
White paper · Reviewed quarterly · Ungated
The Gulf AI Governance Crosswalk
Six Gulf states are writing AI rules and none of them names a standard to comply with. This maps ISO/IEC 42001 against each instrument — and, more usefully, shows what the Gulf requires that the standard does not.
Why a crosswalk rather than a checklist
A group running AI systems in Riyadh, Dubai and Doha is answerable to three sovereign frameworks with three vocabularies, written by three authorities who did not coordinate. Saudi's data and AI authority built its own five-phase risk framework rather than adopting ISO/IEC 23894 or the NIST AI RMF. Abu Dhabi's health department wrote a Responsible AI Standard that cites neither. Qatar's central bank issued a binding guideline of its own. The Dubai AI Seal references no management standard at all.
The temptation is to run three programmes. The alternative is to run one management system and map it outward — which is the only approach that survives the fourth framework when it arrives.
But a crosswalk that only runs one way is marketing. The section that matters here is the second table: the obligations Gulf instruments impose that ISO/IEC 42001 does not reach at all. A firm that certifies and stops will fail on those, and will have been told it was compliant.
ISO/IEC 42001 against the Gulf instruments
Rows follow the standard's management clauses and Annex A control objectives. Cells describe the corresponding requirement in each instrument in our own words — the standards themselves are copyright and are not reproduced here. An em dash means no equivalent requirement, not that the topic is forbidden.
| ISO/IEC 42001 structure | Saudi ArabiaSDAIA AI Risk Management Framework | UAE · DIFCRegulation 10 | UAE · Abu DhabiDoH Responsible AI Standard | QatarQCB AI Guideline | European UnionEU AI Act |
|---|---|---|---|---|---|
| Clause 4Context of the organisation | Phase 1 context and scope definition is the framework's explicit first step. | Scope set by whether a system processes personal data autonomously or semi-autonomously. | Scope covers clinical, financial, administrative and research use, built or bought. | Scope set by the high-risk classification the entity must assign. | Scope set by role — provider, deployer, importer — and by risk tier. |
| Clause 5Leadership and policy | Governance principles stated, with responsibility assigned at entity level. | Deployer and Operator must be designated — named roles, not a policy. | Core Foundations pillar sets eight principles the organisation must adopt. | Board-level accountability and an AI governance policy are explicit. | Provider obligations sit with the legal entity placing the system on the market. |
| Clause 6Planning and AI risk assessment | Phases 2 and 3: seven risk categories, four-by-four likelihood and impact matrix. | High-risk systems must be restricted to human-defined purposes or given an officer. | Risk Management pillar requires proactive, evidence-based assessment and treatment. | Risk classification drives whether prior approval is needed at all. | Risk management system required across the high-risk lifecycle. |
| Clause 7Support, competence and awareness | Competency expectations follow the national data and AI occupational standards. | — | AI Literacy is a full pillar: role-tailored training with competency tracking. | Training is implied by the human-oversight protocol rather than specified. | AI literacy obligation has applied since February 2025. |
| Clause 8Operation | Phase 4 treatment: avoid, mitigate, transfer or accept, with decisions recorded. | Operational registers of use cases, processing and data sharing. | Lifecycle coverage from inception through to decommissioning. | Operation gated by prior approval; changes that are material re-trigger it. | Quality management system and post-market monitoring. |
| Clause 9Performance evaluation | Phase 5 monitoring and review is a named phase of the framework. | Records must evidence compliance with applicable audit and certification requirements. | Continuous monitoring expected across the lifecycle. | AI register disclosable to the Central Bank annually on request. | Logging, record-keeping and serious incident reporting. |
| Clause 10Improvement | Review outputs feed the next cycle. | — | Standard revision cycle with organisational updates expected. | Serious AI incidents must be reported, which drives corrective action. | Corrective action duties on providers and deployers. |
| A.2Policies related to AI | Entities are expected to build internal policy on the framework's vocabulary. | Transparency notices must state the principles underpinning system design. | Policy expectations run through all four pillars. | An AI governance policy is explicitly required. | Internal governance expected of providers. |
| A.3Internal organisation and roles | Responsibility assigned, no named officer required. | Autonomous Systems Officer with DPO-equivalent duties for high-risk systems. | Governance roles required alongside the ADHICS security committee structure. | Board accountability named; no statutory officer specified. | Human oversight roles defined for high-risk systems. |
| A.4Resources for AI systems | Addressed through competency and data standards rather than a resource clause. | — | Data Management pillar covers sourcing, quality criteria, versioning and metadata. | Datasets must be separated into training, validation and testing. | Technical documentation and resources required for high-risk systems. |
| A.5Assessing impacts of AI systems | The four-by-four matrix is the impact assessment method. | Impact on data subjects assessed through the data protection regime. | Impact assessment required as part of risk management. | High-risk classification is itself an impact determination. | Fundamental rights impact assessment for certain deployers. |
| A.6AI system life cycle | Lifecycle implied by the five phases rather than specified. | Registers must track systems in use. | Explicit: inception through decommissioning. | Approval attaches at procurement and at material modification. | Lifecycle obligations across design, testing and post-market. |
| A.7Data for AI systems | Data governance flows from the national data management standards. | Personal data processing is the regulation's whole subject. | Data Management pillar is one of four. | Bias testing on separated datasets is required. | Data and data governance duties for high-risk systems. |
| A.8Information for interested parties | Transparency is among the stated principles. | Initial notices must say whether processing is human-initiated or autonomous. | Transparency expected in clinical decision contexts. | Customer disclosure and a recourse route are required. | Article 50 transparency: chatbot disclosure and synthetic content marking. |
| A.9Responsible use of AI systems | Seven principles, described as grounded in Islamic values. | Use must stay within the purposes notified. | Responsible use is the standard's organising idea. | Human oversight protocol required per system. | Prohibited practices in force since February 2025. |
| A.10Third-party and customer relationships | Third-party expectations follow the national cyber controls rather than this framework. | Sub-processor arrangements are in scope and must be recorded. | Third-party and bought-in systems are explicitly covered. | Approval required before signing purchase, licensing or outsourcing agreements. | Obligations flow along the value chain. |
Compiled from each authority's own published instrument. Clause and control numbering follows ISO/IEC 42001:2023. This is an analytical mapping by Gulf Cyber-Safe, not an endorsement by any regulator or by ISO, and no regulator has adopted it.
