Who it's for
Risk, compliance, and governance professionals responsible for AI oversight in regulated GCC institutions.
What participants can do by the end
Identify the sources of bias in AI systems, data, algorithmic, and deployment bias, and map each to a GCC regulatory risk. Apply a bias detection methodology to a model output and document the source, type, and potential impact of identified bias. Analyze an AI model’s risk profile using a structured model risk assessment framework appropriate for GCC regulated industries. Assess the governance model of an existing AI deployment against CBUAE, SAMA, or SDAIA guidance and identify compliance gaps. Recommend a model governance policy for an AI system, justifying oversight controls, audit schedule, and remediation process.


How the three days build:
Day one covers data bias, selection, historical, representation, algorithmic bias in model architecture and training choices, and deployment bias from context, then moves into bias detection methods, statistical parity, equal opportunity, individual fairness, available tooling, and documenting findings for GCC regulatory reporting, before covering a model risk taxonomy, accuracy, robustness, drift, interpretability, adapted for GCC financial institutions. Day two covers CBUAE AI and machine learning risk management guidance in detail, how SAMA, SDAIA, and TDRA frameworks compare across GCC jurisdictions, then assesses governance models across three types, centralized, federated, and embedded, using a six-dimension scoring framework, and covers incident classification and response protocols for AI failures, performance degradation, bias amplification, and adversarial attack. Day three covers independent model validation, challenger models, shadow deployment, ongoing drift and performance monitoring, then has participants design a full governance policy, scope, risk tiering, validation, monitoring, audit, remediation, and build an implementation roadmap with quick wins and 90-day priorities.
Participants leave with a policy document, not just an understanding of what governance should look like.

Why this matters specifically for regulated institutions:
a model that performs well but has no documented bias assessment, risk tier, or monitoring schedule doesn’t pass a CBUAE, SAMA, or SDAIA review just because its accuracy is high, examiners are asking about process and documentation as much as outcomes. Institutions that build governance policy alongside model development, rather than retrofitting it before an audit, move through regulatory review with far less friction. This program exists to close that documentation gap before a regulator finds it first.


