POC readiness for regulated financial services
How UAE and Saudi financial institutions should set the boundary for a customer-facing AI
A five-gate framework for deciding whether a customer-facing generative AI POC can use customer data, cloud services and automated answers in UAE and Saudi
Executive answer
Start with a narrow, human-controlled customer-service use case, not live financial advice, transaction execution or fully automated decisions. Before testing with identifiable customer information, establish the purpose, data boundary, hosting route, supplier responsibilities, test evidence and an accountable business owner. In Saudi Arabia, regulated financial institutions must also address Saudi Central Bank cloud requirements, including the rule that cloud services should in principle be located in Saudi Arabia, with explicit SAMA approval required when services outside Saudi Arabia are used. In the UAE, the AI Ethics Principles and Guid
The decision is not whether to pilot AI. It is what the pilot is allowed to do.
For a customer-facing generative AI assistant, the first decision is the permitted outcome. A low-risk initial boundary may support answer drafting, policy navigation or handoff to an employee. A higher-risk boundary may influence eligibility, pricing, complaints, fraud handling or another outcome with material customer impact.
The UAE AI Ethics Principles and Guidelines apply their guidance to AI systems that make or inform significant decisions. They call for accountability, transparency, explainability, robustness, safety, human-centred values and privacy-preserving AI. That makes decision classification a practical POC design step, even when the pilot is not yet customer-facing.
- Write one sentence defining the POC outcome and one sentence defining what it must never decide.
- Identify whether the output can affect a customer’s financial position, access to a product or treatment in a complaint process.
- Assign a named business owner, risk owner, technology owner and customer-operations owner.
- Require human review or escalation for advice, exceptions, uncertainty and any sensitive customer situation.
Gate 1: classify the use case before selecting a model or platform
Classify the proposed assistant by its effect on the customer, not by its interface. A chatbot that retrieves published product information is different from one that recommends an action based on a customer profile. The latter has a stronger need for documented rationale, testing and human intervention.
The UAE guidance states that responsibility should be clear for AI impact and that decisions should be understandable and interpretable to non-experts. Use those principles to decide whether the POC can give information only, propose a draft for employee approval, or take an action.
- Information only: published FAQs and product information, with approved content sources.
- Employee assist: drafted answers and summaries, with staff review before sending.
- Customer guidance: personalised suggestions, restricted until the institution can test relevance, disclosure and escalation behaviour.
- Decision or action: eligibility, pricing, complaints outcomes, payments or account changes. Keep outside an initial customer-facing POC unless separate controls and approvals are
Gate 2: establish a customer-data boundary that the team can actually enforce
A generative AI POC has more data paths than its source documents. Customer prompts, chat histories, attachments, retrieved records, logs, evaluation datasets and model outputs can all contain personal data. Saudi PDPL guidance states that the law applies to personal-data processing taking place in the Kingdom and to processing of personal data relating to individuals residing in the Kingdom by a party outside the Kingdom.
The UAE AI Ethics guidance calls for minimum intrusion, data access protocols, specific responsibility for data protection, privacy impact assessment where possible, and measures such as encryption, anonymisation and aggregation. Translate these principles into a testable POC data contract rather than a broad statement that data is secure.
- Begin with synthetic, anonymised or tightly minimised data where the business question allows it.
- List permitted fields, prohibited fields, retention periods, approved users and approved environments.
- Decide whether customer prompts may contain account, identity, health, employment or other sensitive information, and configure the experience accordingly.
- Test whether the system reveals information from another customer, hidden instructions or internal documents.
- Retain evidence that access, consent and deletion requirements were assessed by the appropriate privacy and legal stakeholders.
Gate 3: qualify the cloud and supplier route, especially in Saudi Arabia
For Saudi financial-sector member organisations, the SAMA Cloud Computing control requires cyber security controls for hybrid and public cloud services to be defined, implemented and monitored, with effectiveness periodically measured and evaluated. It also states that cloud services should in principle be located in Saudi Arabia, and that explicit SAMA approval is required where cloud services outside Saudi Arabia are used.
