We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. AI governance framework
AI governance, UAE

Your staff started using AI eighteen months ago. The governance conversation is starting now.

NIST states plainly that the risks posed by AI systems are in many ways unique. A governance framework gives you a defensible answer to what AI is in use, who approved it, what it touches and how you would know if it went wrong.

Book an AI governance reviewSee the framework
AI governance framework for UAE organisations
  • 4 functionsGovern, Map, Measure and Manage
  • 7 characteristicsOf trustworthy AI, per NIST
  • VoluntaryThe AI RMF is not a regulation
  • CertifiableISO/IEC 42001 where you need a certificate
The uncomfortable first finding

Almost every organisation has more AI in use than it thinks.

The inventory is where AI governance engagements start, and it is nearly always the part that surprises people.

  • AI features arrive inside products you already bought. A productivity suite adds summarisation, a support platform adds automated replies, a recruitment tool adds ranking. None of those went through a procurement decision about AI, because they were not sold as one.
  • Individuals adopt tools directly. A free tier, a personal account, a browser extension, a corporate card subscription under the approval threshold. The work these tools touch is real work, and the data they receive is real company data.
  • Then there is the AI your suppliers use on your behalf, which nobody sees at all. A vendor introducing a model into their processing changes what happens to your data without changing anything visible in their contract or their invoice.
  • None of this is misconduct and treating it as such is a mistake. It is what adoption looks like without a framework, and the useful response is an inventory and a decision process rather than a policy telling people to stop.
Ask us to run the inventory
What a framework gives you

Eight things an AI governance programme has to establish.

Most UAE organisations already have AI in production. It arrived through a productivity suite, a vendor feature release or an individual with a corporate card. Governance is the work of finding out what is actually there and deciding what happens next.

AI risk is genuinely different

NIST is direct about this: while there are myriad standards and best practices to help organisations mitigate the risks of traditional software or information based systems, the risks posed by AI systems are in many ways unique. Existing controls do not simply extend.

Govern is the cross-cutting function

It cultivates and implements a culture of risk management, and outlines processes, documents and organisational schemes that anticipate, identify and manage the risks a system can pose. NIST designs it to be infused throughout the other three functions rather than sitting alongside them.

Map establishes context before anything else

Map frames the risks related to an AI system and gives sufficient contextual knowledge about AI system impacts to inform an initial go or no-go decision. That decision point is the part organisations most often skip and most often wish they had not.

Measure means testing, not asserting

Measure employs quantitative, qualitative or mixed-method tools to analyse, assess, benchmark and monitor AI risk. When complete, objective, repeatable or scalable test, evaluation, verification and validation processes are in place, with metrics and methods behind them.

Manage allocates resources on a regular basis

Manage entails allocating risk resources to mapped and measured risks on a regular basis, resulting in plans for prioritising risk and for regular monitoring and improvement. The phrase that matters there is regular, because AI systems drift and so does their context.

Seven characteristics define trustworthy

Valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy enhanced, and fair with harmful biases managed. Those seven give a governance discussion something concrete to assess against.

ISO/IEC 42001 is the certifiable route

It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, defined as the interrelated elements intended to establish policies, objectives and processes for the responsible development, provision or use of AI systems.

Voluntary is not the same as optional

The AI RMF is voluntary, rights preserving, non sector specific and use case agnostic. It is not a law. But customers, insurers, regulators and boards increasingly ask what framework you follow, and voluntary frameworks are what that question is asking about.

The AI RMF Core

Four functions, and what each one produces.

The Core is composed of four functions, each broken into categories and subcategories that subdivide into specific actions and outcomes. Governance runs across all of them.
FunctionWhat it doesWhat you should have afterwards
GovernCultivates a culture of risk managementProcesses, documents and organisational schemes
MapEstablishes the context to frame risksEnough context for a go or no-go decision
MeasureAnalyses, benchmarks and monitors riskRepeatable test, evaluation, verification and validation
ManageAllocates risk resources regularlyPrioritisation plans and ongoing monitoring
Scope of GovernAll stages of AI risk managementInfused through the other three functions
Scope of Map, Measure, ManageSystem-specific contexts and lifecycle stagesApplied per system rather than once
Framework statusVoluntary, rights preservingNon sector specific and use case agnostic
CertificationNot certifiable in itselfISO/IEC 42001 where a certificate is required
How we approach it

Four things that make AI governance work rather than sit in a drawer.

Governance that people route around is worse than none, because it produces a documented position that is not true.

