6pillars in the pre-build governance checklist
4UAE regulatory anchors every checklist item maps to
15 mintime it takes to run one use case through it, properly

Most enterprises I work with don't lack governance intentions. They lack a governance gate. A use case gets approved in a workshop, someone starts building it, and the governance questions, the ones about data, risk, accountability, regulation, only get asked once legal or compliance notices what's already half built. By then, every answer is expensive: a redesign, a delay, or a system that ships with the risk quietly unmanaged.

The fix is not a hundred-page policy document. It's a short, specific checklist that gets run on every AI use case before it moves from idea to build, not after. This is that checklist.


Why evaluate before you build, not after

Governance added at the end of a project is not governance. It's a negotiation between whatever was built and whatever the organisation can tolerate. The team is invested, the timeline is set, and every governance requirement now looks like an obstacle rather than a design input.

Governance evaluated at the start costs almost nothing. It's a conversation, not a rebuild. The six pillars below are deliberately structured as questions you can answer before a line of code is written, so the checklist changes what gets built, not what gets apologised for later.

A governance checklist is not there to slow down good ideas. It exists so that when a regulator, a board member, or a journalist asks a hard question about an AI system, you already have the answer.


The six-pillar checklist

1. Regulatory and legal fit

  • Which UAE frameworks apply: the TDRA AI Ethics Principles, sector-specific rules from ADGM or DIFC for financial services, the UAE PDPL for personal data, and the developing UAE AI Law
  • Is this use case in a regulated sector requiring specific sign-off, such as financial services, healthcare, or government
  • Are there cross-border data transfer implications, and are they permitted under current UAE data protection rules

2. Data governance and provenance

  • What data feeds this use case, and is it properly classified and owned
  • What is the consent basis for any personal data involved
  • What are the retention and deletion rules for this specific use case, not just the organisation's general policy
  • Is the data quality actually sufficient to trust the output

3. Risk tier and human oversight

  • What is the potential for harm if this system is wrong: low, medium, or high
  • What level of human review is required before an output is acted on
  • Is there a documented explainability requirement appropriate to this risk tier

4. Accountability

  • Who is the named owner of this specific use case, not a committee
  • What is the escalation path if something goes wrong
  • Who signs off before this goes live

5. Business case and outcome ownership

  • What specific, measurable outcome does this use case move
  • Who is accountable for that outcome, and is it the same person accountable for the risk
  • What happens if it underperforms, is there a defined point at which the organisation stops and reassesses

6. Vendor and model considerations

  • Where is the model hosted, and what are its data residency terms
  • Does the vendor train on your data by default, and can that be turned off in writing
  • What are the IP and liability terms if the model produces a wrong or harmful output

How to actually use this

Run it as a short, structured session, fifteen to thirty minutes, before any use case moves from idea to build. The named accountable owner completes it, with input from data, risk, and technical leads in the room, not collected separately by email afterward. A gap in the regulatory or data pillars is a hard stop. A gap elsewhere is a flag to resolve before go-live, not necessarily before the project starts.

Keep the completed checklist. It becomes the answer the next time someone, internal or external, asks how this AI system was approved.


A use case that clears this checklist still needs one more decision: whether it's worth building before the other nine on your list. That's a prioritisation question, and we've written up exactly how to score it.

See the worked example: An AI Use Case Scorecard, a worked example or talk to us about our AI Governance Advisory service.