Services
Regulation is the input. Governance is the system. Each engagement turns applicable AI regulation into operational governance — not documentation that sits in a binder.
Who I work with
Financial Institutions
Banks, insurers, fintechs, and payment providers.
Enterprise Technology
Organizations deploying AI products across regulated markets.
Regulated Organizations
Organizations where AI decisions affect customers, employees, or access to essential services.
The initial focus is Gulf financial institutions; the same governance approach applies to any regulated organization with exposure across Europe and MENA.
AI Governance Diagnostic
Map your AI use cases against the regulatory and governance frameworks that apply to you — EU AI Act, ISO 42001, and Gulf/MENA regulatory expectations. Score the gaps and prioritize.
A board-ready risk assessment and remediation roadmap.
AI Governance System
Build the AI inventory, risk classification, decision rights, human oversight mechanisms, and monitoring that produce audit-ready evidence.
An operational AI management system aligned to ISO 42001 and the EU AI Act.
AI Vendor & Procurement Governance
Assess third-party AI systems against supervisory expectations, contractual controls, and regulatory exposure.
A vendor due-diligence framework and contract review.
EU AI Act Readiness
Classify systems against the Act's risk tiers, identify applicable obligations, and build the documentation and oversight structures required.
A classification record and compliance roadmap defensible under audit.
Europe × MENA Governance
Build one governance system, classified against the stricter regime, and map it to each applicable jurisdiction's expectations.
A single governance architecture mapped across EU AI Act, CBUAE, SAMA, QCB, and SDAIA expectations, where applicable.
Regulatory Intelligence Retainer
Monitor primary-source regulatory developments across the EU AI Act and MENA frameworks and brief your board or risk committee.
Regular executive briefings and governance updates.
Areas of focus
- Governance Architecture
- Model inventory, human oversight, decision rights, audit-ready evidence
- Procurement & Vendor Risk
- Third-party AI assessment, contract requirements, due diligence frameworks
- Cross-Border Governance
- Multi-jurisdiction strategy and dual-regime mapping
- MENA / Gulf Governance
- Cross-border compliance for organizations with exposure in the MENA region (CBUAE, SAMA, QCB, SDAIA guidance; Morocco Law 09-08)
- EU AI Act
- Risk tiering, high-risk obligations, transparency requirements, enforcement timeline
- ISO 42001
- AI management systems, governance frameworks, certification readiness