Government (Middle East) Profile
This profile adapts AEEF for public-sector delivery in Middle East jurisdictions. It is intentionally conservative: government systems often carry legal, national security, and citizen trust implications that require stricter controls than commercial systems.
Design Principles
- Sovereignty first: hosting, identity, and audit records align with national requirements.
- Human accountability: high-impact decisions remain attributable to named human roles.
- Explainability and traceability: decisions and AI-assisted implementation history are auditable.
- Controlled adoption: risk-tiered rollout by service criticality.
Government Overlay Controls
| GOV-ME Control ID | Requirement | Typical Evidence |
|---|---|---|
| GOV-ME-01 | Government systems MUST use approved sovereign hosting and data residency patterns | Hosting architecture records, contract clauses |
| GOV-ME-02 | High-impact AI-assisted changes MUST include enhanced review with domain, security, and policy representation | PR approvals, review logs |
| GOV-ME-03 | Procurement of AI tools MUST include legal, security, and data processing terms aligned to public-sector obligations | Procurement checklist, DPA, security annex |
| GOV-ME-04 | Public-facing services MUST maintain transparency artifacts: purpose, scope, limitations, and escalation channels | Service transparency record, support documentation |
| GOV-ME-05 | Incident reporting and escalation for government services MUST include regulator-ready evidence bundles | Incident timelines, provenance package, corrective actions |
| GOV-ME-06 | Critical public services SHOULD maintain service continuity fallback paths independent of external AI providers | DR plans, continuity test results |
| GOV-ME-07 | Government AI programs MUST include Arabic as the primary language for all citizen-facing transparency artifacts, governance documentation, and training materials. See KSA Regulatory Profile — Arabic Language Requirements. | Arabic artifact inventory, translation verification records |
| GOV-ME-08 | Change management programs for government AI adoption MUST incorporate cultural context guidance addressing hierarchical decision-making, relationship-driven trust, and Vision 2030 alignment. See Culture & Mindset — Saudi Organizational Context. | Change management plan with cultural adaptation section, stakeholder engagement records |
Government Assurance Package
For each in-scope system, maintain:
- Service criticality and impact tier.
- Jurisdiction-specific regulatory mapping.
- Data residency and transfer posture.
- AI toolchain approval and supplier risk record.
- Evidence index for audits and regulator requests.
Branching and Delivery Strategy
Default model is a single AEEF core with profile overlays:
corecontrols apply to all teams.ksa-regulatedoverlay applies where Saudi legal/security obligations apply.government-meoverlay applies to public-sector programs.
When to Create a Dedicated Government Branch
Create a dedicated branch only if all are true:
- Normative divergence exceeds 30% of applicable controls.
- Release cadence must differ materially from core (for example regulator-gated release windows).
- Contractual obligations prevent shared baseline updates without prior approval.
If these criteria are not met, keep one core with profile overlays to avoid governance drift.
Rollout Plan for Government Programs
Phase 1: Baseline (0-60 days)
- Apply core AEEF controls and KSA profile where applicable.
- Classify systems by criticality and jurisdiction.
Phase 2: Assurance Hardening (60-120 days)
- Enable government overlay controls.
- Build assurance package and perform internal mock audit.
Phase 3: Operationalization (120+ days)
- Integrate controls in CI/CD and procurement workflow.
- Start quarterly governance review with government stakeholders.
Open Jurisdiction Adapter Pattern
Use the same profile design for other Middle East jurisdictions:
- Define jurisdiction source list (laws, cybersecurity controls, digital government controls).
- Map requirements to AEEF controls and identify gaps.
- Publish profile-specific overlay controls and evidence checklist.
- Keep common controls in core to minimize duplicate maintenance.