Your staff started using AI eighteen months ago. The governance conversation is starting now.
NIST states plainly that the risks posed by AI systems are in many ways unique. A governance framework gives you a defensible answer to what AI is in use, who approved it, what it touches and how you would know if it went wrong.

- 4 functionsGovern, Map, Measure and Manage
- 7 characteristicsOf trustworthy AI, per NIST
- VoluntaryThe AI RMF is not a regulation
- CertifiableISO/IEC 42001 where you need a certificate
Almost every organisation has more AI in use than it thinks.
The inventory is where AI governance engagements start, and it is nearly always the part that surprises people.
- AI features arrive inside products you already bought. A productivity suite adds summarisation, a support platform adds automated replies, a recruitment tool adds ranking. None of those went through a procurement decision about AI, because they were not sold as one.
- Individuals adopt tools directly. A free tier, a personal account, a browser extension, a corporate card subscription under the approval threshold. The work these tools touch is real work, and the data they receive is real company data.
- Then there is the AI your suppliers use on your behalf, which nobody sees at all. A vendor introducing a model into their processing changes what happens to your data without changing anything visible in their contract or their invoice.
- None of this is misconduct and treating it as such is a mistake. It is what adoption looks like without a framework, and the useful response is an inventory and a decision process rather than a policy telling people to stop.
Eight things an AI governance programme has to establish.
AI risk is genuinely different
NIST is direct about this: while there are myriad standards and best practices to help organisations mitigate the risks of traditional software or information based systems, the risks posed by AI systems are in many ways unique. Existing controls do not simply extend.
Govern is the cross-cutting function
It cultivates and implements a culture of risk management, and outlines processes, documents and organisational schemes that anticipate, identify and manage the risks a system can pose. NIST designs it to be infused throughout the other three functions rather than sitting alongside them.
Map establishes context before anything else
Map frames the risks related to an AI system and gives sufficient contextual knowledge about AI system impacts to inform an initial go or no-go decision. That decision point is the part organisations most often skip and most often wish they had not.
Measure means testing, not asserting
Measure employs quantitative, qualitative or mixed-method tools to analyse, assess, benchmark and monitor AI risk. When complete, objective, repeatable or scalable test, evaluation, verification and validation processes are in place, with metrics and methods behind them.
Manage allocates resources on a regular basis
Manage entails allocating risk resources to mapped and measured risks on a regular basis, resulting in plans for prioritising risk and for regular monitoring and improvement. The phrase that matters there is regular, because AI systems drift and so does their context.
Seven characteristics define trustworthy
Valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy enhanced, and fair with harmful biases managed. Those seven give a governance discussion something concrete to assess against.
ISO/IEC 42001 is the certifiable route
It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system, defined as the interrelated elements intended to establish policies, objectives and processes for the responsible development, provision or use of AI systems.
Voluntary is not the same as optional
The AI RMF is voluntary, rights preserving, non sector specific and use case agnostic. It is not a law. But customers, insurers, regulators and boards increasingly ask what framework you follow, and voluntary frameworks are what that question is asking about.
Four functions, and what each one produces.
| Function | What it does | What you should have afterwards | |
|---|---|---|---|
| Govern | Cultivates a culture of risk management | Processes, documents and organisational schemes | |
| Map | Establishes the context to frame risks | Enough context for a go or no-go decision | |
| Measure | Analyses, benchmarks and monitors risk | Repeatable test, evaluation, verification and validation | |
| Manage | Allocates risk resources regularly | Prioritisation plans and ongoing monitoring | |
| Scope of Govern | All stages of AI risk management | Infused through the other three functions | |
| Scope of Map, Measure, Manage | System-specific contexts and lifecycle stages | Applied per system rather than once | |
| Framework status | Voluntary, rights preserving | Non sector specific and use case agnostic | |
| Certification | Not certifiable in itself | ISO/IEC 42001 where a certificate is required |
Four things that make AI governance work rather than sit in a drawer.
