AI Governance for Data Citizens

Executive Summary

This webinar covers the key considerations and strategic approaches for building unified governance and solid data management standards across sectors, with a particular focus on higher education and healthcare. Howard Diesel walks through the challenges of implementing AI, including cybersecurity risks, ethical dilemmas, and regulatory compliance. He makes the case for building data governance into AI initiatives from the start, with practical strategies for deploying technologies like chatbots and graph databases that support data unification and business enablement. Get organisational practices aligned with these standards, and stakeholders can build a secure, efficient technology environment that gets the most out of AI while keeping the risks in check.

Webinar Details

Title: AI Governance for Data Citizens
Date: 09 October 2025
Presenter: Howard Diesel
Meetup Group: African Data Management Community
Write-up Author: Howard Diesel

Unified Governance

Howard Diesel opens the webinar by reflecting on a recent conversation with Rob Jackson about why collaboration and bringing in diverse perspectives matters. Rob had introduced him to a website called Blueprints, which uses mathematical formulas to visualise how collaborative effort drives organisational goals. Howard said he wants to dig deeper into Rob’s work, pointing to examples involving McDonald’s and Barack Obama as compelling illustrations of the concept in action.

From there, Howard moved into his own presentation on unified governance, connecting the two ideas: collective action and cohesive strategy are what actually make organisations work. His goal was to show that a collaborative approach to governance doesn’t just make things more inclusive, it makes organisations more successful too.

Integration of Data Management Standards

The National Data Management Office (NDMO) has a real challenge on its hands: integrating a wide range of data management standards and frameworks. Working with the EDM Council and Prodago, the speaker has been developing a paper on these complexities, including aligning NDMO data management standard 1.5 with the Data Management Body of Knowledge (DMBOK) to sort out compliance and implementation issues.

On top of that, the NDMO also has to consolidate other standards, like the Indian Data Standard (DMBoK Plus Plus), which goes beyond DMBOK to cover open data, Freedom of Information, and data value realisation. Add in frameworks like the National Office of Reference Architecture (NORA), cybersecurity standards (NCA), the National AI Index (NAII), the National Data Index, and National Archives records, and you get a genuinely complex, overlapping landscape that makes integration and compliance a real challenge.

Figure 1 Unified Governance

Figure 2 “Bringing it ALL Together”

Navigating the Challenges of Cybersecurity and AI Ethics

Saudi Arabia’s regulatory landscape is genuinely hard to navigate, given how complex and fragmented it is. Organisations have to deal with multiple overlapping frameworks covering cybersecurity, data security, privacy, records management, and AI ethics, which leads to duplicated effort, compliance gaps, and friction between departments.

The National Cybersecurity Authority (NCA) regulates cybersecurity, while the Digital Management Organisation (DMO) handles data security separately, and that split can cause communication breakdowns that delay collaborative work for months. The recent National AI Index adds yet another layer of regulation on top, without doing much to simplify what’s already there.

Howard’s take is that the fix isn’t merging these bodies into one, but coordinating them better. Some banks have consolidated governance successfully through an integrated approach, but many Saudi organisations are still struggling with fragmented responsibilities, where subject matter experts end up spread thin across multiple stewardship roles. Better orchestration and clearer roles would cut duplication, improve efficiency, and let each regulatory area keep doing its own job properly.

Figure 3 Research Insights – Anthony J Mazzarella III

Figure 4 The Challenge: Siloed Governance

Challenges of AI Implementation

AI’s biggest challenges come down to ethics, data management, privacy, and cybersecurity. Generative AI and retrieval-augmented generation (RAG) systems both need high-quality data, structured and unstructured, to work well. Managing that data raises real concerns, particularly around personally identifiable information (PII) and legal compliance.

Poor communication and coordination between the teams building and governing AI makes effective systems harder to build. One view here is that treating AI as something closer to a human resource means it needs similar support and governance structures, a departure from the traditional model where software developers and data scientists own AI deployments largely on their own.

