Level 1 Digital AI Readiness Assessment
Legal entity: Strategica Enterprise Services LLC
This is the assessment questionnaire

Level 1 Assessment Questionnaire

Complete the 15-point GCC bank AI governance diagnostic. This version is static for testing; no data is submitted or stored.

No-sensitive-data rule: do not enter customer names, account numbers, transaction IDs, credentials, raw transaction logs, production logs, or regulated personal data.
ScopeGCC Bank AI Governance
Questions15 diagnostic items
JurisdictionsUAE / KSA / Qatar / Bahrain
OutputBoard-ready report draft
Question 1 of 15

Has the board formally chartered a cross-functional Group AI Governance Committee to oversee AI deployments?

Q_STR_01
Strategy AlignmentGovernanceCBUAE / SAMA board risk governance
Question 2 of 15

Is there an active registry tracking all AI use cases, differentiating between internal tools and customer-facing models?

Q_STR_02
Strategy AlignmentAI inventoryUse-case registry
Question 3 of 15

Are customer-facing chatbots equipped with automated notifications informing users they are interacting with AI?

Q_ETH_01
Ethical FrameworkChatbotTransparency and consumer protection
Question 4 of 15

Does the bank perform algorithmic bias and fairness testing on models used for credit scoring or automated fraud flagging?

Q_ETH_02
Ethical FrameworkFairnessResponsible AI
Question 5 of 15

Is customer PII actively masked, anonymized, or tokenized before being processed by third-party vendor AI models?

Q_DAT_01
Data GovernanceData privacyPII masking / tokenization
Question 6 of 15

Are AI models and data stores partitioned locally within each country to prevent unauthorized cross-border data leakage?

Q_DAT_02
Data GovernanceData residencyKSA / UAE cross-border risk
Question 7 of 15

Is there a documented risk-tiering matrix that classifies AI systems from low to high/prohibited risk profiles?

Q_RSK_01
Risk & ComplianceRisk classificationAI risk tiering
Question 8 of 15

Does the AML/Fraud AI system generate localized Explainable AI feature-importance scores for regulatory audit trails?

Q_RSK_02
Risk & ComplianceAML / FraudXAI and auditability
Question 9 of 15

Is a formal Human-in-the-Loop protocol enforced before AI-flagged suspicious activities are filed as SARs?

Q_RSK_03
Risk & ComplianceAML governanceHuman review
Question 10 of 15

Are generative AI productivity tools and LLMs isolated within the bank’s secure regional cloud tenant rather than public SaaS?

Q_TEC_01
Technology InfrastructureShadow AISecure tenant controls
Question 11 of 15

Are real-time toxicity guardrails, prompt-injection blocks, and hallucination filters active on consumer-facing chatbots?

Q_TEC_02
Technology InfrastructureChatbot safetyGuardrails
Question 12 of 15

Have front-line compliance staff and customer service agents received training on AI risks, limitations, and escalation paths?

Q_PEO_01
People & SkillsTrainingAI risk awareness
Question 13 of 15

Does the bank run automated quarterly model drift and calibration checks on fraud detection algorithms?

Q_PRC_01
Process MaturityMLOpsModel drift
Question 14 of 15

Is there a mandatory vendor due diligence framework evaluating third-party AI supply chain and training data lineage?

Q_PRC_02
Process MaturityVendor AITraining data lineage
Question 15 of 15

Are financial risk metrics, such as false positive rates in AML, continuously mapped against model performance parameters?

Q_MET_01
Performance MetricsMetricsBoard risk reporting
Need a quick control mapping? Use Strategica Crosswalk Lite to map individual AI governance control statements across major frameworks. Open Crosswalk Lite →