We inventory before we write policy
A policy written without knowing what is in use describes an organisation that does not exist. Map establishes the context to frame risks, and an inventory is what that context is built from, including AI inside products you did not buy as AI.
We build a route to yes
Govern is about cultivating a culture of risk management, not about refusal. A framework that gives people a way to get a tool approved in days is followed. One that only says no gets bypassed, and then nobody knows what is in use.
We insist on testing rather than assertion
Measure requires objective, repeatable or scalable test, evaluation, verification and validation processes with metrics and methods behind them. A vendor claim about accuracy is not a measurement, and treating it as one is how governance becomes theatre.
We are honest about what a framework does not do
The AI RMF is voluntary and it is not a regulation. It will not by itself satisfy a legal obligation such as the EU AI Act, and it is not a certificate. Where you need certification, ISO/IEC 42001 is the standard, and we will say which one you actually need.
Four phases across roughly ten to sixteen weeks.
- 01Weeks 1 to 3
Inventory what is actually in use
Every AI capability in the estate, including features inside existing products, individually adopted tools and AI introduced by suppliers. This maps to the framing work in Map, and it is the input everything else depends on.
- AI inventory across products, teams and suppliers
- Data each system touches identified
- Decisions each system influences documented
- Unapproved adoption surfaced without blame
- 02Weeks 4 to 6
Establish governance
Who decides, on what basis, and with what record. Govern cultivates a culture of risk management and outlines the processes, documents and organisational schemes that anticipate, identify and manage risks, which in practice means an approval route people will actually use.
- AI policy that permits rather than only prohibits
- Approval route with named decision makers
- Acceptable use guidance issued to staff
- Register of approved systems established
- 03Weeks 7 to 11
Assess systems against the characteristics
Each significant system assessed for validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful biases managed. Measure requires testing rather than assertion.
- Per system assessment against the seven characteristics
- Test and evaluation approach defined per system
- Risks recorded with owners and treatment decisions
- Go or no-go decisions taken and recorded
- 04Weeks 12 to 16
Operate and, where required, certify
Manage allocates risk resources on a regular basis with plans for prioritisation, monitoring and improvement. Where a customer or a board requires a certificate, ISO/IEC 42001 provides the certifiable management system and this phase prepares for that assessment.
- Monitoring and review cadence established
- Supplier AI questions added to procurement
- Board reporting format agreed
- ISO/IEC 42001 readiness assessed where certification is wanted
Six situations that trigger the conversation.
A customer questionnaire asks about AI use
It asks what AI systems process their data, what governance you apply and whether you hold a certification. Answering it accurately requires an inventory and a framework, and answering it inaccurately creates a contractual exposure that is hard to unwind.
A regulated firm deploying AI in a decision path
Where AI influences credit, claims, recruitment or eligibility, the characteristics that matter become accountability and transparency, explainability and interpretability, and fairness with harmful biases managed. Those need evidence, not intention.
A board asking what the organisation is exposed to
The honest first answer is usually that nobody knows, because AI arrived through product features and individual adoption rather than through a project. The inventory converts that into a list, and a list is something a board can act on.
A company that needs a certificate to win work
Where a customer requires ISO/IEC 42001, the framework becomes an AI management system with a certification path. Using a certified supplier helps, but the customer remains responsible for engaging an assessor to evaluate their own controls and implementation.
An institution using AI in assessment or admissions
Fairness with harmful biases managed, and explainability, move from desirable properties to the central question. A go or no-go decision informed by proper context is far easier to defend than a deployment that was never formally decided.
An organisation after an AI related incident
An incorrect output acted upon, confidential data entered into a public tool, or a supplier introducing a model without telling anybody. Governance built after an incident is possible, and it is considerably more expensive than governance built before one.