This is not a generic question of whether a provider has a Saudi region. The POC team should map where prompts, retrieval data, logs, backups, support access and model inference are processed. A supplier architecture diagram is evidence only when it covers the actual POC configuration.
- Request a data-flow diagram for prompts, outputs, retrieval, logging, backup, support and model operations.
- Confirm the geographic location of every cloud service used by the POC, not only the primary application environment.
- Document supplier and institution responsibilities for identity, encryption, monitoring, incident response and evidence retention.
- For Saudi financial-sector deployments, have the accountable compliance and cloud-risk teams determine whether the chosen route satisfies applicable SAMA requirements or needs an
Gate 4: test customer harm and operational failure, not just answer quality
NIST describes its Generative AI Profile as a companion resource for managing generative AI risks across the AI lifecycle. It organises suggested actions through the AI RMF functions Govern, Map, Measure and Manage. This gives a practical structure for a financial-services POC: define accountability, map the use context and harms, measure performance and risk, then manage residual risk and incidents.
The evaluation set should contain realistic customer questions, ambiguous requests, adverse scenarios and escalation triggers. A useful pilot result is not an average score alone. It is evidence that the system behaves acceptably on the cases that create regulatory, customer or operational exposure.
- Measure factual grounding against approved source content and identify unsupported claims.
- Test for unsafe financial guidance, inappropriate certainty, discriminatory treatment and harmful refusal behaviour.
- Test prompt injection, malicious attachments, retrieval manipulation and unauthorised disclosure attempts.
- Measure whether the assistant recognises uncertainty and routes the customer to a qualified employee.
- Define incident triage, rollback and customer-remediation steps before the first external test.
Gate 5: define the evidence required to expand, pause or stop
A customer-facing POC needs a pre-agreed decision rule. The institution should specify what evidence permits a broader audience, more data, additional integration or a production procurement decision. Equally, it should state what finding pauses the test, such as repeated unsafe answers, unauthorised data exposure, unclear hosting evidence or an inability to explain ownership.
The UAE guidance is non-mandatory and the NIST AI RMF is voluntary. Neither replaces legal, supervisory, security or internal-policy obligations. Their value is to make the POC decision more disciplined and auditable. For Saudi financial institutions, the cloud control introduces a sector-specific consideration that should be assessed separately from general AI ethics.
- Expand only when the defined use-case, privacy, security, customer and operational tests are met.
- Pause if the team cannot show where data is processed, who can access it or how unsafe outputs are contained.
- Stop if the business value depends on an outcome that the institution cannot govern or validate within the proposed boundary.
- Keep a decision record containing the scope, evidence reviewed, residual risks, approvals, owner and next review date.
Practical questions
Can a Saudi financial institution test a customer AI assistant on a public cloud?
Potentially, but the POC must be assessed against applicable SAMA cloud requirements. The SAMA control requires defined, implemented and monitored cyber security controls for hybrid and public cloud services. It says cloud services should in principle be located in Saudi Arabia and requires explicit SAMA approval when services outside Saudi Arabia are used.
Should the first POC use live customer conversations?
Usually not by default. Start with synthetic, anonymised or minimised data if that can answer the business question. If identifiable customer data is necessary, define the legal and operational basis, allowed fields, access, retention, processing locations, logging and escalation process before testing.
Does a retrieval-augmented assistant avoid privacy and cloud risk?
No. Retrieval can reduce unsupported answers, but prompts, retrieved records, outputs, logs and support access still need assessment. The team should map each data path and test whether the assistant can expose restricted information or follow malicious instructions.
What is the best first customer-facing use case?
Choose a bounded information or employee-assist use case based on approved content, with clear handoff to people. Avoid starting with automated eligibility, pricing, payment, complaint outcomes or personalised financial guidance unless the institution has separately established the required controls and evidence.
Related research
Keep building the complete picture
Turn the POC boundary into a decision-ready plan
QualifiedPOC.ai can help a serious enterprise buyer complete one deep discovery conversation to define the use case, data boundary, supplier evidence, test plan and approval gates before committing to a customer-facing AI POC.
