Book2026 · New release19 chapters · 6 appendices

AI Governance & Compliance Frameworks for the Middle East.

The Enterprise Playbook

The first complete operating manual for governing artificial intelligence inside Middle East financial institutions. Governance as architecture, not paperwork.

Hardcover · 2026 · ISBN forthcoming
§ 01Overview

AI has moved from pilot to production across MENA banking, insurance, and capital markets faster than the governance built to contain it. Credit decisions, fraud interdiction, onboarding, and market surveillance now run on systems no committee yet fully governs, and the regulators are no longer waiting.

SAMA, CBUAE, SDAIA, the DIFC and ADGM authorities, the Qatar Central Bank, and AAOIFI are converging on enforcement, while Sharia governance adds an obligation no imported framework was built to carry.

Drawing on twenty-five years of enterprise AI practice and fifteen years advising MENA institutions, this is not a survey. It is a playbook a chief risk officer can work from on a Monday morning.

§ 02The MESA Framework

Four layers that turn compliance into architecture.

Layer 1
Regulatory floor
The supervisory baseline across the GCC and wider MENA, mapped and harmonized.
Layer 2
Strategic compass
Board-level intent, risk appetite, and the principles that govern automated decisions.
Layer 3
Operational machinery
The committees, gates, and controls that make governance run day to day.
Layer 4
Technical substrate
Data, models, monitoring, and the audit trail beneath every deployed system.

Around the MESA core, the book operationalizes a complete governance system: six frameworks, one coherent discipline.

§ 03The operating system

Six frameworks. One coherent system.

Five-Gate Deployment Model

01

The checkpoints between an AI idea and production, and the AI Governance Operating Model that runs them.

MESA Model Risk Management

02

A six-pillar discipline for validating models in production.

Incl. Sharia dual-validation

AI Data Governance Stack

03

Seven layers from collection to audit.

Incl. Halal data certification

AI Vendor Risk Framework

04

Govern the models you buy, not only the ones you build.

Governance Office Blueprint

05

Structure, the staffing math, and a 90-day stand-up plan to stand the office up.

Incident & GenAI Playbooks

06

Incident response, generative-AI governance, and sector playbooks for banking, healthcare, and government.

§ 04Why this book is different

Built for this region, not borrowed from another.

Brussels has the EU AI Act. Washington has sectoral enforcement. The Gulf has neither, and no imported framework carries Sharia governance, data sovereignty, or the multi-jurisdictional reality MENA institutions inhabit.

This book is built from the region's regulatory architecture upward: SAMA, CBUAE, SDAIA, DIFC, ADGM, QCB, AAOIFI, and the PDPL regimes, integrated into one operating discipline rather than a stack of disconnected obligations.

§ 05A reference you work from

More than a book. A working instrument.

19
Chapters
6
Appendices
50
Question MESA
self-assessment
EN / AR
Bilingual
glossary

Regulatory reference tables across the GCC and MENA, composite case studies drawn from real engagements, deployable templates and checklists, and a fifty-question MESA Self-Assessment that scores your institution's maturity and routes you to the chapters that close each gap.

§ 06Who it is for

For the people accountable for AI.

Board directorsChief risk officersChief compliance officersChief data officersAI governance leadsModel validatorsVendor-risk practitionersIncident-response teamsSharia liaison officersSupervisors & auditors
§ 07From the foreword
"This book fills this gap and comprehensively covers all aspects of AI governance. I hope that decision makers would use this valuable resource to guide their way in implementing AI responsibly in the region."
Dr. Abdul Hameed Ali Hussain
Executive Director for Science & Technology, Kuwait Institute for Scientific Research (KISR)
§ 08About the author
Dr. Nabeel A. Khan

Dr. Nabeel A. Khan is an enterprise AI architect and governance advisor with twenty-five years building AI and machine-learning systems at scale, and the past fifteen years concentrated on the Middle East and North Africa. As Principal Architect at iSystematic, he has built AI governance functions inside regional institutions, served as an independent model validator, and advised banks, insurers, healthcare systems, public-sector bodies, and sovereign-wealth-backed initiatives across the GCC and the wider region.

His practice sits at an unusual intersection: supervisory regulation, quantitative model risk, and the principles of Sharia governance as they apply to automated decision-making. He holds a PhD spanning neuro-marketing and computer science, and his work integrates AI engineering and enterprise architecture (TOGAF, DMBOK, ISO 27001, SOC 2) with behavioral science and business strategy.

Dr. Khan writes as a practitioner. His frameworks are built to be used, contested, and adapted, not merely read. He is based in Winnipeg, Canada, with active advisory engagements across MENA. More at nabeelkhan.com.

§ 09The appendix vault

The working appendices, free for practitioners.

Five appendices behind the book, collected into a single working bundle: the reference tables, the 70+ templates, the glossary, the full case studies, and the assessment rubrics. Request access and the download link is sent to your inbox.

Appendix A
Regulatory Tables & Reference Materials
Supervisory requirements across SAMA, CBUAE, SDAIA, DIFC, ADGM, QCB and AAOIFI, mapped and harmonized.
Appendix B
Templates & Tools
25,000 words · 70+ deployable templates, checklists, and registers: the operational core of the book.
Appendix C
Glossary
The full bilingual EN / AR terminology of AI governance and Sharia model validation.
Appendix D
Full Case Studies
Composite engagements, drawn from real institutions, worked end to end.
Appendix E
Assessment Tools & Rubrics
The fifty-question MESA Self-Assessment with scoring rubrics and maturity routing.
Free download · one bundle

Request the appendix bundle

Tell us where to send it. To keep this free of bots and disposable inboxes, links are issued after a short verification window.

No instant link. We verify every request to keep the bundle free of bots.

Request received.

Check your inbox in 24–48 hours. The wait helps us keep this free of bots and disposable emails.

The institutions that build this architecture will lead the next decade of MENA AI.

Fin · Sheet 04