Leadership, particularly at the CEO level, shapes whether an organisation sees AI as a tool or something closer to an integral entity, and that perception drives governance and adoption strategy directly. Oracle’s shifting recognition of bots as entities within organisational frameworks is a good example of how far this thinking has moved. Getting AI implementation right isn’t just a technology question either; it depends on cultural acceptance, and leadership enthusiasm or resistance shapes how AI actually gets adopted in the workplace.

Considerations in Implementing AI and Data Governance in Higher Education

Bringing AI tools into higher education comes with real opportunities and real challenges, and it takes a balanced approach between innovation and risk management. One attendee stressed the value of finding practical AI use cases that improve departmental efficiency, provided the tools are properly vetted first. Her team runs workshops, one on AWS and AI agents, for instance, and looks into applications like retrieval-augmented generation for managing large volumes of documentation. Getting security, data governance, and AI governance teams working together matters here too, especially for guidelines that keep sensitive information like PII out of AI systems.

Institutional responses to AI adoption vary widely, she said: some leaders rush in and end up with failures, others take a more cautious route. She’s wary of the evolving perception of AI, and warned against attributing human-like qualities to what it can currently actually do. She also pointed to the value of tying data governance to records management, so institutions can manage data types that go beyond traditional databases. Her own institution is smaller and centralised, which helps with streamlined systems, but even then, safe AI implementation isn’t a solved problem. Another attendee echoed this, pointing to fragmented policy creation as a recurring issue and making the case for collaborative governance, careful risk assessment, and a measured pace in adopting AI across education.

Strategies in the Data Governance Journey

Getting a data governance program right means dealing with two big challenges. The first is aligning it with business objectives. Stakeholders will ask, “what’s in it for the business?”, and without a clear answer, getting support and sponsorship is an uphill battle. Business leaders need to actually see the value in data governance before they’ll buy in.

The second challenge is managing data domains that cross functional lines, where ownership is often unclear or split across departments. Appointing domain data stewards, people responsible for a specific data area like customer data across every department that touches it, helps here. They set policy and coordinate across teams so data management stays consistent. Between a clear business case and structured stewardship, organisations can work through these common obstacles and end up with better alignment and accountability.

Creating a Unified Governance for AI

Unified governance, across corporate governance, data governance, records management, cybersecurity, data privacy, and AI governance, is what lets an organisation innovate without losing control of the risks. Different departments will always have specialised roles, the speaker said, but those efforts need coordinating through one cohesive framework rather than a patchwork of isolated policies. He compared AI to a wildfire: what you need are “firebreaks”, coordinated controls from IT governance, data management, and ethics, to balance innovation against the potential for damage.

Right now, a lot of teams operate independently, each sticking to their own standard, ISO 27000, NIST, or local Saudi frameworks, which creates silos and inefficiency. An orchestration engine that pulls these frameworks together and gives everyone a shared, holistic view would fix that. This lines up with Saudi Arabia’s vision for responsible AI and data management, and projects like the “ALARM” LLM project, focused on humane and ethical AI, are a good example of it in practice. The goal is collaboration and consistent controls: innovation with the risks properly managed, and governance frameworks that actually work together instead of against each other.

Figure 5 Unified Governance: the Solution

Figure 6 A Holistic View of Governance

Figure 7 Harmonising Global and Local Frameworks

Figure 8 From Policy to Action: the Power of Orchestration

Data Governance in Health and AI Initiatives

Responsible governance matters across sectors, but it comes up a lot in data and AI initiatives specifically. That means unified policies that keep things strategically aligned, which matters a great deal for health ministries trying to build accessible, nationwide patient records. The obstacle tends to be fragmented management by specialist boards that are reluctant to share data. Getting past that takes strong executive oversight and keeping initiatives tied to the bigger strategic picture.

