regulation10.ae
Demo dashboard — sample data, not a live tenant.

Interactive demo

Northwind Financial (a demo organisation)

A mid-sized retail bank invented for this demo. It runs five AI systems across lending, hiring, payments and service. Assessed against the DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023), and the DIFC Data Protection Law No. 5 of 2020, corpus 2026.08.28.

Northwind Financial is a fictional organisation and its five AI systems are invented. No customer data appears here. The risk classifications and obligations below are computed live by the same deterministic, citation-pinned engines the paid platform runs, from the sample systems described. They are an illustration for qualified professional review, not a legal determination.

Portfolio summary

AI systems in scope
5
Registered in this sample estate
High risk
2
Classified by the risk engine, not declared
Evidence complete
3 of 5
Every artefact the tier requires is locked
Open actions
2
Required artefacts not yet produced
Compliance score
80%
Tier-weighted, locked evidence only

How a system moves through the platform

Filing route shown for the DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023), and the DIFC Data Protection Law No. 5 of 2020

  1. Step 1: Classify. Each registered system is classified from what it does. Module 1.1 risk classification and the Module 1.1b prohibition screen.
  2. Step 2: Prove. The obligations that follow are turned into citation-pinned artefacts. Impact assessment, transparency notice and the evidence register, each content-hashed.
  3. Step 3: Monitor. Live systems are watched for drift and posture change. Module 3.1 drift monitoring, with Sentinel on the Enterprise and Sovereign tiers.
  4. Step 4: File. A reportable incident is routed to the DIFC Commissioner of Data Protection. DIFC DPL 2020 Art. 41 (breach notification) and DIFC Regulation 10 section 10.3. Ongoing monitoring sits under DIFC Regulation 10 section 10.3 (ongoing monitoring).

AI system inventory

Risk class computed by Module 1.1 from each system's description

SystemOwnerRisk classModules runEvidence

Candidate screening assistant

NWF-HR-01

Ranks and shortlists job applicants for interview from their CV and application form. Used by the recruitment team for every open role in the group.

Group HRHigh risk
  • Purpose text implies Annex III 4 employment/worker management
1.1 · 1.1b · 1.2 · 1.3Evidence complete

3 locked artefacts

Consumer credit decision engine

NWF-CR-02

Produces a credit score for retail loan applications and sets the credit limit offered to an approved applicant. Runs on every personal loan and card application.

Retail lendingHigh risk
  • Purpose text implies Annex III 5(b) creditworthiness
1.1 · 1.1b · 1.2 · 1.3 · 2.11 outstanding

2 locked artefacts; outstanding: transparency notice

Payment fraud detection

NWF-FR-03

Screens card and transfer activity as it happens and flags suspected fraud for a human investigator to review before any account action is taken.

Financial crimeLimited risk
  • systematic monitoring without significant effects
1.1 · 1.1b · 3.11 outstanding

1 locked artefact; outstanding: transparency notice

Customer support assistant

NWF-CS-04

Answers customer questions about products, balances and branch services in a chat window, and hands the conversation to an adviser when it cannot answer.

Service operationsMinimal risk1.1 · 1.1b · 1.3Evidence complete

2 locked artefacts

Branch demand forecasting

NWF-OP-05

Forecasts counter and call-centre volume by branch and hour so rotas can be planned a fortnight ahead. Reads aggregated volume counts only.

Operations planningMinimal risk1.1 · 1.1bEvidence complete

1 locked artefact

Compliance posture

Scored with the same tier-aware rule the platform applies inside a tenant: one point per artefact the system's risk class requires, earned only when a content-hashed, current document satisfies it.

80%

across 5 systems, 16 obligations mapped

Systems classified5 of 5
Evidence complete for tier3 of 5
Transparency duty engaged5 of 5

Obligations and filing status

Derived from the DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023), and the DIFC Data Protection Law No. 5 of 2020 by the policy engine

Each control below is pinned to a corpus citation. The platform derives them from the computed risk class, so a re-classification changes the obligation set rather than leaving a stale checklist behind.

  • Candidate screening assistantHigh riskEvidence complete5 controls mapped

    Full provider obligations apply before it can be relied on.

    • difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
    • difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
    • difc-reg10-10.3.1 Confirm an appointed ASO has authority over this system.
    • difc-dpl-2020-art-20 Complete and document a DPIA for this system.
    • difc-reg10-10.2.2 Document the decision logic and provide a data-subject explanation path.
  • Consumer credit decision engineHigh risk1 outstanding5 controls mapped

    Full provider obligations apply before it can be relied on.

    • difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
    • difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
    • difc-reg10-10.3.1 Confirm an appointed ASO has authority over this system.
    • difc-dpl-2020-art-20 Complete and document a DPIA for this system.
    • difc-reg10-10.2.2 Document the decision logic and provide a data-subject explanation path.
  • Payment fraud detectionLimited risk1 outstanding2 controls mapped

    Transparency obligations apply.

    • difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
    • difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
  • Customer support assistantMinimal riskEvidence complete2 controls mapped

    No mandatory high-risk obligations triggered. Good practice still applies.

    • difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
    • difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
  • Branch demand forecastingMinimal riskEvidence complete2 controls mapped

    No mandatory high-risk obligations triggered. Good practice still applies.

    • difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
    • difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.

Sentinel monitoring

Enterprise and Sovereign, closed beta
Monitored
5
On drift watch
2
Open incidents
0

Sample signals for a demo organisation. Sentinel is a closed beta and is not open for enrolment, so no estate is monitored today and these counts are invented. Ongoing monitoring sits under DIFC Regulation 10 section 10.3 (ongoing monitoring). A reportable incident is designed to route to the DIFC Commissioner of Data Protection under DIFC DPL 2020 Art. 41 (breach notification) and DIFC Regulation 10 section 10.3, without undue delay, and where feasible within 72 hours (DIFC DPL 2020 Art. 41).

How Sentinel works

Now run one of your own

The sandbox puts your own AI system through the same engines that produced everything above: the risk classification, the prohibited-practice screen, the obligations that follow and a sample of the evidence. No account, and what you type is not stored.

Demo dashboard — sample data, not a live tenant.

Generated 2026-08-31T09:00:00.000Z from a fixed synthetic seed, so this dashboard renders identically for every visitor. Nothing about your visit is recorded to produce it.