have read the relevant AI guidance, such as the CBUAE's February 2026 Guidance Note (CBUAE) or DIFC Data Protection Regulation 10 (Mayer Brown). | |
7. Security and resilience (4 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 7.1 | We have backups of critical data in more than one location or cloud region, and we have tested restoring them. (In 2026, AWS said it could not restore some data that had been hosted in only one affected Gulf location, fact base A3.) | |
| 7.2 | We use multi-factor authentication and remove access promptly when people leave. | |
| 7.3 | We have a simple plan for running the business if a key system, supplier or shipping route becomes unavailable. | |
| 7.4 | Staff know not to paste confidential or personal data into public AI tools unless approved. | |
8. Customers and trust (3 questions)
| # | Question | 0 / 1 / 2 |
|---|
| 8.1 | Customers are told when they are dealing with an AI system, in Arabic and English where relevant. | |
| 8.2 | Customers can always reach a person, and complaints about automated decisions are reviewed by a person. | |
| 8.3 | We check AI outputs for accuracy, fairness and cultural appropriateness before they reach customers. | |
What your score means
| Score | Where you are | A calm next step |
|---|
| 0–15 | Laying foundations. Most businesses start here. | Focus on the basics: digital records, one clean customer list, backups in two places, and staff guidance on safe AI use. See roadmap stages 0–1. |
| 16–30 | Getting organised. Some good foundations are in place. | Pick one well-understood process, simplify it and try a supervised tool. Write your "never" rules. Roadmap stages 1–3. |
| 31–45 | Ready for careful AI use. You have data, processes and ownership. | Introduce AI assistants in one or two areas with measurement and human approval. Start an AI inventory. Roadmap stages 3–4. |
| 46–60 | Ready to explore agentic workflows. You have strong governance and data. | Pilot a bounded agent with clear limits, logs and a stop mechanism. Review regularly. Roadmap stages 4–5. |
Also look at your lowest area, not just the total. A low score in Governance and law (section 6) or Security and resilience (section 7) matters more than a high score elsewhere. Fix those first.
How the checklist maps to the NIST AI RMF
| NIST function (NIST's definition, summarised) | Checklist sections |
|---|
| Govern: a culture of risk management, with roles and policies | 1.3, 4.2–4.4, 6.1–6.4 |
| Map: understand the context and the risks of each AI use | 1.1–1.2, 2.3–2.4, 3.1, 3.4 |
| Measure: assess, test and track AI risks and performance | 1.4, 8.3 |
| Manage: prioritise and act on risks, including incident response | 5.2, 7.1–7.4, 8.1–8.2 |
The mapping is the platform's own and intended as a guide, not a formal crosswalk.