We inventory before we write policy

A policy written without knowing what is in use describes an organisation that does not exist. Map establishes the context to frame risks, and an inventory is what that context is built from, including AI inside products you did not buy as AI.

We build a route to yes

Govern is about cultivating a culture of risk management, not about refusal. A framework that gives people a way to get a tool approved in days is followed. One that only says no gets bypassed, and then nobody knows what is in use.

We insist on testing rather than assertion

Measure requires objective, repeatable or scalable test, evaluation, verification and validation processes with metrics and methods behind them. A vendor claim about accuracy is not a measurement, and treating it as one is how governance becomes theatre.

We are honest about what a framework does not do

The AI RMF is voluntary and it is not a regulation. It will not by itself satisfy a legal obligation such as the EU AI Act, and it is not a certificate. Where you need certification, ISO/IEC 42001 is the standard, and we will say which one you actually need.

How an engagement runs

Four phases across roughly ten to sixteen weeks.

The inventory and the decision process deliver most of the value in the first month. Certification, where it is wanted, extends the timeline considerably.
  1. 01
    Weeks 1 to 3

    Inventory what is actually in use

    Every AI capability in the estate, including features inside existing products, individually adopted tools and AI introduced by suppliers. This maps to the framing work in Map, and it is the input everything else depends on.

    • AI inventory across products, teams and suppliers
    • Data each system touches identified
    • Decisions each system influences documented
    • Unapproved adoption surfaced without blame
  2. 02
    Weeks 4 to 6

    Establish governance

    Who decides, on what basis, and with what record. Govern cultivates a culture of risk management and outlines the processes, documents and organisational schemes that anticipate, identify and manage risks, which in practice means an approval route people will actually use.

    • AI policy that permits rather than only prohibits
    • Approval route with named decision makers
    • Acceptable use guidance issued to staff
    • Register of approved systems established
  3. 03
    Weeks 7 to 11

    Assess systems against the characteristics

    Each significant system assessed for validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful biases managed. Measure requires testing rather than assertion.

    • Per system assessment against the seven characteristics
    • Test and evaluation approach defined per system
    • Risks recorded with owners and treatment decisions
    • Go or no-go decisions taken and recorded
  4. 04
    Weeks 12 to 16

    Operate and, where required, certify

    Manage allocates risk resources on a regular basis with plans for prioritisation, monitoring and improvement. Where a customer or a board requires a certificate, ISO/IEC 42001 provides the certifiable management system and this phase prepares for that assessment.

    • Monitoring and review cadence established
    • Supplier AI questions added to procurement
    • Board reporting format agreed
    • ISO/IEC 42001 readiness assessed where certification is wanted
Where this comes up

Six situations that trigger the conversation.

The trigger is rarely internal. It is usually a customer, an auditor, an insurer or an incident.

A customer questionnaire asks about AI use

It asks what AI systems process their data, what governance you apply and whether you hold a certification. Answering it accurately requires an inventory and a framework, and answering it inaccurately creates a contractual exposure that is hard to unwind.

A regulated firm deploying AI in a decision path

Where AI influences credit, claims, recruitment or eligibility, the characteristics that matter become accountability and transparency, explainability and interpretability, and fairness with harmful biases managed. Those need evidence, not intention.

A board asking what the organisation is exposed to

The honest first answer is usually that nobody knows, because AI arrived through product features and individual adoption rather than through a project. The inventory converts that into a list, and a list is something a board can act on.

A company that needs a certificate to win work

Where a customer requires ISO/IEC 42001, the framework becomes an AI management system with a certification path. Using a certified supplier helps, but the customer remains responsible for engaging an assessor to evaluate their own controls and implementation.

An institution using AI in assessment or admissions

Fairness with harmful biases managed, and explainability, move from desirable properties to the central question. A go or no-go decision informed by proper context is far easier to defend than a deployment that was never formally decided.

An organisation after an AI related incident

An incorrect output acted upon, confidential data entered into a public tool, or a supplier introducing a model without telling anybody. Governance built after an incident is possible, and it is considerably more expensive than governance built before one.

Three positions

How UAE organisations are handling AI governance.

