Before deploying an AI system, assemble evidence about its purpose, affected people, data, failure behavior and accountable owners. This guide uses the 2025 AI Ethics Principles linked by SDAIA when checked on 12 September 2026. The review matrix and downloadable record are Ting's proposed working tools, not an official SDAIA form, certification or legal determination. Use them to expose unresolved questions before making a deployment decision.
Ting working aid · not an official form
Review the missing evidence, not just the heading
These are proposed working questions for each principle, not SDAIA's complete checklist. Page references point to the English 2025 document. There is no automated assessment or deployment approval.
Fairness
Source principle · p. 12Which affected groups and language variants are represented?
- Suggested evidence
- Test-set description, group-level errors and an explanation of missing coverage.
- If a gap remains
- If a relevant group is missing, collect approved examples or narrow the use case before deciding.
Privacy and security
Source principle · p. 15Where do inputs, outputs and logs go, and who can access them?
- Suggested evidence
- A data-flow map, access rules, retention settings and the relevant privacy review.
- If a gap remains
- Keep real data out of the pilot while the authorized data flow remains unresolved.
Humanity
Source principle · p. 18Can an affected person understand the system's role and reach a responsible person?
- Suggested evidence
- The disclosure, escalation path and a test of the handoff.
- If a gap remains
- Repair a dead-end escalation path; do not substitute an automated response for the missing owner.
Social and environmental benefits
Source principle · p. 20What benefit is intended, and what wider costs or harms need examination?
- Suggested evidence
- A stated benefit, relevant resource-use observations and an impact assessment.
- If a gap remains
- Record unmeasured effects as unknown; do not turn an intended benefit into a claimed result.
Reliability and safety
Source principle · p. 22What happens on a wrong answer, missing source, timeout or unsafe request?
- Suggested evidence
- Versioned test results, rejection behavior, rollback steps and the incident owner.
- If a gap remains
- Do not release the affected scope while a material failure lacks a tested containment path.
Transparency and explainability
Source principle · p. 24Can a reviewer trace an output to its inputs, version and declared limits?
- Suggested evidence
- A sample trace, source/version references and a plain-language explanation of limits.
- If a gap remains
- Resolve missing provenance before using the output as a basis for consequential action.
Accountability and responsibility
Source principle · p. 26Who owns the decision, unresolved issues and post-release monitoring?
- Suggested evidence
- Named role owners, decision rationale, open issues and review triggers.
- If a gap remains
- Keep the decision pending when ownership or resolution responsibility is absent.
Generated locally without submitting data. Every item starts unreviewed and the decision stays pending review. Store your completed copy in your organization's approved storage.
Which SDAIA document does this guide use?
SDAIA's official Artificial Intelligence page linked a 50-page English AI Ethics Principles PDF with 2025 on its cover when we checked it. The older link previously cited by this article still serves a different document: September 2023, Version 1.0. This revision uses the 2025 document and its printed page numbers. A search-result date or title is not enough to establish an edition; inspect the document itself.
The 2025 document describes seven principles: fairness; privacy and security; humanity; social and environmental benefits; reliability and safety; transparency and explainability; and accountability and responsibility. They begin on pages 12, 15, 18, 20, 22, 24 and 26. The matrix above turns those headings into proposed working questions, with a direct page reference for each principle.
Separate risk language, registration and legal applicability
Page 9 states the framework's scope across AI stakeholders in Saudi Arabia and describes little or no risk, limited risk, high risk and unacceptable risk. It says high-risk systems must undergo pre- and post-conformity assessments and describes unacceptable-risk uses as not allowed. Those are the document's words; this guide does not assign your system a category or decide what assessment process applies to it.
Page 31 labels the registration mechanism Optional Registration and describes optional reports for registered entities. That does not establish that every privacy, sector or other legal obligation is optional. Conversely, a paragraph in this guide is not evidence that every business needs the same license, job title or assessment. Ask the responsible legal and governance owners to document the applicable instruments, authority, scope and unresolved interpretation for the specific system.
Build an evidence packet before filling the review record
Start with a system description: intended use, excluded use, users, affected people, model/application version and connections to other systems. Add a data-flow map and a record of permitted processing, test inputs and expected answers, observed failures, incident handling and the proposed rollout boundary. Mark missing evidence as missing rather than filling the space with a benefit statement.
The framework discusses lifecycle activities on pages 10–11, reliability tests and oversight on pages 22–23, traceability and third-party documentation on pages 24–25, and roles on pages 28–31. Our proposed evidence packet groups those concerns for a review meeting; it is not a reproduction of SDAIA's full controls or an exhaustive compliance checklist. Give each evidence item an owner, a version or date, and a location an authorized reviewer can open.
