AI Governance · Cybersecurity · Research

Bassam
Alotaibi

Information Security Manager · PhD Researcher, Newcastle University
Founder, Buniah Association · CISO-level Practitioner

"Accountability cannot be automated."

PhD
Newcastle University
EdgeAI Hub, 2025
MSc
Cybersecurity
Lancaster University
4+
Frameworks &
Research Projects
3
Regulated Domains:
NCA · SAMA · PDPL
AI Governance Federated Learning GRC Frameworks Autonomous Vehicles Saudi Public Sector ISO/IEC 42001 SDAIA · NCA ECC Money20/20 Speaker
About

Building the infrastructure
for accountable AI

BA

Bassam Alotaibi

Riyadh, Saudi Arabia
Information Security Manager at Khebra
Founding President, Buniah Association

I sit at the intersection of AI governance, cybersecurity, and public sector accountability. My work spans hands-on security engineering, academic research, and institution-building — with a consistent thread: how do we make intelligent systems answerable for their decisions?

As Information Security Manager at Khebra, a regulated Saudi financial institution, I operate daily within NCA ECC, SAMA CSF, and PDPL frameworks. My research goes a layer deeper — examining how AI systems used in critical decision-making can be audited, governed, and held accountable at the institutional level.

Through Buniah Association for AI and Data Analytics, I am building Saudi Arabia's civic infrastructure for responsible AI — working with youth, regulators, and practitioners to close the gap between policy aspiration and operational reality.

🎓

PhD Researcher — Newcastle University EdgeAI Hub

2025 → Present · Supervised by Dr Tejal Shah

AI governance in cybersecurity incident response within Saudi public sector organisations. Mixed-methods: SLR, semi-structured interviews, survey research.

🏛️

Founding President — Buniah Association for AI & Data Analytics

Licensed Saudi non-profit · جمعية بُنية

AI governance, data ethics, and digital capacity building for Saudi institutions and youth.

🔐

Information Security Manager — Khebra

Regulated Saudi Financial Institution

NCA ECC, SAMA CSF, and PDPL compliance. GRC intelligence and cybersecurity governance.

🤖

MSc Cybersecurity — Lancaster University

2023–2024 · Supervised by Dr Matthew Bradbury

Thesis: Peer-to-Peer Federated Learning for Intrusion Detection in Autonomous Vehicles. Novel SR-1CNN architecture achieving 99.97% accuracy.

🚀

Founder — Orevix Technologies

Saudi IT Company · Digital Transformation

Targeting digital transformation for government and private sectors. Products include the Midad executive KPI dashboard.

💼

Application Support — Safari Group

2020 – 2022

Provided application support across enterprise systems within Safari Group, building hands-on experience in IT operations and systems management.

Research

From autonomous vehicles
to AI governance

Bridging deep technical research with governance frameworks relevant to regulated environments.

🔬 PhD Research · Newcastle University

AI Governance in Cybersecurity Incident Response — Saudi Public Sector

Examining how AI systems used in incident response within Saudi government organisations can be governed, audited, and held accountable. Mixed-methods: systematic literature review, semi-structured interviews, and survey research.

Supervisor Dr Tejal Shah
Hub EdgeAI, Newcastle
📐 Framework

GARAF — AI Governance & Risk Assessment Framework

A comprehensive framework for evaluating AI governance readiness across Saudi public sector organisations. Ten dimensions, five maturity levels, mapped to SDAIA, NCA ECC, NDMO, PDPL, and ISO/IEC 42001.

Standards ISO/IEC 42001 · SDAIA
Sector Saudi Public Sector
📄 Applied Research

AIG-IRG — AI-Driven Incident Response Governance Framework

Proposes an operational framework for governing AI systems within cybersecurity incident response pipelines. Addresses accountability gaps when automated systems make consequential security decisions.

Focus AI Accountability
Context Incident Response
Projects & Products

Tools built at the
frontier of governance

From GRC intelligence dashboards to AI accountability systems — practical instruments for regulated environments.

🤖

AIDA — AI Decision Audit System

A practical audit instrument for documenting, tracing, and reviewing AI-driven decisions within organisational workflows. Built as both a standalone tool and a potential PhD research instrument. Postgres backend via Netlify Functions.

AI AuditPostgresNetlify
📊

GovAI Pulse — Governance Readiness Platform

An AI governance readiness assessment platform for Saudi public sector organisations. Grounded in the GARAF framework with ten dimensions and five maturity levels. Mapped to SDAIA, NCA ECC, NDMO, PDPL, and ISO/IEC 42001.

GovTechGARAFISO 42001
🛡️

GRC Intelligence Dashboard — Khebra

An internal compliance intelligence dashboard targeting NCA ECC and SAMA CSF frameworks. Provides real-time visibility into control status, risk exposure, and regulatory posture for a regulated Saudi financial institution.

NCA ECCSAMA CSFFinTech
📈

Midad — Executive Dashboard

An executive-level KPI and operational intelligence platform developed under Orevix Technologies. Two verticals: government performance tracking and debt collection operations. Built for decision-makers who need signal over noise.

GovTechKPIOrevix
🚗

P2P Federated IDS for Autonomous Vehicles

Open-source implementation of the MSc thesis framework. SR-1CNN model with ADMM-based asynchronous peer-to-peer federated learning across vehicle mesh networks. Achieves near-perfect detection with zero raw data sharing.

PyTorchFLOpen Source
🌐

Buniah Correspondence Management System

A Firebase-connected correspondence and document management system built for Buniah Association. Deployed on Netlify with a bilingual web portal prototype. Streamlines governance operations for the non-profit.

FirebaseNetlifyNon-profit
Buniah Association · جمعية بُنية

Building Saudi Arabia's
AI governance civil society

A licensed Saudi non-profit dedicated to AI governance, data ethics, and digital capacity building for institutions, practitioners, and youth.

🌐 Visit Buniah Website
بُنية
Buniah Association for AI & Data Analytics

Founded and led by Bassam Alotaibi, Buniah exists to close the gap between AI policy aspiration and operational reality in Saudi Arabia. It works across three tracks: governance standards, practitioner capacity, and youth accountability literacy.

Strategic budget: 18.5M SAR over 2026–2030. Institutional partnerships with SDAIA. Home of Saudi Arabia's first AI accountability programme for youth — Dhameer (ضمير).

18.5M
SAR Strategic
Budget 2026–30
201K
SAR Charitable
Project Funded
3
Core Programme
Pillars
Flagship Initiative
Dhameer — ضمير
Saudi Arabia's first AI accountability programme for youth. Submitted to the "Towards Impact Challenge" grant competition. Builds ethical reasoning skills for the next generation of AI practitioners.
📐

Governance Standards

Developing Saudi-contextualised AI governance frameworks aligned with national regulations (NCA, NDMO, PDPL) and international standards (ISO/IEC 42001, OECD AI Principles).

🎓

Practitioner Capacity

Training programmes, workshops, and the Buniah Academy LMS for security professionals, data practitioners, and public sector employees operating with AI systems.

🌱

Youth Accountability

Dhameer and related initiatives equipping Saudi youth with the conceptual and practical tools to engage critically with AI as citizens, creators, and future decision-makers.

Speaking & Media

Engaging at the frontier
of AI and security

From international financial technology conferences to regulatory engagement and academic forums.

2025

Cybersecurity Governance in the Age of AI

🌍 Money20/20 · International FinTech Conference

Presented on the intersection of AI adoption and cybersecurity governance in regulated financial environments. Addressed accountability gaps in AI-driven security operations for a global fintech audience.

2026

AI Governance Frameworks for Saudi Public Sector

🏛️ SDAIA Institutional Engagement

Engaged with SDAIA on AI governance readiness frameworks. Presented findings from GovAI Pulse and the GARAF framework as practical instruments for Saudi public sector AI accountability.

2026

Dhameer — AI Accountability for Saudi Youth

🌟 Towards Impact Challenge · Grant Competition

Pitched Saudi Arabia's first youth-focused AI accountability programme to grant evaluators. Presented a bilingual programme design grounded in ethical AI literacy and civic responsibility.

2024

Federated Learning & Privacy-Preserving Security

🎓 Lancaster University · School of Computing

Presented MSc thesis research on peer-to-peer federated learning for autonomous vehicle intrusion detection. Demonstrated the SR-1CNN architecture and its implications for privacy-preserving AI security.

Contact

Let's build something
accountable together

Open to collaboration,
research, and conversation.

Whether you are a regulator thinking about AI governance frameworks, a researcher working at the intersection of AI and security, or an organisation looking to build accountability into your AI systems — I would like to hear from you.

I am particularly interested in conversations around AI governance in the Saudi public sector, federated learning for privacy-preserving security, and building civil society capacity for responsible AI.