There’s a push underway to consolidate existing frameworks and standards, DMBoK DCAM, Indiemo, PDPL, into one cohesive policy covering cybersecurity, AI ethics, and data management together. It follows a phased “crawl, walk, run” maturity model: get executive buy-in and enterprise-wide policies in place first, then move on to the more complex implementations. The aim is better collaboration, less duplication, and efficient governance that lets specific projects, chatbot development, for instance, move forward smoothly once the right policies and procedures are in place.

Figure 9 Alignment with Saudi Vision 2030

Figure 10 Integration of Global and Local Standards

Figure 11 From Policy to Action: Governance Orchestration

Figure 12 How Orchestration Works

Implementation of AI and Data Governance in Chat Bots

A chatbot built on large language models (LLMs) and retrieval-augmented generation (RAG) can meaningfully improve decision-making in insurance claim approvals and rejections. With a solid governance framework in place, the project aligns tasks like bias auditing, privacy impact assessments, and risk management across teams, including AI stewards and data management professionals. That collaborative approach cuts down on redundancy and builds compliance in rather than bolting it on, and it’s produced a 30% reduction in processing time for insurance claims, along with better fraud detection.

Making this work means managing cultural change across both business and IT governance. Bringing cybersecurity, data governance, and records management together improves both data quality and decision-making. The orchestration platform being envisioned would pull together different governance frameworks and operational models, so structured and unstructured data both get used properly for accuracy and anomaly detection. The end goal is a governance framework that’s integrated and scalable enough to support automated, high-quality decisions in complex environments, insurance claims processing being the case in point here.

Figure 13 Benefits of Unified Governance

Figure 14 Case Study: Unified Governance in Action

Figure 15 Next Steps for NDMO

Figure 16 Culture and Strategy have Breakfast Together

Figure 17 Driving Change: Culture and Organisational Transformation

Figure 18 Establishing Foundational Stuctures Enterprise Wide

Figure 19 Technology Enablement: Governance Orgchestration Platform

Compliance, AI Governance, and Business Enablement

An integrated governance platform makes compliance more efficient across the software development lifecycle, cutting redundant controls while still meeting regulatory requirements. It centres on KPIs built to minimise compliance work, speed up risk identification, and bring AI, particularly LLMs, into the process to check outputs for issues before they reach users. A unified governance strategy that aligns security, IT, and corporate functions supports better collaboration and keeps the process human-centred, even with the added technology.

None of that works, though, unless business leaders and managers see governance as an enabler rather than extra overhead. Getting data stewards and business professionals genuinely engaged matters, and framing governance as something that improves the quality of their work, not just another compliance task, helps drive that adoption. Good governance ultimately comes down to having the right people in collaborative roles, with shared KPIs that encourage the right behaviours. Done this way, it’s thorough without being invasive: fewer risks, better compliance, and more efficient collaboration across departments.

Figure 20 Measurable Success Criteria

Figure 21 Unified Governance: From Vision to Reality

Advantages of Graph Databases in Data Unification

Graph databases are genuinely useful for integrating different data types, particularly in data management and AI. By mapping relationships between data forms, documents and structured datasets among them, they support a unified approach to analysis and interpretation. That gives you better insights and logical reasoning, and it pairs well with large language models trying to connect and interpret multiple data points at once.

Graph databases also don’t care much about the original data format, relational, XML, document-based, whatever, which means they can overlay enterprise data regardless. That flexibility makes data aggregation simpler and cuts a lot of the usual complexity out of data gathering. Linking medical scripts to hospital data is a good practical example of the richer, more interconnected datasets this makes possible. It adds up to a solid framework for AI-driven understanding and decision-making, and a genuinely useful tool for complex data landscapes.

Practical Implementation of Technology in the Business Environment

Practical, implementation-focused videos matter for showing how the theory in a slide deck plays out in real business environments. William made the point that slides give you the general overview, but real use cases shown in video build understanding and keep people engaged. Howard agreed, noting the Prodigo platform is already working on this kind of content. He pointed to earlier presentations by Mario and Rob Jackson, and to a successful collaboration with MetLife that covered policy frameworks, LLMs, data privacy, and data management in real depth.

Scroll to Top