Three regimes, one record-keeping system
Most organisations do the same work three times: a separate file for the EU, another for the Gulf, another for national data law. Yet all three ask for the same core — which systems exist, what they do, where the data comes from, who owns them, how decisions are logged.
We build a single record-keeping regime and generate each regulator's required output from it. When a new regulation arrives, nobody starts from zero.
This is the largest single source of cost difference. An organisation running three separate files collects the same information three times and keeps none of them current.
The order of work
1. Inventory. Every AI system running in the organisation, including purchased tools. Most organisations find about twice what they expected.
2. Classification. Which risk tier does each system fall into? Done against the regulation's own criteria, not by intuition.
3. Gap analysis. Which obligation is unmet on each system, and by which date it must be met.
4. Build-out. Risk management regime, data governance records, technical documentation, automatic event logging, defined human oversight.
5. Ownership. Every file gets an owner by name. There is no such thing as an unowned compliance programme.
6. Refresh. When a system changes, the record changes. That gets a calendar and a responsible person.
If you are a supplier, this is a sales subject
European and Gulf buyers are pushing these obligations into supplier contracts. Tenders now ask bidders for technical documentation, data-governance records and a defined human-oversight arrangement.
In Saudi Arabia the SDAIA framework sets a mandatory governance baseline for public sector entities, and ISO 42001 is becoming central to procurement. If you intend to sell technology into government, governance is not a preference — it is the entry ticket.
A supplier holding these documents ready beats one that does not. Compliance stops being a cost line and becomes a point of differentiation.
Starting early changes the cost, not the calendar
The EU AI Act's high-risk obligations were postponed by the Digital Omnibus — 2 December 2027 for Annex III, 2 August 2028 for Annex I. That looks like relief. It is not.
As the date approaches, consultant and notified-body capacity becomes the scarcest resource in the market. Producing the same file in late 2027 costs several times what it costs today.
An organisation that starts early also does the work with its own people at its own pace; one that starts late buys it from outside, in a hurry.
AI standards consulting: ISO/IEC 42001, NIST AI RMF and the EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) is law: obligations depend on the system's risk tier and on your role as provider or deployer.
ISO/IEC 42001:2023 is a voluntary, certifiable management-system standard for AI. It organises policy, roles, risk assessment and continual improvement. Certification alone does not prove conformity with the AI Act; presumption of conformity comes from harmonised standards, which CEN-CENELEC JTC 21 is still developing.
NIST AI RMF 1.0 (January 2023) is a voluntary US framework built on four functions: Govern, Map, Measure, Manage. It is useful vocabulary when a US customer asks how you manage AI risk.
We map one control set to all three, so a single inventory, risk register and evidence folder answers the regulator, the certification auditor and the customer questionnaire.
AI procurement compliance: what buyers now ask AI suppliers
Corporate and public buyers increasingly add AI questions to supplier due diligence. The recurring requests are: a description of the AI system and its intended purpose, where training and input data come from, how personal data is handled, what human oversight exists, how incidents are logged, and which standard your management system follows.
If you are the buyer, the same list becomes your vendor checklist and contract annex. If you are the supplier, having these answers written down before the tender shortens the sales cycle.
What each regime asks for
| Regime | Core obligation | Critical date |
|---|---|---|
| EU AI Act — transparency | AI disclosure, machine-readable marking, deepfake disclosure | 2 August 2026 (in force) |
| EU AI Act — high risk | Risk management, data governance, technical documentation, human oversight | 2 December 2027 (Annex III) |
| SDAIA framework (Saudi Arabia) | Data governance, model accountability, transparency, human oversight, risk management | Mandatory baseline for public sector |
| Oman personal data law | Data protection officer appointment, documented consent trail | 5 February 2026 (fully in force) |
| National data protection law | Lawful basis, notice, retention periods, transfer rules | In force |