The middle column is well intentioned and it does not work, because prohibition without a permitted route drives adoption underground rather than stopping it.
Inventory of AI in use
Framework based governanceMaintained
A policy that says noNone
Nothing yetNone
Approval route
Framework based governanceDefined and used
A policy that says noImplicitly refusal
Nothing yetAbsent
Risk assessed per system
Framework based governanceAgainst seven characteristics
A policy that says noNot at all
Nothing yetNot at all
Testing of outputs
Framework based governanceDefined and repeatable
A policy that says noNone
Nothing yetNone
Supplier AI use visible
Framework based governanceAsked in procurement
A policy that says noUnknown
Nothing yetUnknown
Staff behaviour
Framework based governanceUses approved tools
A policy that says noUses tools quietly
Nothing yetUses tools openly
Answer to a customer questionnaire
Framework based governanceDocumented
A policy that says noOverstated
Nothing yetNone
Path to certification
Framework based governanceISO/IEC 42001 ready
A policy that says noFar
Nothing yetFar
Board visibility
Framework based governanceRegular reporting
A policy that says noFalse comfort
Nothing yetNone
Effort to reach
Framework based governanceWeeks
A policy that says noAn afternoon
Nothing yetNone
Feature
Framework based governance
A policy that says no
Nothing yet
Inventory of AI in use
MaintainedNoneNone
Approval route
Defined and usedImplicitly refusalAbsent
Risk assessed per system
Against seven characteristicsNot at allNot at all
Testing of outputs
Defined and repeatableNoneNone
Supplier AI use visible
Asked in procurementUnknownUnknown
Staff behaviour
Uses approved toolsUses tools quietlyUses tools openly
Answer to a customer questionnaire
DocumentedOverstatedNone
Path to certification
ISO/IEC 42001 readyFarFar
Board visibility
Regular reportingFalse comfortNone
Effort to reach
WeeksAn afternoonNone
What the inventory usually finds

Four categories of AI that never went through any approval process.

The inventory is the first deliverable because the answer is consistently larger and stranger than anybody expects.

  • Features inside products you already own. Summarisation in a productivity suite, suggested replies in a support platform, ranking in a recruitment tool, anomaly detection in a monitoring product. None was bought as AI, so none went through an AI decision.
  • Individually adopted tools. A free tier signed up with a work email, a browser extension installed to speed up a routine task, a subscription paid on a personal card and expensed. The work these touch is real work and the data is real company data.
  • Embedded models in software you build. Where a development team calls a model API as part of a product feature, the organisation is a provider rather than only a user, which changes both the governance obligations and the customer facing disclosure position.
  • AI introduced by suppliers. A vendor adding a model to their processing changes what happens to your data without changing anything visible in their contract or their invoice. Asking is the only way to find out, which is why it belongs in procurement.
How an engagement runs

Five steps, and the first one is discovery rather than policy.

We do not open with a policy template. We open with finding out what is already running, because that is what determines whether the policy is realistic.
  1. 1

    Inventory AI across products, people and suppliers

    Features inside existing platforms, individually adopted tools, and AI introduced into supplier processing. For each one, what data it touches and what decisions it influences, which is what allows risk to be assessed rather than guessed at.

  2. 2

    Establish the governance function

    Named decision makers, an approval route with a realistic turnaround, a register of approved systems, and acceptable use guidance that tells people what they may do rather than only what they may not. Governance is cross cutting by design.

  3. 3

    Frame the risks per system

    Enough contextual knowledge about impacts to inform a genuine go or no-go decision, assessed against the seven characteristics of trustworthy AI. Systems that influence decisions about people get more scrutiny than systems that draft internal text.

  4. 4

    Define how each system will be measured

    Repeatable test, evaluation, verification and validation with metrics and methods behind them, proportionate to the risk. This is the step most programmes omit, and its absence is why many AI policies cannot answer how anybody would notice a problem.

  5. 5

    Operate the cycle and prepare for scrutiny

    Risk resources allocated on a regular basis, prioritisation plans, monitoring and improvement, supplier AI questions built into procurement, and readiness for ISO/IEC 42001 assessment where a certificate is genuinely required.

Straight answers

What UAE organisations ask about AI governance.

The NIST AI RMF is explicitly voluntary, rights preserving, non sector specific and use case agnostic. It is a framework rather than a law. Organisations adopt it because customers, boards and insurers ask what governance is applied, not because a regulator mandates it.

Because NIST states that while there are myriad standards to mitigate the risks of traditional software or information based systems, the risks posed by AI systems are in many ways unique. Existing controls help, and they do not cover output quality, bias or explainability.

Govern, Map, Measure and Manage. Govern cultivates a culture of risk management and is designed as a cross cutting function infused through the other three. Map, Measure and Manage apply in system specific contexts and at specific stages of the AI lifecycle.

Seven characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy enhanced, and fair with harmful biases managed. Assessing a system against those seven turns a vague discussion into a specific one.

