Raajeh Consulting AI Governance & Strategy

Knowledge

AI governance glossary

Arabic AI-governance terminology is genuinely unsettled — the same English term is rendered three or four different ways across regional documents. This is a consistent set, aligned to ISO/IEC 42001 vocabulary where the standard provides one. Where a competing rendering is in common use, both are shown.

43 terms

Accountability المساءلة
The obligation of a named individual or body to answer for decisions taken by or with an AI system. Distinct from responsibility: accountability cannot be delegated to a model or a vendor.
AI lifecycle دورة حياة الذكاء الاصطناعي
The stages from conception through design, development, deployment, operation and retirement. ISO/IEC 42001 requires controls across all of them, not only at launch.
AI management system (AIMS) نظام إدارة الذكاء الاصطناعي
The set of interrelated policies, objectives, processes and roles an organisation uses to direct and control its AI activities. This is the object that ISO/IEC 42001 certifies — not the AI system itself.
AI policy سياسة الذكاء الاصطناعي
The top-level statement of intent and direction for AI, approved by leadership. Under ISO/IEC 42001 it is a documented requirement, not an optional artefact.
AI risk assessment تقييم مخاطر الذكاء الاصطناعي
Systematic identification, analysis and evaluation of risks arising from AI systems, against criteria the organisation has defined in advance.
AI system نظام الذكاء الاصطناعي
An engineered system that generates outputs such as predictions, recommendations or decisions for a given set of objectives, with varying degrees of autonomy.
AI system impact assessment تقييم أثر نظام الذكاء الاصطناعي Also seen as: دراسة الأثر
Assessment of the consequences an AI system may have for individuals, groups and society — distinct from risk to the organisation itself. ISO/IEC 42001 requires both.
Anonymisation إخفاء الهوية
Irreversible removal of the link between data and an identifiable person. Distinct from pseudonymisation, which is reversible and remains personal data in law.
Automation bias التحيّز نحو الأتمتة
The human tendency to over-trust automated output and under-apply independent judgement. It quietly defeats human oversight arrangements.
Bias التحيّز
Systematic difference in a system’s treatment of groups or cases. Bias is a property of outcomes, not of intent, and can be introduced by data, design or deployment context.
Certification audit تدقيق الاعتماد
The two-stage external assessment by an accredited certification body: Stage 1 reviews documentation and readiness, Stage 2 tests implementation in practice.
Conformity assessment تقييم المطابقة
The process of demonstrating that specified requirements are fulfilled — by self-declaration, second-party review, or accredited third-party certification.
Corrective action إجراء تصحيحي
Action taken to eliminate the cause of a nonconformity so it does not recur. Correcting the symptom alone does not satisfy the requirement.
Data governance حوكمة البيانات
The allocation of ownership, quality standards and access rules across an organisation’s data. AI readiness rarely fails on models; it fails here.
Data lineage تتبّع مسار البيانات
The documented record of where data originated and every transformation applied to it. Required to answer an auditor’s question of why a system produced a given output.
Data minimisation تقليل البيانات
Collecting and retaining only the data necessary for a stated purpose. A legal requirement under most data protection regimes and a risk reduction in its own right.
Data protection law قانون حماية البيانات
Legislation governing the processing of personal data. Most Gulf states now have one; AI projects touching personal data fall within scope regardless of whether AI is named in the text.
Data residency موطن البيانات Also seen as: الإقامة الجغرافية للبيانات
A requirement that data be stored or processed within a defined jurisdiction. Frequently the constraint that decides which AI vendors are viable in Gulf public-sector work.
Ethics charter ميثاق الأخلاقيات
A published set of principles governing acceptable AI use. Useful only where principles are translated into testable controls; otherwise it is a communications document.
EU AI Act قانون الذكاء الاصطناعي الأوروبي
The European Union’s risk-tiered AI regulation. It carries extraterritorial effect: organisations outside the EU can fall within scope where their AI system’s output is used in the Union.
Explainability قابلية التفسير
The degree to which the reasons for an AI system’s output can be presented in terms a human can understand. Frequently a regulatory requirement in public-sector decisions.
Foundation model النموذج الأساس
A large model trained on broad data and adaptable to many downstream tasks. Governance implication: the organisation deploying it did not train it and may not be able to explain it.
Hallucination الهلوسة Also seen as: التوليد الزائف
Output that is fluent and confident but factually unfounded. A governance issue wherever output reaches a decision without verification.
Human oversight الإشراف البشري
Arrangements ensuring a competent person can understand, monitor, intervene in or override an AI system’s operation. Oversight that cannot actually change the outcome is not oversight.
Human-in-the-loop الإنسان ضمن الحلقة
A configuration in which a person reviews or approves each AI-assisted decision before it takes effect.
Internal audit التدقيق الداخلي
A planned, documented review by competent auditors independent of the activity being audited, verifying that the management system conforms and is effectively implemented. A certification blocker if absent.
ISO/IEC 42001 معيار ISO/IEC 42001
The international standard specifying requirements for establishing, implementing, maintaining and continually improving an AI management system. It is certifiable, and follows the same harmonised clause structure as ISO 27001 and ISO 9001.
Large language model النموذج اللغوي الكبير
A model trained to predict sequences of text, used for generation, summarisation and classification. Its fluency is not evidence of accuracy.
Management review مراجعة الإدارة
Formal review of the management system by top management at planned intervals, covering performance, audit results, risks and improvement opportunities. Must be documented.
Model card بطاقة النموذج
Structured documentation of a model’s intended use, performance, limitations and evaluation data. A practical way to satisfy transparency requirements.
Model drift انحراف النموذج
Degradation of a model’s performance over time as the real-world data it meets diverges from its training data. Requires monitoring, not a one-time validation.
National AI strategy الاستراتيجية الوطنية للذكاء الاصطناعي
A government’s published direction for AI adoption, capability and regulation. A strategy without a named authority and a funded roadmap is a statement of intent, not a strategy.
Nonconformity حالة عدم مطابقة
A failure to meet a requirement. A major nonconformity will block certification; a minor one requires a corrective action plan.
Procurement criteria معايير الشراء
The stated basis on which AI suppliers are evaluated. Mature criteria extend past price to data ownership, auditability, vendor lock-in and exit cost.
Regulatory authority الهيئة التنظيمية
The body holding the mandate to issue, interpret and enforce AI rules. Its powers, funding and independence determine whether a strategy has force.
Residual risk المخاطر المتبقية
The risk that remains after treatment. It must be explicitly accepted by an accountable owner, not left unstated.
Risk treatment معالجة المخاطر
The selected response to an assessed risk: modify, retain, avoid, or share. Retaining a risk is a legitimate choice only when documented and authorised.
Robustness المتانة
The ability of an AI system to maintain its performance under conditions that differ from those it was developed in, including adversarial input.
Statement of Applicability بيان القابلية للتطبيق
The document recording which Annex A controls apply to the organisation, which do not, and the justification for each exclusion. Auditors read it first.
Surveillance audit تدقيق المتابعة
Periodic external audit during the certificate’s validity confirming the system remains effective. Certification is not a one-off event.
Third-party AI الذكاء الاصطناعي من طرف ثالث
AI capability obtained from an external supplier. Accountability for outcomes stays with the deploying organisation regardless of who built the model.
Training data بيانات التدريب
The dataset used to fit a model’s parameters. Its provenance, licensing and representativeness are all governance concerns, not only technical ones.
Transparency الشفافية
Disclosure about an AI system’s capabilities, limitations and use — including telling an affected person that AI was involved at all.