Governance frameworks fail in mid-market companies for a predictable reason: they are written as principles when what the business needs is a list of things somebody can finish. What follows is twenty-eight control points, grouped into eight areas, that a management team of any size can work through in a fortnight of concentrated effort.
How to use this checklist
Assign one owner per section — a named person, not a department. Mark each point done, partial or not started, and record the evidence, because a control with no evidence behind it will not survive a client questionnaire or an investor diligence process. Work the sections in order: the inventory in section A is load-bearing, and every later control depends on it being honest.
Nothing here is jurisdiction-specific advice. It is a working discipline that sits comfortably alongside the obligations a UAE company already carries under data protection law, free-zone regimes and sector rules — a subject covered separately in the UAE governance landscape. Where a control touches a legal question, take advice on the specific facts.
A. AI inventory
A single register of AI-enabled systems exists
One document, one owner, one location. It covers purchased tools, features embedded in software you already licence, anything built in-house, and anything a vendor runs on your behalf. Embedded features are the most commonly missed category — the assistant inside your CRM counts.
Shadow adoption has been actively surveyed, not assumed
Cross-check the register against card and expense records, browser extensions, and an anonymous staff survey. If the register was built only from management interviews, it is incomplete. Assume it undercounts by a third until proven otherwise.
Each entry records purpose, owner, data touched and criticality
Four fields, minimum: what it is used for, who owns the relationship, what categories of data pass through it, and what happens to the business if it becomes unavailable or produces a bad output.
The register has a scheduled review date
Quarterly is the usual cadence. An inventory reviewed once is a snapshot; one reviewed on a schedule is a control. Put the date in a calendar with a named owner attached.
B. Acceptable-use policy
A written acceptable-use policy exists and staff have seen it
Short enough to be read in five minutes. Distributed with acknowledgement recorded, and included in onboarding for new joiners rather than announced once and forgotten.
The policy names permitted, restricted and prohibited uses
Three tiers, with examples drawn from your own business. Generic prohibitions invite workarounds; a policy that says which specific tasks are fine gets followed because it is useful.
It states plainly what must never be entered into a public tool
Client personal data, health information, identity documents, unpublished financials, credentials, and anything covered by a confidentiality undertaking. Name the categories your business actually holds instead of listing abstractions.
There is a documented route to request an exception
A named approver and a stated turnaround. Without a legitimate path, staff with real deadlines will take an illegitimate one, and you lose visibility rather than risk.
C. Data protection alignment
Personal data flowing through AI systems has been mapped
For each register entry: which categories of personal data are involved, whose data it is, and how it entered the system. This mapping is what converts an AI question into a data protection question you can answer.
The lawful basis and any notice or consent position is documented
Whatever regime applies to your entity — federal, DIFC, ADGM or a sector rulebook — the question is the same: on what basis is this processing happening, and have the people concerned been told? Record the answer per use case.
Data location, retention and training terms are known per tool
Where the data is processed and stored, how long the provider keeps it, whether it may be used to improve the provider's models, and which sub-processors are involved. This information sits in the vendor's terms; someone has to read them.
Cross-border transfers have been identified and addressed
Most cloud AI tools process data outside the UAE. Identify where, and make sure the contractual position matches the commitments you have made to clients and staff.
D. Vendor and tool assessment
No AI tool enters the business without an assessment step
A one-page assessment is sufficient for most purchases. The control is that the step exists and is applied consistently, including to free tools — which are the ones with the least favourable terms.
Contract terms have been reviewed for data, liability and exit
Confidentiality, ownership of outputs, whether your content trains their models, service commitments, liability caps, and what happens to your data when the contract ends.
A tiered assessment depth is applied by risk
A meeting-notes tool and a system that scores job applicants or clients do not deserve the same scrutiny. Define two or three tiers so that effort follows consequence rather than being spread evenly and thinly.
Concentration and continuity risk has been considered
If one provider underpins several workflows, note it. Ask what the manual fallback is and how long the business could run on it. This is the question that turns up in operational resilience reviews.
E. Human oversight
Decisions requiring human review are defined in writing
Anything affecting a person's money, employment, health, legal position or access to a service. Anything published externally under the company's name. Anything that would embarrass the business if it were wrong and unreviewed.
The reviewer is a named role with the standing to say no
Oversight assigned to whoever is nearest the screen is not oversight. The reviewer needs the seniority, time and explicit authority to reject an output without it counting against them.
Evidence that review occurred is retained
A sign-off field, a log, an approval step in the workflow. Unrecorded review is indistinguishable from no review the moment anyone asks you to demonstrate it.
F. Incident response
AI failure modes are named in the incident procedure
Confidential data entered into a public tool; a materially wrong output acted upon; a provider outage or breach; an output that is discriminatory, defamatory or infringing. Your existing IT incident process almost certainly does not cover these.
Reporting route, timescale and decision-maker are documented
Who a member of staff tells, within what period, and who decides on notification to clients, regulators or insurers. Rehearse it once so the first live use is not the first use.
Reporting is explicitly blame-light
Most AI incidents are discovered by the person who caused them. If disclosure is punished, disclosure stops and you lose the only early warning system you have.
G. Board reporting
AI is a standing item on the board or ownership agenda
Quarterly, with a short written paper rather than a verbal update. A standing item survives changes of personnel; an ad hoc discussion does not.
The paper reports current state, changes, incidents and decisions needed
Four sections, two pages. What we use, what changed this quarter, what went wrong, and the two or three things that require a decision from this room.
One executive is accountable for AI governance by name
Recorded in the minutes. Shared ownership between IT, legal and operations reliably produces no ownership at all. If the answer to "who owns this?" takes more than one sentence, this control is not met.
H. Training and capability
All staff have had baseline training in the last twelve months
Thirty to sixty minutes covering the policy, the data rules, the reporting route, and a realistic account of where these tools are unreliable. Delivered with the company's own examples.
High-exposure functions have received deeper, role-specific training
Finance, HR, client-facing teams and anyone touching regulated information need more than the baseline, because the consequences of a bad output are concentrated in their workflows.
Training is refreshed on a schedule and covers new joiners
Annual refresh, plus inclusion in onboarding. The tooling changes fast enough that twelve-month-old guidance is materially out of date.
Reading your own score
Count the points marked done with evidence attached. Companies scoring above twenty-two are usually in reasonable shape and should focus on keeping the register and the reporting rhythm alive. Between twelve and twenty-two is the common position for a UAE mid-market business that has thought about the problem but has not finished it — typically strong on policy and weak on inventory, evidence and oversight.
Below twelve is not unusual and is not a crisis, but it does mean the organisation cannot currently answer a client questionnaire or a diligence request without a scramble. The fastest route out is sections A and G: build the honest inventory, name the accountable executive, and the remaining sections acquire an owner and a sequence almost automatically.
Each of these twenty-eight points maps onto one of the five dimensions scored in the UAE AI Governance Readiness Index 2026, our research study of governance maturity in UAE mid-market companies.
The work in this checklist is the substance of a Fractional Chief AI Officer engagement. A disciplined internal team can complete most of it without outside help; what external appointment usually buys is the sequencing, the vendor-terms reading, and a board paper that carries independent weight.