Know what applies. Prove what you run.
Six engagements, each sized to a decision. Every one starts from what your regulators actually require of your organisation — and what they do not.
Applicability Determination
Two weeks, fixed fee. The one thing nobody else sells.
Four answers, every line cited
We establish which obligations apply to your entity, in your jurisdictions, for your AI use cases — and, just as usefully, which do not.
- Applicable — with the clause that triggers it
- Conditionally applicable — with the condition stated
- Not applicable — with the reason
- Watchlist — proposed and consultation instruments
Scope down before you spend
Most organisations begin an AI governance programme without knowing which rules bind them. They over-build in some areas and miss others entirely.
Telling you that CBUAE requirements do not reach your entity is worth as much as telling you that Regulation 10 does. Both shrink the problem to its real size.
Engagements
Each rung stands alone. Each one earns the next.
Applicability Determination
Which obligations apply to you, which do not, and why.
AI Regulatory Readiness Assessment
Your full AI estate — declared, detected and embedded — classified by risk, mapped to your obligations, with the control gaps named.
- Enterprise AI inventory
- Risk classification per system
- Regulatory applicability matrix
- Gap assessment
- Executive risk report
- Target governance framework
- Remediation roadmap
AI Governance Implementation
Closing the gaps the assessment found — the operating model, the frameworks, the registers, the controls and the evidence.
- AI governance operating model
- AI policy and risk frameworks
- AI register implementation
- Control implementation and evidence framework
- Vendor and third-party AI assessment
- Model and agent governance
- Monitoring architecture and board reporting
Continuous AI Governance
Governance decays without attention. New systems appear, models change, vendors change, and regulations move.
- AI inventory monitoring
- Regulatory change alerts, mapped to your systems
- Risk reassessment and evidence tracking
- Control monitoring with expiry
- Quarterly management reporting
Outsourced Autonomous Systems Officer
DIFC Regulation 10 names the role. Most firms are too small to appoint one internally.
- Registers of use cases, processing and automated decisions
- High Risk Processing assessments
- Transparency notice review
- Annual report to the board
Regulatory filing preparation
Where a regulator sets the cadence, the work repeats whether you are ready or not.
- QCB pre-approval submissions
- QCB annual disclosures
- CBUAE remediation updates
- Oman compliance reports
What we will not do.
The refusals are part of the service, not a limitation of it.
No vendor commissions
No referral fees, no reseller margin, no marketing funds — from any AI platform or model provider. You pay us; nobody else does.
No licence resale
We do not sell software. The tooling we use to run an engagement is ours, and it is not on your invoice.
No opinion on our own work
We do not provide an independent validation opinion on any model we have built or remediated. Regulators require validators to be independent of development, and so do we.