Only if somebody requires a certificate. ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, and it is certifiable. The NIST framework is not, which is the practical difference between them.

The published definition is a set of interrelated or interacting elements of an organisation intended to establish policies and objectives, and processes to achieve those objectives, in relation to the responsible development, provision or use of AI systems.

It helps and it does not transfer. Microsoft states that where a business requires certification for implementations of its AI systems the certification can be used in the assessment, but the customer remains responsible for engaging an assessor to evaluate their own controls and implementation.

The inventory. Not the policy. A list of what AI is actually in use, what data each system touches and what decisions each influences. Every other decision depends on that list, and writing policy without it describes an organisation that does not exist.

By giving them an approved route rather than a prohibition. Adoption without governance is not misconduct, it is what happens when there is no way to get something approved. A route to yes with a short turnaround brings that usage back into view.

Measure requires objective, repeatable or scalable test, evaluation, verification and validation processes, including metrics, methods and methodologies. The form varies by system, but a vendor accuracy claim is not a measurement and should not be recorded as one.

Yes, and it belongs in procurement rather than in an annual review. A supplier introducing a model into their processing changes what happens to your data without changing anything visible in the contract, so the question has to be asked rather than inferred.

The framework is use case agnostic and applies to organisations of any size, but proportionality is the point. A small company needs an inventory, an approval route and a review cadence. It does not need the apparatus of a regulated institution.

A voluntary framework is not a legal obligation. If you place AI systems on the EU market or your output is used there, the Act imposes specific duties. Governance built on the framework makes meeting them easier, and it does not substitute for them.

The inventory and the approval route deliver most of the practical value within the first month, because they change what happens day to day. Assessment, measurement and certification readiness extend beyond that, and they build on the same foundation.

We scope by organisation size and how many AI systems the inventory surfaces, which is usually more than expected. The free first step: ask three teams what AI tools they used this week, and compare that list against what has been formally approved.

What is permitted, by whom, with what data, and how to get something approved. A policy consisting only of prohibitions drives usage underground, which leaves the organisation with the same exposure and less visibility of it than before.

By what they touch and what they influence. A system drafting internal text carries different risk from one influencing decisions about people, and the seven trustworthy characteristics give a structured way to assess each against its context.

Somebody from legal, somebody from security, somebody who understands the data, and somebody from the business that wants to use it. Groups without that last participant tend to produce decisions the organisation then routes around.

Risk resources are allocated to mapped and measured risks on a regular basis, with plans for prioritising risk and for regular monitoring and improvement. In practice that means a scheduled review, not a review triggered by something going wrong.

Assess it rather than banning it reflexively. If it passes, approve it and put it on the register. If it does not, explain why and offer an alternative, because withdrawal without a replacement is what teaches people not to declare the next one.
Governance check

Fifteen questions a board is entitled to ask.

If the first group cannot be answered, the answer to the rest is unknown rather than no, and unknown is the harder position to defend.

What exists

  • Can we list the AI systems in use?
    Including features inside products.
  • Do we know what data each touches?
    The first question anybody asks.
  • Do we know which decisions they influence?
    This drives the risk level.
  • Do our suppliers use AI on our data?
    Often invisible.
  • Who approved each of them?
    Often nobody.

How decisions get made

  • Is there an approval route?
    One people will actually use.
  • Is there a go or no-go decision point?
    Map exists to inform it.
  • Who owns each approved system?
    A named person.
  • Is acceptable use published?
    Permission, not just prohibition.
  • Are decisions recorded?
    The record is the governance.

How you would know

  • How is output quality tested?
    Measure means testing.
  • How would we detect drift?
    Context changes over time.
  • Who reviews, and how often?
    On a regular basis.
  • What happens when something goes wrong?
    Decide before it does.
  • Do we need a certificate?
    ISO/IEC 42001 if so.
Related reading

The pages around this one.

EU AI Act compliance

Where AI governance becomes a legal obligation.

Learn more

UAE PDPL compliance

The personal data law behind most AI data questions.

Learn more

IT risk assessment

The wider risk process AI governance sits inside.

Learn more
Next step

Ask three teams what AI tools they used this week.

Then compare that list against what has been formally approved. The gap between those two lists is your AI governance programme, and it takes an afternoon to find.

Book an AI governance reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

EU AI Act compliance

Why UAE companies with no EU entity are still in scope.

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

Security Policy Development

Policies you can actually comply with

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

Third Party Risk Audit

Who can actually reach your systems, and what to do about it

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy