Riyadh Air aircraft flying above the clouds at sunset
Back to Resources
Aviation
Data & AI Governance

Continuous Data and AI Trust, Not Periodic Compliance

How Saudi Arabia's new national carrier is standing up the data and AI trust foundation the rest of the airline is built on.

Download Case Study

For Riyadh Air, data and AI trust is not just a compliance requirement. It is part of the foundation we are building as a new national carrier. The goal is to operationalize governance early, so the evidence, controls, and accountability are already part of how the business runs.

Head of Data and AI Governance, Riyadh Air
Key Takeaways

The Problem

A new national carrier being built on a clean foundation had to satisfy NDMO across fourteen domains, PDPL, and stand up AI governance before AI use cases scale. The standard model of document, refresh at audit, move on, would not hold up.

The Approach

Data Sentinel was engaged to build a Trust Layer that operates, not one that documents. Governance authority, AI governance, data quality, and master data run as one unified program inside the airline's environment.

The Outcome

NDMO Priority 1 documentation delivered across fourteen domains with domain-level operationalization underway. An AI Governance Framework aligned to the EU AI Act and NIST in place and validated with stakeholders. A foundation moving the program toward evidence produced continuously as capability matures.

Results to Date

14

NDMO domains covered by the Trust Layer program.

EU AI Act + NIST

AI Governance Framework aligned to international standards.

One Program

Governance, quality, and AI trust delivered as one integrated program.

Domain by Domain

Trust Layer built through use-case-driven operationalization.

The Context

Riyadh Air didn't want a binder. They wanted a Trust Layer that operates.

Riyadh Air, Saudi Arabia's new national carrier, is being built from a clean technology foundation. That foundation has to satisfy the National Data Management Office (NDMO) across fourteen domains, support privacy obligations under the Personal Data Protection Law (PDPL), and enable AI capability across commercial, operations, and guest experience.

Most enterprises treat regulatory mandates like NDMO as periodic compliance exercises. Build the policies, produce the evidence at audit time, refresh on a cycle, move on. Riyadh Air explicitly rejected that model. The brief was to build continuously, domain by domain, as documentation and operating capability come online together.

  • Make compliance the byproduct of daily operations, not a separate project.
  • Put AI governance in place before AI deployment, not as a retrospective sweep.
  • Make the Trust Layer a living system, not a policy stack on a shelf.

That is the program Data Sentinel was engaged to build.

A Program Designed to Make Trust Continuous, Not Periodic

Three early design decisions shaped how the program runs today.

1

Build the Operating Model Before The Policies.

The governance authority and accountability structures went into place before any documentation. Decision rights, ownership, and the operating model the Trust Layer runs on. Because the Trust Layer had to have authority, not just artifacts.

2

Lead With One Division, Then Scale.

An early-adopter Division was selected as the proving ground for the operating model. The reason: NDMO across fourteen domains, run simultaneously across an entire airline, stalls. Proving the model on one Division first means rollout across the rest of the carrier is a replication exercise, not a redesign.

3

Stand Up AI Governance in Parallel, Not After.

The AI Governance Framework and the AI Risk Management Framework were built alongside the core NDMO work, not bolted on later. By the time AI use cases are ready to deploy, the governance question cannot be “we will figure it out.” It has to be “here are the controls, here is the evidence.”

The result is a single unified program covering NDMO Priority 1 across fourteen domains, AI governance, data quality, and master data, operating as one Trust Layer.

Diagram of the Data Sentinel Trust Layer: enterprise data (Safety, Commercial, Guest, Operations) flows through the Data Foundation and AI Access Gating to AI systems

The Trust Layer between enterprise data and the AI systems that consume it.

The Foundation Being Built

Each component of the Trust Layer is being built inside the airline's environment as the program matures.

Governance and Operating Model

Governance authority and accountability structures established. Decision rights, ownership, and the operating model the Trust Layer runs on. The authority every downstream control depends on.

AI Governance and Risk Management

A comprehensive AI Governance Framework aligned to the EU AI Act and the NIST AI Risk Management Framework. AI Risk Management structured around the four NIST functions: govern, map, measure, manage. Evidence-based AI compliance from day one.

Data Quality Trust Layer

Data Quality framework, standards, policies, and rules being built inside the airline's environment. Live quality monitoring running on the Data Sentinel platform. Measurable controls and continuous improvement, not periodic cleanup.

Audit Evidence

NDMO compliance tracker fully updated and standardized. Deliverable formatting and evidence linkage stand up an audit-ready posture. Movement toward compliance evidence produced continuously.

What This Trust Layer Makes Possible

The Trust Layer at Riyadh Air is being built domain by domain, with governance authority in place, an AI Governance Framework aligned to international standards, and a Data Quality foundation running inside the airline's environment. What it opens up is more consequential than any single deliverable.

Every Data and AI Trust deliverable includes both a current-state view and a set of identified pathways that support Riyadh Air’s National Data Index (NDI) maturity progression across the covered domain.

What It Opens Up

  • AI initiatives will launch against governed, quality-validated data, not against a data preparation backlog.
  • A foundation that moves the program toward compliance evidence produced continuously, not assembled at audit time.
  • One unified Trust Layer serves governance, quality, AI governance, and audit evidence in one place, instead of separate programs.
  • The foundation supports continued NDMO maturity progression without re-architecture.

What Comes Next

Maturity progression continues across NDMO domains. The AI Governance Framework moves from documentation into active enforcement against AI use cases. The Trust Layer extends across the airline's divisions. The continuous foundation becomes the platform on which the rest of the airline is built.

Download Case Study

A Trust Layer That Runs Every Day

This is what continuous looks like: a Trust Layer built into the airline's foundation, producing governance, quality, and AI controls as the airline matures rather than as separate one-off projects.

Download the Full Case Study

Take the Riyadh Air case study with you as a printable PDF. Also available in our resource library.

Download PDF

How trustworthy is your data?

Book a demo to see how a continuously operated Trust Layer becomes the foundation for compliance, quality, and AI.