What the Gulf requires that ISO/IEC 42001 does not
This is the half of the crosswalk that certification does not close. Each of these is a real obligation with no counterpart in the standard, so an organisation that certifies and stops will still be short.
| Gulf requirement | InstrumentWhere it comes from | NatureWhat it actually demands | Why 42001 misses itThe gap |
|---|---|---|---|
| QAPrior regulatory approval | Qatar Central Bank AI Guideline, September 2024. | Approval from the regulator before deploying a high-risk system and before signing the purchase, licensing or outsourcing agreement. | The standard has no concept of an external approval gate. A certified management system does not entitle you to proceed. |
| AENamed statutory roles | DIFC Regulation 10. | A designated Deployer and Operator, and an Autonomous Systems Officer for high-risk systems, with duties equivalent to a data protection officer. | Annex A assigns responsibilities but does not create statutory roles a regulator can hold personally accountable. |
| AEData residency | Federal Law 2/2019 on ICT in health fields, plus the Abu Dhabi patient data privacy standard. | Health data relating to services provided in the UAE may not be processed or stored outside it. | The standard is silent on geography. A fully conformant AI management system can still be unlawful here. |
| AERole-tailored AI literacy | Abu Dhabi DoH Responsible AI Standard, October 2025. | AI literacy as a governed pillar, with training tailored by role and competency tracked as evidence. | Clause 7 requires competence in general terms; it does not require a tracked literacy programme across clinical and administrative staff. |
| SAA prescribed risk method | SDAIA National AI Risk Management Framework. | Seven named risk categories and a four-by-four likelihood and impact matrix with defined bands. | The standard requires a risk process but deliberately does not prescribe the method, so a conformant method may still not be the one the framework expects. |
| QAA disclosable register | Qatar Central Bank AI Guideline. | A register of every AI system with classification, provider, human-oversight protocol and contract dates, disclosable to the regulator annually on request. | Annex A expects records; it does not specify a regulator-facing register with these fields. |
| EUMarking and disclosure | EU AI Act, Article 50, in force since August 2026. | Disclosure that a user is interacting with an AI system, and machine-readable marking of synthetic content. | A management standard does not impose product-level marking obligations, and these reach any Gulf firm whose output is used in the EU. |
If a proposal offers ISO/IEC 42001 certification as the answer to Gulf AI compliance, this table is the question to put to it.
How to use this
A sensible sequence
- Establish which instruments actually reach you. Most organisations are caught by two, not six.
- Build one management system, not three programmes.
- Close the second table's gaps explicitly, because certification will not.
- Decide whether to certify at all — it is a procurement and trust decision here, not a compliance one.
- Re-read the DIFC position each quarter; its anticipated certification requirements are the most likely place a Gulf mandate appears first.
What this paper is not
- It is not a regulator-endorsed mapping. No authority has adopted or reviewed it.
- It does not reproduce the text of ISO/IEC 42001 or of any instrument — the standards are copyright and the cells are our paraphrase.
- It is not legal advice, and several entries in the underlying register carry verification caveats.
- It is not a substitute for reading the instrument that binds you. It tells you which one that is.
Two things that would change this paper
DIFC has anticipated publishing general certification requirements under Regulation 10 — if it names a standard, the Gulf gets its first AI certification mandate and this mapping becomes a compliance document rather than an analytical one. Separately, the Saudi central bank has issued no AI instrument while the UAE's issued guidance in February 2026 and Qatar's issued a binding guideline in September 2024, which makes a Saudi financial-sector instrument a reasonable thing to prepare for. Both are tracked; this paper carries its review date for that reason.
Which of these reach you?
Usually two. Establishing which, and stopping the programmes you do not owe, is the first conversation.
Primary sources
Every instrument this crosswalk maps to, at the issuing body. Check the current version there before relying on any mapping here.
- ISO/IEC 42001:2023, AI management systems (ISO)
- SDAIA National AI Risk Management Framework (Saudi Press Agency announcement)
- DIFC Data Protection Regulations, Regulation 10: autonomous and semi-autonomous systems (DIFC)
- Qatar Central Bank Artificial Intelligence Guideline (Qatar News Agency)
- Abu Dhabi Healthcare Information and Cyber Security Standard, ADHICS v2 (Department of Health Abu Dhabi)
- EU Artificial Intelligence Act, Regulation (EU) 2024/1689 (EUR-Lex)
- NIST AI Risk Management Framework (NIST)