How UAE organisations are handling AI governance.
| Feature | Framework based governance | A policy that says no | Nothing yet |
|---|---|---|---|
Inventory of AI in use | Maintained | None | None |
Approval route | Defined and used | Implicitly refusal | Absent |
Risk assessed per system | Against seven characteristics | Not at all | Not at all |
Testing of outputs | Defined and repeatable | None | None |
Supplier AI use visible | Asked in procurement | Unknown | Unknown |
Staff behaviour | Uses approved tools | Uses tools quietly | Uses tools openly |
Answer to a customer questionnaire | Documented | Overstated | None |
Path to certification | ISO/IEC 42001 ready | Far | Far |
Board visibility | Regular reporting | False comfort | None |
Effort to reach | Weeks | An afternoon | None |
Four categories of AI that never went through any approval process.
The inventory is the first deliverable because the answer is consistently larger and stranger than anybody expects.
- Features inside products you already own. Summarisation in a productivity suite, suggested replies in a support platform, ranking in a recruitment tool, anomaly detection in a monitoring product. None was bought as AI, so none went through an AI decision.
- Individually adopted tools. A free tier signed up with a work email, a browser extension installed to speed up a routine task, a subscription paid on a personal card and expensed. The work these touch is real work and the data is real company data.
- Embedded models in software you build. Where a development team calls a model API as part of a product feature, the organisation is a provider rather than only a user, which changes both the governance obligations and the customer facing disclosure position.
- AI introduced by suppliers. A vendor adding a model to their processing changes what happens to your data without changing anything visible in their contract or their invoice. Asking is the only way to find out, which is why it belongs in procurement.
Five steps, and the first one is discovery rather than policy.
- 1
Inventory AI across products, people and suppliers
Features inside existing platforms, individually adopted tools, and AI introduced into supplier processing. For each one, what data it touches and what decisions it influences, which is what allows risk to be assessed rather than guessed at.
- 2
Establish the governance function
Named decision makers, an approval route with a realistic turnaround, a register of approved systems, and acceptable use guidance that tells people what they may do rather than only what they may not. Governance is cross cutting by design.
- 3
Frame the risks per system
Enough contextual knowledge about impacts to inform a genuine go or no-go decision, assessed against the seven characteristics of trustworthy AI. Systems that influence decisions about people get more scrutiny than systems that draft internal text.
- 4
Define how each system will be measured
Repeatable test, evaluation, verification and validation with metrics and methods behind them, proportionate to the risk. This is the step most programmes omit, and its absence is why many AI policies cannot answer how anybody would notice a problem.
- 5
Operate the cycle and prepare for scrutiny
Risk resources allocated on a regular basis, prioritisation plans, monitoring and improvement, supplier AI questions built into procurement, and readiness for ISO/IEC 42001 assessment where a certificate is genuinely required.
What UAE organisations ask about AI governance.
Fifteen questions a board is entitled to ask.
What exists
- Can we list the AI systems in use?Including features inside products.
- Do we know what data each touches?The first question anybody asks.
- Do we know which decisions they influence?This drives the risk level.
- Do our suppliers use AI on our data?Often invisible.
- Who approved each of them?Often nobody.
How decisions get made
- Is there an approval route?One people will actually use.
- Is there a go or no-go decision point?Map exists to inform it.
- Who owns each approved system?A named person.
- Is acceptable use published?Permission, not just prohibition.
- Are decisions recorded?The record is the governance.
How you would know
- How is output quality tested?Measure means testing.
- How would we detect drift?Context changes over time.
- Who reviews, and how often?On a regular basis.
- What happens when something goes wrong?Decide before it does.
- Do we need a certificate?ISO/IEC 42001 if so.
Ask three teams what AI tools they used this week.
Then compare that list against what has been formally approved. The gap between those two lists is your AI governance programme, and it takes an afternoon to find.
Related Services
Explore more solutions that work great with this service
EU AI Act compliance
Why UAE companies with no EU entity are still in scope.
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
IT Risk Assessment
A short register with an owner against every risk
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
Security Policy Development
Policies you can actually comply with
Compliance as a Service
Keeping the position true between assessments
Virtual CISO Dubai
Security governance and accountability, not more tools
Third Party Risk Audit
Who can actually reach your systems, and what to do about it