Worked review: a fictional internal FAQ assistant
Assume an internal assistant answers from an approved equipment-support knowledge base and cannot modify business records. This is a fictional scenario, not a Ting client deployment or a completed benchmark. For a proposed test, give it a question whose answer is absent from the approved material. Expected behavior: explain that it lacks a supported answer and offer the agreed escalation path. Do not invent a pass rate or classify the system as low risk from this description.
Suppose the observed result in this fictional walkthrough is an unsupported answer and a non-working escalation link. Record the exact test/version, the failed expected behavior, the responsible application owner and the proposed action: remove the unsupported-answer path, repair escalation and repeat the relevant tests. Keep the affected release scope pending. A privacy review, authorization to use the documents and other necessary checks remain separate open items; passing this one test would not resolve them.
Record a decision with scope, reasons and unresolved issues
The downloadable JSON is a blank working record. Replace the placeholders locally with the system scope, evidence references, findings, responsible roles, proposed mitigations and a decision rationale. Its default status is pending review. It does not calculate a compliance score, issue an approval or upload the completed record to Ting. A review owner must define who can make the real deployment decision under the organization's applicable process.
For every unresolved material issue, record the next action and who owns it. If the scope changes, identify exactly what remains excluded and what evidence supports the narrower decision. Do not describe an unresolved issue as closed because a checklist row has text in it. The framework's roles section includes entity leadership/CDO, compliance, responsible AI and assessor responsibilities; our record asks for accountable roles without asserting that its field names create new statutory hiring duties.
Carry the review into deployment and later changes
A pre-deployment record needs a handoff. The framework describes continuing monitoring, performance information, incident logs and assigned alerts in its deployment controls, including pages 23, 25 and 28. Our recommendation is to record the chosen metrics, failure thresholds, alert recipient, rollback owner and events that reopen the review, such as a changed data source, model version, user group or action permission.
Keep the source edition and review date with the record. Recheck applicable guidance and requirements when the system or regulatory context changes; do not merely advance a date on an unchanged checklist. If you need help mapping the workflow, assembling a test plan or identifying missing ownership, the related audit and validation services are next steps—not promises of SDAIA approval.
Key takeaways
- Name the source edition and distinguish framework wording from your own proposed controls.
- Record evidence, missing information and a next action for each principle.
- Treat optional registration separately from other applicable legal obligations.
- A completed checklist is not certification or proof that a system is safe.
What to bring to the review
- A bounded use case and a named accountable decision-maker.
- Versioned evidence for the seven principle areas, including explicit gaps.
- A proposed failure test with expected behavior and a route for unresolved findings.
- A scoped decision rationale, follow-up owners and monitoring/review triggers.
The FAQ assistant walkthrough is fictional and does not report an executed test. · The matrix is a working aid, not SDAIA's official controls or a legal assessment. · No risk classification, certification, measured outcome or client endorsement is inferred.
Frequently asked
Which edition of SDAIA's AI Ethics Principles is used here?
The English document marked 2025 on its cover, linked from SDAIA's official Artificial Intelligence page when checked on 12 September 2026. The older 2023 Version 1.0 link is not the evidence base for this revision.
Is this an official SDAIA checklist or certification?
No. It is Ting's proposed working matrix and blank decision record, with references to the official principles. Completing it does not certify compliance, establish system safety or confer regulatory approval.
Does optional registration mean every AI-related obligation is optional?
No. Page 31 describes an optional registration mechanism. It does not settle separate privacy, sector or other legal requirements. Determine applicability for the actual system with its responsible legal and governance owners.
Does this checklist decide the system's risk category?
No. Page 9 describes the framework's risk categories. The worksheet records your documented assessment and open questions; it does not infer a classification or the required assessment process from a short scenario.
What should happen when a material review item has no evidence?
Record it as unresolved, assign an owner and specify the next action. Do not turn missing evidence into an assumed pass. The accountable decision-maker determines whether to defer or narrow the proposed scope.
Where does the downloaded review record go?
The blank JSON file is generated in your browser and downloaded to your device. There is no submission form or automated assessment in this tool. Keep any completed record in your organization's approved storage.
Related guidance
Government claims verified against official Saudi government sources
Sources
- AI Ethics Principles — 2025 editionSDAIARetrieved: September 12, 2026
- SDAIA Artificial Intelligence — official document linkSDAIARetrieved: September 12, 2026
Editorial revision, 12 September 2026: checked the official source and replaced the prior edition-mixed overview with a 2025-edition guide, proposed review matrix and fictional walkthrough. This is not a new autonomous publication approval or a claim that Ting or this worksheet is SDAIA-certified.


