Interactive demo
Northwind Financial (a demo organisation)
A mid-sized retail bank invented for this demo. It runs five AI systems across lending, hiring, payments and service. Assessed against the DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023), and the DIFC Data Protection Law No. 5 of 2020, corpus 2026.08.28.
Northwind Financial is a fictional organisation and its five AI systems are invented. No customer data appears here. The risk classifications and obligations below are computed live by the same deterministic, citation-pinned engines the paid platform runs, from the sample systems described. They are an illustration for qualified professional review, not a legal determination.
Portfolio summary
How a system moves through the platform
Filing route shown for the DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023), and the DIFC Data Protection Law No. 5 of 2020
- Step 1: Classify. Each registered system is classified from what it does. Module 1.1 risk classification and the Module 1.1b prohibition screen.
- Step 2: Prove. The obligations that follow are turned into citation-pinned artefacts. Impact assessment, transparency notice and the evidence register, each content-hashed.
- Step 3: Monitor. Live systems are watched for drift and posture change. Module 3.1 drift monitoring, with Sentinel on the Enterprise and Sovereign tiers.
- Step 4: File. A reportable incident is routed to the DIFC Commissioner of Data Protection. DIFC DPL 2020 Art. 41 (breach notification) and DIFC Regulation 10 section 10.3. Ongoing monitoring sits under DIFC Regulation 10 section 10.3 (ongoing monitoring).
AI system inventory
Risk class computed by Module 1.1 from each system's description
| System | Owner | Risk class | Modules run | Evidence |
|---|---|---|---|---|
Candidate screening assistant NWF-HR-01 Ranks and shortlists job applicants for interview from their CV and application form. Used by the recruitment team for every open role in the group. | Group HR | High risk
| 1.1 · 1.1b · 1.2 · 1.3 | Evidence complete 3 locked artefacts |
Consumer credit decision engine NWF-CR-02 Produces a credit score for retail loan applications and sets the credit limit offered to an approved applicant. Runs on every personal loan and card application. | Retail lending | High risk
| 1.1 · 1.1b · 1.2 · 1.3 · 2.1 | 1 outstanding 2 locked artefacts; outstanding: transparency notice |
Payment fraud detection NWF-FR-03 Screens card and transfer activity as it happens and flags suspected fraud for a human investigator to review before any account action is taken. | Financial crime | Limited risk
| 1.1 · 1.1b · 3.1 | 1 outstanding 1 locked artefact; outstanding: transparency notice |
Customer support assistant NWF-CS-04 Answers customer questions about products, balances and branch services in a chat window, and hands the conversation to an adviser when it cannot answer. | Service operations | Minimal risk | 1.1 · 1.1b · 1.3 | Evidence complete 2 locked artefacts |
Branch demand forecasting NWF-OP-05 Forecasts counter and call-centre volume by branch and hour so rotas can be planned a fortnight ahead. Reads aggregated volume counts only. | Operations planning | Minimal risk | 1.1 · 1.1b | Evidence complete 1 locked artefact |
Compliance posture
Scored with the same tier-aware rule the platform applies inside a tenant: one point per artefact the system's risk class requires, earned only when a content-hashed, current document satisfies it.
across 5 systems, 16 obligations mapped
Obligations and filing status
Derived from the DIFC Data Protection Regulations, Regulation 10 (enacted 1 September 2023), and the DIFC Data Protection Law No. 5 of 2020 by the policy engine
Each control below is pinned to a corpus citation. The platform derives them from the computed risk class, so a re-classification changes the obligation set rather than leaving a stale checklist behind.
- Candidate screening assistantHigh riskEvidence complete5 controls mapped
Full provider obligations apply before it can be relied on.
- difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
- difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
- difc-reg10-10.3.1 Confirm an appointed ASO has authority over this system.
- difc-dpl-2020-art-20 Complete and document a DPIA for this system.
- difc-reg10-10.2.2 Document the decision logic and provide a data-subject explanation path.
- Consumer credit decision engineHigh risk1 outstanding5 controls mapped
Full provider obligations apply before it can be relied on.
- difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
- difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
- difc-reg10-10.3.1 Confirm an appointed ASO has authority over this system.
- difc-dpl-2020-art-20 Complete and document a DPIA for this system.
- difc-reg10-10.2.2 Document the decision logic and provide a data-subject explanation path.
- Payment fraud detectionLimited risk1 outstanding2 controls mapped
Transparency obligations apply.
- difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
- difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
- Customer support assistantMinimal riskEvidence complete2 controls mapped
No mandatory high-risk obligations triggered. Good practice still applies.
- difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
- difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
- Branch demand forecastingMinimal riskEvidence complete2 controls mapped
No mandatory high-risk obligations triggered. Good practice still applies.
- difc-reg10-10.2.2-g Keep this register entry current and complete so it can be produced on request.
- difc-dpl-2020-art-17 Publish a transparency notice covering this system's processing.
Sentinel monitoring
Enterprise and Sovereign, closed betaSample signals for a demo organisation. Sentinel is a closed beta and is not open for enrolment, so no estate is monitored today and these counts are invented. Ongoing monitoring sits under DIFC Regulation 10 section 10.3 (ongoing monitoring). A reportable incident is designed to route to the DIFC Commissioner of Data Protection under DIFC DPL 2020 Art. 41 (breach notification) and DIFC Regulation 10 section 10.3, without undue delay, and where feasible within 72 hours (DIFC DPL 2020 Art. 41).
How Sentinel worksNow run one of your own
The sandbox puts your own AI system through the same engines that produced everything above: the risk classification, the prohibited-practice screen, the obligations that follow and a sample of the evidence. No account, and what you type is not stored.