Answers your auditors can trace to the clause.
Your policies, procedures and regulatory documents become a system your people can ask questions of, in Arabic and English. Every answer names the clause it came from. Every AI interaction is governed, disclosed and recorded, and the platform runs wherever your data is allowed to live.
The answer already exists inside your organisation
It is spread across hundreds of documents, several versions deep, in two languages. The cost is not that the knowledge is missing. It is that reaching it reliably does not scale.
Your people ask each other instead
A question about a threshold, an eligibility rule or an escalation path goes to whoever is thought to know. The answer varies by who was asked and how recently they read the policy, and none of it is written down.
A confident wrong answer is a regulatory event
General-purpose assistants are fluent, certain and unsourced. In a bank, somebody acts on the answer. The exposure is not an awkward sentence, it is a decision taken on a rule that was never in your policy.
Your regulator now asks about AI directly
Jordan, the UAE and Saudi Arabia have each set explicit expectations for AI in financial services. A capable tool adopted without governance around it does not stay a productivity win; it becomes a finding.
Five behaviours that make it usable in a regulated setting
These are the differences between a knowledge platform an institution can stand behind and a chatbot pointed at a document folder.
Every answer shows its sources
Not the document, the clause: the section, its number and the date it took effect. A reviewer opens the passage the answer came from and checks it in seconds. If a claim cannot be traced to a source, it is not in the answer.
It answers across documents, not only within one
Real questions cross policies. An employee's final settlement touches the gratuity policy, the loan policy and the card policy at once. The platform assembles the answer from all three, and each part carries its own citation so each can be checked independently.
Arabic and English are equal
Ask in Arabic and receive an Arabic answer from Arabic sources, including the spelling and numeral variations Arabic documents actually use. Questions asked in one language can be answered from sources written in the other, which is what a genuinely bilingual policy set requires.
It says when it does not know
Where your documents are silent, the platform says so and shows the closest topics it does cover. It is built to decline rather than to improvise, because in your environment an honest refusal costs far less than a plausible invention.
It can answer as of a date
Updating a policy never erases the previous one. You can ask what the rule was last March, see what changed between versions, and defend an answer given a year ago against the policy that was in force at the time.
Three teams have to say yes
In our experience the platform is evaluated by the business, by compliance and by security, and each has a different question. The product is built to answer all three.
An answer in seconds, with the clause
- Branch, operations, onboarding and service teams ask in plain language and get a sourced answer
- New joiners reach the same answer as a fifteen-year veteran
- Ask in Arabic or English, on the same corpus
- Available through your own channels and, where useful, to your internal AI assistants
Evidence, not assurances
- Every response declares that it was produced by AI, in the customer's language
- Every interaction is classified by risk, and high-risk cases can require human approval before an answer is released
- Any user can escalate an answer for human review, and it reaches a named queue with a deadline
- AI incidents are recorded separately from ordinary system logs, with their own retention and their own notification path
- A complete, tamper-evident record of every question, answer and administrative change, exportable to your monitoring systems
- Nothing the platform infers about your documents enters service without a specialist approving it
Inside your boundary, under your identity
- Runs as a managed service, inside your own cloud, or fully air-gapped with no external calls
- Users sign in through your existing identity provider, with your existing groups
- Document and passage level permissions are honoured: material a user may not see is invisible to the system's search, not merely hidden in the interface
- Each institution's content is isolated from every other, and the isolation is demonstrable rather than asserted
- Safety checks for sensitive personal data and misuse run inside your deployment, with nothing sent to an outside service
Built for the framework your regulator published
Jordan, the UAE and Saudi Arabia set out different documents, but the substance overlaps heavily. The platform provides each expected control as a working feature with a screen and an owner, so your compliance team configures a control rather than commissioning one.
| What is expected | What the platform provides |
|---|---|
| Risk classification of AI use CBJ, CBUAE high-impact decisions, SAMA oversight |
Every interaction is classified low, medium or high, and the level is recorded with the answer. High-risk cases route to a person. |
| An inventory of AI systems CBJ AIBOM, CBUAE model inventory |
A maintained register of every AI component in use, with its purpose, version and lifecycle state, exportable for a regulator. |
| A named accountable owner CBJ, CBUAE board accountability, PDPL |
Each registered system carries a named owner, never a team alias, and the platform escalates when that person leaves the organisation. |
| Disclosure to the customer CBJ point of interaction, CBUAE transparency, PDPL |
Every response declares that it is AI-generated, in wording and language you configure. |
| A fail-safe off switch CBJ, operational resilience |
AI operations can be disabled instantly, for one system, one risk level or the whole institution, without a technical release. |
| Incident recording and notification CBJ FinCERT, CBUAE, SAMA |
A dedicated AI incident log with its own access rules and retention, and notification to the channels your jurisdiction requires. |
| A right to human review CBJ human in the loop, CBUAE |
Every answer carries the ability to request a person, routed by risk to the right queue with a response deadline. |
| Fairness testing CBJ, CBUAE non-discrimination, SDAIA |
Regular testing that answers do not vary with customer characteristics that should not affect them, with results retained. |
| Jurisdictional configuration All three markets |
Regulators, disclosure wording, retention periods and data residency are settings per institution, not a rebuild. |
The platform gives your compliance function the controls and the evidence. It records the facts and leaves the determinations where they belong, with you. No vendor can certify your compliance on your behalf, and we do not claim to.
Thresholds, review routing, disclosure wording, spending limits and the off switch are settings your administrators change themselves, and every change is recorded with who made it and when. Sensitive changes require a second approver. The platform is deliberately built so that its operator, including us, cannot quietly loosen a control or erase the record of having done so.
Your data stays where your policy says it stays
Data residency and sovereignty decide most enterprise deployments in this region, so all three models are first-class rather than an exception we accommodate.
We run it, in your region
- Fastest route to production
- Regional hosting to match your residency requirements
- Encrypted in transit and at rest, isolated per institution
Inside your own tenancy
- Runs in your cloud account, under your controls and monitoring
- Your security team owns the perimeter
- Reporting back to us is configurable, or switched off
Nothing leaves the building
- Fully self-contained, with no external calls at any point
- For institutions whose classification rules make external processing impossible
- Quality differences from the managed configuration are measured and disclosed, not hidden
Quality is measured before every release, not asserted
Answer quality is tested against a bilingual set of questions with verified answers, reviewed by people who know the subject. A drop in quality stops the release.
Measured on our reference corpus. Before a production rollout the same measurement is repeated on your documents and your questions, because the number that matters is the one from your own material.
See it on your own documents
A demonstration on a vendor's sample corpus proves very little. The useful conversation begins when the questions are yours.
A working session
We walk through the platform against a representative set of your policies and the questions your teams actually ask, with your compliance and security colleagues in the room.
A scoped pilot
A bounded deployment in your environment, on a defined corpus and user group, with the governance controls configured to your framework and measured on your material.
Production
Rollout under your identity, your retention rules and your residency requirements, with your teams operating the controls and our support behind them.