02

Design & Readiness Diagnostic

What your system has to be able to do — before someone asks.

This is the core assessment. Your AI system is examined control by control against the obligations established at scoping, using our framework of 164 control points across the EU AI Act, the GDPR and the Saudi stack. What comes back is not only where you stand, but what has to change — written so that an engineering team can act on it without translation.

It runs in both directions. On a system already in production, it reports gaps. On a system still being designed, the same analysis is returned as specifications: what the system must be able to do, produced early enough to build it in rather than retrofit it. Retrofitting controls costs considerably more than designing them in, and that is the entire reason this engagement exists.

What we assess

  • System inventory and classification — which of your deployments fall in scope of which framework, and at what risk tier. Where a system nobody calls AI is doing the deciding, we look for it.

  • Control-by-control scoring — a structured, reproducible score against each applicable framework. Identical inputs always produce the same result, so findings are defensible and comparable over time.

  • Binding and voluntary, scored separately — obligations that carry legal force and frameworks that do not are never blended into a single number. A recommendation must never read as a breach, and a breach must never be diluted by a favourable total.

  • Sufficiency, not presence — for each control, the question is not whether something exists but whether what exists would satisfy someone with the authority to disagree. Every control carries a written sufficiency criterion, and you receive it.

What you receive

  • On a deployed system — a written assessment with per-framework scores, findings ranked by severity, and a prioritised remediation roadmap — P1 urgent, P2 near-term, P3 recommended — so your team knows what to fix first.

  • On a system in design — a design brief. The same analysis, stated as requirements, grouped by what has to happen for each to be met: decisions that constrain the architecture, capabilities the system itself must carry, and records the organisation must keep around it. Deliberately carries no compliance score — a percentage against a system that does not exist yet measures how much of it has not been built.

  • In both cases — the regulatory anchor on every line. These are not recommendations; each one names the obligation it derives from, so it can be argued with.

  • A debrief session to walk through the findings and answer questions.

Who it's for

Teams building or deploying AI who need to know where they stand and what to do about it. Particularly useful before a system is finished — most of what an assessment finds after go-live could have been designed in for a fraction of the cost.

How it works

  1. 01

    Scoping call — the systems and frameworks in scope, confirmed in writing.

  2. 02

    Document and system review — we work from your policies, model documentation and data-flow descriptions. No production access is required at this stage.

  3. 03

    Scoring and analysis — each system scored against each applicable framework.

  4. 04

    Report or design brief, and debrief — delivered within the engagement window.

Timeline

1–2 weeks from kickoff, depending on the number of systems in scope.

Book a diagnostic

Related services

Oxon X

Oxon X

Oxford research × Paris Bar law · Data & AI governance · MENA

Al Madinah Al Munawwarah, Kingdom of Saudi Arabia·CR 7054827998·MISA 24926260750

© 2026 Oxon X. All rights reserved.

Privacy PolicyTerms of UsePDPL · SDAIA · ISO/IEC 42001 · NCA · EU AI Act